Superba Knowledge — Bridging Regulations and Operations Beta
IT/EN
Download
Operational Guide · Registers & Logbooks

Cyber Risk Management in the SMS (MSC.428(98))

The ISM Code has never had a dedicated cyber risk chapter: Resolution MSC.428(98) folded it into the existing risk management framework, making it a mature and auditable requirement from 2021 onward.

ISM Codecyber riskMSC.428(98)SMS

Operational Explanation

Resolution MSC.428(98) (adopted in June 2017) does not introduce a new chapter into the ISM Code, but establishes that cyber risks must be appropriately addressed within the existing Safety Management System, under the Code's general risk management framework (in particular paragraphs 1.2.3.2 and 1.4 on risk assessment and operational procedures). Administrations were encouraged to ensure cyber risks were appropriately addressed in the SMS no later than the first annual verification of the Document of Compliance (DOC) after 1 January 2021: a requirement that is by now mature and well-established, no longer a recent novelty.

Technical support for this requirement is provided by the Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3), revised several times: the latest revision (Rev.3) was approved by the Maritime Safety Committee at its 108th session (May 2024), confirming that the topic remains under active development even years after the requirement was first introduced. The Guidelines structure cyber risk management around five functions: identify, protect, detect, respond and recover.

Regulatory Reference

Resolution MSC.428(98) (June 2017): cyber risks must be appropriately addressed in the SMS under the ISM Code's risk management framework (par. 1.2.3.2, 1.4), no later than the first annual DOC verification after 1 January 2021. Supported by the MSC-FAL.1/Circ.3 Guidelines, latest revision (Rev.3) approved at MSC 108 (May 2024).

Scope of Application

Every Company holding an ISM DOC, covering all IT (information technology) and OT (operational technology, e.g. machinery automation, ECDIS, GMDSS) systems on board and ashore that are relevant to operational safety.

Procedure / How to Complete It

  1. Integrate cyber risk into the SMS's general risk assessment, not as a separate document isolated from the rest of the safety management system.
  2. Apply the five functions of the MSC-FAL.1/Circ.3 Guidelines (Rev.3): identify critical systems, protect them, detect anomalies, respond to incidents and recover operability.
  3. Distinguish and map IT systems (management, communication) and OT systems (machinery automation, navigation, cargo) separately, as they require different countermeasures.
  4. Integrate cyber incidents into the existing NC/Near Miss register, applying the same root cause analysis and CAPA cycle already used for other non-conformities.
  5. Train crew and shore-based personnel on the most common cyber risks (phishing, uncontrolled USB devices, unauthorised remote access to onboard systems).
  6. Verify, at the first subsequent annual DOC verification, that the auditor has documentary evidence of cyber risk integration into the SMS.

Practical Example

Example: a Company maps ECDIS, GMDSS and machinery automation systems as critical OT systems, establishes a control procedure for the use of external USB devices on board, and logs a malware incident detected on a shipboard laptop into the existing NC register, with a corresponding CAPA and effectiveness check.

Real Cases

The absence of a dedicated ISM chapter on cyber risk sometimes leads Companies to treat it as a purely IT matter, managed separately from the rest of the SMS: this is exactly the error Resolution MSC.428(98) is meant to correct, requiring that cyber risk be addressed with the same procedural rigour (risk assessment, procedures, verification, continuous improvement) already applied to other operational risks under the ISM Code.

Common Mistakes Mistake Library

MistakeConsequenceHow to avoid it
Cyber risk managed as a separate IT matter, not integrated into the SMS's general risk assessmentLack of integrated documentary evidence in the event of an audit, despite the existence of technical IT measuresExplicitly integrate cyber risk into the SMS's risk assessment and procedures, not only into the company's IT policy
No distinction between IT and OT systems in the cyber risk assessmentCountermeasures designed for management systems improperly applied to critical automation/navigation systemsMap IT and OT systems separately, with specific countermeasures for each category
Cyber incidents not logged in the existing NC/CAPA cycleLoss of the root cause analysis and continuous improvement opportunity already provided for other non-conformities under the ISM CodeTreat every relevant cyber incident as a full NC, with a corresponding CAPA and effectiveness check

PSC Observations

Certification auditors (DOC/SMC) verify, from the first annual verification after 1 January 2021, the documentary evidence of cyber risk integration into the SMS; PSCOs may treat systemic cyber risk management shortcomings as indicators of an overall weak SMS.

Operational Tips

Checklist

FAQ

Does the ISM Code have a dedicated cyber risk chapter?
No: Resolution MSC.428(98) requires cyber risk to be addressed within the ISM Code's existing risk management framework, not through a new, separate chapter.
Since when has cyber risk management in the SMS been auditable?
Since the first annual verification of the Document of Compliance (DOC) after 1 January 2021.
What are the MSC-FAL.1/Circ.3 Guidelines?
The IMO Guidelines on Maritime Cyber Risk Management, supporting the practical implementation of Resolution MSC.428(98); the latest revision (Rev.3) was approved at MSC 108 (May 2024).
🎬 Additional photos, videos and interactive diagrams for this topic will be available in a future version of the platform.

Related Topics