PrepPass team · Verified against ASIS International's CPP, PCI, PSP, and APP Certification Exams 2026 Handbook (updated 4 August 2026) · How we review
FREE SAMPLE · READ ONLINEChapter 1 · 22% of the exam

Security Principles and Practices

This is Chapter 1 of the CPP Study Guide — 2026 Edition — one complete chapter, free to read right here; no download, no email. It is the same text as the eBook. When you reach the end, the complete guide is one click away.

This is the largest domain on the exam, and it is the one that frames everything else. The CPP treats security as a management discipline: a program is planned, risks are assessed with a repeatable method, the program is improved continuously, relationships outside the organization are managed deliberately, and the workforce is trained. Nearly every question in this chapter tests whether you think like a program manager or like a guard supervisor — the exam rewards the program manager.

Task 1 — Plan, develop, implement and manage the security program (ESRM)

The Body of Knowledge opens with the task to plan, develop, implement, and manage the organization's security program to protect the organization's assets. ASIS's published model for this work is Enterprise Security Risk Management (ESRM): a strategic approach to security management that ties an organization's security practice to its overall strategy using globally established and accepted risk management principles. The single most testable idea in ESRM is the shift in who owns risk. ESRM places the responsibility for security risk management decision making with the asset owners — in other words, whoever owns the asset owns the risk — while the security professional adopts the role of advisor rather than enforcer. On the exam, the wrong answers will cast the security manager as the person who decides what risk is acceptable; the right answer puts that decision with the asset owner and keeps security in the advisory seat.

ESRM runs as a four-step cycle. The first step is to identify and prioritize assets: understand what the assets are, where they are, and why they matter to the organization's mission, then prioritize by the impact each asset has on the organization's ability to execute that mission. The second step is to identify and prioritize risks to those assets. The third step is to mitigate the prioritized risks, choosing strategies that balance costs with acceptable risk levels. The fourth step is ongoing continuous improvement — the program is never declared finished. Underpinning the cycle are four pillars: holistic risk management (consider all types of security risk), partnership with stakeholders (security as trusted partner, not unilateral enforcer), transparency (be open with stakeholders about identified risks and the process used to prioritize and mitigate them), and governance (a governing body or committee leads the risk-tolerance discussion and makes top-level decisions).

How this is tested: a scenario describes a disagreement about a security spend or a residual risk, and asks who decides or what security's role is. The trap answers sound responsible — "the security director accepts the risk" — but in ESRM the director advises and the asset owner decides. Another favorite: asking which step of the cycle comes next. Remember the order — assets first, then risks, then mitigation, then continuous improvement — because the exam will offer "mitigate risks" as a tempting answer to a question whose scenario is still at the asset-identification stage.

Task 2 — The security risk assessment process

Task 2 asks you to develop, manage, or conduct the security risk assessment process. NIST SP 800-30 defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event — typically a function of the adverse impacts if the event occurs and the likelihood of occurrence. That two-factor structure (likelihood × impact) is the spine of every risk assessment method the exam touches.

Assessments come in three flavors. Qualitative assessments use nonnumerical categories or levels — very low, low, moderate, high, very high — and they are best at communicating risk results to decision makers. Quantitative assessments use numbers whose meanings and proportionality hold inside and outside the assessment — dollars, frequencies, probabilities — and they most effectively support cost-benefit analyses of alternative risk responses. Semiquantitative assessments sit between: they use bins, scales, or representative numbers (like a 1–5 matrix) whose values do not carry real-world meaning outside the assessment. The exam loves to ask which method fits a situation: a board presentation asking "how bad is it" wants qualitative; a budget decision comparing two countermeasures wants quantitative.

Quantitative analysis has its own vocabulary, and the exam expects you to compute. Single Loss Expectancy is the loss from one occurrence: SLE = asset value × exposure factor (EF), where EF is the fraction of the asset's value lost to the threat. Annualized Loss Expectancy spreads that over a year: ALE = SLE × ARO, where ARO is the annualized rate of occurrence. A countermeasure is worth buying when its value — the ALE it removes, i.e., ALE before minus ALE after — exceeds its cost; one common formulation is ROI = countermeasure value ÷ countermeasure cost, and a value above 1.0 means the control pays for itself. Watch the trap that confuses SLE with ALE: the question gives an ARO and asks for the annual figure, and one option is the single-loss number.

Finally, once risks are assessed, NIST names five families of risk response: acceptance, avoidance, mitigation, sharing, and transfer. Acceptance means living with the risk; avoidance means eliminating the activity that creates it; mitigation means reducing likelihood or impact; sharing spreads the risk (for example across partners); transfer shifts the financial consequence to a third party, classically through insurance. The exam tests the distinctions: buying insurance is transfer, not mitigation; discontinuing a product line is avoidance, not acceptance.

