<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>IACS - Tag - Maritimeinfosec.org</title><link>https://maritimeinfosec.org/tags/iacs/</link><description>IACS - Tag - Maritimeinfosec.org</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright Maritimeinfosec.org 2018-2026</copyright><lastBuildDate>Thu, 25 Oct 2018 08:27:07 +0000</lastBuildDate><atom:link href="https://maritimeinfosec.org/tags/iacs/" rel="self" type="application/rss+xml"/><item><title>Useful links</title><link>https://maritimeinfosec.org/links/</link><pubDate>Thu, 25 Oct 2018 08:27:07 +0000</pubDate><author>Olivier JACQ</author><guid>https://maritimeinfosec.org/links/</guid><description><![CDATA[<p>A selection of reference websites and documents on maritime and port cybersecurity. This is a long-term effort, so the list is certainly still incomplete. A <a href="https://cybermaretique.fr/liens/" target="_blank" rel="noopener noreferrer ">French version of this page</a> is also available, with the addition of the French national framework.</p>
<h2 id="regulation-standards-and-good-practice">Regulation, standards and good practice</h2>
<ul>
<li>IMO: <a href="https://www.imo.org/en/OurWork/Security/Pages/Cyber-security.aspx" target="_blank" rel="noopener noreferrer ">the International Maritime Organization page on maritime cyber risk</a></li>
<li>IMO: <a href="https://wwwcdn.imo.org/localresources/en/OurWork/Security/Documents/Resolution%20MSC.428%2898%29.pdf" target="_blank" rel="noopener noreferrer ">Resolution MSC.428(98)</a> on maritime cyber risk management in safety management systems</li>
<li>IMO: <a href="https://wwwcdn.imo.org/localresources/en/OurWork/Facilitation/FAL%20related%20nonmandatory%20documents/MSC-FAL.1-Circ.3-Rev.4.pdf" target="_blank" rel="noopener noreferrer ">MSC-FAL.1/Circ.3/Rev.4</a>, Guidelines on maritime cyber risk management, 28 May 2026</li>
<li><a href="https://www.intercargo.org/wp-content/uploads/2024/05/2024-11-14-Guidelines_on_Cyber_Security-v5-final.pdf" target="_blank" rel="noopener noreferrer ">The Guidelines on Cyber Security Onboard Ships</a> (v5), produced by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO and others, also presented on <a href="https://www.bimco.org/about-us-and-our-members/publications/the-guidelines-on-cyber-security-onboard-ships" target="_blank" rel="noopener noreferrer ">the BIMCO website</a></li>
<li>DCSA: <a href="https://dcsa.org/standards/cyber-security/" target="_blank" rel="noopener noreferrer ">implementation guides and templates for cybersecurity on board ships</a></li>
<li>IACS: <a href="https://iacs.org.uk/resolutions/161-180/rec-166-new-corr2-cln/rec-166-new-corr2-cln" target="_blank" rel="noopener noreferrer ">Recommendation on cyber resilience, Rec 166</a></li>
<li>ISO/IEC: <a href="https://www.iso.org/standard/27001" target="_blank" rel="noopener noreferrer ">ISO/IEC 27001, information security management systems</a></li>
<li>NIST: <a href="https://www.nist.gov/cyberframework" target="_blank" rel="noopener noreferrer ">the Cybersecurity Framework</a>, referenced by the IMO guidelines</li>
<li>ENISA: <a href="https://www.enisa.europa.eu/publications/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector" target="_blank" rel="noopener noreferrer ">Good practices for cybersecurity in the maritime sector, port security</a></li>
<li>EMSA: <a href="https://emsa.europa.eu/publications/download/7660/5074/23.html" target="_blank" rel="noopener noreferrer ">MARSEC 9209 publication</a></li>
<li>IAPH: <a href="https://sustainableworldports.org/wp-content/uploads/IAPH-Cybersecurity-Guidelines-Version-2-0.pdf" target="_blank" rel="noopener noreferrer ">Cybersecurity Guidelines for Ports and Port Facilities</a> (v2.0)</li>
<li>IAPH: <a href="https://wwwcdn.imo.org/localresources/en/OurWork/Security/Documents/IAPH%20Cyber%20resilience%20guidelines%20for%20emerging%20technologies%20in%20the%20maritime%20supply%20chain%20ENG.pdf" target="_blank" rel="noopener noreferrer ">Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain</a>, added as a reference by MSC-FAL.1/Circ.3/Rev.4</li>
<li>EU: <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj" target="_blank" rel="noopener noreferrer ">Directive (EU) 2022/2555 (NIS2)</a></li>
<li>EU: <a href="https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32004R0725" target="_blank" rel="noopener noreferrer ">Regulation (EC) No 725/2004 on enhancing ship and port facility security</a></li>
<li>UK Department for Transport: <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/642598/cyber-security-code-of-practice-for-ships.pdf" target="_blank" rel="noopener noreferrer ">Code of Practice, Cyber Security for Ships</a></li>
