Where in-house capability is limited, third parties can assist, including active penetration testing of critical OT and IT to check actual against intended defence (simulating IT attacks, social engineering or physical intrusion), though for OT this may suit only drydock periods; where active testing of OT is too risky, use passive methods that analyse transmitted data without accessing or inserting software. Third parties can also provide asset discovery and inventory, network architecture review and design, and deeper vulnerability assessments including passive scanning; supervising officers and shore staff should coordinate these for safety and choose providers with fleet experience.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.