Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.
Two information security certifications you can trust
Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?
- The International Organization for Standardization (ISO) 27001
- The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)
International Organization for Standardization (ISO)
27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information
System and Organization Controls (SOC)
The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.
SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.
Why ISO 27001 and SOC 2 are important
The value of these third-party attestations is two-fold:
- Organizations can show they have passed an independent external audit
- Third-party attestations save organizations the time of having to do their own audits
In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.
Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.
So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.
We’re powered by decades of setting standards in marketing services
At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.
The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.
Contact us today
About our expert

Ben Rothke, Senior Information Security Manager
Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.
Latest posts

Combined technology gives marketers an enhanced view of the customer for improved planning, targeting and optimization NEW YORK, July 12, 2016/PR Newswire/ - Tapad, the leader in cross-device marketing technology and now a part of Experian, today announced a partnership with Conversion Logic, the martech industry's most accurate unified marketing attribution provider. Conversion Logic will incorporate unified cross-screen data from Tapad's Device Graph™ to identify related devices and media exposures to enhance reporting on the path to conversion. By connecting Conversion Logic's proprietary Ensemble Method, which combines numerous state-of-the-art machine learning algorithms, tuned for each customer use-case for the most accurate results, with Tapad's unified, cross-device technology, marketers will benefit from a highly scientific approach to assessing advertising effectiveness with full, comprehensive customer insights. Linking these technologies will increase marketers' real-time ability to optimize brands' marketing channel spend and creative at a more granular level. During the past six months, Tapad has rapidly grown its data business, doubling the number of companies integrating the Device Graph™ into their platforms and growing the annualized revenue run rate by 210%. Tapad's highly scalable, cross-device data has been confirmed by Nielsen to be very precise. Tapad augments platforms' and publishers' tech stacks with additional scale and relevancy, granting advertisers amplified targeting and analysis options. The growth of the Device GraphTM has allowed Tapad to provide a growing network that benefits all partners with more efficient, effective consumer engagement. "Combining highly accurate data from Tapad with our own user ID technology and understanding how devices may be related at an individual level provides additional visibility into the path to conversion," said Alison Lohse, COO and co-founder of Conversion Logic. "The more we know about the customer journey, the more effective, efficient and customized marketers can be with marketing efforts. With Tapad, we have achieved a unified customer view that helps us piece together the purchase journey while preserving proven accuracy." "Conversion Logic's Ensemble Method delivers singularly customized and precise results that are not just accurate, but actionable," said Dave Fall, COO of Tapad. "The combination of powerful technology and a user-friendly interface, plus Tapad's ability to only consider relevant and scalable components in the marketplace, creates a more concentrated and beneficial environment for both its partners and clients." Contact us today

B2B marketers can now deliver the right message to the right user at the right time across devices and channels NEW YORK, NY–(Marketwired – Jun 1, 2016) - Madison Logic, one of the world's fastest growing companies dedicated to solving the digital needs of B2B marketers, is partnering with Tapad, the leading provider of unified and now a part of Experian, cross-screen marketing technology solutions. Now business-to-business (B2B) marketers can power targeted advertising and content syndication programs across all channels, including smartphones, computers and tablets. The increasing shift in content consumption across mobile devices makes cross-device identification and attribution a top priority for B2B marketers. The Madison Logic and Tapad partnership gives B2B marketers unprecedented reach and scale with the ability to run always-on, cross-device, account-based marketing programs targeting decision makers who are actively researching similar products and services. "Screens are everywhere and so is the B2B buyer," said Vin Turk, SVP of Audience Development for Madison Logic. "This partnership allows marketers to harness the power of Madison Logic's intent data and combine it with Tapad's cross-device solutions to connect with the most-likely-to-convert prospects with hyper-relevant content wherever and whenever they're doing their research." "Relevance is essential to the success of B2B marketers, particularly now, when breaking through the clutter is difficult," said Dave Fall, COO of Tapad. "This partnership with Madison Logic allows marketers to leverage their existing customers while identifying and reaching new audiences with messaging tailored to every device." For more information about Madison Logic's account-based marketing platform, please visit https://www.madisonlogic.com/account-based-marketing/. For more information about Tapad's cross-platform advertising solutions, please visit https://www.experian.com/marketing/consumer-sync. Contact us today

NEW YORK, June 1, 2016 /PRNewswire/ — Are Traasdahl, CEO and founder of Tapad, the leader in cross-device marketing technology and now a part of Experian, has been named Founder of the Year by the Nordic Startup Awards. The Nordic Startup Awards' Founder of the Year Award recognizes an individual that has shown exceptional achievements in fundraising, customer growth, financial savvy, and/or leadership throughout the past year. The Nordic Startup Awards evaluates hundreds of players in the startup ecosystem, ranging from investors and founders, to developers and journalists in Denmark, Sweden, Iceland, Norway and Finland. Taking place in two stages, each country selects its nominees for consideration for the regional awards which were held in Iceland on May 31, 2016. Traasdahl is recognized for his continuous investment in Tapad as a whole, as well as his dedication to growing and developing Tapad since founding the company in 2010. He has led Tapad from startup through a steady period of growth resulting in an acquisition by the Telenor Group for $360 million in February 2016. "I am truly honored to be named Founder of the Year by the Nordic Startup Awards, among so many other remarkable leaders in the space," said Traasdahl. "That said, this has always been a team effort. We started Tapad with the goal of giving employees unprecedented growth opportunities while developing breakthrough solutions for our clients. This is a win for everyone at Tapad who has committed themselves to these principles over the past four-and-a-half years." Tapad is reinforcing its commitment to fostering entrepreneurship with the launch of their new Propeller Program. Through Propeller, Tapad will host five early-stage companies at Tapad's New York headquarters for a year to set them up for global expansion. In its inaugural year, the first participants will come from Traasdahl's native Norway. For more information on the Nordic Startup Awards, please visit: http://www.nordicstartupawards.com. Contact us today