Common weaknesses on existing ships (newbuilds fall under IACS UR E26 and E27) include obsolete and unsupported operating systems, unpatched software, missing or outdated anti-malware, weak security configuration (poor network management, unscreened removable media, default admin accounts and passwords, sometimes on display), weak or shared passwords without MFA, flat networks without boundary protection, safety-critical systems permanently connected ashore, poor third-party access control, untrained staff, missing or untested contingency and response plans, incomplete decommissioning, personal use of business networks and computers that never lock.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.