What’s the difference between PCI and SAS 70 compliance when I am shopping for a hosting company to stick the servers in

hostingpci-dss

I am looking for hosting, ec2 is SAS 70 compliant (almost) and I would have gone straight for PCI compliant and tier 4 only but I'm considering SAS 70. What are the differences or similarities?

Best Answer

Unless you process credit card transactions, PCI compliance is irrelevant for your purposes. Even if PCI compliance is relevant to you, the SAS 70 audit is more important for the purposes of verifying physical and environmental security of your servers, among other issues. However, keep in mind that a SAS 70 audit is considered a replacement from the organization (the data center in this case) being audited over and over by their clients and their client's auditors. Unlike most organizations, you are going to step foot in the data center and will observe many of the controls yourself. However, you still request a copy of the report and review it. Make sure it is current. Ideally, they have a Type 2 SAS 70 audit versus a Type 1 audit. Verify whether the auditor's opinion letter is unqualified (good) or qualified (means an issue was so significant that it was pulled into the letter), and that the scope seems relevant to the services provided.