// Comparison

Cybercriminalité vs La norme ISO/IEC 27005: Which Should You Read?

Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
3/52010
Cybercriminalité

Droit pénal appliqué

Myriam Quéméner, Yves Charpenel

A practitioner's treatment of cybercrime law — offences, procedure, and the application of criminal law to digital crime — by a French magistrate specialised in the field.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Read this if

Lawyers, magistrates, compliance teams and investigators who need the legal framework around cybercrime: what's punishable, how procedure works, how the law is applied.
Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.

Skip this if

Technical readers wanting attacks or defence; this is a French-law legal text, and parts of any 2010 legal book are superseded by newer legislation.
Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.

Key takeaways

  • A specialist legal reference on French cybercrime law, by a magistrate who works the field.
  • Covers the offences, procedure and application of criminal law to digital crime.
  • Law evolves: read for the framework and reasoning, but verify specifics against current legislation.
  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.

How they compare

We rate La norme ISO/IEC 27005 higher (4/5 against 3/5 for Cybercriminalité). For most readers, that means La norme ISO/IEC 27005 is the primary pick and Cybercriminalité is a useful follow-up.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

Cybercriminalité and La norme ISO/IEC 27005 both cover Policy, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics