
La norme ISO/IEC 27005
Maîtriser la gestion des risques en sécurité de l'information · 2nd edition
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Jean-Charles Pons
- Published
- 2025
- Publisher
- Éditions ENI
- Pages
- 296
- Edition
- 2nd edition
- Language
- French
Read this if
Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.
Skip this if
Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.
Key takeaways
- No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
- The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
- Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
Notes
A governance complement to the catalog's more technical titles: pairs with Threat Modeling for the risk-focused design-side approach, and with Sécurité informatique - Ethical Hacking (ACISSI) for the offensive perspective this book deliberately doesn't cover.
What to read before
What to read before La norme ISO/IEC 27005 →Beginner · 2019
The Pragmatic Programmer
Thomas and Hunt's career-defining set of practical heuristics for writing software professionally — orthogonality, broken-windows, DRY, tracer bullets, and the underlying argument that craftsmanship is a posture, not a process.
Beginner · 2018
Click Here to Kill Everybody
Bruce Schneier's policy-level argument that as everything becomes a computer (cars, medical devices, infrastructure, voting), the security failures that used to merely cost us money will start costing lives — and the regulatory shape of that future is being decided now.
Beginner · 2015
La cybersécurité
A pocket-sized primer on cybersecurity as a societal and geopolitical issue — threats, actors, stakes and policy — in the classic French “Que sais-je ?” format.
What to read next
What to read after La norme ISO/IEC 27005 →Advanced · 2015
Sécurité informatique
A rigorous academic course on the foundations of security — cryptography, authentication, access control — with corrected exercises, from a team of well-known French and Swiss cryptographers.
Advanced · 2023
Exercices et problèmes de cryptographie
A rigorous problem book for learning cryptography — over 150 corrected exercises with course summaries, for L3/master/engineering students — by a French academic cryptographer.
Intermediate · 2024
Cybersecurity Tabletop Exercises
Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.
Explore similar books
Alternatives to La norme ISO/IEC 27005 →Intermediate · 2024
Cybersecurity Tabletop Exercises
Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.
Intermediate · 2023
Cybercriminalité
Solange Ghernaouti's structured treatment of cybercrime — how it works, how to prevent it, how to respond — spanning technical, legal and organisational angles.
Beginner · 2019
The Pragmatic Programmer
Thomas and Hunt's career-defining set of practical heuristics for writing software professionally — orthogonality, broken-windows, DRY, tracer bullets, and the underlying argument that craftsmanship is a posture, not a process.