Qualitative Risk Assessment of Cybersecurity and Development of Vulnerability Enhancement Plans in Consideration of Digitalized Ship

被引:20
|
作者
Yoo, Yunja [1 ]
Park, Han-Seon [1 ]
机构
[1] Korea Maritime Inst, Maritime Safety Dept, Busan 49111, South Korea
关键词
cybersecurity; cyber threat; risk identification; risk matrix; risk assessment; MARITIME CYBERSECURITY;
D O I
10.3390/jmse9060565
中图分类号
U6 [水路运输]; P75 [海洋工程];
学科分类号
0814 ; 081505 ; 0824 ; 082401 ;
摘要
The International Maritime Organization (IMO) published the Guidelines on Maritime Cyber Risk Management in 2017 to strengthen cybersecurity in consideration of digitalized ships. As part of these guidelines, the IMO recommends that each flag state should integrate and manage matters regarding cyber risk in the ship safety management system (SMS) according to the International Safety Management Code (ISM Code) before the first annual verification that takes place on or after 1 January 2021. The purpose of this paper is to identify cybersecurity risk components in the maritime sector that should be managed by the SMS in 2021 and to derive priorities for vulnerability improvement plans through itemized risk assessment. To this end, qualitative risk assessment (RA) was carried out for administrative, technical, and physical security risk components based on industry and international standards, which were additionally presented in the IMO guidelines. Based on the risk matrix from the RA analysis results, a survey on improving cybersecurity vulnerabilities in the maritime sector was conducted, and the analytic hierarchy process was used to analyze the results and derive improvement plan priority measures.
引用
收藏
页数:14
相关论文
共 38 条
  • [1] The inhospitable vulnerability: A need for cybersecurity risk assessment in the hospitality industry
    Chen, Hsiangting Shatina
    Fiscus, Joseph
    JOURNAL OF HOSPITALITY AND TOURISM TECHNOLOGY, 2018, 9 (02) : 223 - 234
  • [2] Consideration on improvement of qualitative risk assessment (Quantification of qualitative risk matrix for PHA)
    Mori, Yasushi
    Sugimoto, Noboru
    Nihon Kikai Gakkai Ronbunshu, C Hen/Transactions of the Japan Society of Mechanical Engineers, Part C, 2009, 75 (759): : 3113 - 3121
  • [3] Systematic literature review of threat modeling and risk assessment in ship cybersecurity
    Erbas, Muhammed
    Khalil, Shaymaa Mamdouh
    Tsiopoulos, Leonidas
    OCEAN ENGINEERING, 2024, 306
  • [4] Semi-qualitative method for ship collision risk assessment
    Zhang, W.
    Montewka, J.
    Goerlandt, F.
    SAFETY AND RELIABILITY: METHODOLOGY AND APPLICATIONS, 2015, : 1563 - 1572
  • [5] Ship Cybersecurity Risk Assessment for Safe Operation with Human Involvement: An Experimental Case Study
    Chae, Chong-Ju
    Kim, In-Chul
    Baumler, Raphael
    Ahn, Young-Joong
    WMU JOURNAL OF MARITIME AFFAIRS, 2024,
  • [6] Cybersecurity risk assessment of a marine dual-fuel engine on inland waterways ship
    Bolbot, Victor
    Xiang, La
    Brunou, Paivi
    Kiviharju, Mikko
    Ding, Yu
    Banda, Osiris Valdez
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART M-JOURNAL OF ENGINEERING FOR THE MARITIME ENVIRONMENT, 2025, 239 (01) : 67 - 91
  • [7] Development of Easy Risk Assessment Tool for Factory Cybersecurity: Short Paper
    Sasaki, Hiroshi
    Watanabe, Kenji
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, CRITIS 2023, 2024, 14599 : 263 - 269
  • [8] Development of a quantitative risk assessment model for ship collisions in fairways
    Chai, Tian
    Weng, Jinxian
    Xiong, De-qi
    SAFETY SCIENCE, 2017, 91 : 71 - 83
  • [9] Development of qualitative and quantitative AOPs and their integration into risk assessment
    Bois, F. Y.
    Gao, W.
    Yang, H.
    Carta, G.
    van der Stel, W.
    Delp, J.
    Gayraud, G.
    Beltman, J. B.
    Jennings, P.
    Leist, M.
    van de Water, B.
    TOXICOLOGY LETTERS, 2019, 314 : S22 - S22
  • [10] The method of average navigation risk assessment with consideration of inequality of ship's accident probability along the waterway
    Gucma, L
    RISK ANALYSIS II, 2000, 3 : 125 - 134