UR E26/27 Q&A
FAQ / Related Files
UR E26/27 Q&A and Related Files
This page provides Q&A information regarding compliance with UR E26/27 in HTML format. By publishing the questions and answers directly on this page, it improves readability and searchability while also providing quick access to the official Q&A list on Box.
* The HTML version of this FAQ reflects the content as of the update date shown above. For the latest and official version, please refer to the Excel file on Box.
Updated 2026/07/08
How to Use This FAQ
- Use “Search and Filter FAQs” to find the relevant topic, then open the corresponding category heading.
- Stakeholder labels indicate whether each Q&A is mainly relevant to shipowners, integrators, or suppliers.
- For the latest information, please refer to the official Excel file on Box.
Search and Filter FAQs
You can filter FAQs by keyword, category, and stakeholder. You can also expand or collapse all accordion items as needed.
General 3 items
Q4
4.2.1(15) & 5.2.1(10)., Part X of the Rules
Is the term "integrated system" used in Part X, Chapters 4 and 5, the same as "system of systems" used in Chapter 3?
These are different terms defined as follows: An "integrated system" is limited to those that "interact" with each other.
"Integrated system" means a system combining a number of interacting sub-systems and/or equipment organized to achieve one or more specified purposes.
“System of systems” means a system which is made up of several systems. In the context of this Chapter, a system of systems encompasses all monitoring, control and safety systems delivered from the shipyard as a part of a vessel.
Q11
1.1.1, Part X of the Rules
Is it necessary to obtain approval under Chapter 4 of Part X of the Rules for systems and equipment that do not use computer-based systems?
The requirements of Part X of the Rules apply to computer-based systems. Therefore, systems and equipment that do not use computers are not subject to the requirements of Chapters 4 and 5 of Part X, and approval is not required.
Q12 Does a system that uses a microcomputer fall under the category of a computer system?
In Chapters 4 and 5, Part X of the Rules, a "computer-based system" is defined as "a programmable electronic device, or an interoperable set of programmable electronic devices, organized to achieve one or more specified purposes such as collection, processing, maintenance, use, sharing, dissemination, or disposition of information."
The systems that utilize the following are also considered to fall under the definition of a computer-based system as defined in Chapters 4 and 5 of Part X:
-Microcomputer
-PLC
-Embedded PC
-etc.
Ch4 Part X(E27) 40 items
Q5
4.4.1(4)(b), Part X of the Rules
Description of security Capabilities states that " means to update test results and record findings during the testing" should be included. Does this mean that updates and records should be made electronically?
The means for updating and recording observations are not specifically prescribed; therefore, electronic updates or handwritten records on paper are acceptable as long as the method is specified.
Q6
4.1.2-1.(2), Part X of the Rules
For ships listed in this section, it is stated that the guidelines can be used as "non-mandatory guidelines." If this chapter is not applied, is it correct to assume that on-board computer-based systems do not need to be approved in accordance with Chapter 4?
That is correct. However, if the ship applies this chapter, the on-board computer-based systems must comply with Chapter 4.
Q7
Item 2 of Table4.1 in Part X
There is no definition of a human users, but is it correct to understand that it includes not only crew members but also supplier engineers?
That is correct.
Q16
Chapter 4,Part X of the Rules
Who determines whether Chapter 4 of Part X / IACS UR E27 is applicable to a certain system (supplier or system integrator)?
The supplier is to in cooperation with the system integrator determine if this Chapter 4 of Part X / IACS UR E27 is mandatory for the system.
(4.6.1-1, Part X of the Rules)
Q18
Chapter 4,Part X of the Rules
How to find products that have obtained ClassNK's UR E27 (Part X Chapter 4) approval?
Products approved by ClassNK are published on the following website:
https://www.classnk.or.jp/appr_list/material_search.aspx?lang=en
Please turn on the advanced search option, then enter "CY" in the "Approval No.
/Appraisal No." field of the advance search section on the above URL.
Q20
Item 14 of Table4.1 in Part X
Regarding audit storage capacity, are there any specific requirements on the required capacity?
Supplier needs to consider and determine the necessary capacity for incident analysis, taking into account factors such as:
-Logging frequency during normal operation
-Logging frequency during cyberattacks
-Log review intervals
Q21
Table4.1 in Part X
Is it permissible to create a hidden account that is recognized only by the supplier?
Details such as passwords do not need to be included in the documents, but the documents must include a statement that there is a supplier-only account.
Q23
Chapter 4,Part X of the Rules
How the supplier should submit the relevant documents for obtainment of type approval certificate related to UR E27 (Chapter 4, Part X)?
The relevant documents should be submitted to us via NK-PASS. Advanced registration is mandatory for usage of NK-PASS. As for how to register/use of NK-PASS is referred to the following link of our web site.
https://www.classnk.or.jp/hp/zh/activities/portal/nk-pass.html
If it is difficult to submit documents via NK-PASS, email submissions are also acceptable. In this case, please send the documents to the Machinery Department (mcd@classnk.or.jp).
Q32 I think each supplier (manufacturer) will get E27 (Chapter 4, Part X) type approval, but I am concerned about the progress.
You can check the type approved products on the NK website.
(Enter "CY" in the approval number/appraisal number and search)
https://www.classnk.or.jp/appr_list/material_search.aspx?lang=ja
Q33 Are the controllers of thrusters in scope of the rules?
We consider that they are in scope in case they are used as propulsion equipment, or Class 2 or 3 DPS (Dynamic positioning system)component.
In other words, if they are not used for propulsion or DPS, they are not applicable.
However, even in this case, they may still be subject to the requirements depending on the system and/or network configuration of the system and/or the ship. For the details, please refer to the attached file.
(Q10_reference.pdf)
Q36 Is it a prerequisite to obtain UR E10 or E22 approval to obtain UR E27 approval?
Obtaining UR E10 or E22 approval is not a prerequisite for obtaining E27 approval.
Regarding E10 or E22 approval, please consider obtaining approval based on the requirements that require each approval.
Q38
-Does an L3 switch require UR E27 (Chapter 4, Part X) approval?
-Does an L2 switch require UR E27 (Chapter 4, Part X) approval?
-Does a firewall require UR E27 (Chapter 4, Part X)approval?
-If an L3 switch controls communication within the applicable system, or with external systems, E27 approval is required.
-If an L2 switch controls communication within the applicable system, or with external systems, E27 approval is required. However, approval is not required if it is an unmanaged switch.*
(*According to the rules, we consider that the locations where it can actually be used are limited.)
-If a firewall controls communication within the applicable system, or with external systems, E27 approval is required.
Q45
Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use
What documents should the Supplier prepare and submit to NK when obtaining E27 approval?
The documents to be prepared and submitted by the supplier are the following 9 types of documents.
1.Computer-based system asset inventory: A list of hardware and software components constituting the system.
2.Topology diagrams: Diagrams showing the physical and logical network configuration of the system.
3.Description of security capabilities: A document explaining how the system meets the required security capabilities.
4.Test procedure of security capabilities: A document describing how compliance with the required security capabilities is demonstrated by testing.
5.Security configuration guidelines: A document describing the default settings and other information necessary for the system integrator and shipowner to properly install, configure, and operate the system.
6.Secure development lifecycle documents: Documents describing that the supplier has established internal processes and controls to consider security and incorporate appropriate security measures at each stage of the product lifecycle, including planning and requirements analysis, design, implementation, verification, release, maintenance, and end of life.
7.Plans for maintenance and verification of the computer-based system: Documents describing procedures for maintaining, checking, and verifying the security functions of the system.
8.Information supporting the owner's incident response and recovery plan: Information or instructions necessary for the shipowner to prepare and implement incident response and recovery plans.
9.Management of change plan: A document describing the management of change process.
In addition, test reports are to be submitted after type approval has been granted, when the product is assigned to an individual ship. These reports provide evidence, based on the supplier’s internal tests, that design, construction, testing, configuration, and hardening have been completed.
Q46
Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use
If a product obtains the approval of use of systems and equipment with improved cyber resilience (E27 type approval), will the supplier no longer need to submit drawings and conduct shop test in the presence of NK Surveyor?
For products that have been granted E27 type approval, the supplier will need to submit the following 3+2 documents for each vessel to Machinery Department:
-Computer-based system asset inventory (Specific to the individual ship*1)
-Topology diagrams (Specific to the individual ship*1)
-Test reports
-In addition, you must submit the above documents along with an application for omission (*2) that includes which product is assigned to which vessel, and a soft copy of the type approval certificate.
On the other hand, shop tests in the presence of NK Surveyor are not required.
*1. This means, for example, specifying the version information described as a range at the time of type approval (e.g., 1.x→1.1), or identifying the specifications and configurations within the approved scope that are applicable to the individual ship.
*2. For the format of the application for omission, please refer to FAQ Q97.
Q49
Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use
What is the estimated time required to obtain Type approval?
While the timeframe may vary depending on the degree of completion of the submitted documents at the time of submission, etc., it generally takes at least 4 months from the document review to the test witnessing, and at least another 2 months from the test witnessing to the issuance of the certificate.
Q50
Chpater 4, Part X
Is there a provision for omitting document submission and/or attendance at surveys for E27 individual approval in cases where a system lacks Type approval but shares specifications with a previously approved system on a sister vessel?
Regarding the possibility of omitting without a Type approval, the details are as follows:
-Submission of drawings: "Reuse" of drawings using our drawing submission system "NK-PASS" is possible.
-Attendance survey:It cannot be omitted.
(Q50_reference.pdf)
※We initially explained that when installing the same system on sister vessels, the document submission and the attendance at surveys could be omitted. This was also explained in the "Guidelines on Cyber Resilience of on-board systems and equipment(Edition 1.0)".
Q56
Chpater 4, Part X
Is there a way to find out about products that are currently under application (under review) for UR E27 (Chapter 4 of Part X) Type approval?
NK does not disclose information about products that are currently under review.
