Skip to content

Evidence request lists

BIMCO Cyber Security

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

BIMCO Ch10: Respond and Recover

BIMCO-10.2
The four phases of incident response

Incident response. The company should respond to cyber incidents following the four phases (preparation, detection and analysis, containment/eradication/recovery, and post-incident activity), with onboard and shore coordination.

Artefacts an auditor will ask for
  • Incident response plan following the four phases
  • Ship-shore coordination and escalation procedures
  • Incident records and post-incident reviews
Where this commonly fails
  • No incident response plan
  • No ship-shore coordination
  • Post-incident review not performed
BIMCO-10.3
Recovery plan

Recovery plan. The company should maintain a recovery plan to restore affected shipboard systems and safe operation following a cyber incident.

Artefacts an auditor will ask for
  • Recovery plan for affected shipboard systems
  • Recovery priorities aligned to safety and operations
  • Recovery testing/exercise records
Where this commonly fails
  • No recovery plan
  • Recovery priorities undefined
  • Recovery untested
BIMCO-10.4
Data recovery capability

Data recovery capability. The company should maintain backups and a data recovery capability for critical shipboard data and system configurations.

Artefacts an auditor will ask for
  • Backup regime for critical data and OT configurations
  • Tested restoration of backups
  • Offline/immutable backup protection against ransomware
Where this commonly fails
  • No backups of critical data/config
  • Restoration untested
  • Backups not protected from compromise
BIMCO-10.5
Investigating cyber incidents

Investigating cyber incidents. The company should investigate cyber incidents to determine root cause and inform improvements, preserving evidence where appropriate.

Artefacts an auditor will ask for
  • Incident investigation/root-cause records
  • Evidence preservation procedures
  • Feedback of lessons learned into the risk assessment and plans
Where this commonly fails
  • Incidents not investigated
  • No root-cause analysis
  • Lessons not fed back

BIMCO Ch1: Cyber Security and Risk Management

BIMCO-1.2
Senior management involvement

Senior management involvement. The company's senior management should be involved in and own cyber risk management, integrating it with the safety management system and the company's overall risk management.

Artefacts an auditor will ask for
  • Evidence of senior-management ownership of the cyber risk programme
  • Integration of cyber risk into the Safety Management System (SMS)
  • Management review records of cyber risk
Where this commonly fails
  • Cyber risk not owned by senior management
  • Not integrated with the SMS
  • No management review
BIMCO-1.3
Roles, responsibilities and tasks

Roles, responsibilities and tasks. Clear roles, responsibilities and tasks for cyber risk management should be defined across the company and onboard, including ship and shore personnel.

Artefacts an auditor will ask for
  • Documented cyber roles and responsibilities (ship and shore)
  • Assignment of a responsible person/function
  • Task allocation for cyber risk activities
Where this commonly fails
  • Roles undefined or unassigned
  • No ship/shore split of responsibility
  • Accountability unclear
BIMCO-1.4
Differences between IT and OT systems

Differences between IT and OT systems. The Guidelines require recognising the differences between information technology (IT) and operational technology (OT) systems onboard and managing the distinct risks of OT (navigation, propulsion, cargo and other shipboard systems).

Artefacts an auditor will ask for
  • Inventory distinguishing IT and OT systems onboard
  • Risk treatment that accounts for OT availability/safety constraints
  • Segregation/interface controls between IT and OT
Where this commonly fails
  • IT and OT not distinguished
  • OT safety constraints ignored in controls
  • No IT/OT interface management
BIMCO-1.5
Plans and procedures

Plans and procedures. The company should develop cyber security plans and procedures, embedded in the SMS, covering protection, detection, response and recovery for ship and shore.

Artefacts an auditor will ask for
  • Cyber security plans and procedures embedded in the SMS
  • Onboard procedures for protection/detection/response/recovery
  • Document control and review of the plans
Where this commonly fails
  • No documented cyber plans/procedures
  • Plans not embedded in the SMS
  • Plans not reviewed/updated
BIMCO-1.8
Relationship with vendors and other external parties

Relationship with vendors and external parties. The company should manage cyber risk arising from vendors, service providers and other external parties that connect to or service ship systems.

