Prepare for SSA by training one habit: classify each situation by ISPS role (SSO, CSO, PFSO, master), security level (1, 2, or 3), and the awareness-level response (recognize, challenge verbally if safe, report, record, protect information). As a matter of the subject itself, the awareness-level response to an observation is to route it upward through the ship security structure rather than acting alone.
Awareness level versus Designated Security Duties: draw the line before you study
Security Awareness training under STCW covers recognizing threats, reporting concerns, and avoiding disclosure of security-related information. Designated Security Duties training adds active tasks such as monitoring restricted areas and operating screening. Keep the two syllabi separate in your notes.
The awareness-level syllabus is built on verbs like recognize, report, and know. It expects you to identify weapons, dangerous substances, stowaway indicators, and suspicious behavior; to understand why the Ship Security Plan exists; and to handle security information discreetly. It does not expect you to conduct searches, operate screening equipment, or perform monitoring duties assigned to specially trained crew.
This boundary is worth close attention when working through scenarios. An option describing a correct action in principle - say, screening baggage at the gangway - is the wrong choice for an awareness-level crew member because that task belongs to designated security duties or the Ship Security Officer. When you rehearse scenarios, first ask whose role the action is, then whether your own level permits it. Only the option passing both tests is the best answer.
The ISPS responsibility chain: SSP, SSO, CSO, PFSO, and the Declaration of Security
The ISPS Code distributes security responsibilities: the Ship Security Plan governs the vessel, the SSO runs shipboard security, the CSO covers the company, the PFSO covers the port facility, and the master retains overriding authority.
Learn each role as a functional anchor, not just a phrase. The SSP documents the ship's protective measures and who performs them. The SSO is your immediate reporting point for anything suspicious aboard. The CSO ensures company-level support and liaison. The PFSO manages security on the facility side, and a Declaration of Security records agreed responsibilities when ship and port facility, or ship and ship, coordinate their measures.
For an awareness-level crew member, this chain simplifies decision-making enormously: your default is to report observations to the SSO, or to the master if the SSO is unavailable or implicated. Options that have you calling port authorities first, confronting a person yourself, or improvising outside the plan are weaker choices precisely because they bypass the documented chain. Trace every scenario to its correct escalation point before comparing the remaining options.
Security levels 1 to 3: how protective measures escalate and what you will notice
ISPS defines three security levels: level 1 for normal operation, level 2 when a heightened threat requires additional protective measures, and level 3 when further specific measures respond to a probable or actual incident.
The levels describe gradations of the same framework, not different regimes. Moving from 1 to 2 typically tightens access control, expands restricted areas, intensifies searches, and raises communication readiness. Level 3 may involve measures such as further restricting access, preparing for possible evacuation or transfer of people, and responding to a specific incident, often coordinated with national authorities. Awareness-level crew experience escalation mainly through instructions issued by the SSO.
Study the levels as cause and effect: if a scenario states a credible threat near the port, ask which measures the ship would logically raise, then check which answer matches that state. Use the table below as a rehearsal template - cover the right-hand columns and reconstruct them from memory, then reverse the exercise by reading measures and naming the level.
| Security level | General meaning | Example direction of measures | Typical awareness-level crew experience |
|---|---|---|---|
| Level 1 | Normal operating conditions | Standard access control, ID checks, routine restricted-area discipline | Follow the SSP as briefed; report anything unusual to the SSO |
| Level 2 | Heightened threat; additional protective measures for a period | Extra checks at access points, additional watches, tightened restricted areas | Comply with new instructions, expect more screening, report observations promptly |
| Level 3 | Further measures for a specific probable or actual incident | Measures possibly beyond normal routine, often coordinated with authorities | Follow SSO or master instructions exactly; escalate information immediately |
Threat recognition: weapons, drugs, stowaways, and behavior patterns
Recognition in SSA means noticing categories of concern - weapons or dangerous substances, smuggling indicators, stowaway signs, and suspicious behavior - and converting observations into a factual report rather than an investigation.
Treat each category as a checklist of indicators. Dangerous substances include weapons, explosives, and chemical or biological agents, whether carried by people or hidden in stores and cargo. Smuggling awareness focuses on anomalies: altered spaces, unfamiliar packages, collusion attempts. Stowaway awareness covers access points, concealment spaces, and provisions that suggest someone intends to hide aboard. Suspicious behavior is judged by pattern - unusual questions about the ship, loitering near access points, attempts to bypass identification checks.
