IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems
IACS UR E27 SBOM + Secure Dev

IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity: IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity

UR E27 requires equipment manufacturers to provide Software Bill of Materials (SBOM) and demonstrate secure development. SBOM contents per CISA SBOM Minimum Elements + SPDX or CycloneDX format: component name + version + supplier + license + dependency relationships + hash; coverage of: operating system + libraries + frameworks + open source + commercial components + firmware. SBOM provided to ship owner at delivery + updated on patch / firmware update; supports vulnerability matching (CVE feeds + open source advisories) by owner over equipment lifecycle. Secure Software Development Lifecycle (SDLC) per IEC 62443-4-1: governance + roles + security requirements + threat modeling + secure design + secure coding + code review + static analysis + dynamic analysis (SAST + DAST + IAST) + dependency scanning + penetration testing + verification + documentation. Type approval process: class society reviews SDLC evidence + capability claims + testing + SBOM + documentation; certifies equipment compliant with UR E27 for specific category + SL. Software integrity protection at runtime: code signing + integrity verification at boot + secure update mechanisms (signed firmware + rollback protection + atomic update) + tamper detection. Coordinates with IEC 62443-4-1 Process requirements + IEC 62443-4-2 Component requirements. IACS UR E27 + SBOM + SDLC + Type Approval + Software Integrity applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.