CPP Exam Domains and Knowledge Statements
CPP Exam Domains and Knowledge Statements
Task 1: Plan, develop, implement, and manage the organization's security program to protect the
organization's assets
Task 3: Evaluate methods to improve the security program on a continuous basis through the use of
auditing, review, and assessment
Task 4: Develop and manage external relations programs with public sector law enforcement or other
external organizations to achieve security objectives
Task 5: Develop, implement, and manage employee security awareness programs to achieve
organizational goals and objectives
1. Training methodologies
2. Communication strategies, techniques, and methods
3. Awareness program objectives and program metrics
4. Elements of a security awareness program (e.g., roles and responsibilities, physical risk,
communication risk, privacy)
Task 2: Develop, implement, and manage policies, procedures, plans, and directives to achieve
organizational objectives
Task 4: Develop, implement, and manage security staffing processes and personnel development
programs in order to achieve organizational objectives
Task 5: Monitor and ensure a sound ethical climate in accordance with regulatory requirements and
the organization's directives and standards to support and promote proper business practices
Task 6: Provide advice and assistance to management and others in developing performance
requirements and contractual terms for security vendors/suppliers
1. Key concepts in the preparation of requests for proposals and bid reviews/evaluations
2. Service Level Agreements (SLA) definition, measurement and reporting
3. Contract law, indemnification, and liability insurance principles
4. Monitoring processes to ensure that organizational needs and contractual requirements are
being met
Task 2: Manage or conduct the collection and preservation of evidence to support investigation
actions
1. Surveillance techniques
2. Technology/equipment and personnel to conduct surveillance
3. Laws pertaining to managing surveillance processes
Task 4: Manage and conduct investigations requiring specialized tools, techniques, and resources
Techniques, tools and resources related to:
Task 6: Provide coordination, assistance, and evidence such as documentation and testimony to
support legal counsel in actual or potential criminal and/or civil proceedings
1. Statutes, regulations and case law governing or affecting the security industry and the
protection of people, property and information
2. Criminal law and procedures
3. Civil law and procedures
4. Employment law (e.g., wrongful termination, discrimination and harassment)
Task 1: Develop, implement, and manage background investigations for hiring, promotion, or
retention of individuals
Task 2: Develop, implement, manage, and evaluate policies, procedures, programs and methods to
protect individuals in the workplace against human threats (e.g., harassment, violence)
Task 1: Conduct facility surveys to determine the current status of physical security
1. Security protection equipment and personnel
2. Survey techniques
3. Building plans, drawings, and schematics
4. Risk assessment techniques
5. Gap analysis
Task 2: Select, implement, and manage physical security strategies to mitigate security risks
Task 3: Assess the effectiveness of physical security measures by testing and monitoring
Task 1: Conduct surveys of information asset facilities, processes, systems, and services to evaluate
current status of information security program
Task 2: Develop and implement policies and procedures to ensure information is evaluated and
protected against all forms of unauthorized/ inadvertent access, use, disclosure, modification,
destruction or denial
1. Principles of management
2. Information security theory and terminology
3. Information security industry standards (e.g., ISO, PII, PCI)
4. Relevant laws and regulations regarding records management, retention, legal holds and
destruction practices
5. Practices to protect proprietary information and intellectual property
6. Protection measures, equipment, and techniques; including information security processes,
systems for physical access, data control, management, and information destruction
Task 3: Develop and manage a program of integrated security controls and safeguards to ensure
information asset protection including confidentiality, integrity, and availability
Task 2: Prepare and plan how the organization will respond to incidents
Task 4: Recover from incidents by managing the recovery and resumption of operations