Home India Ministry of Ports, Shipping and Waterways Implementation of Cyber-security risk mitigation measures on...
Date: 2017-11-06 Category: DGS Circular State: Union Government Country: India

Implementation of Cyber-security risk mitigation measures on board Indian Flag Ships.

Issued by Ministry of Ports, Shipping and Waterways · Directorate General of Shipping

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This circular, issued by the Director General of Shipping, Ministry of Shipping, Govt. of India, addresses the implementation of cyber-security risk mitigation measures on board Indian Flag Ships. It is to ensure that all shipping companies comply with the International Maritime Organization (IMO) requirements for cyber risk management. Compliance is required no later than the first annual verification of the company's Document of Compliance after 1 January 2021. **Key Points / Main Content** * **Background:** * Modern shipboard systems increasingly use networked information technology. * The exchange of data via the internet is susceptible to cyber-attacks, which can lead to various consequences, including business disruption and damage to the ship. * IMO approved Resolution MSC.428 (98) on Maritime Cyber Risk Management in Safety Management Systems, encouraging member states to address cyber risks in safety management systems. * Cyber risk management should be part of operational risks and an extension of existing safety and security practices. * **Requirements:** * **For new DOC applicants requesting for initial DOC audit on/after 1 January 2018:** * Cyber-risk management procedures must be included in the SMS risk mitigation manuals and reviewed by a Recognized Organization (RO) before the initial DOC audit. * The Administration Surveyor will review and verify satisfactory implementation of cyber-security risk mitigation during the initial audit. The audit report should reflect this. * A memo stating satisfactory compliance with IMO requirements should be raised in the survey status of each vessel. * **For existing DOC holders wishing to demonstrate compliance prior to 1 January 2018:** * Companies are advised to not wait until the first annual/renewal DOC audit after 1st January 2021. * A company may conduct a cyber-risk assessment and include the mitigation procedures in their SMS after RO review. * Request a DGS auditor to verify compliance during the next due annual/renewal DOC audit, and for the Administration auditor to follow procedures detailed in Paragraph B)1(i)(b). * RO/Administration auditor carrying out the next due intermediate/renewal SMS audit (after demonstrating the verification of compliance in the last DOC audit) to follow procedures detailed in Paragraph B)1(i)(c). * **On/After 1 January 2021:** * No request for DOC annual/renewal audit will be accepted unless risk mitigation procedures reviewed by RO are included in SMS manuals. * No request for vessel SMC intermediate/renewal audit will be entertained unless the report narrative of previous DOC audit states compliance with the IMO requirement with respect to cyber-security risk management. **Impact Analysis** **Shipping Companies holding DOC** * **Impact** * Must implement cyber-security risk mitigation measures on board their ships. * Must integrate cyber-risk management procedures into their Safety Management System (SMS). * Could face delays in DOC annual/renewal audits if cyber-security risk mitigation procedures are not properly implemented and documented. * **Action Required** * Assess cyber risks and develop mitigation procedures. * Update SMS manuals to include cyber-risk management procedures. * Ensure compliance is verified during DOC audits. * Report compliance to the concerned RO/s. **Recognized Organizations (ROs)** * **Impact** * Must review and approve cyber-risk management procedures in shipping companies' SMS manuals. * Must verify the satisfactory implementation of cyber-security risk mitigation measures during DOC audits. * **Action Required** * Update audit procedures to include cyber-security aspects. * Review shipping companies' SMS manuals for cyber-risk management procedures. * Report verification of compliance in audit reports. **Administration Auditors (DGS)** * **Impact** * Must verify the implementation of cyber-security risk mitigation measures during DOC audits. * **Action Required** * Follow the procedures detailed in Paragraph B)1(i)(b) with respect to verification and reporting during the annual/renewal DOC audit.

