SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Blog Feature

SOC Examinations

By: LAUREN EDMONDS
September 14th, 2015

Can I have disaster recovery controls within my SOC 1 test of controls matrix?

Blog Feature

SOC Examinations

By: DEBBIE ZALLER
June 15th, 2015

Is there a SOC certification similar to an ISO 27001 certification?

Blog Feature

SOC Examinations

By: STEPHEN HALBROOK
August 14th, 2014

Is your organization ready for a SOC 2 examination? Here are five steps to help successfully prepare for one: 1. Validate the nature of the request. Does your client base understand the various SOC reporting options and what they are asking of your organization from a compliance reporting perspective? Is there a connection to internal controls over financial reporting (ICFR) of the services that you provide to your clients, or are you looking at general controls of a system that are relevant to security, availability processing integrity, confidentiality, and privacy? SOC 1 can oftentimes be misused by the general public as a generic reference to third party audits. There is misconception in the marketplace; help prevent it.

Blog Feature

Compliance and Certification | SOC Examinations

By: MIKE MEYER
May 11th, 2014

Periodic reviews of system access are critical for service organizations who wish to maintain strong internal control around information security. Access privileges to systems or physical locations that impact the customer’s business environment should be commensurate with the requirements of the services provided. These privileges should also facilitate segregation of incompatible duties. For example, in order to segregate incompatible duties, a system developer generally should not also have access to migrate changes to the production environment.

Blog Feature

SOC Examinations

By: DANNY MANIMBO
April 7th, 2014

When auditors begin to test procedures for compliance examinations (i.e., SOC 1, SOC 2), there are cases where the clients are performing certain tasks; however, they are not documented, which puts the auditors in a precarious position.

Blog Feature

SOC Examinations

By: RYAN BUCKNER
March 1st, 2014

In my line of work, it is not only advisable to have a mastery of the facts, but prudence would suggest that a good dose of foresight and reason based on actual experience can often times be as valuable a tool. Since the days of the SAS 70, we have seen several subjective opinions about both the appropriateness and/or the ineffectiveness of the SAS 70 report. Even today, there continues to be concerns on how SOC 1 reports, also known as SSAE 16 examinations, are being used in situations that fail to have bearing on internal controls over financial reporting.

Blog Feature

Cloud Computing | SOC Examinations

By: Douglas Barbin
December 17th, 2012

DevOps, like Agile development before it, accents the continuous evolving state of software development, particularly in cloud-base software. Like any technology change, there is no surprise that auditor and security professionals are challenged as the traditional separation of duties become more and more gray. As someone who oversaw product management in an Agile / SaaS development environment and now manages audits and certifications for leading edge cloud solution providers, I offer my perspective.

Blog Feature

Cloud Computing | ISO Certifications | SOC Examinations

By: RYAN BUCKNER
May 23rd, 2011

In October, I posted an article on the various alternatives for CPA attestation reports. This past week, the AICPA issued its guidance on Service Organization Controls (SOC) 2 reports and an update to that post was in order. Here is what the newly released SOC 2 guidance states:

{