BIMCO Cyber Security
BIMCO Ch8: Develop Detection Measures

BIMCO Cyber Security BIMCO-8.1: Detection, logging, blocking and alerts

Establish and manage a baseline of normal activity for systems, applications, accounts and the network and expected data flows so alert thresholds can be set, collecting and normalising logs from onboard sources, with defined detection roles; consider a SIEM (often as a service) and an IDS or IPS in the network, communications solution or firewall (Annex 3). Relevant staff ashore or aboard should understand alerts and carry out agreed response and recovery, and detected incidents should go to a named person or provider responsible for acting.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • C10 Control 10: Network operation monitoring (UR E26 4.3.1)
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in BIMCO Ch8: Develop Detection Measures

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.