Expertise · ISO/IEC 27005

From uncertainty to strategic decision

How the information security risk management process framework turns uncertainty into structured governance — through a dual defensive and offensive reading.

ISO/IEC 27005 and ISO/IEC 27001 — a fundamental relationship

ISO/IEC 27005 is the natural extension of ISO/IEC 27001. Where ISO/IEC 27001 establishes the requirements for an Information Security Management System (ISMS) — not to be confused with information systems security, a confusion that remains frequent — ISO/IEC 27005 defines the process framework that allows the five requirements relating to risk assessment and treatment to be instantiated.

Clarification · ISO/IEC 27005 is not a method

Contrary to a widespread belief, ISO/IEC 27005 is neither a method nor a methodology. It is a guidance standard that defines a process framework for information security risk management. Methods such as EBIOS Risk Manager, OCTAVE, MEHARI, CRAMM or FAIR do not replace ISO/IEC 27005 — they instantiate its framework according to the organisation's context, objectives and maturity level.

This distinction is structuring: it conditions how organisations choose their risk assessment method and align their practices with certification requirements.

Methods that instantiate the ISO/IEC 27005 framework

EBIOS RM

French method, recognised internationally

OCTAVE

Approach centred on organisational assets

MEHARI

Harmonised risk analysis method

CRAMM

British risk management method

FAIR

Financial quantification of cyber risk

Two complementary approaches

In its latest version, ISO/IEC 27005 gives significant weight to scenario-based approaches — an evolution that shows decisive convergence with modern risk assessment practices, notably EBIOS Risk Manager. Two complementary approaches take centre stage.

Offensive perspective

Scenario-based approach

  • Objectives pursued by attackers
  • Modes of operation and attack chains
  • Advanced Persistent Threats (APT)
  • State-sponsored attacks
  • Adversarial logic and strategy
Defensive perspective

Asset-based approach

  • Identification and classification of assets
  • Exposure to risks and vulnerabilities
  • Security measures and countermeasures
  • Defence-in-depth architecture
  • Alignment with ISO/IEC 27002

Together, these two approaches turn uncertainty into a structured, repeatable and governable decision process.

My training approach

Most ISO/IEC 27005 training programmes describe the standard's processes. My approach is different: it consists of placing ISO/IEC 27005 back within its true governance ecosystem and showing how this process framework connects with the full set of frameworks that structure information security risk management.

Fundamental concepts — the vocabulary of decision-making

Particular attention is given to notions that are still too often misunderstood or insufficiently implemented within organisations.

Four key concepts of risk governance

Risk Appetite

The level and nature of risk an organisation is willing to take in pursuit of its strategic objectives.

Risk Tolerance

The acceptable variation around risk appetite — the operational limits within which the organisation agrees to operate.

Risk Criteria

The terms of reference used to assess the significance of a risk and guide treatment decisions.

Risk Acceptance Criteria

The thresholds beyond which risks cannot be accepted without treatment — the foundation of decision-making consistency.

Offensive dimension — a dual strategic reading

I integrate into this training approach the offensive dimension developed through my teaching at the École de Guerre Économique (Economic Warfare School): understanding adversaries' objectives, strategies, modes of operation and attack chains. This dual reading — defensive and offensive — makes it possible to approach risk management as a genuine strategic governance tool, rather than a compliance exercise.

Grounded in operational experience

These concepts are illustrated by field experience drawn from engagements with major organisations, civilian and defence, in France and internationally — notably with organisations operating in high-risk environments and subject to strict regulatory requirements.

Training formats

Open enrolment

Open sessions, France & international

In-house

On site or remote, tailored

Individual coaching

Personalised guidance towards certification

e-Learning

Certified self-paced training, in French and English

ISO/IEC 27005 only reveals its full potential once it stops being perceived as a technical standard and becomes a genuine framework for governing decisions in the face of risk. Understanding risk means understanding, at once, the logic of the defender and that of the attacker. That is the vision I convey in every training programme I deliver.

Dominique Bourra  ·  PECB Platinum Trainer

Train your teams or certify individually?
In French and English, on site or remote.

Request a programme →