// Comparison

Cybercriminalité vs La norme ISO/IEC 27005: Which Should You Read?

Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
3/52023
Cybercriminalité

Comprendre, prévenir, réagir

Solange Ghernaouti

Solange Ghernaouti's structured treatment of cybercrime — how it works, how to prevent it, how to respond — spanning technical, legal and organisational angles.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Read this if

Students (law, management, engineering), managers and investigators who want a structured, up-to-date overview of cybercrime across technical, legal and human dimensions.
Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.

Skip this if

Practitioners wanting forensic or offensive technique; like Ghernaouti's other work, it's a structured survey, not a hands-on manual.
Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.

Key takeaways

  • A 2023 structured survey of cybercrime spanning technique, law and prevention — broad rather than deep.
  • Strong on the legal and organisational response that purely technical books skip.
  • A natural companion to Ghernaouti's Cybersécurité, focused on the criminal dimension.
  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.

How they compare

We rate La norme ISO/IEC 27005 higher (4/5 against 3/5 for Cybercriminalité). For most readers, that means La norme ISO/IEC 27005 is the primary pick and Cybercriminalité is a useful follow-up.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

Cybercriminalité and La norme ISO/IEC 27005 both cover Policy, Foundations, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics