Technical controls should be practical, cost-effective and kept current, drawing on the CIS Critical Security Controls. Covered are: limiting network ports, protocols and services to business need with managed routers; configuring firewalls, routers and switches to separate controlled networks (ship operation, supplier remote access, cargo and mandatory reporting) from uncontrolled ones (guest, crew internet, normally any wireless), partitioning into trusted zones with regular firewall review (Annex 3, IEC 62443, IACS Rec. 166); physical security of IT and OT areas, cable runs and USB ports as ISPS restricted areas; satellite and radio links (VPN or encryption, hidden terminal admin pages and port forwarding, no public routable ship IP, shore firewall routing, monitoring outbound tunnels, securing the last mile, protecting management interfaces and changing default passwords, MFA); wireless access limited to authorised devices with strong regularly changed keys, enterprise authentication, WIPS and NAC, and protected wiring; secure baseline configurations under change management and restricted user profiles; least privilege and limited admin accounts; email and browser protection (anti-phishing, encryption, SPF, DKIM, DMARC, hardened sandboxed browsers); and a patching plan, monthly for IT, with compatibility checks and compensating controls such as isolation or virtual patching where OT cannot be patched.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.