// Comparison

La norme ISO/IEC 27005 vs Tribe of Hackers: Which Should You Read?

Two cybersecurity books on Career, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52025
La norme ISO/IEC 27005

Maîtriser la gestion des risques en sécurité de l'information

Jean-Charles Pons

A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.

Beginner
3/52019
Tribe of Hackers

Cybersecurity Advice from the Best Hackers in the World

Marcus J. Carey, Jennifer Jin

An interview anthology of practitioners answering the same set of career and craft questions, useful as a wide-angle view of how working security people actually think about the field.

Read this if

Project managers, systems and network administrators, CISOs, CIOs, and anyone involved in information-security risk management who needs a pedagogical reference on the ISO/IEC 27005:2022 standard.
Newcomers and career-shifters who want a wide-angle view of how working security people actually think. The interview format pulls signal across roles (red team, blue team, IR, AppSec, leadership) without committing to any single voice.

Skip this if

Readers looking for direct offensive or defensive technique; this book is about risk-management governance and methodology, not attacking or defending a system.
Experienced practitioners. The interviews are short and the same questions repeat; you've heard much of it at conferences. Specialists looking for technical depth should pick books in their lane instead.

Key takeaways

  • No risk-management or ISO-compliance book existed in this catalog until now, filling a real gap for CISO and governance-track careers.
  • The second edition follows the current ISO/IEC 27005:2022 standard, not an outdated version.
  • Fictional case studies let readers apply each process concretely rather than staying at the theoretical level.
  • The book's structure (same questions to many voices) is unusually useful for spotting consensus and disagreement; what most respondents agree on tends to be true.
  • Career advice in security is unusually consistent across the field: communicate, document, ship, mentor, repeat. The book makes this visible.
  • Diversity of voice across the panel (junior to CISO, offensive to defensive) is the value; pick interviews to match your current question, not read straight through.

How they compare

We rate La norme ISO/IEC 27005 higher (4/5 against 3/5 for Tribe of Hackers). For most readers, that means La norme ISO/IEC 27005 is the primary pick and Tribe of Hackers is a useful follow-up.

La norme ISO/IEC 27005 is pitched at intermediate level. Tribe of Hackers is pitched at beginner level. Read the easier one first if you're not yet comfortable with the topic.

La norme ISO/IEC 27005 and Tribe of Hackers both cover Career, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics