September 17, 2004—The basic components of a security manager’s job have not changed in spite of the upheaval since 9/11, according to a new study from ASIS International, the global organization for security management professionals.
ASIS’s most recent Job Analysis Study, conducted among Certified Protection Professionals (CPPs) worldwide, is intended to reexamine CPPs’ major areas of responsibility, work-related tasks, and knowledge and skills. The job analysis, by firmly linking the CPP certification exam to job requirements, provides the foundation that makes the exam valid and legally defensible.
Although the basic components of a security manager’s job have not changed, the study did find some changes reflecting the new realities of the security profession:
- The security environment is reflected in new tasks and knowledge statements, which appear in almost every domain. For example, questions on new methods of identifying people on a “watch” list could appear under “Personnel Security,” “Information Security,” or even “Emergency Management.”
- The domain formerly known as “Protection of Sensitive Information” is now “Information Security,” with a broader range of coverage.
- The “Security Management” domain is now divided into “Security Principles and Practices” and “Business Principles and Practices.”
ASIS, which has administered the CPP designation for more than 25 years, uses these periodical surveys for the critical project of defining the parameters and scope of the professions certified by ASIS, and updating the CPP exam to reflect current realities.
ASIS executives say they are confident that the updated CPP examination specifications capture the context of security managers’ positions in this new era. New exam questions have been written to reflect the updated job analysis, and the official reference list contains new editions of two books, a new book on information security management, and a revision of the Canadian law resource.

