Overview
ISO 23799:2024 - Ships and marine technology - Assessment of onboard cyber safety - defines a structured approach for conducting onboard cyber risk assessments. The standard applies to shipboard network technologies that include bridge systems, cargo management, propulsion and machinery control, power systems, access control, passenger‑facing networks, core infrastructure, administrative/crew welfare systems and communications. It sets out the elements and process for assessing onboard cyber safety: assessment preparation, risk identification, risk analysis and risk evaluation.
Keywords: ISO 23799:2024, onboard cyber safety, shipboard network security, maritime cybersecurity, onboard cyber risk assessment.
Key topics and requirements
- Risk assessment process: Conforms with ISO 31000 and IEC 31010 and comprises four main stages - assessment preparation, risk identification, risk analysis and risk evaluation.
- Assessment preparation: Define objectives, scope, boundaries, form an assessment team, select methods and obtain senior management approval.
- Risk identification: Systematic identification of assets (IT and OT), threats, vulnerabilities and existing control measures across physical, software and data assets. The standard emphasises both IT (information) and OT (operational) distinctions due to differing impact profiles.
- Risk analysis: Evaluate likelihood and impact (consequences) of incident scenarios; use expert judgement where statistical data are absent and apply techniques (e.g., judgement matrices) to check consensus.
- Risk evaluation: Prioritise and rank derived risks against defined assessment criteria to inform mitigation and risk acceptance decisions.
- Documentation and governance: Continuous communication, negotiation and record-keeping throughout the assessment lifecycle; reassess when operational, threat or policy conditions change.
- Scope of systems: Explicitly includes bridge, cargo, propulsion/machinery, power control, access control, passenger services, passenger-facing networks, core infrastructure, administrative systems and communication systems.
Applications and who uses it
ISO 23799:2024 is intended for organisations involved in maritime operations and ship systems design, including:
- Shipowners and operators performing onboard cyber risk assessments and compliance checks
- Shipyards and system integrators during design and installation phases
- Classification societies and flag administrations evaluating shipboard cyber safety
- Maritime cybersecurity teams, risk assessors and consultants conducting vulnerability and threat analyses
- Procurement and maintenance teams, to define contractual security requirements and vendor support obligations
Practical uses include pre‑commissioning risk assessments, periodic security reviews, incident scenario analysis, supplier evaluation, and aligning onboard cyber risk management with operational safety goals.
Related standards
- ISO 31000 - Risk management - Guidelines
- IEC 31010 - Risk assessment techniques
- ISO/IEC 27005:2022 - Information security risk management
- References in the ISO text: MSC‑FAL circulars and IACS recommendations (e.g., IACS Rec.171, UR E26, UR E27) which inform maritime cyber guidance.