Ship owners and operators will need to comply with Resolution MSC.428(98) from 1 January 2021.
The International Maritime Organization (IMO) adopted Resolution MSC.428(98) Maritime Cyber Risk Management in Safety Management Systems on 16 June, 2017 and issued MSC-FAL.1/Circ.3 Guidelines on Maritime Cyber Risk Management on 5 July, 2017.
Whilst recognising that cyber technologies had become essential to the operation and management of numerous systems critical to the safety and security of shipping and the protection of the marine environment, the IMO acknowledged the vulnerabilities of these technologies to cyber risks and cyber threats. Noting that the rapidly changing technologies and threats made it difficult to address these risks only through technical standards, the IMO recommended that cyber risks are addressed in existing safety management systems required by the International Safety Management (ISM) Code. Ship owners and operators will need to comply with Resolution MSC.428(98) from 1 January 2021 (and no later than the first annual verification of the company’s DOC after this date).
MSC-FAL.1/Circ.3 provides guidance on how to conduct an assessment of the cyber risks for complying with the Resolution. Additional guidance is available from publications including The Guidelines on Cyber Security Onboard Ships by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI, the US National Institute of Standards and Technology’s (NIST) Framework and from Members’ Classification Societies.
If Members have any questions on this IMO Resolution, your usual contact at the Club will be pleased to assist you.