← Port Facility Security Officer (PFSO) Certification
Test yourself →

ISPS Code and UK Maritime Security Legislation

## The ISPS Code: International Maritime Security Framework

The International Ship and Port Facility Security (ISPS) Code is a comprehensive set of measures to enhance the security of ships and port facilities. Adopted by the International Maritime Organization (IMO) in December 2002, it came into force globally on July 1, 2004. Its primary purpose is to detect and deter security threats within the international maritime transport sector.

The ISPS Code is structured into two parts:

  • Part A: Contains the mandatory provisions that must be implemented by signatory states, ships, and port facilities.
  • Part B: Provides guidance and recommendations on how to implement the mandatory requirements of Part A.

Key elements of the ISPS Code include:

  • Security Levels: Three levels indicating the degree of risk: Level 1 (normal, minimum protective security measures), Level 2 (heightened risk, additional protective measures), and Level 3 (imminent or actual threat, specific protective measures for a limited period).
  • Port Facility Security Assessment (PFSA): A comprehensive risk analysis to identify threats, vulnerabilities, and potential consequences for a port facility.
  • Port Facility Security Plan (PFSP): A detailed document outlining the measures and procedures to be followed to ensure the security of the port facility, based on the PFSA.
  • Port Facility Security Officer (PFSO): The individual responsible for the development, implementation, revision, and maintenance of the PFSP, and for liaison with Ship Security Officers (SSOs) and Company Security Officers (CSOs).
  • Declaration of Security (DoS): An agreement between a ship and a port facility (or another ship) specifying the security measures each will implement during their interface.

## UK Maritime Security Legislation

In the United Kingdom, the ISPS Code's mandatory provisions are primarily implemented through The Ship and Port Facility (Security) Regulations 2004 (SI 2004/1495). These regulations transpose the international requirements into UK law, making compliance legally binding for relevant port facilities and ships operating in UK waters or interfacing with UK ports.

Other key UK legislation includes:

  • Aviation and Maritime Security Act 1990 (AMSA 1990): Provides the Department for Transport (DfT) with powers to issue Security Directions to port facilities and ships, ensuring compliance with security requirements and addressing specific threats.

The Department for Transport (DfT) acts as the Designated Authority (DA) for maritime security in the UK. DfT Maritime Security Inspectors are responsible for conducting audits, inspections, and enforcing compliance with the ISPS Code and national legislation. Non-compliance can lead to significant penalties, including fines and operational restrictions.

  • The ISPS Code came into force globally on July 1, 2004, to enhance maritime security.
  • The UK implements the ISPS Code primarily through The Ship and Port Facility (Security) Regulations 2004.
  • The **Department for Transport (DfT)** is the UK's Designated Authority for maritime security.
  • ISPS Code Part A contains mandatory provisions, while Part B provides guidance.
  • There are three **Security Levels**: 1 (normal), 2 (heightened), and 3 (imminent/actual threat).
  • A **Port Facility Security Assessment (PFSA)** identifies threats and vulnerabilities.
  • A **Port Facility Security Plan (PFSP)** details measures to counter identified risks at a port facility.
  • The **PFSO** is responsible for the implementation and maintenance of the PFSP.
  • A **Declaration of Security (DoS)** is an agreement on shared security measures between a ship and a port facility.
When did the ISPS Code come into force internationally?
July 1, 2004.
tap to reveal
Which UK Regulations primarily implement the ISPS Code?
The Ship and Port Facility (Security) Regulations 2004.
tap to reveal
What is the UK's Designated Authority (DA) for maritime security?
The Department for Transport (DfT).
tap to reveal
What are the three ISPS Code Security Levels?
Security Level 1 (normal), 2 (heightened), and 3 (imminent/actual threat).
tap to reveal
What is the purpose of a Port Facility Security Assessment (PFSA)?
To identify threats, vulnerabilities, and potential consequences for a port facility.
tap to reveal
What document details the security measures for a port facility?
The Port Facility Security Plan (PFSP).
tap to reveal
What is a Declaration of Security (DoS)?
An agreement between a ship and a port facility (or another ship) specifying security measures.
tap to reveal
What is the difference between ISPS Code Part A and Part B?
Part A contains mandatory provisions; Part B provides guidance and recommendations.
tap to reveal

Port Facility Security Assessment (PFSA)

## Port Facility Security Assessment (PFSA)

The Port Facility Security Assessment (PFSA) is a comprehensive and systematic analysis of a port facility's security vulnerabilities, threats, and potential consequences of a security incident. It is a mandatory requirement under ISPS Code Part A, Section 15, and serves as the foundational document for developing the Port Facility Security Plan (PFSP).

