Protect CBSs in scope from unauthorised access and other threats from untrusted networks: supply a user manual for controlling remote access with defined roles and permissions; expose no in-scope IP address to untrusted networks; use secure connections such as tunnels with endpoint authentication, integrity protection and encryption at the transport or network layer, and confidentiality for read-restricted information. CBSs must let the onboard end terminate a connection and refuse remote access until a responsible person aboard accepts it, handle interruptions without harming OT safety or data, and log all remote access for later review. Remote maintenance also needs documentation of the shore connection, patches tested and confirmed by the supplier before installation, supplier plans and availability of security updates (E27 5.2 to 5.4), the ability for authorised staff to halt the work at any time and return to an earlier safe configuration, MFA for human users from untrusted networks, lockout after a set number of failed attempts, and automatic logout if the link drops.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.