NEW
Font size
WorksheetsWK. 15 - IMO regulation for cyber security
Total questions: 15
Worksheet time: 15mins
What is the main reason cyber risk is now part of the SMS under IMO rules?
It affects crew entertainment systems
Cyber incidents can threaten ship safety and operations
It is only for office compliance
It is optional for modern vessels
IMO Resolution MSC.428 requires cyber risk to be included in:
Crew rest hour logs
Ship Safety Management System (SMS)
Garbage Management Plan
Port clearance documents
What can GPS spoofing cause?
Loss of food supplies
False vessel position
Slow crew Wi-Fi
New ballast sensors
In maritime cybersecurity, 'Identify' means:
Restarting all systems
Listing and understanding ship systems and risks
Changing all passwords
Disconnecting from the internet
What is the primary focus of OT/ICS systems on a ship?
Managing crew schedules
Controlling physical ship operations
Providing internet access
Handling payroll
Which year did the IMO mandate cyber risk management in SMS?
2015
2017
2021
2024
What is a potential consequence of malware infection in ECDIS?
Improved navigation accuracy
OT system compromise
Enhanced entertainment
Faster internet speed
IMO requires ships to create a separate “Cyber Manual.”
True
False
Not mentioned
Sometimes true
Remote vendor access to OT systems can be a cyber vulnerability.
True
False
Phishing is a major threat because it tricks crew into giving access or installing malware.
True
False
What is the main reason phishing is considered a major threat?
It damages ship engines
It tricks crew into giving access or installing malware
It causes physical harm
It only affects navigation
Which of the following is NOT an example of an insider threat?
Crew member exposing systems
Hacker from another country
Crew member accidentally sharing passwords
Crew member intentionally leaking data
What is the correct procedure during a cyber incident response?
Ignore alarms
Panic and shut down everything
Follow SMS-approved incident response steps
Allow all port personnel access
What does the IMO require regarding cyber manuals?
Ships must create a separate “Cyber Manual”
Ships do not need a cyber manual
Ships must use the same manual for all risks
Only port authorities need a cyber manual
How is cyber risk audited on ships?
Differently from fire safety
The same way as fire safety and navigation safety
Only by port authorities
Not audited at all
