ISP Cheat Sheet 2026

The 30 highest-yield ISP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here โ€” free, no sign-up.

150 questions
180 min time limit
75% to pass
  1. An industrial facility's Emergency Operations Center (EOC) differs from the on-scene command post in that the EOC: โ†’ Provides strategic coordination and resource support removed from the hazard area
  2. Which perimeter barrier type provides the HIGHEST level of vehicle impact resistance for industrial facilities? โ†’ Anti-ram bollards rated to K12 standard
  3. What is the primary objective of crisis management? โ†’ To manage and mitigate the impact of a crisis
  4. Which type of security assessment involves an independent reviewer examining policies, procedures, and controls without physically testing them? โ†’ Security audit
  5. What is the legal consequence under 18 U.S.C. ยง 798 for knowingly and willfully communicating classified communications intelligence to an unauthorized person? โ†’ Up to 10 years imprisonment and/or fines
  6. How often should cleared personnel typically receive refresher security training? โ†’ At least annually, with additional training when threats or requirements change
  7. An adversarial simulation in which a team attempts to bypass physical and electronic security controls to reach a target within a facility is called a: โ†’ Red team assessment
  8. Why is incident response planning important in security risk management? โ†’ To ensure a coordinated and effective response to security incidents
  9. An industrial security professional receives a bomb threat call. The FIRST priority is to: โ†’ Keep the caller talking and gather as much information as possible
  10. What is the role of surveillance systems in physical security? โ†’ To monitor and deter unauthorized activities
  11. An insider threat is BEST defined as a risk posed by which of the following? โ†’ Current or former employees, contractors, or partners who misuse authorized access
  12. Which population typically receives the MOST targeted security training in an industrial facility due to their elevated access? โ†’ Systems administrators, security managers, and executives with privileged access
  13. Which clause in a vendor contract BEST helps protect an organization if a supplier experiences a security incident? โ†’ Security breach notification requirement clause
  14. A key purpose of post-incident debriefs (After Action Reviews) in industrial crisis management is to: โ†’ Document lessons learned to improve future response
  15. What is the primary goal of physical security in facility protection? โ†’ To protect facilities and assets from physical threats
  16. What is the role of lighting in facility protection? โ†’ To enhance security by increasing visibility and deterring crime
  17. Which category of emergency notification system is MOST critical for alerting off-site communities to an industrial chemical release? โ†’ Outdoor warning sirens combined with Emergency Alert System broadcasts
  18. Why is access control important in facility security? โ†’ To limit access to secure areas and protect sensitive information
  19. What is the purpose of security awareness training? โ†’ To help employees recognize and respond to security risks
  20. In the ASIS Risk Analysis framework, what does the term 'vulnerability' specifically refer to? โ†’ A weakness that could be exploited by a threat
  21. Which security risk management concept requires that countermeasures be proportional to the level of risk they are intended to address? โ†’ Proportionality of response
  22. The Purdue Model (Industrial Automation and Control Systems reference architecture) is PRIMARILY used to: โ†’ Define network segmentation zones and security boundaries between IT and OT systems
  23. What is the role of security audits in ensuring compliance? โ†’ To ensure security measures meet legal standards and identify gaps
  24. An ISP candidate is conducting a Business Impact Analysis (BIA). The PRIMARY purpose of this analysis is to: โ†’ Determine the financial and operational consequences of disruptions to critical functions
  25. The ISA/IEC 62443 standard series applies to: โ†’ Security for Industrial Automation and Control Systems (IACS) across the entire lifecycle
  26. Which access control model grants permissions based on a user's job function rather than individual identity? โ†’ Role-Based Access Control (RBAC)
  27. What is the importance of security policy enforcement? โ†’ To ensure that security measures are followed consistently
  28. During an active shooter event at an industrial facility, the widely recommended response protocol for employees is: โ†’ Run, Hide, Fight โ€” in that priority order
  29. During a declared emergency at an industrial facility, mutual aid agreements with neighboring facilities and local agencies are MOST valuable because they: โ†’ Provide pre-authorized access to additional resources when internal capacity is exceeded
  30. Which element is considered the cornerstone of an effective Business Continuity Plan (BCP) for an industrial facility? โ†’ A Business Impact Analysis (BIA) identifying critical functions
Was this helpful?