UR E26 Goal 3 (Detect) requires monitoring + detection capabilities to identify cyber incidents. Logging: all CBS log security-relevant events (authentication + authorization + configuration change + privileged action + network connection + failure); log centralisation where feasible to dedicated log server / SIEM (on-board or hybrid with shore SOC); log retention per criticality + per applicable maritime regulations (typically 90 days online + 1 year archive minimum); log integrity protection (signed + write-only + tamper-evident); log review on routine basis. Network monitoring: passive network traffic analysis on OT segments (Dragos / Claroty / Nozomi class IDS + flow analysis); intrusion detection rules + signatures + behavioral; anomaly detection (baseline + deviation); alert generation for: failed auth + new device + unusual port + malware signature + lateral movement + data exfiltration pattern; pairing with shore Security Operations Centre (SOC) where vessel connectivity permits 24/7 monitoring; integrated with vessel alarm system (IAS) for critical alerts. Audit trail: configuration changes + access changes + control disablement + emergency overrides recorded + reviewed periodically. Class society survey verifies logging + monitoring capability. IACS UR E26 Detect + logging + monitoring + SIEM + SOC + audit applies.
This control maps to 29 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.