Procedural controls in company policy, SMS and security procedures govern how people use onboard systems, and security-sensitive plans stay confidential. They cover: training and awareness for onboard and shore staff beyond STCW familiarisation (email and phishing with simulations, internet and social media, public geolocation data, personal devices, infected media or software, safeguarding credentials, unsupervised technicians, spotting and reporting suspicious activity, consequences of incidents, preventive maintenance, service providers' media, remote maintenance on OT), recognising signs of compromise, cyber scenarios in drills with the Master and senior officers showing proficiency, and checking third parties' preparedness; restricting and supervising visitor computer access, with an isolated computer or direct-wireless printer and media blockers; rules for crew personal devices; evaluating unsupported hardware and software, timely updates of software and firmware and the BIMCO and CIRM software maintenance standard; keeping anti-malware current; remote access policy defining who, when, how and what, via secure approved means, coordinated with the Master, risk assessed with fallbacks, logged and periodically reviewed; administrator rights only for trained staff who need them, removed when people leave, no shared generic accounts; a password or passphrase policy with MFA as widely as practicable and no posted passwords; removable media policy with scanning on an isolated computer or before boarding and electronic transfer from trusted sources where possible; and destroying data before equipment disposal.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.