Task 3 — Continuous improvement through auditing, review and assessment

Task 3 — evaluate methods to improve the security program on a continuous basis through auditing, review, and assessment — is the ESRM fourth step wearing operational clothes. Audits test conformance against a standard or policy; reviews are management-level examinations of whether the program still fits the organization's needs; assessments measure current performance against objectives. Incidents and investigations feed this loop: ESRM explicitly notes that operational tasks like incident response offer the ancillary benefit of fueling continuous improvement. The trap here is treating improvement as a one-time project with an end date — the exam's right answers always describe a recurring cycle, and the wrong ones describe a single certification or a finished overhaul.

Task 4 — Relationships with external organizations

Task 4 asks you to develop and manage professional relationships with external organizations to achieve security objectives. This is the liaison portfolio: law enforcement agencies, emergency services, regulators, industry groups, and neighboring organizations. The tested principles are practical — know your contacts before the crisis, establish information-sharing channels in advance, understand jurisdictional boundaries, and coordinate rather than freelance. Questions here are usually scenario-based: a facility faces a threat that crosses property lines, and the correct answer involves engaging the appropriate external agency or mutual-aid partner rather than handling it entirely in-house. The wrong answers either ignore the external party or suggest the security team assume powers it does not have.

Task 5 — Workforce security awareness programs

Task 5 — develop, implement, and manage workforce security awareness programs — treats the workforce as a control. A program needs defined objectives tied to organizational goals, content matched to roles and risk (executives, travelers, new hires, contractors), delivery methods that fit the audience, and measurement: completion rates, phishing-test click rates, incident-reporting rates. The exam tests two things repeatedly: that awareness is an ongoing program rather than a one-time briefing, and that it is measured. A tempting wrong answer describes a single annual video with no follow-up; the right answer describes recurring training with metrics and reinforcement.

Key numbers & deadlines

FigureValueSource
Risk (NIST SP 800-30)Function of adverse impact × likelihood of occurrence[1]
SLEAsset value × exposure factor[2]
ALESLE × annualized rate of occurrence[2]
Countermeasure ROICountermeasure value ÷ countermeasure cost[2]
Risk responsesAcceptance, avoidance, mitigation, sharing, transfer[1]
ESRM cycleAssets → risks → mitigation → continuous improvement[3]

Key takeaways

  • In ESRM, asset owners own risk decisions; security advises. The exam punishes answers that make the security manager the decider.
  • Assess in order: identify and prioritize assets first, then risks, then mitigate, then improve continuously.
  • Qualitative communicates to decision makers; quantitative supports cost-benefit decisions; semiquantitative uses bins and scales.
  • SLE is per-occurrence loss; ALE is per-year loss (SLE × ARO). A countermeasure pays when its ALE reduction exceeds its cost.
  • Insurance is risk transfer; dropping the activity is avoidance; reducing likelihood or impact is mitigation.
  • Improvement is a recurring cycle fed by audits, reviews, assessments, and lessons from incidents — never a one-time project.
  • Awareness programs are ongoing and measured, not one-time briefings.

Chapter 1 quiz — 22 questions

1. A security analyst must compare two proposed countermeasures for the board and show which one returns more value per dollar spent. Which assessment type most effectively supports that cost-benefit analysis?

  • A. A qualitative assessment
  • B. A semiquantitative assessment
  • C. A quantitative assessment
  • D. A descriptive assessment

2. A new security manager is building the company's first formal security program. According to the ESRM cycle, what should she do first?

  • A. Buy countermeasures for the highest risks
  • B. Write the incident response procedures
  • C. Benchmark against peer company programs
  • D. Identify and prioritize the organization's assets

3. A manufacturing firm's operations VP refuses to fund a recommended upgrade to the plant's intrusion alarms, saying the current risk is acceptable to her. Under the ESRM model, whose decision is that to make?

  • A. The security director, as the program owner
  • B. The operations VP, as the asset owner
  • C. The finance director, as the budget holder
  • D. The alarm vendor, as the technical expert

4. A company discontinues its cash-handling service at retail sites after a string of robberies. Which risk response does this represent?

  • A. Risk avoidance
  • B. Risk acceptance
  • C. Risk mitigation
  • D. Risk transfer

5. A security manager wants to know whether the phishing awareness program is working. Which metric best measures its effectiveness?

  • A. The number of training slides used
  • B. The total hours of training delivered
  • C. The trainer's satisfaction survey score
  • D. The phishing-test click rate over time

6. A CEO asks why the security budget funds both guards and cybersecurity tools instead of focusing on one. Which ESRM pillar best justifies the answer?