## Purpose and Responsibility

The primary purpose of the PFSA is to identify and evaluate the security risks to a port facility, its personnel, vessels, cargo, and operations. This includes assessing the likelihood of a security incident occurring and the potential impact if it does. The Port Facility Security Officer (PFSO) is ultimately responsible for ensuring the PFSA is conducted, reviewed, and updated. While the PFSO may lead the assessment, it can also be carried out by a Recognised Security Organisation (RSO) or other appropriately qualified personnel.

## Methodology and Key Elements

A thorough PFSA involves several key steps:

  • On-Scene Survey: A physical inspection of the port facility to identify existing security measures, physical layout, access points, critical assets, and potential weaknesses.
  • Review of Documentation: Examination of existing security plans, procedures, incident reports, facility blueprints, and relevant operational information.
  • Interviews: Discussions with facility personnel, management, security staff, and other stakeholders to gather insights into operations, security practices, and potential threats.
  • Threat Assessment: Identification of potential security threats (e.g., terrorism, piracy, smuggling, cyber-attacks, insider threats) and their likelihood.
  • Vulnerability Assessment: Analysis of weaknesses in physical security (fencing, lighting, CCTV, access control), personnel procedures, communication systems, and information technology that could be exploited by threats.
  • Consequence Analysis: Evaluation of the potential impact (e.g., loss of life, economic disruption, environmental damage) should a security incident occur.

The assessment considers all aspects of the facility, including physical security, structural integrity, personnel security procedures, cargo handling, vessel interfaces, communications, and emergency preparedness.

## Output and Confidentiality

The output of the PFSA is a detailed, confidential report. This report outlines the findings, identified threats, vulnerabilities, and provides recommendations for security measures and procedures to mitigate the identified risks. It directly informs the development and content of the Port Facility Security Plan (PFSP), which details how these recommendations will be implemented. The PFSA must be periodically reviewed and updated, especially after significant changes to the facility, operations, or the prevailing security threat environment.

  • The **Port Facility Security Assessment (PFSA)** identifies threats, vulnerabilities, and risks to a port facility.
  • It is a mandatory requirement under **ISPS Code Part A, Section 15**.
  • The **PFSO** is responsible for ensuring the PFSA is conducted and kept current.
  • A PFSA typically involves an **on-scene survey**, document review, interviews, and threat/vulnerability analysis.
  • It covers physical security, personnel, cargo, communications, and emergency preparedness.
  • The PFSA report is **confidential** and forms the foundation for the **Port Facility Security Plan (PFSP)**.
  • The PFSA must be reviewed and updated periodically or following significant changes to the facility or threat environment.
  • It can be conducted by the PFSO or a **Recognised Security Organisation (RSO)**.
What is the primary purpose of a Port Facility Security Assessment (PFSA)?
To identify vulnerabilities, threats, and risks to a port facility and its operations.
tap to reveal
Under which international code and section is the PFSA a mandatory requirement?
ISPS Code Part A, Section 15.
tap to reveal
Who is ultimately responsible for ensuring the PFSA is conducted and maintained?
The Port Facility Security Officer (PFSO).
tap to reveal
Name three key methodologies used when conducting a PFSA.
On-scene survey, review of existing documentation, interviews with personnel, threat assessment, vulnerability assessment, consequence analysis.
tap to reveal
What critical document is developed directly from the findings of the PFSA?
The Port Facility Security Plan (PFSP).
tap to reveal
What type of information is contained within a PFSA report, and what is its classification?
It details identified threats, vulnerabilities, and recommended countermeasures; it is a confidential document.
tap to reveal
When should a PFSA be reviewed or updated?
Periodically, or when there are significant changes to the facility, operations, or the prevailing security threat environment.
tap to reveal
Who, besides the PFSO, might conduct a PFSA?
A Recognised Security Organisation (RSO) or other appropriately qualified personnel.
tap to reveal

Port Facility Security Plan (PFSP) Development and Implementation

## Port Facility Security Plan (PFSP) Development and Implementation

The Port Facility Security Plan (PFSP) is a critical document mandated by the ISPS Code Part A and UK Maritime Security Regulations. Its primary purpose is to ensure the application of security measures designed to protect the port facility and ships using it from security threats and incidents.

