ISTPIndustrial Security & Terrorism Preparedness
Home › About the Programme › Standards Mapping

Standards Mapping

Mapping of the 14 ISTP topics against ASIS CPP domains, CTCB CCTP knowledge areas, and ISO and NIST standards.

How to read this table. The mapping shows the domains and knowledge areas used as design references for each topic — not equivalence or credit recognition. "Partial" means only part of the domain is covered; "applied" means the domain is practised in the field; "no direct equivalent" is stated openly.
CodeTopicASIS CPPCTCB CCTPStandard / Regulation
ISTP-M01The Role of Industrial Security in Terrorism PreventionDomain 1 — Security Principles & Practices (partial)Terrorism Fundamentals, Prevention and MitigationLaw No. 5/2018
ISTP-M02Intelligence Gathering for Industrial SecurityDomain 3 — Investigations (partial)Threat Identification—
ISTP-M03Psychology for Industrial SecurityDomain 4 — Personnel Security (partial)Threat Identification—
ISTP-M04Criminological Theory and Security System ConceptsDomain 1 — Security Principles & PracticesPrevention and Mitigation—
ISTP-M05Terrorist Motivations and Modi Operandi in IndonesiaNo direct domain equivalentTerrorism Fundamentals, Threat Identification—
ISTP-M06Regulatory Framework and StandardsDomain 2 — Business Principles & Practices (partial); Domain 1 — Security Principles & Practices (partial)Prevention and MitigationISO 18788:2015, ISO 28000:2022
ISTP-M07Security LeadershipDomain 2 — Business Principles & Practices—ASIS ESRM Guideline
ISTP-M08Cyber Security for IndustryDomain 6 — Information Security—NIST CSF 2.0, ISO/IEC 27001:2022
ISTP-M09Industrial Security FoundationsDomain 1 — Security Principles & PracticesTerrorism Fundamentals—
ISTP-M10Risk AnalysisDomain 1 — Security Principles & PracticesThreat IdentificationISO 31000:2018
ISTP-M11Crisis ManagementDomain 7 — Crisis ManagementPreparedness and ResponseISO 22301:2019
ISTP-M12Physical Security SystemsDomain 5 — Physical SecurityPrevention and MitigationISO 18788:2015
ISTP-M13Counter-Terrorism and Early DetectionDomain 1 — Security Principles & Practices (partial)Threat Identification, Prevention and Mitigation—
ISTP-M14Field Case Study — On-Site Security Assessment (Role Play: Counter-Surveillance)Domain 1 — Security Principles & Practices (applied); Domain 5 — Physical Security (applied)Threat IdentificationISO 31000 (field application)

ASIS CPP — 7 domains

  • Domain 1 — Security Principles & Practices (22%)
  • Domain 2 — Business Principles & Practices (15%)
  • Domain 3 — Investigations (9%)
  • Domain 4 — Personnel Security (11%)
  • Domain 5 — Physical Security (16%)
  • Domain 6 — Information Security (14%)
  • Domain 7 — Crisis Management (13%)

Domain weightings follow ASIS International's published specification for the CPP examination.

CTCB CCTP — 4 knowledge areas

  • Terrorism Fundamentals
  • Threat Identification
  • Prevention and Mitigation
  • Preparedness and Response

Based on the Certified Counter Terrorism Practitioner structure published by the Counter Terrorism Certification Board (Singapore).

Methodology notes

  • TVC and TVRA. The Risk Analysis topic uses the Threat–Vulnerability–Consequence (TVC) framework to assess a single scenario, then connects it to a Threat, Vulnerability and Risk Assessment (TVRA) as the full assessment process that produces risk treatment priorities. The two are taught as stages, not as interchangeable terms.
  • CARVER+Shock is introduced with its origin — developed for food defence as a derivative of the military CARVER method — and is used as an aid to asset prioritisation, not as a standalone method.
  • "Hybrid threat" is used in its national security doctrine sense (Industrial Security Foundations); the combination of physical and cyber attack is referred to as a "combined physical–cyber attack" (Cyber Security for Industry).

ASIS CPP® is a mark of ASIS International. CCTP is a credential of the Counter Terrorism Certification Board. ISTP is an independent professional programme and is not a certification issued by, affiliated with, or endorsed by those bodies.

WhatsApp