IT manages data and business functions; OT directly monitors or controls physical equipment and must work independently of IT, though it may connect for monitoring or remote support, in which case the interface needs at least a firewall so OT weaknesses are not exposed, since OT patching is often not feasible. OT failure can endanger crew, cargo and environment, and some IT failures can too (for example lacking the dangerous goods manifest during a container fire). Because OT is bought and updated differently (by makers, under management of change, compatibility checks and class approval), someone with cyber knowledge should take part in OT procurement, and the person responsible for onboard cyber security benefits from an OT inventory.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.