## Development

The Port Facility Security Officer (PFSO) is responsible for the development, implementation, maintenance, and review of the PFSP. The plan's content is directly informed by the Port Facility Security Assessment (PFSA), which identifies potential threats, vulnerabilities, and consequences. The PFSP must address all elements identified in the PFSA, detailing specific measures for each of the three ISPS security levels.

Key components typically found in a PFSP include:

  • Security Organisation: Roles, responsibilities, and authorities of personnel.
  • Preventative Measures: Procedures for preventing unauthorised access to the port facility and restricted areas.
  • Cargo and Stores: Security measures for handling cargo, ship's stores, and unaccompanied baggage.
  • Monitoring: Details on surveillance equipment, lighting, and patrols.
  • Incident Response: Procedures for responding to security incidents, threats, and evacuation.
  • Liaison: Procedures for communicating with Ship Security Officers (SSOs) and Company Security Officers (CSOs), including the use of a Declaration of Security (DoS).
  • Training and Drills: Requirements for personnel training, drills, and exercises.
  • Reporting: Procedures for reporting security incidents.

Once developed, the PFSP must be submitted to and approved by the Department for Transport (DfT) in the UK.

## Implementation and Review

Effective implementation requires that all relevant personnel understand their roles and responsibilities within the plan. This is achieved through comprehensive training, regular drills, and exercises, which test the plan's effectiveness and personnel readiness.

The PFSP is a confidential document, and access must be strictly controlled to prevent misuse of sensitive security information.

The PFSP is not static; it requires continuous review and updating. This typically occurs:

  • At least every five years.
  • When significant changes occur to the port facility, its operations, or the security environment.
  • Following a security incident or a major exercise.
  • When new regulations or guidance are issued.

Any amendments to the PFSP must also be submitted to the DfT for approval. This ensures the plan remains relevant, effective, and compliant with current security requirements.

  • The PFSP is mandatory under ISPS Code Part A and UK regulations.
  • The PFSO is responsible for the PFSP's development, implementation, and review.
  • Its content is based directly on the Port Facility Security Assessment (PFSA).
  • All PFSPs for UK ports must be approved by the Department for Transport (DfT).
  • The PFSP details specific security measures for each of the three ISPS security levels.
  • It is a confidential document, with access strictly controlled.
  • PFSPs must be reviewed and updated at least every five years, or after significant changes.
  • Includes procedures for liaison with ships, often via a Declaration of Security (DoS).
What is the primary purpose of a Port Facility Security Plan (PFSP)?
To ensure the application of security measures designed to protect the port facility and ships using it.
tap to reveal
Who is responsible for the development and implementation of the PFSP?
The Port Facility Security Officer (PFSO).
tap to reveal
What document forms the basis for the PFSP's content?
The Port Facility Security Assessment (PFSA).
tap to reveal
Who must approve the PFSP in the UK?
The Department for Transport (DfT).
tap to reveal
How often should a PFSP generally be reviewed or updated?
At least every 5 years, or when significant changes occur (e.g., facility layout, threats, regulations, after incidents/exercises).
tap to reveal
What is the confidentiality status of a PFSP?
It is a confidential document, and access must be strictly controlled.
tap to reveal
Name three key elements that a PFSP must address.
(Any three from): Preventing unauthorised access, restricted areas, cargo handling, monitoring, incident response, DoS procedures, training, liaison with ships.
tap to reveal
What does the PFSP detail for each ISPS security level?
The specific security measures and procedures to be applied.
tap to reveal

Security Threats, Recognition, and Response

## Security Threats, Recognition, and Response

The Port Facility Security Officer (PFSO) is central to identifying and responding to security threats. Understanding potential risks is paramount to maintaining a secure port environment.

