IACS cyber security requirements mandatory from 2024

Importer
cyber security is a growing concern

The requirements, E26 and E27, are based on recognized international standards for the cyber security of industrial automation and control systems, such as IEC 62443.

DNV has issued a note on the deadline, saying the new IACS URs cover the following main topics:

  • Scope of applicability, including OT systems for important vessel functions
  • Identification and protection against cyber threats
  • Detection of incidents
  • Means to respond and recover.

The technical security requirements of the URs are fully aligned with DNV’s class notations for cyber security and are covered by the current edition of the DNV class notation Cyber secure(Essential).

DNV notes that suppliers of systems within the scope of the URs should be aware that their systems may need further development and design changes to comply with the URs.

The new IACS cyber security requirements can be implemented before 2024 if desired, and DNV will host a webinar on the upcoming IACS URs for cyber security on 23 August 2022.

Until the new URs are in force, DNV encourages product suppliers, shipyards, and shipowners to implement cyber security into control systems, ship design and relevant management systems on board.