Guidelines - Cyber Risk Management for Ports
CYBER RISK MANAGEMENT FOR PORTS December 2020
CYBER RISK MANAGEMENT FOR PORTS Guidelines for cybersecurity in the maritime sector DECEMBER 2020
CYBER RISK MANAGEMENT FOR PORTS
December 2020
ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. For more information, visit www.enisa.europa.eu. CONTACT For contacting the authors please use resilience@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu. AUTHORS Dr. Athanasios Drougkas, Anna Sarri, Pinelopi Kyranoudi, EU Agency for Cybersecurity ACKNOWLEDGEMENTS For providing valuable information that helped shape the report (in alphabetical order): Peter Alkema, Strategic Policy Advisor and Project Manager, Harbour Master’s Office, Port of Amsterdam Sylvie Andraud, Maritime Sector Coordinator, The National Cybersecurity Agency of France (ANSSI) Jérôme Besancenot, CIO, HAROPA Port of Le Havre Javier Castillejo Reyes, Head of Maritime Safety&Security Unit, Spanish Maritime Administration Rafael Company, Director of Safety and Security, Fundación Valenciaport Joost Daem, CISO, PSA Antwerp Neil Davis, Head of Cybersecurity Risk Management, A.P. Moller Maersk Chris Day, Senior Cybersecurity Consultant - OT, A.P. Moller Maersk Aymeric de Marcellus, Senior Project Officer, Unit Safety & Security / Department Safety, Security and Surveillance, EMSA Simone Fortin, Head of Cybersecurity, MSC Cruises Luca Gargano, Project Officer for Maritime Security - Unit Safety & Security / Department Safety, Security and Surveillance, EMSA Amol Ghatol, Cybersecurity Risk Manager, A.P. Moller Maersk Soren Martin Hansen, Port Inspector, Danish Transport, Construction, and Housing Authority Yannick Herrebaut, Cyber Resilience Manager - CISO, Port of Antwerp Lance Kaneshiro, Chief Information Officer, Port of Los Angeles Indrek Korela, Information Security Manager, Port of Tallinn Niels Martin Madsen, Head of Section, Department for Aviation & Railway Security, Cyber- and Information Security Unit (DCIS), Danish Transport, Construction, and Housing Authority Ilias Manos, IT Security Officer, Piraeus Port Authority Flavio Marangi, CyberSecurity and Space Officer, Italian Ministry of Infrastructure and Transport - Central Security Unit Ethan Moore, Cybersecurity Risk Manager, A.P. Moller Maersk Machiel Noijen, Safety & Security Advisor, Harbour Master’s Office,, Port of Amsterdam CYBER RISK MANAGEMENT FOR PORTS
December 2020
Ruben Panés Butrón, Project Officer – Unit Safety & Security / Department Safety, Security and Surveillance, EMSA Ricardo Pinto, IT Security Officer, PSA Sines Díaz Puyol María del Carmen, Marine Surveyor, Barcelona Harbour Master Office Jan Schirrmacher, Port Cyber Security Officer, Bremenports Ward Veltman, Cyber Security & Risk Officer, Port of Rotterdam Belle Webster, Head of IT and Cybersecurity, Port of Amsterdam LEGAL NOTICE Notice must be taken that this publication represents the views and interpretations of ENISA, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 2019/881. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2020 Reproduction is authorised provided the source is acknowledged. For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. ISBN 978-92-9204-403-9 - DOI 10.2824/671060 CYBER RISK MANAGEMENT FOR PORTS
December 2020
TABLE OF CONTENTS
1. INTRODUCTION 8 1.1 BACKGROUND 8 1.2 STUDY OBJECTIVES 9 1.3 STUDY SCOPE 9 1.4 TARGET AUDIENCE 9 1.5 USING THIS DOCUMENT 10 1.6 METHODOLOGICAL APPROACH 11 2. IDENTIFYING CYBER-RELATED ASSETS AND SERVICES 12 2.1 GUIDELINES FOR IDENTIFYING CYBER-RELATED ASSETS AND SERVICES 12 2.2 RELATED CHALLENGES 13 2.3 RELATED GOOD PRACTICES 14 3. IDENTIFYING AND EVALUATING CYBER-RELATED RISKS 16 3.1 GUIDELINES FOR IDENTIFYING AND EVALUATING CYBER-RELATED RISKS 16 3.2 RELATED CHALLENGES 17 3.3 RELATED GOOD PRACTICES 18 4. IDENTIFYING SECURITY MEASURES 20 4.1 GUIDELINES FOR IDENTIFYING SECURITY MEASURES 20 4.2 RELATED CHALLENGES 26 4.3 RELATED GOOD PRACTICES 26 5. ASSESSING CYBERSECURITY MATURITY 28 5.1 INTRODUCTION 28 5.2 RELATED CHALLENGES 29 CYBER RISK MANAGEMENT FOR PORTS
December 2020
5.3 RELATED GOOD PRACTICES 29 5.4 PORT CYBERSECURITY MATURITY LEVELS 31 5.5 MATURITY LEVELS FOR PORT CYBERSECURITY MEASURES 33 5.5.1 Policies 33 5.5.2 Organisational practices 39 5.5.3 Technical measures 44 6. SUMMARY 53 A ANNEX: NATIONAL APPROACHES 54 B ANNEX: INDUSTRY STANDARDS AND METHODOLOGIES 55 CYBER RISK MANAGEMENT FOR PORTS
December 2020
FIGURES AND TABLES
TABLES Table 1: Mapping of security measures to assets and threats 21 Table 2: Maturity level definitions 32 Table 3: Standards and methodologies currently used by port stakeholders 55 FIGURES Figure 1: Cyber risk management phases 10 Figure 2: Methodology adopted for the study 11 Figure 3: High-level categories of port assets and services 13 Figure 4: Mapping of good practices against challenges in identifying and evaluating cyberrelated assets and services 15 Figure 5: High-level categories of threats and possible impacts of cybersecurity incidents 17 Figure 6: Mapping of good practices against challenges in identifying and evaluating cyberrelated risks 19 Figure 7: Mapping of good practices against challenges in selecting and prioritising mitigation measures 27 Figure 8: Mapping of good practices against challenges in addressing cybersecurity maturity 31 CYBER RISK MANAGEMENT FOR PORTS
December 2020
EXECUTIVE SUMMARY
Over the last few years EU port operators have started to gradually address cyber risks as part of their security risk management processes in a more systematic manner. However, contrary to traditional security risk management, addressing cyber risks introduces entirely new challenges for port operators who often lack the internal expertise, organisational structure and processes or the resources to effectively assess and mitigate them. Moreover, the nature of port operations and, especially, the interconnectedness and service inter-dependencies across port ecosystems requires all involved operators to achieve and maintain a baseline level of cybersecurity. This report aims to provide port operators with good practices for cyber risk assessment that they can adapt to whatever risk assessment methodology they follow. In order to achieve this, this report introduces a four-phase approach to cyber risk management for port operators, which follows common risk management principles and is mapped to the steps of the risk assessment methodology that is laid out in the ISPS Code and relevant EU legislation for Port and Port Facility Security. Specifically, the four phases are: Phase 1: Identifying cyber-related assets and services Phase 2: Identifying and evaluating cyber-related risks Phase 3: Identifying security measures Phase 4: Assessing cybersecurity maturity For each of these phases, this report provides actionable guidelines to assist port operators in their efforts, lists common challenges associated with the performance of the relevant activities, good practices that can be readily adopted and customised by individual organisations and a mapping of the listed good practices for each phase with the respective challenges they address. The proposed guidelines and good practices may be adapted to any common cyber risk management methodology and can be tailored to the unique characteristics of port operators of different sizes, cybersecurity maturity, information security budgets and operational scope. Phase four of this approach also introduces a model for port operators to perform cybersecurity maturity self-assessment founded on the selected security measures and to identify priorities for investing resources for either improving on or building an organisational cybersecurity maturity program. CYBER RISK MANAGEMENT FOR PORTS
December 2020
1. INTRODUCTION
Ports serve a critical function in facilitating domestic and international supply-chain activities by connecting sea and inland transport services. In the EU seaports play a significant role, supporting 90 percent of EU exports and an additional 43 percent of internal market exchange . Ports are considered as critical information infrastructure for water transport. The Directive 2016/1148 (NIS Directive) classifies managing bodies of ports (defined as “any specified area of land and water, with boundaries defined by the Member State MS in which the port is situated, containing works and equipment designed to facilitate commercial maritime transport operations” in the Directive 2005/65/EC ), including their port facilities (defined as “a location where the ship/port interface takes place; this includes areas such as anchorages, awaiting berths and approaches from seaward, as appropriate” in the Regulation (EC) No 725/2004 ) and entities operating works and equipment contained within ports as eligible to be identified as Operators of Essential Services (OES). This report builds on the Port Cybersecurity: Good Practices for Cybersecurity in the Maritime Sector report published in November 2019 by ENISA, the EU Agency for Cybersecurity and provides additional guidelines to port operators for managing their cyber risks. 1.1 BACKGROUND The NIS Directive requires OES to conduct risk assessments that “cover all operations including the security, integrity and resilience of network and information systems” . According to the NIS Directive, these risk assessments, along with the implementation of appropriate mitigation measures, should promote “a culture of risk management” to be developed through “appropriate regulatory requirements and voluntary industry practices” . While some EU Member States (MS) have issued relevant guidance to port operators on how to conduct cyber risk assessment (see Annex A for reference), most port operators have chosen to adopt one of the different methodologies introduced in the various industry standards (see Annex B for reference). However, there is no common methodology for port cyber risk assessment. Of the three types of port OES defined in the NIS Directive, the closest framework to a common risk assessment methodology is the International Maritime Organisation’s International Ship and Port Facility Security (ISPS) Code, which concerns port facilities / terminal operators. The ISPS code is implemented in the EU by Regulation 725/2004 and ensures that port facilities implement Port Facility Security Assessments (PFSAs) and Port Facility Security Plans (PFSPs). The ISPS Code focuses primarily on physical security, though Part B, paragraph 15.3.5 of the Code recommends that the PFSA address computer systems and networks. It further specifically identifies radio and telecommunication systems, including computer systems and networks, and associated procedural policies. The ISPS code also defines minimum port facility security assessment elements/steps. EU Directive 2005/65 on enhancing port security introduces similar requirements and extends them to ports, namely with the CYBER RISK MANAGEMENT FOR PORTS
December 2020
implementation of Port Security Plans (PSP) and Port Security Assessments (PSA). These measures should apply to all ports in which one or more port facilities covered by Regulation (EC) No 725/2004 are situated. Annex I of the Directive describes the minimum requirements for conducting a PSA in the same manner as Regulation 725/2004. PSAs shall take due account of the specificities of different sections of a port and, where deemed applicable by the relevant authority of the MS, of its adjacent areas if these have an impact on security in the port and shall take into account the assessments for port facilities within their boundaries as carried out pursuant to Regulation (EC) No 725/2004. Stocktaking for this report revealed that a fragmented approach in the performance of cyber risk assessments occurs across the EU port sector. Almost without exception, each port’s attempt to address cyber risk within context of existing security risk assessment frameworks and standards, followed a unique approach. Even more, port facilities complying with ISPS Code requirements indicated that significant gaps emerged in their organisational cyber risk assessments. Inconsistent approaches represented only half the challenge. Key aspects of organisations were left un-assessed due to a variety of factors that included but were not limited to port resource availability and variability, variations in stakeholder knowledge and degrees of engagement, compliance based focus, and inconsistent perceptions in how cyber risk can affect a port facility’s operations. 1.2 STUDY OBJECTIVES This report aims to provide port operators with a set of guidelines and good practices to effectively manage commonly referenced cyber risk management challenges. Specifically, the objectives of this report are established to provide port operators with: Good practices for cyber risk assessment that can be adapted to a range of risk assessment methodologies; Actionable guidelines that make effective use of the taxonomies (e.g. assets, threats etc.) presented in the 2019 ENISA report; and, A framework for identifying appropriate cybersecurity measures to address cyber risks and to conduct a cybersecurity maturity self-assessment that will facilitate the development, prioritisation, and efficient allocation of cybersecurity budgets. 1.3 STUDY SCOPE This study outlines good practices for cyber risk management in the maritime port ecosystem concerning both IT systems and OT systems. The port ecosystem comprises all the stakeholder groups involved in port operations: port managing bodies (Port Authorities, terminal and facility operators), national authorities (customs, police, cities, etc.), transport companies (shipping companies, railway companies, etc.) and all the service providers essential to port operations (oil companies, energy companies, etc.). 1.4 TARGET AUDIENCE The primary target audience of this study are people responsible for cybersecurity (CISOs, CIOs etc.) within operators in the port ecosystem, namely Port Authorities; Port facilities / terminal operators; Other entities operating within ports. In addition, the study can be useful for National Competent Authorities who may wish to develop guidance for port operators to support them in conducting cyber risk assessment or cybersecurity maturity self-assessment. CYBER RISK MANAGEMENT FOR PORTS
December 2020
1.5 USING THIS DOCUMENT This report introduces a four-phase approach to cyber risk management for port operators, 10 11 which follows common principles of risk management . The approach is not intended to provide a comprehensive methodology for cyber risk management but rather provide actionable guidelines for managing cyber risk that can be mapped to any framework or methodology the port operator is currently using or may wish to use. The first three phases are also mapped to the steps of the risk assessment methodology (minimum assessment requirements) articulated in the ISPS Code, Regulation 725/2004 and described in Annex I of Directive 2005/65. The fourth phase introduces a model for port operators to employ in performing cybersecurity maturity self-assessments for the selected security measures, identifying priorities for investing resources for improvement and/or building the programmatic foundations for organisational cybersecurity maturity. The four phases are: Phase 1: Identifying cyber-related assets and services (ISPS Code Section 15.5.1: Identification and evaluation of important assets and infrastructure it is important to protect) Phase 2: Identifying and evaluating cyber-related risks (ISPS Code Section 15.5.2: Identification of possible threats to the assets and infrastructure and the likelihood of their occurrence, in order to establish and prioritize security measures, ISPS Code Section 15.5.4: Identification of weaknesses, including human factors in the infrastructure, policies and procedures) Phase 3: Identifying security measures (ISPS Code Section 15.5.3: Identification, selection and prioritization of counter measures and procedural changes and their level of effectiveness in reducing vulnerability) Phase 4: Assessing cybersecurity maturity Figure 1: Cyber risk management phases Each of these four phases is reviewed in Chapters 2 – 5, respectively, with a specific emphasis on the following themes: Actionable guidelines to assist port operators in their efforts to perform each phase. These include specific guidance in how to effectively apply the various taxonomies presented in ENISA’s Port Cybersecurity report of 2019 . Challenges associated with the performance of activities as reported by port stakeholders who were interviewed/surveyed for this report. Good practices that can be readily adopted and customised by individual organisations and easily tailored and integrated into any risk assessment methodology utilised by port operators. A mapping of the listed good practices for each phase with the respective challenges they address. CYBER RISK MANAGEMENT FOR PORTS
December 2020
1.6 METHODOLOGICAL APPROACH Figure 2: Methodology adopted for the study Task 1 - Definition of the project scope and identification of experts: This first step consisted of establishing the scope of the project and selecting subject matter experts whose input and insights were considered for the development of the report. Task 2 - Desktop research: This involved the collection of information from reports, white papers, and guidelines, as well as EU and (inter-)national regulations and industry-specific standards concerning cybersecurity risk management and relevant maturity models. Task 3 - Questionnaire and series of interviews with selected subject matter experts: During this task interviews were conducted and an online survey was designed and published by ENISA to collect additional information. Specifically, 18 semi-structured interviews were performed with stakeholders representing 11 EU Member States and 49 responses were collected from the survey, which collectively represented a wide cross-section of port industry stakeholders from 16 EU member states. Overall, inputs were collected from 20 port authorities, 17 terminal operators, 6 EU National Competent Authorities including EMSA, 17 shipping companies, 4 service providers and an EU research institute. Task 4 - Analysis of collected material and report development: All inputs collected from desktop research efforts and collaboration with stakeholders were thoroughly analysed. Based on this analysis, the first draft of this report was developed. Task 5 - Review and validation: The report was reviewed with and subsequently validated by ENISA's subject matter experts. Feedback was solicited and provided by experts throughout this process. CYBER RISK MANAGEMENT FOR PORTS
