Skip to content

Evidence request lists

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

IMO MSC-FAL Detect Function

IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms
IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation

Detect is the third of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Anomaly Detection - behavioural baselines for OT systems (bridge equipment patterns + engine room SCADA + propulsion + cargo) + network anomaly detection (deep packet inspection where feasible) + IDS/IPS at perimeter + EDR on IT + threat intelligence integration + maritime-specific TTPs detection (AIS spoofing + GPS jamming + ECDIS chart manipulation + bridge integrity violations). (2) Continuous Monitoring of OT/IT Systems - SIEM where feasible + log aggregation from network devices + servers + ECDIS + radar + AIS + GMDSS + engine room + cargo systems + access control + camera systems + 24/7 monitoring shore-based SOC + dependent on satellite bandwidth + offline buffering during silent satellite periods + on-vessel processing + correlation rules + threat hunting. (3) Bridge and Engine Roo

Artefacts an auditor will ask for
  • Anomaly detection + OT baselines + GPS/AIS spoofing rules + IDS/IPS + threat intel records
  • SIEM + log aggregation + shore-based SOC + satellite bandwidth + offline buffering + correlation
  • Bridge Alarm Mgmt + cyber alarm integration + watchkeeper SOPs + escalation procedure
  • Log retention + tamper-evident + clock sync + VDR cyber dimension + forensics ready + records
  • Crew reporting + Just Culture + Maritime ISAC subscription + USCG alerts + flag State alerts
Where this commonly fails
  • Anomaly detection IT-only (no OT bridge or ECDIS monitoring)
  • SIEM absent or shore-based without offline buffer (silent loss during satellite gap)
  • Bridge alarms cyber-blind (only navigation/engine alarms surface)
  • Log retention insufficient (no forensics + VDR has no cyber events)
  • Crew reluctant to report (no Just Culture + blame-and-train pattern)

IMO MSC-FAL Framework Alignment

IMO-MSC-FAL-FrameworkAlignment-NISTCSF-Identify-Protect-Detect-Respond-Recover-IndustryGuidelinesV4-IEC62443
IMO MSC-FAL Framework Alignment - 5 Functional Elements Map to NIST CSF + Industry Guidelines on Cyber Security Onboard Ships v4 + IEC 62443 + ISO 27001 + USCG NVIC + EU NIS2 + Class Notations

Framework Alignment captures the cross-walk between IMO MSC-FAL.1/Circ.3/Rev.2 5 functional elements and parallel international standards + industry guidance for operational implementation. The IMO 5 Functional Elements explicitly mirror NIST Cybersecurity Framework (CSF) v1.1 / v2.0 Functions: Identify + Protect + Detect + Respond + Recover (NIST CSF v2.0 adds Govern as 6th function which IMO captures in MSC.428(98) SMS integration + governance requirements). Industry Guidelines on Cyber Security Onboard Ships v4 (December 2020, jointly published by BIMCO + ICS + INTERTANKO + INTERCARGO + INTERMANAGER + OCIMF + WSC + IUMI + ICCSA + ICS + AICS + others) provides the operational detail for implementation - structured in same 5 functional elements + provides asset categories + threat catalogue + technical and procedural cyber risk management + practical recommendations + Annexes 1-6 coveri

Artefacts an auditor will ask for
  • IMO 5 functions to NIST CSF v2.0 6-function (incl Govern) mapping + cross-reference matrix
  • Industry Guidelines v4 operational implementation evidence + Annex 1-6 application records
  • IACS UR E26/E27 compliance + class notation + Rec 166 + IACS unified survey scheme
  • IEC 62443 + ISO 27001 + ISMS + ISO 27005 + 27035 + 28001 + 22301 integration map
  • Multi-jurisdictional alignment + USCG NVIC + EU NIS2 + UK Code + AU SOCI + class notation
Where this commonly fails
  • IMO functions implemented without NIST CSF cross-walk (audit fails on translation)
  • Industry Guidelines v4 not integrated as operational detail (high-level only)
  • IACS UR E26/E27 not addressed in newbuild specs or retrofit plan
  • IEC 62443 zones/conduits absent (no industrial cybersecurity architecture)
  • Multi-jurisdictional reporting fragmented (one regulator covered, others missed)

IMO MSC-FAL Govern - Third Party + Supply Chain

IMO-MSC-FAL-Govern-ThirdParty-SupplyChain-Manufacturer-Yard-PortFacility-IACS-E26-E27
IMO MSC-FAL Govern - Third Party Cyber Risk + Supply Chain + Equipment Manufacturer + Yard + Port Facility + IACS UR E26/E27 + Continuous Improvement + Audit

Govern covers third party cyber risk + supply chain + continuous improvement extending from the 5 functional elements per MSC-FAL.1/Circ.3/Rev.2 + Resolution MSC.428(98). Third Party and Supply Chain Risk: covers (1) Equipment manufacturers + vendors - cyber security requirements in procurement specifications + Software Bill of Materials (SBOM) + secure-by-design per IACS UR E26 Cyber Resilience of Ships (1 Jan 2024 newbuild + retrofit by 1 Jan 2026) + IACS UR E27 Cyber Resilience of On-board Systems and Equipment (1 Jan 2024) + IEC 62443-4-1 SDL secure development lifecycle + IEC 62443-4-2 component requirements + manufacturer disclosure of vulnerabilities + secure remote support procedures + access logging + privileged credential management + manufacturer cyber declaration. (2) Shipyards - secure handover + security commissioning + change management at yard + crew training during commi

