Subscribe to our Mailing Lists (It's free!)
Thursday, March 23, 2023
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    stowaway

    Spanish authorities arrest stowaway with cocaine

    Fire aboard oil tanker in Portugal

    Fire aboard oil tanker in Portugal

    Derelict tug

    Tug sinks off Seattle’s Ship Canal

    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

    Life coaching tips: How to maintain a good work-life balance

    Life coaching tips: How to maintain a good work-life balance

    Wabi sabi

    Wabi Sabi: Imperfection makes perfection at work

    sexual abuse

    Sexual abuse at sea: Where we stand

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    green corridor

    Five industries collaborate for a green corridor between South Africa and Europe

    Stolt Tankers acquires two fuel efficient tankers

    Stolt Tankers acquires two fuel efficient tankers

    Port Arthur LNG

    Port Arthur LNG project launched in Texas

    ABS approves joint industry Carbon Capture System project

    ABS approves joint industry Carbon Capture System project

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    NAPA: Simulation software aids in predicting CII

    NAPA: Simulation software aids in predicting CII

    Canada, UK join forces for R&D digital project on decarbonization

    Canada, UK join forces for R&D digital project on decarbonization

    technology

    How a joined-up approach to technology drives people performance

    New smart project aims to improve maritime logistics

    New smart project aims to improve maritime logistics

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
    australia sea mines

    AMSA imposes 90-day ban on Dutch vessel

    Singapore

    Eco Spark arrested in Singapore

    Liberia

    Liberia: key guidance for machinery space deficiencies

    orange county oil spill fines

    Taiwan’s Wan Hai Lines to pay $950,000 in civil penalties

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
    offshore wind supply chain

    More Norwegian companies invest in offshore wind

    Institute of Chartered Shipbrokers

    Allied Market Research: Marine scrubber market to reach $20.3 billion by 2031

    BIMCO: China’s refinery output rises as exports grow 74%

    BIMCO: China’s refinery output rises as exports grow 74%

    Seatrade Maritime Logistics Middle East set to showcase opportunities in the region’s offshore marine sector

    Seatrade Maritime Logistics Middle East set to showcase opportunities in the region’s offshore marine sector

  • Columns
    WSC: Minimising accidents is at the top of liner shipping’s agenda

    WSC: Minimising accidents is at the top of liner shipping’s agenda

    technology

    How a joined-up approach to technology drives people performance

    SCMA: Maritime arbitration is expected to rise in prominence

    SCMA: Maritime arbitration is expected to rise in prominence

    Trending Tags

    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Resilience
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    stowaway

    Spanish authorities arrest stowaway with cocaine

    Fire aboard oil tanker in Portugal

    Fire aboard oil tanker in Portugal

    Derelict tug

    Tug sinks off Seattle’s Ship Canal

    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

    Life coaching tips: How to maintain a good work-life balance

    Life coaching tips: How to maintain a good work-life balance

    Wabi sabi

    Wabi Sabi: Imperfection makes perfection at work

    sexual abuse

    Sexual abuse at sea: Where we stand

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    green corridor

    Five industries collaborate for a green corridor between South Africa and Europe

    Stolt Tankers acquires two fuel efficient tankers

    Stolt Tankers acquires two fuel efficient tankers

    Port Arthur LNG

    Port Arthur LNG project launched in Texas

    ABS approves joint industry Carbon Capture System project

    ABS approves joint industry Carbon Capture System project

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    NAPA: Simulation software aids in predicting CII

    NAPA: Simulation software aids in predicting CII

    Canada, UK join forces for R&D digital project on decarbonization

    Canada, UK join forces for R&D digital project on decarbonization

    technology

    How a joined-up approach to technology drives people performance

    New smart project aims to improve maritime logistics

    New smart project aims to improve maritime logistics

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
    australia sea mines

    AMSA imposes 90-day ban on Dutch vessel

    Singapore

    Eco Spark arrested in Singapore

    Liberia

    Liberia: key guidance for machinery space deficiencies

    orange county oil spill fines

    Taiwan’s Wan Hai Lines to pay $950,000 in civil penalties

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
    offshore wind supply chain

    More Norwegian companies invest in offshore wind

    Institute of Chartered Shipbrokers

    Allied Market Research: Marine scrubber market to reach $20.3 billion by 2031

    BIMCO: China’s refinery output rises as exports grow 74%

    BIMCO: China’s refinery output rises as exports grow 74%

    Seatrade Maritime Logistics Middle East set to showcase opportunities in the region’s offshore marine sector

    Seatrade Maritime Logistics Middle East set to showcase opportunities in the region’s offshore marine sector

  • Columns
    WSC: Minimising accidents is at the top of liner shipping’s agenda

    WSC: Minimising accidents is at the top of liner shipping’s agenda

    technology

    How a joined-up approach to technology drives people performance

    SCMA: Maritime arbitration is expected to rise in prominence

    SCMA: Maritime arbitration is expected to rise in prominence

    Trending Tags

    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Resilience
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

USCG launched guidance for SMS to address cyber risks

by The Editorial Team
March 29, 2021
in Cyber Security
uscg cyber security

Credit: Shutterstock

FacebookTwitterEmailLinkedin

USCG published a guidance, calling for Safety Management Systems required under the ISM Code to address cyber risks. The guidance regards the USCG commercial vessel compliance program’s approach to assessing the cyber risk on vessels to ensure vessels do not pose a risk to the Marine Transportation System (MTS) due to a cyber event.