## Understanding Security Threats

Port facilities face a diverse range of security threats. These include:

  • Terrorism: Acts intended to cause serious harm or disruption.
  • Piracy: Acts of boarding or attempting to board a ship with intent to commit theft or other crime.
  • Smuggling: Illicit trafficking of drugs, weapons, or persons (migrants, human trafficking).
  • Stowaways: Persons secreted on a ship or in cargo without the consent of the shipowner or master.
  • Sabotage: Deliberate damage or destruction of port infrastructure, equipment, or vessels.
  • Cyber-attacks: Malicious attempts to disrupt, disable, or gain unauthorized access to IT systems.
  • Unauthorized Access: Individuals or vehicles gaining entry without permission.
  • Internal Threats: Malicious acts or negligence by port personnel.

## Threat Recognition & Indicators

Effective threat recognition relies on constant vigilance and awareness of unusual activities. Key indicators of potential threats include:

  • People: Individuals loitering, taking excessive photographs, avoiding security personnel, wearing inappropriate clothing, or attempting to gain access to restricted areas.
  • Vehicles: Unauthorised vehicles, unusual parking, suspicious modifications, or unattended vehicles in critical areas.
  • Packages/Items: Unattended bags, suspicious deliveries, or items with unusual wiring or markings.
  • Vessels: Unannounced arrivals, unusual manoeuvres, or small craft approaching restricted zones.

The Port Facility Security Assessment (PFSA) identifies vulnerabilities, while security equipment like CCTV, access control systems, and alarms aid in monitoring. Regular patrols and intelligence sharing with relevant authorities are also crucial.

## Response to Security Incidents

Upon recognising a potential threat or incident, the PFSO's immediate actions are critical:

1. Assess: Quickly evaluate the nature and severity of the threat.

2. Notify: Inform relevant internal personnel and external authorities (e.g., police, Coastguard, port authority, Company Security Officer (CSO), Ship Security Officer (SSO)).

3. Initiate PFSP: Activate appropriate procedures from the Port Facility Security Plan (PFSP). The PFSP details specific responses for different threats and ISPS Code Security Levels:

  • Level 1 (Normal): Routine, minimum protective security measures.
  • Level 2 (Heightened): Additional protective measures maintained for a period due to increased risk.
  • Level 3 (Exceptional): Specific protective measures for a limited time when a security incident is probable or imminent.

The PFSO coordinates the response, ensuring effective communication and liaison with all parties. Post-incident, the PFSO is responsible for reviewing the incident, updating the PFSP, and conducting investigations to prevent recurrence.

  • The ISPS Code defines three Security Levels: 1 (Normal), 2 (Heightened), and 3 (Exceptional).
  • The Port Facility Security Plan (PFSP) is the primary document guiding a PFSO's response to security incidents.
  • Common threats include terrorism, piracy, smuggling, stowaways, sabotage, and cyber-attacks.
  • PFSOs must liaise with the Ship Security Officer (SSO) and Company Security Officer (CSO) for ship-port interface security.
  • Vigilance for suspicious behaviour (people, vehicles, packages, vessels) is crucial for threat recognition.
  • A Port Facility Security Assessment (PFSA) identifies vulnerabilities within the port facility.
  • The PFSO's immediate response involves assessing, notifying, and initiating PFSP procedures.
What are the three ISPS Code Security Levels?
Level 1 (Normal), Level 2 (Heightened), Level 3 (Exceptional).
tap to reveal
What is the primary document guiding a PFSO's response to a security incident?
The Port Facility Security Plan (PFSP).
tap to reveal
Name three common security threats to a port facility.
Terrorism, piracy, smuggling, stowaways, sabotage, cyber-attacks, unauthorized access.
tap to reveal
What is a key indicator of suspicious behaviour related to individuals?
Loitering, unusual photography, avoiding security, attempting unauthorized access, wearing inappropriate clothing.
tap to reveal
Who must the PFSO liaise with regarding ship security?
The Ship Security Officer (SSO) and Company Security Officer (CSO).
tap to reveal
What is the PFSO's immediate action upon recognizing a potential threat?
Assess the situation, notify relevant authorities, and initiate PFSP procedures.
tap to reveal
What does PFSA stand for?
Port Facility Security Assessment.
tap to reveal

Security Equipment and Systems

## Security Equipment and Systems

Effective security equipment and systems are fundamental to implementing the Port Facility Security Plan (PFSP) and ensuring compliance with the ISPS Code and UK maritime security regulations. Their primary purpose is to deter, detect, delay, and facilitate a response to security threats.

