Compliance mapping demonstrates how your digital signage deployment meets specific regulatory and industry standards. When auditors ask "how does this system meet ISO 27001 Annex A controls?" or "what SOC2 Trust Service Criteria does this address?" — you need documented answers. SpinetiX's architecture maps cleanly to major security frameworks because security was designed in, not bolted on.
SpinetiX vs Compliance Requirements
| Requirement | Standard | SpinetiX Control |
|---|---|---|
| Access control | ISO 27001 A.9, SOC2 CC6 | RBAC, SSO (SAML/OIDC), 802.1X |
| Audit logging | ISO 27001 A.12.4, SOC2 CC7 | Full action logging in Arya, exportable |
| Encryption in transit | ISO 27001 A.10, SOC2 CC6.1 | TLS 1.2+ enforced, strong ciphers only |
| Vulnerability management | ISO 27001 A.12.6, SOC2 CC7 | Quarterly patches with CVE advisories |
| Change management | ISO 27001 A.12.1, SOC2 CC8 | Signed firmware, staged rollouts, rollback |
| Asset management | ISO 27001 A.8 | Fleet dashboard, serial tracking, firmware inventory |
| Network security | ISO 27001 A.13, SOC2 CC6.6 | VLAN isolation, minimal port exposure, 802.1X |
| Data residency | GDPR Art. 44-49 | On-premises (Elementi) keeps all data local |
| Data minimization | GDPR Art. 5(1)(c) | Template-based: display only required data fields |
| Incident response | ISO 27001 A.16, SOC2 CC7.3 | Emergency override, remote re-flash, audit trail |
| Business continuity | ISO 27001 A.17, SOC2 A1 | Offline-first, dual-image firmware, local cache |
Key Certifications
- Arya Cloud: ISO 27001, BSI C5, GDPR compliant
- DSOS: NCC Group security audit (2024) — no critical vulnerabilities found
- Hardware: CE, FCC, RoHS, WEEE certified
Common Mistakes
- Ignoring signage in compliance scope. If media players connect to your corporate network, they're in scope for ISO 27001 and SOC2. Include them in your ISMS.
- No documentation for auditors. Having good security controls is pointless if you can't document them. Prepare a signage security brief that maps to your audit framework before the audit starts.
- Assuming cloud compliance covers everything. Arya Cloud's ISO 27001 covers the cloud infrastructure. Your network, access policies, and content management practices are your responsibility. Use our security checklist →