  • A. Holistic risk management
  • B. Governance by committee
  • C. Transparency with stakeholders
  • D. Continuous improvement cycles

7. A hospital buys an insurance policy covering losses from equipment theft. Which risk response does the purchase represent?

  • A. Risk mitigation
  • B. Risk sharing
  • C. Risk transfer
  • D. Risk acceptance

8. Under ESRM, a security professional who tells business units which risks they must accept and enforces the decision is violating which pillar?

  • A. Stakeholder partnership
  • B. Holistic risk management
  • C. Transparency of process
  • D. Governance structure

9. During a regional flood, a plant's security team considers directing traffic on public roads around the site. What is the correct approach to external coordination?

  • A. Take over traffic control immediately
  • B. Hire contractors to block the roads
  • C. Coordinate with local law enforcement
  • D. Close the roads without notice

10. A company installs sprinklers that cut a fire's expected damage from 70% of a warehouse's value to 20%. If the warehouse is worth $1,000,000, what is the single loss expectancy after the control?

  • A. $700,000
  • B. $500,000
  • C. $200,000
  • D. $300,000

11. A facility borders a rail yard where trespassers regularly cut through the property. The security manager wants a coordinated response. Which external relationship is most appropriate to develop first?

  • A. The rail operator's security team
  • B. A private investigation firm
  • C. An executive protection provider
  • D. A cybersecurity consultant

12. A server worth $200,000 faces a ransomware threat expected to destroy 40% of its value per incident, occurring on average once every four years. What is the annualized loss expectancy?

  • A. $80,000
  • B. $20,000
  • C. $50,000
  • D. $32,000

13. A company rolls out security awareness training as a single 20-minute video shown once at new-hire orientation, with no follow-up. What is the principal weakness of this program?

  • A. The video format is outdated
  • B. It is not ongoing or measured
  • C. New hires are the wrong audience
  • D. Orientation is too early for training

14. An organization shares threat intelligence with peer companies through an industry group so all members benefit. Which risk response does this best illustrate?

  • A. Risk transfer
  • B. Risk sharing
  • C. Risk avoidance
  • D. Risk acceptance

15. An assessment scores threats on a 1-to-5 scale where the numbers rank severity but do not represent dollars or real frequencies. Which type is it?

  • A. Semiquantitative
  • B. Quantitative
  • C. Qualitative
  • D. Deterministic

16. A security director presents risk findings to the executive team using plain-language categories because the audience needs a clear picture fast. Which assessment strength is she relying on?

  • A. Quantitative precision in dollar terms
  • B. Statistical modeling of rare events
  • C. Automated scoring of vulnerabilities
  • D. Clear communication to decision makers

17. A security program's annual review finds that the threat landscape changed but the policies did not. Which improvement activity most directly addresses that gap?

  • A. A compliance audit against the old policy
  • B. A guard force headcount increase
  • C. A vendor contract renewal
  • D. A management review of program fit

18. A countermeasure costs $15,000 per year and reduces a threat's ALE from $60,000 to $30,000. What is the countermeasure's ROI under the value-over-cost formulation?

  • A. 0.5
  • B. 1.0
  • C. 4.0
  • D. 2.0

19. During a risk workshop, stakeholders disagree about how much risk the company should tolerate. Under the ESRM pillars, which body should lead that discussion and make the top-level decision?

  • A. The security department alone
  • B. A governing committee
  • C. The external audit firm
  • D. The insurance broker

20. A risk assessment report states that a data-center flood has "high" impact and "low" likelihood, using labeled categories rather than dollar figures. Which assessment type does this describe?

  • A. A qualitative assessment
  • B. A quantitative assessment
  • C. A semiquantitative assessment
  • D. A probabilistic assessment

21. After a theft investigation reveals a guard tour was skipped for weeks, the security manager revises the patrol policy and adds supervisor spot-checks. Which ESRM step does this illustrate?