December 2020
2. IDENTIFYING CYBER-RELATED ASSETS AND SERVICES
2.1 GUIDELINES FOR IDENTIFYING CYBER-RELATED ASSETS AND SERVICES Phase one focuses on the identification of key IT and OT assets and the port services they support. In general, port operators should follow a service-based risk assessment in order to focus mainly on the aggregated business/operational impact of risks, However, port operators functioning at a more nascent stage of cybersecurity maturity will likely focus initial efforts on asset identification and enumeration. The identification and evaluation of these assets, systems and services is not necessarily constrained to the organisation’s own operational ecosystem. Ports represent complex ecosystems where assets and systems are increasingly integrated and interconnected, resulting in service-based interdependencies and voluminous data exchanges that occur every day. At the same time external third-party stakeholders (partners, vendors) frequently request or maintain continuous access to port IT/OT assets, systems, supporting infrastructure, and data, exponentially increasing the attack surface for potential malicious cyber threat actors. With all those touch points, especially those found in port community system enabled environments, vulnerabilities will inevitably arise. Within the context of this digital environment the port must be able to assess its ability to continue provisioning services in the event an asset, system or service is rendered unavailable as a result of a cyber incident, and also understand the extent to which rapid re-establishment of normal operation is possible. Specific actions that port operators can perform include: Identify cyber-related assets and related services Develop indicators to assess cybersecurity incident impact on cyber-related assets and related services (e.g. number of users affected, economic impact, environmental impact, recovery time objectives etc.) Assess impact on the availability of cyber-related assets and related services Assess impact on the integrity of cyber-related assets and related services Assess impact on the confidentiality of cyber-related assets and related services Identify internal dependencies Identify external dependencies with third parties ENISA’s 2019 report on Port Cybersecurity identifies the main port services and infrastructure and presents a port asset taxonomy. Port operators can use the proposed taxonomies as the basis to identify their key cyber-related assets and services. The high-level categories of these assets and services are depicted in Figure 3, while the ENISA 2019 report provides a detailed description of each taxonomy. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Figure 3: High-level categories of port assets and services 2.2 RELATED CHALLENGES Difficulty in identifying vulnerable IT and OT systems. As different departments/divisions handle a variety of IT and OT equipment, identifying the vulnerable systems based on predefined criteria is challenging. Difficulty in compiling and maintaining IT and OT systems risk registries. Difficulty in evaluating 3rd party-managed assets and services. Difficulty in attributing all assets, applications, systems and staff that relate to the provisioning of specific services. This involves data creation, processing, transmission, exchange, and storage, which involves numerous stakeholders, both internally and externally. Increasing integration, technology refresh, evolution and integration create a range of challenges. Difficulty in handling configuration management of OT systems. Most OT systems providers do not offer access to extensive configuration management interfaces such CYBER RISK MANAGEMENT FOR PORTS
December 2020
as user and system settings, which result in supply chain dependencies based more heavily on vendor support availability. Difficulty in applying automated tools for identifying cyber-related assets, since the deployment of such tools may inadvertently interfere with the normal functioning of critical OT assets, which may rely on legacy system/software or reside on segmented networks. Difficulty in managing the procurement of software-enabled assets and standalone applications due to local performance, compliance and/or certification requirements resulting in varying procurement mechanisms. This challenge is greater for large organisations with multiple business units, i.e. a company operating several port terminals around the globe. 2.3 RELATED GOOD PRACTICES Define the assessment focus. It is critical to define the specific focus of the assessment based on the unique characteristics of the port operator. An assessment can be asset-based or service-based, such as loading and unloading of containers, where several applications and assets are used to deliver specific services. Maintain an asset inventory for cyber-related assets. Assets should be identified and registered in the asset inventory by the System they relate to. Assets should be identified and registered in the asset inventory by the Service they support. Assets should be identified and registered in the asset inventory by the Information they handle. Dependencies should be identified on the technical interface (and/or data exchange) requirements with third party software. Dependencies should be identified on the technical interface (and/or data exchange) requirements with vendors. Dependencies should be identified on the technical interface (and/or data exchange) requirements between IT and OT systems. Deploy automated tools for asset identification, logging and monitoring. Include the department/division responsible for cybersecurity in procurement contract review and implementation in order to ensure cybersecurity is addressed. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Figure 4: Mapping of good practices against challenges in identifying and evaluating cyberrelated assets and services CYBER RISK MANAGEMENT FOR PORTS
December 2020
3. IDENTIFYING AND EVALUATING CYBER-RELATED RISKS
3.1 GUIDELINES FOR IDENTIFYING AND EVALUATING CYBER- RELATED RISKS Phase two focuses on the identification and evaluation of cyber risks related to the assets and services identified in phase one. There exist a variety of methodologies and frameworks that offer detailed steps for how risk identification and evaluation should occur. For instance, the ISPS Code recognizes threat identification and vulnerability identification as essential and distinct activities in the performance of a port facility security assessment. Regardless of the methodology, framework or standard employed, results derived from this phase should include the identification of all relevant risks, which should be accompanied by an analysis of their likelihood and potential impact expressed in either a quantitative (e.g. score-based) or qualitative way. Specific actions that port operators can perform include: Contextualise the risk identification and evaluation process Identify cyber-related threats Identify vulnerabilities to assets and services Identify internal and external dependencies Assess the possible likelihood and impact of a cybersecurity incident Adopt a specific methodology for identifying and evaluating risks (e.g. scenario-based, empirical, data-driven, workshops/brainstorming sessions etc.) Develop indicators (qualitative or quantitative) to evaluate identified risks Calculating the likelihood of occurrence of a cyber incident, along with identifying related vulnerabilities to assets, services, policies and procedures, is critical to establishing and prioritizing mitigation measures. It is commonly recognized by port stakeholders that although relatively minor threats may individually result in negligible impact to operations, a series of cascading minor threats, if left unaddressed, does harbour the potential to cause major disruption. Therefore, the identification of vulnerabilities should not be limited to assets and applications used in the organisation’s ecosystem. Maintaining safe and secure operations also involves people handling the equipment and their adherence to defined policies, procedures and operational guidelines. Ultimately, any holistic vulnerability assessment should take the human element into consideration. ENISA’s 2019 report on Port Cybersecurity identifies the main threats to port assets and services and proposes a threat taxonomy and also lists the key possible impacts of cybersecurity incidents. Port operators can use the proposed taxonomies as the basis to identify their key cyber-related risks. The high-level categories of these threats and possible impacts are depicted in Figure 5. ENISA’s 2019 report also provides a detailed description for each taxonomy. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Figure 5: High-level categories of threats and possible impacts of cybersecurity incidents 3.2 RELATED CHALLENGES Cyber risk is not specifically identified in currently utilized risk assessment methodologies. Threats have been identified for physical security and IT security, but they are not combined for asymmetrical risk consideration. Approved PSP/PFSPs reflect assessment inputs that have not been updated to accommodate (let alone acknowledge) the potential impact cyber threats pose. Difficulty in calculating risk factors (likelihood, impact of a cyber incident) Difficulty in calculating aggregated risk, as assets and services are increasingly interrelated within the digital port environment. Lack of organisation-wide cyber awareness and commensurate cyber training, which makes it difficult for staff to consistently identify threats and recognize potential CYBER RISK MANAGEMENT FOR PORTS
December 2020
vulnerabilities of assets and services that may exist across the organisation’s different departments/divisions. Lack of recordkeeping regarding past incidents and subsequent response and recovery activities. Lack of information/intelligence regarding IT / OT systems' vulnerabilities, actual and/or emergent. Lack of available resources (people, budget) to carry out an effective risk assessment, as they are perceived to be time-consuming and costly or require additional expenditures for obtaining information, such as automated vulnerability scanning tools etc. Difficulty in defining cyber residual risk/risk acceptance thresholds, based on the organisation’s risk appetite. 3.3 RELATED GOOD PRACTICES Perform a cyber risk assessment at the enterprise level. Engage representatives from all the departments/divisions in order to collect accurate information and solicit cross-functional insights. Clearly define stakeholder responsibilities, authorities and risk ownership for assets or services within each department/division/business unit. The security of IT and OT systems should be the responsibility of the same department/division. Integrate cyber risk assessment and management with existing risk assessment and management frameworks, such as the PSA/PFSA or PSP/PFSP and/or the organisation’s Enterprise Risk Management Strategy. Adopt a comprehensive and consistent approach to calculating the likelihood of occurrence for a cyber incident, including factors such as threat actor motivation, their available resources, access to the port IT/OT infrastructure and target-specific knowledge. Adopt a comprehensive and consistent approach to calculating the impact of a cyber incident, in all business areas through a scenario-based approach that includes legal, reputational damage, health and safety, financial damage and business operations. Engage in sectorial initiatives, where organisations can liaise with each other to identify common risks, share best practices and communicate in a secure and trusted environment. Include cyber threat intelligence (CTI) inputs in the risk assessment methodology. CTI is a key capability that can provide critical insights into an organisation’s potential risk exposure. In some cases, national competent authorities and/or commercial vendors can play a key role in the provision of such information to ports and port facilities. Develop a methodology to calculate residual risk/risk acceptance determinations. All risks in the risk registry should have an Inherent, Residual, and Target risk score. The inherent risk is the initial risk identified without any existing controls applied. If mitigation measures are in place, the risk can be given a residual risk score. If there are additional actions that can be taken to further mitigate that risk, it can be assigned a target risk score. Progress should be tracked and once the actions are completed the process can restart with the new risk score and the new inherent risk score. Develop a methodology to track cyber risk indicators, such as the number of infected systems per month, in order to identify trends and measure scope. Deploy a business impact analysis methodology which provides an assessment, using a scoring mechanism, against specific attributes, such as data Confidentiality, Integrity, Availability, and operational safety and security. Such a tool should also take into consideration systems’ criticality and sensitivity. This can be scenario-CYBER RISK MANAGEMENT FOR PORTS
December 2020
based, as it is easier for all stakeholders to understand how cyber threats can affect port operations. Perform a cyber vulnerability assessment/penetration test. This can help identify assets that may be unrecorded or not appropriately assessed and expose weaknesses in the port environment. Involve senior management in the process of defining residual risk/risk acceptance levels. Figure 6: Mapping of good practices against challenges in identifying and evaluating cyberrelated risks CYBER RISK MANAGEMENT FOR PORTS
December 2020
4. IDENTIFYING SECURITY MEASURES
4.1 GUIDELINES FOR IDENTIFYING SECURITY MEASURES Phase three focuses on the identification and prioritisation of security measures that should be implemented to reduce the identified risks to acceptable levels. Security measures should be adopted following a risk-based approach that directs budget, resources and technical capabilities towards the implementation of those security measures that will have the most substantial impact on the organisation’s cyber risk posture. As such, this phase heavily relies on the evaluation of the identified risks. Specific actions that port operators can perform include: Identify security measures to mitigate identified risks Assess the effectiveness and impact of the security measures in terms of how they influence the risk evaluation Assess resource requirements for the implementation of security measures Define a process for prioritising security measures ENISA’s 2019 report provides a comprehensive list of baseline security measures grouped in specific domains. When identifying security measures, port operators can reference the mapping in Table 1 to identify which security measures are most appropriate for protecting identified assets against acknowledged threats. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Table 1: Mapping of security measures to assets and threats
Domain Security Measures Assets Threats
Security policy PS-01: Information System Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and and organisation Security Policy (ISSP) Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical Systems, People, Information and Data, Network & attacks, Failures & Malfunctions PS-02: Security governance Communication Components, IT end-devices
PS-03: Share ISSP with all stakeholders
PS-04: Review ISSP annually
Risk and Threats PS-05: Risk-based approach Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and Management Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical PS-06: Conduct and update risk Systems, People, Information and Data, Network & attacks, Failures & Malfunctions analysis Communication Components, IT end-devices
PS-07: Security indicators and assessment methods
PS-08: Threat intelligence process
Security and PS-09: Project methodology Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and including security Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical
privacy by
Systems, People, Information and Data, Network & attacks, Failures & Malfunctions
design
Communication Components, IT end-devices
PS-10: Privacy and compliance People, Information and Data Eavesdropping, interception, hijacking, Nefarious activity and abuse, Disaster, Unintentional damage, Physical attacks
PS-11: Data classification OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and Security Systems, People, Information and Data, Network & abuse, Disaster, Outages, Unintentional damage, Physical Communication Components, IT end-devices attacks, Failures & Malfunctions
Asset inventory PS-12: Asset inventory and Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and and management management Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical Systems, People, Information and Data, Network & attacks, Failures & Malfunctions Communication Components, IT end-devices
PS-13: Policy for authorized OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and devices/software Security Systems, People, Information and Data, Network & abuse, Unintentional damage, Failures & Malfunctions Communication Components, IT end-devices
PS-14: Asset monitoring Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical Systems, People, Information and Data, Network & attacks, Failures & Malfunctions Communication Components, IT end-devices
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Domain Security Measures Assets Threats
PS-15: Define objectives and Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and
Cyber Resilience
(Business strategic guidelines (BCP and Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical continuity and DRP). Systems, People, Information and Data, Network & attacks, Failures & Malfunctions crisis Communication Components, IT end-devices PS-16: Business continuity
management)
parameters (RTO, RPO, MTO etc.)
