Threat Assessment & Risk Management Flashcards
7 cards from real SSO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Assessment & Risk Management flashcards as text
What does 'consequence' mean in the risk assessment formula used in maritime security?
Answer: The potential impact or harm resulting from a successful security breach
Consequence refers to the potential impact, harm, or damage that would result if a threat successfully exploited a vulnerability on the vessel.
Which body is responsible for approving a ship's Security Plan under the ISPS Code?
Answer: The flag state Administration or a Recognized Security Organization acting on its behalf
The flag state Administration, or a Recognized Security Organization (RSO) it authorizes, is responsible for reviewing and approving the Ship Security Plan.
When conducting a threat assessment, the SSO should consider which combination of factors?
Answer: The ship type, cargo, trading routes, and regional threat intelligence
A comprehensive threat assessment combines ship-specific factors such as type, cargo, and routes with available intelligence about threats in the regions the ship will transit.
What is a 'countermeasure' in the context of maritime security risk management?
Answer: A measure implemented to reduce the risk posed by identified threats and vulnerabilities
A countermeasure is any security action or procedure implemented to reduce or mitigate the risk presented by identified threats and vulnerabilities.
How frequently must a Ship Security Assessment be reviewed according to the ISPS Code?
Answer: Before significant operational changes or security incidents, and at regular intervals
The ISPS Code requires the SSA to be reviewed when there are significant changes to the ship's operations or following a security incident, as well as at regular intervals to remain current.
Which best describes the difference between Security Level 1 and Security Level 2?
Answer: Level 1 is the normal operating state; Level 2 is set when there is a heightened risk of a security incident
Security Level 1 represents normal operations with minimum appropriate protective security measures, while Level 2 is set when there is a heightened risk of a security incident.
Which information gathered during a Ship Security Assessment is treated as confidential?
Answer: Identified vulnerabilities and specific countermeasures in the Ship Security Plan
Vulnerabilities identified in the SSA and the countermeasures outlined in the Ship Security Plan are confidential to prevent adversaries from exploiting this knowledge.