• los angeles data center
  • chicago data center
  • san francisco data center
  • new york data center
  • new jersey data center

    SSAE 16 Compliant Data Center

    SSAE 16 logo

    After completing a rigorous audit from a certified independent CPA, Colocation America is proud to announce that all 22 data centers are operating in full compliance to the new SSAE 16 standards. With this new certification, all servers hosted with Colocation America are secured through the implementation of IT controls that adhere to the new SSAE 16 guidelines. Technicians working within the data center facility operate according to a strict internal process to ensure that all servers are managed according. The new guidelines set forth by the American Institute of Certified Public Accountants (AICPA) are the standard that many colocation providers must comply with but many are unsure about SSAE 16. There is much confusion as to which reporting standards a business should ask for from its data center service provider so here is a basic rundown for each type of SSAE 16 reports.

    What is SSAE 16?

    The Statement on Standards for Attestation Engagements No. 16, or simply SSAE 16, is a set of guidelines for reporting on the level of controls at a service organization. The guidelines were created by the AICPA and went into effect June 15, 2011; replacing SAS 70 as an auditing standard for service organization. The new standard of reporting on internal controls of a service organization was drafted in order to update organizations in the US service industry to reporting standards that complies with the International Standard of Assurance Engagements No. 3402 (ISAE 3402). There are two types of reports for SSAE 16 along with the addition of a new reporting framework, the Service Organization Control (SOC).

    SSAE 16 Type I and Type II

    An SSAE 16 Type I and Type II report is an effective way to communicate information about the controls a service organization has on its system. Both reports detail the opinion of an independent service auditor's report on the organization's system and the service organization's description of the system. However, any information provided by the independent auditor in regards to testing the service and its operating effectiveness are optional for a Type I report.  A Type I report is geared towards service organizations that had not gone through a SAS 70 audit and would like to be set on its own path to a Type II reporting standard. The report covers the service organization's controls of its system for a specific point in time. A Type II report details the testing done on the service organization's controls and its effectiveness. The audit usually last over a minimum period of six months which is stated in the report.

    SSAE 16 type II compliant data center

    Service Organization Control (SOC) Reports

    With the new framework of the SOC reports added to the SSAE 16 standards, SSAE 16 can now replace SAS 70 for service organizations to report on its internal business practices and system controls. The SOC reporting framework consists of 3 types of reporting standards; the SOC 1, SOC 2, and SOC 3. SOC 1 reporting uses the SSAE 16 professional standard and is more geared towards reports on the Internal Control over Financial Reporting (ICFR). It is designed to be a reporting standard for a business' financial reports, highlighting its financial accounting and reporting practices. Although it is similar to the SAS 70 reports it is not relevant to service organizations like data centers which manage a business' IT infrastructure.

    SOC 2 & SOC 3 Reports for Data Center Providers

    SOC 2 and SOC 3 reports are issued under the guidelines set forth by the AT Section 101 attest standard. The report details the service organization's internal system architect focusing on the following criteria:

    AICPA SOC reporting standard
    • Security
    • Availability
    • Processing Integrity
    • Confidentiality
    • Privacy

    Due to the rise in data center hosting, SaaS, and cloud hosting, the new SOC framework was put in place by the AICPA in order to separate service organizations into different categories. In short, an SOC 1 report detail the controls over financial reporting of an organization while SOC 2 and SOC 3 reports are about the internal controls of the system that host the financial accounts and records of an organization. Both SOC 2 and SOC 3 reports are more relevant for a business that are looking for a detailed reports over the internal controls a data center provider have set in place to protect against security breaches and prevention of data corruption.

    Still Confused?

    We here at Colocation America are ready to help you figure out your financial reporting needs. Corporations that abide by the Sarbanes-Oxley regulations will have to get a thorough understanding of the security practices put in place that protect their dedicated servers. Figuring out which reports would provide the most relevant information is a key part in understanding the security of your sensitive business data. We will be happy to discuss with you and your auditor which type of reports you need to make sure that you (and us) stay in compliance with the operating standards of a good business.

    Click to Talk
    • Get A Free Quote
      • Value entered for e-mail is invalid
        Please fill up missing fields below
         
         
         
         
        Can not see the code.
    • Los Angeles Colocation
      • Located in the downtown area of Los Angeles, California, One Wilshire is one of the industry's premier points of interconnection for Los Angeles Colocation. Originally built in 1966, the facility has been renovated over time to accommodate the needs of telecommunications companies and colocation hosting service providers in respect to electricity, emergency power, cooling and connectivity requirements. These dramatic changes have enabled media solutions providers, content delivery networks and hosting firms to connect to well over 240 of the world's top carriers.

    • New York Colocation
      • Located in the heart of Tribeca in New York City, our 60 Hudson location is one of the premier strategy connection points for the largest IP carriers in the world. Because of its quality infrastructure, strategic market location and advanced data backup features, this New York Data Center has become a popular choice for firms targeting East Coast markets. The East Coast is a prime hot spot for market movers, consumer demand and media consumption. Placing a server in this region gives your business an upper hand in reaching your targeted audience quickly and efficiently. At 60 Hudson, we offer the flexibility and scalability at competitive pricing to help your business thrive.

    • New Jersey Colocation
      • Our New Jersey Data Center offers reliable custom solutions for businesses who need dependable colocation services. Strategically located on the backbone of Internet sources for the state, this center provides simple and quick access to East Coast users. Whether you're looking to reach a new targeted market, searching for reliable data backup or looking to expand IT operations at competitive pricing, our New Jersey location can help fulfill your needs. Our expert engineers are there to assist with troubleshooting, server monitoring and custom configurations for your hardware.

    • San Francisco Colocation
      • Located in the Paul network data transfer center, our San Francisco Colocation offers the tools needed to boost your business productivity. With direct access to quality IP providers, your speed, reliability and security will be maximized. Because of its location and updated facility, clients are privy to maximum uptime, secure data transfers, as well as firewall and physical security 24/7. With its proximity to Silicon Valley, our San Francisco data center offers simple connectivity to Asian markets and West Coast audiences.

    • Chicago Colocation
      • Our 14 Chicago Data Centers are properly poised to give companies an edge over their competition. The combination of advanced infrastructure, market location and extensive backup features facilitate the connection to targeted Mid-West markets. Our experienced staff are there to provide you with 24/7 support with anything you may need and help keep your hardware and software updated. Whether you're looking to connect with Chicago, the Mid-West or the broader US, our proven track record will keep your connections will give you an advantage over your competitors.

    data center news
    colocation provider
    dedicated server
    Be the first to know about our
    new products/deals Enter your email adress:
     
     
    SSAE 16 compliant
    pci compliant hosting
    hipaa compliant