PS-17: Crisis management
PS-18: Training/exercises for recovery procedures
Endpoints OP-01: Endpoint protection IT Systems, Information and Data, Network & Communication Eavesdropping, interception, hijacking, Nefarious activity and strategy Components, IT end-devices abuse, Unintentional damage, Physical attacks, Failures &
protection and
Malfunctions
lifecycle
OP-02: Device and software
management
whitelisting
OP-03: Change management
OP-04: Return and disposal of end-devices
Vulnerabilities OP-05: Vulnerability management OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and management process Security Systems, Information and Data, Network & abuse, Outages, Unintentional damage, Physical attacks, Communication Components, IT end-devices Failures & Malfunctions OP-06: Intelligence processes for cybersecurity
OP-07: Collaboration of OT and IT departments
Human Resource OP-08: Professional references of Mobile Infrastructure, Fixed Infrastructure, OT Systems & Nefarious activity and abuse, Unintentional damage Security key personnel Networks, OT end-devices, IT Systems, Safety and Security Systems, People, Information and Data, Network & OP-09: Cybersecurity training Communication Components, IT end-devices OP-10: Security awareness raising program
Supply chain OP-11: Third-party access control OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and Security Systems, Information and Data, Network & abuse, Outages, Unintentional damage, Physical attacks,
management
OP-12: Partnership with third Communication Components, IT end-devices Failures & Malfunctions parties
OP-13: Define categories of Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and
Detection and
incident incidents Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical response Systems, People, Information and Data, Network & attacks, Failures & Malfunctions OP-14: Policy and procedures for Communication Components, IT end-devices incident detection and response
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Domain Security Measures Assets Threats
OP-15: Improve and update procedures
OP-16: Security Operations Centre (SOC)
OP-17: Define alerting procedures and communication plan
OP-18: Incident reporting and continuous improvement
Control and OP-19: Cybersecurity audits OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and auditing Security Systems, Information and Data, Network & abuse, Physical attacks, Failures & Malfunctions Communication Components, IT end-devices
OP-20: Periodic reviews OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and Security Systems, Information and Data, Network & abuse, Unintentional damage, Physical attacks, Failures & Communication Components, IT end-devices Malfunctions
IT and OT OP-21: Physical protection for Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and physical safety Networks, OT end-devices, IT Systems, Safety and Security abuse, Disaster, Outages, Unintentional damage, Physical protection Systems, People, Information and Data, Network & attacks, Failures & Malfunctions OP-22: Maintenance operations Communication Components, IT end-devices traceability
TP-01: Network segmentation OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and
Network security
Security Systems, Information and Data, Network & abuse TP-02: Regular network scans Communication Components, IT end-devices
TP-03: Perimetric security
TP-04: Centralised tools for IAM OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and
Access control
Security Systems, People, Information and Data, Network & abuse, Unintentional damage TP-05: IAM strategy Communication Components, IT end-devices
TP-06: Restrict generic accounts
TP-07: Password complexity policies/rules
TP-08: Multi-factor authentication
TP-09: Physical/remote access Mobile Infrastructure, Fixed Infrastructure, OT Systems & Eavesdropping, interception, hijacking, Nefarious activity and control Networks, OT end-devices, IT Systems, Safety and Security abuse, Unintentional damage, Physical attacks Systems, People, Information and Data, Network & Communication Components, IT end-devices
TP-10: Accounts and access right OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and reviews Security Systems, People, Information and Data, Network & abuse, Unintentional damage, Physical attacks Communication Components, IT end-devices
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Domain Security Measures Assets Threats
TP-11: Installation and OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and
Administration
and configuration policy Security Systems, Information and Data, Network & abuse, Unintentional damage Configuration Communication Components, IT end-devices TP-12: Administrators accounts
Management
TP-13: Privilege Account Management
TP-14: Dedicated administration networks
Threat TP-15: Anti-malware, anti-spam IT Systems, Safety and Security Systems, IT end-devices Nefarious activity and abuse management and anti-virus
Cloud security TP-16: Cloud security assessment IT Systems Eavesdropping, interception, hijacking, Nefarious activity and method abuse, Disaster, Outages, Unintentional damage, Physical attacks, Failures & Malfunctions TP-17: Security / availability in cloud SLAs
TP-18: Cloud options for detection/response
Machine-to- TP-19: Secure M2M exchanges OT Systems & Networks, OT end-devices, IT Systems, Information Eavesdropping, interception, hijacking, Nefarious activity and machine security and Data abuse TP-20: Secure communication protocols
TP-21: Cryptography Information and Data Eavesdropping, interception, hijacking, Nefarious activity and
Data protection
abuse, Unintentional damage, Failures & Malfunctions TP-22: Anonymise / secure personal data
Update TP-23: Define update OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and management management process Security Systems, Information and Data, Network & abuse, Failures & Malfunctions Communication Components, IT end-devices TP-24: Software/firmware authenticity
TP-25: Verify the source of updates
Detection and TP-26: Monitor availability of the OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and port systems and devices Security Systems, Information and Data, Network & abuse, Disaster, Outages, Unintentional damage, Physical
monitoring
Communication Components, IT end-devices attacks, Failures & Malfunctions TP-27: Logging system
TP-28: Log correlating and analysis systems
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Domain Security Measures Assets Threats
TP-29: OT systems in security OT Systems & Networks, OT end-devices, Information and Data Eavesdropping, interception, hijacking, Nefarious activity and
Industrial control
measures abuse, Failures & Malfunctions
systems security
TP-30: Network segmentation OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and between IT/OT Security Systems, Information and Data, Network & abuse Communication Components, IT end-devices
TP-31: Specific security measures OT Systems & Networks, OT end-devices, IT Systems, Safety and Eavesdropping, interception, hijacking, Nefarious activity and for IoT Security Systems, Information and Data, Network & abuse, Disaster, Outages, Unintentional damage, Physical Communication Components, IT end-devices attacks, Failures & Malfunctions
TP-32: Set up backups and ensure OT Systems & Networks, OT end-devices, IT Systems, Safety and Nefarious activity and abuse, Disaster, Outages,
Backup and
restore they are regularly maintained and Security Systems, Information and Data, Network & Unintentional damage, Physical attacks, Failures & tested Communication Components, IT end-devices Malfunctions
CYBER RISK MANAGEMENT FOR PORTS
December 2020
4.2 RELATED CHALLENGES Difficulty in assessing the effectiveness of mitigation measures Lack of available internal resources (people, time, budget) for the identification, adoption, implementation and review of suitable mitigation measures. Difficulty in sharing established security measures, procedures and policies, both internally and externally, with third party stakeholders, which impedes the development of a common approach to driving port community resilience. Difficulty in identifying and selecting security measures based on business continuity requirements. Most port stakeholders are currently focused on implementing security measures in response to cyber incidents instead of adopting proactive security measures. The perception that any attempt to protect the entire organisation against cyber threats may exhaust organisational resources (time consuming, costly, large number of dedicated staff, etc.). 4.3 RELATED GOOD PRACTICES Implement security measures based on predefined criteria, applicable to the entire organisation, such as those that drive cost reduction, deliver risk reduction and/or reduce the impact of a cyber incident. Assess all security measures for risk reduction effectiveness by implementing a scoring methodology. Test security measures during cyber drills/exercises, or security drills/exercises that include detailed cyber elements, both internally and externally with port stakeholders. Coordinate the identification, adoption and implementation of security measures with the asset risk owner. Adopt a ‘security-by-design’ approach in all procurement activities. Taking cybersecurity into consideration in the conceptualisation phase of a project minimises the need for additional allocation of resources during the operational cycle of the asset/service. - For less mature organisations focus on identifying and implementing security measures that offer detection, response and recovery capabilities in the event of a cyber incident. - For mature organisations focus on identifying and implementing security measures that protect the organisation’s most critical assets/services. Consider cyber insurance as a risk reduction mitigation measure. Cyber insurance can contribute to the organisation’s resilience by reducing risk of financial loss and can also help to mobilize resources (e.g. funding, expertise) quickly in response to a cyber incident. Introduce cyber specific metrics, or Key Performance Indicators (KPIs), such as monitoring the availability of IT and OT assets and related services, awareness levels of staff, number of critical security incidents etc. These should be periodically reported to and reviewed by senior management. Highlight the role of individuals as the first line of defence, response and recovery. Training plays a prominent role in raising awareness and developing capacity in responding to cyber incidents. For effective incident response, prioritise response capabilities to focus on key business-critical assets / services / departments / divisions / business units, along with the organisations they are connected to in order to contain a potential cyber incident. Figure 7 maps the relevant challenges and good practices. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Figure 7: Mapping of good practices against challenges in selecting and prioritising mitigation measures CYBER RISK MANAGEMENT FOR PORTS
December 2020
5. ASSESSING CYBERSECURITY MATURITY
5.1 INTRODUCTION Phase four goes beyond the adoption of baseline security measures to identify areas where port operators can improve their cybersecurity maturity. The process of cybersecurity maturity selfassessment can support organisations in their efforts to understand where they currently stand in terms of maturity in security domains – or individual security measures – of interest and plan their organisational progression accordingly. Identifying where organisations need to improve their cybersecurity practices informs the prioritisation and allocation of limited resources that will result in the most effective outcome. This chapter lists the security measures proposed in the 2019 ENISA report and introduces maturity levels that port operators can select to help prioritise security measures and conduct a self-assessment for the purpose of determining their current maturity level. Results from this effort will guide stakeholders in their selection of security measures and better understand the specific actions they should undertake in order to improve their organisational cybersecurity capabilities, and thus achieve higher maturity levels. A maturity self-assessment model is a set of characteristics, attributes, indicators, or patterns that represent capability and progression in a particular discipline. This provides a benchmark against which an organisation can evaluate the current level of capability exhibited by the dayto-day implementation of its controls, practices, processes, tools, and personnel, and supports stakeholders in their effort to set goals and priorities for continuous improvement A maturity model approach relies on the fact that effective cyber risk management cannot be achieved through a “checklist mentality”, since cyber threats represent a persistent, constantly evolving risk to port operations. Achieving and sustaining organisational cyber resiliency requires effective cyber risk assessment and management at an organisational level. The first step to effective cyber resilience is the establishment of an organisation-wide cybersecurity capability baseline that is commensurate with the nature and scale of the cyber risks associated with its operations and supporting supply chain. To establish a realistic baseline requires that port organisations gain situational awareness of their current cybersecurity capabilities and identify the cybersecurity capability gaps that may exist. The next step includes the “institutionalisation” of the organisation’s existing cybersecurity capability posture, throughout the various business assets, services, and processes. This is achieved through structured and well-defined recurring activities focused on maintaining an increased cyber risk awareness, revised risk-based behaviours, and appropriate resource allocation (people, processes, tools and funding). The approach proposed here is based on the introduction of maturity levels of implementation for the security measures proposed in the 2019 ENISA report on Port Cybersecurity. Each maturity level includes a description of what the organisation needs to put in place in order to achieve the respective level. CYBER RISK MANAGEMENT FOR PORTS
