ISO/IEC 27005 is the natural extension of ISO/IEC 27001. Where ISO/IEC 27001 establishes the requirements for an Information Security Management System (ISMS) — not to be confused with information systems security, a confusion that remains frequent — ISO/IEC 27005 defines the process framework that allows the five requirements relating to risk assessment and treatment to be instantiated.
Clarification · ISO/IEC 27005 is not a method
Contrary to a widespread belief, ISO/IEC 27005 is neither a method nor a methodology. It is a guidance standard that defines a process framework for information security risk management. Methods such as EBIOS Risk Manager, OCTAVE, MEHARI, CRAMM or FAIR do not replace ISO/IEC 27005 — they instantiate its framework according to the organisation's context, objectives and maturity level.
This distinction is structuring: it conditions how organisations choose their risk assessment method and align their practices with certification requirements.
Methods that instantiate the ISO/IEC 27005 framework
EBIOS RM
French method, recognised internationally
OCTAVE
Approach centred on organisational assets
MEHARI
Harmonised risk analysis method
CRAMM
British risk management method
FAIR
Financial quantification of cyber risk
In its latest version, ISO/IEC 27005 gives significant weight to scenario-based approaches — an evolution that shows decisive convergence with modern risk assessment practices, notably EBIOS Risk Manager. Two complementary approaches take centre stage.
Scenario-based approach
- Objectives pursued by attackers
- Modes of operation and attack chains
- Advanced Persistent Threats (APT)
- State-sponsored attacks
- Adversarial logic and strategy
Asset-based approach
- Identification and classification of assets
- Exposure to risks and vulnerabilities
- Security measures and countermeasures
- Defence-in-depth architecture
- Alignment with ISO/IEC 27002
Together, these two approaches turn uncertainty into a structured, repeatable and governable decision process.
Most ISO/IEC 27005 training programmes describe the standard's processes. My approach is different: it consists of placing ISO/IEC 27005 back within its true governance ecosystem and showing how this process framework connects with the full set of frameworks that structure information security risk management.
Fundamental concepts — the vocabulary of decision-making
Particular attention is given to notions that are still too often misunderstood or insufficiently implemented within organisations.
Four key concepts of risk governance
Risk Appetite
The level and nature of risk an organisation is willing to take in pursuit of its strategic objectives.
Risk Tolerance
The acceptable variation around risk appetite — the operational limits within which the organisation agrees to operate.
Risk Criteria
The terms of reference used to assess the significance of a risk and guide treatment decisions.
Risk Acceptance Criteria
The thresholds beyond which risks cannot be accepted without treatment — the foundation of decision-making consistency.
Offensive dimension — a dual strategic reading
I integrate into this training approach the offensive dimension developed through my teaching at the École de Guerre Économique (Economic Warfare School): understanding adversaries' objectives, strategies, modes of operation and attack chains. This dual reading — defensive and offensive — makes it possible to approach risk management as a genuine strategic governance tool, rather than a compliance exercise.
Grounded in operational experience
These concepts are illustrated by field experience drawn from engagements with major organisations, civilian and defence, in France and internationally — notably with organisations operating in high-risk environments and subject to strict regulatory requirements.
Training formats
Open enrolment
Open sessions, France & international
In-house
On site or remote, tailored
Individual coaching
Personalised guidance towards certification
e-Learning
Certified self-paced training, in French and English
ISO/IEC 27005 only reveals its full potential once it stops being perceived as a technical standard and becomes a genuine framework for governing decisions in the face of risk. Understanding risk means understanding, at once, the logic of the defender and that of the attacker. That is the vision I convey in every training programme I deliver.