assurance - Re: [Assurance] RE: Passwords and Office365
Subject: Assurance
List archive
- From: Steven Carmody <>
- To:
- Subject: Re: [Assurance] RE: Passwords and Office365
- Date: Thu, 07 Mar 2013 10:51:17 -0500
- Authentication-results: sfpop-ironport07.merit.edu; dkim=neutral (message not signed) header.i=none
On 3/6/13 3:01 PM, Etan Weintraub wrote:
So, if my understanding is correct, then it is not something that would
eliminate the possibility of Silver, but we must implement some type of
policy and procedure for if it is compromised at the foreign system.
I.e. knowing every account that is on that system, and have a policy
that if that system is compromised, they would need to notify us, and
then we would require all accounts in that population to change/reset
their passwords?
Our Auditor and Security Officer have suggested that in cases like this (ie an enterprise password potentially passing thru a data center/machine outside the control of the campus enterprise) that we should ask both the data center operator and the application owner (if different) for the results of an audit using the SOC2 framework.
It is their opinion that SOC2 is much more detailed than previous frameworks (eg SAS-70), and that any "situation" that can prove a successful audit against SOC2 would be "more than compliant with Silver". They tell me that Google has already supplied us with a SOC2 audit, for instance.
Has anyone else thought of using this approach ?
- [Assurance] Passwords and Office365, Etan Weintraub, 03/06/2013
- [Assurance] RE: Passwords and Office365, Michael W. Brogan, 03/06/2013
- [Assurance] RE: Passwords and Office365, Etan Weintraub, 03/06/2013
- Re: [Assurance] RE: Passwords and Office365, Michael R. Gettes, 03/06/2013
- Message not available
- RE: [Assurance] RE: Passwords and Office365, Brian Arkills, 03/07/2013
- RE: [Assurance] RE: Passwords and Office365, Etan Weintraub, 03/07/2013
- RE: [Assurance] RE: Passwords and Office365, Brian Arkills, 03/07/2013
- Re: [Assurance] RE: Passwords and Office365, Steven Carmody, 03/07/2013
- RE: [Assurance] RE: Passwords and Office365, Etan Weintraub, 03/07/2013
- RE: [Assurance] RE: Passwords and Office365, Brian Arkills, 03/07/2013
- RE: [Assurance] RE: Passwords and Office365, Etan Weintraub, 03/07/2013
- [Assurance] RE: Passwords and Office365, Etan Weintraub, 03/06/2013
- [Assurance] RE: Passwords and Office365, Brian Arkills, 03/06/2013
- Re: [Assurance] RE: Passwords and Office365, Cantor, Scott, 03/06/2013
- [Assurance] RE: Passwords and Office365, Michael W. Brogan, 03/06/2013
Archive powered by MHonArc 2.6.16.