1.1Understand, adhere to, and promote professional ethics
1.2Understand and apply security concepts
1.3Evaluate and apply security governance principles
1.4Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
1.5Understand requirements for investigation types
1.6Develop, document, and implement security policy, standards, procedures, and guidelines
1.7Identify, analyze, assess, prioritize, and implement business continuity (BC) requirements
1.8Contribute to and enforce personnel security policies and procedures
1.9Understand and apply risk management concepts
1.10Understand and apply threat modeling concepts and methodologies
1.11Apply supply chain risk management (SCRM) concepts
1.12Establish and maintain a security awareness, education, and training program