Information system security accreditation: implement the ANSSI approach
Information system security accreditation should enable an explicit decision on risk. Structure the ANSSI approach, identify stakeholders and prepare the evidence needed for the dossier. Strengthen your ability to coordinate work and present residual risks to the decision-maker.
- Duration
- 2 days 14 hours
- Code
- GIT002FR Code
Presentation
With growing cyber threats and stricter regulation, security accreditation of your information system is essential. This course helps you understand and implement a robust accreditation process aligned with ANSSI's rigorous recommendations to ensure effective management of organisational risk.
Through a pragmatic approach combining theory and real case studies, you will learn to navigate the complex regulatory framework. You will discover how to coordinate responsibilities between CIOs, CISOs and business stakeholders and structure a dossier that is both realistic and legally sound.
By the end of these 2 days, you will have the foundations to compile a complete accreditation dossier, use the results of a risk assessment such as EBIOS, and prepare a formal decision that engages the designated authority's responsibility with confidence.
Objectives
By the end of this course, you will be able to:
- understand the regulatory framework and the purpose of security accreditation;
- identify the roles and responsibilities of the accreditation authority, CISO and CIO;
- structure and compile an accreditation dossier that meets ANSSI expectations;
- use risk assessment results to define an appropriate treatment plan;
- prepare and formalise the accreditation decision to maintain security over time.
Program
Module 1: Understanding the framework and principles of accreditation
- Definition and objectives of accreditation: risk control and traceability.
- The regulatory and standards context, and differences from certification or audit.
- The risk-based approach and acceptance of residual risk.
- Overview of ANSSI's official guides and recommendations.
Module 2: Identifying stakeholders and structuring governance
- Identifying key stakeholders: accreditation authority, committee, CISO, CIO and business teams.
- Defining each party's legal and organisational responsibilities.
- Connecting accreditation, IS governance and risk management.
- The specific case of outsourced or shared information systems.
Module 3: Compiling the accreditation dossier
- Standard structure and content of a dossier aligned with ANSSI standards.
- System description, security policy and statement of applicability.
- Integrating the EBIOS RM risk assessment and treatment plan.
- Updating the dossier and keeping it operationally relevant.
Module 4: Formalising the accreditation decision and ensuring follow-up
- The decision-making process and its formalisation in the accreditation decision.
- Managing validity periods and renewal conditions.
- Monitoring action plans, risks and changes to the information system.
- Best practices for pragmatic, sustainable accreditation.
Audience
This course is intended for key information security stakeholders, including:
- CISOs and IT managers responsible for information system compliance and security;
- project managers and internal auditors incorporating accreditation requirements into projects or controls;
- public and semi-public sector decision-makers who may act as accreditation authorities and sign decisions.
Prerequisites
The following prerequisites apply:
- Knowledge: general knowledge of information systems and security issues is recommended.
- Experience: initial participation in an EBIOS or equivalent risk assessment is an advantage, but not mandatory.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- ANSSI alignment: a programme closely aligned with the guides and recommendations of the French National Cybersecurity Agency.
- Field expertise: delivered by specialist accreditation consultants with ISO 27001 certification.
- Pragmatic approach: theory alternates with case studies inspired by real situations for immediate application.
- Legal robustness: learn to build a legally sound process that ensures traceability and protects decision-makers' accountability.
#cybersecurity-governance
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
ANSSI, the French National Cybersecurity Agency, is the national authority for information system security and defence (cyber.gouv.fr).
EBIOS® is a trademark registered by the French Secretariat-General for Defence and National Security.
ISO/IEC 27001 is an international information security standard published by ISO (www.iso.org).
#CybersecurityGovernance
fr
en