Perform a search on the site.

Your currency

Information system security accreditation: implement the ANSSI approach

Information system security accreditation should enable an explicit decision on risk. Structure the ANSSI approach, identify stakeholders and prepare the evidence needed for the dossier. Strengthen your ability to coordinate work and present residual risks to the decision-maker.

Duration
2 days 14 hours
Code
GIT002FR Code

Presentation

With growing cyber threats and stricter regulation, security accreditation of your information system is essential. This course helps you understand and implement a robust accreditation process aligned with ANSSI's rigorous recommendations to ensure effective management of organisational risk.

Through a pragmatic approach combining theory and real case studies, you will learn to navigate the complex regulatory framework. You will discover how to coordinate responsibilities between CIOs, CISOs and business stakeholders and structure a dossier that is both realistic and legally sound.

By the end of these 2 days, you will have the foundations to compile a complete accreditation dossier, use the results of a risk assessment such as EBIOS, and prepare a formal decision that engages the designated authority's responsibility with confidence.

Objectives

By the end of this course, you will be able to:

  • understand the regulatory framework and the purpose of security accreditation;
  • identify the roles and responsibilities of the accreditation authority, CISO and CIO;
  • structure and compile an accreditation dossier that meets ANSSI expectations;
  • use risk assessment results to define an appropriate treatment plan;
  • prepare and formalise the accreditation decision to maintain security over time.
Last update: 24/09/2026

ANSSI, the French National Cybersecurity Agency, is the national authority for information system security and defence (cyber.gouv.fr).
EBIOS® is a trademark registered by the French Secretariat-General for Defence and National Security.
ISO/IEC 27001 is an international information security standard published by ISO (www.iso.org).

#CybersecurityGovernance