The Document of Compliance holder is ultimately responsible for managing onboard cyber risk. Where a third party manages the ship, owner and manager should agree in writing, and sign, how responsibilities are split, what is expected, what instructions the manager gets, whether it joins purchasing decisions and what the budget is, taking account of laws beyond the ISM Code such as the GDPR or coastal state cyber rules.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.