Cyber security protects IT, OT, information and data against unauthorised access, manipulation and disruption, and incidents may come from targeted attacks, attacks on others that spill over, or plain error (for example chart data corrupted by a poisoned download, an infected USB used in maintenance, phishing, or spoofed GNSS). Shipping-specific weak points (many stakeholders blurring accountability, crew rotation, unsupported legacy systems, OT that cannot be patched because of type approval, online links with shore parties and remote access by makers, shared commercial data, multi-vendor automation integrated by yards with little cyber regard, poor decommissioning) should be weighed and written into company policy and the SMS. Cyber risk management should be part of the safety and security culture at every level, fitted to the company's risk profile and flag rules, and should identify roles of users, key staff, third parties and management; identify systems, assets, data and capabilities whose disruption endangers the ship; put in place protection, detection, impact limitation and continuity measures; meet regulation; report and investigate incidents under the SMS; and exercise contingency and response plans. Sensitive material such as the risk assessment, inventories and network maps should be protected and kept out of the SMS where possible, and assessment repeated regularly.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.