December 2020
5.2 RELATED CHALLENGES Lack of communication between the departments responsible for physical security and cybersecurity. Poor (or lack of) effective communication is frequently exacerbated by the fact that in the majority of cases personnel responsible for physical security risk management fail to communicate with and/or involve cybersecurity or IT experts in security planning, coordination, and preparation activities. The IT department is tasked to assume the responsibility for cybersecurity without appropriate training or internal coordination with other departments. IT and OT systems are the responsibility of different working groups or divisions, and, therefore, fall under different organisational authorities (usually IT and Technical). Thus, efforts to develop a holistic cybersecurity strategy that address both IT and OT systems are often uncoordinated and inconsistently resourced. Cybersecurity maturity varies among different groups or operating divisions across the organisation, including senior management and board of directors. This is usually a result of a lack of organisation-wide cyber awareness and related cyber training, including tailored training for executives. Lack of available resources (people, processes, tools, budget, time) to fully organize, develop, conduct and regularly update the organisation’s baseline cyber risk assessment. Difficulty in staffing. This is exacerbated by the shortage of cybersecurity experts currently available in the global market. Difficulty in assigning internal roles. This is worsened by the difficulty among key stakeholders in fully apprehending the nature of the cyber threat. Difficulty in managing internal change. Organisations finding it difficult to encompass and comprehend changes made to existing policies and procedures regarding cybersecurity. Difficulty in third-party management. Larger organisations with several business units and external partners are finding it difficult to implement a consistent cyber risk management approach across their organisation. Variety of cyber risk assessment standards/frameworks. The large number of standards regarding IT security, cybersecurity or risk assessment is causing confusion to port stakeholders, making the selection and implementation of the appropriate standard or framework challenging for organisations with limited resources or low cyber maturity. Fragmentation and distribution of governance of ports operators. Ports are characterized by a very fragmented and distributed governance especially in the private sector. Frequently, organisations or entities responsible for part/full of operations at ports comprise multiple stakeholders, and cybersecurity responsibilities are unclear and complex to implement. 5.3 RELATED GOOD PRACTICES Ensure the cyber risk assessment includes all aspects of the scoped environment. As cybersecurity is not only an IT issue, linking it to all plans, policies, resources and capabilities are included to ensure a more accurate determination of the current cybersecurity state and the implementation of cyber risk assessment good practices. Implement cybersecurity awareness and technical training programmes. Awareness training represents a fundamental capability in addressing several of the aforementioned challenges. Standardized training ensures consistency in establishing CYBER RISK MANAGEMENT FOR PORTS
December 2020
minimum cybersecurity awareness across all staff irrespective of their functional activities. Also, develop and deploy specific content that is relevant for the organisation’s operating environment and to educate staff specifically on how to safely and securely access and use corporate, software-enabled, assets and equipment. Formally organize a cybersecurity working group. Staff with key leadership and/or representatives from each of the organisation’s operational areas and/or divisions. All functions of the organisation should be represented, and individuals should be assigned specific responsibilities. Establish a regular schedule, preferably monthly, and grant appropriate authorities to the group to support cyber risk management activities. The working group size will vary by organisation. Seek advice from external sources, such as contracting governments, national/international competent authorities or private companies. Using external assistance to secure guidance on how best to implement and sustain cyber risk assessment standards/ frameworks can help an organisation avoid repeating mistakes. Develop a cybersecurity programme. This should include a cyber risk management strategy that is supported by documented plans, policies, procedures, and internal guidelines informed by referenced standards. This should identify and define the cybersecurity working group, resource allocations, training, performance objectives, budgets and the various cyber risk management activities that are performed to meet defined cybersecurity objectives. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Figure 8: Mapping of good practices against challenges in addressing cybersecurity maturity 5.4 PORT CYBERSECURITY MATURITY LEVELS The proposed approach is structured to (1) assess an organisation’s cybersecurity capabilities over three maturity levels and (2) follow a dual progression approach that characterizes both capability progression and institutionalisation is adopted: Capability progression measures the degree to which the organisation has implemented cybersecurity capabilities (people, processes, tools, and funding). Institutionalisation measures how deeply entrenched specific activities, controls, processes, and procedures are within and across the organisation. The more ingrained these are, the more likely the organisation will maintain them consistently during and after an incident. CYBER RISK MANAGEMENT FOR PORTS
December 2020
Additionally, the three maturity levels of the proposed approach are defined in Table 2. Table 2: Maturity level definitions Maturity Level Description This level corresponds to the minimum-security measures that are implemented 1 to achieve a security objective. The organisation performs baseline activities (Basic) and/or capabilities, even in an ad hoc manner. This level corresponds to more sustained capabilities that align with identified standards and best practices. The organisation implements, manages, monitors, 2 and measures capabilities against defined objectives and operational applicability. (Intermediate) Documentation (i.e. plans and policies) guides the application and utilisation of resources for specific and/or coordinated activities. This level corresponds to activities and/or capabilities that are planned, tested, policy-informed, and repeatable; subject to regular oversight and reviews to 3 confirm effectiveness; and improve the implementation of security measures, taking into account disciplined changes, tests, and exercises. The organisation (Optimal) regularly measures capabilities to support continuous improvement efforts to attain and sustain defined performance objectives. Section 5.5 provides examples of the proposed maturity levels for the security measures defined in the ENISA 2019 report. Port operators can use the information therein as follows: 1. Following their own implementation of the previous risk assessment/management phases, port operators can identify a list of security measures that are most relevant to them. 2. Port operators can then review the policies, practices and technical measures throughout the tables in section 5.5. For each security measure, the respective maturity level indicates examples or evidence that the measure is implemented at a specific maturity level. 3. Port operators should carefully consider the evidence/examples to ensure relevance to their operational environment and appropriateness to capabilities. For example, operators such as customs are not required to consider examples related to PSPs/PFSPs requirements, while a port authority may have a Port Security Officer but not a Port Facility Security Officer. Similarly, the examples/evidence provided should be tailored by the port operator to match their organisation’s unique characteristics regarding cyber risk management (e.g. terminology, information security framework etc.). 4. Port operators should assess their current maturity level in terms of implementing the selected security measures by determining how their current practices map to the maturity levels of the provided examples/evidence. It’s important to note that in many cases a port operator may select one or more security measures that may result in an organizational cybersecurity posture that reflects variable maturity levels. 5. Port operators can identify priorities for improvement depending on specific needs, as well as determine the viability of and benefits derived from actions that can be easily and quickly implemented. CYBER RISK MANAGEMENT FOR PORTS
December 2020
5.5 MATURITY LEVELS FOR PORT CYBERSECURITY MEASURES 5.5.1 Policies
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Security policy and organisation
PS-01: Write and implement The organisation has drafted one or more The organisation has formally codified its The organisation regularly reviews its ISSPs an information systems information system security policies (ISSPs) ISSPs in an overarching plan that provides to ensure that policies and procedures security policy (ISSP), which that provide technical guidance and tailored guidance to stakeholders regarding accord with defined objectives. describes all organisational supporting procedures to stakeholders in the organisation's unique IT/OT environment. The organisation includes ISSP elements and technical means and protecting information technology and Top management have reviewed and within quarterly drills and annual exercises to procedures, including topics operational technology environments. approved the organisation's ISSPs. align security activities with IT/OT operating related to the OT The ISSPs include cybersecurity environments. The updated PSP/PFSP includes a environment. This ISSP must considerations. cybersecurity appendix (or annex) that The organisation shares its ISSPs with key be approved by the port's top management team to The organisation's designated Port Facility includes all relevant ISSPs addressing stakeholders across the organisation. Security Officer is familiar with the ISSPs. cybersecurity considerations. guarantee the high-level endorsement of the policy. The organisation has updated its PSP/PFSP Key elements of the ISSP can to include ISSPs. be integrated in the Port Facility Security Plan required by the ISPS Code. PS-02: Enforce security The organisation has identified and defined The organisation has established and The organisation reviews stakeholder roles governance of both IT and OT roles and responsibilities for stakeholders documented within its ISSPs a senior and responsibilities at least annually to environments through the responsible for supporting security activities leadership role (or roles) that defines ensure that proper oversight of all IT and OT ISSP by describing the roles across all IT and OT operating responsibility for managing cyber risk across environments. and responsibilities of each environments. all areas of the organisation, including IT stakeholder (Port Authority, and OT environments. The organisation has established terminal operators, service stakeholder roles and responsibilities The organisation has defined and providers, suppliers, etc. supporting security activities and identified documented executive and senior them within one or more ISSPs. leadership roles and responsibilities in order Stakeholder roles and responsibilities to identify the individuals responsible for managing and mitigating cyber risk factors supporting security activities distinguish between internal and external stakeholder when the organisation suffers a cyberincident. engagement. The organisation has clearly defined the Managing Director’s role and responsibilities for cybersecurity oversight, post-incident response, and crisis communications after a cyber-incident.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
PS-03: Share the ISSP with The organisation shares its ISSP, or The organisation shares its ISSP, or relevant The organisation regularly reviews ISSP all stakeholders involved in relevant information within the ISSP, with all ISSP elements, with all stakeholders documentation to revalidate cybersecurity port operations, or, if more stakeholders involved in port operations. involved in port operations consistent with a responsibilities of named stakeholders relevant a light version The organisation's ISSP articulates each documented procedure that identifies with involved in operations at the port level. underlying each party whom to share the document. party's cybersecurity responsibilities at the responsibilities towards port level. The ISSP’s documentation sharing cybersecurity at port level. procedure(s) includes notification procedures. PS-04: Review annually the The organisation's leadership reviews ISSP The organisation has a documented process The effectiveness of the ISSP review process ISSP by considering the or similar security documentation, audit that facilitates annual reviews of is assessed to identify continuous results of cyber security tests results, and test findings to identify areas cybersecurity audit, test, and/or evaluation improvement objectives (e.g. additional and risk analysis to tackle requiring updating. results against existing ISSP or similar sources of input for the annual ISSP review). new threats and risks. documentation cybersecurity to identify areas requiring updating.
