The Pragmatic Auditor Blog is about audits, assessments, compliance, and certification in the real world of information technology and services.
The Pragmatic Auditor is of the firm belief that:
- No one likes audits — even the IT and security audits that sound more appealing than financial statements
- The vast majority of audits are not optional to the client
- Companies are over-audited due to a standards and regulations that appear unique and different
- There is optimization and efficiencies to be gained when aligning audit and compliance requirements with a company's core set of controls
- A refined methodology and experienced auditors can make the overall process less painful for the client
- There are providers out there that have invested in their security and controls
The blog is the official blog of BrightLine CPAs & Associates, Inc., the first CPA firm established specifically to provide audit services in accordance with Statement on Auditing Standards No. 70 (SAS 70). The company now offers a comprehensive suite of attestation and compliance services that include SSAE 16 examinations (SOC 1), reports on security, availability, processing integrity, confidentiality, and privacy (SOC 2), PCI DSS validations, ISO 27001 certification, compliance assessment, and other attestation services.