Artefacts an auditor will ask for
  • Cyber requirements in vendor/service contracts
  • Control of vendor remote access and onboard service visits
  • Assessment of vendor cyber risk
Where this commonly fails
  • Vendor access uncontrolled
  • No cyber terms in contracts
  • Vendor risk not assessed

BIMCO Ch2: Identify Threats

BIMCO-2.1
Threat actors

Threat actors. The Guidelines require identifying the threat actors relevant to the maritime context (e.g. opportunists, activists, criminals, state-sponsored actors and insiders).

Artefacts an auditor will ask for
  • Documented assessment of relevant maritime threat actors
  • Use of maritime threat intelligence sources
  • Periodic update of the threat picture
Where this commonly fails
  • Threat actors not identified
  • No maritime threat intelligence
  • Threat picture not updated
BIMCO-2.2
Types of cyber threats

Types of cyber threats. The company should identify the types of cyber threats (untargeted and targeted, including malware, phishing, social engineering and OT-specific threats) that could affect ship systems.

Artefacts an auditor will ask for
  • Catalogue of relevant cyber threat types (targeted and untargeted)
  • Mapping of threats to vulnerable shipboard systems
  • Awareness material reflecting current threat types
Where this commonly fails
  • Threat types not catalogued
  • OT-specific threats omitted
  • Threats not linked to systems

BIMCO Ch3: Identify Vulnerabilities

BIMCO-3.1
Common vulnerabilities

Common vulnerabilities. The company should identify common vulnerabilities in shipboard IT and OT (e.g. obsolete systems, unpatched software, weak access controls, lack of segregation).

Artefacts an auditor will ask for
  • Vulnerability assessment of shipboard IT/OT
  • Register of identified vulnerabilities and remediation
  • Review of obsolete/unsupported systems
Where this commonly fails
  • Vulnerabilities not assessed
  • No remediation tracking
  • Obsolete systems unmanaged
BIMCO-3.3
Typical vulnerable systems

Typical vulnerable systems. The Guidelines identify typical vulnerable shipboard systems (navigation/ECDIS, propulsion and machinery, cargo management, communication, access control and administrative systems) to be assessed.

Artefacts an auditor will ask for
  • Inventory of typical vulnerable shipboard systems
  • Per-system vulnerability assessment
  • Prioritisation by criticality to safety and operations
Where this commonly fails
  • Critical shipboard systems not assessed
  • Navigation/propulsion OT omitted
  • No criticality prioritisation
BIMCO-3.4
Ship to shore interface

Ship to shore interface. The company should address vulnerabilities at the ship-to-shore interface (data exchange, remote connections, shore-based management of ship systems).

Artefacts an auditor will ask for
  • Mapping of ship-to-shore data flows and connections
  • Controls securing the ship-to-shore interface
  • Monitoring of shore-initiated connections
Where this commonly fails
  • Ship-to-shore connections unmapped
  • Interface not secured
  • Shore connections unmonitored
BIMCO-3.6
Remote access

Remote access. The company should manage the cyber risks of remote access to shipboard systems (by shore staff, vendors and service providers), including authentication and monitoring.

Artefacts an auditor will ask for
  • Remote access policy for shipboard systems
  • Strong authentication and logging of remote sessions
  • Approval and time-bounding of vendor remote access
Where this commonly fails
  • Remote access uncontrolled
  • No authentication/logging
  • Vendor remote access not approved
BIMCO-3.7
System and software maintenance

System and software maintenance. The company should manage vulnerabilities arising from system and software maintenance, including patching, updates and maintenance by third parties.

Artefacts an auditor will ask for
  • Patch/update procedures for IT and OT (with OT change-control constraints)
  • Control of maintenance media and third-party maintenance
  • Records of maintenance activities
Where this commonly fails
  • No patch/update process
  • Maintenance media uncontrolled
  • Third-party maintenance unlogged

BIMCO Ch4-6: Likelihood, Impact and Risk Assessment

BIMCO-4
Assessing the likelihood

Assessing the likelihood. The likelihood of a cyber incident is assessed as the product of threat and vulnerability, and quantified to inform the risk assessment.

Artefacts an auditor will ask for
  • Likelihood assessment combining threat and vulnerability
  • Documented likelihood ratings per scenario
  • Basis/assumptions for likelihood quantification
Where this commonly fails
  • Likelihood not assessed
  • No threat x vulnerability basis
  • Ratings undocumented
BIMCO-5.1
Impact assessment (CIA model)

Impact assessment. The impact of a cyber incident is assessed against the confidentiality, integrity and availability (CIA) of affected systems, with particular weight on availability and integrity for OT and safety-critical systems.

