Comparison

EBIOS RM vs ISO 27005: Which One Fits Your Project?

EBIOS RM vs ISO 27005: one is the ANSSI risk method, the other a risk management standard. Key differences, when each fits and how to combine them.

Back to blogSeptember 25, 20268 min read

EBIOS RM vs ISO 27005: a false choice

The "EBIOS RM vs ISO 27005" question comes up in almost every cyber risk management project, and it starts from a misunderstanding: the two do not belong to the same category. ISO/IEC 27005 is an international standard giving guidance on information security risk management, particularly within an information security management system (ISMS) that meets ISO 27001. EBIOS Risk Manager is a method, published by ANSSI, the French national cybersecurity agency, with the Club EBIOS, that describes concretely how to run the analysis in five workshops. One says what a risk management process must contain, the other says how to produce the analysis. Pitting them against each other usually means comparing two different levels. This article compares their purpose, their deliverables and the effort they require, corrects a few misconceptions, and offers a simple way to decide project by project.

ISO 27005: a risk management framework, not a step-by-step method

ISO/IEC 27005 belongs to the ISO 27000 family. It details the risk management process ISO 27001 expects: establish the context, assess the risks (identify, analyse and evaluate them), treat them, get the residual risk accepted, communicate, and monitor over time. It builds on the general principles of ISO 31000. What it does not do is prescribe workshops, scales or a mandatory threat catalogue: it leaves the organisation free to choose its method, as long as repeated assessments produce consistent, valid and comparable results, which ISO 27001 also requires. The 2022 revision describes two ways to identify risks, one event-based and one asset-based, without imposing either. Another point often misunderstood: there is no ISO 27005 certification. Certification applies to the ISMS, under ISO 27001, and ISO 27005 is the guide for building the risk part of that system. In short, an ISO 27005 risk assessment is defined by its process, not by a fixed sequence of steps.

EBIOS Risk Manager: the ANSSI risk method

EBIOS Risk Manager is the risk analysis method promoted by ANSSI. It is organised in five workshops: scope and security baseline, risk sources, strategic scenarios, operational scenarios, risk treatment. Its logic is the attacker's: you start from what has value for the business, identify who would have an interest in harming it and why, then build attack scenarios. Two features set it apart. First, the security baseline, established in workshop 1, which checks how the applicable frameworks (hygiene rules, regulatory requirements) are applied before working on more targeted scenarios. Second, the ecosystem, covered in workshop 3: suppliers, service providers, partners and customers are rated on the threat they represent, which brings supply chain attacks to the surface. Finally, the method provides two review cycles, a longer strategic cycle and a shorter operational one, so the analysis keeps pace with how the system changes.

EBIOS RM vs ISO 27005, point by point

The difference between EBIOS RM and ISO 27005 lies first in their nature: a guidance standard on one side, an operational method on the other. On scope, ISO 27005 covers the whole risk management cycle within a management system, communication and monitoring included, while EBIOS RM focuses on assessing and treating the risks of a given study object. On approach, ISO 27005 leaves the choice between asset-based and event-based identification, whereas EBIOS RM imposes a reading through risk sources and attack scenarios. On the ecosystem, EBIOS RM devotes a full workshop to it, while ISO 27005 leaves it to the chosen method to cover. On deliverables, ISO 27005 expects documented results without fixing their form, whereas EBIOS RM produces specific objects: business values, feared events, risk source and target objective pairs, a threat map of the ecosystem, attack paths, a treatment plan.

Combining them: EBIOS RM inside an ISO 27005 compliant process

In practice, the right answer is often: both, at two levels. ISO 27005 structures the organisation's process: who owns the risks, how often they are reassessed, how acceptance is decided, how management is kept informed. EBIOS RM provides the method that produces, inside that process, the analyses themselves. ANSSI itself presents EBIOS RM as compatible with the international risk management standards, including ISO 31000 and ISO 27005. The mapping is natural: workshop 1 scoping matches context establishment, workshops 2 to 4 match risk identification and analysis, and workshop 5 covers evaluation, treatment and acceptance of the residual risk. What stays with the ISMS is communication, monitoring, management review and improvement of the system itself. An ISO 27001 auditor mainly checks that this process is defined, applied and repeatable: a recognised, documented method makes that easier to demonstrate.

