BIMCO Cyber Security
BIMCO Ch7: Develop Protection Measures

BIMCO Cyber Security BIMCO-7.2: Technical protection measures

Technical controls should be practical, cost-effective and kept current, drawing on the CIS Critical Security Controls. Covered are: limiting network ports, protocols and services to business need with managed routers; configuring firewalls, routers and switches to separate controlled networks (ship operation, supplier remote access, cargo and mandatory reporting) from uncontrolled ones (guest, crew internet, normally any wireless), partitioning into trusted zones with regular firewall review (Annex 3, IEC 62443, IACS Rec. 166); physical security of IT and OT areas, cable runs and USB ports as ISPS restricted areas; satellite and radio links (VPN or encryption, hidden terminal admin pages and port forwarding, no public routable ship IP, shore firewall routing, monitoring outbound tunnels, securing the last mile, protecting management interfaces and changing default passwords, MFA); wireless access limited to authorised devices with strong regularly changed keys, enterprise authentication, WIPS and NAC, and protected wiring; secure baseline configurations under change management and restricted user profiles; least privilege and limited admin accounts; email and browser protection (anti-phishing, encryption, SPF, DKIM, DMARC, hardened sandboxed browsers); and a patching plan, monthly for IT, with compatibility checks and compensating controls such as isolation or virtual patching where OT cannot be patched.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C2 Control 2: Network protection (UR E26 4.2.1 and 4.2.2)
  • C4 Control 4: Access control (UR E26 4.2.4)
  • C5 Control 5: Wireless communication (UR E26 4.2.5)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch7: Develop Protection Measures

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.