UR E26 Goals 4 (Respond) + 5 (Recover) require incident response + recovery capabilities. Incident Response Plan (IRP) covers: detection triggers + classification (safety-impact + business-impact); response team roles + responsibilities (Captain + Officer + IT + shore support + class society); response procedures per incident category (malware + ransomware + unauthorised access + physical tampering + denial-of-service + supply chain); containment + eradication procedures; escalation + reporting (Captain + shore + flag administration + class society + cyber insurer + national CSIRT + IMO if required); incident communication internal + external + media + stakeholders. Recovery: backup strategy per CBS (frequency + location + retention + offline copies + air-gapped); restoration procedures + recovery time objective (RTO) per CBS criticality + recovery point objective (RPO); recovery testing + tabletop exercises; failover + degraded mode operation procedures; safety-critical system manual override and recovery; voyage continuation vs port diversion decision criteria. Lessons learned: post-incident review + root cause analysis + corrective action + control improvement + sharing with Member Society + industry (BIMCO Cyber Security Workgroup + IUMI). IACS UR E26 Respond + Recover + IR + Recovery + Backup + Lessons applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.