Companies are now more and more dependent on their information system, which leads them to set up a function of Information Systems Security Officer (CISO). The role of the CISO is to manage the risks associated with this dependency. For this, the first job of the CISO is to define the company's Information Security Policy (ISP).