{"id":30,"date":"2012-10-13T07:15:00","date_gmt":"2012-10-13T07:15:00","guid":{"rendered":""},"modified":"2022-04-06T20:23:29","modified_gmt":"2022-04-06T20:23:29","slug":"misconceptions-around-ssae-16-isae3402-csae-3416","status":"publish","type":"post","link":"http:\/\/mayanktrivedi.net\/technotes\/2012\/10\/13\/misconceptions-around-ssae-16-isae3402-csae-3416\/","title":{"rendered":"Misconceptions around SSAE 16 \/ ISAE3402 \/ CSAE 3416"},"content":{"rendered":"<div dir=\"ltr\" style=\"text-align: left;\">Post my previous post, I received a mail from one of my Friend around SSAE 16 \/ ISAE 3402 and I provided the reply to the friend and then thought, why not share the explanation with the wider Audiences for the good. &nbsp;May be if somewhere I made a mistake, I would also get to learn &#8211;<\/p>\n<p><\/p>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">Hi MT,<\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">&nbsp;<\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">You are doing a good job&#8230;:-)<\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">&nbsp;<\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\"><span style=\"color: red;\">&#8220;The discussion was more centered around the need of Assurance Standards like SSAE 16 and ISAE 3402 and the interesting twist that was brought in was &#8220;If my organization is ISO 27001 Certified, do I still need to undergo SSAE 16 or ISAE 3402 Audits?&#8221;<\/span><\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\"><span style=\"color: red;\">It took me good enough time initially to make the person understand that the ISO 27001 standard and the controls framework revolves around the Information Security and not just IT Security.&#8221;<\/span><\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">&nbsp;<\/div>\n<div style=\"background-color: white; color: #222222; font-family: arial, sans-serif; font-size: 13.333333969116211px;\">\n<div>Well, I&#8217;ve the same confusion&#8230; rather argument. Though ISO27001 is focused on Information Security, it doesn&#8217;t stop you from adding additional controls, if required. As it is a standard, everything is in black and white..nothing more nothing less&#8230;just follow\/comply to&nbsp;whatever is mentioned. If you need to add additional controls that you considered as very important, then add the controls and comply.<\/div>\n<div>&nbsp;<\/div>\n<div>Wherein SSAE16 leads to confusion as they allow you to define your own controls based on GCC (general computer controls). If I select 10 controls, which I feel as important,&nbsp;for example, it is not necessary that you will agree to that, as you may have a different opinion and probably select few different controls that you feel as important. In other words, if 2 people are asked to define the controls for the same environment, the list of controls will definitely not match.<\/div>\n<div>&nbsp;<\/div>\n<div>Whether it is ISO27001 or SSAE 16, the auditor will test the stated\/defined controls and provide an opinion&#8230;of course in a different way i.e. either qualification or non-conformity, but the end result is the same.<\/div>\n<div>&nbsp;<\/div>\n<div>So, the question is still the same, &#8220;If my organization is ISO 27001 Certified, why do I still need to undergo SSAE 16 or ISAE 3402 Audits?&#8221;<\/div>\n<div>&nbsp;<\/div>\n<div>Can you help me understand please?<\/div>\n<div>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/div>\n<div>My Reply &#8211;&nbsp;<\/div>\n<div><\/div>\n<div>\n<div style=\"font-size: 13.333333969116211px;\"><span style=\"color: #000099;\"><span style=\"font-family: verdana,sans-serif;\">The point is the way the Audit is approached. &nbsp;ISO 27001 is quite Generic Control Set that revolves around the set of Industry Standard Controls that may or may not be applicable to the set of given Industry Scenario. &nbsp;The ISO 27001 is Organization wide control environment where you may select or omit the control from within the 133 controls that are defined in the Standard. &nbsp;You may add a new control, but that needs to be covered under one of the predefined 11 control clauses (domains). &nbsp;once done, you define the SOA to identify the controls as applicable\/omitted from your Organizational environment. &nbsp;Under such case the Audit is focused around the SOA and the reasoning for omitting a given control.