// Comparison

La norme ISO/IEC 27005 vs Reversing: Which Should You Read?

Two cybersecurity books on Foundations, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Intermediate
4/52005
Reversing

Secrets of Reverse Engineering

Eldad Eilam

The book that taught a generation how software actually looks once you strip away the source. Still the clearest on-ramp to thinking in assembly, even with dated tools.

Read this if

Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.
People who want to genuinely understand reverse engineering from first principles rather than just running a disassembler and hoping. Self-taught practitioners filling in the gaps under their tooling.

Skip this if

Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.
Anyone who wants a modern, hands-on lab course. Skip this if you expect Ghidra walkthroughs or current malware samples; the toolchain here is OllyDbg and IDA-era and the OS examples are Windows XP.

Key takeaways

  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
  • Reverse engineering is a disciplined reading skill, not magic; the fundamentals of how compilers, stacks, and calling conventions work outlast any tool.
  • The most durable part of the book is the bridge from high-level constructs to their assembly fingerprints, which you will recognize for the rest of your career.
  • The Windows-internals, copy-protection, and anti-reversing material is a snapshot of 2005 and should be treated as historical context, not current practice.

How they compare

La norme ISO/IEC 27005 and Reversing are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

La norme ISO/IEC 27005 and Reversing both cover Foundations, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics