Articles & insights
ISO/IEC 27001 in Senegal: A Practical Guide for Businesses and Executives
Understand ISO/IEC 27001 in Senegal: ISMS, risks, Statement of Applicability, audit, certification and an executive roadmap for 2026.
Explore the full story
ISO/IEC 27001 is often reduced to a “cyber certification”. That is the wrong way to understand it.
ISO/IEC 27001:2022 defines the requirements for an information security management system (ISMS). It requires an organisation to structure its governance, risks, responsibilities, controls, evidence and continual improvement.
For a Senegalese business or one operating in West Africa, the benefit is concrete: turning fragmented cybersecurity into a system that management can steer.
Key takeaway
ISO/IEC 27001 does not guarantee that an organisation will never be attacked. It aims to ensure that it knows how to identify, treat, monitor and improve its security risks in a structured way.
ISO/IEC 27001 as a mental model
Imagine five simple questions:
- What really matters? — scope, assets, critical services.
- What could go wrong? — risk assessment.
- What are we doing about it? — risk treatment and controls.
- How do we know it works? — metrics, audits and reviews.
- What do we change next? — corrective actions and continual improvement.
That is the heart of an ISMS.
Why this is becoming strategic in Senegal
Senegal's New Deal Technologique promotes digital services, digital identity, technology sovereignty and infrastructure security. In June 2026, the Presidency also emphasised sovereign protection of critical data, systems and information infrastructure.
The more an organisation relies on digital technology, the more it must be able to answer governance questions:
- which services cannot stop;
- which data is most sensitive;
- which suppliers represent a point of failure;
- which risks are accepted;
- who may approve that acceptance;
- what evidence shows that a control actually works.
ISO/IEC 27001 provides a framework for organising these answers.
The building blocks of an ISO/IEC 27001 ISMS
| Building block | Management question |
|---|---|
| Context & scope | What exactly are we protecting? |
| Leadership | Who owns the ISMS and who accepts risks? |
| Gap analysis | Where are we today? |
| Risks | Which scenarios could genuinely affect us? |
| Statement of Applicability | Which controls do we select, and why? |
| Implementation | Do the measures actually exist? |
| Competence & awareness | Do teams know what to do? |
| Operations & incidents | How do we respond when an event occurs? |
| Measurement | Which indicators demonstrate effectiveness? |
| Internal audit | Does the system withstand independent review? |
| Management review | Does the executive committee see the decisions needed? |
| Continual improvement | Do we correct causes, not just symptoms? |
The Statement of Applicability: the document many underestimate
The Statement of Applicability — often called the SoA — is central to implementation.
It documents, among other things:
- applicable security controls;
- the reasons for selecting them;
- exclusions and their justification;
- implementation status.
It is not a generic checklist to copy.
Good practice
A credible SoA should tell the organisation's own risk story. If two very different businesses produce exactly the same SoA, there is probably a problem.
What timeline should you expect?
The standard does not prescribe a universal implementation duration.
For an organisation that is already well structured, a project can progress quickly. For a business with many legacy systems, suppliers, subsidiaries or undocumented processes, the work may take much longer.
Example sequence — illustrative, not normative
| Phase | Objective |
|---|---|
| 1. Scoping | Executive sponsor, scope, interested parties |
| 2. Gap analysis | Understand the current situation |
| 3. Risk assessment | Prioritise risk scenarios |
| 4. Treatment & SoA | Select and justify controls |
| 5. Implementation | Establish controls, processes and documentation |
| 6. Measurement | Indicators, monitoring and evidence |
| 7. Internal audit | Test conformity and effectiveness |
| 8. Management review | Executive decision |
| 9. Corrective actions | Address findings |
| 10. Certification | External audit if the organisation chooses certification |
Certification is not mandatory to benefit from an ISMS. An organisation can implement ISO/IEC 27001 without immediately requesting a certificate. Certification does, however, provide additional external assurance to some clients, partners or investors.
What management should avoid
“This is the CISO's project”
No. ISO/IEC 27001 requires leadership involvement. The CISO can lead the project but cannot accept every business risk alone.
“We will buy a GRC tool and the problem will be solved”
A tool can make tracking easier. It cannot replace risk judgement, accountability or evidence quality.
“We only want the certificate”
Certification obtained without real change creates paper security. The system must stay alive after the audit.
“We will apply every control in the same way”
The standard's approach is based on risk and context. Measures must be justified.
ISO 27001, AI and cloud: why the ISMS must evolve
The PECB ISO/IEC 27001 Lead Implementer programme explicitly addresses trends and technologies such as artificial intelligence, machine learning, cloud computing and outsourcing.
This makes sense: modern organisations no longer directly control their entire environment.
They must know, in particular:
- where their data is;
- which subcontractors can access it;
- which AI agents can read or modify it;
- which activities are outsourced;
- which risks are transferred — and which remain their responsibility.
For AI uses, ISO/IEC 27001 can also be combined with ISO/IEC 42001, the artificial intelligence management system standard.
Lead Implementer training: what it actually covers
The official PECB Certified ISO/IEC 27001 Lead Implementer programme spans five days:
- Day 1: introduction to ISO/IEC 27001 and initiation of ISMS implementation;
- Day 2: implementation plan;
- Day 3: ISMS implementation;
- Day 4: monitoring, continual improvement and audit preparation;
- Day 5: certification exam.
The exam covers seven competence domains, from understanding the ISMS to preparing for the certification audit.
Important: passing the exam does not automatically confer the “PECB Certified ISO/IEC 27001 Lead Implementer” credential. PECB also requires specific professional and project experience for the Lead Implementer credential. Candidates who do not yet have that experience may pursue other credentials in the same family under PECB's rules.
See also: How to Become an ISO/IEC 27001 Lead Implementer: Role, Skills and Certification Path.
Executive checklist before launching the project
- Executive sponsor identified;
- Initial scope clearly understood;
- Critical assets and services identified;
- Risk assessment method defined;
- Business owners involved;
- Critical suppliers mapped;
- Project resources available;
- Evidence/documentation process planned;
- Metrics and management reporting defined;
- Internal audit planned before certification.
ECW ISO/IEC 27001 Lead Implementer Executive Experience — Dakar
From 14 to 18 December 2026, ECW is organising the ISO/IEC 27001 Lead Implementer Executive Experience in Dakar, based on the PECB Certified ISO/IEC 27001 Lead Implementer programme.
The public price is €2,500 excluding tax, and the experience also includes ECW VIP status, the Closing Dinner on 17 December, access to the ECW Executive Forum on 19 December and the Executive Forum Dinner.
Explore the Executive Experience
Sources
- ISO — ISO/IEC 27001:2022: https://www.iso.org/standard/27001
- PECB — ISO/IEC 27001 Lead Implementer: https://pecb.com/fr/education-and-certification-for-individuals/iso-iec-27001/iso-iec-27001-lead-implementer
- Presidency of Senegal — New Deal Technologique: https://www.presidence.sn/fr/actualites/new-deal-technologique-une-ambition-nationale-pour-faire-du-senegal-un-leader-de-leconomie-numerique-en-afrique/
- Presidency of Senegal — Council of Ministers, 17 June 2026: https://www.presidence.sn/fr/actualites/communique-du-conseil-des-ministres-du-mercredi-17-juin-2026/
- ISO — ISO/IEC 42001:2023: https://www.iso.org/fr/standard/81230.html
