After delivery the owner runs the technical and organisational countermeasures: modifies CBSs under E22 management of change with documentation kept current; keeps the test procedure aligned with CBSs, networks, emerging risks, threats and vulnerabilities; provides procedures, periodic training and drills; maintains hardware and software; and keeps test results and the current procedure aboard for the Society. Before the first annual survey it submits a ship cyber security and resilience programme (policies, procedures and plans for the processes in section 4) for approval and then shows records of implementation; later annual surveys check implementation on request; a change of management company needs re-verification; and special survey includes witnessed testing to the test procedure.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.