Q59
Regarding the following four documents required by E27(Chapter 4, Part X), E27 Section 3.1 (4.4.1, Part X) states that "This documents/documentation is to be submitted to the Society "upon request". Could you please clarify in which cases submission to NK is required?
-Secure development lifecycle documents
-Plans for maintenance and verification of the computer-based system
-Information supporting the owner’s incident response and recovery plan
-Management of change plan
In principle, submission is required.
(By the way, if you are reusing documents previously submitted to ClassNK for approval under Part X, Chapter 3 / E22, you may omit submission by specifying this in the application form 7-10.)
Q62 Regarding systems or equipment installed on E26 applicable ships, could you please tell me in what cases E27 approval is not required?
We believe that the cases where chapter 4 of Part X (E27) approval is not required (outside the scope of application) can be organized into the following three cases. ※1
-Case 1: Not a computer-based system
-Case 2: It is a computer-based system, but it is not an applicable OT system ※2
-Case 3: It is a computer-based system and an applicable OT system, but it can be excluded from the application by the exclusion provision of X5.5 (Chapter 6 of E26).
※1: Computer-based systems include network devices.
※2: Except for cases where the applicable computer-based system has functions for IP communication with other systems.
Q63 Is it possible to obtain E27 approval for individual components (e.g., a general-purpose PLC alone) that make up computer-based system?
Even if an individual component obtains E27 approval, it is necessary to obtain E27 approval again for the entire computer-based system in a configured state.
Q66
I would like to know about the process of assigning E27 type approved products to individual vessels.
1. Is a witness test required?
2. Is it necessary to submit any documents?
3. Will a certificate be issued?
4. Is there a specific format for the application for omission?
1. A witness test is not required.
2. For each vessel, you will need to submit the following 3+2 documents to the ClassNK Machinery Department:
-Computer-based system asset inventory (Specific to the individual ship)
-Topology diagram (Specific to the individual ship)
-Test Report signed by the supplier
-An application for exemption stating which products will be assigned to which vessels, and a soft copy of the type approval certificate.
3.No certificate will be issued. (However, if a witness test is conducted due to requirements other than E27, a certificate may be issued based on those requirements and test result.)
4. A specific format is not required. For the format of the application for omission, please refer to FAQ Q97.
Q72
Regarding UR E27 type approval:
-How can I obtain type approval?
-Where can I find detailed information about type approval?
-Which application form should I use for the type approval application?
-What documents are required when applying for type approval?
-What methods are available for submitting the documents for type approval?
-Who should I contact regarding the fees for type approval?
-What is the validity period of type approval?
At first, please refer to the dedicated portal including guidelines ClassNK has created, FAQ, etc.
https://www.classnk.or.jp/hp/zh/activities/cybersecurity/ur-e26e27.html
■Application Form
Applicants for type approval should submit application form “Form 7-10(E)” to Machinery Department.
■Document Submission
At the time of application, the application form and following documents are to be submitted.
1. CBS asset inventory
2. Topology diagrams
3. Description of Security capabilities
4. Test procedure of security capabilities
5. Security configuration guidelines
6. Secure development lifecycle documents
7. Plans for maintenance and verification of the CBS
8. Information supporting the owner’s incident response and recovery plan
9. Management of change plan
The application form and following documents are to be submitted in one of the following ways.
a)NK-PASS
b)Email (mcd@classnk.or.jp)
c)Regular mail (three copies of each document are to be submitted.)
■Estimated time
The estimated time required to obtain type approval is a total of 6 months, with 4 months for drawing review and 2 months from testing to certificate issuance.
■Approval fee
For inquiries regarding fees, please contact the Machinery Department (mcd@classnk.or.jp) and include an overview of your product as well as details of its network configuration by your e-mail.
■Validity Period
Valid for 5 years.
Q73
Table X2.3, Part X / E27 Appendix II
4.4.1(10), Part X / E27 3.1.10
Even after obtaining E27 Type Approval, the submission of a "Test Report" is required for each product/ship. Does this refer to the report of Test of security capabilities (2.2.2.3, Part X) conducted at the time of obtaining the E27 Type Approval?
No, this does not refer to the test report of Test of security capabilities generated when obtaining Type Approval.
It is documentation serving as evidence that security function configuration and hardening have been implemented for each product/ship. This refers to the results of the supplier's internal tests concerning these specific implementations.
Please note that although the wording in UR E27 is somewhat unclear on this point, we consider that this does not require conducting Test of security capabilities via internal testing for every individual ship.
Q76
Is it possible to issue a single type approval certificate that integrates the existing E10 and E22 certificates with the E27 certificate?
・E10(Environmental performance)
・E22(Manufacturing quality of computer systems)
・E27(Cyber resilience of computer systems)
It is possible to combine the type approvals for the E10, E22, and E27 requirements into one certificate. Please notify us of your intention when applying for type approval. (Select yes or no in the checkbox on application Form 7-10.)
・E10: Guidance for the Approval of Materials and Equipment for Marine Use, 7-1, Automatic Devices and Equipment
・E22: Guidance for the Approval of Materials and Equipment for Marine Use, 7-8, Computer Based Systems
・E27: Guidance for the Approval of Materials and Equipment for Marine Use, 7-10, Equipment with Improved Cyber Resilience
(Form 7-10 Example: Q76_reference.pdf)
However, the following points should be considered:
・If integrating with an existing certificate, the shortest expiration date will apply. (Or you can apply for renewal at the same time)
Differences in the components included in the approval scope.
Differences in the intended purpose of the system.
Q82 Is there a template or sample format for the E27(Chapter 4, Part X) documents to be submitted by a supplier?
To help you understand the expected content for the documents listed below, we have prepared examples detailing some security capabilities. Please use these for reference:
-Description of security capabilities (Example Description_Description of security capabilities.pdf)
-Test procedure of security capabilities (Example Description_Test procedure of security capabilities.pdf)
Q87 Is it mandatory to prepare an English version of the documents for E27 Type Approval?
According to the Rules, the preparation of an English version of the documents for E27 Type Approval is not a mandatory requirement.
However, please note that the type approval documents you submit will be handed over from the Supplier to the Shipyard, and then from the Shipyard to the Shipowner, in accordance with the provisions of the Rules. Therefore, if it is anticipated that your product will be used by overseas Shipowners or crew, it is strongly recommended that you prepare an English version of these documents.
Part X, 4.6.2-3 / E27, 6.2, Part X, 2.2.3-2.(5) / E26, Ch.5
Q88
Can a VPN connection itself be counted as one of the "factors" for multi-factor authentication?
Part X 4.4.3, Table X4.2 / UR E27 4.2, Table 2, No. 31
To be precise, the VPN connection, which is a communication channel, is not an authentication factor in itself. However, it is considered possible to achieve multi-factor authentication by incorporating a "device certificate" into the VPN's authentication process.
In this case, the combination of:
・The first factor (something you have): A "device certificate" installed only on an authorized PC.
・The second factor (something you know): A "password" entered by the user.
This combination can confirm that access is from the "correct PC with the certificate" by the "correct person who knows the password." Therefore, this approach is considered to satisfy the requirements for multi-factor authentication.
Q92
Part X, 4.4.1(3)(e)iii) / E27, 3.1.3
The rules state that a compensating countermeasure should not be a security control required by other requirements. However, is it possible for a single measure, such as a port blocker, to satisfy multiple requirements?
Yes, that is correct. The key is to distinguish between "substituting a requirement" and "using a single measure for multiple purposes."
Prohibited: Substituting a Requirement
You cannot use the fulfillment of one requirement (e.g., audit log generation) to justify not meeting another (e.g., user authentication). Each requirement must be independently satisfied.
Permitted: Using a Single Measure for Multiple Requirements
It is acceptable for a single "measure," like a port blocker, to satisfy multiple requirements simultaneously.
In conclusion, substituting one requirement for another is prohibited, but satisfying multiple requirements with a single countermeasure is permissible.
Q95
Part X 4.4.3, Table X4.2, No. 31
Can a firewall's IP address whitelist (a setting that permits communication only from specific IP addresses) be considered one of the "factors" for multi-factor authentication (MFA)?
No, an IP address whitelist itself is not considered a factor for multi-factor authentication.
Multi-factor authentication typically verifies a user's identity by combining two or more of the three common authentication factors:
-Something you know (knowledge)
-Something you have (possession)
-Something you are (biometrics)
An IP address whitelist permits access from a specific "location" and does not directly fall under any of these authentication factors.
Q96 For a product with E27 (Part X, Chapter 4) Type Approval, is Approval of Manufacturers also required to omit the attendance of the Society's surveyor at the shop tests regarding E27 for each individual ship, which are conducted at the supplier's factory?
No, Approval of Manufacturers is not required.
If a product has a valid Type Approval for E27 (Part X, Chapter 4), the attendance of the Society's surveyor for shop tests regarding E27 conducted at the supplier's factory for each individual ship is not required, even without Works Approval. However, please note that the submission of some documents, such as the "Test reports signed by the supplier," is still necessary for each ship.
(Please note that the handling of test omissions related to E22 (Part X, Chapter 3) is out of the scope of this FAQ. For details, please refer to NK Technical Information TEC-1348.)
Q97 Is there a specific format for the "application for omission" when assigning an E27 type-approved product to an individual ship?
ClassNK has prepared an application form template.
-Form_Application for Omission for Type Approved Products.docx
This form can be used when applying to assign a product with Type Approval to an individual ship.
Please note that the use of this form is optional. You may continue to submit your application in any format.
Q100
I'm not sure how to fill out the following sections on the Type approval application Form 7-10:
-Apply to additional security capabilities
-Apply to “Automatic Devices and Equipment (Environmental Test)”
-Apply to “Approval of Use of Computer Based System”
Please determine how to fill in each item as follows:
Apply to additional security capabilities
"Yes": Select this if your product has the capability to communicate with "untrusted networks" (as specified in the additional security capabilities required by Part X, 4.4.3 / UR E27 4.2).
