3.4 Security Professional Ethics & Code of Conduct

Key Takeaways

  • The ASIS Code of Ethics mandates professional integrity, strict confidentiality, avoidance of conflicts of interest, competence, and legal compliance.
  • Navigating ethical dilemmas requires balancing legitimate workplace monitoring against employee privacy expectations through transparent policy governance.
  • The ASIS Ethics Committee investigates alleged ethical violations and enforces sanctions ranging from private reprimand to credential revocation.
  • Maintaining professional objectivity in vendor procurement and breach reporting is critical to upholding institutional trust and certification integrity.
Last updated: July 2026

Security Professional Ethics & Code of Conduct

Ethical conduct is the bedrock of professional security practice. Security managers are entrusted with sensitive corporate information, high-value physical assets, personal employee data, and human lives. The ASIS Code of Ethics defines the moral obligations, professional duties, and behavioral standards required of all ASIS members and credential holders (APP, CPP, PCI, PSP). Security leaders must maintain uncompromised ethical standards while navigating complex organizational dilemmas and managing disciplinary processes.


The ASIS Code of Ethics: Core Pillars

The ASIS Code of Ethics establishes mandatory guidelines governing professional behavior. Certified professionals must adhere strictly to five fundamental ethical pillars.

PillarEthical MandateOperational Application
I. Professional IntegrityPerform duties with honesty, integrity, and due diligence.Provide objective, truthful risk assessments without exaggerating threats or concealing security vulnerabilities for personal gain.
II. ConfidentialityProtect sensitive client and employer information.Maintain strict confidentiality regarding proprietary data, security plans, and executive protection details; disclose info only when required by law.
III. Avoidance of ConflictsAvoid actions or relationships that compromise objectivity.Refuse personal gifts, kickbacks, or financial interests in vendors bidding on corporate security contracts.
IV. Competence & DiligenceMaintain and enhance professional competence.Engage in continuous professional development, maintain active certifications, and perform services only within areas of expertise.
V. Compliance with LawsObserve all applicable statutory and regulatory laws.Refuse to execute unlawful commands, such as conducting unauthorized wiretaps or illegal employee surveillance.

Ethical Dilemmas in Security Management

Security professionals frequently encounter complex ethical challenges where corporate objectives, legal mandates, and individual privacy rights conflict.

       ┌────────────────────────────────────────────────────────┐
       │             Common Security Ethics Dilemmas            │
       └───────────────────────────┬────────────────────────────┘
                                   │
  ┌─────────────────┬──────────────┴──────────────┬─────────────────┐
  ▼                 ▼                             ▼                 ▼
┌──────────────┐  ┌──────────────┐             ┌──────────────┐  ┌──────────────┐
│  Employee    │  │  Transparent │             │  Vendor      │  │  Whistle-    │
│  Privacy vs. │  │  Breach      │             │ Selection &  │  │  blowing &   │
│ Monitoring   │  │ Disclosure   │             │ Procurement  │  │  Compliance  │
└──────────────┘  └──────────────┘             └──────────────┘  └──────────────┘

1. Employee Privacy vs. Workplace Monitoring

  • The Challenge: Organizations have a legitimate business interest in protecting intellectual property and preventing workplace violence through computer monitoring, CCTV surveillance, and email audits. However, employees maintain a reasonable expectation of privacy in certain contexts.
  • Ethical Resolution: Security management must uphold transparency. Monitoring should be governed by clear, written policies distributed to all employees, obtaining explicit written acknowledgments. Covert surveillance must be restricted exclusively to targeted, legally authorized investigations of suspected criminal activity, and monitoring must never extend into private areas such as restrooms, locker rooms, or changing facilities.

2. Transparent Breach Disclosure vs. Reputation Management

  • The Challenge: When a security failure or data breach occurs, corporate executives may pressure security managers to downplay the incident or delay public disclosure to protect stock prices and brand reputation.
  • Ethical Resolution: Security managers must prioritize honesty, regulatory compliance, and public safety over short-term corporate public relations. Withholding information regarding significant breaches violates statutory notification laws and compromises professional integrity under the ASIS Code of Ethics.

3. Conflicts of Interest in Vendor Selection

  • The Challenge: Security managers responsible for procuring security systems, guard forces, or consulting services may receive personal perks—such as expensive dinners, sports tickets, or sponsored travel—from vendors seeking contracts.
  • Ethical Resolution: Managers must adhere strictly to corporate procurement guidelines, maintain full transparency, disclose any potential personal relationships, and recuse themselves from vendor evaluation committees if a conflict of interest exists.

Disciplinary Procedures & Credential Revocation

ASIS International maintains a formal process to investigate alleged violations of the Code of Ethics and enforce disciplinary actions against credential holders under the ASIS Professional Conduct Guidelines.

The Disciplinary Process

   ┌──────────────────────────────────────────────────────────┐
   │            ASIS Ethics Disciplinary Process              │
   └────────────────────────────┬─────────────────────────────┘
                                │
       ┌────────────────────────┼────────────────────────┐
       ▼                        ▼                        ▼
┌──────────────┐         ┌──────────────┐         ┌──────────────┐
│   Formal     │         │ Impartial    │         │ Committee    │
│  Complaint   │────────>│ Investigation│────────>│ Review &     │
│ Submission   │         │ (Ethics Comm)│         │ Recommendation
└──────────────┘         └──────────────┘         └──────┬───────┘
                                                         │
                                                         ▼
                                                  ┌──────────────┐
                                                  │ Professional │
                                                  │ Sanction     │
                                                  │ Imposed      │
                                                  └──────────────┘
  1. Complaint Submission: Formal, written complaints alleging an ethical violation by an ASIS member or certified professional (APP, CPP, PCI, PSP) are submitted to the ASIS Ethics Committee.
  2. Investigation: The ASIS Ethics Committee conducts an impartial, confidential investigation, providing due process by notifying the accused individual and allowing them to submit evidence and a written defense.
  3. Adjudication: The Ethics Committee reviews the findings and determines whether a violation occurred based on clear and convincing evidence.

Sanctions Spectrum

If an ethical violation is substantiated, ASIS International may impose sanctions based on the severity of the misconduct:

  • Private Admonition: A confidential written warning issued to the individual for minor, first-time infractions without intent.
  • Censure / Public Reprimand: A formal public statement of rebuke published to the ASIS membership for moderate ethical violations.
  • Certification Suspension: Temporary suspension of ASIS credentials (APP, CPP, etc.) for a specified duration, requiring remediation before reinstatement.
  • Permanent Credential Revocation: Permanent revocation of ASIS certifications and expulsion from ASIS International membership for egregious violations, such as criminal convictions, fraud, or intentional breach of client confidentiality.

Due Process & Right to Appeal

To guarantee fairness, the ASIS Professional Conduct Guidelines provide an Appeals Process. Credential holders subjected to adverse sanctions have the right to file a formal appeal to the ASIS Board of Directors Appeals Committee within a specified timeframe, ensuring independent administrative review before final sanction execution.

Test Your Knowledge

A certified security professional receives valuable gifts and sponsored resort vacations from a vendor competing for a major physical security integration contract. Which core principle of the ASIS Code of Ethics is directly violated?

A
B
C
D
Test Your Knowledge

What formal body within ASIS International investigates alleged violations of the Code of Ethics and recommends sanctions against credential holders?

A
B
C
D
Test Your Knowledge

When balancing corporate monitoring and employee privacy, which ethical practice best ensures compliance and trust?

A
B
C
D