Establish and manage a baseline of normal activity for systems, applications, accounts and the network and expected data flows so alert thresholds can be set, collecting and normalising logs from onboard sources, with defined detection roles; consider a SIEM (often as a service) and an IDS or IPS in the network, communications solution or firewall (Annex 3). Relevant staff ashore or aboard should understand alerts and carry out agreed response and recovery, and detected incidents should go to a named person or provider responsible for acting.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.