Risk and threats management
PS-05: Adopt a risk-based Consistent with the IMO's ISPS Code The organisation has identified cyber risks in As part of the organisation's continuous approach to build the port requirements, the organisation has facility security assessments and considered improvement process, updated cyber risk cybersecurity strategy and set conducted a port facility security cyber risks in safety and security plans in criteria are accessible to stakeholders for up a continuous improvement assessment that includes cybersecurity order to align cybersecurity with physical use in re-validating cyber risk impacts to process to ensure that the risks. security and safety. critical assets, systems, and/or services; rerisks identified are under affirming organisational cyber risk The organisation evaluates existing health Cyber risk management policies and control and that new risks are and safety, security, and incident response procedures are documented for all IT/OT tolerances, such as risk mitigation, properly identified in a timely acceptance, or transfer; and re-confirming plans to ensure alignment with cyber risk environments and align with the manner. Ensure identified management best practices. organisation's defined performance cyber incident response elements. cyber risks are considered in The organisation maintains, references, and objectives, which include resilience The organisation reviews its cyber risk safety and security plans to requirements to support delivery of critical management practices, procedures, align cybersecurity with communicates established best practices to support cyber risk management activities in services. directives, and/or or related activities at least physical security and safety annually to ensure adherence to (in particular, through the Port both administrative and operational To verify effectiveness and operational environments. readiness, the organisation performs regular documented requirements and defined Facility Security Assessment performance objectives in order to ensure required by the ISPS Code). The organisation has evaluated cyber risk internal audits and/or inspections against adherence to established standards. defined policies, including regulatory factors for their potential to impact the Lessons learned are documented. organisation's regulatory compliance. regimes that include documented cyber risk. Management policies and/or procedures.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
PS-06: Conduct and regularly The organisation performs regular audits of The organisation conducts risk assessments The organisation regularly reviews and update risk analysis to identify its Port Facility Security Plan consistent with for all projects and initiatives, such as those updates to reflect the current cyber threat risk and threats related to the the requirements of the IMO's ISPS Code. involving the adoption of new technologies environment its cyber risk management port ecosystem. In particular, PFSP and PSP audits include analysis of and systems (e.g., Big Data, Internet-of- strategy, which includes cyber risk risk analysis must be Things enabled systems, Blockchain, etc.), tolerances for services, systems, and assets cyber risk factors that can impact both the conducted for new projects organisation specifically and the broader in order to identify potential cyber supporting administrative and operational (SmartPort initiatives such as vulnerabilities. areas and risk response options. port community within which the Big Data, IoT, blockchain, organisation functions. The organisation performs threat The organisation has identified cyber risk etc.). assessments to inform recurring risk factors (including threats) for IT and OT assessment activities. systems that may impact complex infrastructure and/or other critical assets or control systems whereby an incident may threaten health and safety of staff and/or jeopardize the surrounding port community. PS-07: Set up security The organisation has a mechanism or Threats and vulnerabilities are analysed to As part of the organisation's continuous indicators and assessment process that facilitates the collection of determine relevance to the organisation's improvement process, updated cyber risk methods to evaluate the cybersecurity threat information from internal operating environment, including its criteria are accessible to stakeholders for compliance of the port and/or external sources. compliance posture. use in re-validating cyber risk impacts to systems and processes to the The organisation has performed a The organisation has a process in place to critical assets, systems, and/or services; re- ISSP and risk management affirming organisational cyber risk vulnerability assessment of its IT/OT facilitate the analysis, prioritization and performance, by involving operating environment. mitigation of threats and cybersecurity gaps tolerances, such as risk mitigation, several stakeholders when acceptance, or transfer; and re-confirming identified in a Vulnerability Assessment. relevant. cyber incident response elements. The organisation has rules and supporting procedures (within ISSPs) that guide the Documented cyber threat monitoring and response activities inform, leverage and sharing of newly discovered threat and/or vulnerability information among relevant trigger pre-defined security and operational states (i.e. Maritime Security Level internal and external stakeholders. changes). The organisation's documented threat and vulnerability management plans, policies, procedures are regularly reviewed in ensure conformance with defined goals and referenced standards. PS-08: Set up a threat The organisation has a mechanism or The organisation has developed Documented cyber threat monitoring and intelligence process to watch process that facilitates the collection of documented policies that guide vulnerability response activities inform, leverage, and continuously for cybersecurity threat information from internal analysis and resolution activities. trigger pre-defined security and operational vulnerabilities, identify new and/or external sources. The organisation has a process to facilitate states, such as changes to the Security risks and threats and deploy Level. The organisation has invested in tools the analysis, prioritization, and mitigation of actions to mitigate them. and/or methods to support the identification cybersecurity gaps. The organisation's management regularly of vulnerabilities in assets and/or detect The organisation has allocated adequate reviews documented threat and vulnerability malicious code in assets (including mobile management activities for effectiveness. and risk-appropriate resources (people, assets). tools, and funding) to support threat and The organisation tracks the status of vulnerability management activities. unresolved threats and vulnerabilities and informs system/asset owners of that status.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Security and privacy by design
PS-09: Develop a project For all new and ongoing projects and The organisation regularly performs cyber To support ongoing cyber risk management methodology including initiatives, the organisation employs a risk risk assessments of critical IT/OT systems activities, the organisation regularly reviews security assessments and assessment methodology that includes an and includes an analysis of dependent and updates its risk register, which includes checkpoints, including for overall risk review, an architecture security operations in SmartPort environments. all risks identified through cybersecurity agile projects (risk analysis, review, test and acceptance procedures, The organisation's network architecture assessments for administrative and architecture security review, and a formal approval procedure. operational environments. informs cyber risk assessment activities security tests, security The organisation has a current cybersecurity addressing all critical IT and OT system approval, etc.) for new and architecture that can be referenced in a environments. existing projects, considering documented security policy to manage the criticality and exposure of recurring risk analysis. the system. More specifically, strongly include cybersecurity issues in SmartPort projects from the design stage to implementation. PS-10: Address privacy The organisation adheres to all local, The organisation has performed a Data The privacy assessment processes are related issues based on national, and international regulations (e.g., Protection Impact Assessment (DPIA), reviewed periodically for effectiveness and applicable local and GDPR), where applicable. where appropriate. suitability. international regulations, such The organisation has established as the General Data documented data protection policies, Protection Regulation procedures, and processes, and security (GDPR). controls. The organisation has formally established the role and responsibilities of a Data Protection Officer (DPO). PS-11: Launch a data The organisation classifies data critical to The organisation documents data The organisation has documented all classification project to port operations. classification criteria in policies and/or policies designed to specifically protect identify critical data for port The organisation classifies personal data to procedures. sensitive information, such as information operations as well as personal defined by privacy regulations and ensure privacy protections. The organisation has mapped and data and to protect them documented data flows for critical IT/OT commercial confidential, or third-partyaccordingly and to map the The organisation maps data flows sensitive-but-unclassified information. systems. data flows, especially for The organisation reviews and re-validates The organisation has documented data personal data and operational flows for all ship-shore interfaces data flow maps. data related to vessel, dangerous goods and cargo. (passenger list exchanges, Notice of Arrivals, dangerous goods and cargo, etc.).
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Asset inventory and management
PS-12: Use centralized tools The organisation maintains an inventory of The organisation has a process or To ensure adherence to documented for asset inventory and IT assets, including servers, related software procedure that facilitates management performance objectives, the organisation management and ensure that applications, and, where applicable, oversight of asset inventorying and change has a process that facilitates the regular you keep them up-to-date software that supports operating systems of management activities. monitoring of asset inventorying and change (applications, software operational activities. The organisation has a process that management activities. platforms, networks, network The organisation maintains an inventory of facilitates efforts to maintain the inventory of components, servers, physical all OT systems, including, where applicable, all inter-connected assets as current. devices, OT systems, software operating systems and related administration components, applications. etc.) PS-13: Define a policy The organisation has a documented policy The organisation documents all updates and The effectiveness of the policy regarding regarding authorized devices establishing authorization procedures for changes to IT, OT, or communication authorized devices and software is reviewed and software to ensure than devices and software prior to deployment on systems following testing and prior to periodically. only reliable components are any network. implementation. (Same as OP-03) introduced to the port The organisation tests new or modified IT, network. OT, and communication assets prior to deployment in the organisation's live operating environment. (Same as OP-03) PS-14: Use centralized tools The organisation monitors critical IT/OT The organisation employs and configures The organisation regularly reviews endpoint to monitor the different assets assets for irregular activity. endpoint monitoring tools to support monitoring activities for effectiveness. by adapting them according organisation-specific requirements for the specificities and the monitoring critical IT/OT assets for associated risks (e.g. passive unauthorized access. monitoring for OT systems) The organisation has a documented policy and detect unauthorized that provides guidance regarding endpoint assets. monitoring, alerting, and response activities.
Cyber resilience (Business continuity and crisis management)
PS-15: Ensure cyber The organisation has defined business The organisation has documented Business The organisation reviews its Business resilience of port systems by continuity and disaster recovery objectives Continuity and Disaster Recovery Plans. Continuity and Disaster Recovery Plans defining objectives and for port systems. The organisation has identified and annually. strategic guidelines regarding documented stakeholder roles and business continuity and responsibilities within Business Continuity recovery management and and Disaster Recovery Plans. set up associated key The organisation has identified and services and processes (Business Continuity Plan and prioritized critical IT/OT systems are identified and prioritized within the Business Disaster Recovery Plan). Continuity and Disaster Recovery Plans.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
PS-16: Define important The organisation has identified all IT/OT The organisation has established Key The organisation regularly reviews and reparameters for port’s business systems that support critical port services. Recovery Time Objectives (RTOs) within the validates recovery parameters within continuity, such as a recovery Business Continuity and Disaster Recovery Business Continuity and Disaster Recovery time objective (RTO), Plans. Plans. recovery point objective The organisation has established Key The organisation tests recovery parameters (RPO), maximum tolerable Recovery Time Objectives (RTOs) within the in drills and exercises. outage (MTO) and minimum Business Continuity and Disaster Recovery business continuity objective Plans. (MBCO). The organisation has established Key Recovery Point Objectives (RPOs) within the Business Continuity and Disaster Recovery Plans. The organisation has established Minimum Business Continuity Objectives (MBCOs) within the Business Continuity and Disaster Recovery Plans. PS-17: Define a crisis The organisation has identified resources to The organisation has a documented Crisis Agreements have been established with management organisation by support crisis management activities. Management Plan and supporting policies other port organisations that define formalizing a specific policy and procedures that detail the organisational communication protocols, information and by setting up the structure of a crisis response team and its sharing procedures, resourcing capabilities, associated crisis management functions. and processes to facilitate mutual aid in the process, including all the port event of a crisis. The organisation has identified and stakeholders. assigned individuals roles and responsibilities to support the crisis response team.
