- FR
- EN
Information Security Management System
ISO 27001
- Secure information in all its forms, including digital data, paper-based or stored in the Cloud
- Increase resilience to cyber-attacks
- Provide a centrally managed framework that secures all information in one place
- Ensure organization-wide protection, especially against technology-based risks and other threats
- Respond to evolving security threats
- Reduce costs and spending on ineffective defense technologies
- Protect the integrity, confidentiality and availability of data
The standard specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this standard are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this standard.
To keep their sensitive information secure, organizations can rely on the ISO/IEC 27000 family of standards.
ISO 27001 is the best-known standard in this family, which includes no fewer than a dozen standards. It specifies the requirements for information security management systems (ISMS). Using this family of standards helps organizations of any kind manage the security of sensitive assets such as financial information, intellectual property, employee details or information entrusted to them by third parties.
Key features
Risk management
ISO 27001 Annex A controls management
CyFun requirements management
Technical and organizational measures management
Incident / nonconformity management
CyFun self-assessment 2023 / 2025
Internal and external audit management
Action management
Automatically generated Statement of Applicability
Objectives and indicators management
Process management
Processor and supplier management
Alert management
Risk management
The software lets you create assessment criteria for each standard (ISO or GDPR)
A validation cycle is defined.
A status history helps you follow the various exchanges between the people involved.
ISO 27001 Annex A controls management
CyFun requirements management
CCB framework.
Technical and organizational measures management
Technical and organizational measures are managed by area (ISO/GDPR). The person responsible for each measure and its completion date, actual or planned, are identified and managed.
A measures management screen gives an overall view for tracking measures, deadlines and owners by area.
Incident / nonconformity management
Incident and nonconformity management tool
Email notifications are sent to the assigned owner.
CyFun self-assessment 2023 / 2025
Internal and external audit management
Plan your internal and external audits. Write your audit reports directly in the software.
Action management
Tool to manage all actions.
Email notifications are sent to the assigned owner.
Automatically generated Statement of Applicability
Objectives and indicators management
Process management
Identification of processes and sub-processes by entity
Identification of process owners
Processor and supplier management
This feature lets you manage contract compliance and assess your critical suppliers based on assessment criteria.
Alert management
Alerts on deadlines (actions, data subject requests, breaches, ...) and gaps (contracts, justifications, ...) are automatically identified by the software. A register of all alerts is generated so that the person in charge can manage them.