"No": Select this if your product does not have this capability.
Apply to “Automatic Devices and Equipment (Environmental Test)”
"Yes": Select this if you are simultaneously applying for approval of environmental testing (equivalent to UR E10)*¹, or if you wish to integrate it with an existing certificate*².
Apply to “Approval of Use of Computer Based System”
"Yes": Select this if you are simultaneously applying for approval of the manufacturing quality of computer-based systems (equivalent to UR E22)*¹, or if you wish to integrate it with an existing certificate*².
*¹: If you wish to receive separate certificates, please select "No", and please submit Form 7-1 or Form 7-8 separately.
*²: If you wish to integrate with an existing certificate, please enter the existing certificate number (e.g., xxAxxx, xxCPxxx, TAxxxxxM) in the "Remarks" section.
Q104
Part X 4.5.8(1) / E27 5.7a)
What is "security context"?
It refers to the overall security situation and configuration of the environment where a product actually operates. It encompasses not only the functions of the product itself but also the surrounding environment, including:
-Technical environment: such as other connected systems, network configurations, and firewalls.
-Organizational environment: such as operational policies defined by the shipowner, including password policies and access control rules.
-Physical environment: such as the lock management of the room where the equipment is installed.
Q105
Part X 4.5.8(1) / E27 5.7a)
What does "Integration of the product, including third-party components, with its product security
context" require?
This requires the product supplier (manufacturer) to provide "security hardening guidelines" that describe specific procedures for securely integrating their product into the customer's operational environment (the security context).
In other words, it's not enough to simply supply a product and state that it's secure. The supplier is required to provide documented, concrete instructions to adapt the product to its operational environment, such as:
-"When connecting to this system, please use these specific port settings."
-"Please change the minimum password length to align with the shipowner's policy."
-"If this function is not needed, please disable it to reduce the potential attack surface."
Q109 Are Class 1 Dynamic Positioning Systems (DPS) or DPS installed voluntarily (not subject to class approval) considered applicable OT systems under UR E26/E27?
These DPS are not considered applicable OT systems.
However, E27 (Part X, Chapter 4) approval is required if installed in the same security zone as an applicable computer-based system (applicable OT system). (E26 4.2.1.3 / Part X, 5.4.3(1)(c)i))
Q112
4.1.2-2.(1)(k), Part X of the Rules
For navigation and radio communication equipment that has obtained IEC 61162-460 certification, is it necessary to obtain approval under Chapter 4 of Part X (UR E27), and are document submission and testing required?
Even if the equipment has obtained IEC 61162-460 certification, approval under Chapter 4 of Part X (UR E27) is required, and submission of documents and review by the Society are necessary.
In the submitted documents (such as the Description of security capabilities), compliance must be organized and described for each requirement of Chapter 4 of Part X (UR E27).
However, if test results conducted during the IEC 61162-460 certification process are submitted, the Society will review the contents. For items judged to be equivalent to the tests required by Chapter 4 of Part X (UR E27), the execution of those tests may be omitted.
Q127
4.4.1(10), Part X / E27 3.1.10
When assigning an E27 type-approved product to an individual ship, the submission of "Test reports" is required. However, if no ship-specific security configuration or hardening work is generated due to the product's specifications (e.g., security settings are hardcoded), what should be stated in the test report?
Please state in the test reports that there are no applicable items for ship-specific security configuration or hardening due to the product's specifications (e.g., settings are fixed by design).
Please note that even if no individual configuration work is required, the test report must still include the confirmation results showing that the product is built to the approved specifications, the results of operational checks, and the installed software versions.
Q129 Is access to the management interface of a firewall or similar device installed at a zone boundary with an untrusted network subject to the additional security capabilities specified in Part X 4.4.3 / UR E27 4.2?
Yes. If the management function of a firewall, router, or other zone boundary device can be accessed from the untrusted network side, such access is also subject to the additional security capabilities specified in Part X 4.4.3 / UR E27 4.2.
If the management function of a zone boundary device is compromised, security functions such as traffic control and access control may be modified or disabled.
Therefore, management access from the untrusted network side should be disabled, and this should be clearly stated in the Description of security capabilities or other relevant documents. Where such access is necessary, appropriate protective measures, such as MFA, encrypted communication, source restriction, explicit onboard approval, and logging, are to be applied and described in the Description of security capabilities.
Q130 Can existing alarm history logging functions or similar functions of OT systems, such as an AMS data logger, be used as a means of storing or reviewing audit records required by Items No.13, No.14 and No.23 of Table X4.1, Part X of the Rules (E27 4.1 Table 1)?
Yes. Items No.13, No.14 and No.23 of Table X4.1, Part X of the Rules (E27 4.1 Table 1) require functions related to generation of audit records, audit storage capacity and audit log accessibility, but they do not uniformly require a dedicated device or system to be newly provided for audit records. Therefore, existing alarm history logging functions or similar functions of OT systems, such as an AMS data logger, may be used as a means of storing or reviewing audit records, provided that the required auditable events can be recorded and reviewed as necessary. However, the auditable events to be recorded, recorded information, retention period or storage capacity, and review method are to be clearly described in the submitted documents, such as the Description of security capabilities.
Q135 What is the difference between "approval of use" and "type approval" relating to UR E27 (Part X, Chapter 4)? Has the terminology been changed?
For applications submitted on or after 1 July 2026, the approval previously referred to as "Approval of Use" has been renamed"Type Approval." Accordingly, the title of the relevant Guidance has also been changed from "Guidance for the Approval and Type Approval of Materials and Equipment for Marine Use" to "Guidance for the Approval of Materials and Equipment for Marine Use." This amendment is intended solely to consolidate and clarify the nomenclature; no substantive change has been made to the technical requirements. The old and new terms are therefore to be understood as referring to the same approval scheme.
Ch5 Part X(E26) 62 items
Q1
1.2.4-35., Part A of the Rules
For ships contracted for construction on or after July 1, 2024, is there a difference between the drawings/documents that should be submitted and those required for the class notation "CybR"?
Among ships contracted for construction on or after 1 July 2024, there are ships for which the application of Chapters 4 and 5 of Part X (UR E27 and E26) is mandatory, and those for which it is not. The class notation "CybR" will be affixed to all ships subject to the application of these requirements.
For all ships to which the "CybR" notation is affixed, all drawings and documents listed in Part X 2.1.1(1)(b) and (c) as well as (2)(b) must be submitted.
On the other hand, for ships to which the "CybR" notation is not affixed, the submission of such documents is not required.
Q2
2.2.3-5.(5)., Part X of the Rules
If the supplier of an onboard computer-based system goes bankrupt or withdraws, does the system need to be immediately replaced?
If the supplier goes bankrupt or withdraws, it is not necessary to replace the system immediately, but it is necessary to replace it as soon as possible to keep each computer-based system up to date. It is generally expected that documents and support are handed over to another supplier, and it is rare for support to end immediately.
Q3
2.2.3-5.(5)., Part X of the Rules
For on-board computer-based systems, how can we demonstrate that they are maintained up to date, and how does the classification society verify this?
In accordance with 5.4.2(1)(d)iii)3) of Part X, the rules provide two examples of how to verify that software is kept up to date:
- Vulnerability scanning (services that identify exploitable weaknesses, including software that needs updating on the system)
- Checking the software versions of computer-based systems while switched on (manually or using tools to confirm that the software version is up to date).
As indicated in Item 1 of Table B5.32 in Part B, the Society will verify these during special surveys.
Q8
5.4.3(4)(c)i), Part X of the Rules
As a requirement for physical access control, it is stated that "Computer-based systems of Category II and Category III are to generally be located in rooms that can normally be locked or in controlled space to prevent unauthorized access, or are to be installed in lockable cabinets or consoles." Do the following spaces qualify as "controlled spaces"?
- Engine control room where the engine room alarm monitoring systems is installed
- Engine room where the main engine local control systems is installed
- Cargo control room where monitoring systems for cargo control is installed
That is correct. "Controlled spaces" refer to rooms where visual monitoring by the crew is carried out (e.g., rooms where crew are constantly present) or rooms where access control is implemented by sealing doors with tamper-evident seals.
Q9
5.4.5(4), Part X of the Rules
What does "fallback to minimal risk condition" specifically refer to?
Fallback to minimal risk condition meansbring itself in a stable, stopped condition to reduce the risk of possible safety issues, as stated in 5.4.5(4)(a), Part X of the Rules.
Q17 What is the existing class notation "CybR-G"?
The notation "CybR" (abbreviated of Cyber Resilience) is affixed to the ships that are subject to the application of Chapter 4 and Chapter 5 of Part X which incorporate IACS UR E26 Rev.1 and E27 Rev.1.
On the other hand, the notation "CybR-G" (abbreviated of Cyber Resilience-Guideline) is affixed to ships that conform to our non-mandatory guideline "Cybersecurity Design Guidelines for Ships".
Q19
5.5, Part X of the Rules
Is a risk assessment necessary even for computer based systems that do not seek exemption?
It is not necessary.
Q22
5.4.2(1), Part X of the Rules
Is it necessary to include computer based systems that are out of scope or have been excluded in the risk assessment in the vessel asset inventory?
It is not mandatory.
Q24
4-7, Guidelines for Cyber Resilience of Ships
5.4.3(1)(d)iv)1), Part X of the Rules
Regarding section "5.4.3(1), Part X of the Rules / Security zones and network segmentation" in "4-7 Ship cyber security and resilience program", chapter 4 of the guidelines, the description of the guidelines list "4) Protection against connection of unauthorized devices" in the security audit records of firewalls.
Does this mean to require NAC/Network Access Control ?
The explanation in this guideline does not require the implementation of NAC. This explanation assumes network-related events as audit targets, and basic auditing is possible through methods such as IP address monitoring or log analysis. Therefore, we believe that configuration can be performed on zone boundary devices such as firewalls.
