This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Technical Notices
ISM Code | Industry Cyber Risk Management Guidelines- Version 4
The fourth edition of the industry cyber risk management guidelines, Guidelines on Cyber Security Onboard Ships is now available and lays the foundation for further improvements and refinement of companies’ cyber security risk assessments.
The version 4 of the cyber security guidelines is published at a time when shipowners and ship managers are faced with a requirement to implement cyber risk management in their safety management systems (SMS) by the time of their first Document of Compliance audit after 1 January 2021. While the previous version (version 3 dated November 2018) offered the necessary guidance for the initial work of implementing cyber risk management in the SMS, the new version contains several improvements.
The fourth version contains general updates to best practices in the field of cyber risk management, and as a key feature, includes a section with improved guidance on the concept of risk and risk management. The improved risk model takes into consideration the threat as the product of capability, opportunity, and intent, and explains the likelihood of a cyber incident as the product of vulnerability and threat. Thus, the improved risk model offers explanation as to why still relatively few safety-related incidents have unfolded in the maritime industry, but also why this should not be misinterpreted and make shipping companies lower their guard.
Attachment:
Guidelines on Cyber Security Onboard Ships (v4)