AlgoSecure accompanies you through the implementation of an Information Security Management ISO 27001 on a defined perimeter, and the obtention of its certification Our consultants certified ISO 27001 (Lead Implementer and Lead Auditor) are available to accompany our clients through their certification projects.

ISO 27001, or more precisely ISO/IEC 27001, is part of the ISO 27000 family of standards, of which it is the best known. Concretely, this international standard from ISO and IEC sets up strict requirements for Information Security Management Systems (ISMS).
The main feature of ISO/IEC 27001 is that it deals with security by a risk-based approach. In other words, by being certified ISO 27001, an organization demonstrates that it has identified the security risks that could affect it and its sensitive data, and that it has taken the necessary organizational measures to manage these risks.
ISO/IEC 27001 certification is aimed at a wide range of organizations, whatever their size, sector of activity or geographical location. It is particularly relevant for organizations :

For several years, AlgoSecure has been supporting organizations in their ISO 27001 certification process, developing in-depth and recognized expertise.
The ISO 27001 certification starts with the definition of the ISMS according to the needs of the organization, through the realization of a study of the risks which weighs on the sensitive data included in this perimeter of intervention. The study is carried out at both the micro and macro levels. It also concerns the environment in which the organization in question evolves. After identifying the risks, the ratio between the probability of the event occurring and its impact is determined. This allows for the selection of adequate protective measures, listed in the ISO 27002 standard.
By implementing the ISO 27001 standards (and the other standards of the ISO 27000 family by extension), a company can effectively protect itself from the risks weighing on its sensitive assets such as information relating to its personnel, its financial data or its intellectual property documents.
The project team relies on the following elements :
Phase 2 is the execution of the project plan made in phase 1.
Analysis of present situation
The goal of this phase is to analyze precisely the present situation and apprehend the risks on the defined perimeter.Phase 2.2: Establishment of the IMS
The goal of this phase is to build the ISMS (we've written a guide on this topic).Phase 2.3: Monitoring and improvement of the IMS
The goal of this phase is to carry on the action plan and implement the monitoring and piloting tools.Phase 2.4: Certification mock audit
L'objectif de cette phase est de construire le SMSI.Phase 2.5: ISO-27001 certification
In addition to our PASSI qualification, we have chosen to obtain ISO 27001 certification for the perimeter of our infrastructure from which we conduct our PASSI audits. On the one hand, this certification allows us to raise our security level even higher, not only from a technical point of view, but also and especially from an organizational and process management point of view. On the other hand, it demonstrates that we apply to ourselves the advice we give to our customers. Obtaining this certification is the result of several months of work, but it is worth the effort to enable us to better protect the sensitive data we may be handling.
Adoption of the ISO 27001 standard is voluntary; it is therefore not compulsory. Nevertheless, it has become an essential industry standard for responding to tenders and reassuring partners, particularly in the fields of IT outsourcing and cloud computing.
Furthermore, it provides a structural framework for demonstrating compliance with strict regulations such as the NIS2 Directive, DORA and the GDPR. It should be noted that, for healthcare data hosting (HDS) providers, specific certification based on ISO 27001 is a regulatory requirement in France.
The certification is valid for a fixed period of three years. This period is structured as follows:
The time taken to implement the scheme depends on the size of your organisation, the complexity of the scope of certification, your initial level of maturity and the resources allocated to the implementation.
As a general rule, it takes between 9 and 15 months for an SME, and up to 24 months for large groups. Once the initial audit has been approved, the preparation for surveillance and renewal audits takes much less time.
ISO 27001 sets out the organisational requirements for an Information Security Management System (ISMS): it is the only standard that can be certified.
ISO 27002, on the other hand, is not certifiable; it is a guide to best practice that provides the keys to the practical implementation of security controls.
ISO 27001 is the general international standard governing the ISMS.
ISO 27005, which is based on ISO 31000 (the general framework for risk management), focuses specifically on guidelines for managing risks related to information security. It is the risk assessment framework that must be applied for ISO 27001.
EBIOS RM, developed by ANSSI, is a method compliant with ISO 27005, thereby enabling the implementation of a compliant risk management framework.
The essential prerequisite is that your organisation has implemented and is operating a comprehensive ISMS. This involves validating several key stages :
The audit and certification are carried out by an independent, accredited third-party body, which ensures an expert and impartial assessment.
There are several organisations on the market that can carry out these audits, such as LSTI (which is also accredited by ANSSI), AFNOR Certification, Bureau Veritas and Certi-Trust.
We help you evaluate the risks that are cast on your systems, and establish a plan in order to deal with these risks.
We perform organizational audits to ensure that security measures are in place.
Certifications, qualifications and quality labels obtained by Algosecure (ISO 27001, PASSI, Expert cyber, OSEP, OSCP...).
Specialists in information security and pentest throughout France
You've enabled "Do Not Track" in your browser, we respect that choice and don't track your visit on our website.