How are elliptic curves selected?

•Unlike
DLOG on (Z/nZ)*, there can be many
elliptic curves having the same order.

•Elliptic curves over finite fields can be

–“supersingular”: have subexponential attacks.

–“ordinary”: so far, no subexponential attacks.*

•Want E(Fq) to be prime, or at least have a large
prime factor. E(Fq) should be a cyclic group.

Essentially: known pitfalls are avoided, with limited understanding.