MEOClassOneAll oral topicsWritten study desk

MEO CLASS 1 · ORAL QUESTION 70

Q50- Implement Cyber security as CE. How will you implement Cyber security on a ship as per ISM?

Answer

A – Cyber Risk Management should be included in SMS as per MSC 428(98).

Any contingency Plan must include 6 modules from IMO guidelines for contingency planning as stated in A.1072(28) Cyber Security Plan must form part in the Ship’s SMS. (Identify- Detect- Protect- Respond- Recover)
1.There must be a Cyber Security Policy.

2.Appointment of Cyber Security Officer.

3.Identification of equipment/ systems prone to Cyber-attacks.

4.Contingency Plans for unaffected normal operation of ship under Cyber-attack.

5.Risk Control measures- Firewall, Antivirus etc.

6.Early detection with continuous monitoring by designated officer.

7.Training of ship-staff – discussion of cyber case studies and Do’s/ Don’ts, Hardware blockers like USB blockers, outside people shouldn’t be allowed to connect their devices, Blockers for web-surfing on ship’s systems. 8.Access levels to be defined for crew/ junior officers/ top management.

9.Separate computer for crew’s day to day purposes.

10.Vigilant eye to be kept ship’s essential equipment like Electronic Engines, Ecdis, Loadicator etc.

11.Passwords to be kept secure with Cyber security officer.

12.Shore assistance measures to respond / recover a cyber-attack situation.

13.Procedures to report cyber-attacks for timely recovery.