The Cyber Academy take
EBIOS Risk Manager is the French national risk-assessment method published by ANSSI, focused on strategic cyber-attack scenarios. ISO/IEC 27005 is the international risk-management standard for information security, aligned with ISO 31000 and used as the methodology layer for ISO 27001 ISMS work. Both are practitioner methodologies; they are complementary more than alternatives.
TL;DR
- 1EBIOS RM is strategic and scenario-driven. Maps business processes onto attacker objectives, then derives technical controls. Strong in French public sector and operators of vital importance.
- 2ISO 27005 is methodology-agnostic and pairs natively with ISO 27001 Annex A. Standard in international audits.
- 3EBIOS RM produces a smaller number of high-impact scenarios with rich narrative. ISO 27005 produces a comprehensive risk register.
- 4Both are accredited PECB credentials: EBIOS Risk Manager (5 days), ISO/IEC 27005 Risk Manager (5 days). Lead Risk Manager exists only for ISO 31000.
- 5In practice: ISO 27005 for the ISMS risk register, EBIOS RM as a complement to identify the strategic scenarios that warrant board attention.
How each method actually runs in a project
The split between the two methods is not a question of quality; it is a question of starting point. ISO 27005 starts from assets and threats and walks outward to a complete risk register. EBIOS RM starts from what the organisation is afraid of losing and walks backward through the attacker who would cause that loss. The two produce different artefacts because they ask different opening questions, and that difference is what your auditor, your board, and your project plan will feel.
ISO 27005 work is iterative and exhaustive by design. You establish context, identify risks across the scope, analyse likelihood and consequence, evaluate against acceptance criteria, then treat. The output is a living register that you re-run on a cycle. It is the natural risk engine for an ISO 27001 ISMS because it speaks the same language as the management system: scope, criteria, treatment plan, residual risk, sign-off.
EBIOS RM runs as five workshops with a defined sequence: framing and security baseline, risk origins, strategic scenarios, operational scenarios, and risk treatment. The method forces you to name the feared events first, then the sources of risk (who would attack and why), then the high-level attack paths, before you ever touch a control. The EBIOS Risk Manager course walks each workshop with real deliverables so you leave able to facilitate the sequence, not just describe it.
EBIOS RM vs ISO 27005 at a glance
The table below is the comparison most teams need in the room: not the philosophy, but what each method focuses on, what it hands you at the end, and where it is actually expected.
| Dimension | EBIOS RM | ISO 27005 |
|---|---|---|
| Origin | French national method, published by ANSSI | International standard, ISO/IEC, aligned with ISO 31000 |
| Focus | Strategic attack scenarios; business stakes mapped onto threat sources | Systematic information-security risk identification across the scope |
| Starting point | Feared events and risk origins (top-down) | Assets, threats, vulnerabilities (bottom-up) |
| Output | A small set of high-impact, narrative scenarios with treatment strategy | A comprehensive, repeatable risk register with treatment plan |
| Granularity | Few scenarios, deep narrative, board-readable | Many risks, structured, ISMS-readable |
| Relationship to ISO 27001 | Complement; feeds strategic risks into the ISMS | Native methodology layer for Clause 6.1.2 and Annex A |
| Where expected | French public sector, OIV/OES, ANSSI-influenced procurement | International audits, multinational ISMS, customer assurance |
| Accredited credential | PECB EBIOS Risk Manager (5 days) | PECB ISO/IEC 27005 Risk Manager (5 days) |
How both map to ISO 27001
ISO 27001 requires a defined information-security risk assessment and treatment process, but it does not mandate a specific method. That single fact is why this comparison exists at all. Clause 6.1.2 tells you to assess risk and produce a Statement of Applicability; it does not tell you to use ISO 27005 or anything else. Auditors check that your process is consistent, repeatable, and produces defensible treatment decisions. The method is your choice.
ISO 27005 is the path of least resistance here because it was written to be the methodology layer under the standard. Its terminology, its acceptance-criteria logic, and its treatment-plan structure drop straight into the ISMS without translation. If you are building or running the management system, learn the engine that fits it: the ISO/IEC 27005 Risk Manager course covers the full assessment and treatment cycle, while the ISO/IEC 27005 Foundation course is the right entry point if you need the concepts before you facilitate.
EBIOS RM maps to the same clause from a different angle. It does not replace the register; it sharpens the top of it. The strategic scenarios become the small set of risks that justify the most scrutiny in the SoA and the board pack. Teams that need to own the methodology end to end, including assessment governance and the lead role across an organisation, take the ISO/IEC 27005 Lead Risk Manager course.
