Loading...

Tapad earns SOC 2 Type 2 certification for third year in a row

by Experian Marketing Services 4 min read January 24, 2023

Up next in our Ask the Expert series, Ben Rothke, Senior Information Security Manager, reviews two certifications that should be part of your information security strategy: Service Organization Control (SOC) 2 Type 2 and International Organization for Standardization (ISO) 27001. Tapad, a part of Experian, is 27001 and SOC 2 Type 2 compliant.

Two information security certifications you can trust

Seals from Good Housekeeping and Underwriters Laboratories give consumers confidence that they can trust the product that they’re buying. For IT solutions or service providers, what, or who can you turn to for that seal of approval? There are many equivalent third-party attestations you can use. But which should you trust?

  1. The International Organization for Standardization (ISO) 27001
  2. The American Institute of Certified Public Accountants (AICPA) System and Organization Controls (SOC)

International Organization for Standardization (ISO)

27001 is an international standard for information security from the ISO. ISO 27001 is globally acknowledged and sets requirements for controls, maintenance, and certification of an information security management system (ISMS). This international standard provides organizations with a framework to identify, manage and reduce risks related to the security of information

System and Organization Controls (SOC)

The SOC, as defined by the AICPA, is a set of audit reports. SOC reports, like 27001 certificates, are used by service organizations to give their customers the confidence they have adequate information security controls in place to protect the data that they handle.

SOC 2 is an assessment of controls at a service organization regarding security, availability, processing integrity, confidentiality, and privacy. The purpose of the report is to provide extensive information and assurance to a broad range of users about the controls at a service organization that are relevant to the security, availability, and processing integrity of the systems that process user data, as well as the confidentiality and privacy of the information processed by these systems.

Why ISO 27001 and SOC 2 are important

The value of these third-party attestations is two-fold:

  1. Organizations can show they have passed an independent external audit
  2. Third-party attestations save organizations the time of having to do their own audits

In addition to 27001 and SOC 2 Type 2 compliance, we are also certified with ISO 27017 and 27018, which are add-ons to 27001 that are specific to cloud computing. We take the security and privacy of our customers’ data as seriously as they do.

Every cloud service provider (CSP) has a responsibility matrix that details what security and privacy tasks they are responsible for and which ones the customer is responsible for. Any cloud customer that needs to be made aware of what their security tasks are is putting themselves at risk.

So, when you want to engage a CSP, ask them for their attestations. They worked hard for them and will be proud to share their compliance.

We’re powered by decades of setting standards in marketing services

At Experian, we’re a privacy-first business. We’re highly focused on respecting people, their data, and their privacy. We continue to show our dedication to information security by completing these security audits every year.

The constant changes to data compliance regulations can be challenging to navigate, but you don’t have to do it alone. Contact us today. We will be your guide so you can ethically and confidently reach your customers.


About our expert

Ben Rothke headshot

Ben Rothke, Senior Information Security Manager

Ben Rothke, CISSP, CISA, is a Senior Information Security Manager at Tapad, a part of Experian. He has over 25 years of industry experience in information systems security and privacy. His areas of expertise are in risk management and mitigation, security and privacy regulatory issues, cryptography, and security policy development. Ben is the author of Computer Security – 20 Things Every Employee Should Know (McGraw-Hill), and writes security and privacy book reviews for the RSA Conference Blog and Security Management magazine.


Latest posts

Loading…
Deliverability: the key to email marketing – how to ensure your customers actually receive your emails

Learn what deliverability really means in email marketing and how to ensure your customers actually receive your emails.

Published: Feb 10, 2017 by

5 marketing resolutions for better customer engagement

Top 5 marketing resolutions to improve your marketing programs. Learn the most effective way for better customer engagement.

Published: Feb 08, 2017 by

Dextro Analytics partners with Tapad, a part of Experian, to deliver persistent measurement across devices

Dextro clients to achieve increased accuracy in cross-device consumer measurement and engagement NEW YORK, Feb. 6, 2017 /PRNewswire/ — Dextro Analytics, a pure play analytics company that harnesses the power of human learning and artificial reasoning to drive more informed and effective consumer marketing, is partnering with Tapad, the leading provider of unified, cross-screen marketing technology solutions and now a part of Experian. The deal is effective immediately and the scope of the partnership covers North America. Additional terms were not disclosed. Leveraging Tapad's privacy-safe Device Graph™, Dextro Analytics will be able to significantly bolster its insight engine to decode complex customer journeys. Armed with more relevant, actionable insights, marketers can use Dextro's cross-screen, closed-loop measurement systems to reach and engage the right customer at the right time through the right channel. "Being able to accurately map consumer preferences, behaviors and journeys in a privacy-safe and unified way across devices is still one of the biggest pain points for marketers," said Ajith Govind, co-founder of Dextro Analytics. "At the same time, this partnership engages customers with the right message at the right time." "Detecting latent patterns and signals, and tracing backward- and forward-looking behavioral characteristics, are keys to sustaining a competitive advantage in a crowded space," said Manmit Shrimali, co-founder of Dextro Analytics. "With the proliferation of data and devices, connecting the dots is of paramount importance." "Dextro is solving some of the biggest challenges in analytics today," said Pierre Martensson, GM of Tapad's data division. "Our partners consistently see notable improvements in both budget allocation and device optimizations after integrating with the Tapad Device Graph, and I have every confidence that Dextro will be among them." For more information about Dextro Analytics' revolutionary approach to using human learning and artificial intelligence algorithms to solve business and analytical problems, please visit http://dextroanalytics.com/. For more information about Tapad's cross-platform advertising solutions, please visit https://www.experian.com/marketing/consumer-sync Contact us today!

Published: Feb 06, 2017 by Experian Marketing Services

Subscribe to our newsletter

Enter your name and email for the latest updates

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

About Experian Marketing Services

At Experian Marketing Services, we use data and insights to help brands have more meaningful interactions with people. As leaders in the evolution of the advertising landscape, Experian Marketing Services can help you identify your customers and the right potential customers, uncover the most appropriate communication channels, develop messages that resonate, and measure the effectiveness of marketing activities and campaigns.

Visit our website

Subscribe to our newsletter

Stay up to date on the latest industry news and receive expert tips from our marketing experts.
Subscribe now!