BIMCO Cyber Security
BIMCO Ch3: Identify Vulnerabilities

BIMCO Cyber Security BIMCO-3.7: System and software maintenance

Where IT and OT maintenance is outsourced, the company may not be able to verify providers' security, and where different providers handle software and security checks, suppliers should be asked for details of updates. An example of navigation computers crashing during pilotage on outdated, unsupported operating systems shows how simple servicing prevents mishaps.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C9 Control 9: Systems updates and maintenance (UR E26 4.1.1.4.4)
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch3: Identify Vulnerabilities

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.