PS-18: Ensure the efficiency The organisation participates in drills and The organisation participates in the drafting The organisation incorporates lessons of recovery procedures by exercises that test crisis response activities of post-exercise reports that detail all learned derived from multi-organisational setting up annual training involving multiple organisations. findings and lessons learned. drills and exercises into the continuous exercises, making sure that all improvement process. The organisation disseminates postcritical port stakeholders (local exercise reports all training event The organisation updates Incident authorities, Port Authorities, participants. Response, Security, Business Continuity, terminal operators, service and Disaster Recovery Plans using lessons providers, etc.) are involved learned. as much as possible, and by formalizing post-exercise reports.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
5.5.2 Organisational practices
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Endpoints protection and lifecycle management
OP-01: Define an endpoint The organisation employs endpoint The organisation has a documented The organisation periodically reviews its protection strategy to monitor protection to monitor port-end devices. endpoint protection strategy that includes all endpoint protection strategy to ensure port end-devices and to networked environments. effectiveness. The organisation employs antivirus enforce their security by protection. The organisation's endpoint protection implementing security tools The organisation employs encryption. strategy aligns endpoint protection and mechanisms such as measures with security tools and antivirus, encryption, mobile The organisation performs mobile device mechanisms, such as antivirus, encryption, device management (MDM) management. mobile device management (MDM) and and hardening (disabling of The organisation secures its USB ports. hardening actions (the disabling of unnecessary services, unnecessary services, such as securing especially by securing USB USB ports in all port systems). ports in all port systems). OP-02: Implement device and The organisation manages user privileges The organisation has a documented The organisation regularly reviews software whitelists and review by employing whitelisting. process that provides guidance on software whitelisting activities and supporting the list at least annually or in and device whitelisting activities. documentation to ensure that appropriate case of a major system privileges to devices and software change. applications are valid and accurately maintained. OP-03: Define a change The organisation evaluates newly procured Prior to adding, changing, or removing an The organisation documents all updates and management process to technologies or equipment before entering IT, OT, or communication asset or system changes to IT, OT, or communication introduce any new device into them into service. critical to the delivery of services, the systems following testing and prior to the port systems (acceptance The organisation employs a change organisation assesses the asset or system implementation. tests, validation steps, etc.). for specific cyber risk impact. management methodology or process to support modifications to its IT, OT, and The organisation tests new or modified IT, information assets. OT, and communication assets prior to deployment in the organisation's live operating environment. OP-04: Ensure all employees The organisation's employees return end- The organisation has a documented The organisation reviews end-device return and contractors return their devices at service contract termination. process that facilitates end-device return at and disposal activities, processes, and end-devices at contract service life end for all employees. procedures at least annually to ensure Contractors return end-devices at service termination and define contract termination. The organisation has a documented effectiveness. processes for secure end- process that facilitates end-device return at devices disposal. service life end for all contractors. The organisation has a policy that establishes clear end-device disposal protocols.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Vulnerabilities management
OP-05: Define a vulnerability The organisation identifies vulnerabilities in The organisation deploys commercially The organisation has documented policies, management process to IT/OT assets. available vulnerability scanning tools to practices, and/or procedures that guide identify asset vulnerabilities, it automate the discovery of new and existing asset vulnerability identification and can be based on automatic threats to its IT/OT networked operating management activities and manual tools such as environment. vulnerability scans. OP-06: Define intelligence The organisation has one or more business The organisation has established and The organisation regularly reviews policies, processes for cybersecurity in processes, methodologies, and/or documented rules, plans, policies, procedures, and/or directives guiding order to be aware of newly mechanisms that facilitate the dissemination procedures, and/or written practices that information sharing activities. disclosed vulnerabilities and of collected cyber risk information to guide all cybersecurity information-sharing take quick compensatory designated stakeholders. activities. actions (network segregation, The organisation has established The organisation has established and service disabling, etc.) procedures to guide both normal operations maintains internal protocols and/or and enable rapid incident response actions procedures that protect and facilitate the for administrative and operational secure sharing of confidential or environments. commercially sensitive information. OP-07: Establish tight OT and IT department personnel The organisation has documented policies To ensure that all OT, IT, data/asset/system collaboration of OT and IT collaborate in cybersecurity activities, which and procedures that facilitate regular owners, decision-making authorities and departments ensuring that also includes proactive communication with collaboration between OT and IT other stakeholders routinely collaborate, the their collaboration with data/asset/system owners, decision-making departmental personnel in coordinated organisation regularly reviews and systems business owners, authorities, and other stakeholders. cybersecurity activities across all revalidates all information sharing policies, decision-making authorities operational areas. alert/exception and escalation procedures, and other stakeholders is OT-IT collaboration procedures define notification protocols, and related efficient and ensure a communication activities. information-sharing protocols for supporting homogeneous cybersecurity data/asset/system owners, decision-making The organisation mitigates identified level for IT and OT. authorities, and other stakeholders to communication gaps among OT and IT ensure coordination and consistency of department personnel, as well as among all cybersecurity activities across all data/asset/system owners, decision making operational areas. authorities and other key stakeholders, and develops and shares lessons learned about this mitigation.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Human resource security
OP-08: Ensure professional The organisation collects and checks The organisation performs all vetting The organisation reviews all vetting activities references and audits of professional references of key personnel activities, including reference checks, drug and supporting documentation at least criminal records of key responsible for the management of IT and tests, and criminal background consistent annually to ensure effectiveness and personnel for IT and OT OT systems, as well as those in critical with documented policies. alignment with defined policies and management (system security roles, such as the Chief Information procedures. administrators, developers, Security Officer (CISO) or Data Protection etc.) and key personnel Officer (DPO). appointed in security roles The organisation performs vetting (e.g., such as CISO or DPO. drug tests, criminal background checks) of key personnel responsible for the management of IT and OT systems, as well as those in critical security roles, such as the CISO or DPO. OP-09: Develop specific and The organisation has developed customized The organisation delivers cybersecurity The organisation incorporates cyber risk mandatory cybersecurity cybersecurity training material and courses training material and courses for key staff factors that may impact critical assets or training courses for some key for key staff areas, including personnel areas, including personnel responsible for services managed by key suppliers or population dealing daily with responsible for IT/OT systems. IT/OT systems, as part of a documented vendors into drills and exercises designed to IT and OT (system admins, The organisation’s cybersecurity training is plan. test Facility Security and/or Incident project managers, Response and Recovery Plans. mandatory for all employees and occurs at The organisation delivers cybersecurity developers, security officers, least annually. and/or cyber risk awareness training to The organisation requires contractors to harbor master, etc.). The organisation informs visitors, employees and contractors before granting confirm that they have delivered access to key assets as part of the cybersecurity awareness training to customers, vendors, contractors, and other partners of established cybersecurity performance of their assigned personnel prior to their arrival at the responsibilities. organisation's facilities. policies and/or advisories defining expectations and responsibilities regarding Cybersecurity and/or cyber risk awareness The organisation's cybersecurity awareness cyber risk concerns and prevention training for administrative personnel is training content identifies the connection measures prior to their entry to the tailored to their job functions and between cyber risk factors and potential organisation’s facilities. responsibilities. impacts to personnel health safety, the environment, and critical system asset Cyber risk factors that may impact the Cybersecurity and/or cyber risk awareness organisation's Facility Security or Incident training for personnel working in a marine security. Response and Recovery Plans have been facility operating environment with OT The organisation identifies lessons learned introduced into drills and exercises but not assets and systems is tailored to their job during drills and exercises that incorporate as part of a documented plan. functions and responsibilities. potential cyber risk factors when testing security and incident response and recovery The organisation's cybersecurity and/or plans. cyber risk awareness training program for all staff covers how cyber risks may Senior leadership regularly evaluates the degrade a port or terminal facility's ability to performance and effectiveness of the operate. organisation's cyber awareness training program to identify where knowledge gaps may exist and to implement improvements to address those gaps.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
OP-10: Set up a security All employees (administrative and The organisation's cybersecurity and/or The organisation manages and monitors awareness-raising program to operations) receive cybersecurity cyber risk awareness training program for cyber risk management activities both address the whole port awareness training reflecting both the all employees includes appropriate use of internally and across the port ecosystem to ecosystem, focusing first on organisation's operating environment and social media and cyber risks related to identify opportunities for refining training the main threats (e.g. social the broader port ecosystem within which it social media exploitation. content. engineering). operates.
Supply chain management
OP-11: Strictly control access The organisation restricts third-party access The organisation manages third-party The organisation periodically reviews of third parties to port systems to port systems. access to port systems based on policies defining third-party access control by only granting access on documented policies and protocols that protocols for accuracy and effectiveness. demand, in a specified time define specific time frames, objectives (visit window, for a specific purpose) and strict minimum privilege purpose, and in a least requirements (least privilege). privileged way OP-12: Clearly define all The organisation maintains agreements and The organisation has a documented Agreements with all third parties supporting relevant aspects of the contracts with third parties that include clear process that facilitates the annual review of critical systems include audit clauses partnership with third parties, descriptions of all goods and/or services all agreements and contracts with all third (clauses that allow the organisation to including security, within the procured, relevant terms and service levels, parties supporting critical systems (PCS, validate that the third-party has implemented appropriate agreements and and communication protocols. CCS, security systems, etc.) in order to cybersecurity best practices consistent with contracts, especially for Agreements with third parties supporting revalidate the accuracy of all terms and the terms of such agreements). critical systems provided by conditions, including security. critical systems (PCS, CCS, security, etc.) third-parties (PCS, CCS, include clearly defined security standards All agreements and contracts with third security systems, etc.) and performance requirements. parties supporting critical systems include clearly defined terms and conditions describing breach of security notification procedures.
OP-13: Identify the risks and The organisation categorizes identified risks The organisation has identified and The organisation has a documented process threats at all levels of the port and threats to IT/OT systems, as well as to assigned personnel to collect, prioritize and and/or mechanism in place (risk registry) to to define categories of third parties within the port ecosystem. categorize cybersecurity threat information. support assigned personnel in interpreting incidents and the potential collected cybersecurity vulnerability The organisation evaluates identified risks The organisation has a process and/or impacts by using the results for impact in all port operational areas. methodology for analysing and de- information for impact to critical IT/OT of risk analysis, threat systems. conflicting information received from intelligence, previous incident multiple sources. history, discussion with other ports, etc.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
OP-14: Define a policy and The organisation has identified stakeholder The organisation has established The organisation reviews documented procedures for incident roles and responsibilities for incident documented policies defining stakeholder policies and procedures for incident detection and reaction detection and response. roles and responsibilities at the port or state response, communication, and coordination including the description of The organisation has identified stakeholder level (if applicable) for incident detection, activities least annually for effectiveness. the roles and responsibilities response, communication, and coordination roles and responsibilities for incident The organisation re-validates documented of each stakeholder of the response communications and coordination. activities. policies defining stakeholder roles and port or state level (if The organisation has defined and responsibilities at least annually. applicable), as well as the documented procedures for incident coordination method and detection, response, communication, and communicate this to all coordination activities. relevant parties. OP-15: Improve and keep The organisation incorporates cyber The organisation regularly tests The organisation regularly reviews integrated these (OP-14,15) procedures incident detection, response, documented procedures for incident testing and training activities to identify up-to-date by testing them communication, and coordination activities detection, response, communication, and lessons learned, which it shares among through training exercise, and into training exercises. coordination activities in planned training relevant stakeholders. identification of new feared exercises in order to identify opportunities events. for improvement. The organisation tests documented procedures for incident detection, response, communication, and coordination activities in training exercises when new threats are identified in order to identify opportunities for improvement. OP-16: Consider the setup of The organisation has a Cybersecurity The organisation has a Cybersecurity The organisation’s Cybersecurity Operations a Cybersecurity Operations Operations Centre (SOC) that Operations Centre (SOC) that supports Centre (SOC) relates to similar SOCs to Centre (SOC) including IT accommodates IT/OT environments to integrated (cyber-physical) security support information sharing and coordinated and OT environments to support security requirements. monitoring for its IT/OT environments. incident response support security and cyber The organisation has confidential incidents. The SOCs of the information sharing agreements with port different stakeholders must organisations that participate in SOC collaborate (or can be activities. mutualized) to ensure the detection and reaction of incidents at port level.
OP-17: Define alerting The organisation has a business process, The organisation has established The organisation has documented procedures and identify the methodology, tool, or other mechanism(s) agreements with third parties that define information-sharing policies that define right contacts for each that facilitates collection of cyber risk information sharing requirements with third performance and (where applicable) stakeholder of the port information from selected individuals, port parties. compliance oversight requirements. depending on the incident partners, CSIRTs, and/or national criticality (CISO, port authorities. management and board, The organisation has formally identified and national authorities, CSIRTs, designated specific individual(s) who are etc.). responsible for coordinating internal information sharing sources and activities.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
OP-18: Implement The organisation performs cyber incident The organisation has documented policies The organisation regularly reviews incident procedures for incident reporting and procedures that define cyber incident reporting activities for effectiveness and to reporting and continuous reporting protocols. identify lessons learned. improvement The organisation shares lessons learned among stakeholders to support continuous improvement activities.
Control and auditing
OP-19: Perform regular The organisation performs penetration tests The organisation regularly performs The organisation's senior leadership cybersecurity audits of its networked operating environment to penetration tests of networked operating regularly reviews cyber risk management (penetration testing, red team, identify vulnerabilities. environments in accordance with activities for effectiveness and, when etc.) to check the application The organisation performs ad hoc reviews established security policies and specific gaps and/or vulnerabilities are and effectiveness of security procedures. identified, ensures that the organisation of existing security measures for measures and assess the effectiveness. The organisation performs Red Team tests develops, implements, and documents level of security of port relevant corrective actions. against its organisation's IT/OT operating systems environment to test detection and response The organisation performs Red Team capabilities. assessments that involve integrated cyberphysical attack tactics, techniques and procedures, also referred to as “TTPs”. OP-20: Perform periodic Organisational leadership periodically The organisation has documented policies The organisation re-validates requirements reviews of network rules, reviews network and networked-asset that facilitate regular reviews of network and for network asset configurations and access access control privileges and configurations and access control privileges. networked asset configurations and access controls at least annually. asset configurations. control privileges.
IT and OT physical protection
OP-21: Ensure IT and OT The organisation has appropriately The Port Facility Security Plan identifies (or The organisation periodically reviews systems hosted in the port are deployed safety (fire detection) and security has been updated to identify) safety and documentation of IT/OT system protected following (CCTV) systems to adequately protect security systems that the organisation has maintenance activities to ensure traceability established best practices for IT/OT systems. deployed to protect IT/OT systems. to requirements. safety (fire detection, airconditioning, etc.) and security (access control, CCTV, etc.) OP-22: Keep traceability of all The organisation maintains records of all The organisation maintains maintenance The organisation periodically reviews maintenance operations done security system maintenance activities, documentation on IT and OT physical documentation of IT/OT system on IT and OT physical including software and firmware upgrades systems to ensure traceability of operational maintenance activities to ensure traceability systems and patches. requirements, security objectives, and to requirements. service functionality.
Jmffk gbadbdb CYBER RISK MANAGEMENT FOR PORTS
December 2020
5.5.3 Technical measures
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Network security
TP-01: Define network The organisation segments critical port The organisation has a documented network The organisation review its network segmentation architecture to systems (e.g., VTS/VTMIS, security architecture that segments critical port segmentation at least annually (or when a limit the propagation of systems) from administrative networks with systems (e.g., VTS/VTMIS, security change occurs) to re-validate effectiveness. attacks within the port Internet connectivity. systems) from port networks with Internet systems and avoid direct connectivity. access from the Internet to very critical port systems such as VTS/VTMIS and security systems. TP-02: Perform regular The organisation performs network scanning The organisation has documented policies The organisation has a documented process network scans to detect to detect unauthorized networks (e.g., Wi-Fi) that provide guidance to stakeholders facilitating the analysis of log data to support unauthorized and malicious and devices. performing regular network scans. business operations and security activities. networks (WIFI for example) The organisation regularly reviews policies as well as end-devices acting and procedures supporting network as bridges between two scanning activities to ensure effectiveness. segregated zones (with interfaces in two network zones for example). TP-03: Define parametric The organisation employs parametric The organisation defines parametric security The organisation has a documented policy security, with filtering rules. security. with filtering rules. that provides guidance on parametric security definitions and filtering rules applicable to its operating environment.
