IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems
IACS UR E26 Detect

IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting: IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM

UR E26 Goal 3 (Detect) requires monitoring + detection capabilities to identify cyber incidents. Logging: all CBS log security-relevant events (authentication + authorization + configuration change + privileged action + network connection + failure); log centralisation where feasible to dedicated log server / SIEM (on-board or hybrid with shore SOC); log retention per criticality + per applicable maritime regulations (typically 90 days online + 1 year archive minimum); log integrity protection (signed + write-only + tamper-evident); log review on routine basis. Network monitoring: passive network traffic analysis on OT segments (Dragos / Claroty / Nozomi class IDS + flow analysis); intrusion detection rules + signatures + behavioral; anomaly detection (baseline + deviation); alert generation for: failed auth + new device + unusual port + malware signature + lateral movement + data exfiltration pattern; pairing with shore Security Operations Centre (SOC) where vessel connectivity permits 24/7 monitoring; integrated with vessel alarm system (IAS) for critical alerts. Audit trail: configuration changes + access changes + control disablement + emergency overrides recorded + reviewed periodically. Class society survey verifies logging + monitoring capability. IACS UR E26 Detect + logging + monitoring + SIEM + SOC + audit applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 29 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

GHG Protocol · 1 control

HITECH Act · 1 control

ISO/IEC 27011:2024 · 1 control

MITRE D3FEND · 1 control

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.