BIMCO Cyber Security
BIMCO Ch3: Identify Vulnerabilities

BIMCO Cyber Security BIMCO-3.3: Typical vulnerable systems

Vulnerability identification analyses applications, systems and procedures, with internal or maritime-aware external experts, to find weaknesses that could compromise confidentiality, integrity or availability, whether temporary exposures, design flaws, implementation errors or procedural and user errors. Stand-alone systems are less exposed than those on uncontrolled or internet-connected networks (Annex 3 covers segregation). Systems to review include cargo and loading management, bridge systems (ECDIS, GNSS, AIS, VDR, radar, even when updated only by removable media), propulsion, machinery and power control, access control, passenger servicing and management, passenger-facing public networks and administrative and crew welfare networks (both to be treated as uncontrolled and never linked to safety-critical systems), and communication systems including VSAT (consider encryption, do not rely solely on the provider, follow authorities' authentication rules). For each, ask whether it is stand-alone or connected, externally reachable, has built-in protection such as encryption, needs regular updates, accepts removable devices and is easy to reach physically.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch3: Identify Vulnerabilities

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.