Practice recognition as description, not diagnosis. A strong observation states what you saw, where, when, and who was involved; it avoids guessing motives or treating people as suspects based on appearance. In written scenarios, the strongest answers preserve the person's dignity, keep a safe distance, and route the description to the SSO. This matters because premature confrontation can create danger and destroy the value of the observation for the investigation that follows.
Worked scenario: an unidentified person at the gangway at night
A person without identification claims to be a contractor and tries to board during a night watch. The awareness-level response is a safe verbal challenge, denying access, and immediate reporting - not physical intervention.
The tempting mistake is to grab the person, block the gangway physically, or search their bag. These exceed awareness-level scope: physical intervention creates risk to you and others, can escalate violence, and may compromise evidence. Distractor wording can make this mistake sound like decisiveness - a phrase such as 'stop him from getting away' reads as responsible, yet the underlying action belongs to trained security personnel operating under the plan.
The better decision has four moves. First, keep a safe distance and give a clear verbal challenge appropriate to the situation. Second, if the person cannot satisfy the access requirement, deny access without detaining them. Third, alert the watchkeeper and SSO immediately with a factual description - clothing, direction of movement, vehicle if any. Fourth, record the event and cooperate with the SSO's follow-up. The significance is structural: the security system works when observations flow up the chain quickly, and rehearsing this scenario trains your reflexes to route through it.
Worked scenario: a suspected narcotics package in the storeroom
A sealed package with no ship's markings is found wedged behind stores. Do not open, smell, or move it; restrict the area as far as your role allows, report immediately, and protect the information.
The plausible mistake is treating the package like lost property: picking it up to bring it to the office, opening a corner to check contents, or discussing it over the crew mess. Each action adds harm - unknown substances can be dangerous to touch or inhale, moving the package disturbs evidence, and casual disclosure leaks security information beyond those with a need to know. An option phrased as 'carry it carefully to the SSO' can look diligent because it shows initiative; the error is acting on the package at all.
The better decision is containment through the chain: leave the package untouched, note exactly where and when you found it and anything unusual nearby, prevent casual access to the storeroom within the limits of your role, and report to the SSO at once. Then follow the SSO's instructions and keep the matter confidential. Why it matters: the substance may be hazardous, the SSO may need to coordinate with the CSO or port authorities, and the integrity of the find depends on the first responder doing less, precisely and early.
Practical exercise, self-check rubric, and an adaptable preparation sequence
Run a paper security survey of a familiar vessel, rebuild your role-action-level grid from memory, and score yourself against a rubric; then follow a short sequence that cycles concepts, scenarios, and re-testing.
Exercise: using your own ship or a written vessel description, list every restricted area, every access point, the SSO's escalation route, and one awareness-level duty per security level. Then rewrite the survey as if the ship moved to level 2, noting which measures tighten. Expected observations: you should feel hesitation only on level-3 measures and on Designated Security Duties tasks; anything confusing at levels 1 and 2 marks a gap to restudy.
Self-check rubric - treat scores as learning milestones, not predictions of any outcome. Name the four ISPS roles and the SSP without notes (aim: complete). Assign eight written actions to awareness level versus designated duties (aim: 8 of 8). State the escalation steps for two suspicious-event scenarios (aim: verbal challenge where safe, deny access, report to SSO, record). Reconstruct level 1, 2, and 3 measures from the table template (aim: three correct measures per level).
Adaptable sequence: days 1-2, learn the ISPS structure and roles; day 3, build and memorize the security levels table; day 4, write your own three scenarios and solve them with the grid; day 5, take practice questions and log every miss against the grid dimension it violated; days 6-7, re-run the rubric and close gaps. Adjust the pace to your schedule, but keep the cycle of concept, scenario, and error analysis intact.
- Readiness check 1: you can explain, in one sentence each, what the SSP, SSO, CSO, PFSO, and a Declaration of Security do.
- Readiness check 2: given any exam-style scenario, you identify the correct reporting point before looking at the answer options.
- Readiness check 3: you can state three actions that are outside awareness-level scope and why they are assigned elsewhere.
- Readiness check 4: you can describe how your daily routine would visibly change between levels 1 and 2.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
