ISM obligation, whole fleet
IMO cyber risk management, judged as a safety management system
Resolution MSC.428(98) put cyber risk inside the ISM Code. That single decision is why this is a superintendent's problem and not an IT department's: it is verified the way every other ISM element is verified — by asking the ship to demonstrate it, and by reading the records.
The expectation was that cyber risk would be addressed in the SMS no later than the first annual verification of the company's Document of Compliance after 1 January 2021. If your SMS has not been reviewed on this point since, the gap is now several verification cycles old — and the fleet has changed in the meantime.
The five functional elements, translated into records
Identify
Ship-specific inventory of computer-based systems and the personnel, data and processes that depend on them. Criticality assigned the same way you assign it to machinery.
Protect
Access control, removable media rules, network segregation, and — the part that gets skipped — a controlled process for vendor remote support.
Detect
The crew reporting abnormal behaviour of a system through the normal non-conformity channel, not a separate route nobody uses.
Respond
A rehearsed contingency for loss of a critical system: which manual procedure applies, who ashore is called, what is recorded.
Recover
Backups that have actually been restored at least once, with the restoration evidenced and dated.
How Full Ahead Maritime carries this
Cyber items are handled as ordinary statutory work: assigned intervals, owners, and evidence captured at the point of work — including offline. Drills, restoration tests and remote-support sessions land in the same audit-ready register as ISM, ISPS, SOLAS and MARPOL, so an auditor gets one export rather than a search.
Common questions
What does IMO Resolution MSC.428(98) require?
It requires that cyber risks be appropriately addressed in the safety management system, and it set the expectation that this would be verified no later than the first annual verification of the company's Document of Compliance after 1 January 2021. In other words: cyber risk management is an ISM matter for the whole managed fleet, not an IT project.
Is there separate guidance on how to do it?
Yes — MSC-FAL.1/Circ.3/Rev.2, the IMO Guidelines on maritime cyber risk management. They are non-prescriptive and functional: identify, protect, detect, respond, recover. They point to industry standards such as the BIMCO Guidelines on Cyber Security Onboard Ships for practical implementation.
How does this differ from IACS UR E26 and E27?
MSC.428(98) is a management-system obligation that applies across your fleet regardless of ship age. IACS UR E26 and E27 are prescriptive class requirements that apply to ships contracted for construction from 1 July 2024. Managers with mixed fleets satisfy both, through different evidence.
What do ISM auditors actually test?
Whether the risk assessment exists and is specific to your ships; whether the crew know what to do when a critical system behaves abnormally; whether incidents and near-misses of a cyber nature are reported through the same channel as any other; whether remote access and software changes are controlled; and whether any of it has been reviewed since it was written.
What is the most common finding?
A policy that was written once, is generic, names systems the ship does not have, and has no records behind it. The document is not the compliance — the operating record is.
Practitioner's summary, not legal advice. Work from the current IMO texts and your flag state's implementing guidance.
Get the changes that affect your SMS
Short, dated briefs — no commentary padding.