SSO Performance Monitoring & QA 3 — Questions and Answers
Question 1: Under ISPS Code requirements, who is responsible for verifying that the Ship Security Plan is implemented effectively?
- Port State Control Officer
- Ship Security Officer (SSO) (Correct answer)
- Flag State Administration surveyor
- Company Security Officer (CSO) exclusively
Correct answer: Ship Security Officer (SSO)
The SSO bears primary onboard responsibility for implementing and verifying the effectiveness of the SSP on a day-to-day basis.
Question 2: A key performance indicator (KPI) for security training is best measured by:
- Hours of training delivered per crew member per year
- Pre- and post-training assessment scores combined with drill performance (Correct answer)
- Number of training manuals distributed aboard
- Amount spent on external security training providers
Correct answer: Pre- and post-training assessment scores combined with drill performance
Combining knowledge assessments with observed drill performance gives the most accurate picture of whether training is actually effective.
Question 3: Which of the following is a leading indicator of security performance, as opposed to a lagging indicator?
- Number of security incidents recorded last quarter
- Percentage of crew up to date on security awareness training (Correct answer)
- Number of stowaway discoveries in the past year
- Total fines levied by port state control for security deficiencies
Correct answer: Percentage of crew up to date on security awareness training
Training currency is a leading indicator because it predicts future performance, whereas incident counts and fines reflect past failures.
Question 4: When a security drill is deemed unsatisfactory, what must the SSO do in addition to scheduling a repeat drill?
- Immediately notify the Coast Guard
- Conduct a root cause analysis and document corrective actions in the security record (Correct answer)
- Suspend all shore leave until retraining is complete
- File an official protest with the union
Correct answer: Conduct a root cause analysis and document corrective actions in the security record
Root cause analysis and documented corrective actions are required by quality assurance principles and support continuous improvement.
Question 5: The SSO is reviewing security equipment maintenance logs and finds that lifebuoy light testing has not been recorded for 45 days. Under QA protocols, this gap indicates:
- The lights are functioning correctly and need no attention
- A record-keeping or maintenance compliance failure requiring immediate corrective action (Correct answer)
- Port state control should be notified before departure
- The maintenance cycle was extended by the CSO and no action is needed
Correct answer: A record-keeping or maintenance compliance failure requiring immediate corrective action
Unrecorded maintenance intervals represent a compliance gap; the SSO must verify actual equipment status and restore the documentation trail.
Question 6: Which tool is most appropriate for identifying systemic weaknesses across multiple security measures simultaneously?
- A single-question crew survey
- A structured security audit using a checklist aligned to the SSP (Correct answer)
- An informal walkthrough by the captain
- A review of media coverage about maritime security
Correct answer: A structured security audit using a checklist aligned to the SSP
A structured audit using the SSP as the reference baseline systematically identifies gaps across all security domains at once.
Question 7: How should the SSO handle a situation where corrective actions from a previous internal audit have not been closed out by the agreed deadline?
- Carry them forward indefinitely until resources permit
- Escalate to the CSO and update the risk register with the overdue status (Correct answer)
- Close the finding administratively to keep records clean
- Wait for the next external audit to address outstanding items
Correct answer: Escalate to the CSO and update the risk register with the overdue status
Overdue corrective actions increase risk and must be escalated to the CSO so company-level support can be applied and the risk register updated.
Under ISPS Code requirements, who is responsible for verifying that the Ship Security Plan is implemented effectively?