The company's approved safety management system should take account of cyber risk management in line with the objectives and functional requirements of the ISM Code, and Administrations are encouraged to make sure cyber risks are properly addressed in the SMS no later than the first annual verification of the company's Document of Compliance after 1 January 2021. In practice this is where flag States and recognised organizations audit the Guidelines: cyber risks sit in the SMS risk assessment, procedures, responsibilities, training, emergency preparedness, non-conformity reporting, internal audit and management review, with confidential parts protected as paragraph 3 allows.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.