(Reference)
While NAC solutions manage devices based on multiple factors such as:
- Device IDs such as MAC addresses
- Policies such as OS versions, antivirus software versions, etc.
- Behavior in the application layer
Q26 In "Zone and conduit diagram", to what extent should zones outside the scope of E26 be indicated?
Please refer to the attached file for a flowchart summarizing "Necessity of inclusion in Vessel asset inventory" and "Whether to include in Zone and conduit diagram"
(Q26_reference.pdf)
In the Zone and Conduit Diagram, it is necessary to clearly indicate the communication between devices within the E26 range and non-applicable devices. (5.4.3(d)i)2), Part X)
Therefore, it is requested that non-applicable devices that communicate with applicable devices and the zones or segments that include them be clearly indicated.
Q27
Guidelines for Cyber Resilience of Ships Fig. 2.5 and Fig. 4.2
In Fig. 2.5, the Radar downstream of the VDR is indicated as being within the E26 range. However, in the sample diagram of the zone and conduit diagram in Fig. 4.2, the equipment in the OT zone downstream of the VDR is outside the E26 range. Please let us know whether the equipment downstream of the VDR that makes IP connection to the VDR is applicable to the E26.
A radar is an applicable system of E26(E27) as indicated in 2-2.1 of the Guidelines.
Also, a system connected to VDR (an applicable system of E26(E27)) via IP without going through a zone boundary device are covered by E26.
On the other hand, if a system is not an applicable system of E26(E27) and is not connected via IP, it is not covered by E26.
Q28
In the "Guidelines for Cyber Resilience of Ships" issued by NK Fig. 4.2
In the sample of the zone and conduit diagram, there are 2 firewalls (both within the E26 scope). Is a network configuration acceptable where only the upper firewall is installed, and it connects to each zone?
There are no specific regulations regarding the number of Firewalls (or other zone boundary devices) to be installed. Therefore, according to the rules, it is possible to achieve the segmentation of each zone with a single Firewall. However, please be aware that there may be potential drawbacks, such as the Firewall rule settings becoming complex, and possible security vulnerabilities when compared to a setup with separate Firewalls for each zone.
Q29
5.4.4(1)(d)iii)1), Part X
Regarding the requirement in Part X, 5.4.4(1)(d)iii)1) of the Rules for the Survey and Construction of Steel Ships:
"Test that abnormally high network traffic is detected, and that alarm and audit record is generated."
Depending on the design, network traffic may not reach the alarm threshold. In such cases, is it still possible to pass the test?
Countermeasures such as bandwidth limiting are implemented, and if the alarm threshold is not reached, it is acceptable to clearly state that such countermeasures are in place in the "Security Function Specification," "Security Function Test Procedure," and "Ship Cyber Resilience Test Procedure." During testing, it is confirmed that the countermeasures function correctly and the alarm threshold is not reached.
In addition, if the test has been conducted in the test for obtaining approval for each computer system regarding Part X, Chapter 4 (UR E27), the test at the shipyard can be omitted.
Q30 Regarding the information to be included in the documents submitted to NK, such as details on owner-supplied items, if the information about owner-supplied items cannot be obtained before an early stage of construction and is mentioned as TBD (To Be Determined), by when should this information be updated?
The deadline for updating the "TBD" information and finalizing the documents is the delivery of the ship. However, since attendance surveys will be conducted based on these documents, you need to obtain approval with sufficient time to ensure these surveys can be carried out smoothly.
For this reason, the shipyard needs to closely coordinate with the shipowner.
Q31 If the information required at the time of drawing design is not shared among items supplied by the shipowner, it is stated that it is OK to display it as "TBD" for the time being, but if the necessary drawings are not collected for items other than those supplied by the shipowner, is it okay to submit it as "TBD" for the time being?
That is correct.
Q34
5.4.3(1)(a)i), Part X
Does "air gapped" mean that there is no connection from other systems? Is it correct to understand that it is not necessary to separate rooms?
"air gapped" means that a system is isolated from other networks both physically and logically. It is not something that cannot be achieved without separating rooms.
Q39
5.4.4, Part X
Regarding the alarm required for detection, are there any rules regarding the alarm destination (e.g., output to AMS), alarm display method, or presence/absence of an audible alarm?
There are no specific provisions regarding the alarm destination, alarm display method, or presence/absence of an audible alarm. Therefore, signal output to an alarm monitoring system (AMS) and the installation of an audible alarm are not mandatory.
However, alarms are essential elements for early detection of cyber incidents and for executing response procedures and recovery plans. The design of the alarm system will influence the content of the Ship Cyber Security Resilience Plan, which is created by the shipowner to plan for these incidents. Therefore, please design your system with this in mind.
Q40 In NK's explanation documents, a configuration with two firewalls installed is shown as an example, but is NK requiring the installation of two or more firewalls?
There is no specific requirement for the number of firewalls to be installed; it is merely an example. Installing only one firewall is acceptable under the rules.
Please consider factors such as security and maintainability when designing your configuration.
Q42
5.5.4-2(3), Part X
4-4.2 of the "Guidelines for Cyber Resilience of Ships" cites compartments that are constantly monitored by crew members, such as the bridge and engine control room, as examples of "areas to which physical access is controlled".
However, on M0 ships, the engine control room is periodically unmanned. Also, there are times when the bridge is unmanned, such as during cargo operations. In these cases, can the compartments still be considered "areas where physical access is controlled"?
Those compartments can be considered "areas where physical access is controlled" if they are lockable.
The management of locking must be described in the Ship Cyber Security and Resilience Program created by the shipowner and operated accordingly.
Q43
5.4.6(1)(c)iii), Part X / E26 4.5.1.3
Are there any specific rules regarding the recovery time objective (RTO) and recovery point objective (RPO)?
RTO/RPO must be specified in the ship owner's recovery plan, but there are no rules regarding specific time periods.
Achievable RTO/RPO depends on the ship and system design, so it is recommended that this be considered by the ship owner, shipyard, and relevant suppliers.
In general, RTO/RPO are decided in consideration of the importance of the system, the impact on the vessel, the time required for recovery, the frequency of data updates, etc.
Q44
5.4.3(2)(d)iii)1), Part X
Regarding the "Test denial of service (DoS) attacks targeting zone boundary protection devices, as applicable." in the commissioning phase, from what position to what position should the load be applied in the assumed data flow?
You will need to apply the load from the IT zone side (outside the scope of UR E26 application). Please refer to the reference document.
By the way, installation/testing of the firewall at the lower side of the attached document is optional. However, if you install it, E27 approval is required for it.
(Q44_reference.pdf)
Q47
Chapter 5, Part X
What documents should the Systems Integrator (Shipyard) prepare and submit to NK when obtaining E26 approval?
Systems Integrator (Shipyard) prepares and submits the following 6 documents.
1.Zone and conduit diagram: A diagram that visually illustrates the configuration of the ship's security zones.
2.Cybersecurity design description: A document that describes the technical measures for the ship's cyber security.
3.Ship asset inventory: A list of hardware and software for computer systems onboard.
4.Risk assessment for the exclusion of computer-based systems: A document for computer systems for which exclusion is requested, which is intended to show that the exclusion is reasonable.
5.Description of compensating countermeasures: Compensating countermeasures to meet the security requirements of computer-based systems.
6.Ship cyber resilience test procedure: A test plan for evaluating the ship's cyber resilience.
Q48
Chapter 5, Part X
What document should the Shipowner (Management company) prepare and submit to NKl?
Shipowner (Management company) prepares and submits the Ship Cyber Security and Resilience Program.
This is a document that describes the management of computer system cyber security and cyber resilience.
Q51 The firewall (indicated by the blue frame in the reference material p.1) that separates the IT zone (outside the scope of E26) and the OT zone (within the scope of E26) will be supplied by the shipowner. However, information about the firewall cannot be shared with the shipyard until the ship management company is decided. How should we shipowner proceed? (Q51_reference.pdf-p.1)
Please consider the following measures.
Regardless of the ship management company, the shipyard should be informed of the provisional selection of the Firewall (UR E27 approved product), which is expected to be adopted. (Parts that cannot be decided should be marked as TBD (To Be Determined), and the shipyard should be informed sequentially as each part is decided.)
When contracting with the ship management company, it should be discussed that the Firewall should be an E27 approved product.
If an E27 approved product cannot be selected for the firewall, the ship management company should be informed that the equipment in the IT zone cannot be connected to the equipment within the scope of E26 (ship OT system). (Q51_reference.pdf-p.2)
Q52
5.4, Part X
The Rules require a demonstration during the commissioning phase. Does this indicate that the demonstration must be done during the sea trial? Must this be completed during the sea trial?
The rules do not require the demonstration to be performed during sea trials. If there is enough time in the schedule after the sea trial and before the vessel's delivery, it is acceptable to conduct the demonstration after the sea trials.
Q53 Is it necessary to link the Ship Cyber Security and Resilience Program to the SMS Manual?
It is not mandatory to link the Ship Cyber Security and Resilience Program to the SMS Manual.
If you wish to link them, the relevant part of the SMS Manual needs to be reviewed in accordance with the ISM Code. Therefore, you will need to submit the relevant part also to the NK Ship Management System Department (SMD)*.
*In the case of vessels for which NK conducts ISM Code reviews.
(Q53_Reference.pdf)
Q54 For E26 applicable vessels, is it necessary to apply to NK when installing a new satellite communication system after commissioning?
Not only when installing a new satellite communication system, but also when there is a change in the drawings required to be submitted at the time of newbuilding (e.g., Ship Asset Inventory, Zones and Conduit Diagram), you must submit the modified drawings to the NK Machinery Department and conduct tests based on the test procedure approved in an occasional survey.※
※ The criteria for requesting submission of modified drawings are: When replacing components (applicable items) in the Ship Asset Inventory, and when the Zones and Conduit Diagram changes due to changes in connections.
