Security

Compliance Mapping: SOC2, ISO 27001, GDPR for Digital Signage

· By Media La Vista

Compliance mapping demonstrates how your digital signage deployment meets specific regulatory and industry standards. When auditors ask "how does this system meet ISO 27001 Annex A controls?" or "what SOC2 Trust Service Criteria does this address?" — you need documented answers. SpinetiX's architecture maps cleanly to major security frameworks because security was designed in, not bolted on.

SpinetiX vs Compliance Requirements

RequirementStandardSpinetiX Control
Access controlISO 27001 A.9, SOC2 CC6RBAC, SSO (SAML/OIDC), 802.1X
Audit loggingISO 27001 A.12.4, SOC2 CC7Full action logging in Arya, exportable
Encryption in transitISO 27001 A.10, SOC2 CC6.1TLS 1.2+ enforced, strong ciphers only
Vulnerability managementISO 27001 A.12.6, SOC2 CC7Quarterly patches with CVE advisories
Change managementISO 27001 A.12.1, SOC2 CC8Signed firmware, staged rollouts, rollback
Asset managementISO 27001 A.8Fleet dashboard, serial tracking, firmware inventory
Network securityISO 27001 A.13, SOC2 CC6.6VLAN isolation, minimal port exposure, 802.1X
Data residencyGDPR Art. 44-49On-premises (Elementi) keeps all data local
Data minimizationGDPR Art. 5(1)(c)Template-based: display only required data fields
Incident responseISO 27001 A.16, SOC2 CC7.3Emergency override, remote re-flash, audit trail
Business continuityISO 27001 A.17, SOC2 A1Offline-first, dual-image firmware, local cache

Key Certifications

  • Arya Cloud: ISO 27001, BSI C5, GDPR compliant
  • DSOS: NCC Group security audit (2024) — no critical vulnerabilities found
  • Hardware: CE, FCC, RoHS, WEEE certified

Common Mistakes

  1. Ignoring signage in compliance scope. If media players connect to your corporate network, they're in scope for ISO 27001 and SOC2. Include them in your ISMS.
  2. No documentation for auditors. Having good security controls is pointless if you can't document them. Prepare a signage security brief that maps to your audit framework before the audit starts.
  3. Assuming cloud compliance covers everything. Arya Cloud's ISO 27001 covers the cloud infrastructure. Your network, access policies, and content management practices are your responsibility. Use our security checklist →

Compliance Mapping: SOC2, ISO 27001, GDPR for Digital Signage FAQ

Is digital signage covered by ISO 27001?

Yes, if it is connected. A media player sitting on a corporate network is an information asset like any other endpoint, and an auditor will expect it inside the ISMS scope rather than treated as furniture. Four Annex A areas do most of the work. Asset management (A.8) — a fleet inventory carrying serial numbers, firmware versions and physical location for every screen. Access control (A.9) — role-based accounts, SSO over SAML or OIDC, and 802.1X for port-level admission. Vulnerability and change management (A.12.6 and A.12.1) — a patch cadence you can evidence, which on the SpinetiX platform means quarterly firmware releases with CVE advisories and cryptographically signed images that support staged rollout and rollback. And logging and monitoring (A.12.4) — exportable action logs, plus read-only SNMP v2c so the estate reports into the monitoring stack the rest of your infrastructure already uses. Scope the fleet in deliberately; the alternative is an auditor asking why undocumented devices share a VLAN with everything else.

Is SpinetiX ISO 27001 certified?

The cloud platform is; the player is not. SpinetiX ARYA cloud infrastructure holds ISO 27001 certification, meets BSI C5 (the Cloud Computing Compliance Controls Catalogue) and complies with GDPR. That certificate covers the cloud service, not every product in the range. An on-premises Elementi deployment carries no certificate of its own — it inherits the certification of the organisation running it, which for most regulated buyers is the better answer anyway, because content and logs never leave an environment they already certified. Phrase the question in your tender as 'which specific service is certified, to which scope, and valid until when' rather than 'is the vendor certified', or you will collect answers that are technically true and commercially useless.

