ISO/IEC 27001 is currently the standard approach to Information System (IS) security. It explains
how to establish an Information Security Management System (ISMS) which objective is
a continual improvement of information security. The associated certification is an evidence for
the stakeholders of the organisation that security risks are assessed and treated. However,
this standard is still considered as difficult to implement by SMEs, mainly due to their limited
financial and human resources. It is generally a costly process until being certified and a deep
knowledge of the standard and its principles is required. In order to consider this issue, we developed
within a research project an implementation guide, templates and software tools to
assist SMEs in ISMS establishment. This paper presents the validation of these results
through industrial experimentations in three different organisations.