## Access Control Systems

These systems regulate entry and exit to the port facility and its restricted areas.

  • Physical Barriers: Include perimeter fences, walls, gates, turnstiles, bollards, and vehicle barriers. They create a physical deterrent and define secure zones.
  • Personnel Identification & Verification: Involves Access Control Readers (e.g., card readers, biometric scanners for fingerprints or iris recognition) linked to databases. ID cards (e.g., Port Pass, company IDs) are crucial for visual and electronic verification.
  • Vehicle Control: Utilises barriers, Automatic Number Plate Recognition (ANPR) systems, under-vehicle surveillance systems (UVSS), and designated vehicle search areas.

## Surveillance and Intrusion Detection

These systems provide monitoring and alert capabilities.

  • Closed-Circuit Television (CCTV): A cornerstone of port security. Systems include fixed cameras for general overview, Pan-Tilt-Zoom (PTZ) cameras for detailed observation, and thermal cameras for low-light conditions. They must be linked to recording devices and monitored from a control room.
  • Intrusion Detection Systems (IDS): Designed to detect unauthorised entry. Examples include perimeter alarm systems (e.g., fence-mounted sensors, buried cable sensors), motion detectors (PIR, microwave), and door/window contacts.

## Screening and Detection Equipment

Used to identify prohibited items or substances.

  • X-ray Scanners: For inspecting baggage, parcels, and cargo containers.
  • Metal Detectors: Walk-through metal detectors (WTMD) for personnel and handheld metal detectors (HHMD) for secondary screening.
  • Explosive and Narcotics Trace Detectors: Devices that analyse samples for traces of illicit substances.
  • Radiation Detection Systems: To identify radioactive materials.

## Communication Systems

Essential for internal coordination and external liaison.

  • Internal Communications: Two-way radios, public address (PA) systems, intercoms, and internal telephone networks.
  • External Communications: Landline and mobile phones, satellite communications, and dedicated links to emergency services and relevant authorities.

## Lighting

Adequate and strategically placed lighting is critical. It enhances the effectiveness of CCTV, aids security personnel patrols, and acts as a significant deterrent to intruders, especially in vulnerable areas and at access points.

## Integration, Maintenance, and Testing

All security equipment should be integrated where possible to provide a comprehensive security picture and facilitate rapid response. Regular maintenance, calibration, and testing are paramount to ensure systems remain operational and effective. The PFSO is responsible for overseeing these aspects.

  • Security equipment helps deter, detect, delay, and respond to threats under the ISPS Code.
  • Access control systems regulate entry using physical barriers, ID verification, and vehicle checks.
  • CCTV, including fixed, PTZ, and thermal cameras, is crucial for surveillance and recording.
  • Intrusion Detection Systems (IDS) like perimeter alarms alert to unauthorised entry.
  • Screening equipment includes X-ray scanners, metal detectors, and trace detectors for prohibited items.
  • Effective communication systems are vital for internal coordination and external emergency liaison.
  • Adequate lighting enhances surveillance and acts as a significant deterrent.
  • Regular maintenance, calibration, and testing are essential for all security systems' effectiveness.
  • The PFSO is responsible for overseeing the operational readiness of security equipment.
What are the four primary functions of security equipment in a port facility?
To **deter**, **detect**, **delay**, and facilitate a **response** to security threats.
tap to reveal
Name three types of access control equipment used in port facilities.
Physical barriers (fences, gates), ID card readers/biometrics, vehicle barriers, ANPR (Automatic Number Plate Recognition).
tap to reveal
What does CCTV stand for, and what are its key components in a security system?
**Closed-Circuit Television**. Key components include cameras (fixed, PTZ, thermal), recording devices, and monitoring screens/control room.
tap to reveal
Give two examples of intrusion detection systems (IDS) for a port facility.
Perimeter alarm systems (e.g., fence sensors), motion detectors, door/window contacts.
tap to reveal
Why is adequate lighting crucial for port facility security?
It enhances CCTV effectiveness, aids security personnel patrols, and acts as a significant deterrent to intruders.
tap to reveal
Name two types of screening and detection equipment used for cargo or personnel.
X-ray scanners, metal detectors (WTMD/HHMD), explosive/narcotics trace detectors, radiation detection systems.
tap to reveal
What is the PFSO's key responsibility regarding security equipment?
Overseeing its regular maintenance, calibration, testing, and ensuring its operational readiness and effectiveness.
tap to reveal
Why is system integration important for security equipment?
It provides a comprehensive security picture, allows systems to work together, and facilitates a rapid and coordinated response to incidents.
tap to reveal

