Iron Mountain stores and protects billions of customer information assets – everything from medical records and business documents to some of the world’s most valuable historical and cultural artifacts. As a result, secure and compliant business practices are extremely important. When Iron Mountain expanded its data center colocation business, it was critical to establish a partnership with a first-rate auditing firm to codify Iron Mountain’s ability to maintain and exceed industry standard compliance requirements for customers in highly regulated industries.
With the exponential growth of consumption-based/cloud services, the corresponding risks have skyrocketed, disrupting IT departments globally. Highly regulated organizations require third-party service providers to maintain FISMA-compliant infrastructure while balancing efficient, agile, and cost-effective IT. The rapid rate of technology change also affects the ability to forecast future demand and commit capital to long-term projects.
So, what are highly regulated organizations doing to solve the challenge? They are going big–finding global brands they know and trust, who feature comprehensive compliance portfolios that satisfy specific regulatory needs.
After 30 years of providing wholesale data center management services to enterprise customers, Iron Mountain found itself fielding multiple requests from existing customers for a secure data center colocation solution that would meet the needs of highly regulated industries. While Iron Mountain is well known for storage and information management, third-party assessment would help validate the company’s expansion into the data center colocation space. By leveraging Schellman’s single assessor advantage, Iron Mountain’s data center team quickly and effectively completed the certifications and attestations that their highly regulated customer base required.
Chris Bair | Iron Mountain Vice President of Sales and Marketing
It was clear that to serve banks, hospitals, and federal agencies, Iron Mountain needed to extend existing compliance certifications and attestations into the data center line of business. The company needed a partner who was familiar with data center best practices to effectively align new controls with FISMA, ISO 27001 and PCI. Schellman’s extensive experience in the data center space was pivotal to the company’s selection.
After thorough market research and numerous pre-sales engagements, Iron Mountain Data Centers selected Schellman to perform three separate audits. Iron Mountain Data Center executives cited numerous determining factors including Schellman’s status as a CPA firm with a globally licensed PCI Qualified Security Assessor, an ISO Certification Body and a FedRAMP 3PAO. This unique combination allowed Iron Mountain Data Centers to obtain FISMA, ISO, and PCI-DSS compliance from a single firm, creating a set of common controls to use across all three assessments.
“Schellman understood our business model right away,” said Jennifer Bertelli, Iron Mountain Data Centers’ Compliance Manager. “The collaborative discussion on controls and industry best practices put us on the fast track to capturing the compliance standards demanded by our enterprise customer base in an expedited time frame.”
Jennifer Bertelli | Iron Mountain | Compliance Manager
In order for federal government and other public sector agencies to deploy with a third-party data center provider such as Iron Mountain Data Center’s, the desired facilities must meet the same underlying NIST SP 800-53 requirements as would an in-house facility under FISMA regulations. Schellman assessed the Iron Mountain Data Centers Information Security Management System (ISMS) and related processes and controls across all Iron Mountain data centers. This involved on-site and remote research; identifying and mapping the necessary in-scope FISMA requirements, and travelling to the data centers and corporate headquarters to observe and inspect all in-scope controls.
Doug Barbin | Schellman Principal and Security Services Leader
Pursuing an ISO 27001 certification was a key objective because Iron Mountain supports an international customer base and ISO’s ISMS management framework is internationally recognized as the “gold standard.” “By successfully completing the ISO 27001 audit, Iron Mountain has demonstrated a mature security system to prospective and existing customers that conduct businesses both domestically and internationally,” explained Doug Barbin, Schellman Principal and Security Services leader. “ISO certifies Iron Mountain’s ability to successfully self-monitor, assess risks, respond to threats, and adapt to unexpected changes.”
Schellman completed the entire ISO 27001 audit from initial assessment to formal certification in five months. The two-stage process included on-site assessments at Iron Mountain Data Centers and its corporate headquarters, collaborative review of their ISMS policies and procedures, and testing of Iron Mountain Data Centers controls.
Doug Barbin | Schellman Principal and Security Services Leader
Financial service organizations, hosted payment gateways, and other organizations that handle, store, or transmit sensitive data such as credit card and social security numbers or other Personally Identifiable Information (PII) are subject to PCI-DSS regulations. As with FISMA and ISO, PCI-DSS provides detailed requirements for internal and third-party services provider controls.
Doug Barbin | Schellman Principal and Security Services Leader
Jane Doe | CEO, box