Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.
Two information security certifications you can trust
Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?
- The International Organization for Standardization (ISO) 27001
- The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)
International Organization for Standardization (ISO)
27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information
System and Organization Controls (SOC)
The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.
SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.
Why ISO 27001 and SOC 2 are important
The value of these third-party attestations is two-fold:
- Organizations can show they have passed an independent external audit
- Third-party attestations save organizations the time of having to do their own audits
In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.
Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.
So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.
We’re powered by decades of setting standards in marketing services
At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.
The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.
Contact us today
About our expert

Ben Rothke, Senior Information Security Manager
Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.
Latest posts

AI is working its way into all aspects of marketing. AI will soon be used to personalize ads for viewers while optimizing based on data.

Discover the importance of navigating the post-cookie world and learn how UID2 can enhance sustainable advertising.

Magnite and Experian have formed a strategic integration to enhance cross-device audience targeting in the advertising industry. Magnite, the largest independent sell-side platform, and Experian, a leader in consumer data and identity solutions, aim to optimize advertising capabilities by activating Experian's Consumer View in Magnite Access, an omnichannel audience product suite. This marks one of Experian’s first forays into a direct sell-side integration, a crucial step for the cookieless era. This collaboration offers targeting and efficiency across digital channels, providing advertisers and agencies with a more effective way to reach consumers. With Experian's robust deterministic offline data, generated from consumer purchase activity, enriched with insights on over 250 million U.S. consumers and 126 million U.S. households, advertisers can look forward to a new benchmark in targeted advertising available through Magnite Access. Thriving in a cookieless world With the looming deprecation of third-party cookies, audience, and identity solutions using first-party data are shifting to the sell-side. To that end, Magnite developed Magnite Access, a suite of omnichannel audience products that make it easier for media owners and their advertising partners to maximize the value of their first-party data assets. Access is adept at thriving in a post-cookie world through its effective utilization of sell-side first-party data, including within Magnite Streaming and SpringServe. Magnite Access’ deterministic and probabilistic tools provide sellers and buyers with a comprehensive solution to leverage their first-party data for audience targeting and insights. Experian's solutions are built to work efficiently in offline environments, making them well-equipped to thrive in a cookieless world. Brands can benefit from Experian's deep integrations within the ecosystem, providing data and audience solutions designed to perform in cookieless environments. "We're excited about the collaborative approach between Magnite and Experian. This off-the-shelf integration of Experian's syndicated audiences and the streamlined ability to receive custom audiences will provide a more accurate and cohesive consumer view, allowing us to reach our target audience and enhance campaign performance seamlessly."sam bloom, ceo, camelot Reach and impact As companies continue to rely on data-driven insights to make smarter, more efficient business decisions, partnerships between leading data and technology providers are becoming increasingly valuable. "Integrating with Magnite allows us to translate our extensive offline and online data into actionable, intelligent solutions for making smarter, more efficient business decisions. With Magnite's expertise in the omnichannel sell-side environment, this partnership is poised to empower businesses with the tools they need to succeed in today's data-driven landscape."chris feo, svp, sales & partnerships, experian Strengthening foundations within streaming Magnite's cutting-edge streaming solutions, integrated with Experian's robust data, facilitate a connection between data and inventory, providing enhanced targeting capabilities and consumer insights. "By integrating Experian's Consumer View capabilities into our platform, we are enabling advertisers to unlock improved targeting capabilities while benefiting from Experian's wealth of consumer insights. Our collaboration with Experian amplifies the value of our streaming solutions and enhances the overall advertising ecosystem by seamlessly connecting data, identity, and inventory."kristen williams, svp, strategic partnerships, magnite Precision and innovation: A new advertising era The synergistic partnership between Magnite and Experian is paving the way for a new era in advertising, offering targeting efficiency across digital channels. This collaboration is not merely a confluence of technologies but a testament to both companies' relentless pursuit of excellence in creating a consumer-conscious advertising ecosystem. By harnessing the wealth of consumer insights and integrating state-of-the-art technologies, Magnite and Experian are contributing to shaping the future of advertising, emphasizing accuracy and efficiency. It's a revolutionary stride toward understanding and reaching the consumer in more meaningful and impactful ways, setting new benchmarks in the advertising world. In a rapidly evolving digital landscape, this collaboration stands as a beacon, guiding brands toward intelligent, informed, and innovative advertising solutions, redefining the possibilities in targeted advertising and audience solutions. Connect with us to learn more about how you can access Experian’s Consumer View data solutions in Magnite Access. To learn more about our partner Magnite, visit their website. Latest posts