Overview
ISO 23806:2022 - Ships and marine technology - Cyber safety - provides requirements and recommendations for establishing, implementing, maintaining and continually improving a cyber risk assessment system within a company’s Safety Management System (SMS). The standard focuses on cyber risks that can affect the safe and environmentally sound operation of ships, particularly risks to Operational Technology (OT) that may have physical safety or pollution consequences. ISO 23806:2022 is intended to be traceable within the SMS by direct inclusion or reference.
Key topics and requirements
- Scope and context: Companies must determine the scope of cyber safety risk assessment based on installed OT, OT/IT integration, operational use, interfaces with third parties and rate of technological change.
- Management commitment: Senior management must demonstrate leadership by embedding cyber risk management into the company’s safety and environmental protection policy, allocating resources, defining roles and authorities, and integrating cyber risk into audits and management review.
- Risk identification and exposure: Identify cyber hazards and risks to ship safety, personnel and the marine environment. Perform generic fleet-level assessments and ship-specific assessments where operational or technical characteristics differ materially.
- OT focus: Emphasis on availability and integrity of OT (bridge systems, propulsion, cargo handling, machinery management, navigation), and on the potential for IT/OT integration to introduce safety-critical impacts.
- Documentation and traceability: Scope, policies, procedures, protective measures and responsibilities should be documented within or referenced by the SMS.
- Detection and reporting: The cyber risk management system shall include actions to detect and report cyber-events in a timely manner.
- Continual improvement: Periodic evaluation of effectiveness, considering OT lifecycle, changes to systems, threats and operational conditions; training and awareness for personnel.
Practical applications and users
ISO 23806:2022 is practical for organizations that operate or manage ships and need to integrate cyber risk into existing safety management frameworks:
- Shipowners, ship managers and operators integrating cyber safety into the ISM-based SMS
- Company safety and security managers responsible for OT/IT governance
- Maritime cyber security teams, compliance officers and internal auditors
- Classification societies, flag administrations and recognized organizations assessing compliance
- Third-party vendors and system integrators providing OT solutions or remote access services
Practical uses include defining the scope of cyber assessments, documenting responsibilities, specifying detection/reporting processes, and embedding cyber risk controls and training into the SMS.
Related standards and guidance
- IMO guidance (MSC-FAL.1/Circ.3) on Maritime Cyber Risk Management
- ISM Code and SOLAS Chapter IX requirements for Safety Management Systems
- ISO/IEC 27000 series (information security principles) - complementary guidance for IT-focused controls
- IMO resolution MSC.428(98) and ISPS Code references on cyber aspects of ship security
Keywords: ISO 23806:2022, ships cyber safety, maritime cyber risk, safety management system, operational technology (OT), shipboard cybersecurity, ISM Code, SOLAS.