ISM cyber security race starts on 1 January
At first sight, the 2017 IMO resolution behind the change – MSC.428(98) – seems vague and undefined: in its crucial sentence, it “encourages administrations to ensure that cyber risks are appropriately addressed in safety management systems no later than the first annual verification of the company’s Document of Compliance after 1 January 2021.”
One class society that offers a cyber security class notation, DNV GL, acknowledges this lack of detail on its website where, as well as the revised ISM Code, it refers to IMO’s Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3) that were released in July 2017. “As both leave much of the interpretation to the company responsible for the safety management system, there are still many uncertainties of how to handle the requirements,” it remarks.
When The Motorship spoke to Jarle Coll Blomhoff, DNV GL’s group leader for cyber safety and security, in late November, his reaction underlined its apparent subjectivity. Shipowners will make their own risk assessments about how important cyber risk is to them which, at one extreme, could involve a full overview of all systems on board and involve every department in the company, he said.
On the other hand, an owner might consider a ship to be low risk if it is not connected to any external networks and those coming on board are restricted about how they use their own devices. In that scenario, some training and regular risk assessments would probably be accepted as a compliant response.
The Motorship also suggested to him that the resolution’s use of the word ‘encourages’ implied that it was not mandatory, but he insisted this was not the case. Because it has been incorporated into the ISM Code, which is mandatory, “this is also mandatory,” he said.
Although the ISM Code does not apply to manufacturing companies, they should consider the risks and potential actions that ship managers will have to consider as a result of this amendment and review how they can support their customers, Mr Blomhoff said during a webinar about cyber security shortly before our conversation.
During his presentation, he described three levels of risk, representing them as three concentric rings and describing the potential cyber risks of each one. There should be protection between each ring, he said.
His outer ring represented physical access to systems – such as USB ports – while the middle one illustrated the risks from system integration. For example, if someone connects an infected device to the system, how far can its malware reach? It should not be able to reach the engine control system, he advised. The inner ring reflected the need for barriers for individual systems, for example by using encryption and passwords that are only known by those who need them.
Yet he told the webinar’s attendees that this goes beyond what the revised ISM Code will require, which can be satisfied addressing only physical security, he suggested. “Over time, IMO will look into more technical measures,” he predicted.
So when DNV GL developed its cyber security class notation it looked beyond the ISM Code to an existing standard issued by the International Electrotechnical Commission (IEC). IEC 62443 covers networked control systems in many industries and “is probably the one that engine manufacturers should look towards,” he told The Motorship.
For its own notation – which was launched in July 2018 and revised in February 2020 – DNV GL selected relevant parts of that standard and is now working with machinery manufacturers with a view to issuing them with certificates to confirm that they have incorporated suitable cyber security barriers to make their systems secure.
Mr Blomhoff offered readers some practical advice to improving cybersecurity for machinery installation: “never connect your engine control system to the IT or crew zones,” he said. “And if there’s a connection where you take out data … you should have a boundary control or a firewall [that] controls communication towards it.”
These are requirements in DNV GL’s notation, along with a requirement for an audit log of security-related events so that if something happens, it is possible to discover why it happened and improve the system afterwards.
Although the ISM revisions are only now coming into force, many ship operators have already incorporated cyber security strategies into their management systems. Tanker owners, in particular, have responded to the commercial implications since OCIMF added cyber security to its Tanker Management Self Assessment (TMSA) programme in January 2018. This puts them ahead of other sectors in meeting the revised ISM requirement, Mr Blomhoff said.