Q57 Is there a template or sample format for the E26(Chapter 5, Part X) documents to be submitted?
We have prepared the following samples. Please make sure to understand the contents of each of the information sheets before using them.
-Vessel asset inventory(sample_Vessel Asset Inventory.xlsx)
-Risk assessment for the exclusion of computer-based systems (sample_Risk Assessment for Exclusion of CBS_English.xlsx)
Q58
Can multiple VLANs on a single L2 switch be used for logical segmentation? / Can multiple VLANs on a single L2 switch be used for physical segmentation?
(Is a configuration allowed in which security zones are separated using VLANs and the VLANs are connected via zone boundary devices?)
By using VLANs, you can create multiple virtual LANs on a single L2 switch and logically segment the network by separating those VLANs with zone boundary devices.
However, physical segmentation is required in 5.4.3(1)(c), Part X of the Rules for the following two cases, and therefore segmentation by VLANs (logical segmentation) built on a single L2 switch is not permitted.
iii) Separating systems that provide required safety functions.
vi) Separating a network (security zone) containing applicable systems from an untrusted network.
(Q58_reference.pdf)
Q65 I would like to know about the work and schedule related to UR E26 for shipyards.
Please refer to the attached document, which summarizes the typical work and schedule required for shipyards to comply with E26.
(Q65_reference.pdf)
As described on page 2 of the reference material, in order to smoothly proceed with the shipbuilding project, it is important that by the inquiry stage, each manufacturer (supplier) understands the necessity of obtaining E27 approval, and for products that require approval, it is essential that they have already acquired E27 use approval or have the prospect of acquiring it. We believe that shipyards will proactively request potential manufacturers to take necessary actions for this matter. However, if there is any doubt about the manufacturers’ understanding or concerns about their response, please inform the ClassNK Machinery Department. We will provide support, including direct guidance.
Q67 The explanatory documents and samples for the vessel asset inventory include IP addresses. If an IP address is changed, is it necessary to update the entry on the vessel asset inventory each time?
If you include IP addresses in the vessel asset inventory, you need to update it each time.
However, including IP addresses in the vessel asset inventory is not mandatory, so it is also possible not to include them. It is recommended to discuss this matter with the shipyard and the shipowner beforehand.
Q68 Normally, chart updates are performed using the ECDIS server, but if communication becomes impossible due to a failure, etc., updates are performed using a USB memory stick. If a USB memory stick is used, is it necessary to revise the Ship Cyber Security and Resilience Program?
If you include the operation of using a USB memory stick for chart updates in advance, we believe that it will not be necessary to revise the Ship Cyber Security and Resilience Program.
Q69
5.5.4-2(2), Part X
We are considering installing port blockers on physical interface ports such as USB as a method of physically disabling them. Is it acceptable to use dust caps?
We considery that dust caps do not meet the intended purpose. It is necessary to select blockers that cannot be removed without a dedicated key or tool.
Q71 Is compliance with UR E26 not required for ships that have absolutely no internet connectivity?
No, compliance is required.
Even for ships not connected to the internet, cybersecurity threats exist, such as malware infections via USB drives and insider threats. UR E26 establish comprehensive cybersecurity requirements, including measures against these threats, and apply regardless of internet connectivity.
Q75
5.4.5(1)(c)ii), Part X / E26 4.4.1.3
E26・In the Incident Response Plan (included in the Ship Cyber Security and Resilience Program), reporting/notifying to the the proper authority is required, but where is the specific reporting/notifying destination?
"The Incident response plan shall provide procedures to respond to detected cyber incidents on networks by notifying the proper authority, reporting needed evidence of the incidents..."
E26 provides a framework for cyber resilience of ships, but does not specify the authority to be reported/notified in the event of a cyber incident. It is assumed that this requirement is intended to incorporate the procedure in cases where reporting obligations are stipulated in requirements other than E26 (requirements of the flag/port authority, etc.).
Q80 Is training required in UR E26?
Yes.
-UR E26 requires the shipowner to provide periodic training and carry out drills for onboard personnel and other concerned personnel ashore. This is to ensure they are familiar with the computer systems and networks onboard and can properly manage the measures adopted to meet the requirements (E26 5.3 / 2.2.3-5.(4), Part X).
-Personnel with administrator privileges are required to be appropriately trained (E26 4.2.4.3.5 / 5.4.3(4)(c)v)3), Part X).
-It states that users of Intrusion Detection Systems (IDS) should be trained and qualified personnel (E26 4.3.1.3 / 5.4.4(1)(c), Part X).
-However, there are no specific provisions regarding the detailed content of the training itself.
Q81 Is it required to include content related to training in the Ship cyber security and resilience program?
The Ship cyber security and resilience program is the document that covers the processes and activities for managing cybersecurity and cyber resilience as required by E26 (E26 5.3.1 / 2.2.3-5., Part X). Additionally, E26 5.3 / 2.2.3-5.(4), Part X requires the shipowner to provide periodic training. For these reasons, the Ship cyber security and resilience program needs to include policies, procedures, plans, or other relevant information concerning the implementation of this required training.
Q83 How long does it take for the Ship Cyber Security and Resilience Program to be approved and returned after submitting it to ClassNK?
The standard review and return period is approximately one month from the receipt of the documents. However, please be aware that programs submitted for the first time by a shipowner may require more time for detailed review, potential inquiries, and subsequent revisions, as they tend to have more points requiring modification. Therefore, we kindly request that you submit the program with ample time to ensure its approval before the first annual survey.
Q84
It is understood that the "Ship Cyber Security and Resilience Program" must be approved before the first annual survey. Is there a specific period stipulated for the operational records that need to be presented during this survey?
(Is it necessary to have the program approved before the first annual survey to be able to record these operations?)
UR E26 does not stipulate a specific number of days for the operational record-keeping period. However, at the first annual survey, the shipowner is required to present records demonstrating that operations have been conducted in accordance with the approved "Ship Cyber Security and Resilience Program". So, we kindly request that the shipowner ensure sufficient time for program approval, subsequent operations, and the creation of records ahead of the first annual survey.
Q91 Is it necessary to keep the Incident Response Plan and the Recovery Plan, which are part of the Ship Cyber Security and Resilience Program, in hard copy?
Yes, it is necessary. The requirements stipulate the following:
Incident Response Plan: The Incident response plan is to
be kept in hard copy in the event of complete loss of electronic devices enabling access to it.
(Part X 5.4.5(1)(c)iii) / E26 4.4.1.3)
Recovery Plan: Recovery plans in hard copy onboard and ashore are to be available to personnel responsible for cyber security and who are tasked with assisting in cyber incidents.
(Part X 5.4.6(1)(c)vi) / E26 4.5.1.3)
These are requirements to ensure that response and recovery actions can be carried out reliably, even during a system outage.
Q94
5.4.6(1)(c)iii), Part X / E26 4.5.1.3
Must the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) be determined individually for every computer-based system?
No, it is not strictly necessary to define them individually for every computer-based system.
The RTO and RPO are to be defined within the recovery plan (Ship Cyber Security and Resilience Program) created by the shipowner. It is required to set rational and achievable objectives, considering factors such as the criticality of the system, the impact on the vessel, the realistic time required for recovery, and the frequency of data updates.
Therefore, while it is desirable to set individual objectives for critical systems, it is also permissible to group multiple systems and establish common objectives based on their functions or other relevant factors.
Q98 Are there any specific testing tools that shipyards must use for onboard testing? Also, do these tools need to be certified in advance?
No. There are no specific products or models designated for the testing tools, and prior certification for these tools is not required.
However, it is necessary to specify the testing equipment to be used in the Ship Cyber Resilience Test Procedure. [Part X, 2.2.3-4.(2) / E26 5.2.1]
Q99 In cases where physical segmentation is required, is it necessary to install a separate firewall for each security zone?
It is not strictly necessary to install a separate firewall. The requirements can be met as long as physical separation is ensured through the functions and configuration of a single firewall.
[Explanation]
The Rules requires physical segmentation in the following two cases:
-Separating systems that provide required safety functions. (Part X, 5.4.3(1)(c)iii) / E26 4.2.1.3)
-Separating a network (security zone) containing applicable systems from an untrusted network. (Part X 5.4.3(1)(c)vi) / E26 4.2.1.3)
"Physical segmentation" is defined as a network segment where physical components are not shared by other network segments (Part X, 5.2.1(15) / E26 Section 2).
Many firewalls are equipped with functions that treat each physical port as an independent network segment, where physical components are not considered to be shared between the ports. Therefore, for such firewalls, a configuration that connects a "zone providing safety functions" and "another zone" to different physical ports of a single firewall is acceptable as meeting the requirement for physical segmentation.
However, please note that methods that logically divide a network by sharing a single physical port, such as VLANs, are not considered physical segmentation.
Q101 Are penetration tests required during the ship's commissioning phase?
No, penetration testing is not explicitly required by the Rules.
What the rules require during the commissioning phase is primarily security capability verification testing. This testing is to confirm that the designed and implemented security capabilities (e.g., access controls, firewall rules, network monitoring functions) operate correctly as specified in the approved documents.
The objective of this verification testing differs from that of a penetration test, which involves actively attempting to breach the system from an attacker's perspective to discover and exploit unknown vulnerabilities.
Q102 Denial of Service (DoS) attack tests and vulnerability scans are also mentioned. Are they different from penetration tests?
Their objectives and scope are different.
DoS Attack Test: In accordance with Part X, 5.4.3(2)(d)iii), a test to demonstrate resilience against Denial of Service (DoS) attacks is required. While this can be considered a component of penetration testing, the rules specifically require testing against this particular attack scenario to verify the system's response.
In contrast, a penetration test is a comprehensive assessment that employs a wide range of attack methodologies, which may include DoS attacks, to actively search for and attempt to exploit unknown vulnerabilities to gain unauthorized access.
