BIMCO Cyber Security
BIMCO Ch10: Respond and Recover

BIMCO Cyber Security BIMCO-10.2: The four phases of incident response

Following NIST, preparation (roles, prioritised critical components and their location, regular backups, single points of failure with contingencies, a rehearsed response plan with shore and crew roles, communication and recovery steps); detection and analysis (collect and monitor logs from IT, OT and IoT for unauthorised access or use, breaches of change procedures and loss of critical systems, then triage how it happened, what is affected, what data are touched and what threat remains); containment and eradication (remove or quarantine the device, check boundary controls and firewall rules, close exposed remote management ports, update anti-malware, take full disk images under chain of custody and memory dumps before any restart, and advise on shutting down systems or shore links and using recovery tools); and post-incident recovery (clean and restore systems and data per 10.3, investigate root cause per 10.5, correct protection gaps, advise on rebuilds in layup or drydock, and run regular exercises).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C14 Control 14: Incident detection, response and recovery (UR E26 4.4.1 and 4.5.1)
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch10: Respond and Recover

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.