// Comparison

Click Here to Kill Everybody vs La norme ISO/IEC 27005: Which Should You Read?

Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.

Beginner
4/52018
Click Here to Kill Everybody

Security and Survival in a Hyper-Connected World

Bruce Schneier

Bruce Schneier's policy-level argument that as everything becomes a computer (cars, medical devices, infrastructure, voting), the security failures that used to merely cost us money will start costing lives — and the regulatory shape of that future is being decided now.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Read this if

Engineers, policy people, and managers who need to brief leadership on why IoT, OT, and cyber-physical systems are categorically different from the IT security they grew up with. Also the right first Schneier book for anyone newly responsible for cyber-physical risk.
Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.

Skip this if

Readers wanting hands-on IoT-hacking technique; for that, Practical IoT Hacking (Chantzis et al.) and The Hardware Hacking Handbook are the references. Also dated on specific 2018 examples even though the structural arguments hold.
Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.

Key takeaways

  • Internet+ — Schneier's term for cyber-physical convergence — changes the consequences of security failure, not just the surface.
  • Markets won't fix this; the book's policy argument is that liability, regulation, and procurement standards are the only working levers.
  • Engineering culture and policy culture talk past each other; the book is a useful Rosetta stone in both directions.
  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.

How they compare

Click Here to Kill Everybody and La norme ISO/IEC 27005 are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Click Here to Kill Everybody is pitched at beginner level. La norme ISO/IEC 27005 is pitched at intermediate level. Read the easier one first if you're not yet comfortable with the topic.

Click Here to Kill Everybody and La norme ISO/IEC 27005 both cover Policy, Foundations, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics