Treat VSO preparation as an attribution exercise. For every paper scenario, state the responsible role, the governing document (assessment, plan, DoS, or record), and the level-appropriate action. Rehearse that three-part loop until it is automatic, then verify your reasoning against 46 CFR 11.337 and 33 CFR 104.215.
What 46 CFR 11.337 Actually Requires for the VSO Endorsement
The regulation sets three gates: satisfactory documentary evidence under 33 CFR 104.215, a physical examination under 46 CFR part 10 subpart C, and safety, suitability, and National Driver Registry requirements under 46 CFR 10.209(e).
Read 46 CFR 11.337 first, because it is short and gives you the endorsement's structure: applicants must show documentary evidence that satisfies 33 CFR 104.215, meet the physical examination requirements in part 10 subpart C, and satisfy the safety and suitability and National Driver Registry review requirements in 10.209(e) — unless those were met within the previous five years for another endorsement. Grouping the rule into these three buckets keeps your study of the credential itself focused.
Note what the section does not do: it does not restate a training curriculum, an exam format, or application fees. It points you to 33 CFR 104.215 for the evidence of training, so that section is the one to consult for what qualifies. Also avoid citation confusion — part 11 subpart E covers engineer officers and is unrelated to this endorsement. For administrative application details, go to the National Maritime Center rather than reconstructing them from memory; the eCFR page below is the citation to anchor your notes.
- Bucket 1: documentary evidence — defined by 33 CFR 104.215, not by 11.337 itself.
- Bucket 2: physical examination — 46 CFR part 10, subpart C.
- Bucket 3: safety/suitability and NDR review — 10.209(e), with a five-year lookback if recently met for another endorsement.
Whose Call Is It? Telling the VSO Apart from the CSO, FSO, and Master
The VSO implements and maintains security on the vessel; the CSO owns company-level plans and amendments; the FSO/PFSO owns the facility side. The master retains overriding authority. Attribution errors happen when these boundaries blur.
Under the ISPS/MTSA framework, the company security officer operates at the company level: developing and maintaining the ship security plan, coordinating with administrations, and handling amendments. The vessel (or ship) security officer is the shipboard counterpart — the ISPS term 'ship security officer' describes essentially the same shipboard function — responsible for implementing the plan, conducting drills, maintaining records, and acting as the shipboard security point of contact. The facility security officer mirrors that role ashore. The master's overriding authority sits above operational security decisions.
Worked scenario: during a night port call, a small unlit skiff lingers near the stern. A plausible mistake is for the VSO to draft a permanent change to the ship security plan on the spot and independently renegotiate restricted-area arrangements with the facility. The better sequence: record the event, apply the plan's measures appropriate to the current level, arrange a Declaration of Security if the interface arrangements need formalizing, and route any permanent plan change through the CSO. The distinction matters because the VSO's authority is to implement and document, not to redefine the approved plan alone.
| Role | Security domain | Typical decision scope | Example call in a paper scenario |
|---|---|---|---|
| Master | Overall vessel command | Overriding authority in security and safety decisions | Can override conflicting instructions when safety demands |
| VSO / Ship Security Officer | Onboard the vessel | Implements the plan, conducts drills and training, keeps records, liaises shipboard | Logs a suspicious approach and applies level-appropriate measures |
| CSO | Company level | Develops and maintains the ship security plan, handles amendments and company coordination | Approves a proposed plan amendment arising from a lesson learned |
| FSO / PFSO | Facility level | Facility plan implementation and ship-facility interface | Signs or receives a Declaration of Security for a port call |
What Actually Changes at Security Levels 1, 2, and 3
Security levels set a graduated response: level 1 is the normal baseline, level 2 adds focused protective measures for a period, and level 3 applies further exceptional measures during a specific incident or heightened threat.
Level 1 is the standing posture: normal access control, routine screening, standard communication and monitoring per the plan. Level 2 means the ship must apply additional, targeted protective measures — the plan defines which ones — for as long as that level holds. Level 3 means further special measures applied for a limited period during a security incident or in response to a specific heightened threat, often coordinated closely with authorities and possibly restricting normal ship operations. The plan, not improvisation, defines what each level means for a given ship.
A recurring decision trap is assuming a level change is a local shipboard choice. Under the ISPS framework, security levels are set by the responsible government authority, and the ship responds by applying its plan's provisions for that level. Two follow-on decisions follow directly from attribution: if the ship and the facility (or another ship) operate at different levels during an interface, that mismatch is a reason to consider a Declaration of Security; and any new measure the situation seems to demand should be checked against the plan's level-2 or level-3 provisions before it is invented on the spot.
- Level 1: baseline measures the plan requires at all times.
- Level 2: additional focused measures, temporary, defined by the plan.
- Level 3: further exceptional measures for a specific incident or threat, time-limited.
- Level is set by the responsible authority; the ship's job is to execute the matching plan provisions.
Keeping the Ship Security Assessment and the Plan Straight
The ship security assessment is the structured evaluation that identifies threats, vulnerabilities, and existing measures; the ship security plan is the approved response built on that assessment. They serve different purposes and change through different processes.
Think of the assessment as the analytical input and the plan as the operational output. An assessment examines the ship's operations, infrastructure, and likely threat scenarios, evaluates weaknesses, and identifies what measures already exist and what is missing. The plan then converts those findings into defined measures, assigned responsibilities, procedures for each security level, reporting arrangements, drill and training expectations, and interfaces with companies and facilities. Losing this separation turns every study question into guesswork about which document a decision belongs to.
