IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems
UR E26 sections 5 and 6: demonstration of compliance and exclusions – IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems

IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems E26-6: E26 6 Risk assessment for exclusion of CBS from the application of requirements

Excluding an in-scope CBS from the requirements needs a documented risk assessment showing acceptable risk, based on knowledge of similar designs, the CBS category, connectivity and functional requirements and threat information, kept current by the integrator during build and by the owner in service (informing the Society and resubmitting if risk rises above the threshold), analysing operating environments, likelihood and impact on safety of people, ship and environment, the attack surface, emerging risks, vulnerabilities, internal and external threats and integration effects including remote access. The Society accepts exclusion only with assurance of no safety impact, and the CBS must be isolated from IP networks, have no accessible ports (unused ones disabled), be in a physically controlled area and not be an integrated system serving several ship functions; it should also not serve Cat. III functions, have known risks considered and a minimised attack surface.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in UR E26 sections 5 and 6: demonstration of compliance and exclusions – IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.