// Comparison
Cybersecurity Tabletop Exercises vs La norme ISO/IEC 27005: Which Should You Read?
Two cybersecurity books on Policy, compared honestly: who each is for, what each does best, and which to read first.
From Planning to Execution
Robert Lelewski, John Hollenberger
Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.
Maîtriser la gestion des risques en sécurité de l'information
Jean-Charles Pons
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
Read this if
Skip this if
Key takeaways
- Splits cleanly into process (how to plan, facilitate, and evaluate an exercise) and content (ready-made scenarios across technical, executive, and cross-functional levels).
- Facilitation technique gets real attention — keeping participants engaged is treated as a skill, not an afterthought.
- Evaluation and follow-up are covered as seriously as the exercise itself, closing the loop that many tabletop efforts skip.
- No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
- The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
- Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
How they compare
Cybersecurity Tabletop Exercises and La norme ISO/IEC 27005 are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.
Both books target intermediate-level readers, so the choice is about topic, not difficulty.
Cybersecurity Tabletop Exercises and La norme ISO/IEC 27005 both cover Policy, Career, so reading them in sequence reinforces the same material from different angles.
Keep reading
Cybersecurity Tabletop Exercises
→ Alternatives to Cybersecurity Tabletop Exercises→ What to read after Cybersecurity Tabletop ExercisesLa norme ISO/IEC 27005
→ Alternatives to La norme ISO/IEC 27005→ What to read after La norme ISO/IEC 27005