Worked scenario: after a near-miss in which an unauthorized person briefly entered a restricted space, the VSO wants to immediately tighten that space's access procedures. The tempting mistake is to rewrite the relevant plan measures directly. The better decision: first extend the assessment — what changed in likelihood or consequence, which vulnerabilities were exposed, which existing measures failed or worked — then propose plan amendments through the company, because the CSO owns plan maintenance and the amendment follows the approval chain. This matters because an uncoordinated plan edit breaks the link between the approved measures and the analysis that justified them, leaving the plan incoherent during any later review.
- Assessment question: what are the threats, vulnerabilities, and current measures?
- Plan question: what do we do, who does it, and at which security level?
- New risk: assess first, amend the plan through the CSO second.
- Do not assume access to real plans — they are sensitive; train on generic framework examples.
When a Declaration of Security Applies and Who Handles It
A Declaration of Security formalizes agreed security arrangements between a ship and a facility (or another ship) during an interface, especially when levels differ, one party has non-standard arrangements, or risk is elevated.
A DoS answers a practical question: during this interface, whose procedures govern, what will each side do, and where do the two security regimes meet? Typical triggers include a mismatch between the ship's and the facility's security levels, the ship or facility operating with non-standard or limited measures, or shipboard activities carrying heightened risk. The ship side typically involves the master or the VSO, mirrored by the FSO or the other ship's security officer, and the completed agreement is recorded — a documented exchange, not a verbal understanding.
Paper mini-scenario: your ship sits at level 1, but the facility has been raised to level 2 for the call. The common slip is assuming one side's level silently covers the interface. The better handling: verify each side's current level, recognize the mismatch as a DoS trigger, agree on the interface arrangements, and ensure the DoS is completed and retained as a record. This matters because an undocumented interface is exactly the kind of gap the framework's recordkeeping is designed to close, and it is a decision you can practice entirely on paper.
- Mismatched levels between ship and facility: a DoS consideration.
- Non-standard or limited security arrangements: a DoS consideration.
- Shipboard activity with heightened risk: a DoS consideration.
- Output: a signed, recorded agreement — not an informal understanding.
Drills, Training, and Records You Should Be Able to Describe
Expect to reason about three documentation families: security training for shipboard personnel, security drills exercising plan elements, and records — including drill logs, DoS records, and threat or incident documentation — that the VSO maintains.
Frame your study around what each family demonstrates. Training shows personnel understand the plan, can recognize security threats, and know their assigned duties. Drills exercise specific plan elements — responding to a suspicious package, controlling restricted areas, managing an interface — and expose whether the procedures actually work. Records tie both together: training and drill documentation, completed DoS forms, records of security threats and incidents, and evidence of reviews. Being able to say which record evidences which activity is the documentation half of attribution practice.
A caution on sources: actual ship and facility security plans are sensitive documents, so your preparation should stay with the framework level — what the plan must contain, what drills must exercise, what records must exist — using generic examples and paper cases rather than any real plan content. A useful check while studying: for each documentation family, write one sentence naming its purpose and one naming who on board would typically hold or produce it. If you cannot fill either sentence from memory, that family needs another pass in your review cycle rather than another round of generic flashcards.
- Training evidence: personnel know plan duties and threat recognition.
- Drill evidence: specific plan elements were exercised and observed.
- Record set: drills, training, DoS forms, threat/incident logs, reviews.
- Study at framework level; real plans are sensitive and not your study source.
A Preparation Sequence and Paper-Drill Self-Check for VSO Study
Build study in layers: regulatory gates, role vocabulary, security levels, the assessment-to-plan chain, DoS triggers, then documentation — finishing with a paper attribution map you can complete without notes.
A workable sequence: first, read 46 CFR 11.337 and record the three requirement buckets in your own words, flagging 33 CFR 104.215 as the evidence reference. Second, build the role map — VSO, CSO, FSO/PFSO, master — using the table above until each boundary is instant. Third, memorize what changes across levels 1, 2, and 3 and who sets them. Fourth, trace the assessment-to-plan chain. Fifth, list DoS triggers and the signing/recording flow. Sixth, map the documentation families. Then convert everything into paper scenarios you write yourself from these patterns.
Self-check exercise (paper-based, no access to actual security plans): take three prompts you invent — a suspicious craft approach, an unauthorized restricted-area entry, and a ship/facility level mismatch — and for each produce an attribution map answering: whose decision, which document, what action at the current level, what gets recorded, and what escalates to the CSO. Rubric for your map: every role named without hesitation; level provisions cited, not improvised; DoS triggers identified unprompted; the amendment path through the CSO stated correctly; record types listed for each event. These are learning milestones for your review cycle, not predictions of any scoring outcome — treat an incomplete map as a signal to revisit that layer, and re-run the drill after a day or two spaced apart.
- Layer 1: 11.337's three gates; Layer 2: role boundaries; Layer 3: security levels.
- Layer 4: assessment → plan chain; Layer 5: DoS triggers and records; Layer 6: documentation families.
- Exercise: three self-written scenarios → attribution maps → rubric check → spaced re-run.
- Readiness check: rebuild the role table and the DoS trigger list from a blank page.
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