The guidance also include a compliance timeline and inspection process for non-Safety Management System vessels that are subject to the Marine Transportation Safety Act of 2002. These vessels are required to address cybersecurity vulnerabilities within their Vessel Security Assessment no later than 31 December 2021.

Vessels subject to the ISM Code (U.S. & Foreign Vessels)

The MI/PSCO shall identify when basic cyber hygiene procedures are not in place onboard. These include, but not limited to the following:

RelatedNews

Allied Market Research: Marine scrubber market to reach $20.3 billion by 2031

Tug sinks off Seattle’s Ship Canal

  • Poor cyber hygiene: Username / Password openly displayed, computer system appears to require a generic login or no login for access, computer system does not appear to automatically log out after extended period of user inactivity, heavy reliance on flash drive/USB media use.
  • Shipboard computers readily appear to have been compromised by ransomware/excessive popups.
  • Officers/crew complain about unusual network issues and reliability impacting shipboard systems.
  • Unit/vessel screener received potential ‘spoofed’ email from master/crew onboard.

Guidance for assessing cybersecurity onboard a vessel subject to the ISM Code

During the course of a normal inspection/examination, the MI/PSCO should evaluate whether or not a cybersecurity event was a factor in the failure of a system required for the safe navigation or operation of the vessel.

If clear grounds are established, the MI/PSCO should conduct a more detailed inspection consistent with the applicable guidance for a foreign o U.S. vessel. Based on objective evidence, the MI/PSCO may discover and can issue deficiencies based on the portion of the SMS that is not being effectively implemented with respect to cyber risk management.

If objective evidence is identified indicating that the vessel failed to implement its SMS with respect to cyber risk management, the MI/PSCO should direct the vessel to take the following actions:

For U.S. Vessels

MIs should follow the guidance in reference which sets forth guidance for assessing the effectiveness of a company’s SMS on U.S. flag vessels.

For Foreign vessels

  • If cyber risk management has not been incorporated into the vessel’s SMS by the company’s first annual verification of the DOC after January 1, 2021, a deficiency should be issued with action code 30 – Ship Detained, with the requirement of an external audit within 3 months or prior to returning to a U.S. port after sailing foreign.
  • When objective evidence indicates that the vessel failed to implement its SMS with respect to cyber risk management, then the PSCO should issue a deficiency for both the operational deficiency and an ISM deficiency with an action code 17 – Rectify Prior to Departure and require the vessel to conduct an internal audit, focused on the vessel’s cyber risk management, within 3 months or, prior to returning to a U.S. port after sailing foreign.
  • When objective evidence indicates there is a serious failure to implement the SMS with respect to cyber risk management that directly resulted in a cybersecurity incident impacting ship operations (e.g. diminished vessel safety/security, or posed increased risk to the environment), after gaining concurrence from the OCMI, the PSCO should issue a deficiency for both the operational deficiency and an ISM deficiency with action code 30 – Ship Detained with the requirement of an external audit within 3 months or prior to returning to a U.S. port after sailing foreign.

Non-SMS U.S. Vessels subject to MTSA

Questions for MIs to ask during Maritime Transportation Security Act (MTSA) Verifications:

  • Does your VSP address measures taken to address cybersecurity vulnerabilities? If yes: Are these measures in place? If no, then ask: Has the vessel experienced any cybersecurity events within the past 12 months?
  • If yes, then ask: Have you reported these cybersecurity incidents to your CSO? If yes: Reasonably verify reporting to CSO, then no further action. If no: Issue deficiency.

Finally, when attending a vessel for a damage survey, inservice inspection or port state control exam following a report of a marine casualty the MI/PSCO or Investigating Officer (IO) should always consider the possibility of the incident being related to a cybersecurity event in cases where system/equipment failure have no obvious causes.

MIs/PSCO/IO should utilize the procedures outlined above to assist with this determination. The MI/PSCO/IO should determine if there was a failure of a system required for the safe navigation or operation of the ship, and then determine if it was a cybersecurity event.

After making this determination, the MI/PSCO/IO ensure that the owner or operator promptly report the incident to the National Response Center (NRC) or the Department of Homeland Security National Communications and Cybersecurity Information Center (NCCIC) to initiate a coordinated federal response.

READ USCG CIRCULAR FOR MORE

Tags: cyber incidentscyber riskcyber securityreportssmUSCG

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

offshore wind supply chain

More Norwegian companies invest in offshore wind

March 22, 2023
NAPA: Simulation software aids in predicting CII

NAPA: Simulation software aids in predicting CII

March 22, 2023

SEAFiT Poll

What is the biggest obstacle for the social life onboard?

Stay tuned for the results!

MARITIME EVENTS

Explore

  • Safety
  • Green
  • Smart
  • Risk
  • Others
  • Events
  • Plus

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Contact

RISK4SEA Facts

Did you know that Class matters for 2020? General Cargo with DNV had approximately 28% less on Detention Rate than the global average.

Learn more risk4sea.com

© 2021 SAFETY4SEA

No Result
View All Result
  • Safety
    • Alerts
    • Accidents
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Opinions
    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus

© 2021 SAFETY4SEA

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Disclaimer.