Drills, Exercises, and Emergency Preparedness

## Drills, Exercises, and Emergency Preparedness

Purpose and Importance

Drills and exercises are fundamental components of a robust port facility security regime. Their primary purpose is to test the effectiveness of the Port Facility Security Plan (PFSP), ensure that all personnel are proficient in their security duties, and identify any weaknesses or gaps in security procedures and equipment. They are crucial for maintaining a high level of security awareness and preparedness, ensuring the port facility can respond effectively to various security threats and incidents.

## Frequency Requirements (ISPS Code)

Compliance with the International Ship and Port Facility Security (ISPS) Code mandates specific frequencies for drills and exercises:

  • Drills: Port facility security drills must be conducted at least once every 3 months. These typically focus on specific elements of the PFSP, such as access control, search procedures, or communication protocols.
  • Exercises: Port facility security exercises must be conducted at least once every calendar year, but the interval between exercises must not exceed 18 months. Exercises are broader in scope, testing the full functionality of the PFSP and coordination with relevant authorities.

## Planning and Conduct

The Port Facility Security Officer (PFSO) is responsible for developing, maintaining, and testing the PFSP, which includes planning and overseeing drills and exercises. Key aspects include:

  • Scenario Development: Creating realistic and varied scenarios that challenge different aspects of the PFSP and personnel capabilities.
  • Stakeholder Involvement: Engaging relevant external agencies such as law enforcement, emergency services, port authorities, and shipping companies to ensure coordinated response capabilities.
  • Safety: Ensuring all drills and exercises are conducted safely, without posing undue risk to participants or port operations.

## Evaluation, Review, and Records

After every drill or exercise, a thorough debriefing session is essential. This process involves:

  • Lessons Learned: Identifying strengths, weaknesses, and areas for improvement.
  • Corrective Actions: Developing an action plan to address any deficiencies found.
  • PFSP Amendment: Updating the PFSP as necessary based on the outcomes and lessons learned.
  • Record Keeping: Detailed records of all drills and exercises, including dates, participants, scenarios, outcomes, and corrective actions, must be maintained for a minimum of 3 years. These records demonstrate compliance and provide a history of security readiness.

## Emergency Preparedness

Drills and exercises contribute significantly to overall emergency preparedness. They ensure that the port facility can integrate its security response with other emergency plans (e.g., fire, medical, environmental) and effectively coordinate with external emergency responders, enhancing the facility's resilience against a wide range of incidents.

  • Port facility security drills must occur at least once every 3 months.
  • Port facility security exercises must occur at least annually, not exceeding 18 months.
  • The PFSO is responsible for developing, maintaining, and testing the Port Facility Security Plan (PFSP).
  • Drills test specific elements of the PFSP, while exercises test the entire plan and coordination.
  • Records of all security drills and exercises must be kept for a minimum of 3 years.
  • A crucial step after any drill or exercise is a debriefing to identify lessons learned.
  • Findings from drills and exercises may necessitate amendments to the PFSP.
  • Effective emergency preparedness relies on integration with other emergency plans and external agencies.
What is the minimum frequency for port facility security drills?
At least once every 3 months.
tap to reveal
What is the maximum interval allowed between port facility security exercises?
Not exceeding 18 months.
tap to reveal
Who is primarily responsible for developing, maintaining, and testing the Port Facility Security Plan (PFSP)?
The Port Facility Security Officer (PFSO).
tap to reveal
For how long must records of security drills and exercises be maintained?
A minimum of 3 years.
tap to reveal
What is a key purpose of conducting drills and exercises?
To test the effectiveness of the PFSP and train personnel.
tap to reveal
What is a crucial step that must follow every security drill or exercise?
A debriefing session to identify lessons learned and areas for improvement.
tap to reveal
Name one type of exercise recognized under the ISPS Code.
Tabletop exercise (or seminar, workshop, full-scale exercise).
tap to reveal

Security Administration and Audits

## Security Administration & Audits Overview

Effective security administration is fundamental to maintaining a secure port facility. It encompasses the systematic management of security information, documentation, and processes to ensure continuous compliance with the ISPS Code and national regulations (e.g., UK's Ship and Port Facility (Security) Regulations 2004). Audits and reviews are critical tools for verifying the effectiveness and adherence to the Port Facility Security Plan (PFSP).

