Designing and implementing an information security policy
Your security strategy should give teams clear direction. Translate organisational challenges into policy, responsibilities and an action plan so priorities are easy to understand. Strengthen your ability to coordinate measures and monitor implementation.
- Duration
- 2 days 14 hours
- Code
- GSI004FR Code
Presentation
With cyberthreats multiplying and regulatory requirements becoming stricter, including NIS2 and the GDPR, formalising your security approach is no longer optional. This 2-day course helps you structure an information security policy (PSSI in French) that effectively protects your assets while supporting your business strategy.
The program draws on recognised standards, particularly the ISO 2700x family, and the EBIOS method for risk analysis. Build your documentation framework step by step, from access management rules to continuity plans, while ensuring it can be applied in practice.
Beyond drafting documents, this course gives you the tools to keep this governance framework active. You will be able to implement audit plans, raise employee awareness and support continuous improvement to maintain your level of compliance over time.
Objectives
By the end of this course, you will be able to:
- understand the strategic and legal implications of an information security policy for your organisation;
- master reference standards, including ISO 27001 and 27002, and the EBIOS risk management method;
- design a security policy aligned with regulatory requirements such as the GDPR and NIS2;
- structure the governance framework and internal control processes;
- implement an awareness plan and lead continuous security improvement.
Program
Module 1: defining the policy's scope and challenges
- Definition and central role of the information security policy.
- Identifying financial, legal and organisational impacts.
- Aligning the security policy with the organisation's overall strategy.
Module 2: understanding the standards and regulatory landscape
- Detailed presentation of ISO 27001:2022, 27002:2022 and 27005:2022.
- Understanding the legal framework: GDPR, LPM, NIS2 and LCEN.
- Introduction to risk management methods, focusing on EBIOS Risk Manager.
Module 3: structuring and drafting the security policy
- Risk analysis and mapping potential threats.
- Defining security rules for access management, data protection and continuity.
- Classifying information to protect critical assets.
- Employee awareness and training strategy.
Module 4: managing implementation and monitoring
- Developing an action plan for effective implementation.
- Establishing governance and steering bodies.
- Organising compliance audits and internal controls.
- Tracking key performance indicators (KPIs) and continuous improvement.
Module 5: applying the information security policy approach
- Build a complete information security policy for a typical organisation.
- Simulate a risk analysis using the EBIOS method.
- Implement and manage an operational awareness plan.
Audience
This course is intended for IT governance and security professionals, including:
- chief information security officers (CISOs) leading cyberdefence strategy;
- CIOs and network administrators responsible for technical policy implementation;
- compliance managers and auditors ensuring legal obligations are met;
- IT project managers integrating security into the project lifecycle.
Prerequisites
The following background is recommended:
- Basic knowledge: a good understanding of fundamental cybersecurity concepts and ISO 2700x standards will help you benefit fully from the workshops.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
- Methodological framework: apply ISO 2700x standards and the EBIOS method for a rigorous professional approach.
- Compliance focus: integrate the latest regulatory requirements, including NIS2 and the GDPR, directly into your policies.
- Practical approach: dedicate an entire module to simulation and hands-on policy drafting.
- Certified expertise : benefit from support from trainers with expertise in ISO standards to validate the relevance of your strategic choices.
#CybersecurityGovernance
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
#CybersecurityGovernance
fr
en