ASIS-APP Exam Information and Outline
Associate Protection Professional
Syllabus Update Checked on: August 26, 2026
ASIS-APP Exam Syllabus & Study Guide
Before you start practicing with our exam simulator, it is essential to understand the
official ASIS-APP exam objectives. This course outline serves as your roadmap.
The information below reflects the 2026 syllabus defined by
ASIS.
Below are complete topics detail with latest syllabus and course outline, that will help you good knowledge about exam objectives and topics that you have to prepare. These contents are covered in questions and answers pool of exam.
ASIS-APP - Associate Protection Professional Exam
DOMAIN 1 — SECURITY FUNDAMENTALS — 35%
— Implement and coordinate the organization's security program(s) to protect the organization's assets
- Security theory and terminology
- Project management techniques
- Security industry standards
- Protection techniques and methods
- Security program and procedures assessment
- Security principles of planning, organization, and control
— Implement methods to improve the security program on a continuous basis through auditing, review, and assessment
- Data collection and intelligence analysis techniques
- Continuous assessment and improvement processes
- Audit and testing techniques
— Develop and coordinate external relations programs with public-sector law enforcement or other external organizations to achieve security objectives
- Roles and responsibilities of external organizations and agencies
- Local, national, and international public/private partnerships
- Methods for creating effective working relationships
— Develop, implement, and coordinate employee security awareness programs
- Nature of verbal and nonverbal communication and cultural considerations
- Security industry standards
- Training methodologies
- Communication strategies, techniques, and methods
- Security awareness program objectives and metrics
— Implement and/or coordinate an investigative program
- Report preparation for internal purposes and legal proceedings
- Components of investigative processes
- Types of investigations, including:
- Incident investigations
- Misconduct investigations
- Compliance investigations
- Internal and external resources supporting investigative functions
— Provide coordination, assistance, and evidence such as documentation and testimony to support legal proceedings
- Required components of effective documentation, including:
- Legal documentation
- Employee documentation
- Procedural documentation
- Policy documentation
- Compliance documentation
- Evidence collection and protection techniques
- Relevant laws and regulations concerning:
- Records management
- Records retention
- Legal holds
- Destruction practices
— Conduct background investigations for hiring, promotion, and/or retention of individuals
- Background investigation and personnel-screening techniques
- Quality and types of information and data sources
- Criminal, civil, and employment law and procedures
— Develop, implement, coordinate, and evaluate policies, procedures, programs, and methods to protect individuals in the workplace against human threats
Examples include harassment and violence.
- Principles and techniques of policy and procedure development
- Protection personnel, technology, and processes
- Regulations and standards governing or affecting:
- Security industry
- Protection of people
- Protection of property
- Protection of information
- Educational and awareness-program design and implementation
— Conduct and/or coordinate an executive/personnel protection program
- Travel security program components
- Executive/personnel protection program components
- Protection personnel, technology, and processes
— Develop and/or maintain a physical security program for an organizational asset
- Resource management techniques
- Preventive and corrective maintenance for systems
- Physical security protection equipment, technology, and personnel
- Security theory, techniques, and processes
- Fundamentals of security system design
— Recommend, implement, and coordinate physical security controls to mitigate security risks
- Risk mitigation techniques, including:
- Technology
- Personnel
- Processes
- Facility design
- Infrastructure
- Physical security protection equipment, technology, and personnel
- Security survey techniques
— Evaluate and integrate technology into the security program to meet organizational goals
- Surveillance techniques and technology
- Integration of technology and personnel
- Plans, drawings, and schematics
- Information security theory and systems methodology
— Coordinate and implement security policies that contribute to an information security program
- Practices to protect proprietary information and intellectual property
- Information-protection technology, investigations, and procedures
- Information security program components, including:
- Asset protection
- Physical security
- Procedural security
- Information-systems security
- Employee awareness
- Information destruction and recovery capabilities
- Information security threats
DOMAIN 2 — BUSINESS OPERATIONS — 22%
— Propose budgets and implement financial controls to ensure fiscal responsibility
- Data-analysis techniques and cost-benefit analysis
- Principles of business-management accounting, control, and audits
- Return on Investment (ROI) analysis
- Fundamental business-finance principles and financial reporting
