Under IMO resolution MSC.428(98) the SMS should address cyber risk in line with the ISM Code, and MSC 101 agreed that cyber aspects, physical security included, belong in the Ship Security Plan under the ISPS Code without a separate parallel management system. A simple arrangement puts procedures on physical access to IT and OT areas and a durable reference to the SMS cyber procedures in the SSP (worded so SMS changes do not force re-approval), and the rest in the SMS without sensitive system documentation. Reporting, communication and decision authority procedures should cover cyber incidents, the Master needs a defined resource to call on, and the SMS needs a cyber contingency response plan (chapter 9, Annex 2). Ship-specific assessments and procedures should be considered where configurations differ, and the risk assessment and system documentation should be stored and controlled like the Ship Security Assessment and SSP.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.