## Security Records Management

The Port Facility Security Officer (PFSO) is responsible for maintaining comprehensive and accurate security records. These records provide evidence of compliance, support incident investigations, and inform future security planning.

  • Types of Records: Include the Port Facility Security Assessment (PFSA), the PFSP itself, records of security training, drills and exercises, security incidents and breaches, Declarations of Security (DoS), and records of internal and external audits.
  • Retention: All security records must be retained for a minimum period of three years, or longer if specified by the Designated Authority (DfT).
  • Confidentiality: Records containing sensitive security information must be protected from unauthorised access, disclosure, modification, or destruction.

## Reporting & Incident Management

Prompt and accurate reporting of security incidents and breaches is crucial.

  • Incident Reporting: The PFSO must establish procedures for reporting security incidents to the Company Security Officer (CSO), Ship Security Officer (SSO) (if applicable), and the Designated Authority (DfT).
  • Communication: Clear communication channels must be maintained with relevant authorities and stakeholders to coordinate responses and share vital information during security events.

## Audits, Reviews & Amendments

Regular evaluation ensures the PFSP remains robust and relevant.

  • Internal Reviews: The PFSO must regularly review the PFSP, typically at least annually, to ensure its continued effectiveness and compliance. This review should consider changes in the port facility, threat assessments, and lessons learned from incidents, drills, and exercises.
  • External Audits (Inspections): The Department for Transport (DfT), as the Designated Authority in the UK, conducts regular inspections and audits of port facilities to verify compliance with the ISPS Code and national regulations.
  • PFSP Amendments: Any proposed amendments to the approved PFSP, whether due to changes in operations, security levels, or audit findings, must be submitted to and approved by the DfT before implementation.

## Compliance & Coordination

The PFSO acts as the primary point of contact for security matters, ensuring seamless coordination and compliance.

  • Stakeholder Coordination: Liaise with port authorities, law enforcement, emergency services, and other relevant bodies to integrate security measures and respond effectively to threats.
  • Continuous Improvement: Utilise audit findings, incident reports, and exercise outcomes to identify areas for improvement and update security procedures and the PFSP accordingly.
  • The PFSO is responsible for maintaining all port facility security records.
  • Security records must be retained for a minimum of three years.
  • The Port Facility Security Plan (PFSP) must be reviewed at least annually.
  • The Department for Transport (DfT) is the Designated Authority for maritime security in the UK.
  • Any amendment to the PFSP requires approval from the DfT.
  • Security audits verify compliance with the ISPS Code and the approved PFSP.
  • Declarations of Security (DoS) are key records for ship-port interface security.
  • Confidentiality of security records is paramount to prevent misuse.
What is the minimum retention period for security records required by the ISPS Code?
Three years.
tap to reveal
Who is the Designated Authority for maritime security in the UK?
The Department for Transport (DfT).
tap to reveal
How often must the Port Facility Security Plan (PFSP) be reviewed?
At least annually, and following significant changes, incidents, or audit findings.
tap to reveal
Who must approve any amendments to the Port Facility Security Plan (PFSP)?
The Designated Authority (DfT).
tap to reveal
What is the primary purpose of a security audit for a port facility?
To verify compliance with the ISPS Code, national regulations, and the approved PFSP, and to assess the plan's effectiveness.
tap to reveal
Name three types of security records a PFSO must maintain.
Port Facility Security Assessments (PFSA), PFSP, training records, drill/exercise records, incident reports, Declarations of Security (DoS), audit reports.
tap to reveal
What is a Declaration of Security (DoS)?
An agreement between a ship and a port facility (or between ships) specifying security measures to be taken during an interface.
tap to reveal
Why is confidentiality important for security records?
To prevent unauthorised access, disclosure, or misuse of sensitive security information that could compromise the port facility's security.
tap to reveal

Ship-Port Interface and Security Coordination

## Ship-Port Interface and Security Coordination

The ship-port interface is the critical point where a ship and a port facility interact, requiring robust security measures and seamless coordination to prevent security incidents. The ISPS Code (International Ship and Port Facility Security Code) provides the framework for this, with Part A being mandatory requirements and Part B offering guidance for both ships and port facilities.

