Answer
A – MSC. 428(98), EIF- 1 Jan 2021
MSC-FAL 1/ Circ.3/ Rev 2 – Guidelines on Maritime Cyber Risk management
5 Principles/IMO Guidelns , Functional elements –
Identify – Define personnel roles & responsibilities for cyber risk mngmnt& identify the systems, assets, data & capabilities that when disrupted, pose risk to ship operation
Protect – Implement risk control Processes & measures, & contingency planing to protect against a cyber event & ensure continuity of shopping operation
Detect – Develop & implement activities necessary to detect a cyber event in a timely mnnr
Respond – Dvlp & implmnt actvties & plans to provide resilience & to restore necessary for shppng operations or services impaired due to cyber evnt
Recover – Identify measures to backu & restore cyber systems necessary for shipping oprtns impacted by a cyber evnt.
4 principles/ ICS guidelines –
Identify the roles & respnsbilities of users, key personnel and mangment both ashore & on board.
Identify the systems, assets, data & capabilities that if disrupted could pose risk to ships operation &safety
Implement techncl & procedural measures to protect angst a cyber incdnt, timely detect of Incidents & ensure continuity of operations
A contingency plan which is regularly excercised.
Cyber risk management means the process of Identifying, Analyzing, Assessing and Communicating [IAAC] a Cyber related risk and accepting, avoiding, transferring or mitigating it to an acceptable level [AATMA].