Here is the honest situation. IMO Resolution MSC.428(98) requires cyber risks to be appropriately addressed in a ship's safety management system under the ISM Code, and the IMO guidelines set out the functional elements: identify, protect, detect, respond and recover. It applies across IT and operational technology and depends on both shore and crew. An operator that runs ships but cannot show cyber risk in its SMS, its protective measures or its response plans is exactly where operators fall short at an ISM audit.
This Kit removes the guesswork. It is the maritime cyber requirement written as adopt-ready controls you personalize in a weekend, with the evidence an auditor examines.
What you get, the moment you buy
Grounded in IMO Resolution MSC.428(98) and the IMO guidelines on maritime cyber risk management, with SMS integration, the identify, protect, detect, respond and recover functions, IT and OT systems, crew training, third-party risk and ISM verification called out. Editable Word and Excel files.
What one control looks like
This is integrating cyber risk into the safety management system, where the requirement begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A duty you cannot evidence is an ISM audit finding. This tells you what an auditor examines and where operators fall short, for every duty.
- Identify-to-recover built in. The SMS integration and the identify, protect, detect, respond and recover functions are written into the controls, the substance the IMO guidelines set out.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The IMO functions mirror the NIST framework, so this work feeds your wider cyber and safety programs.
Who buys this
Shipowners, operators and managers and their DPA, safety, IT and OT leads. Whether it is a first SMS integration or an audit-readiness pass, you save weeks and walk in with identify, protect, detect, respond and recover structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this an ISM certificate? No. It is an implementation toolkit grounded in the IMO guidance. Certification is through your ISM audit; this gets your SMS cyber content and evidence in order fast.
Does it cover operational technology? Yes. Identifying and protecting OT and control systems is built as controls.
Does it cover response and recovery? Yes. Responding to and recovering from cyber incidents and maintaining safe operation are built as controls.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com