The framework: plans, officers and certificates
Part A of the Code is mandatory. Part B is guidance, and many administrations treat parts of it as effectively mandatory. Every ship in scope carries an approved Ship Security Plan, restricted material developed from a formal Ship Security Assessment, and appoints a Ship Security Officer on board and a Company Security Officer ashore. Port facilities mirror the structure with their own assessments, plans and officers. Compliance is certificated through the International Ship Security Certificate, issued for a period not exceeding five years, with at least one intermediate verification between the second and third anniversary date. Separately, under SOLAS Regulation XI-1/5, every ship in scope maintains a Continuous Synopsis Record. This is an on-board history of the ship's flag, name, registered owner, bareboat charterer, ISM company, classification society and certificate issuers, kept in an unbroken sequence so that a vessel's identity is traceable. It sits in Chapter XI-1 rather than in the ISPS Code, but it came out of the same 2002 conference and it is checked in the same breath.
Security levels and the Declaration of Security
The Code operates on three security levels. Level 1 is normal protective measures. Level 2 is heightened measures for elevated risk. Level 3 is exceptional measures for a probable or imminent security incident. Administrations set the level for their ships and ports, and the Ship Security Plan prescribes what changes at each step: more access control, more monitoring, restricted operations. Where a ship and a port facility, or two ships, operate at different security levels, or where specific concerns exist, a Declaration of Security records who is responsible for which security measures during the interface. Knowing when a Declaration of Security is required, and keeping the completed ones on file, is a routine verification item.
The measures inspectors actually test
In practice, security verification is concrete. Is gangway access genuinely controlled, with identification checked and visitors logged? Are restricted areas marked and locked? Are stores and provisions checked before acceptance? Do the records show security drills at the required frequency, with scenarios that go beyond the tick box? Can the Ship Security Officer explain the ship's procedures at each security level without reading them off the page? The Code's guidance sets drills at least once every three months, with an additional drill within one week where more than 25 per cent of the ship's personnel are replaced at one time by personnel who have not previously participated in any drill on that ship within the last three months. Exercises are expected at least once each calendar year, with no more than 18 months between them. The Ship Security Alert System, required by SOLAS Regulation XI-2/6, is the covert alarm that signals a security threat ashore without alerting anyone on board. It must work and it must be tested in line with the plan. Under Regulation XI-2/9 port States have control powers too. A ship without a valid ISSC, or where there are clear grounds of noncompliance, can face inspection, delay, restriction of operations or expulsion from port.
Security as a living posture
The regions of concern move. Piracy high-risk areas, conflict zones, stowaway hotspots and sanctions exposure all shift, and industry guidance moves with them, so a static Ship Security Plan ages quickly. Good operators run the security cycle the way they run the safety one: reassess routes and threats, update measures, brief crews before each voyage phase, and capture lessons from incidents and near misses. The Code provides the skeleton. Current threat intelligence and honest drills give it muscle.