The ISPS Code is the part of SOLAS that asks one question of every ship: can it keep unauthorised people, weapons and threats away from the crew, the cargo and the vessel itself? For the Ship Security Officer (SSO) it is a daily job, not a certificate on the wall. You run the Ship Security Plan (SSP) on board, control who comes up the gangway, keep restricted areas restricted, run the drills and keep the records an inspector will ask for. This guide explains the three security levels in plain English, what is inside an SSP, the access-control measures that matter at each level, the drill and exercise rhythm, and how your records show you are compliant. See digital security rounds for ship security officers in Marine Inspection to log gangway checks, drills and incidents from a tablet, with a timestamp on every entry.

ISPS at a Glance: The Numbers an SSO Works To
3
Security Levels
Normal, heightened and exceptional
3 months
Between Drills
At least one security drill in every three months
25%
Crew Change Trigger
Over 25% new crew means a drill within one week
5 years
ISSC Validity
With an intermediate verification between years 2 and 3
Free trial available. Or book a walkthrough built around your own vessels.
The Three Security Levels: What Changes at the Gangway
LEVEL 1
LEVEL 2
LEVEL 3
Normal
Minimum protective measures are always in place.
Control access to the ship
Only authorised persons enter restricted areas
Continuous gangway control and monitoring
Heightened
A higher risk of a security incident exists.
Close selected access points
Intensive checks at the points left open
More patrols and better lighting
Exceptional
An incident is probable or imminent.
Limit access to one controlled point
Admit only those responding to the threat
Possible suspension of cargo operations or evacuation
Security levels are set by governments, not by the ship. The measures shown are typical examples drawn from the Code's level descriptions. Your SSP defines the exact actions for your vessel.
The Gangway Control Path: Five Checks Before Anyone Boards
1
Verify identity
Check a valid ID against the person's stated reason for boarding.
2
Confirm the purpose
Match the visit to a notified delivery, service or authority visit.
3
Screen belongings
Search bags and items as the SSP requires, with more intensity at level 2 or 3.
4
Record the visit
Log name, company, time on and off, and who they are visiting.
5
Control movement
Issue a pass, escort where needed, and keep restricted areas locked.
The order of checks is our suggested working sequence. Identity verification and restricted-area control are SSP elements. Follow your approved plan where it differs.

Every gangway entry is evidence. Log security drills free and keep visitor, drill and incident records in one searchable place.

What Is Inside the Ship Security Plan: 13 Required Elements
Keep Threats Out
Weapons and unauthorised devicesRestricted areas and access controlVisitor identity checks
Respond
Response to security threatsEvacuation proceduresShip security alert system (SSAS)
People and Contacts
Duties of security staffSSO and CSO contact detailsShip and port facility coordination
Prove It
Training and drill schedulesIncident reportingSecurity auditingEquipment testing and maintenance
The flag Administration or a Recognized Security Organisation approves the SSP. The organisation that did the Ship Security Assessment must not approve the plan. Groupings are ours.
The SSO Calendar: What to Do and What to Record
CadenceRequirementRecord to keep
Every port callControl the gangway, check restricted areas and agree a Declaration of Security where requiredVisitor log, round sheets, Declaration of Security copy
At least every 3 monthsRun a security drillDrill report with date, scenario and participants
Within 1 week of a big crew changeDrill when more than 25% of ship personnel are newCrew change date and drill record
Each calendar yearExercise with the CSO and authorities, no more than 18 months apartExercise report, lessons learned
OngoingKeep security equipment workingTest and maintenance records
5-year ISSC cycleIntermediate verification between years 2 and 3, then renewalISSC, verification endorsements
Drill and exercise intervals are from ISPS Code Part B section 13. SSAS test frequency and Declaration of Security triggers vary by flag and port, so follow your SSP and flag rules.
Why Gangway Vigilance Matters: Where 2025 Piracy and Armed Robbery Incidents Occurred
137
incidents
East and Southeast Asia95
Gulf of Guinea21
Somalia5
Other regions16
Source: IMB Piracy and Armed Robbery Against Ships report for 2025. Of the 137 incidents, 121 were boardings and 4 were hijackings. Singapore Strait alone accounted for 80 of the incidents. "Other regions" is the remainder. Piracy is one threat inside the ISPS scope, so use this as context for vigilance, not as a full risk picture.
Make Security Records Inspection-Ready
Capture gangway logs, drills and security equipment checks with timestamps, so the evidence is ready when an inspector asks.
Free trial available. Or book a walkthrough built around your own vessels.
ISM Versus ISPS: Two Codes, Two Jobs

ISM Code
ISPS Code
Protects against
Accidents, pollution and unsafe practice
Unlawful acts, intruders and security threats
Key person ashore
Designated Person Ashore (DPA)
Company Security Officer (CSO)
Key person on board
The master
Ship Security Officer (SSO)
Core document
Safety Management System
Ship Security Plan (SSP)
Ship certificate
Safety Management Certificate (SMC)
International Ship Security Certificate (ISSC)
What are the three ISPS security levels?
Level 1 is normal, with minimum protective measures. Level 2 is heightened, when a higher risk of an incident exists. Level 3 is exceptional, when an incident is probable or imminent. Governments set the level and ships apply the matching SSP measures.
What does the Ship Security Officer do?
The SSO inspects the ship to ensure security measures are observed, supervises implementation of the SSP, reports security incidents and threats, and makes sure security equipment is maintained and works properly. The SSO also runs drills and keeps the records.
How often must security drills be held?
At least once every three months, and within one week if more than 25% of ship personnel have changed. Exercises with the CSO and authorities are held at least once each calendar year, with no more than 18 months between them.
Who approves the Ship Security Plan?
The flag Administration or a Recognized Security Organisation. Port state control checks that an approved plan exists, but its contents are confidential. See how Marine Inspection keeps security records audit-ready.
What do port state inspectors check on security?
Typically that an approved SSP exists, that a valid ISSC is on board, that crew security awareness training is complete and that Declaration of Security procedures work with the port facility. Records of drills and exercises support all of these.
Get Your SSP Records Audit-Ready
Give every SSO one simple place for rounds, drills, visitor logs and security findings, with the fleet view for your CSO.
Free trial available. Or book a walkthrough built around your own vessels.