BIMCO Cyber Security
BIMCO Ch7: Develop Protection Measures

BIMCO Cyber Security BIMCO-7.3: Procedural protection measures

Procedural controls in company policy, SMS and security procedures govern how people use onboard systems, and security-sensitive plans stay confidential. They cover: training and awareness for onboard and shore staff beyond STCW familiarisation (email and phishing with simulations, internet and social media, public geolocation data, personal devices, infected media or software, safeguarding credentials, unsupervised technicians, spotting and reporting suspicious activity, consequences of incidents, preventive maintenance, service providers' media, remote maintenance on OT), recognising signs of compromise, cyber scenarios in drills with the Master and senior officers showing proficiency, and checking third parties' preparedness; restricting and supervising visitor computer access, with an isolated computer or direct-wireless printer and media blockers; rules for crew personal devices; evaluating unsupported hardware and software, timely updates of software and firmware and the BIMCO and CIRM software maintenance standard; keeping anti-malware current; remote access policy defining who, when, how and what, via secure approved means, coordinated with the Master, risk assessed with fallbacks, logged and periodically reviewed; administrator rights only for trained staff who need them, removed when people leave, no shared generic accounts; a password or passphrase policy with MFA as widely as practicable and no posted passwords; removable media policy with scanning on an isolated computer or before boarding and electronic transfer from trusted sources where possible; and destroying data before equipment disposal.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C7 Control 7: USB protection and use of portable devices (UR E26 4.2.7)
  • C8 Control 8: Training (UR E26 5.3)
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch7: Develop Protection Measures

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.