// Comparison

La norme ISO/IEC 27005 vs The Pragmatic Programmer: Which Should You Read?

Two cybersecurity books on Foundations, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Beginner
5/52019
The Pragmatic Programmer

Your Journey to Mastery

David Thomas, Andrew Hunt

Thomas and Hunt's career-defining set of practical heuristics for writing software professionally — orthogonality, broken-windows, DRY, tracer bullets, and the underlying argument that craftsmanship is a posture, not a process.

Read this if

Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.
Every working software engineer, regardless of years of experience. The 20th-anniversary edition is the most current version of the field's most quoted book on professional software development; security engineers benefit because most security failures are software-quality failures wearing a different name.

Skip this if

Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.
Readers wanting domain-specific (security, ML, distributed-systems) depth; the book is deliberately general. Also not a methodology book — Thomas and Hunt are anti-methodology in spirit and explicitly so in the text.

Key takeaways

  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
  • Most security defects are software-quality defects; the book teaches the foundations that make secure code possible to write.
  • The list of heuristics is shorter than the book — 100 tips on a card — but the prose is what makes them stick.
  • The 20th-anniversary updates (concurrency, declarative thinking, observability) are the parts that justify the new edition for someone who read the original.

How they compare

We rate The Pragmatic Programmer higher (5/5 against 4/5 for La norme ISO/IEC 27005). For most readers, that means The Pragmatic Programmer is the primary pick and La norme ISO/IEC 27005 is a useful follow-up.

La norme ISO/IEC 27005 is pitched at intermediate level. The Pragmatic Programmer is pitched at beginner level. Read the easier one first if you're not yet comfortable with the topic.

La norme ISO/IEC 27005 and The Pragmatic Programmer both cover Foundations, Career, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics