Key Requirements and Checklist for Ship Cybersecurity Certification

Strengthened Cybersecurity Requirements of IMO and IACS: Key Checklist for Classification Society Cybersecurity Certification

As IMO and IACS reinforce cybersecurity requirements, specific criteria must be met to obtain cybersecurity certification from classification societies.

In this post, we will summarize the key checklist for acquiring classification society cybersecurity certification.








✅ Key Requirements and Checklist for Classification Society Cybersecurity Certification

CategoryChecklist ItemsDescriptionApplicable to
1. Cybersecurity Policy & ManagementCybersecurity and Resilience ProgramEstablishing a protection and response framework for ship IT/OT systemsOwner
Management of Change (MoC)Security assessment and approval procedures when modifying ship IT/OT systemsOwner
Cyber Risk AssessmentConducting risk assessments in compliance with IACS UR E26/E27Shipyard
2. Network Security DesignZones and Conduit DiagramDefining network segmentation and data flowShipyard
Firewall Configuration & Access ControlFirewall setup, network access control, and monitoring policiesOwner
Remote Access SecurityApplying multi-factor authentication (MFA), VPN, and logging for remote accessOwner
Wireless Communication SecuritySecurity settings and control measures for wireless networksOwner
3. Equipment Cybersecurity RequirementsSupplier Security ComplianceVerifying security certification (ClassNK, DNV, ABS) of equipment suppliersSupplier
Secure Development Lifecycle (SDL)Ensuring security validation procedures during equipment development and maintenanceSupplier
TA (Type Approval) CertificationObtaining classification society approval, including cybersecurity featuresSupplier
4. System Security ManagementSoftware & Firmware UpdatesManaging security patches and updates for IT/OT systemsOwner
Malware Protection & Endpoint SecurityApplying antivirus, ransomware protection, and EDROwner
Data Backup & Disaster Recovery (BCP/DRP)Establishing data protection and recovery plans for emergenciesOwner
5. Security Monitoring & Incident ResponseIntrusion Detection System (IDS) & SIEMOperating real-time security anomaly detection and log analysis systemsOwner
Incident Response Plan (IRP)Defining detection, response, and recovery processes for cyber incidentsOwner
Penetration Testing & Cyber Resilience TestConducting security checks and penetration testing on ship IT/OT systemsShipyard
6. Testing & ValidationFAT (Factory Acceptance Test)Performing security function tests before equipment shipmentSupplier
SAT (Site Acceptance Test)Conducting security verification and performance testing after ship installationShipyard
Security Configuration AuditChecking security settings and ensuring regulatory complianceShipyard
7. Training & MaintenanceCrew Cybersecurity TrainingDeveloping cybersecurity training and education plans for crew membersOwner
Regular Security Audits & Compliance ChecksConducting regular security audits to comply with ClassNK requirementsOwner
Continuous Security Improvement PlanEstablishing a plan for ongoing improvement of cybersecurity policies and systemsOwner

🔍 Essential Documents for Cybersecurity Certification

To obtain classification society cybersecurity certification, the following essential documents must be submitted:

📌 Documents Submitted by Ship Owners (Owner)
✅ Ship Cybersecurity and Resilience Program
✅ Management of Change (MoC) Plan
✅ Firewall & Remote Access Policy
✅ Incident Response Plan (IRP) and Response Procedures
✅ Disaster Recovery Plan (DRP) and Backup Policy
✅ Security Awareness Training & Crew Education Plan
✅ Intrusion Detection System (IDS) and Log Monitoring Policy
✅ Regular Security Audit & Compliance Check Report

📌 Documents Submitted by Shipyards (Shipyard)
✅ Zones and Conduit Diagram (Network Security Design)
✅ Cybersecurity Risk Assessment Report
✅ Ship Cyber Resilience Test Procedure
✅ Security Configuration Guidelines
✅ Site Acceptance Test (SAT) Report

📌 Documents Submitted by Equipment Suppliers (Supplier)
✅ Type Approval (TA) Certification
✅ Secure Development Lifecycle (SDL) Documentation
✅ FAT (Factory Acceptance Test) Report
✅ Security Configuration Guidelines
✅ Test Reports for Security Capabilities


🚀 Preparation Strategy for  Cybersecurity Certification

1️⃣ Consider Security from the Design Stage!

  • Incorporate network security architecture (Zones & Conduits Diagram) and firewall settings into the initial design.
  • Conduct security reassessments through Management of Change (MoC) when design changes occur.

2️⃣ Ensure Security Certification (Type Approval, TA) for Equipment

  • Major equipment such as engines, propulsion systems, and navigation systems must be certified by ClassNK, DNV, ABS, etc.
  • Security functions must be verified through FAT/SAT testing.

3️⃣ Maintain Security and Establish Regular Inspection Plans During Operation

  • Conduct Security Audit & Compliance Checks to ensure ongoing security during ship operation.
  • Cybersecurity training for crew members (Security Awareness Training) is essential.

🚢 Conclusion: Cybersecurity Certification Requires Thorough Preparation!

As IMO and classification societies strengthen cybersecurity requirements, security measures must be applied across design, equipment, and operations to obtain certification.

✅ Incorporate security requirements during the design phase (Shipyard)
✅ Secure equipment cybersecurity certification (Supplier)
✅ Maintain and conduct regular security inspections during ship operations (Owner)

Classification society cybersecurity certification is not just about regulatory compliance—it is an essential element for safe and reliable ship operations.

🚢 Is your ship ready for classification society cybersecurity certification?
Share your thoughts and let's discuss together! 😊

🔍 Stay tuned for our next post, where we will introduce FAT/SAT Security Testing and Certification Procedures! 🚢✨

Comments

Popular posts from this blog

[MaritimeCyberTrend] Relationship and prospects between U.S. Chinese maritime operations and maritime cybersecurity

인공지능 서비스 - 챗봇, 사전에 충분한 지식을 전달하고 함께 학습 하기!

[Curriculum] Sungkyunkwan University - Department of Information Security - Course Sequence by Areas of Interest