// Comparison

Cybersecurity Tabletop Exercises vs La norme ISO/IEC 27005: Which Should You Read?

Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52024
Cybersecurity Tabletop Exercises

From Planning to Execution

Robert Lelewski, John Hollenberger

Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Read this if

Incident responders, security managers, and anyone tasked with improving an organization's readiness who needs to actually run a tabletop, not just read about why they matter. Includes ready-to-adapt scenarios, injects, and storyboards for technical, executive, and cross-functional exercises.
Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.

Skip this if

Readers looking for incident-response technique itself (forensics, containment, eradication); this book is about rehearsing and testing a response plan, not executing one. Pair with Incident Response and Computer Forensics or Intelligence-Driven Incident Response for that side.
Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.

Key takeaways

  • Splits cleanly into process (how to plan, facilitate, and evaluate an exercise) and content (ready-made scenarios across technical, executive, and cross-functional levels).
  • Facilitation technique gets real attention — keeping participants engaged is treated as a skill, not an afterthought.
  • Evaluation and follow-up are covered as seriously as the exercise itself, closing the loop that many tabletop efforts skip.
  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.

How they compare

Cybersecurity Tabletop Exercises and La norme ISO/IEC 27005 are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

Cybersecurity Tabletop Exercises and La norme ISO/IEC 27005 both cover Policy, Career, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics