Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.
Two information security certifications you can trust
Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?
- The International Organization for Standardization (ISO) 27001
- The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)
International Organization for Standardization (ISO)
27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information
System and Organization Controls (SOC)
The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.
SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.
Why ISO 27001 and SOC 2 are important
The value of these third-party attestations is two-fold:
- Organizations can show they have passed an independent external audit
- Third-party attestations save organizations the time of having to do their own audits
In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.
Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.
So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.
We’re powered by decades of setting standards in marketing services
At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.
The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.
Contact us today
About our expert

Ben Rothke, Senior Information Security Manager
Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.
Latest posts

Strong Revenue Performance and Thriving Culture Contribute to Industry Recognition NEW YORK, Sept. 15, 2016 /PRNewswire/ — Tapad, the leader in cross-device marketing technology and now a part of Experian, was named a top company on Inc. Magazine’s list of the 5000 fastest-growing private companies in the U.S. In addition, Tapad won the TMCnet 2016 Tech Culture Award. The exclusive Inc. 5000 ranking highlights the fastest-growing privately-held* companies in America. These distinguished companies have achieved success in strategy, service and innovation. TMCnet recognizes talented tech professionals who are committed to building a culture that prioritizes employee growth, collaboration and engagement. Tapad continues to broaden their presence into new markets, having launched in APAC earlier this year, as well as continuing their European expansion. Tapad’s proprietary technology, The Device Graph™ is leveraged by more marketers and brands to understand digital engagement across devices. The company’s rapidly expanding client base includes numerous Fortune 500 company brands as well as all four major advertising holding companies in the U.S. “We have an exceptional team of innovative people who are all working very hard to achieve the kind of results these publications are recognizing,” said Tapad CEO and Founder, Are Traasdahl. “Given that, we have an even greater responsibility to our talent to create an environment that fosters innovation and nurtures open communication. Ultimately, this is how we will continue to reach our very ambitious goals of becoming the world’s leading unified marketing technology provider.” Tapad’s award-winning work culture is defined by its gold-standard benefits which include a six-month parental leave policy, unlimited vacation time, company-sponsored meals and office space designed to facilitate collaboration and open communication. Tapad’s highly talented team has also received multiple customer service awards in 2016. These awards include the iMedia ASPY awards for Best Customer Service and Best Mobile Partner as well as recognition from The Communicator Awards of Excellence in Interactive Media. *Prior to Tapad’s acquisition by Telenor in February 2016. Contact us today

The Tapad Device GraphTM Had Twice the Precision and Three Times the Scale as Next Competitor New York, September 14, 2016 – Just-released findings of a Hotels.com® study revealed that Tapad’s (part of Experian) cross-screen marketing technology achieved the highest levels of precision and scale among competitors. According to the leading online accommodation booking website, after a rigorous, three-and-a-half month vendor analysis, Tapad achieved twice the precision of the next highest-scoring cross-screen offering and three times greater scale. The two other companies evaluated were not named. Said Helene Cameron-Heslop, Senior Manager of Analytics of the Hotels.com brand, “Our team implemented an extremely rigorous vetting of open, cross-screen technology vendors. At the outset, we assumed we would have to compromise on either scale or accuracy – particularly given the importance to our brand of operating in a privacy-safe setting. We were surprised to find a complete package, but Tapad’s Device Graph won out on scale, accuracy and privacy; making our choice of partners very clear.” In another metric critical to the Hotels.com brand, The Tapad Device GraphTM was eight times more “unique” than the next closest offering, meaning Tapad’s graph was found to have a much greater number of connections not seen in any of the other graphs. In addition to precision, uniqueness and scale, the Tapad Device GraphTM was found to have: ● 100% higher recall● 47% more incremental matches● 53% higher North American market coverage● 101% higher F-Score* “A valuable cross-device solution should enable partners to get everything they’re looking for from a single vendor,” said Tapad Founder and CEO, Are Traasdahl. “We are deeply impressed with how thorough Hotels.com was in their vetting, and we confidently tackle the complex challenges of the martech industry thanks to our superior technology. Everyone loves a bake-off, and Tapad is no exception – delivering best-in-class results in areas that really count.” *F-score is a statistical measurement that takes precision and recall together. The calculation is 2*(precision*recall)/precision + recall). It gives you one number instead of two numbers to look at and judge performance. Contact us today

Five Norwegian startups selected to establish U.S. presence NEW YORK, Aug. 15, 2016 /PRNewswire/ — Tapad, the leader in cross-device marketing technology and now a part of Experian, has announced its new entrepreneurial mentorship initiative, the Propeller Program. Five early-stage startups from Norway have been chosen by Are Traasdahl, native of Norway and Tapad’s CEO and founder. The selected companies will share Tapad’s New York City workspace, receive C-level guidance and help establish a U.S. presence. The following companies have been selected to participate in the inaugural Propeller Program – a 12-month program beginning September 19, 2016: Bubbly – Developers of a platform that enables in-store customer feedback with dashboards and tools that facilitate real-time store response BylineMe – A marketplace for freelancers, publishers and brands to connect for content creation and distribution services Eventum – A property-sharing group that digitally assists in securing venues for meetings and corporate events Xeneta – A database that organizes the best contracted freight rates in real time and on demand “We are supporting startups that we feel represent the future of service offerings,” said Traasdahl. “It is with incredible pride that we invite these entrepreneurial teams from Norway to join us in New York Citythis year. Mentorship opportunities for early-stage companies are so important, particularly for those based outside the U.S. I look forward to giving the Propeller Program participants access to the expertise of my seasoned team and to our wide network of resources. Hopefully, it will be a game-changing year for many of them.” Contact us today