Knowledge Library

EVERYTHING YOU NEED
TO KNOW & PASS.

Study materials, free tools, research reports, webinars, and external references, organized for the CRE security practitioner. Filter by what you need.

17 resources
Study Materials
5 items
Included with ExamStudy
CCP-CRE Common Body of Knowledge v1.0

The authoritative reference for all 7 exam domains. 300+ pages of CRE-specific content with OT/BAS architecture, physical-cyber convergence, tenant risk, REIT compliance, and 7 real-world case studies. The exam is written from this document.

PDF · 300+ pages · 3 labsGet with exam →
Included with ExamStudy
CCP-CRE Domain Study Guide

Condensed exam-focused companion to the CBK. All 7 domains summarized with key concepts, exam tips, and 30 practice questions with full explanations and CBK references. Built for active recall.

PDF · 7 domains · 30 practice QsGet with exam →
Included with ExamStudy
CCP-CRE Practice Exam Simulator

Full 80-question practice exam matching the real exam's domain weighting and format. Timed mode (120 min), domain filter, flag for review, instant feedback. Candidates scoring 80%+ have an 87% first-attempt pass rate.

Web · 80 questions · Timed + untimedGet with exam →
$35 Add-onStudy
CCP-CRE Flashcard Set

350 digital flashcards covering key terms, framework mappings, and protocol definitions across all 7 domains. Especially useful for BAS protocol characteristics and NIST CSF function definitions. Anki-compatible export included.

Digital · 350 cards · Anki-compatible
FreeStudy
CRA-RE Study Guide (Foundation Level)

Foundation-level study guide for the CRA-RE credential, open to all real estate professionals. Covers the 5 awareness domains: Phishing, Password Hygiene, Physical Security, Incident Reporting, and Building System Awareness. 11 practice questions included.

PDF · 5 domains · 11 practice QsTake the CRA-RE Exam →
Free Downloads, Tools & Templates
4 items
FreePlaybook
Ransomware Response Playbook for CRE

Structured incident response playbook for commercial real estate, containment decisions that balance OT safety, tenant impact, and evidence preservation. Includes decision trees, communication templates, and a post-incident review checklist.

PDF · 24 pages · Editable appendicesDownload →
FreeGuide
OT/BAS Network Segmentation Guide

Practical segmentation guidance for commercial buildings, from basic VLAN separation (Bronze-B) through firewall-enforced zero-trust (Gold-B). Reference network diagrams for Class A office, industrial, and mixed-use properties included.

PDF · 18 pages · Network diagramsDownload →
FreeTemplate
Vendor Remote Access Policy Template

Editable policy template governing OT/BAS vendor remote access, credential provisioning, session monitoring, MFA requirements, and de-provisioning. Structured to satisfy Bronze-B and Silver-B vendor access management requirements.

DOCX · Editable · Legal-reviewed structureDownload →
FreeChecklist
CRE Building Security Assessment Checklist

120-control checklist covering all four B Series tiers, color-coded by tier. Use it to self-assess your building's current posture before engaging with the formal certification process. Scoring built in.

XLSX · 120 controls · Self-scoringDownload →
Research & Reports
3 items
Case StudyFree
Case Study: Guacamole Gateway Compromise

Detailed analysis of an internet-exposed Apache Guacamole gateway used to pivot from IT into WebCTRL BAS servers and Avigilon surveillance. Covers the attack chain, detection failures, containment decisions, and 14 remediation items. Anonymized from a real 2025 incident.

PDF · 12 pages · Incident analysisDownload →
Research BriefFree0.5 CPE
Qilin Ransomware in CRE: Attribution & TTPs

Analysis of Qilin ransomware group targeting CRE environments, RDP brute force as initial access, lateral movement through flat OT networks, and double extortion against REIT operators. MITRE ATT&CK ICS mapped throughout.

PDF · 8 pages · ATT&CK mappedDownload →
Research BriefFree
OT/BAS Vendor Risk: The Generic Credential Problem

Analysis of vendor account persistence and shared credential exposure across 85 commercial buildings. Covers the "Engineer" account pattern, BACnet default credential exposure, and a framework for vendor access lifecycle management.

PDF · 10 pages · Survey-basedDownload →
Webinars & Events
3 items
UpcomingFree1.5 CPE
OT/BAS Security in High-Rise Office Buildings

Live session covering top attack vectors against BAS systems in Class A office, BACnet exposure, Niagara Framework vulnerabilities, and practical segmentation that doesn't break building operations. Q&A included.

April 15, 2026 · 60 min · ZoomRegister free →
On-DemandFree1.5 CPE
SEC Cyber Disclosure for REITs: What the 2023 Rules Require

Material incident thresholds, 4-day Form 8-K requirements, annual 10-K disclosures, and what your audit committee needs from the security team. Specifically structured for REIT operators and CRE security leaders.

Recorded · 55 min · Slides includedWatch on-demand →
On-DemandFree1.0 CPE
Building Certification Walkthrough: Bronze-B to Gold-B

Recorded walkthrough of the B Series certification process, what the assessment involves, what documentation is required, how to read your gap analysis, and how to structure your remediation roadmap. Includes Q&A with a past certification client.

Recorded · 48 min · Slides includedWatch on-demand →
External References
3 items
External · FreeExam Relevant
NIST Cybersecurity Framework 2.0

Essential reading for Domains 1 and 6 of the CCP-CRE exam. Understand all six CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) as they apply to CRE organizations. Exam questions directly reference CSF 2.0 tiers and functions.

NIST · Official publication · Free PDFAccess at NIST ↗
External · FreeExam Relevant
MITRE ATT&CK for ICS

The ICS ATT&CK matrix covering techniques most relevant to BAS attacks, Initial Access via internet-facing applications, OT lateral movement, Inhibit Response Function tactics. Domain 2 exam questions reference ATT&CK ICS directly.

MITRE · Web + PDF · FreeAccess at MITRE ↗
External · Free
CISA ICS-CERT Advisories, BAS & OT

CISA's ongoing ICS vulnerability advisories, filter for BACnet, Niagara, Tridium, and BAS vendors. Staying current with CISA ICS advisories is part of a mature OT vulnerability management program and is referenced in the Gold-B assessment framework.

CISA · Updated continuously · FreeAccess at CISA ↗
CPE Credits Available
4.0
Across all webinars and research briefs on this page, all count toward CCP-CRE annual renewal.
Annual Renewal Requirement
20
CPE credits required annually to maintain CCP-CRE. Webinars, case studies, and new domain modules all qualify.
More CPE Coming
Q2 '26
New domain update modules releasing Q2 2026, OT threat intelligence, Genea/WebCTRL deep dive, CCPR-CRE preview.
🔍
No resources match that filter.
Try a different category or view all resources.

READY TO PUT THE
KNOWLEDGE TO WORK?

Register for the CCP-CRE exam and get immediate access to the CBK, study guide, and practice exam simulator.