ISP Cheat Sheet 2026
The 30 highest-yield ISP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here โ free, no sign-up.
150 questions
180 min time limit
75% to pass
- An industrial facility's Emergency Operations Center (EOC) differs from the on-scene command post in that the EOC: โ Provides strategic coordination and resource support removed from the hazard area
- Which perimeter barrier type provides the HIGHEST level of vehicle impact resistance for industrial facilities? โ Anti-ram bollards rated to K12 standard
- What is the primary objective of crisis management? โ To manage and mitigate the impact of a crisis
- Which type of security assessment involves an independent reviewer examining policies, procedures, and controls without physically testing them? โ Security audit
- What is the legal consequence under 18 U.S.C. ยง 798 for knowingly and willfully communicating classified communications intelligence to an unauthorized person? โ Up to 10 years imprisonment and/or fines
- How often should cleared personnel typically receive refresher security training? โ At least annually, with additional training when threats or requirements change
- An adversarial simulation in which a team attempts to bypass physical and electronic security controls to reach a target within a facility is called a: โ Red team assessment
- Why is incident response planning important in security risk management? โ To ensure a coordinated and effective response to security incidents
- An industrial security professional receives a bomb threat call. The FIRST priority is to: โ Keep the caller talking and gather as much information as possible
- What is the role of surveillance systems in physical security? โ To monitor and deter unauthorized activities
- An insider threat is BEST defined as a risk posed by which of the following? โ Current or former employees, contractors, or partners who misuse authorized access
- Which population typically receives the MOST targeted security training in an industrial facility due to their elevated access? โ Systems administrators, security managers, and executives with privileged access
- Which clause in a vendor contract BEST helps protect an organization if a supplier experiences a security incident? โ Security breach notification requirement clause
- A key purpose of post-incident debriefs (After Action Reviews) in industrial crisis management is to: โ Document lessons learned to improve future response
- What is the primary goal of physical security in facility protection? โ To protect facilities and assets from physical threats
- What is the role of lighting in facility protection? โ To enhance security by increasing visibility and deterring crime
- Which category of emergency notification system is MOST critical for alerting off-site communities to an industrial chemical release? โ Outdoor warning sirens combined with Emergency Alert System broadcasts
- Why is access control important in facility security? โ To limit access to secure areas and protect sensitive information
- What is the purpose of security awareness training? โ To help employees recognize and respond to security risks
- In the ASIS Risk Analysis framework, what does the term 'vulnerability' specifically refer to? โ A weakness that could be exploited by a threat
- Which security risk management concept requires that countermeasures be proportional to the level of risk they are intended to address? โ Proportionality of response
- The Purdue Model (Industrial Automation and Control Systems reference architecture) is PRIMARILY used to: โ Define network segmentation zones and security boundaries between IT and OT systems
- What is the role of security audits in ensuring compliance? โ To ensure security measures meet legal standards and identify gaps
- An ISP candidate is conducting a Business Impact Analysis (BIA). The PRIMARY purpose of this analysis is to: โ Determine the financial and operational consequences of disruptions to critical functions
- The ISA/IEC 62443 standard series applies to: โ Security for Industrial Automation and Control Systems (IACS) across the entire lifecycle
- Which access control model grants permissions based on a user's job function rather than individual identity? โ Role-Based Access Control (RBAC)
- What is the importance of security policy enforcement? โ To ensure that security measures are followed consistently
- During an active shooter event at an industrial facility, the widely recommended response protocol for employees is: โ Run, Hide, Fight โ in that priority order
- During a declared emergency at an industrial facility, mutual aid agreements with neighboring facilities and local agencies are MOST valuable because they: โ Provide pre-authorized access to additional resources when internal capacity is exceeded
- Which element is considered the cornerstone of an effective Business Continuity Plan (BCP) for an industrial facility? โ A Business Impact Analysis (BIA) identifying critical functions
Turn these facts into recall:
Was this helpful?