<li>UK Department for Transport: <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/859925/cyber-security-for-ports-and-port-systems-code-of-practice.pdf" target="_blank" rel="noopener noreferrer ">Good Practice Guide, Cyber Security for Ports and Port Systems</a></li>
<li>United States: <a href="https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system" target="_blank" rel="noopener noreferrer ">Cybersecurity in the Marine Transportation System</a>, the US Coast Guard final rule published in the Federal Register</li>
<li>United States: <a href="https://safety4sea.com/wp-content/uploads/2020/11/USCG-CVC-WI-027-%E2%80%9CVessel-Cyber-Risk-Management%E2%80%9D-2020_10.pdf" target="_blank" rel="noopener noreferrer ">USCG Office of Commercial Vessel Compliance, Vessel Cyber Risk Management Work Instruction</a></li>
</ul>
<h2 id="ecosystem">Ecosystem</h2>
<ul>
<li><a href="https://www.normacyber.no/" target="_blank" rel="noopener noreferrer ">NORMA Cyber</a>, the Norwegian Maritime Cyber Resilience Centre</li>
<li><a href="https://www.mtsisac.org/" target="_blank" rel="noopener noreferrer ">MTS-ISAC</a>, the Maritime Transportation System Information Sharing and Analysis Center</li>
<li><a href="https://www.iaphworldports.org/" target="_blank" rel="noopener noreferrer ">IAPH</a>, the International Association of Ports and Harbors</li>
</ul>
<h2 id="classification-and-certification">Classification and certification</h2>
<ul>
<li>IACS: <a href="https://iacs.org.uk/resolutions/unified-requirements/ur-e" target="_blank" rel="noopener noreferrer ">Unified Requirements E26 and E27</a> on the cyber resilience of ships and of onboard systems and equipment</li>
<li>Bureau Veritas: <a href="https://marine-offshore.bureauveritas.com/nr659-rules-cyber-security-classification-marine-units" target="_blank" rel="noopener noreferrer ">NR 659, Rules on Cybersecurity for the Classification of Marine Units</a></li>
<li>Bureau Veritas: <a href="https://marine-offshore.bureauveritas.com/sites/g/files/zypfnx136/files/media/document/642-NR_2018-07.pdf" target="_blank" rel="noopener noreferrer ">NR 642, Cybersecurity Requirements for Products to be Installed On-Board Naval Ships</a></li>
<li>ClassNK: <a href="https://www.classnk.or.jp/hp/en/info_service/cyber/" target="_blank" rel="noopener noreferrer ">cyber security services and guidelines</a></li>
<li>DNV: <a href="https://www.dnv.com/siteassets/images/pdf-documents/dnv-gl-rp-0496.pdf" target="_blank" rel="noopener noreferrer ">RP-0496, Cyber security resilience management for ships and mobile offshore units in operation</a>, and <a href="https://www.dnv.com/maritime/insights/topics/maritime-cyber-security/index.html" target="_blank" rel="noopener noreferrer ">the DNV maritime cyber security pages</a></li>
</ul>
<h2 id="research">Research</h2>
<ul>
<li><a href="https://www.plymouth.ac.uk/research/maritime-cyber-threats-research-group" target="_blank" rel="noopener noreferrer ">Maritime Cyber Threats Research Group (University of Plymouth, United Kingdom)</a>: the group works on decision support, supply chain vulnerabilities, the cybersecurity of autonomous ships and the human factor.</li>
<li>In the summer of 2013, researchers from the University of Texas ran <a href="https://news.utexas.edu/2013/07/29/ut-austin-researchers-successfully-spoof-an-80-million-yacht-at-sea/" target="_blank" rel="noopener noreferrer ">the first GPS spoofing experiments against a luxury yacht at sea</a>.</li>
</ul>
<h2 id="reports-and-vulnerability-research">Reports and vulnerability research</h2>
<ul>
<li><a href="https://ioactive.com/pdfs/IOActive_SATCOM_Security_WhitePaper.pdf" target="_blank" rel="noopener noreferrer ">IOActive report on the vulnerabilities of satellite terminals</a></li>
<li><a href="https://www.pentestpartners.com/security-blog/sinking-container-ships-by-hacking-load-plan-software/" target="_blank" rel="noopener noreferrer ">Pentest Partners on vulnerabilities in container ship load planning software</a></li>
<li><a href="https://www.pentestpartners.com/security-blog/osint-from-ship-satcoms/" target="_blank" rel="noopener noreferrer ">Pentest Partners on OSINT and social engineering risks around ship satellite communications</a></li>
<li><a href="https://info.publicintelligence.net/DHS-SeaportCyberAttacks.pdf" target="_blank" rel="noopener noreferrer ">A US Department of Homeland Security document on the cyber risks of port operations</a></li>
</ul>
<h2 id="awareness-videos">Awareness videos</h2>
<p>Most of the awareness videos I collect are gathered in a dedicated YouTube playlist:</p>]]></description></item></channel></rss>