Assessments cover existing, new and second-hand ships (the last deserving extra attention) and are likely to need third-party help. Phase 1, pre-assessment: review the 3.2 documentation and potential impacts, identify key makers of critical equipment on a risk basis, set up cyber contacts with them, review maintenance and support records and establish contractual obligations for network and equipment support. Phase 2, ship assessment: assess system by system from functionality, data flows and every cable or wireless connection, with staff, makers and experts; do not confuse it with crew operational risk assessments; mitigate any risk above acceptance criteria to an acceptable residual level, holistically and cost-effectively; review configurations of computers, servers, routers and firewalls against company standards; involve the ship's senior officers (Master, Chief Officer, Chief Engineer); and judge mitigation effectiveness within change management. Phase 3, debrief and reporting: keep the assessment a coherent, current document meeting the ISM Code, reached iteratively; an external assessor's interim report (executive summary, technical findings, prioritised actions not tied to its own products, supplementary data, appendices) is finalised after decisions. Phase 4, manufacturer's debrief: send relevant findings to makers, with experts working through their cyber contacts, so remediation is complete.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.