IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
IMO MSC-FAL Scope + ISM Code SMS Integration

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) IMO-MSC-FAL-Scope-MSC-FAL1Circ3Rev2-MSC42898-2017-1Jan2021-ISMCode-SMS: IMO Maritime Cyber Risk Management Scope - MSC-FAL.1/Circ.3 + Rev.2 + Resolution MSC.428(98) + ISM Code Safety Management System Integration + 1 January 2021 Effective + Senior Management Commitment

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management originally adopted as joint circular MSC-FAL.1/Circ.3 by the Maritime Safety Committee (MSC) at its 98th session 7-16 June 2017 and Facilitation Committee (FAL) at its 41st session 4-7 April 2017. Revision MSC-FAL.1/Circ.3/Rev.1 (June 2021) and current MSC-FAL.1/Circ.3/Rev.2 (2022) updated guidance reflecting evolving cyber threat landscape and industry implementation experience. Provides high-level recommendations on maritime cyber risk management to safeguard shipping from current and emerging cyber threats and vulnerabilities. Complemented by IMO Resolution MSC.428(98) Maritime Cyber Risk Management in Safety Management Systems (adopted 16 June 2017 at MSC 98th session) which AFFIRMS that an approved safety management system should take into account cyber risk management in accordance with the objectives and functional requirements of the ISM Code + ENCOURAGES Administrations to ensure cyber risks are appropriately addressed in safety management systems no later than the first annual verification of the company Document of Compliance after 1 January 2021. This effectively makes cyber risk management mandatory for SOLAS-class vessels through ISM Code compliance. Scope applies to: ship owners + ship operators + classification societies + Administrations (flag States) + Recognised Organisations (ROs) + manufacturers + service providers + ports + port facilities + maritime industry stakeholders. Covers Operational Technology (OT) systems (Bridge Systems + Cargo Handling + Engine Monitoring + Communication + Crew Welfare/Administrative) and Information Technology (IT) systems. Scoped to safety + security objectives of: International Convention for the Safety of Life at Sea (SOLAS) + International Safety Management (ISM) Code Chapter IX SOLAS + International Ship and Port Facility Security (ISPS) Code SOLAS Chapter XI-2. Public + freely available via imo.org. Coordinates with Industry Guidelines on Cyber Security Onboard Ships v4 (published December 2020) jointly developed by BIMCO + Chamber of Shipping + International Chamber of Shipping + INTERCARGO + INTERTANKO + INTERMANAGER + International Union of Marine Insurance + OCIMF + International Marine Contractors Association + WSC + IACS + Cruise Lines International Association + ICS + IACS Unified Requirements E26 Cyber Resilience of Ships (1 Jan 2024) + E27 Cyber Resilience of On-board Systems and Equipment (1 Jan 2024) + IACS Recommendation 166 Cyber Resilience + IEC 62443 + NIST Cybersecurity Framework (CSF) + ISO 27001 + ISO 27002 + USCG NVIC 01-20 Guidelines for Addressing Cyber Risks at MTSA Regulated Facilities + EU NIS2 Directive 2022/2555 + EU MaRiSa Cyber Maritime + EU MARSEC Initiative + ENISA Port Cybersecurity + UK Code of Practice Cyber Security for Ships + DNV Cyber Secure Notation + Lloyd Cyber Security Class Notation. IMO MSC-FAL + Rev.2 + Resolution MSC.428(98) + ISM Code SMS integration applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.