Maritime Reader

NEWS INTELLIGENCE ARCHIVE
03 AUG 2026 MONDAY
Advanced filters
Keywords | type to search… Date: All time Sources: All Topics: All
News 09 Nov, 2020 USCG Issue Cyber Risk Management Guidelines Cyber Risk Management Guidelines come into force on 1st January 2021 for all ships trading to the United States.  Download PDF Key points: Every flag state is in scope Serious deficiencies will require fixing and an external audit within 90 days or risk detention Minor deficiencies will need an internal audit within 90 days and the deficiencies to be fixed prior to departure Inspections will only cover networked systems directly relevant to vessel safety Where faults have occurred in systems critical for vessel safety the inspector/port security control officer is mandated to investigate if the cause was ‘cyber -related’, and if so whether the right procedures were followed prior to that fault occurring If the inspector believes there are clear grounds for an expanded inspection, and clear evidence is gathered of poor implementation of the cyber risk management element of the SMS, further deficiencies may be issued The US Coast Guard document focuses on safety and security. Environmental protection remains in scope, but appears deemphasised in the USCG document  USCG Guidance to inspectors - Astaara view Who does this affect? All shipowners rigs and offshore units – of any flag state, that trade or operate in US. What are the USCG looking for when they inspect a ship/ unit? Ideally they will find a vessel that has fully integrated cyber risk management into its SMS, and has ample documentary evidence to prove it. However they have been tasked to look out for evidence of poor cyber hygiene problems, including but not limited to the following: A. Poor cyber hygiene (such as password and/or logins on open display, generic logins or no logins, no automatic logout after a period of inactivity, heavy reliance on USB drives and no obvious means of virus checking prior to use) B. Evidence of malware on ship computers – popups /any ransomware C. Records or complaints of unusual network activity / re
← Back to latest
pi_circular West of England ·2020-11-09

USCG Issue Cyber Risk Management Guidelines

West of England
Read full article at West of England →
Opens West of England in a new tab

Topics & segments

← Back to latest

Related Knowledge

Documents on the same topic from the archive