Virtustream Achieves Cloud Security Alliance’s Level 2 Star Attestation

Share Article

Achievement Evidences Virtustream’s Strong Security and Compliance Strategy

Schellman & Company, LLC (Schellman), a leading provider of compliance and audit services, today announced that Virtustream, Inc. (Virtustream), the enterprise-class cloud provider and an EMC Federation company, has achieved the Cloud Security Alliance’s (CSA) Level 2 Star Attestation, making Virtustream one of only five organizations to successfully complete a STAR Attestation examination.

“Many of Virtustream’s customers are blue chip enterprises with complex technology landscapes that require adherence to the industry’s most stringent security controls and policies for cloud environments,” said Kevin Herrin, vice president cloud services at Virtustream. “Achieving the Star Attestation is a component of an overall security and compliance strategy that places Virtustream among an elite set of cloud service and software providers capable of meeting enterprise-level security needs.”

The STAR Attestation examination was conducted on the Virtustream Storage Cloud, a hyper-scale storage platform with enterprise-class resiliency and performance. The scope included the Security, Availability, and Confidentiality Trust Services Principles set forth in TSP section 100; Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, Technical Practice Aids); as well as the 16 domains within the Cloud Controls Matrix (CCM) version 3.0.1. The examination was completed in October 2015 to cover a review period beginning June 10, 2015, through September 30, 2015.

“This is a great achievement for Virtustream and their compliance team,” said Ryan Mackie, Schellman’s ISO practice director. “A tremendous amount of effort went into preparing for the examination, as well as supporting the audit fieldwork. To be identified as one of only five organizations to successfully complete the STAR Attestation is a true accomplishment.”
The STAR Attestation report provides evidence that Virtustream has a well-founded control set, based on cloud service provider best practices, and is operating effectively to deliver trust to their clients and prospects. Virtustream conducted the STAR Attestation examination in tandem with a SOC 1, SOC 2, and SOC 3 examination.

Schellman & Company, LLC is a global provider of assurance and compliance services. As the only company in the world fully accredited to provide a suite of services that includes SSAE 16 (SOC 1) examinations, SOC 2 examinations, PCI DSS / PA-DSS compliance validation, ISO 27001 certification, ISO 9001 certification, HITRUST certification, FedRAMP Assessments, network and application penetration testing services, and now P2PE assessments, Schellman offers clients the unique opportunity to achieve multiple compliance objectives through a single third party assessor. For further information, please visit

Avani Desai, Executive Vice President
866.254.0000 ext. 140

Share article on social media or email:

View article via:

Pdf Print

Contact Author

Avani Desai
Schellman & Company, LLC
+1 866-254-0000 Ext: 140
Email >
Schellman & Company, LLC
since: 05/2002
Like >
Schellman & Company, LLC

Visit website