Docaposte Document Process Solutions (DPS) is a subsidiary of the French company La Poste, which is the number one in France in providing a complete panel of solutions to manage the dematerialisation of papers or to monitor and archive digital documents.
The Snapshot
1
Docaposte DPS, a leading French provider of document management solutions, aimed to renew its ISO 27001 security certification in 2014.
2
The challenge was to secure an external project manager who could provide a fresh perspective to audit and improve existing security standards for the Dematerialisation Department.
3
The solution involved a multi-faceted approach including comprehensive internal audits, risk management, a gap analysis against the new ISO standard, and the development of a strategic action plan to ensure compliance.
Main Challenges
In 2014, the Dematerialisation Department of Docaposte DPS decided to audit their current security standards in order to renew their ISO27001 certification. Docaposte DPS’s targets are the CAC 40 enterprises and the SMB.
Docaposte DPS asked Devoteam to help prepare and project manage the renewal of the ISO27001 certification for their Dematerialisation Department. They wanted an external project manager to provide a fresh pair of eyes to improve the process and reach the right security agreements.
What Did We Solve?
Devoteam focused on adding value to Docaposte DPS’s business. The project was not just about achieving the renewal of the ISO27001 certification for the Dematerialisation Department, but also about acquiring the best methods and creating the best security conditions to realise the benefits of being compliant with this certification.
In collaboration with Docaposte DPS, Devoteam tailored the preparation process to fit the Dematerialisation Department’s organisation and needs. Devoteam used different consultants for the different areas, and Docaposte DPS was pleased to benefit from a team of different Devoteam experts.
Devoteam delivers knowledge and assistance on many subtopics within the security area, e.g. Risk Management, Asset Management and Compliance Management. In concrete terms, to realise internal audits, to evaluate the global level of the Information System Security, to provide technical expertise, to identify defaults in the security process, to develop a final action plan in order to reach the right security level. All these topics were considered and part of the planning, execution and follow-up.
Furthermore, in order to provide excellent service, Devoteam went further in its mission and realised a preview gap analysis to show which aspects and processes the Dematerialisation Department of Docaposte DPS will have to improve to be compliant with the 2013 version of the norm ISO27001.
Main Benefits
Secured the renewal of the essential ISO 27001 certification.
Delivered a final action plan to correct security process defaults and elevate the overall security level.
Provided a proactive gap analysis to ensure future compliance with the new version of the standard.
Devoteam’s international team of experts was a clear advantage in this project. Also, Devoteam’s ability to manage large-scale projects covering multiple subtopics was greatly appreciated in this project.
With the renewal of the ISO27001 certification, the Dematerialisation Department of Docaposte DPS is now better able to support, promote, and provide its clients with the best security practices.