Q110
5.5.4-2.(4), Part X of the Rules
Is equipment controlled by contact signals from an IAS (Integrated Automation System) (e.g., an LO pump control system) considered an "integrated control system" due to its connection to the IAS? (Does this mean it cannot meet the exclusion criterion in Part X, 5.5.4-2.(4), which states: "The computer-based system is not to be an integrated control system providing more than one of the ship's functions in the scope of applicability of this Chapter"?)
No, it is not considered an "integrated control system." If the equipment provides only a single function, it meets this criterion (i.e., it can be excluded).
Part X, 5.5.4-2.(4) stipulates that the computer-based system to be excluded must not itself be an integrated system responsible for multiple functions (e.g., both propulsion and steering). If the equipment in question (e.g., LO pump control system) provides only a single function (e.g., lubrication of the main engine), it does not fall under the definition of an "integrated control system," even if it receives contact signals from the IAS.
Furthermore, connection via contact signals (e.g., hardwired connection) is not considered an IP network connection. Therefore, it does not conflict with the requirement for "isolation (i.e., no IP network connection)" stipulated in 5.5.4-2.(1). Consequently, providing other exclusion criteria are also met, the equipment may be excluded from the scope of applicability.
Q111 Does EtherCAT communication constitute an "IP network connection" as defined in 5.5.4-2(1), Part X?
Whether EtherCAT communication constitutes an "IP network connection" depends on its implementation method.
Standard EtherCAT communication (which operates at Layer 2 of the OSI model and does not use the IP protocol) is not considered an "IP-network connections" under 5.5.4-2(1), Part X.
However, if EtherCAT over Ethernet (EoE) is used, where the EtherCAT protocol is encapsulated within UDP/IP packets for communication, this utilizes the IP network and is considered an "IP network connection."
Q113
Part X 5.5 / UR E26 Section 6
If a computer-based system is excluded from the application of Part X Chapter 5 (E26) based on the risk assessment under Part X 5.5 (E26 Section 6), is it also excluded from the application of Part X Chapter 3 (IACS UR E22)?
No, it is not excluded. The exclusion under Part X 5.5 applies only to the requirements of Part X Chapter 5 (E26). The applicability of Part X Chapter 3 (E22) must be determined separately in accordance with the provisions of Chapter 3 (3.1.1 and 3.3).
Q114
Part X 5.5 / UR E26 Section 6
For computer-based systems excluded from the application based on the risk assessment under Part X 5.5 (E26 Section 6), is it correct to assume that UR E27 (Part X Chapter 4) approval is not required?
Your understanding is correct. For computer-based systems excluded from the scope of Part X Chapter 5 in accordance with Part X 5.5, UR E27 (Part X Chapter 4) approval is not required.
Q115
Part X 5.5 / UR E26 Section 6
Who carries out the risk assessment for the exclusion of computer-based systems, and who verifies it?
The Integrator (typically the Shipyard) is to carry out the risk assessment and submit the results (Risk assessment for the
exclusion of computer-based systems) to the Society. ClassNK will verify and approve the content. (Refer to Part X, 5.5.3-1. and Table X2.4)
Suppliers wishing to have their products excluded are strongly recommended to consult with the Integrator to ensure that their products are included and appropriately evaluated in the said risk assessment.
Q116
Part X 5.5 / UR E26 Section 6
Is the Shipowner required to review the "Risk assessment for the exclusion of computer-based systems" during the operational phase?
The Rules require the Shipowner to update the risk assessment during the ship's operational life (refer to Part X, 5.5.3-2).
However, as long as the conditions for exclusion (such as isolation from networks and disabling of physical ports) are maintained, it is considered rare that the risk assessment needs to be revised. Please notify the Society and submit the updated risk assessment only when the risk level may exceed the acceptable threshold due to changes in system configuration, etc.
Q117
Part X 5.5 / UR E26 Section 6
In what specific cases is it necessary for the Shipowner to review the "Risk assessment for the exclusion of computer-based systems" during the operational phase?
Basically, a review is required when there are changes to the "isolation status" or "physical management status" of the system. Specifically, the following cases are envisaged:
1. Changes in System Configuration (Changes in Connectivity)
-When a previously standalone system is connected to a network.
-When disabled physical ports are enabled for use.
2. Changes in Operational Environment (Changes in Physical Access)
-When a location that was previously locked becomes constantly open.
-When the system is relocated to an area accessible by unauthorized personnel.
3. Discovery of New Vulnerabilities (Rare Case)
-When a critical vulnerability is discovered in the system, and it is determined that current physical protection measures (such as locking and isolation) alone are insufficient to keep the risk at an acceptable level.
Please note that as long as no such changes are made and the approved status (isolation, locking, etc.) is maintained, it is considered that in most cases, periodic review work will be substantially unnecessary.
Q118
Part X 5.4.3(2)(d)iii)1)
Regarding the "Test denial of service (DoS) attacks targeting zone boundary protection devices," what specific scope and intensity of testing is required?
The purpose of this test is to verify that zone boundary protection devices (e.g., firewalls) "respond" as designed in the approved documents when subjected to a DoS attack (e.g., traffic load).
Specifically, the test should be conducted at a level sufficient to confirm the following:
-Operation of Defense Mechanisms: Verify that defense functions, such as blocking traffic or limiting bandwidth, operate correctly when subjected to intentional communication loads (e.g., SYN flood attacks).
-Detection and Recording: Verify that alarms are triggered and logs (audit records) are generated appropriately when an attack occurs. (Refer to Part X, 5.4.4)
-Maintenance of Security State: Verify that security capabilities are maintained even under traffic load. (Ensure that the device does not enter an insecure state, such as "failing open" and allowing blocked traffic to pass due to overload.)
Q119
Part X 5.4.3(2)(d)iii)2)
Regarding the DoS attack test (network flooding and application layer attacks) required in the Ship Cyber Resilience Test Procedure during the commissioning phase, what specific content and load levels should be applied?
The Society recommends reproducing a "reasonably high load condition in actual operation" of the target system and verifying its behavior. Specifically, based on the definitions in the Rules, the test content should include the following perspectives:
1. Network Flooding (Consuming available capacity)
-Method: Generate traffic at a level that pressures the actual communication bandwidth (e.g., loads exceeding set bandwidth limits or alarm thresholds).
-Verification: Confirm that network alarms (Part X, 5.4.4(1)(c)i)5)) are correctly triggered and that critical control communication is maintained even under high load (effectiveness of QoS, etc.).
2. Application Layer Attacks (Consuming processing capacity)
-Method: Use valid protocols utilized by the target equipment (Modbus/TCP, HTTP, etc.) and apply a load by sending a large volume of requests in a short time to consume the endpoint's CPU or memory resources.
-Verification: Confirm that the equipment does not freeze or run out of control and that it processes (or limits) requests appropriately. If the equipment malfunctions, it is acceptable if it is confirmed that it falls back to a safe state (minimal risk condition) (Part X, 5.4.5(4)).
Note that if equivalent tests were successfully conducted by the supplier (manufacturer) during the approval process for Part X, Chapter 4 (UR E27), the tests on board may be omitted.
Q122 Is it acceptable to submit a conventional electric cable wiring diagram as the "Zone and Conduit Diagram" required by Part X Chapter 5?
In principle, submitting a conventional electric cable wiring diagram as a "Zone and Conduit Diagram" without modification is not acceptable. There are two main reasons for this:
1. Difference in Information Requirements The "Zone and Conduit Diagram" must clearly visualize the configuration of security zones, communication between zones (conduits), and connections to untrusted networks (refer to Part X, 5.4.3(1)(d)i)2)). Conventional wiring diagrams primarily show physical connections and power distribution. They typically lack the necessary information for evaluating cybersecurity measures, such as "logical grouping (zones)" and "data flows (conduits)," or are often too cluttered to be legible for this purpose.
2. Consistency with Other Documents The names of systems and equipment used in the "Zone and Conduit Diagram" must be fully consistent with those in other submitted documents, such as the "Ship Asset Inventory." The names and symbols used in conventional wiring diagrams often do not match these documents, making it difficult to verify consistency from a cybersecurity perspective.
Q123 Is the installation of an Intrusion Detection System (IDS) mandatory?
No, it is not mandatory.
However, if an IDS is implemented for computer-based systems within the scope of Chapter 4/5 of Part X, it must comply with the following requirements based on the Rules (5.4.4(1)(c)ii), Part X):
-The IDS must be qualified by the suppliers of the respective computer-based systems.
-The IDS must be passive and not activate protection functions that may affect the performance (intended operation) of the computer-based systems.
-The users of the IDS should be trained and qualified personnel.
Furthermore, the implemented IDS must be verified by the Society (5.4.4(1)(d)iii)2), Part X). Specifically, the following actions are required:
-Submission of relevant documents: While no special documents dedicated to the IDS are required, information regarding the IDS (including the information mentioned above) must be included in documents such as the "Cybersecurity design description (CSDD)".
-Surveys/tests onboard: Technical tests, such as demonstrating the passive nature of the IDS, may be omitted if they have already been performed during the certification tests under Chapter 4 of Part X (5.4.4(1)(d)iii)1), Part X). However, the final onboard survey to verify that the IDS is correctly implemented and appropriately connected to the network as designed (e.g., checking the installation status and configuration) cannot be omitted.
Q124
Part X, 5.4.4
Is the installation of an NMS (Network Monitoring System) mandatory?
No, it is not mandatory.
An NMS generally means a system that continuously monitors the status of onboard networks and connected devices, including communication conditions and alarms. However, Chapter 5 of Part X does not require the installation of a specific item of equipment or system called an “NMS.”
On the other hand, it is required that networks within the scope of Chapter 5 of Part X are monitored and that alarms are generated in the event of failure or degraded functionality. Therefore, some means to achieve these functions is necessary, but it does not have to be an NMS.
