SESAN Service Mapping
Case Study: SESAN – Public Interest Group for eHealth in Île-de-France
About SESAN
- The Regional Support Group for eHealth Development in Île-de-France (1)
- Deploys digital tools and supports healthcare stakeholders in their digital transformation projects
- 400 member institutions
- 130+ employees
- 70+ applications available in the “SESAN Store”
- 300+ servers
Objective: Gaining a Clearer Understanding of the SESAN Information System
The Information System Mapping Initiative is led by SESAN’s Information Systems Security Department. This department operates both internally and in collaboration with healthcare institutions across Île-de-France.
The initiative was initially driven by a need for a shared, up-to-date view of the SESAN IS. It also aims to apply and monitor best practices recommended by the French National Cybersecurity Agency (ANSSI).
Another Key Driver of the IS Mapping Initiative: Healthcare Institutions’ Account Certification
“We have worked on the certification process for healthcare institutions’ accounts. As part of this certification, an audit of the Information System, including an inventory of applications, is required. We have also implemented this process internally.”
A Collaborative Approach to IS Mapping
At SESAN, IS mapping is divided into two main areas:
- Mapping of SESAN’s internal Information System
- Mapping of the digital services provided to the healthcare sector in Île-de-France
The second area constitutes the core of SESAN’s mapping initiative.
SESAN has adopted a participatory and collaborative approach to building and maintaining its IS mapping.
“At SESAN, all employees contribute to building the IS mapping.
We do not have a dedicated team for this task.”
– Didier DEMANTE, Information Systems Security Consultant
After testing several IS mapping solutions, SESAN ultimately chose myCarto.
“With myCarto, we found ease of use. It’s an ergonomic and intuitive tool…”
– Rémi TILLY, Director of the Information Systems Security Department
“myCarto allows us to unify and consolidate all the information spread across SESAN’s various departments.
myCarto provides answers that would be impossible to obtain with office tools. Whether for operations, member relations, or securing SESAN’s IS, it has become indispensable.“
Rémi TILLY – Director of the Information Systems Security Department
Results & Benefits of SESAN’s IS Mapping Initiative
As Rémi TILLY points out, IS mapping is a continuous process in a constantly evolving digital environment. However, the benefits are already tangible. Here are some key examples:
- Integration of SESAN’s 400 member healthcare institutions into the IS model and repository.
- Impact assessment in case of failure (outage, cyberattack, etc.), ensuring visibility on affected SESAN Store services and potential service degradation for member institutions.
- A critical input for SESAN’s Business Continuity Plan (BCP).
- Identification of obsolete components and proactive planning for replacements.
- Simplified obsolescence management and better anticipation of future changes.
- Support for project managers by visualizing application-related data flows.
Overall, SESAN now has better visibility and knowledge of its Information System.
"ON THE WAY" TIP
Every quarter, SESAN identifies a set of applications to review and updates their information in the IS mapping system.
Mapping helps us be more efficient in both security management and awareness efforts.
Whenever we identify a vulnerability, IS mapping allows us to instantly assess its impact across application layers, data flows, and servers.
Didier DEMANTE – Information Systems Security Consultant
When One IS Mapping Reveals Another…
Beyond using myCarto for its own Information System, SESAN has also integrated the mapping tool into its service catalog.
“A diagram created with office tools may meet certain regulatory requirements,
but it does not replace a real IS mapping solution.”
– Emilie SAINZ, Deputy Director of the Information Systems Security Department
“This is the key difference between compliance and security. Office tools may be sufficient for compliance,
but securing an IS requires a mapping solution like myCarto, with the most comprehensive description possible.
This enables a clear understanding of impacts and helps identify everything affected in case of an incident,
application failure, or server outage.”
– Rémi TILLY, Director of the Information Systems Security Department
One of the first questions asked by ANSSI (the French National Cybersecurity Agency) when assisting an organization after a cyberattack is:
“Do you have a map of your Information System?”
To help its members respond with more than just an Excel file—assuming it hasn’t been encrypted during the attack—SESAN now offers myCarto in a hosted mode on an HDS-certified server.
Additional Information on the Case Study
- (1) – SESAN website
- (2) GHT – Regional Hospital Group (Groupement Hospitalier de Territoire)
- ANSSI – French National Cybersecurity Agency (website)
- HDS – Health Data Hosting Provider