Key Entities Referenced

Maritime Cyber Risk Management in Safety Management Systems: Resolution MSC.428 (98) addressing cyber security in maritime safety management systems. International Safety Management (ISM) Code: A standard for the safe management and operation of ships and for pollution prevention. Directorate General of Shipping, Ministry of Shipping, Govt. of India: The issuing authority for the circular, responsible for implementing maritime regulations in India. Document of Compliance (DOC): A document issued to shipping companies that comply with the International Safety Management Code. Recognized Organization (RO): Organizations authorized to conduct audits and certifications on behalf of the Directorate General of Shipping.
Official Source Record View Original Source →
See Full Document Text
ffishipping,MinistryofShipping,Govt.of|ndia,Mumbai ISM CELL ENGG. Circular Authorized by No.06 of 2017 the Subiect: Implementation of Cvber-securitv risk Ghief Surveyor mitisation measures on board Indian Flas Ships with GOI File No. : ENG/lSM-59(4)/97-Vol Vll. Dated: 06.11.2017 A) Backeround: 1) Modern developments in information and communication technology have led shipboard machineries and equipments fitted with complex control systems and such control systems are increasingly being networked with the information technology wherein the technology uses data as information for operation, monitor and control the physical processes 2) The exchange of information and data via networked systems using internet is susceptible to cyber-attack. The consequences of a cyber-attack are wide-ranging, that is, from business disruption, damage to ship, pollution, safety of crew to ship collision. Therefore, it is important that these information and data exchange systems be protected from risks that may occur via un-authorized access or malicious affacks to ships' systems and networks and from personnel having access to the systems onboard, for example by introducing malware via removable media. 3) To address the issues related to cyber-security IMO at the 98th session of the Maritime Safety Committee held on June 16, 2017, approved Resolution MSC.428 (98) on Maritime Cyber Risk Management in Safety Management Systems. The resolution affirms that approved safety management systems should take cyber risk management into account in accordance with the objectives and requirements of the International Safety Management Code. Further the member states are encouraged to ensure cyber risks are appropriately addressed in safety management systems no later than the first annual verification of the company's Document of Compliance after I JanuarY 2021. 4l The IMO guidelines define cyber risk management as being "the process of identiffing, analyzing, assessing and communicating a cyber-related risk and accepting, avoiding, transferring, or mitigating [that risk] to an acceptable level [after] the costs and benefits of actions taken to stakeholders." Further, Cyber " rio sn kr i md" ar nin agg e ment should be considered a part of operational risks and should evolve "as a natural extension ofexisting safety and security practices" Page 1 of 3B) Requirements: 1) To ensure that all shipping companies holding DOC issued under ISM Code comply with the IMO requirement within the prescribed time limit, the Directorate hereby specifies the following procedure: I i) All new DOC applicants requesting for initial DOC audit on/after January 2018: a) Cyber-risk management procedures to be included in the SMS risk mitigation manuals. These procedures to be reviewed by Recognized Organization prior conduct of initial DOC audit by the Administration auditor. b) Review and verification of satisfactory implementation of the said cyber-security risk mitigation during the initial audit by the Administration Surveyor. The initial audit report narrative and Document review record narrative to clearly state the same' c) A suitable memo (stating the satisfactory compliance to the said IMO requirement) be raised in the survey status of each vessel owned/managed by the said company by the RO conducting the initial audit after satisfactory verification of the implementation of the cyber- risk mitigation measure on board each such vessel during the initial audit. The audit report narrative to include verification of the compliance with such requirement on board' iD All other DOC holders wishing to demonstrate compliance prior "*irting to l't January 2018: a) lt is Ldvised that Indian DOC holders may not wait till the l't annual/renewal DOC audit after 1" January 202I' b-) A Company wishing to demonstrate compliance with the said IMO requiremeni earlier may carry out a cyber-risk assessment and include the mitigation procedures in their SMS after due review by Ro. c) Requesi DG$ auditor to verify compliance during the next due to DOC audit. Administration auditor follow annual/renewal procedures detailed in Paragraph B)l(i)(b) above with respect to verification and reporting during this annual/renewal DOC audit' A copy of such report to be forwarded by the Company to the concerned RO/s which conducted previous SMS audits on the Company managed vessels. d) Ro/Administration auditor carrying out the. next due intermediate/renewal SMS audit (after demonstrating the verification of compliance in the last Doc audit)on the company managed vessel/s to follow procedures detailed in Paragraph B)l(iXc) above withrespecttocompliance,reportnarrativeandraisingofasuitable Memo in the survey status of the said vessel/s' tr. Page 2 of 3iir) l On/After January 20211 a) No request for DOC annual/renewal audit shall be accepted unless risk mitigaiion procedures reviewed by RO are included in the SMS manuals. b) No request for vessel/s SMC intermediate/renewal audit shall be entertained unless the report narrative of previous DOC audit states compliance with the said IMO requirement with respect to cyber- security risk management. This is issued with the approval of the competent authority. (sa math) Enginee{and ShiP SurveYor-cum- Dy.Director General (Tech) To, l. The principal Officer/ Mercantile Marine Department, MumbaiA(olkata/ Chennaii Kandla/Cochin. 2. The Surveyor-in-charge, Mercantile Marine Department, Goa/Jamnagar/Port Blair A/isakhapatanam /Tuticorin /Delh i fttaldial Paradip /Mangalore. 3. All Recognised Organizations. 4. ICC Shipping Association (ICCSA), Mumbai' 5. CSA{A/CSS/Jt.D.G. 6. Hindi Cell. 7. Guard hle. 8. Computer Cell. Page 3 of 3

Continue your research