Q125
Part X, 5.4.3(6)(d)iii)
Regarding the onboard tests for "Control of remote access and communication with untrusted networks" required during the commissioning phase, is it impossible to conduct the tests until the ship's satellite communication system is contracted and activated?
Tests can be conducted even if the satellite communication system is not yet contracted or activated, provided that compliance with the requirements can be demonstrated based on the approved test procedures.
Instead of the actual satellite communication line, a dummy line (e.g., a temporary shore network or mobile router) can be connected to simulate an "untrusted network" and establish an external communication environment for testing.
However, even when using a dummy line, the rules and network settings of the zone boundary devices (e.g., firewalls) installed on board must reasonably represent the actual production environment intended for satellite communication (i.e., settings based on the approved "Cybersecurity design description"). Furthermore, it is necessary to demonstrate that the regulatory requirements (such as multi-factor authentication for remote users and explicit access approval) are satisfied.
Q126 What is the difference between a security zone and a network segment?
A security zone is a grouping of systems to which the same security requirements and access control policy are applied.
A network segment, on the other hand, is a communication division within the network architecture.
Accordingly, a zone is a security-based classification, whereas a segment is a network design-based classification.
They may coincide in some cases, but they are not necessarily the same.
For example, a single security zone may include multiple network segments.
Conversely, dividing a network into segments does not automatically mean that separate security zones have been established.
In practice, the distinction may be understood as follows:
-Zone: a classification showing which systems are subject to the same security requirements and access control policy
-Segment: a classification showing how the network is actually arranged or separated to implement that design
Q131 For a ship to which UR E26/E27 are not applicable, such as an existing ship whose contract for construction was concluded before 1 July 2024, is compliance with UR E26/E27 newly required due to a change of shipowner or ship management company?
No. Compliance with UR E26/E27 (Part X, Chapters 5/4 of the Rules) is not required solely due to a change of shipowner or ship management company. UR E26/E27 generally apply to applicable ships contracted for construction on or after 1 July 2024, and are not applied to existing ships or non-applicable ships due to a change of shipowner or ship management company.
Q133 What should a ship management company do if a ship to be newly managed appears to be subject to E26/E27 but has not been brought into compliance?
For ships for which E26/E27 (Part X, Chapters 4 and 5 of the Rules) compliance is mandatory, the required plan approval and surveys are carried out, and the “CybR” notation is assigned. Therefore, it is not normally expected that such a ship would be found non-compliant at the time management is taken over. When taking over management, please first confirm whether the ship is subject to E26/E27 and whether the “CybR” notation has been assigned. If the ship appears to be subject to E26/E27 but the “CybR” notation or compliance status cannot be confirmed, the shipowner should consult the Society.
Q134 For a ship subject to E26/E27, if the ship management company changes, is a new Ship Cyber Security and Resilience Program required to be prepared and approved? By when must approval be obtained from the Society?
In principle, the new management company is required to prepare a new Ship Cyber Security and Resilience Program and obtain approval from the Society.
However, if the Society-approved Program is taken over from the previous management company and the new management company continues to manage the ship in accordance with the Program, preparation and approval of a new Program are not required.
If the new management company does not have such a Society-approved Program, the Program is to be submitted to the Society and approved by the next periodical survey (Annual Survey, Intermediate Survey or Special Survey). During the survey, records demonstrating that cyber resilience management has been implemented in accordance with the approved Program are to be verified.
Ch4 Part X(E26) 1 items
Q17 What is the existing class notation "CybR-G"?
The notation "CybR" (abbreviated of Cyber Resilience) is affixed to the ships that are subject to the application of Chapter 4 and Chapter 5 of Part X which incorporate IACS UR E26 Rev.1 and E27 Rev.1.
On the other hand, the notation "CybR-G" (abbreviated of Cyber Resilience-Guideline) is affixed to ships that conform to our non-mandatory guideline "Cybersecurity Design Guidelines for Ships".
Ch4 Part X(E26 & E27) 16 items
Q10
4.1.2-2., Part X of the Rules
Are the following (Example) systems considered outside the scope of the requirements?
(Example)
Packaged air conditioner
Food refrigeration unit
Passenger elevator
EGCS (Exhaust Gas Cleaning System)
SCR
EGR
BWTS
Incinerator
Bilge alarm
Bilge separator
FO/LO purifier
Sewage treatment plant
Fresh Water Generator (excl. main boiler vessel)
Anemometer / Wind speed and direction meter (excl. DPS vessel)
Provision crane
E/R crane
These systems are not considered OT systems under 4.1.2-2, Part X, so they are basically not applicable. However, they may still be subject to the requirements depending on the system and/or network configuration of the system and/or the ship.
For the details, please refer to the attached file.
(Q10_reference.pdf)
Q13
4.1.2-1., Part X of the Rules
Are the requirements mandatory to ships not engaged in international voyages?
The requirements are not mandatory for ships not engaged in international voyages.
Q14
4.1.2-1.(1)(e), Part X of the Rules
Do CTVs fall under the category of "Self-propelled mobile offshore units engaged in construction"?
We consider that CTVs do not fall under the category of "Self-propelled mobile offshore units engaged in construction.
Q15
4.1.2-1., Part X of the Rules
Are the requirements mandatory to CTVs?
We consider that the requirements are mandatory for CTVs of 500 GT and upwards engaged in international voyages.
Q64 In 4.1.2(2), Part X, "other systems" are defined as "any other systems connected to OT systems, either permanently or temporarily (e.g. during maintenance)". Does this include a work PC that a service engineer of an OT system supplier brings on board and connects to the OT system to perform maintenance? For this reason, is the OT system considered to be connected to an untrusted network?
The work PC that a service engineer from an OT system supplier brings on board and connects to the OT system to perform maintenance is not considered to be an "other systems".
-It is not necessary to obtain E27 approval for the work PC itself. (However, the supplier is responsible for ensuring appropriate cybersecurity management of the work PC.)
-Subjected OT system is not considered to be connected to an untrusted network.
Q77 Is E27 approval required for PMS Software (Planned Machinery Maintenance Scheme Management Software)?
In principle, E27 approval is not required for PMS software itself or for PCs with PMS software installed.
However, if it is placed in the same security zone as a system subject to E26 (Applicable OT system), the PMS software must also meet E27 requirements. (See E26 4.2.1.3 / 5.4.3(1)(c)i), Part X)
Q78 Is a system that incorporates a logic IC considered a computer based system?
Simply integrating a logic IC is not considered a system as a “computer based system” as defined in UR E26 and UR E27.
Q85 Are E26 and E27 specifically intended for autonomous ships (such as Maritime Autonomous Surface Ships (MASS), etc.)? Furthermore, were these URs developed with the future operation of autonomous ships in mind?
As of Revision 1, UR E26 and UR E27 do not establish requirements specifically for autonomous ships (including MASS, etc.). It is understood that these URs are not designed with the application to ships utilizing specific advanced technologies in mind, but rather they define general minimum requirements for cyber resilience on board ships.
Q86
4.1.2-1., Part X of the Rules
Do IACS UR E26/E27 apply to ships subject to the IP Code?
(IP Code = International Code of Safety for Ships Carrying Industrial Personnel)
The application of the IP Code itself is not a direct condition for the applicability of E27 (Chapter 4, Part X) and E26 (Chapter 5 Part X).
However, if the said ship subject to the IP Code meets all of the following conditions, the requirements apply:
-The ship's contract for construction is dated on or after July 1, 2024.
-The ship is engaged on international voyages.
-The ship has a gross tonnage of 500 or upwards.
Q90 Is CCTV considered an applicable OT system under UR E26/E27?
The applicability of CCTV is considered to depend on its intended purpose.
Case 1: For general monitoring purposes.
CCTV installed for general purposes such as ship security or work monitoring is not considered an applicable OT system. (However, if it is placed in the same security zone as an applicable OT system, it must meet the E26/27 (Chapter 5/4, Part X) requirements.)
Case 2: When installed as an alternative means of bridge visibility.
CCTV installed as an essential alternative equipment to ensure the field of vision from the bridge as required by the SOLAS Convention is considered an applicable OT system. (However, it can be exempted from the application if it satisfies the exclusion requirements in Part X, 5.5 / E26 Section 6.)
When used for fire detection please see Q108.
Q93
4.1.2-1., Part X of the Rules
Are tugboats subject to the application of Part X Chapter 4/5(UR E27/E26)?
Tugboats that meet all of the following conditions are considered to be subject to the application:
-The ship is contracted for construction on or after 1 July 2024.
-The ship is engaged in international voyages.
-The gross tonnage is 500 GT or upwards.
Q103 Is the control system for a wind-assisted propulsion system, to which the "Guidelines for Wind-Assisted Propulsion Systems for Ships (Edition 2.2)" apply, subject to the cyber resilience requirements (Rules for the Survey and Construction of Steel Ships, Part X, Chapters 4 and 5)?
The control system for a wind-assisted propulsion system installed based on the "Guidelines for Wind-Assisted Propulsion Systems for Ships (Edition 2.2)" is, in principle, outside the scope of application of Chapter 4 (UR E27) and Chapter 5 (UR E26) of Part X of the Rules.
However, if it is installed in the same security zone as an applicable computer-based system (applicable OT system), it must comply with the requirements of E26/27 (Part X, Chapters 5/4).
Q107 Is it necessary for a maintenance PC used by a user (e.g., crew) to have approval under Chapter 4 of Part X (UR E27)? Also, if this PC is connected to an OT system, is the OT system considered to be connected to an untrusted network?
Under certain conditions, Chapter 4 of Part X (E27) approval for the PC is not required, and it is not considered a "connection to an untrusted network."
[Conditions]
-Limited Purpose: The connection is strictly limited to maintenance and servicing tasks, such as software updates, configuration changes, or log retrieval.