<\/span><\/span><\/div>\n<div style=\"font-size: 13.333333969116211px;\"><span style=\"color: #000099;\"><span style=\"font-family: verdana,sans-serif;\"><br \/><\/span><\/span><\/div>\n<div style=\"font-size: 13.333333969116211px;\"><span style=\"color: #000099;\"><span style=\"font-family: verdana,sans-serif;\">However, when you look at the specific set of operations for the given Client, the environment may differ from the overall organizational control set. &nbsp;Certain controls may be applicable from the current set of ISO 27001 controls and certain controls that have been omitted from the Organizational perspective may be applicable in that scenario. &nbsp;This certainly requires the organizations to go for SSAE 16 \/ ISAE 3402 (CSAE 3416 in Canadian Context) by defining specific set of controls. &nbsp;<\/span><\/span><\/div>\n<div style=\"font-size: 13.333333969116211px;\"><span style=\"color: #000099;\"><span style=\"font-family: verdana,sans-serif;\"><br \/><\/span><\/span><\/div>\n<div style=\"font-size: 13.333333969116211px;\"><span style=\"color: #000099;\"><span style=\"font-family: verdana,sans-serif;\">Let me give you an interesting perspective on the difference of Scope of ISO 27001 and SSAE 16 \/ ISAE 3402 \/ CSAE 3416 &#8211;&nbsp;<\/span><\/span><\/div>\n<div style=\"font-size: 13.333333969116211px;\">\n<ol>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">ISO 27001 specifically focuses on the Controls around Information Security, it does not cover the other scope like Contract Management, Delivery Organization &amp; SLAs, these controls may be defined in the SSAE 16 \/ ISAE 3402 \/ CSAE 3416. &nbsp;ISO 27001 doesn&#8217;t have the provision on these sets<\/span><\/li>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">ISO 27001 Certification revolves around the Set of 11 Control Clauses, where as in case of the SSAE 16 \/ ISAE 3402 \/CSAE 3416, you would find that the Control Clauses can be customized to suit the environment, operations and services to be covered.<\/span><\/li>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">Interesting point is around the set of Controls and Operations that are covered in both the cases. &nbsp;As I mentioned above ISO 27001 focuses on Information Security and the Controls and Operations around that. However if we look at the SSAE 16 \/ ISAE 3402 \/ CSAE 3416 they can cover other set of operations and controls like Accounting Principles, Financial Controls etc.<\/span><\/li>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">SSAE 16 \/ ISAE 3402 \/ CSAE 3416 SOC 1 controls and Audit Reports revolve around the Service Organization Controls that impact the Internal Controls on Financial Reporting (ICFRs) of the client. ISO 27001 does not focus on ICFRs.<\/span><\/li>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">SOC 2 Reporting focuses more around 5 Trust Principles and how each control is implemented, monitored, executed etc. &nbsp;Even SOC 3 Controls focus on the same 5 trust principles, but the objective of reports is different<\/span><\/li>\n<li style=\"margin-left: 15px;\"><span style=\"color: #000099; font-family: verdana, sans-serif;\">SOC 1 &amp; SOC 2 Audit Reports are restrictive reports and the Intended Audience are limited set of people within the Service Provider and Client Organization. SOC 3 reports are not so confidential and can be shared publicly as desired.<\/span><\/li>\n<\/ol>\n<div><span style=\"color: #000099; font-family: verdana, sans-serif;\">I hope this clarifies you with the difference between the two Standards and Reporting Requirements<\/span><\/div>\n<div><span style=\"color: #000099; font-family: verdana, sans-serif;\"><br \/><\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Post my previous post, I received a mail from one of my Friend around SSAE 16 \/ ISAE 3402 and I provided the reply to the friend and then thought, why not share the explanation with the wider Audiences for the good. &nbsp;May be if somewhere I made a mistake, I would also get to &hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,42,17,41,43],"tags":[],"class_list":["post-30","post","type-post","status-publish","format-standard","hentry","category-audits","category-csae-3416","category-governance-risk-and-compliance","category-isae-3402","category-ssae-16","entry entry-center"],"_links":{"self":[{"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/posts\/30","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/comments?post=30"}],"version-history":[{"count":1,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/posts\/30\/revisions"}],"predecessor-version":[{"id":84,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/posts\/30\/revisions\/84"}],"wp:attachment":[{"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/media?parent=30"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/categories?post=30"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/mayanktrivedi.net\/technotes\/wp-json\/wp\/v2\/tags?post=30"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}