BIMCO Cyber Security
BIMCO Ch1: Cyber Security and Risk Management

BIMCO Cyber Security BIMCO-1.3: Roles, responsibilities and tasks

Allocate cyber risk responsibilities and tasks clearly across the company, including any outsourced to third parties, and map them to SMS job or role descriptions, naming who is responsible and who supports; aligning with the normal chain of command often works best, for example making the Master or Chief Engineer responsible for onboard compliance as is done for the ship security officer, with role-specific training. A responsibility matrix (managing director, company and ship IT managers, safety, procurement, fleet technical, training and marine HR managers) helps IT and OT owners coordinate.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C11 Control 11: Responsible person(s) ashore (UR E26 4.5.1.3)
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch1: Cyber Security and Risk Management

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.