Cyber Resilience of Ships: An Evaluation of Guideline and Frameworks

The increasing adoption of smart ship design and the rising proportion of IT equipment on ships have significantly increased the frequency and severity of maritime cyber incidents. To address this issue, the International Association of Classification Societies introduced UR E26 in 2022. However, co...

Full description

Saved in:
Bibliographic Details
Main Authors: Jin Kim, Sam Youl Lee
Format: Article
Language:English
Published: IEEE 2025-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/11007106/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:The increasing adoption of smart ship design and the rising proportion of IT equipment on ships have significantly increased the frequency and severity of maritime cyber incidents. To address this issue, the International Association of Classification Societies introduced UR E26 in 2022. However, compared to the cybersecurity frameworks established by the National Institute of Standards and Technology (NIST), such as the Cybersecurity Framework (CSF) and Cyber Resilient Systems (CRS), Unified Requirement (UR) E26 lacks comprehensiveness and specificity. This study employed the Analytic Hierarchy Process (AHP) method to assess the prioritization of key elements of UR E26 across the four stages of the ship lifecycle, based on pairwise comparison surveys from 18 maritime cybersecurity experts. The analysis revealed that the critical elements of UR E26 vary by lifecycle phase and that UR E26 fails to adequately address these phase-specific requirements. In the comparative framework analysis, UR E26 was found to align with only 8.5% of the evaluation items in NIST CSF and 53.8% of the objectives in NIST CRS, indicating significant gaps in coverage. Furthermore, this study proposes practical improvement measures for UR E26 to enhance its applicability and effectiveness, ultimately contributing to the advancement of cyber resilience in the maritime industry.
ISSN:2169-3536