Cyber Security: Supply Chain Risk Management and Defense-in-Depth requirements for Maritime Systems
Description
Cybersecurity for maritime operations requires a robust defense-in-depth approach from the initial sourcing of components, software, and systems; continuing through robust security engineering during the design, implementation, and deployment processes of those systems; and extending to proactive defensive measures of not only traditional information communications technology (ICT) systems but operational technology (OT) systems as well. Global connectivity has extended the risk of network attack even while a vessel is underway. Additionally, the long lifecycle of many maritime systems contributes to the challenge of defending outdated or no longer supported components and systems, (which are difficult to patch or totally unpatchable in many cases). Emerging standards and regulatory guidance are pushing the maritime industry toward compliance. These initiatives provide an opportunity to achieve improved operational practices and eliminate the underlying cyber security vulnerability as well. International bodies such as BIMCO, the Oil Companies International Marine Forum (OCIMF), and the International Maritime Organization’s (IMO) extension of the International Safety Management (ISM) Code and the International Ship and Port Facility Security Code (ISPS) are excellent resources to address cyber security risk. The new IMO guidance, adopted by the Maritime Safety Committee on June 16, 2017, as Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, encourages organizations “to ensure that cyber risks are appropriately addressed in existing safety management systems.”[1] Many experts recommend adopting one of several international security standards or frameworks already developed to help identify, assess, and mitigate cyber security risk; these include the International Standards Organization (ISO)/ International Electrotechnical Commission (IEC) 27000 Information Security Management Systems (ISMS) family of standards, the Center for Internet Security (CIS) Top 20 Controls, and the United States National Institute of Standards and Technology (NIST) Cybersecurity Risk Management Framework. Another family of standards, the IEC 62443 Industrial Networks and Systems Security series of standards, have a direct application to shipboard automation and control systems typically found throughout a vessel’s propulsion, stabilization, electrical control, and deck machinery systems. Organizations can leverage a growing number of IEC 62443 compliant components, systems, and processes to help streamline the steps required for overall compliance and help address their underlying cyber security risk overall. This paper will focus on addressing supply chain cyber risk management for maritime operations and effective cyber security defense-in-depth practices for the vessel’s hull, mechanical, and electrical shipboard systems.
Files
INEC_2020_Paper_80.pdf
Files
(1.6 MB)
Name | Size | Download all |
---|---|---|
md5:a046a65538b83994b54da4f40c77bca1
|
1.6 MB | Preview Download |
Additional details
References
- Based off the Cyprus Shipping Chamber City Chambers, Limassol, Cyprus, www.csc-cy.org, Version 2.0 – May 2018, p. 10.
- https://trapx.com/anatomy-of-an-attack-1/
- Anatomy of an Attack, Zombie Zero, Weaponized Malware Targets ERP Systems, TrapX Research Labs March 1, 2017
- https://www.seatrade-maritime.com/europe/antwerp-incident-highlights-maritime-it-security-risk
- https://www.dco.uscg.mil/Portals/9/DCO%20Documents/5p/MSIB/2019/MSIB_004_19.pdf
- Assessing and Strengthening the Manufacturing and Defense Industrial Base and Supply Chain Resiliency of the United States Report to President Donald J. Trump by the Interagency Task Force in Fulfillment of Executive Order 13806, September 2018, p. 51.
- NIST Special Publication 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations, Jon Boyens, Celia Paulsen, Rama Moorthy, Nadya Bartol, April 2015, p. 7
- Center for Strategic and Budgetary Assessments Report, Strengthening the U.S. Defense Maritime Industrial Base, A Plan to Improve Maritime Industry's Contribution to National Security, Bryan Clark, Timothy A. Walton, Adam Lemon, 2020, p. 58.
- IEC 62443-4-1:2018 © IEC 2018, p. 24.
- https://www.cisecurity.org/controls/cis-controls-list/
- https://www.navsea.navy.mil/Home/RMC/SRFJRMC/JapanTours/WhyJapan/SEVENTHFleet/