Custom software for the ISPS security plan
Every ISPS-regulated port facility has an approved security plan. What is rarely in place is evidence that the measures in that plan were carried out at the moments that mattered. And the moment that matters most is the change to a higher security level: within a short time, measures have to take effect that nobody has practised this month.
Why the change of level is the pivot point
The ISPS Code has applied to ships and port facilities since 2004. In the Netherlands, implementation is set out in the Port Security Act, with the measures prescribed by European Regulation 725/2004. Each facility requires a security assessment, an approved security plan, a designated port facility security officer, and operation at one of three security levels.
The plan describes access control, restricted zones, staff screening, cargo handling and exercises. The port facility security officer oversees this through their own inspections, organises exercises and training, and sends the report of the annual full-scale exercise to Bureau Port Security. Reports of all exercises must be made available to the supervisory authorities on request.
What a plan does not solve is execution under time pressure. Raising the level to two brings different measures: more checks, different access rules, additional monitoring of restricted zones. These are written into the plan and must then actually take effect within a short time. Someone who, at that moment, goes looking through a folder to find which measures apply and who carries them out is too late, and someone who cannot afterwards show that they were carried out has a problem with the regulator.
This page is about managing the plan. Recording at the quay itself, at the gate and during patrols is described in the app for access and patrols at a port facility.
How we build this
Here the measure is the unit, not the plan. If every measure is tied to a level and to an executor, a change of level becomes a button rather than a meeting.
We turn the approved plan into individual measures, each with an owner, a level and a checkpoint. The plan itself remains leading and does not change.
What happens when the level goes up, who is notified and who must confirm. This is the part where most facilities rely on experience rather than set-up.
Access controls, inspection rounds and exercises are recorded at the moment itself rather than gathered afterwards. Evidence that depends on manual work is missing precisely when it is needed.
We simulate an escalation and measure how long it takes for every measure to be confirmed. That time is your real capacity to respond.
What the software actually does
The register of measures per level holds everything together. Which components you need depends on the size of your facility and how many parties come onto the site.
Measures per security level
For each measure, which level activates it, who carries it out and how it is confirmed. A plan on paper cannot answer that question at the moment the level goes up.
Level change with confirmation
When the level rises, the notification goes out to those involved and each measure is confirmed as active. Afterwards it is recorded when the level changed and how quickly everything was in place.
Access, screening and restricted zones
Who may enter where, on what grounds and until when. Screening validity and access rights expire, and discovering an expired authorisation during an inspection is the worst possible moment.
Exercises and training on record
When an exercise took place, who took part, what went wrong and what was done about it, including the annual full-scale exercise and the report that follows from it.
Incidents and deviations with follow-up
An open gate, a visitor without an escort, a check that was skipped. Each of these becomes an action with an owner and a deadline, rather than a note in a waiting logbook.
Evidence for oversight in one place
Exercise reports, completed checks and level history in a single overview, ready to be made available for inspection. During an inspection, how quickly you can produce it is itself a signal.
Who we build for
What happens on your site determines the focus. Four situations.
Terminals and loading and unloading
High traffic, many external drivers and rotating shifts. Access control is here both the largest volume and the most frequently circumvented part of the plan.
Industry with its own quay
You see yourself as a producer and carry a security obligation with it. The organisation is not set up for a security officer, yet the requirements are the same as for a terminal.
Port operators with multiple facilities
Each facility has its own plan and its own security officer, but the level often changes for the whole area. You want to steer per facility and report on the whole.
Contractors and maintenance on site
Work on installations brings in people who should not be there without an escort. That is exactly the point where access control is stretched in practice. If your site also falls under the Wwke, a second accountability runs alongside this one.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
The security plan has been approved and does not change lightly. Everything relating to execution should therefore be adjustable without the plan itself changing, and stored per version.
Why Appfront
The level change is the real work
We build it as an action with confirmation per measure, so that afterwards it is clear how quickly everything was in place and who did what.
Supervision asks for evidence, not a plan
Exercise reports must be made available for inspection on request. We bring that evidence together rather than gathering it each time.
Authorisations expire silently
Screening and access rights have end dates that nobody keeps track of. We monitor them and flag them in advance rather than during an inspection.
Connecting to your access system
Gates, passes and cameras already exist. We connect to them via integrations rather than building a second access administration.
Security and privacy
For this subject, the content of the system itself is the risk. An overview of your restricted zones, your measures per level and your open gaps is exactly the document someone with bad intentions would be looking for. We therefore keep access tightly controlled by role and by facility, show no more than a function requires, and log every view. Administrators do not automatically see everything either.
There is also a personal data dimension that weighs more heavily than in a typical access app. Staff screening touches on privacy, and with visitor registration you record data of people who do not work for you. We keep only the minimum there: the outcome and the validity date rather than the investigation itself, and visitor data with an explicit retention period rather than indefinitely. What the registration provides as evidence, however, must be tamper-proof. How we handle security internally is set out in our information security policy; reports from outside go through our vulnerability disclosure policy.
Frequently asked questions about ISPS and port security
For each port facility, a security assessment, an approved security plan, a designated port facility security officer and operation at one of three security levels. The plan covers, among other things, access control, restricted areas, staff screening, cargo handling and exercises. In the Netherlands implementation runs through the Port Security Act, alongside the measures from the European regulation.
No, and it cannot. The plan is approved and remains authoritative. What we build is its implementation: linking measures to levels, having changes confirmed, and recording exercises and checks. If the plan changes, the set-up changes with it, not the other way round.
Additional measures from your plan then apply and must be actively in place within a short time. In practice, things go wrong not because people do not know what needs to happen, but because nobody has an overview of what is already in place and what is not. That is why we build confirmation per measure rather than a notification to the group.
The report on the annual full-scale exercise goes to the Bureau Port Security. Reports on all exercises must also be made available to the supervisory authorities on request. This means that smaller exercises too must be easy to find, and it is precisely those that usually disappear into an inbox today.
If your facility is subject to ISPS, the same requirements apply as for a terminal, regardless of how you see yourself. For industrial companies this is often the unwelcome discovery: it comes with a designated officer, a plan and an exercise rhythm. Whether your quay falls under it is determined by the competent authority, not by your size.
Usually yes, and that is the biggest gain because access control has the highest volume. We connect to your existing access system via integrations, so rights are managed in one place. What we add is the reason behind a right: which zone, based on which screening, and until when.
Terminal operations concerns cargo flows, planning and handling; see port software and maritime software. ISPS concerns the security of the facility and demonstrable compliance towards the supervisory authority. They share the site and little else.
That depends on the number of facilities, whether access and visitor logging must be included, and whether integration with existing systems is needed. The measures register with level switching is usually quick to put to use and gives immediate oversight; integrations cost more. We provide a reasoned estimate after the discovery phase.
Handling level changes and exercises demonstrably?
Ask how long it takes for all level two measures to be confirmed as active, and check where that answer comes from. That is the question that comes up in an audit. We build this as a standalone application and as part of a broader custom software project.