Performance Monitoring & QA Flashcards
7 cards from real SSO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Performance Monitoring & QA flashcards as text
What is the correct frequency for reviewing the Declaration of Security (DoS) process as part of QA activities?
Answer: After each interface with a port facility and periodically as part of internal audit cycles
DoS effectiveness should be reviewed after each port interface and as part of routine internal audits to ensure the process remains fit for purpose.
A performance monitoring report shows that 30% of security incidents are not being reported within the timeframe specified in the SSP. The best corrective action is:
Answer: Conduct targeted retraining on incident reporting procedures and monitor compliance for 30 days
Retraining followed by a monitored compliance period directly addresses the root cause while maintaining the required standard.
Which of the following best describes a 'nonconformity' in the context of ship security QA?
Answer: A failure to fulfill a requirement specified in the SSP, ISPS Code, or related regulation
A nonconformity is formally defined as any departure from an applicable requirement in the SSP or governing regulations.
How does the SSO use trend analysis in performance monitoring?
Answer: To identify recurring issues that suggest systemic failures requiring structural corrective action
Trend analysis reveals patterns that indicate systemic rather than isolated problems, prompting structural rather than one-off corrective measures.
During a quarterly QA review, the SSO notes that restricted area signage in the cargo hold has faded to the point of being illegible. This is classified as:
Answer: A security deficiency that must be documented and corrected before the next cargo operation
Illegible restricted area signage is a security deficiency that compromises access control and must be formally documented and corrected.
What information should the SSO capture in a post-incident QA review to prevent recurrence?
Answer: Immediate cause, root cause, contributing factors, and corrective actions taken
A complete post-incident QA review captures immediate and root causes along with contributing factors and corrective actions to prevent recurrence.
The ISPS Code requires that records of security activities be kept for a minimum of how long?
Answer: 3 years
The ISPS Code requires security records to be retained for a minimum of 3 years to support audits, investigations, and port state control inspections.