Access control
TP-04: Set up centralized The organisation centrally manages user The organisation has implemented a The organisation has identity management tools to manage identities and identities, profiles, and access rights to port centralized credentialing system to manage plans, policies and procedures that define access rights to the port systems. user profiles, identities, and access identity management activities. systems. If different tools are privileges to port systems. The organisation has updated its Port set up, due to diversity of the The organisation centrally manages user Facility Security to include identify port stakeholders (Port identities, irrespective of automatic or management policies and procedures. Authorities, terminal manual provisioning capabilities of specific operators, local authorities, port systems. third-parties, etc.) and their The organisation has identified stand-alone systems, automatic or manual provisioning can be defined. tools for specific systems and they inform centralized administration of user credentials.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-05: Define an Identity & The organisation actively manages access The organisation has a documented identity The organisation has documented Access Management (IAM) rights of port stakeholder identities. and access management strategy. policies/procedures that facilitate regular restrategy and its associated The organisation informs stakeholders of The organisation regularly re-validates user validation reviews of user identities and processes to manage the access rights to port systems. password guidelines. profiles. lifecycle of identities and their The organisation consistently implements The organisation issues user credentials The organisation deactivates user access rights (automatic based on the principle of least privilege. credentials upon termination or a change in identity and access management activities deactivation of accounts, across all areas of the organisation. regular review, least privilege duties. principle and segregation of duties, password guidelines, etc.). This strategy must be, as much as possible, built in common with the stakeholders of the port ecosystem. TP-06: Forbid as much as The organisation employs user accounts The organisation has documented policies The organisation regularly reviews and repossible the use of generic that are identity-based, not role-based, for that define role-based user accounts as a validates user accounts for sensitive accounts, by enforcing unique all port systems, especially sensitive requirement. systems. and individual accounts in all systems (PCS, CCS, TOS, VTS/VTMIS, port systems, especially for security, etc.). sensitive systems (PCS, CCS, TOS, VTS/VTMIS, security systems). TP-07: Enforce, whenever The organisation's passwords force users to The organisation has a documented policy The organisation reviews its documented possible, password apply a minimum number of characters with that establishes minimum requirements for password policy and supporting rules at complexity policies and rules alpha-numeric complexity. password complexity and refresh rules (e.g., least annually to ensure effectiveness. for systems. every 3 months). TP-08: Implement multi-factor The organisation employs multi-factor The organisation has implemented multi- The organisation regularly reviews authentication mechanisms authentication at least on an ad hoc basis. factor authentication for all critical documented policies and/or procedures for accounts accessing critical applications and systems (i.e. PCS, CCS, defining multi-factor authentication for applications (especially for TOS, VTS/VTMIS). effectiveness. PCS, CCS, TOS, The organisation has implemented multi- VTS/VTMIS) and data factor authentication to control access to the (personal data, sensitive organisation's data (e.g., personal data, operational data such detailed sensitive operational data regarding vessels, information on vessels, dangerous goods, cargos, financial dangerous goods and cargo), information, etc.) and in case of poorly or The organisation has documented policies unprotected environments (external access through and/or procedures that define multi-factor authentication requirements for accessing Internet for example, thirdparty access from other port systems and networks. corporate networks, etc.).
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-09: Consider physical The organisation has established physical The organisation has documented physical The organisation periodically re-validates access in the access lifecycle access security requirements for port/ port access control requirements within the Port/ and reviews documentation establishing (port facilities, port area, facilities, including restricted areas. Port Facility Security Plan. physical and remote access control buildings, etc.) and define requirements for effectiveness. The organisation has defined and specific measures for remote documented remote access security access. requirements and protocols for port facilities. TP-10: Regularly perform The organisation reviews access rights of The organisation has a documented policy The organisation evaluates access rights at accounts and access right stakeholders with access to sensitive data that defines requirements for periodically least annually to ensure effectiveness. reviews to ensure accesses (personal data, sensitive operational data, reviewing access rights of all stakeholders The organisation evaluates access rights are still legit, especially for and dangerous goods). with access to sensitive data. reviews at least annually to ensure the accounts that have access to The organisation has a documented policy effectiveness of privacy controls. sensitive data (personal data, that defines access rights to data subject to sensitive operational data, privacy requirements. dangerous goods information, etc.).
Administration and configuration management
TP-11: Define installation and The organisation employs operational The organisation has documented The organisation periodically reviews configuration policy and rules security baselines to protect port systems. installation and baseline configuration documentation supporting installation and and establish security The organisation employs baseline policies for essential security platforms and baseline configuration activities to revalidate baselines to only install essential port system equipment. security platforms and essential port system functional configurations for port security needed services and equipment and essential systems. equipment to ensure ongoing functionality. functionalities and authorize The organisation has established installation essential equipment for the security and the functioning of configurations of security equipment based on functional requirements. port systems. TP-12: Set up specific The organisation has dedicated and The organisation has defined and The organisation periodically reviews accounts only used by documented administrator accounts for each documented administrator account lifecycle administrator account lifecycle management administrators to perform system with exclusive privileges for management processes. processes for effectiveness and adherence administration operations performing administrative operations. Third party administrator accounts comply to plan. (installation, configuration, with the organisation’s account lifecycle The organisation requires third parties with The organisation periodically audits third maintenance, supervision, administrative privileges to comply with its management processes and third parties party administrator accounts for compliance etc.). own security policies on managing may be asked to provide evidence of with organisational processes and policies. administrator accounts compliance. Administrator account requirements for third parties are integrated in the organisation’s procurement processes. TP-13: Define Privilege The organisation employs Privilege Account The organisation has defined and The organisation periodically reviews Account Management (PAM) Management (PAM) processes to support documented PAM processes, related documented PAM processes, related process, security security requirements security requirements, and lifecycle security requirements, lifecycle management requirements on those management rules. rules, and supporting procedures for The organisation requires third parties with accounts and rules to manage administrative privileges to follow PAM effectiveness and adherence to plan. their lifecycle. Especially processes. enforce this process for thirdparties who oversee administration operations.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-14: Set up, as much as The organisation employs additional security The organisation has established dedicated The organisation has documented policies possible, dedicated policies for accessing critical systems (e.g., safe zone(s), separated by a firewall, to and procedures that establish dedicated administration networks to VTS/VTMIS, security systems) in networked support critical systems (e.g., VTS/VTMIS, safe zones for critical systems. create safe zones, in priority environments. security systems). The organisation reviews safe zone for critical systems (especially configurations supporting critical systems for for VTS/VTMIS, Radio effectiveness at least annually, or whenever systems, security systems, a change occurs to the environment. etc.).
Threat management
TP-15: Ensure anti-malware, The organisation employs and maintains as The organisation has a documented policy The organisation periodically reviews antianti-spam and anti-virus is current anti-malware, anti-spam, and anti- that defines minimum requirements for anti- malware, anti-spam and anti-virus solutions installed and up to date on all virus on all port systems, including desktops malware, anti-spam, and anti-virus to ensure they are performing in accordance port systems, including and servers. implementations on all port systems. with requirements. desktops and servers.
Cloud security
TP-16: Define a cloud security When considering engaging a cloud solution The organisation utilizes a documented As part of the security assessment assessment method to vendor, the organisation analyses the security assessment framework to guide framework the organisation uses in evaluate the impact and the potential impact and risk to applicable laws stakeholders in evaluating potential cloud evaluating cloud solution providers, the risks of choosing cloud and regulations. solutions for risk and impact related to organisation performs an operational impact solutions by considering applicable laws and regulations. analysis to further quantify the potential risks applicable laws and as they relate to applicable laws and regulations. regulations.
TP-17: Include, as much as The organisation incorporates language The organisation maintains and regularly The organisation regularly reviews possible, security and describing minimum-security criteria reviews and updates documented policies agreements with cloud security providers to availability aspects in regarding data access, transmission, defining minimum-security criteria in ensure that data access, security, agreements with cloud storage, and availability terms in all agreements with cloud security providers. transmission, storage, and availability terms security providers. agreements with cloud security vendors. are consistent with best practices.
TP-18: Try to include, as The organisation applies cloud solutions to The organisation has incorporated cloud The organisation regularly reviews the much as possible, Cloud support cyber threat detection solutions in support of cyber threat detection applicability and performance of applied solutions in the detection and The organisation applies cloud solutions to to its policies and procedures cloud solutions that support cyber threat response mechanisms. detection support cyber incident response The organisation has incorporated cloud solutions in its cyber incident response The organisation regularly reviews the policies and procedures applicability and performance of applied cloud solutions that support cyber incident response
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
Machine-to-machine security
TP-19: Implement The organisation secures machine-to- The organisation has established The organisation periodically reviews mechanisms to secure machine communication exchanges (e.g., documented policies and procedures that documented policies and procedures machine-to-machine EDI messages). define security for all machine-to-machine guiding machine-to-machine exchanges (including EDI communications. communications to ensure alignment with The organisation requires that machine-tomessages and API mostly machine communication exchanges via the The organisation has established the organisation's defined performance used with external requirements. Internet employ secure authentication documented policies and procedures that stakeholders, such as protocols, such as encryption, PKI, digital define authentication protocols for all shipping companies) and certificates, digital signatures, time Internet-based communications. provide mutual authentication, stamping, etc. integrity and confidentiality with the port systems such as encryption, PKI or digital certificates, integrity checks, digital signature, time stamping, especially when exchanges are done over the Internet.
TP-20: Use communication The organisation's stakeholders employ The organisation has clearly established The communication protocol security protocols that include a standardized re-validation procedures to communication re-validation protocols within process is evaluated periodically to assess functionality to detect if all or confirm messaging. a documented policy or procedure. effectiveness part of a message is an unauthorized repeat of a previous message
Data protection
TP-21: Implement The organisation employs cryptography to The organisation has documented The organisation reviews documented cryptography procedures and protect data confidentiality, authenticity, cryptography procedures and mechanisms cryptography procedures and mechanisms mechanisms to protect and/or integrity of port systems. to protect data confidentiality, authenticity, to protect data confidentiality, authenticity confidentiality, authenticity and/or integrity of port systems (which and/or integrity of port systems (which and/or integrity of data in the includes data at rest and in transit). includes data at rest and in transit) at least port systems (at rest, in transit annually for effectiveness. or in use). This measure shall be implemented depending on the data classification done.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-22: Anonymize and The organisation anonymizes processed The organisation has documented policies The organisation regularly reviews all secure any direct or indirect personal data. and procedures that define security and documented policies and procedures personal data processed anonymization requirements for personal managing privacy requirements for personal The organisation has reviewed all legal within the company, e.g. requirements regarding data privacy. data creation, processing, transmission, and data for appropriateness and effectiveness. through role-based access storage. The organisation encrypts personal data at control and encryption, having considered all relevant legal rest and in transit. requirements.
Update management
TP-23: Define an update The organisation assesses inventoried The organisation has a documented plan To ensure adherence to documented management process to assets to determine if they are obsolete, that defines change management policies performance objectives, the organisation ensure that port IT and OT and, if so, disables or disconnects them from and configuration management procedures has a process that facilitates the regular assets are up-to-date, and, if the network. for inventoried assets. monitoring of asset inventorying and change not possible, apply The organisation secures obsolete and/or The organisation implements System management activities. compensatory measures unsupported assets through compensatory Development Life Cycle practices to (network segregation, security measures (e.g., network manage assets and systems supporting accounts hardening, etc.), segregation). critical services. especially for legacy systems (OT systems without any possible update, obsolete but critical applications, etc.). TP-24: Verify endpoints' The organisation verifies endpoint device The organisation has documented policies The organisation periodically reviews software/firmware authenticity software and firmware at deployment and defining endpoint device software and documented policies facilitating endpoint and integrity and ensure tight periodically re-validates them thereafter. firmware verification and re-validation device software and firmware verification control over the update. procedures. and re-validation procedures. TP-25: Verify the source of The organisation verifies software and The organisation evaluates software and The software and firmware update the update and execute firmware updates and their sources. firmware updates for cyber risk prior to verification process is reviewed periodically automatic update procedures entering them into service. for effectiveness. only if they are based on the risk analysis.
Detection and monitoring
TP-26: Monitor availability of The organisation monitors the availability of The organisation has documented policies The organisation regularly reviews technical the port systems and devices critical port systems and devices (e.g., and procedures that define technical monitoring activities for all critical IT/OT in real time, where technically computer workstations, VTS/VTMIS, radar, monitoring requirements for all critical IT/OT systems for effectiveness. feasible, by focusing first on and security systems) systems. the critical systems and The organisation actively monitors all critical devices such as networked IT/OT systems, where feasible. administration workstations, radio systems and enddevices, VTS/VTMIS, radar systems or security systems and OT end-devices, etc.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-27: Set up logging system The organisation performs event logging of The organisation’s event logging of access The organisation regularly reviews event to record events related, at access control activities. control activities includes user logon and logs. least, to user authentication, authentication, access right and security The organisation regularly reviews management of accounts and modifications, and asset/device/system documentation governing event logging access rights, modifications to access. criteria and monitoring activities to security rules, and the The organisation has documented policies determine effectiveness. functioning of the port and procedures that define event logging systems. and monitoring requirements. TP-28: Set up log correlating Organisational stakeholders correlate event The organisation has implemented tools The organisation regularly reviews event and analysis systems to logs at least in an ad hoc fashion. (e.g., security information event correlation activities for effectiveness. detect events and contribute management) that enable event log to cybersecurity incident correlation and analysis for enhanced detection. cybersecurity detection. The organisation has identified and assigned individuals to support event correlation activities. The organisation has documented policies and procedures that define event correlation, analysis, and alerting activities for monitored assets and/or systems.
