// Comparison
Cybercriminalité vs La norme ISO/IEC 27005: Which Should You Read?
Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.
Solange Ghernaouti's structured treatment of cybercrime — how it works, how to prevent it, how to respond — spanning technical, legal and organisational angles.
Maîtriser la gestion des risques en sécurité de l'information
Jean-Charles Pons
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
Read this if
Skip this if
Key takeaways
- A 2023 structured survey of cybercrime spanning technique, law and prevention — broad rather than deep.
- Strong on the legal and organisational response that purely technical books skip.
- A natural companion to Ghernaouti's Cybersécurité, focused on the criminal dimension.
- No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
- The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
- Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
How they compare
We rate La norme ISO/IEC 27005 higher (4/5 against 3/5 for Cybercriminalité). For most readers, that means La norme ISO/IEC 27005 is the primary pick and Cybercriminalité is a useful follow-up.
Both books target intermediate-level readers, so the choice is about topic, not difficulty.
Cybercriminalité and La norme ISO/IEC 27005 both cover Policy, Foundations, so reading them in sequence reinforces the same material from different angles.