The decision: which one, and when both
Most teams frame this as either/or and then regret it. The honest answer is that the question has two layers: what does your audit or your sector require, and what does your risk picture actually need. Resolve them in that order.
- If an ANSSI-influenced buyer, a French public contract, or an OIV/OES obligation is in play, EBIOS RM is the expected language. Lead with it for the strategic layer.
- If your assurance comes from an international ISO 27001 certificate or multinational customer audits, ISO 27005 is the default the auditor reads fluently.
- If you have a real adversary problem (a high-value target, a regulated critical service, board-level cyber risk), run EBIOS RM on top of the register to surface the scenarios that warrant escalation.
- If you have neither a French-sector mandate nor an acute adversary profile, ISO 27005 alone is sufficient and cheaper to operate.
Running both is not redundant when you scope it correctly. ISO 27005 gives you breadth: every risk in the register, treated and tracked. EBIOS RM gives you depth on the few scenarios that would actually hurt. The mistake is running both at the same granularity, which doubles the work and produces two registers nobody reconciles. Use EBIOS RM to select and narrate; use ISO 27005 to enumerate and track.
Common mistakes and the audit-room reality
The failures are predictable, and they are rarely about the method itself.
- Choosing the method by preference instead of by audience. The right question is who reads the output: a French public buyer expects EBIOS RM vocabulary, an international certification auditor expects an ISO 27005-shaped register. Pick for the reader.
- Treating EBIOS RM scenarios as a substitute for a full register. Strategic scenarios are deliberately few. An auditor checking ISO 27001 coverage will ask where the rest of the risk landscape is documented, and a handful of narratives is not an answer.
- Running ISO 27005 as a one-time spreadsheet. The standard is iterative. A register dated eighteen months ago with no review cadence is a finding waiting to happen.
- Confusing the credentials. There is no Lead Auditor or Lead Risk Manager for EBIOS RM, and the only Lead Risk Manager credential sits under ISO 31000, not ISO 27005. Plan your team certification path against what actually exists.
In the audit room, the reality is simpler than the debate suggests. The certification auditor does not grade your method against a rival; they test whether your chosen process is documented, applied consistently, and traceable from risk to treatment to residual acceptance. EBIOS RM helps you explain why specific high-impact risks got specific attention. ISO 27005 helps you show that nothing fell through the gaps. The strongest posture, for organisations that genuinely need both, is an ISO 27005 register as the system of record with EBIOS RM scenarios layered on top to justify the decisions that mattered most.
Frequently asked questions
01Which one does my auditor expect?
For an ISO 27001 certification audit, the auditor expects an ISO/IEC 27005-aligned methodology by default. The 2022 revision of ISO 27005 explicitly bridges to ISO 27001 Clause 6 and to ISO 31000 principles.
For French public-sector audits (HFDS, ANSSI inspections of operators of vital importance under LPM, NIS 2 supervision by ANSSI), EBIOS RM is the expected language. Failure to articulate strategic scenarios in EBIOS RM vocabulary will be flagged.
02Can I use both at the same time?
Yes, and many organisations do. EBIOS RM produces 5 to 10 strategic attack scenarios with named threat sources, business assets and feared events; these become the inputs to an ISO 27005 risk register that handles the operational layer (vulnerability-asset combinations, likelihood-impact scoring, treatment options).
The combination works because EBIOS RM operates at the scenario level (board-friendly) while ISO 27005 operates at the asset/control level (audit-friendly). Mapping the two requires discipline but is well-trodden ground in French entities subject to both ANSSI supervision and ISO 27001 certification.
03Is EBIOS RM only relevant in France?
Mostly, yes. Outside France, ISO 27005 is the lingua franca for ISMS risk methodology. EBIOS RM is recognised by ENISA in some publications and used by French-influenced jurisdictions, but you will rarely encounter it in audits outside France or Francophone Africa.
If your audit footprint is purely international, ISO 27005 is the safer single choice. If you operate in France, in the public sector, or sell to French state entities, EBIOS RM literacy is expected.
04What does the PECB EBIOS Risk Manager credential cover?
Five days. Covers the five EBIOS RM workshops: scope and security baseline, risk sources, strategic scenarios, operational scenarios, risk treatment. Exam is open-book, three hours, mix of multiple-choice and scenario questions.
The credential is recognised by ANSSI through the PECB Gold Partner accreditation pathway. It does not substitute for ISO/IEC 27005 Risk Manager if your auditor expects the ISO methodology; it complements it.