- Budget-planning process
- Required components of effective documentation, such as:
- Budgets
- Balance sheets
- Vendor work orders
- Contracts
— Implement security policies, procedures, plans, and directives to achieve organizational objectives
- Principles and techniques of policy/procedure development
- Guidelines for individual and corporate behavior
- Improvement techniques, including:
- Pilot programs
- Education
- Training
— Develop procedures/techniques to measure and improve departmental productivity
- Communication strategies, methods, and techniques
- Techniques for quantifying:
- Productivity
- Metrics
- Key performance indicators (KPIs)
- Project-management fundamentals, tools, and techniques
- Principles of performance evaluations, 360-degree reviews, and coaching
— Develop, implement, and coordinate security staffing processes and personnel development programs to achieve organizational objectives
- Retention strategies and methodologies
- Job-analysis processes
- Cross-functional collaboration
- Training strategies, methods, and techniques
- Talent management and succession planning
- Selection, evaluation, and interview techniques for staffing
— Monitor and ensure a sound ethical culture in accordance with regulatory requirements and organizational objectives
- Interpersonal communication and feedback techniques
- Relevant laws and regulations
- Governance and compliance standards
- Generally accepted ethical principles
- Guidelines for individual and corporate behavior
— Provide advice and assistance in developing key performance indicators and negotiate contractual terms for security vendors/suppliers
- Confidential-information protection techniques and methods
- Relevant laws and regulations
- Key concepts in preparing requests for proposals (RFPs) and bid reviews/evaluations
- Service Level Agreement (SLA) definition, measurement, and reporting
- Contract law, indemnification, and liability-insurance principles
- Monitoring processes to ensure organizational needs and contractual requirements are met
- Vendor qualification and selection process
DOMAIN 3 — RISK MANAGEMENT — 25%
— Conduct initial and ongoing risk-assessment processes
- Risk-management strategies:
- Avoid
- Assume/accept
- Transfer
- Mitigate
- Risk-management and business-impact-analysis methodology
- Risk-management theory and terminology, including:
- Threats
- Likelihood
- Vulnerability
- Impact
— Assess and prioritize threats to address potential consequences of incidents
- Potential threats to an organization
- Holistic approach to assessing all-hazard threats
- Techniques, tools, and resources related to internal and external threats
— Prepare, plan, and communicate how the organization will identify, classify, and address risks
- Risk-management compliance testing, including:
- Program audits
- Internal controls
- Self-assessment
- Quantitative and qualitative risk assessments
- Risk-management standards
- Vulnerability, threat, and impact assessments
— Implement and/or coordinate recommended countermeasures for new risk-treatment strategies
- Countermeasures
- Mitigation techniques
- Cost-benefit-analysis methods for risk-treatment strategies
— Establish a business continuity or continuity of operations plan (COOP)
- Business-continuity standards
- Emergency-planning techniques
- Risk analysis
- Gap analysis
— Ensure pre-incident resource planning
Examples include mutual-aid agreements and tabletop exercises.
- Data-collection and trend-analysis techniques
- Techniques, tools, and resources related to internal and external threats
- Quality and types of information and data sources
- Holistic approach to assessing all-hazard threats
DOMAIN 4 — RESPONSE MANAGEMENT — 18%
— Respond to and manage an incident using best practices
- Primary roles and duties in an incident-command structure
- Emergency Operations Center (EOC) management principles and practices
— Coordinate the recovery and resumption of operations following an incident
- Recovery-assistance resources
- Mitigation opportunities during response and recovery processes
— Conduct a post-incident review
- Mitigation opportunities during response and recovery processes
- Post-incident review techniques
— Implement contingency plans for common types of incidents
Examples specifically identified by ASIS include:
- Bomb threats
- Active-shooter incidents
- Natural disasters
- Short- and long-term recovery strategies
- Incident-management systems and protocols
— Identify vulnerabilities and coordinate additional countermeasures for an asset in a degraded state following an incident
- Triage/prioritization and damage-assessment techniques
- Prevention, intervention, and response tactics
— Assess and prioritize threats to mitigate consequences of incidents
- Triage/prioritization and damage-assessment techniques
- Resource-management techniques
— Coordinate and assist with evidence collection for post-incident review
Examples include documentation and testimony.
- Communication techniques and notification protocols
- Communication techniques and protocols of liaison
— Coordinate with emergency services during incident response
- Emergency Operations Center (EOC) concepts and design
- EOC management principles and practices
- Communication techniques and protocols of liaison
— Monitor the response effectiveness to incident(s)
- Post-incident review techniques
- Incident-management systems and protocols