// Comparison

La norme ISO/IEC 27005 vs Social Engineering: Which Should You Read?

Two cybersecurity books on Foundations, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Intermediate
4/52018
Social Engineering

The Science of Human Hacking

Christopher Hadnagy

Christopher Hadnagy's broad procedural reference on social engineering as a discipline — recon, pretexting, elicitation, microexpressions, and the structured engagement model his consultancy operationalized.

Read this if

Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.
Working SE practitioners, awareness-program leads, and people building structured social-engineering engagements who want a single reference for the discipline. Stronger on framework and process than Mitnick; the elicitation and influence chapters draw heavily on Cialdini and Ekman.

Skip this if

Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.
Readers wanting Mitnick-style war stories or modern AI-driven SE tradecraft (deepfake voice clones, LLM-assisted spearphish). Hadnagy's controversial separation from DEF CON in 2022 is also worth being aware of as context for the author rather than the book.

Key takeaways

  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
  • SE is a structured engagement, not a stunt; the book operationalizes the kill chain in a way most practitioners can adapt directly.
  • Microexpression and influence material is borrowed but well-applied; the chapters on elicitation are the book's most cited.
  • The framework (information gathering → pretext → influence → exit) is the book's lasting contribution and the implicit syllabus for most modern SE training.

How they compare

La norme ISO/IEC 27005 and Social Engineering are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

La norme ISO/IEC 27005 and Social Engineering both cover Foundations, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics