UR E27 requires equipment manufacturers to provide comprehensive documentation package to ship owner at delivery covering: SBOM (per UR E27 SBOM control); security capabilities mapping to IEC 62443-4-2 CRs + SL profile + Category; hardening guide + secure configuration baseline; secure update procedure + rollback + emergency reverse; user authentication setup + RBAC role definitions + default credential change procedure; logging configuration + event types + retention; backup + recovery procedure; vendor remote support agreement (per UR E26); vulnerability disclosure policy + CVE notification + advisories; lifecycle support commitment + EOL planning; type approval certificate + class society approval reference. Coordination with international maritime cyber framework: IMO Resolution MSC.428(98) Maritime Cyber Risk Management in SMS (effective 1 January 2021 SMS audits); IMO MSC-FAL.1/Circ.3/Rev.2 Guidelines on Maritime Cyber Risk Management; BIMCO Guidelines on Cyber Security Onboard Ships (5th edition); IEC 62443 industrial automation cybersecurity standards (IEC 62443-1-1 to IEC 62443-4-2); ISO/IEC 27001 ISMS; NIST CSF Functions (Identify + Protect + Detect + Respond + Recover) directly mapped to UR E26 goal-based structure. 2024-2025 pipeline: IACS revision cycle (Rev 2 expected 2026-2027) + IMO MSC + FAL cyber updates + EU NIS2 Directive maritime applicability + EU Maritime Cyber Strategy + USCG Cyber Action Plan + IUMI Cyber Insurance maritime guidelines + ENISA Port Cyber Security + AI / autonomous ship + MASS (Maritime Autonomous Surface Ships) cyber considerations + quantum-resistant crypto for satellite communications. IACS UR E27 + documentation package + IMO + IEC 62443 + NIST CSF + BIMCO + 2024-2025 pipeline applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.