UR E27 requires equipment manufacturers to deliver hardened CBS with secure default configuration + secure communications. Hardening: minimum services + disabled debug + locked BIOS + secure boot + Trusted Platform Module (TPM) or equivalent root of trust + signed boot loader + secure firmware update + tamper detection; vendor-provided hardening guide + secure configuration baseline; default credentials changed mandatorily before delivery + no shared default credentials across deployments. Secure communications: cryptographically protected communications between CBS components (TLS 1.2/1.3 + IPsec + WireGuard + maritime-specific); strong cryptographic algorithms (AES-256 + RSA-2048+ / ECDSA / EdDSA + SHA-256+); key management + lifecycle + rotation; certificate management (X.509 + Public Key Infrastructure or pre-shared keys for constrained CBS); integrity protection of communications (HMAC + AEAD); replay protection + sequence numbers. Maritime-specific considerations: limited bandwidth (satellite) requires efficient crypto; safety-critical real-time messaging cannot tolerate latency from heavy crypto; some legacy bus protocols (NMEA 0183 + Modbus) without native security need wrapping or compensating controls. IACS UR E27 + hardening + secure config + communications + cryptography + maritime applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.