Allocate cyber risk responsibilities and tasks clearly across the company, including any outsourced to third parties, and map them to SMS job or role descriptions, naming who is responsible and who supports; aligning with the normal chain of command often works best, for example making the Master or Chief Engineer responsible for onboard compliance as is done for the ship security officer, with role-specific training. A responsibility matrix (managing director, company and ship IT managers, safety, procurement, fleet technical, training and marine HR managers) helps IT and OT owners coordinate.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.