Govern covers third party cyber risk + supply chain + continuous improvement extending from the 5 functional elements per MSC-FAL.1/Circ.3/Rev.2 + Resolution MSC.428(98). Third Party and Supply Chain Risk: covers (1) Equipment manufacturers + vendors - cyber security requirements in procurement specifications + Software Bill of Materials (SBOM) + secure-by-design per IACS UR E26 Cyber Resilience of Ships (1 Jan 2024 newbuild + retrofit by 1 Jan 2026) + IACS UR E27 Cyber Resilience of On-board Systems and Equipment (1 Jan 2024) + IEC 62443-4-1 SDL secure development lifecycle + IEC 62443-4-2 component requirements + manufacturer disclosure of vulnerabilities + secure remote support procedures + access logging + privileged credential management + manufacturer cyber declaration. (2) Shipyards - secure handover + security commissioning + change management at yard + crew training during commissioning + integration testing. (3) Class Societies + Recognised Organisations - cyber survey + class notation (DNV Cyber Secure + LR Cyber Security + ABS CyberSafety + BV Smart Vessel) + classification additional notation + verification at periodic surveys + IACS Recommendation 166 cyber resilience. (4) Service Providers - chart update services + ECDIS support + remote engineering support + crew welfare service providers (Internet + content) + satellite communication providers + IT managed services + cyber insurance carriers + maritime cyber consultants. (5) Charterer + Cargo Owners - cyber requirements in charter party agreements + cargo data exchange (Maersk EDI + electronic bills of lading) + customs interface (port community systems). (6) Port Facilities - cyber coordination with port + per ISPS Code + US MTSA Maritime Transportation Security Act + EU Port Cybersecurity Initiative. Continuous Improvement and Audit: cyber risk management reviewed at minimum annually + alongside ISM Code internal audit + Document of Compliance audit + Class survey + Flag State inspection + Port State Control (PSC) inspection + post-incident updates + threat landscape changes + lessons-learned integration + IACS unified survey scheme + ICAO-like cyber improvement programme. Coordinates with Industry Guidelines on Cyber Security Onboard Ships v4 Annex 6 + IACS UR E26 + E27 + IACS Rec 166 + IEC 62443-2-4 SP + 4-1 SDL + 4-2 CR + ISO 28001 Supply Chain Security + ISO 27036 Supplier Relationships + US NIST SP 800-161 SCRM + EU NIS2 + EU MaRiSa + DNV Cyber Secure Notation + LR Cyber Secure Class Notation + ABS CyberSafety + BV Smart Vessel. IMO MSC-FAL Govern + Third Party + Supply Chain applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.