Home › About ISTP › Standards Mapping
Standards Mapping
Mapping of the 14 ISTP modules to ASIS CPP domains, CTCB CCTP knowledge areas and ISO/NIST standards.
How to read this table. Mapping shows the domains/knowledge areas used as design references for each module, not equivalence or credit recognition. "Partial" means only part of a domain is covered; "applied" means the domain is practised in the field; "no direct equivalent" is stated openly.
| Code | Module | ASIS CPP | CTCB CCTP | Standards / Regulation |
|---|---|---|---|---|
| ISTP-M01 | The Role of Industrial Security in Terrorism Prevention | Domain 1 — Security Principles & Practices (partial) | Terrorism Fundamentals, Prevention and Mitigation | Law No. 5/2018 |
| ISTP-M02 | Intelligence Gathering for Industrial Security | Domain 3 — Investigations (partial) | Threat Identification | — |
| ISTP-M03 | Psychology for Industrial Security | Domain 4 — Personnel Security (partial) | Threat Identification | — |
| ISTP-M04 | Criminological Theory and Security System Concepts | Domain 1 — Security Principles & Practices | Prevention and Mitigation | — |
| ISTP-M05 | Terrorist Motivation and Modus Operandi in Indonesia | No direct domain equivalent | Terrorism Fundamentals, Threat Identification | — |
| ISTP-M06 | Regulatory Frameworks and Standards | Domain 2 — Business Principles & Practices (partial); Domain 1 — Security Principles & Practices (partial) | Prevention and Mitigation | ISO 18788:2015, ISO 28000:2022 |
| ISTP-M07 | Security Leadership | Domain 2 — Business Principles & Practices | — | ASIS ESRM Guideline |
| ISTP-M08 | Cyber Security for Industry | Domain 6 — Information Security | — | NIST CSF 2.0, ISO/IEC 27001:2022 |
| ISTP-M09 | Industrial Security Foundations | Domain 1 — Security Principles & Practices | Terrorism Fundamentals | — |
| ISTP-M10 | Risk Analysis | Domain 1 — Security Principles & Practices | Threat Identification | ISO 31000:2018 |
| ISTP-M11 | Crisis Management | Domain 7 — Crisis Management | Preparedness and Response | ISO 22301:2019 |
| ISTP-M12 | Physical Security System | Domain 5 — Physical Security | Prevention and Mitigation | ISO 18788:2015 |
| ISTP-M13 | Counter-Terrorism and Early Detection | Domain 1 — Security Principles & Practices (partial) | Threat Identification, Prevention and Mitigation | — |
| ISTP-M14 | Field Case Study — On-Site Security Assessment (Role Play: Counter-Surveillance) | Domain 1 — Security Principles & Practices (applied); Domain 5 — Physical Security (applied) | Threat Identification | ISO 31000 (field application) |
ASIS CPP — 7 domains
- Domain 1 — Security Principles & Practices (22%)
- Domain 2 — Business Principles & Practices (15%)
- Domain 3 — Investigations (9%)
- Domain 4 — Personnel Security (11%)
- Domain 5 — Physical Security (16%)
- Domain 6 — Information Security (14%)
- Domain 7 — Crisis Management (13%)
Domain weights follow ASIS International publications for the CPP examination.
CTCB CCTP — 4 knowledge areas
- Terrorism Fundamentals
- Threat Identification
- Prevention and Mitigation
- Preparedness and Response
Based on the Certified Counter Terrorism Practitioner structure published by the Counter Terrorism Certification Board (Singapore).
Methodology notes
- TVC and TVRA. The Risk Analysis module uses the Threat–Vulnerability–Consequence (TVC) framework to assess a single scenario, then links it to Threat, Vulnerability and Risk Assessment (TVRA) as the whole-facility process that produces risk-treatment priorities. They are taught as stages, not interchangeable terms.
- CARVER+Shock is introduced with its origin (developed for food defence as a derivative of the military CARVER method) and used as an asset-prioritisation aid, not a stand-alone method.
- "Hybrid threat" is used in the state-security doctrine sense (Industrial Security Foundations); combined physical and cyber attacks are called "combined physical–cyber attacks" (Cyber Security for Industry).
ASIS CPP® is a mark of ASIS International. CCTP is a credential of the Counter Terrorism Certification Board. ISTP is an independent professional programme and not a certification issued by, affiliated with or endorsed by those bodies.