Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.
Two information security certifications you can trust
Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?
- The International Organization for Standardization (ISO) 27001
- The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)
International Organization for Standardization (ISO)
27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information
System and Organization Controls (SOC)
The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.
SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.
Why ISO 27001 and SOC 2 are important
The value of these third-party attestations is two-fold:
- Organizations can show they have passed an independent external audit
- Third-party attestations save organizations the time of having to do their own audits
In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.
Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.
So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.
We’re powered by decades of setting standards in marketing services
At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.
The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.
About our expert
Ben Rothke, Senior Information Security Manager
Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.
Latest posts
Kevin Dunn shares his thoughts after 30 days as Experian’s new Chief Revenue Officer.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris rhoncus augue sit amet mi rutrum, et egestas neque hendrerit. Aenean quis lectus dui. Quisque vitae posuere lectus. Nulla varius tincidunt mauris ut pharetra. Pellentesque semper mauris risus, et varius ante pretium ut. Duis varius ante a augue sodales, in consequat augue vehicula. Suspendisse potenti. Donec massa leo, efficitur vel eros ac, facilisis luctus massa. Ut pharetra eros diam, in fringilla neque elementum et. Morbi velit mauris, blandit et congue eu, convallis non augue. Curabitur porta sodales tellus vel porta. Morbi vel felis non neque efficitur venenatis. Nullam lobortis blandit ex id mollis. Donec euismod iaculis rutrum. Heading Description Heading Description Heading Description Vestibulum sed quam elit. Quisque bibendum nulla quam, non gravida tellus venenatis id. Ut a tellus facilisis, elementum ipsum ut, sodales orci. Nullam justo leo, condimentum in volutpat eu, gravida vel est. Ut placerat nulla erat, vel finibus lorem gravida at. Vivamus quis est id diam rhoncus blandit. Cras dignissim auctor diam, lobortis consectetur felis. Nulla accumsan lorem et augue pulvinar fermentum. Quisque ac nisl suscipit, imperdiet mauris eget, dignissim augue. Quisque tempus condimentum rhoncus. Vivamus in blandit nisi. Suspendisse sed metus rhoncus, vehicula nulla laoreet, volutpat neque. Morbi viverra in lacus id gravida. Aliquam velit ex, blandit at metus a, efficitur rutrum tortor. Fusce facilisis, nulla eget dapibus sagittis, sapien justo rhoncus nisi, ut placerat velit orci at velit. Sed finibus turpis ligula, et fermentum ligula rhoncus sit amet. Our 2026 Digital trends and predicitions report is available nowand ereveals five trends that will define 2026. From curation becoming the standard in programmatic to AI moving from hype to implementation, each trend reflects a shift towards more connected, data-driven marketing. The interplay between them will define how marketers will lead in 2026. Download now
Why an identity framework matters more than any single identifier The challenge facing marketers today isn’t a single identifier on a deprecation timeline. It’s the increasing fragmentation of signals and identifiers across browsers, devices, apps, and platforms. This shift introduces complexity into how audiences are reached and measured, as signals behave differently in every environment, and it becomes more complex to piece together a complete view of the consumer. Each environment contributes to its own set of visibility gaps, making identity less predictable and more uneven. The result is a patchwork of inconsistent identity signals rather than a single, predictable decline. While you can’t control how platforms evolve, you can control how you respond to fragmentation. The future won’t be defined by the loss of any single identifier, but by your ability to unify, interpret, and activate the many signals that remain. Marketers who adopt a flexible, identity framework will be best positioned to create consistency in an otherwise fragmented landscape. At Experian, we believe flexibility starts with intelligence. For decades, we’ve used AI and machine learning to help marketers understand people’s behavior more clearly, respect their privacy, and deliver messages that drive business outcomes. Our technology brings identity, insight, and intelligence together, so even as the number of signals grows and becomes more varied across environments, marketers can reach the right people with relevance, respect, and simplicity. This intelligence acts as the connective tissue across fragmented ecosystems, ensuring marketers can recognize and reach audiences consistently wherever they appear. What forces are driving fragmentation in identity and signals? Changes to traditional IDs: Since Apple introduced ATT, access to IDFA has become inconsistent across apps and devices. Google’s evolving Android privacy roadmap adds another layer of variability, fragmenting mobile addressability. Safari and Firefox have long restricted third-party cookies, while Chrome continues to support them for now. This creates different signal availability across browsers, contributing to an uneven and increasingly fragmented identity landscape on the open web. Shifts in signals: IPv4 to IPv6 migration introduces mismatched identity structures that complicate continuity across environments. Platform-driven fragmentation: Closed ecosystems and uneven adoption of evolving RTB standards (like OpenRTB 2.6 updates designed to support new identifiers and consent signals) create differences in which identifiers and consent signals are shared in the bidstream. At the same time, the rise of alternative or “universal” IDs—often developed by individual platforms, publishers, or technology companies—means that multiple ID types can appear within the same auction, each with its own structure, rules, and level of support. These differences reduce interoperability across platforms and contribute to a more fragmented activation landscape. Each change creates an identity silo. Together, they form an ecosystem defined by fragmentation rather than absence. Without an identity framework, these environments operate as disconnected identity islands. A multi-ID world requires a unified identity framework Alternative IDs play an important role, but they also expand the number of signals marketers must reconcile. Without a consistent identity layer, more IDs often mean more complexity—not more clarity. Common alternative IDs in use today: UID2: The Trade Desk’s UID 2.0, an iteration of their original Unified ID 1.0, which was still reliant on third-party cookies, creates persistent IDs with user-provided email addresses and phone numbers. ID5: This independent identity provider builds an identity infrastructure that powers addressable advertising across channels. It can create an ID based on both deterministic and probabilistic data. Hadron ID: Hadron ID is a unique, interoperable identity system (including first-party, audience-based, contextual, deterministic, and probabilistic) developed by Audigent, now part of Experian, to drive revenue for publishers by making their audience data and inventory actionable for media buyers. Industry reports suggest roughly one-third to two-fifths of open-auction traffic carries alternative IDs, sometimes multiple per request. Among Experian clients, adoption of alternative IDs rose 50% year over year, with a 30% increase in IDs resolved to individuals via our Digital Graph. Identity isn’t disappearing; it’s multiplying. A modern identity framework resolves these identifiers into a single, privacy-safe consumer view.