Industrial control systems security
TP-29: Consider OT systems The organisation segregates all IT and OT The organisation has established The organisation regularly reviews IT/OT into all the security measures networks. documented IT/OT network segmentation network configurations to ensure persistent defined in this report to secure requirements, including architectures, separation between administrative networks as much as possible the supporting security measures, policies, and industrial controls systems and industrial control systems and controls, and procedures for maintaining networks supporting operations. networks. If these cannot be organisational configurations. applied, define and implement compensating measures (network segregation, accounts hardening, etc.) TP-30: Ensure network The organisation segregates all IT and OT IT and OT network segregation is not only IT and OT network segregation is tested segmentation between IT and networks. logical but physical (e.g. separate network periodically and evaluated for effectiveness. OT systems. devices for IT and OT)
CYBER RISK MANAGEMENT FOR PORTS
December 2020
Security measure Examples/evidence for maturity level 1 Examples/evidence for maturity level 2 Examples/evidence for maturity level 3
TP-31: When implementing When implementing IoT systems, the When implementing IoT systems, the When deploying an IoT system, the IoT, consider setting up organisation secures and centralizes access organisation has documented secure organisation establishes documented specific security measures. logs of IoT devices. password policies that provide specific escalation and vulnerability reporting guidance for changing default passwords. procedures with ongoing vendor support. When implementing IoT systems, the organisation changes default passwords The organisation employs single-sign-on When procuring IoT systems, the upon implementation. tools to manage access to IoT systems and organisation selects platforms/devices that devices. enable encryption. When implementing IoT systems, the organisation employs encryption protocols When implementing IoT systems, the When procuring IoT systems, the to secure communications. organisation establishes documented organisation selects platforms/devices policies defining encrypted protocols for where the vendor has clearly defined secure When implementing IoT systems, the organisation trains staff to recognize secure communications. firmware update policies. security alerts related to IoT endpoints. When implementing IoT systems, the organisation implements restrictive network communications policies and sets up virtual LANs.
Backup and restore
TP-32: Set up backups and The organisation tests backup systems for The organisation has documented policies The organisation regularly reviews backup ensure they are regularly critical IT/OT systems. and procedures that facilitate maintenance activities to ensure that they are performed maintained and tested, and testing of all backup infrastructure according to relevant plans. especially for most central supporting critical IT/OT systems (including and critical systems, like Active Directory) Active Directory, PCS, CCS, TOS, etc.
CYBER RISK MANAGEMENT FOR PORTS
December 2020
6. SUMMARY
This report offers some practical and actionable good practices to support port operators in conducting effective cyber risk management. Regardless of the framework or methodology used to conduct a cyber risk assessment, port operators are typically confronted by the same challenges related to the complexity of the increasingly integrated IT/OT environment, lack of expertise, security risk management responsibilities split between different operational areas and/or business units, etc. The proposed good practices in this report can be implemented in alignment with any standard risk management methodology, including the framework defined in the ISPS Code, Regulation 725/2004 and Directive 2005/65. Moreover, this report offers practical guidance on how port operators can use the taxonomies introduced in ENISA’s 2019 report on Port Cybersecurity to support their cyber risk management activities. Finally, building on the security measures described in the 2019 ENISA report, this document introduces three maturity levels for assessing their organisational cybersecurity capability maturity. Findings derived from these efforts can be used to identify operational vulnerabilities, prioritize security and allocate their cybersecurity resources in a sustainable manner. People responsible for cyber risk management in port operators can use this document by tailoring the guidelines, good practices and resources presented for each phase of the proposed four-phase approach to their own cyber risk management methodologies and operational and organisational context. Moreover, for each phase port operators may consult the relevant list of common challenges to identify those good practices most relevant to their needs. The four phases are: Phase 1: Identifying cyber-related assets and services; port operators may use the guidelines, good practices and resources/taxonomies presented here to identify their assets and services that should be addressed in the context of cyber risk management more effectively Phase 2: Identifying and evaluating cyber-related risks; port operators may adapt the guidelines, good practices and use the relevant taxonomies in the context of their risk identification and evaluation methodologies. Phase 3: Identifying security measures; port operators may use the guidelines, good practices and reference security measures to prioritise those security measures that would be most impactful and practical in the context of their own cyber risk management. Phase 4: Assessing cybersecurity maturity; port operators may adapt and employ the proposed model in performing cybersecurity maturity self-assessments for the security measures selected in phase 3, identifying priorities for investing resources for improvement and/or building the programmatic foundations for organisational cybersecurity maturity. CYBER RISK MANAGEMENT FOR PORTS
December 2020
A ANNEX: NATIONAL APPROACHES
In addition to the national transpositions of the EU NIS Directive and of the EU maritime security legislation into their national law, several EU member states have developed and introduced national strategies, guidelines, frameworks or standards that include a cyber risk assessment component, which can be employed by port stakeholders, such as: The Baseline Informatiebeveiliging Rijksdienst standard (BIR 2012), in The Netherlands; The BSI-Standard 200-3: Risk Analysis based on IT-Grundschutz], Standard -1 Information Security Management Systems (ISMS) and BSI-Standard -2: IT- Grundschutz from the Federal Office for Information Security (BSI) in Germany; The Critical Infrastructures Information Protection” (CIIP) Law and the EBIOS Risk Manager Method and related guides from the French Government. Controlling the Digital Risk published by ANSSI and AMRAE . The Danish Cyber and Information Security Strategy ; The Methodology for Information Systems Risk Analysis and Management (MAGERIT) (Spain, Ministry for Public Administrations); Guidelines and good practices for cybersecurity risk management in vessels and port facilities (Spain, National Maritime Security Council). Non-EU countries have also published relevant guidelines, most notably the US Coast Navigation and Vessel Inspection Circular No. 01-20: Guidelines for Addressing Cyber Risks at Maritime Transportation Security Act (MTSA) Regulated Facilities and the NIST Framework for Improving Critical Infrastructure Cybersecurity. CYBER RISK MANAGEMENT FOR PORTS
December 2020
B ANNEX: INDUSTRY STANDARDS AND METHODOLOGIES
There are several international or industry standards and risk methodologies that, although not port specific, can be referenced by port stakeholders in their efforts to conduct cyber risk assessments. An indicative list is tabulated in Table 3 below: Table 3: Standards and methodologies currently used by port stakeholders Publication Description International Organisations ISO/IEC 27001:2013 It specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organisation. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organisation. ISO/IEC 27002:2013 It provides guidelines for organisational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organisation's information security risk environment(s). ISO/IEC 27005:2018 It provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. ISO/IEC 27701:2019 It specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the context of the organisation. ISO/IEC 28000:2007 It specifies requirements for a security management system, including those aspects critical to security assurance of the supply chain. Security management is linked to many other aspects of business management ISO/IEC 31000 series The series provide principles, a framework and a process for managing risk. It can be used by any organisation regardless of its size, activity or sector. ANSI/ISA/IEC 62443 series The series provide a flexible framework to address and mitigate current and future security vulnerabilities in industrial automation and control systems (IACSs). ISO 28005-2:2011 The standard contains technical specifications that facilitate efficient exchange of electronic information between ships and shore for coastal transit or port calls. It is intended to cover safety and security information requirements related mainly to the relationships between the ship and the port and coastal state authorities. CYBER RISK MANAGEMENT FOR PORTS
December 2020
HMG IA Standard No 1 Technical Risk Assessment – IA Standard for Risk Managers and IA Practitioners responsible for identifying, assessing and treating the technical risks to ICT systems and services handling HMG information. Supplier Information Guidance on how the Supplier Information Assurance Tool (SIAT) Assurance Assessment question sets and tool specification can be used by suppliers of key Framework and Guidance business services to HMG. Supplier Information A brief summary of the Supplier Information Assurance Tool (SIAT) Assurance Tool (SIAT) – Community of Interest set up to drive development of a supplier Summary Information Assurance model. ISAB Approved. Shipping Industry Guidelines IMO Guidelines on Maritime MSC-FAL.1/Circ.3 Guidelines on maritime cyber risk management Cyber Risk Management provide high-level recommendations on maritime cyber risk management to safeguard shipping from current and emerging cyber threats and vulnerabilities and include functional elements that support effective cyber risk management. Resolution MSC.428(98)- Maritime Cyber Risk Management in Safety Management Systems encourages administrations to ensure that cyber risks are appropriately addressed in existing safety management systems no later than the first annual verification of the company's Document of Compliance after 1 January 2021 BIMCO Guidelines on Cyber It is designed to assist shipping companies in formulating their own Security Onboard Ships approaches to cyber risk management on-board ships, providing a risk-based approach to identifying and responding to cyber threats. Generic Risk Assessment Methodologies CCTA Risk Analysis and It comprises three stages, each supported by objective Management Method questionnaires and guidelines. The first two stages identify and (CRAMM) analyse the risks to the system. The third stage recommends how these risks should be managed. Center for Internet Security CIS RAM is an information security risk assessment method that Risk Assessment Method helps organisations implement and assess their security posture (CIS RAM) against the CIS Controls cybersecurity best practices. Risk Assessment Matrix It is a project management tool that allows risks to be evaluated in (RAM) terms of the likelihood or probability of the risk and the severity of the consequences. Hazard and Operability Study It is a structured and systematic examination of a complex planned or (HAZOP) existing process or operation in order to identify and evaluate problems that may represent risks to personnel or equipment Failure mode and effect It is an analysis tool used to determine the chance of failure and the analysis (FMEA) ensuing risks in developmental processes of services, products or production methods. What-if Analysis It is a tool that runs reverse calculations, sensitivity analysis and scenarios comparison. Bow-Tie Analysis (BTA) It is a tool that displays the links between the potential causes, preventative and mitigating controls and consequences of a major incident. Fault Tree Analysis (FTA) It is a tool that facilitates the determination of the cause of failure or test the reliability of a system by stepping through a series of events logically. -N -EN -790 -20 -02 TP ABOUT ENIS A The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. For more information, visit www.enisa.europa.eu. ISBN 978-92-9204-403-9 DOI: 10.2824/671060
Fotnoter
- 2 https://ec.europa.eu/transport/modes/maritime_en 3 See https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32016L1148 4 See https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2005:310:0028:0039:FR:PDF 5 See https://eur-lex.europa.eu/legal-content/En/TXT/?uri=CELEX%3A32004R0725 6 https://www.enisa.europa.eu/publications/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector 7 See paragraph (13) page L.194/3 of https://eur-lex.europa.eu/legalcontent/EN/TXT/PDF/?uri=CELEX:32016L1148&from=EN See paragraph (44) page L.194/8 of https://eur-lex.europa.eu/legalcontent/EN/TXT/PDF/?uri=CELEX:32016L1148&from=EN 9 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32005L0065
- ISO 31000:2018, Risk management – Guidelines 11 ISO 31010:2009 – Risk Management – Risk assessment techniques 12 https://www.enisa.europa.eu/publications/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector
- 13 A key common factor behind all these challenges is how cybersecurity is positioned in the maritime sector. Cyber security is still mainly viewed as an IT problem. Isolating cybersecurity in the IT department and lack of appropriate reporting lines for cyber risk within the organisation results in limitations in terms of responsibility, competences, approach, resources, budget, etc.
- 14 See https://www.ssi.gouv.fr/uploads/2019/11/anssi-guide-ebios_risk_manager-en-v1.0.pdf https://www.ssi.gouv.fr/uploads/2019/04/mapping_the_information_system-anssi-pa-046.pdf https://www.ssi.gouv.fr/uploads/2014/01/Managing_Cybe_for_ICS_EN.pdf https://www.ssi.gouv.fr/uploads/2014/01/industrial_security_WG_detailed_measures.pdf https://www.ssi.gouv.fr/uploads/2014/01/industrial_security_WG_Classification_Method.pdf https://www.ssi.gouv.fr/uploads/2014/01/Use_Case_EN.pdf 15 https://www.ssi.gouv.fr/en/guide/controlling-the-digital-risk-the-trust-advantage/ 16 See https://digst.dk/media/16943/danish_cyber_and_information_security_strategy_pdfa.pdf 17 See https://www.enisa.europa.eu/topics/threat-risk-management/risk-management/current-risk/risk-managementinventory/rm-ra-methods/m_magerit.html and https://www.pilartools.com/doc/magerit/MAGERIT_v_3_%20book_1_method_PDF_NIPO_630-14-162-0.pdf 18 https://www.federalregister.gov/documents/2020/03/20/2020-05823/navigation-and-vessel-inspection-circular-nvic-01-20guidelines-for-addressing-cyber-risks-at