simpl.
Maritime Compliance 12 items

Maritime Cyber Risk Management Inspection

Evaluates cyber risk management integration into the Safety Management System under IMO Resolution MSC.428(98) and MSC-FAL.1/Circ.3.

ISM CodeIMO MSC.428(98)

Free PDF · enter your email to download.

Governance and SMS Integration

  • Are cyber risks addressed within the ship's Safety Management System? *
  • Are roles and responsibilities for cyber risk management defined ashore and on board? *
  • Has a cyber risk assessment identified critical OT and IT systems and their vulnerabilities? *

Technical and Access Controls

  • Are critical systems (ECDIS, radar, engine/OT networks) segregated or protected from uncontrolled network access? *
  • Are software and antivirus/security updates managed and applied for shipboard systems? *
  • Is use of removable media and personal devices controlled by procedure? *
  • Are user accounts, passwords, and administrator privileges managed and default credentials changed? *

Awareness and Training

  • Have crew received cyber awareness training relevant to their duties? *
  • Are personnel aware of phishing, social engineering, and safe use of shore/vendor connections? *

Detection, Response and Recovery

  • Are procedures in place to detect and report cyber incidents affecting safety-critical systems? *
  • Are backups of critical system data and configurations maintained and tested for recovery? *
  • Is there a contingency plan for operating navigation and machinery if key systems are compromised? *

Download the full Maritime Cyber Risk Management Inspection checklist

Get it as a clean, printable PDF — free.