<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloud provider auditing requirement in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Cloud-provider-auditing-requirement/m-p/18452#M840</link>
    <description>&lt;P&gt;Dear friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My company needs to go through auditing by our customers (large financial firms) as part of our sales process. We use one of the major cloud providers for most of our infrastructure, and one of our clients insists on auditing the actual cloud provider. Does anyone know anything about such a process, where Azure or AWS would submit to a security audit for one their customers' customers? If so, how does one start?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jan 2019 03:04:29 GMT</pubDate>
    <dc:creator>talhorns</dc:creator>
    <dc:date>2019-01-30T03:04:29Z</dc:date>
    <item>
      <title>Cloud provider auditing requirement</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Cloud-provider-auditing-requirement/m-p/18452#M840</link>
      <description>&lt;P&gt;Dear friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My company needs to go through auditing by our customers (large financial firms) as part of our sales process. We use one of the major cloud providers for most of our infrastructure, and one of our clients insists on auditing the actual cloud provider. Does anyone know anything about such a process, where Azure or AWS would submit to a security audit for one their customers' customers? If so, how does one start?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 03:04:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Cloud-provider-auditing-requirement/m-p/18452#M840</guid>
      <dc:creator>talhorns</dc:creator>
      <dc:date>2019-01-30T03:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud provider auditing requirement</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Cloud-provider-auditing-requirement/m-p/18458#M841</link>
      <description>&lt;P&gt;You could try contacting your cloud provider and asking them, but they're very likely to point you in the direction of their SOC reports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/trustcenter/compliance/soc" target="_blank"&gt;https://www.microsoft.com/en-us/trustcenter/compliance/soc&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://aws.amazon.com/compliance/soc-faqs/" target="_blank"&gt;https://aws.amazon.com/compliance/soc-faqs/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://cloud.google.com/security/compliance/soc-2/" target="_blank"&gt;https://cloud.google.com/security/compliance/soc-2/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 11:06:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Cloud-provider-auditing-requirement/m-p/18458#M841</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-01-30T11:06:52Z</dc:date>
    </item>
  </channel>
</rss>

