SchellmanCON is back! Join us for our virtual conference on March 6 & 7, 2025

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

IRON MOUNTAIN CASE STUDY

Iron Mountain Uses a Single Assessor for Agile Expansion of Data Center Compliance

Over 156,000 organizations in the corporate and public sectors depend on Iron Mountain to protect what matters most.

Iron Mountain stores and protects billions of customer information assets – everything from medical records and business documents to some of the world’s most valuable historical and cultural artifacts. As a result, secure and compliant business practices are extremely important. When Iron Mountain expanded its data center colocation business, it was critical to establish a partnership with a first-rate auditing firm to codify Iron Mountain’s ability to maintain and exceed industry standard compliance requirements for customers in highly regulated industries.

With the exponential growth of consumption-based/cloud services, the corresponding risks have skyrocketed, disrupting IT departments globally. Highly regulated organizations require third-party service providers to maintain FISMA-compliant infrastructure while balancing efficient, agile, and cost-effective IT. The rapid rate of technology change also affects the ability to forecast future demand and commit capital to long-term projects.

So, what are highly regulated organizations doing to solve the challenge? They are going big–finding global brands they know and trust, who feature comprehensive compliance portfolios that satisfy specific regulatory needs.

After 30 years of providing wholesale data center management services to enterprise customers, Iron Mountain found itself fielding multiple requests from existing customers for a secure data center colocation solution that would meet the needs of highly regulated industries. While Iron Mountain is well known for storage and information management, third-party assessment would help validate the company’s expansion into the data center colocation space. By leveraging Schellman’s single assessor advantage, Iron Mountain’s data center team quickly and effectively completed the certifications and attestations that their highly regulated customer base required.

“Offering secure and compliant data center services means doing more than checking boxes. You have to fully understand what it entails from the customer’s perspective and be able to offer a service that helps them mitigate risk.”

Chris Bair | Iron Mountain Vice President of Sales and Marketing

It was clear that to serve banks, hospitals, and federal agencies, Iron Mountain needed to extend existing compliance certifications and attestations into the data center line of business. The company needed a partner who was familiar with data center best practices to effectively align new controls with FISMA, ISO 27001 and PCI. Schellman’s extensive experience in the data center space was pivotal to the company’s selection.

After thorough market research and numerous pre-sales engagements, Iron Mountain Data Centers selected Schellman to perform three separate audits. Iron Mountain Data Center executives cited numerous determining factors including Schellman’s status as a CPA firm with a globally licensed PCI Qualified Security Assessor, an ISO Certification Body and a FedRAMP 3PAO. This unique combination allowed Iron Mountain Data Centers to obtain FISMA, ISO, and PCI-DSS compliance from a single firm, creating a set of common controls to use across all three assessments.

“Schellman understood our business model right away,” said Jennifer Bertelli, Iron Mountain Data Centers’ Compliance Manager. “The collaborative discussion on controls and industry best practices put us on the fast track to capturing the compliance standards demanded by our enterprise customer base in an expedited time frame.”

“The efficiencies gained from working with a single assessor like Schellman cannot be understated. From an internal resources perspective, it was a lot easier to work with one auditor who understood our business and could verify our compliance against several standards versus working with three different auditors and explaining our business three different times. We also considered the implementation. There were quite a few shared control requirements across FISMA, ISO, and PCIDSS. Schellman & Company executives quickly identified the common controls, isolated the nuances, then gathered the supporting data and applied it to all three audits.”

Jennifer Bertelli | Iron Mountain | Compliance Manager

Schellman Services

Iron Mountain Data Centers initially worked with Schellman to obtain a NIST attestation to assist their federal customers with FISMA efforts. Soon after followed additional projects, including an ISO 27001 certification and PCI-DSS validation. 

Fisma Compliance

In order for federal government and other public sector agencies to deploy with a third-party data center provider such as Iron Mountain Data Center’s, the desired facilities must meet the same underlying NIST SP 800-53 requirements as would an in-house facility under FISMA regulations. Schellman assessed the Iron Mountain Data Centers Information Security Management System (ISMS) and related processes and controls across all Iron Mountain data centers. This involved on-site and remote research; identifying and mapping the necessary in-scope FISMA requirements, and travelling to the data centers and corporate headquarters to observe and inspect all in-scope controls.

“The efficiencies gained from working with a single assessor like Schellman cannot be understated. From an internal resources perspective, it was a lot easier to work with one auditor who understood our business and could verify our compliance against several standards versus working with three different auditors and explaining our business three different times. We also considered the implementation. There were quite a few shared control requirements across FISMA, ISO, and PCIDSS. Schellman & Company executives quickly identified the common controls, isolated the nuances, then gathered the supporting data and applied it to all three audits.”

Doug Barbin | Schellman Principal and Security Services Leader

ISO Certification

Pursuing an ISO 27001 certification was a key objective because Iron Mountain supports an international customer base and ISO’s ISMS management framework is internationally recognized as the “gold standard.” “By successfully completing the ISO 27001 audit, Iron Mountain has demonstrated a mature security system to prospective and existing  customers that conduct businesses both domestically and internationally,” explained Doug Barbin, Schellman Principal and Security Services leader. “ISO certifies Iron Mountain’s ability to successfully self-monitor, assess risks, respond to threats, and adapt to unexpected changes.”

Schellman completed the entire ISO 27001 audit from initial assessment to formal certification in five months. The two-stage process included on-site assessments at Iron Mountain Data Centers and its corporate headquarters, collaborative review of their ISMS policies and procedures, and testing of Iron Mountain Data Centers controls.

"By successfully completing the ISO 27001 audit, Iron Mountain has demonstrated a mature security system to prospective and existing customers that conduct businesses both domestically and internationally. ISO certifies Iron Mountain’s ability to successfully self-monitor, assess risks, respond to threats, and adapt to unexpected changes."

Doug Barbin | Schellman Principal and Security Services Leader

PCI Validation

Financial service organizations, hosted payment gateways, and other organizations that handle, store, or transmit sensitive data such as credit card and social security numbers or other Personally Identifiable Information (PII) are subject to PCI-DSS regulations. As with FISMA and ISO, PCI-DSS provides detailed requirements for internal and third-party services provider controls.

"While there were common controls across each of the Iron Mountain Data Centers compliance engagements with Schellman, PCI-DSS presented some unique requirements than can often lead to long validation turn times. Thankfully, Iron Mountain had been through PCI with its core document business. Leveraging existing security practices and its dedicated compliance resources helped Schellman complete the assessment within one month."

Doug Barbin | Schellman Principal and Security Services Leader