Framework Alignment captures the cross-walk between IMO MSC-FAL.1/Circ.3/Rev.2 5 functional elements and parallel international standards + industry guidance for operational implementation. The IMO 5 Functional Elements explicitly mirror NIST Cybersecurity Framework (CSF) v1.1 / v2.0 Functions: Identify + Protect + Detect + Respond + Recover (NIST CSF v2.0 adds Govern as 6th function which IMO captures in MSC.428(98) SMS integration + governance requirements). Industry Guidelines on Cyber Security Onboard Ships v4 (December 2020, jointly published by BIMCO + ICS + INTERTANKO + INTERCARGO + INTERMANAGER + OCIMF + WSC + IUMI + ICCSA + ICS + AICS + others) provides the operational detail for implementation - structured in same 5 functional elements + provides asset categories + threat catalogue + technical and procedural cyber risk management + practical recommendations + Annexes 1-6 covering Cyber Risk Management Process + Asset List + Technical Cyber Risk Management + Incident Response + Recover + Third Party Risk. IACS Unified Requirements: UR E26 Cyber Resilience of Ships (effective 1 January 2024 newbuild + retrofit 1 January 2026 SOLAS) provides class-level requirements for ship cyber resilience including IACS Function Areas (FA1-FA6); UR E27 Cyber Resilience of On-board Systems and Equipment (effective 1 January 2024) provides type approval cyber requirements for individual systems and equipment. IACS Recommendation 166 Cyber Resilience provides further interpretation. IEC 62443 series (industrial cybersecurity): IEC 62443-2-1 Security Programme for IACS Asset Owners + IEC 62443-2-4 Security Programme for IACS Service Providers + IEC 62443-3-2 Security Risk Assessment for System Design + IEC 62443-3-3 System Security Requirements + IEC 62443-4-1 Secure Product Development Lifecycle + IEC 62443-4-2 Technical Security Requirements for IACS Components. ISO 27001 ISMS + ISO 27002 controls + ISO 27005 risk + ISO 27035 incident management + ISO 28001 supply chain + ISO 22301 business continuity. USCG NVIC 01-20 Guidelines for Addressing Cyber Risks at MTSA Regulated Facilities + USCG Cyber Strategic Outlook. EU NIS2 Directive 2022/2555 covers maritime as essential entity sector + EU MaRiSa Maritime Cybersecurity Strategy + ENISA Port Cybersecurity Guidance. UK Code of Practice Cyber Security for Ships + UK MCA Maritime Cyber Code. Australia SOCI Act 2018 + amendments. Class Society Cyber Notations: DNV Cyber Secure CS (3 levels Basic-Advanced-Plus) + Lloyds Register ShipRight Cyber Security + ABS CyberSafety + BV Smart Vessel + RINA. National flag State implementation guidance (e.g. Singapore MPA + UK MCA + Norway NMA + Marshall Islands + Liberia + Panama). IMO MSC-FAL framework alignment + NIST CSF + Industry Guidelines v4 + IEC 62443 + class notations applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.