When to lean on one or the other

Several contexts shape the choice. If your goal is ISO 27001 certification, start from the ISO 27005 process and pick a method that fits inside it: EBIOS RM works, and so does an in-house method if it is documented and repeatable. If you are a regulated French entity, a public body, or an operator historically designated as an OIV (operator of vital importance) or OSE (operator of essential services), EBIOS RM is the method ANSSI promotes and the one your counterparts know, especially in security accreditation (homologation). For NIS2, article 21 calls for policies on risk analysis and information system security without naming a method: EBIOS RM, an ISO 27005 process or an in-house method can all meet it, provided they cover the expected measures, supply chain security among them. For an international group, ISO 27005 offers a shared vocabulary across subsidiaries, and EBIOS RM can remain the method for French entities or sensitive projects.

Effort, skills and deliverables: what each choice commits you to

The effort is not of the same kind. Setting up an ISO 27005 process is mostly governance work: define acceptance criteria, scales, roles and review cadence, then keep them alive. A full EBIOS RM analysis is project work: several workshops, with different participants depending on the workshop, business owners for values and impacts, architects for attack paths, procurement or legal for the ecosystem. It needs a facilitator who knows the method well, and a workshop 4 run without real knowledge of the architecture produces generic scenarios. On deliverables, the ISO 27005 process leaves a governance trail: criteria, risk register, acceptance decisions, review minutes. The EBIOS RM analysis leaves a study file, a threat map, a treatment plan and a formally accepted residual risk. Both meet in the risk register, which has to stay linked to the measures that were decided.

Common misconceptions about EBIOS Risk Manager vs ISO 27005

Four misconceptions keep coming back when EBIOS Risk Manager and ISO 27005 are compared. First: ISO 27005 is the international method and EBIOS RM the French one. That is inaccurate, since ISO 27005 is not a method and imposes none. Second: ISO 27001 certification requires ISO 27005. In reality, ISO 27001 requires a defined and applied risk assessment process, not the use of 27005, even if 27005 is its natural guide. Third: EBIOS RM is mandatory for NIS2. The directive imposes no method, even though EBIOS RM is consistent with ANSSI's approach. Fourth: EBIOS RM is too heavy for a mid-sized organisation. The method is modular, and its workshops are used according to the purpose of the study. The weight usually comes from a scope that is too broad, a search for completeness, or deliverables kept in files nobody can update.

Deciding project by project, and where AI fits in EBIOS RM

The decision is rarely made once and for all: it is made project by project, inside a single process. A critical project, exposed to third parties or handling sensitive data, warrants a full EBIOS RM analysis. A less critical project can go through a flash assessment, lighter, recorded in the same register and using the same criteria. That is the logic Vailor follows: a pre-assessment, started by the business, lets security qualify the project, then the analysis runs in EBIOS RM across all five workshops or as a flash assessment. ISO 27005 is not implemented there as a separate method: EBIOS RM analyses carried out in Vailor fit into an ISO 27005 compliant risk management process. On the AI side, the tool reads the project documents and prefills fields from excerpts, then the experts validate. The AI proposes, your experts decide.

EBIOS RM or ISO 27005: the takeaways

ISO 27005 answers the question "how do we manage risk over time", EBIOS RM the question "how do we analyse this particular scope". For an ISO 27001 programme, the process comes from 27005 and the method can be EBIOS RM. For a regulated French entity or a public body, EBIOS RM is the expected choice, and it remains compatible with governance aligned on ISO standards. For NIS2, what matters is being able to show a risk analysis that is documented, kept current and extended to suppliers, whatever the method. In every case, scale the effort: a full analysis where the risk justifies it, a lighter one elsewhere, a single register to track everything. Book 30 minutes: we listen to your context and tell you concretely how Vailor addresses it.

Let's talk about your context

Book 30 minutes. We listen to your priorities, tell you concretely how Vailor addresses them, and if it makes sense, we scope a pilot together.

Book a demo