Artefacts an auditor will ask for
  • Procurement cyber requirements + IACS UR E26/E27 + SBOM + manufacturer cyber declarations
  • Shipyard cyber commissioning + Class Society cyber survey + class notation + RO verification
  • Service provider cyber agreements + remote support audit + port facility coordination + ISPS
  • Annual cyber risk management review + ISM internal audit integration + DOC audit + PSC
  • Continuous improvement + lessons learned + IACS Rec 166 alignment + threat landscape updates
Where this commonly fails
  • Procurement silent on cyber (no IACS E26/E27 requirements in newbuild specs)
  • Shipyard cyber commissioning skipped (vessel handover without cyber baseline)
  • Service providers unmonitored (remote vendor sessions ungated)
  • Cyber risk review off-cycle from ISM (separate annual exercise without DOC integration)
  • Lessons learned not integrated into industry threat intel (one-way consumption)

IMO MSC-FAL Identify Function

IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities
IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

Identify is the first of five functional elements per MSC-FAL.1/Circ.3/Rev.2 (aligned with NIST CSF Identify). Activities include: (1) Asset Inventory of vulnerable systems organisationally + onboard ship - Operational Technology (OT) systems including Bridge Systems (ECDIS + RADAR + AIS + GPS/GNSS + Voyage Data Recorder + Long Range Identification and Tracking LRIT + Integrated Navigation System INS + Dynamic Positioning DP + Autopilot) + Propulsion Power and Machinery Management and Power Control Systems (PMS + Engine Control + Boiler Control) + Cargo Handling and Cargo Management Systems (Loadicator + tank monitoring + reefer + RTM) + Access Control Systems + Passenger Servicing and Management Systems + Passenger-facing Public Networks + Administrative and Crew Welfare Systems + Communication Systems (Inmarsat VSAT + GMDSS + LTE + Wi-Fi); Information Technology (IT) systems including

Artefacts an auditor will ask for
  • OT + IT asset inventory + per Industry Guidelines v4 categories + per vessel + per shore + records
  • Threat catalogue + maritime-specific TTPs + nation-state + GPS/AIS spoofing + ransomware case studies
  • Vulnerability assessment + OT scan + legacy system register + remote support audit + records
  • Cyber risk assessment matrix + Safety/Sec/Env/Ops impact + qualitative + FAIR + records + review
  • Role assignments + DPA + CSO + Cyber Risk Manager + crew responsibilities + RACI + training
Where this commonly fails
  • Asset inventory IT-only (no OT/ICS systems mapped)
  • Threats generic (no GPS/AIS spoofing or maritime-specific TTPs)
  • Vulnerabilities not scanned on OT (legacy and accepting status quo)
  • Risk assessment Safety-only (no Operational/Environmental impact)
  • Roles undefined (Master responsible but no CSO/DPA cyber accountability)

IMO MSC-FAL Protect Function

IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity
IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

Protect is the second of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Access Control - identity and access management for IT + OT systems + role-based access + least privilege + privileged access management (PAM) for OT engineering workstations + multi-factor authentication where feasible + ECDIS/RADAR/AIS console access controlled + bridge wing access + remote vendor support gated through jump server + secure VPN + session monitoring + privileged credential vaulting + USB port lockdown + physical access control to engine control room + DP class areas + server rooms. (2) Network Segmentation - segregate OT (bridge + propulsion + cargo) from IT (ship admin + crew welfare) + DMZ between ship and shore + air-gap critical safety systems where possible (ECDIS chart update via approved process not direct Internet) + zones and conduits per IEC 62443 + microsegmen

Artefacts an auditor will ask for
  • IAM + PAM + MFA records + USB lockdown policy + physical access control to bridge + ECR
  • Network architecture diagram + OT/IT segregation + DMZ + Zones/Conduits per IEC 62443 + firewall rules
  • Malware defence + EDR + USB scanning station + email gateway + maritime ISAC threat feeds
  • Patch management + OT testing + vendor coord + compensating controls register + ECDIS update
  • Awareness training + role-based + simulated phishing + crew BYOD policy + records per crew member
Where this commonly fails
  • IAM weak on OT (shared admin credentials on bridge workstation)
  • OT/IT not segmented (flat network across vessel)
  • Malware defence absent on OT systems (signature AV impossible)
  • Patching deferred on OT due to vendor warranty fears (no compensating controls)
  • Crew awareness annual e-learning only (no role-specific bridge crew cyber training)

IMO MSC-FAL Recover Function

IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills
IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience

Recover is the fifth of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Backup and Restore - prioritised backup of critical OT and IT systems (ECDIS charts + voyage planning + engine control configuration + cargo loading software + crew records + cargo manifests + administrative systems) + backup integrity verification + offline/air-gapped backup retention + secure transport of backup media + restore testing scheduled + restore time objective (RTO) and recovery point objective (RPO) per system. (2) Continuity of Navigation - paper chart fallback + manual celestial navigation + radar navigation + GPS/GNSS resilience + multi-constellation receivers (GPS + GLONASS + Galileo + BeiDou) + alternative position fixing (LORAN where available + dead reckoning) + maintained competency of bridge crew in non-electronic navigation + bridge team management. (3) Continuity o

Artefacts an auditor will ask for
  • Backup + restore + RTO/RPO per system + offline retention + restore tests + records
  • Continuity of navigation + paper chart + multi-GNSS receivers + manual navigation competency
  • Continuity of propulsion + cargo + manual procedures + crew competency + drill records
  • Lessons learned + CAPA per ISM continual improvement + ISAC share-back + industry contribution
  • Cyber drills + tabletop + functional + full-scale + SOLAS integration + Bridge Resource Mgmt
Where this commonly fails
  • Backup IT-only (OT configurations not backed up)
  • Bridge crew lost ability to navigate without ECDIS (no paper-chart competency)
  • Manual propulsion procedures untested in years
  • Lessons learned filed without CAPA or industry contribution
  • Cyber drills paper-only (no full-scale exercise with bridge + shore)

IMO MSC-FAL Respond Function

IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC
IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT

Respond is the fourth of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Cyber Incident Response Plan - integrated with ISM Code Emergency Preparedness procedures + classified by impact tier (Safety-critical vs Operational vs Administrative) + activation criteria + Roles (Master + Chief Engineer + DPA + CSO + Cyber Incident Response Team CIRT) + decision authority for emergency actions (e.g. disconnect from ECDIS chart update server during attack + revert to paper chart navigation + disable AIS during piracy with cyber correlation + revert to manual propulsion control) + integration with bridge and engine room emergency procedures + tabletop and live exercise schedule + drill records. (2) Containment Strategies - network isolation procedures + OT segmentation enforcement + suspected device isolation + USB removal + crew device confiscation procedures + safe m

Artefacts an auditor will ask for
  • Cyber IR plan + ISM Emergency integration + tier classification + activation + roles + CIRT
  • Containment procedures + safe mode + reversion to paper chart + manual steering + drills
  • Reporting matrix + Flag State + Port State + Class + USCG NVIC + EU NIS2 + national CSIRT
  • National CSIRT coordination + Maritime ISAC + forensics readiness + chain of custody
  • Tabletop + live exercise records + drill outcomes + Marine Casualty Investigation integration
Where this commonly fails
  • Cyber IR plan separate from ISM Emergency Manual (no integration)
  • Containment requires shore decision (vessel loses time during attack)
  • Reporting matrix incomplete (USCG NVIC missed for US port calls)
  • No coordination with national CSIRT or Maritime ISAC (siloed)
  • Exercises only on paper (no live drill with bridge crew)

IMO MSC-FAL Scope + ISM Code SMS Integration

IMO-MSC-FAL-Scope-MSC-FAL1Circ3Rev2-MSC42898-2017-1Jan2021-ISMCode-SMS
IMO Maritime Cyber Risk Management Scope - MSC-FAL.1/Circ.3 + Rev.2 + Resolution MSC.428(98) + ISM Code Safety Management System Integration + 1 January 2021 Effective + Senior Management Commitment

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management originally adopted as joint circular MSC-FAL.1/Circ.3 by the Maritime Safety Committee (MSC) at its 98th session 7-16 June 2017 and Facilitation Committee (FAL) at its 41st session 4-7 April 2017. Revision MSC-FAL.1/Circ.3/Rev.1 (June 2021) and current MSC-FAL.1/Circ.3/Rev.2 (2022) updated guidance reflecting evolving cyber threat landscape and industry implementation experience. Provides high-level recommendations on maritime cyber risk management to safeguard shipping from current and emerging cyber threats and vulnerabilities. Complemented by IMO Resolution MSC.428(98) Maritime Cyber Risk Management in Safety Management Systems (adopted 16 June 2017 at MSC 98th session) which AFFIRMS that an approved safety management system should take into account cyber risk management in accordance with the objec

Artefacts an auditor will ask for
  • MSC-FAL.1/Circ.3/Rev.2 adoption + ISM Code SMS integration + verified at DOC annual audit
  • Resolution MSC.428(98) compliance evidence + post-1 Jan 2021 SMS cyber inclusion + records
  • Senior management cyber risk policy + Master/CSO accountability + crew responsibilities
  • OT + IT asset scope per Industry Guidelines v4 categories + SOLAS coordination
  • Flag State coordination + Class Society engagement + Recognised Organisation audit + industry
Where this commonly fails
  • MSC-FAL.1/Circ.3 referenced but not integrated into SMS Manual
  • Resolution MSC.428(98) compliance pro forma without operational audit
  • Senior commitment absent (CSO role unfilled or token)
  • OT systems excluded from scope (IT-only cyber program)
  • Flag State + Class not engaged (vessel operates without verification)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.