Artefacts an auditor will ask for
  • Impact assessment using the CIA model per system
  • Consideration of safety, environmental and operational impact for OT
  • Impact ratings feeding the risk assessment
Where this commonly fails
  • Impact not assessed against CIA
  • Safety/operational impact of OT ignored
  • Impact not linked to risk
BIMCO-6.2
The four phases of a risk assessment

Risk assessment. The company should conduct a cyber risk assessment following the four phases (identify, assess likelihood and impact, evaluate and prioritise risk, and decide treatment), documented and periodically reviewed.

Artefacts an auditor will ask for
  • Documented cyber risk assessment following the four phases
  • Risk register with prioritised risks and treatment decisions
  • Periodic review/update of the assessment
Where this commonly fails
  • No structured risk assessment
  • Risks not prioritised or treated
  • Assessment not reviewed
BIMCO-6.3
Third party risk assessments

Third party risk assessments. The company should assess cyber risks introduced by third parties (vendors, ports, agents) and reflect them in the risk assessment and contracts.

Artefacts an auditor will ask for
  • Assessment of third-party cyber risk
  • Reflection of third-party risk in contracts and the risk register
  • Monitoring of significant third parties
Where this commonly fails
  • Third-party risk not assessed
  • Not reflected in contracts
  • No monitoring of third parties

BIMCO Ch7: Develop Protection Measures

BIMCO-7.1
Defence in depth and in breadth

Defence in depth and in breadth. Protection should apply layered (defence in depth) and broad (defence in breadth) measures across people, processes and technology for both IT and OT.

Artefacts an auditor will ask for
  • Layered protection architecture for IT and OT
  • Coverage of people, process and technology controls
  • Network segmentation between IT, OT and external networks
Where this commonly fails
  • Single-layer protection only
  • People/process controls missing
  • No segmentation
BIMCO-7.2
Technical protection measures

Technical protection measures. The company should implement technical protections including network segmentation, access control, wireless access control, system hardening, malware protection and secure configuration of shipboard systems.

Artefacts an auditor will ask for
  • Network segmentation and boundary controls onboard
  • Access control and wireless access control configurations
  • System hardening and secure-configuration baselines
Where this commonly fails
  • No segmentation between IT/OT
  • Default/weak configurations
  • Wireless access uncontrolled
BIMCO-7.3
Procedural protection measures

Procedural protection measures. The company should implement procedural protections including crew training and awareness, physical and removable media controls, upgrade/patch procedures and access management.

Artefacts an auditor will ask for
  • Crew cyber awareness and training programme and records
  • Physical and removable-media control procedures
  • Access management procedures (joiner/mover/leaver, visitors)
Where this commonly fails
  • No crew training
  • Removable media uncontrolled
  • Access not managed

BIMCO Ch8: Develop Detection Measures

BIMCO-8.1
Detection, logging, blocking and alerts

Detection measures. The company should implement detection, logging, blocking and alerting to identify cyber incidents affecting shipboard systems in a timely manner.

Artefacts an auditor will ask for
  • Logging and monitoring of shipboard IT/OT where feasible
  • Alerting and blocking mechanisms
  • Review of logs and alerts
Where this commonly fails
  • No logging/monitoring onboard
  • No alerting
  • Logs not reviewed
BIMCO-8.2
Malware detection

Malware detection. The company should deploy malware detection and prevention appropriate to IT and OT, recognising constraints on OT systems.

Artefacts an auditor will ask for
  • Malware detection/prevention on IT systems
  • Compensating controls where OT cannot run anti-malware
  • Update process for detection signatures
Where this commonly fails
  • No malware detection
  • OT compensating controls absent
  • Signatures not updated

BIMCO Ch9: Establish Contingency Plans

BIMCO-9
Establish contingency plans

Establish contingency plans. The company should establish contingency plans to maintain or restore safe operation of the ship in the event of a cyber incident affecting critical systems, including manual/fallback procedures.

Artefacts an auditor will ask for
  • Contingency plans for loss of critical IT/OT systems
  • Manual or fallback operating procedures
  • Testing of contingency arrangements
Where this commonly fails
  • No contingency plans for critical systems
  • No manual fallback
  • Contingency not tested
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.