Can SpinetiX help with our SOC 2 compliance?

It supports the controls; it cannot supply the report. SOC 2 audits your organisation's controls, so no supplier hands you compliance — but the architecture maps onto the Trust Service Criteria directly. Role-based access control, SSO and 802.1X for the logical-access criteria (CC6). Exportable audit logging, quarterly patching with CVE advisories and fleet monitoring for system operations (CC7). Cryptographically signed firmware with staged rollouts and rollback for change management (CC8). Offline-first playback, dual-image firmware and local content cache for availability (A1). Media La Vista supplies the security documentation and architectural description your assessor will ask for. Network segmentation, account lifecycle and content approval remain yours to evidence.

Does GDPR apply to digital signage?

Only when screens carry personal data — which is more often than teams assume. Employee names on a welcome board, visitor details at reception, queue systems tied to identifiable people and any camera-based analytics all pull the deployment into scope. Three controls carry most of the weight. Data minimisation (Art. 5(1)(c)): template-based content renders only the fields required, instead of pushing a whole record to a screen in a public corridor. Access control: a documented answer to who can view and edit personal data in the CMS, which is the same RBAC and audit-log evidence ISO 27001 asks for. Data residency (Art. 44–49): an on-premises Elementi hub keeps content and logs inside your own jurisdiction, closing the international-transfer question rather than arguing it. Camera analytics is a separate processing activity with its own lawful basis, notice and retention obligations — it is not covered by the signage platform's posture.

What security evidence should a tender require from a signage vendor?

Five documents, all requestable before award. A named certification with its scope — which service, which standard, valid until when, rather than a logo on a datasheet. An independent test report: for the SpinetiX platform that is the NCC Group security audit of DSOS in 2024, which found no critical vulnerabilities, alongside the platform's zero-CVE record since 2007. A firmware lifecycle statement — release cadence, CVE advisory practice, and how long the specific model you are buying will keep receiving signed firmware. An access and audit description — supported identity protocols, role granularity, what the audit log records, and the format it exports in. And a support commitment with consequences attached: response time, resolution time, escalation path, and a penalty for missing them, because an SLA with no penalty is a marketing document rather than a contract. Request all five as attachments to the bid; a vendor who can only produce the first has told you something useful.

What happens if media players are left out of your ISO 27001 scope?

They become the unmanaged endpoints the audit finds. Signage is easy to omit because it is bought by marketing or facilities rather than IT, and the omission surfaces the same way every time: players on the corporate VLAN with no owner in the asset register, no patch record, a shared local password, and logs nobody reviews. An auditor reaching that finding is unmoved by the fact that the device only shows a lobby video — it holds network access. Two things close it. Put the fleet in the asset inventory with serials, firmware and location, and put the patch cadence in writing. Then be precise about what certification you claim for the equipment, because ISO 27001 certifies an organisation's management system and not a device: ARYA cloud infrastructure holds the certificate, while DSOS on the player is security-hardened and independently audited rather than certified. Claiming a certificate for a media player becomes a finding of its own the moment an evaluator asks to see it.

Need Help With Your Project?

Media La Vista provides Tier 1–3 local support across the Middle East. 10-minute response for Partner Club members.

This page is available in English only
هذه الصفحة متوفرة باللغة الإنجليزية فقط
NS
Media La Vista support
Typically replies natively
مرحباً بكم في دعم SpinetiX عبر واتساب

كيف يمكنني مساعدتكم في حلول اللوحات الرقمية، أو البنية التحتية AV/IT، أو منتجات SpinetiX؟
Hello and welcome to SpinetiX Support on WhatsApp.

How can I help you with digital signage solutions, AV/IT infrastructure, or SpinetiX products?