## Key Roles and Communication

Effective coordination relies on clear communication between key personnel:

  • Port Facility Security Officer (PFSO): Responsible for the development, implementation, revision, and maintenance of the Port Facility Security Plan (PFSP) and liaison with ship security personnel.
  • Ship Security Officer (SSO): Responsible for the ship's security, implementing the Ship Security Plan (SSP), and liaising with the PFSO.
  • Company Security Officer (CSO): Responsible for the company's fleet security, ensuring SSPs are in place and effective.

Continuous and timely communication between the PFSO and SSO is paramount, especially regarding security levels, threats, and operational changes. This ensures mutual understanding and coordinated action.

## Declaration of Security (DoS)

The Declaration of Security (DoS) is a vital agreement between a ship and a port facility, or between two ships, specifying the security measures each will undertake during a specific period or operation.

  • Purpose: To ensure all security concerns are addressed and responsibilities are clearly defined, especially when there's a heightened risk.
  • When Required:
  • At a higher Security Level than the ship or port is currently operating at.
  • Following an actual security threat or incident.
  • When the ship or port facility has a specific reason to request it.
  • At Security Level 3, a DoS is always mandatory.
  • Agreement: The DoS is agreed upon and signed by the PFSO and the SSO, formalising their commitment to specific security actions.

## Security Levels and Procedures

Changes in Security Level (1, 2, or 3) directly impact the ship-port interface. The PFSO must inform the SSO of the port facility's current security level and any specific measures required.

  • Coordination: Procedures for access control, cargo handling, delivery of ship's stores, and embarkation/disembarkation of personnel must be coordinated to align with the prevailing security level and the respective security plans (PFSP and SSP).
  • Incident Response: Joint procedures for reporting and responding to security incidents that affect the interface are crucial. Regular drills and exercises involving both ship and port personnel are essential to test and refine these procedures and ensure preparedness.
  • The Declaration of Security (DoS) is agreed upon and signed by the PFSO and the SSO.
  • The ISPS Code Part A contains the mandatory security requirements for ships and port facilities.
  • A DoS is always mandatory when a port facility or ship is operating at Security Level 3.
  • Effective and timely communication between the PFSO and SSO is critical for ship-port interface security.
  • The Port Facility Security Plan (PFSP) details the port facility's security measures and procedures.
  • Security Levels (1, 2, 3) dictate the intensity of security measures required at the ship-port interface.
  • Joint drills and exercises are essential for testing and refining ship-port interface security procedures.
  • The PFSO is responsible for liaison with ship security officers and company security officers.
What is the primary purpose of ship-port interface security coordination?
To ensure robust security measures and seamless interaction between a ship and a port facility to prevent security incidents.
tap to reveal
Who are the two key individuals who agree and sign the Declaration of Security (DoS)?
The Port Facility Security Officer (PFSO) and the Ship Security Officer (SSO).
tap to reveal
Under what specific security level is a Declaration of Security (DoS) always mandatory?
Security Level 3.
tap to reveal
What document outlines the security measures and procedures for a port facility?
The Port Facility Security Plan (PFSP).
tap to reveal
Name three circumstances (other than Security Level 3) when a DoS might be required.
At a higher Security Level than the ship/port is operating at; following a security threat/incident; when the ship or port facility has a specific reason to request it.
tap to reveal
What is the role of the Ship Security Officer (SSO) in ship-port interface coordination?
To implement the Ship Security Plan (SSP) and liaise with the PFSO regarding security matters.
tap to reveal
How do changes in security levels (1, 2, 3) affect the ship-port interface?
They dictate the intensity and type of security measures and procedures required, demanding increased coordination between PFSO and SSO.
tap to reveal
Why are joint drills and exercises important for ship-port interface security?
To test, evaluate, and refine the effectiveness of security procedures and communication protocols between ship and port personnel.
tap to reveal