  • A. Identifying and prioritizing assets
  • B. Ongoing continuous improvement
  • C. Mitigating prioritized risks
  • D. Establishing governance pillars

22. A risk register lists a threat with an annualized rate of occurrence of 0.25. What does that figure mean?

  • A. The threat occurs every four months
  • B. The threat has a 25% chance each month
  • C. The threat is expected once every four years
  • D. The threat already occurred 25 times

Answer key & explanations

1. C. Quantitative assessments use numbers whose meanings and proportionality hold inside and outside the assessment, and they most effectively support cost-benefit analyses of alternative risk responses. Comparing value per dollar is exactly that analysis, so the quantitative approach fits and the qualitative one does not.[1]

2. D. The ESRM cycle begins by identifying and prioritizing assets — understanding what they are, where they are, and why they matter to the mission — before risks are identified, mitigated, or improved upon. Buying countermeasures first skips the foundation the whole cycle rests on, which is why it is the trap.[3]

3. B. ESRM places security risk management decision making with the asset owners — whoever owns the asset owns the risk — and the security professional serves as advisor rather than enforcer. The operations VP, as asset owner, decides whether the residual risk is acceptable; the security director's role is to frame the risk and recommend, not to overrule. The tempting wrong answer is the security director, which describes the old enforcer model ESRM replaces.[3]

4. A. Avoidance eliminates the activity that creates the risk — here, the cash-handling service itself. Mitigation would reduce the robbery risk while keeping the service; acceptance would keep the service and live with the risk. Discontinuing the activity is the textbook avoidance move.[1]

5. D. Effectiveness is shown by outcomes: NIST treats the number of people who report a phishing test appropriately[4] and the share who change a behavior[4] as measures of whether the program works. Slides, hours and trainer satisfaction measure activity.

6. A. Holistic risk management means ESRM considers all types of security risk, so the budget properly spans physical and cyber rather than betting on one. Governance describes who decides, not what the program covers, which is why it is the trap.[3]

7. C. Transfer shifts the financial consequence of a risk to a third party, classically through insurance. The theft risk itself is unchanged — the cameras and locks that would reduce it would be mitigation — but the dollar consequence now sits with the insurer.[1]

8. A. The partnership pillar positions security professionals as trusted partners who advise asset owners, not as authoritarians who unilaterally define and enforce policy. Dictating risk acceptance to business units is the enforcer model ESRM explicitly replaces.[3]

9. C. Directing traffic on public roads is a job for the agency with authority, and NIMS expects government and the private sector to work together in response[5]. A private security team has no authority on public roads, so coordinating with local law enforcement is correct.

10. C. SLE after the control equals asset value times the new exposure factor: $1,000,000 × 0.20 = $200,000. The $700,000 figure is the pre-control loss, the trap for readers who compute the reduction but forget the question asks for the after-control figure.[2]

11. A. Security risks that cross property lines are managed through partnerships: NIMS describes government, NGOs and the private sector working together to prevent, protect against and respond to incidents[5]. The rail operator controls the adjacent risk, so it is the relationship to build first; the other providers do not address the trespass path.

12. B. SLE equals asset value times exposure factor: $200,000 × 0.40 = $80,000 per incident. ALE equals SLE times the annualized rate of occurrence: $80,000 × 0.25 = $20,000. The trap is stopping at the $80,000 single-loss figure and forgetting to annualize.[2]

Sources cited in this excerpt

  1. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments (2012). https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
  2. Quantitative Security (CS 559 lecture slides, Colorado State University, Yashwant K. Malaiya; slide dated September 3, 2025). https://www.cs.colostate.edu/~cs559/slides/L4.pdf
  3. ASIS International, A Brief Guide to ESRM Implementation (2022). https://www.asisonline.org/globalassets/publications-and-resources/documents/a-brief-guide-to-esrm-implementation.pdf
  4. NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program (2024). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-50r1.pdf
  5. FEMA, National Incident Management System, 3rd ed. (2017). https://www.fema.gov/sites/default/files/2020-07/fema_nims_doctrine-2017.pdf
You've read the free chapter

Get the complete guide

That was Chapter 1 of 7 — one complete chapter, exactly as it ships. The other chapters go just as deep on every section of the exam, plus practice questions with answer explanations — as a clean PDF and EPUB you keep forever.

  • All seven CPP domains, with every published task under its own heading
  • A quiz closing each of the 7 chapters, with worked explanations
  • A 225-question practice exam at the published domain weights
  • 326 original questions, each explained and cited to its source
  • Taught from public sources: NIST, FEMA, DHS, OSHA
  • PDF + EPUB you keep

Own the complete book — PDF + EPUB

The practice questions and timed mock stay free. The book is the studying half:

  • Taught chapter by chapter — every exam section explained in order, not just questions
  • Print it & tab it — a paper reference you can highlight and mark up
  • Works offline — PDF for print, EPUB for your phone or e-reader
  • Everything in one file — every chapter together, searchable and printable

This book is written in English.

$24.99one-time · lifetime download · no subscription

14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. Refund policy

A free sample chapter is on this site — try before you buy. One payment unlocks the complete book as a PDF + EPUB you keep.

One-time $24.99 · PDF + EPUB · yours forever · see everything inside.

Free sample — one complete chapter of the CPP — Certified Protection Professional study guide. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: August 2026.

Report