press_release Compliance & regulationOperational risk Bureau Veritas
Cyber managed notation Home Press release "Cyber managed" from Bureau Veritas: the pragmatic path to cyber resilience and protection Jan. 20 2020 LinkedIn Twitter Facebook share Cyber Managed is a class notation providing a pragmatic approach to cyber security -reflecting industry needs and cyber security best practiceCyber Managed is based on BV’s rule NR 659 and was co-developed with marine security expertsThe notation will enable shipowners to meet IMO 2021 requirements for cyber securityCyber Managed notation is now being applied to growing number of ships including some large fleetsParis La Défense, 20 January 2020 Bureau Veritas Marine & Offshore (BV) is seeing a rapid growth in the number of ships applying for its ‘Cyber Managed’ notation.The notation was co-developed by BV and external marine security experts as part of joint technical working groups organized by BV. It ensures compliance with the main existing cybersecurity standards (IMO MSC-Fal 1-Circ3, NIST, BIMCO etc.) and will enable shipowners to meet the requirements of IMO’s guidance to administrations that maritime cybersecurity risk should be reflected in ship security practice under the ISM Code by January 1, 2021.Shipowners in Greece have been pioneers in applying the notation and now it is gaining traction with other shipowners and across the entire maritime ecosystem, including ship managers, charterers, insurers, and offshore operators.BV expects that more than 100 ships will be operating under the ‘Cyber Managed’ notation in 2020.Cyber Managed focuses on ensuring that cybersecurity is managed onboard as per industry best practice for change management and traceability of IS/IT systems onboard, emergency procedures and basic security protection measures.Cyber Managed works because it is based on a security risk assessment developed from an initial mapping of onboard systems that result in a practical set of requirements.The initial risk analysis and mapping exercise can be performed either during the newbuilding phase or at any time during the lifecycle of the vessel. As such, the notation is applicable to both new and existing ships.This initial risk analysis results in the definition of mitigation actions that can be achieved through the development of ad-hoc procedures. These procedures are then incorporated into the ship management system (as per IMO MSC-Fal1-Circ3 requirements). The risks may also be mitigated through security protection of remote access and network connections that can usually be performed through software updates. Cyber Managed does not require new equipment to be fitted onboard.Completion of an initial survey on board vessels allows the award of the ‘Cyber Managed’ notation. Annual surveys of similar scope combined with other class surveys ensure regular update of the documentation and crew training, and thus the maintenance of the notation. Image Paillette Palaiologou, Vice President for the Hellenic Black Sea & Adriatic Zone, Bureau Veritas, said: “Cyber Managed provides a holistic yet pragmatic response to cyber threats to keep owners continually protected." Paillette Palaiologou, Vice President for the Hellenic Black Sea & Adriatic Zone, Bureau Veritas, said: “Cyber Managed provides a holistic yet pragmatic response to cyber threats to keep owners continually protected. BV’s network of surveyors are confirming compliance with the notation requirements on ships world-wide for Greek owners. We are stressing the practical – the pragmatic
"Cyber managed" from Bureau Veritas: the pragmatic path to cyber resilience and protection
Bureau Veritas
Read full article at Bureau Veritas →
Opens Bureau Veritas in a new tab