ISO 23799:2024
Ships and marine technology — Assessment of onboard cyber safety
Ships and marine technology — Assessment of onboard cyber safety
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 18
- Дата публикации:
- 26 января 2024 г.
- Издание:
- ISO IS 23799 edition 1 version 1
- ICS:
- 47.020.01
This document establishes the elements of onboard cyber risk assessment and specifies requirements for the assessment process, assessment preparation, risk identification, risk analysis and risk evaluation. This document applies to the risk assessment of onboard cyber systems based on network technologies which mainly include bridge systems, cargo management systems, propulsion and machinery management and power control systems, access control systems, passenger or visitor servicing and management systems, passenger-facing networks, core infrastructure systems, administrative and crew welfare systems and communication systems.
Abstract
Overview
ISO 23799:2024 - Ships and marine technology - Assessment of onboard cyber safety - defines a structured approach for conducting onboard cyber risk assessments. The standard applies to shipboard network technologies that include bridge systems, cargo management, propulsion and machinery control, power systems, access control, passenger‑facing networks, core infrastructure, administrative/crew welfare systems and communications. It sets out the elements and process for assessing onboard cyber safety: assessment preparation, risk identification, risk analysis and risk evaluation.
Keywords: ISO 23799:2024, onboard cyber safety, shipboard network security, maritime cybersecurity, onboard cyber risk assessment.
Key topics and requirements
- Risk assessment process: Conforms with ISO 31000 and IEC 31010 and comprises four main stages - assessment preparation, risk identification, risk analysis and risk evaluation.
- Assessment preparation: Define objectives, scope, boundaries, form an assessment team, select methods and obtain senior management approval.
- Risk identification: Systematic identification of assets (IT and OT), threats, vulnerabilities and existing control measures across physical, software and data assets. The standard emphasises both IT (information) and OT (operational) distinctions due to differing impact profiles.
- Risk analysis: Evaluate likelihood and impact (consequences) of incident scenarios; use expert judgement where statistical data are absent and apply techniques (e.g., judgement matrices) to check consensus.
- Risk evaluation: Prioritise and rank derived risks against defined assessment criteria to inform mitigation and risk acceptance decisions.
- Documentation and governance: Continuous communication, negotiation and record-keeping throughout the assessment lifecycle; reassess when operational, threat or policy conditions change.
- Scope of systems: Explicitly includes bridge, cargo, propulsion/machinery, power control, access control, passenger services, passenger-facing networks, core infrastructure, administrative systems and communication systems.
Applications and who uses it
ISO 23799:2024 is intended for organisations involved in maritime operations and ship systems design, including:
- Shipowners and operators performing onboard cyber risk assessments and compliance checks
- Shipyards and system integrators during design and installation phases
- Classification societies and flag administrations evaluating shipboard cyber safety
- Maritime cybersecurity teams, risk assessors and consultants conducting vulnerability and threat analyses
- Procurement and maintenance teams, to define contractual security requirements and vendor support obligations
Practical uses include pre‑commissioning risk assessments, periodic security reviews, incident scenario analysis, supplier evaluation, and aligning onboard cyber risk management with operational safety goals.
Related standards
- ISO 31000 - Risk management - Guidelines
- IEC 31010 - Risk assessment techniques
- ISO/IEC 27005:2022 - Information security risk management
- References in the ISO text: MSC‑FAL circulars and IACS recommendations (e.g., IACS Rec.171, UR E26, UR E27) which inform maritime cyber guidance.
Технические детали
- Технический комитет
- ISO/TC 8 - Ships and marine technology
- SKU
- ISO 23799:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 31000:2018
ДействующийRisk management — Guidelines
Overview ISO 31000:2018 - Risk management - Guidelines provides a unified, organization‑wide approach to managing risk. It offers adaptable guidance that can be customized to any organization, sector…
BS EN IEC 31010:2019
ДействующийRisk management. Risk assessment techniques.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…