Excluding an in-scope CBS from the requirements needs a documented risk assessment showing acceptable risk, based on knowledge of similar designs, the CBS category, connectivity and functional requirements and threat information, kept current by the integrator during build and by the owner in service (informing the Society and resubmitting if risk rises above the threshold), analysing operating environments, likelihood and impact on safety of people, ship and environment, the attack surface, emerging risks, vulnerabilities, internal and external threats and integration effects including remote access. The Society accepts exclusion only with assurance of no safety impact, and the CBS must be isolated from IP networks, have no accessible ports (unused ones disabled), be in a physically controlled area and not be an integrated system serving several ship functions; it should also not serve Cat. III functions, have known risks considered and a minimised attack surface.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.