-PC Management: The PC is under the shipowner's control and is operated under appropriate security policies, including malware protection.
-OT System Countermeasures: The target OT system implements the security capabilities required by Table X4.1, No. 10 "Use control for portable and mobile devices " in Part X, and has functions to allow connection only from authorized devices, including the said PC.
Please note that this applies only to temporary connections for maintenance and servicing purposes. Permanent connections or use for purposes other than maintenance are not covered by this interpretation.
Q108 Is CCTV used for early fire detection considered an applicable OT system under UR E26/E27?
Generally, it is considered that CCTV is mostly installed and used within the scope of Case 1 in Q90 (for general monitoring purposes).
However, if CCTV is installed as an alternative design, approved by the flag administration, to substitute for a fire detection system required by conventions such as SOLAS, it effectively functions as a fire detection system (Part X, 4.1.2-2.(1)(e) / E26 1.3.2 a)). In this case, it is considered an applicable OT system. (However, it can be exempted from the application if it satisfies the exclusion requirements in Part X, 5.5 / E26 Section 6.)
Q132 For determining the applicability of Part X, Chapters 4 and 5 of the Rules (UR E27/E26), what contract date does the “date of contract for construction” refer to?
The “date of contract for construction” generally means the date on which the contract to build the ship is signed between the prospective owner or other relevant contracting party and the shipbuilder. It does not mean the date of a ship management agreement, charter party, equipment purchase contract, or delivery of the ship. The Society confirms the applicability of the Rules based on the date of contract for construction declared by the applicant for classification and stated in the application for classification or other relevant documents. If the ship management company or other relevant party is not aware of this date, please confirm the date stated in such documents with the shipowner or shipbuilder. For the treatment of the date of contract for construction for a series of ships, optional ships, additional ships, or changes in ship type, please also refer to the ClassNK Technical Information TEC-0704.
(Q132_reference(TEC-0704).pdf)
Q136 Is E27 (Chapter 4, Part X) approval required for an electronic inclinometer?
An electronic inclinometer is navigational equipment required by SOLAS regulation V/19.2.12, as amended by resolution MSC.532(107), for container ships and bulk carriers of 3,000 gross tonnage and upwards constructed on or after 1 January 2026. An electronic inclinometer installed in accordance with this requirement falls under applicable OT systems subject to Chapters 4 and 5, Part X (UR E27 and E26); therefore, if it is equipped with a computer, E27 (Chapter 4, Part X) approval is required.
(However, if the exclusion requirements in 5.5, Part X / E26 Section 6 are satisfied, it may be excluded from application and E27 (Chapter 4, Part X) approval is not required.)
Ch4 Part X(E27) / Ch5 Part X(E26) 15 items
Q25 What should the integrator (shipyard) do when equipment that has not have type approval certificate of IACS UR E27 is installed on a ship?
The first step is to conduct network isolation, etc., and consider exemptions based on risk assessment to exclude the application. (5.5, Part X)
If exemptions are not possible, approval for individual products must be obtained, the manufacturer must submit the documents required in E27, and the manufacturer must undergo a witnessed survey before shipment.
Q35 Are the applicable systems common between UR E22 (Chapter 3 of Part X) and UR E26/E27 (Chapter 4/5 of Part X)?
Some systems are subject to both UR E22 and UR E26/E27, but they are basically different.
In UR E22 rev.3, the applicable equipment and systems will be determined by the integrator. For details, please refer to NK Technical Information TEC-1348.
Q37 Is it correct that the alarm function triggered by excessive bandwidth is not required by UR E27?
In addition to the requirements of E27 (Part X, Chapter 4), the following provisions exist, so it is considered necessary to consider them in the design.
- The requirements in 5.4.4(1)(c)i), Part X of the Rules:
i) Measures to monitor networks in the scope of applicability of this Chapter are to have the following capabilities:
5) generate alarm if utilization of the network’s bandwidth exceeds a threshold specified as abnormal by the supplier (see 3.7.2-1).
- The requirements in 3.7.2-1, Part X of the Rules for Category II or III products:
Data links are to comply with following (1) to (5). In addition, loss of a data link is to be specifically addressed in risk assessment analysis / FMEA (see 3.4.2-3).
(3) Data links are to be provided with means for preventing or coping with excessive communication rates.
(5) Detected failures are to initiate alarms.
Q41 Part X, Chapter 5 requires the preparation of a Ship Cyber Security and Resilience Program. However, it is my understanding that this program has not yet been created at the time of ship completion. (I understand that the shipowner creates it and obtains NK approval after the ship enters service and before the first annual survey.) Even in this case, is it correct to understand that the notation "CybR" will be affixed to the Classification Characters at the time of completion?
Your understanding is correct. Part X, Chapter 5 requires that the Ship Cyber Security and Resilience Program be created by shipowner and approved by ClassNK by the first annual survey. At the time of ship completion, the notation of “Cyber Resilience” (abbreviated to CybR) will be affixed to the Classification Characters even if the program is not yet available.
Q55 Do existing vessels (those with construction contracts concluded before July 1, 2024) need to comply with E26/E27?
No action is required.
Q60
Is E27 (Chapter 4 of Part X) approval necessary for the following products?
-Rate-of-turn indicator
-Engine telegraph
Since those products fall under the applicable OT systems, it is necessary to obtain approval under E27 (Chapter 4, Part X) if they are computer-based systems.
(However, if the exclusion provisions of E26 Section 6 (5.5, Part X) are satisfied, these products will be excluded from the application and approval under E27 (Chapter 4, Part X) will not be required.)
Q61
・Is it necessary to have a qualified person to comply with E26/E27(Chapter 4/5 of Part X)?
・Are there any qualifications required to carry out the tests required by E26/E27(Chpater 4/5 of Part X)?
・Is it necessary to request tests or evaluations by an accredited testing laboratory, etc. to carry out the tests required by E26/E27(Chapter 4/5 of Part X)?
It is not required to use a qualified person or a certified testing organization.
Q70 Even if an applicable OT system communicates P2P with a system that has not obtained E27 approval, can the OT system be treated as having no communication with an untrusted network by installing a firewall on the communication path?
When an applicable OT system communicates P2P (Peer to Peer) with a system that has not obtained E27 approval (a computer-based system on an untrusted network), the OT system is considered to have communication with an untrusted network, even if there is a firewall with E27 approval on the communication path.
Therefore, the OT system must obtain E27 approval for connection with an untrusted network, or the communicating system must obtain E27 approval.
(Q70_reference.pdf)
Q74 If an OT system subject to UR E26/E27 is replaced or newly installed on an existing ship (a ship for which the shipbuilding contract was concluded before July 1, 2024), is compliance with UR E26/E27 required?
No, it is not required.
Q79 In a network configuration shown in the attachment (Q79_reference.pdf), what kind of operations possible from the Remote PC would lead to the OT system being considered as having a connection to an untrusted network?
If the remote PC can perform any operations on the OT system, it implies that the remote PC has access to the OT system. Therefore, in such cases, the OT system is considered to have a connection to an untrusted network.
Q89 What is the relationship between IACS URs E26, E27 and the Rules for the Survey and Construction of Steel Ships?
The IACS (International Association of Classification Societies) Unified Requirements (URs) E26 and E27 are incorporated into Part X of Nippon Kaiji Kyokai's (ClassNK) Rules for the Survey and Construction of Steel Ships.
The specific correspondence is as follows:
UR E27 corresponds to Part X, Chapter 4, "CYBER RESILIENCE OF ON-BOARD SYSTEMS AND EQUIPMENT" of the Steel Ship Rules.
UR E26 corresponds to Part X, Chapter 5, "CYBER RESILIENCE OF SHIPS" of the Steel Ship Rules.
(Q89_reference.pdf)
Q106 Are the requirements based on UR E26 and E27 (Part X, Chapters 5 and 4 in ClassNK rules) different among IACS member societies?
Basically, the minimum requirements based on each UR are consistent across all IACS member societies.
UR E26 and E27 are Unified Requirements (URs) established by the International Association of Classification Societies (IACS). All member societies are required to incorporate these URs into their own rules.
However, it is possible for an individual classification society to impose additional requirements on top of the URs, or for interpretations and operational details to differ. For specific details regarding a particular society's rules, please contact that society directly.
For instance, ClassNK has incorporated UR E27 into Part X, Chapter 4 and UR E26 into Part X, Chapter 5 of our rules. While there may be minor differences in structure or phrasing, the technical requirements are fully aligned with the respective URs.
Q120 Is compliance with Chapters 4 and 5 of Part X (UR E27 and E26) unnecessary for systems classified as Category I or considered outside the scope of Chapter 3 of Part X (UR E22)? Also, is a risk assessment for exemption unnecessary in such cases?
Compliance may be required, as the classification under Chapter 3 of Part X (UR E22) and the scope of applicability for Chapters 4 and 5 of Part X (UR E27 and E26) are determined based on different criteria.
Chapters 4 and 5 of Part X apply to OT systems and other relevant systems specified in 4.1.2-2 of Part X. Even if a system is classified as Category I or is outside the scope of Chapter 3 of Part X, it falls within the scope of Chapters 4 and 5 if it meets the criteria in 4.1.2-2.
Furthermore, if you wish to exclude a system that falls within the scope of 4.1.2-2 from the requirements of the Rules, the system must meet the exclusion criteria in 5.5 of Part X (UR E26 Section 6), regardless of its category under Chapter 3. In such cases, the system needs to be included in the "Risk assessment for the exclusion of computer-based systems" prepared by the shipyard (integrator).
Q121
Part X, Table X4.1 / 5.5.4-2.(2)
Can assigning an incorrect or random IP address to an unused interface be accepted for the following purposes?
1. To be considered "logical disabling" as required by Part X, 5.5.4-2.(2).
2. To treat security capability requirements (e.g., Table X4.1) for that interface as "Not Applicable (N/A)".
No, it is not accepted in either case.
Merely changing the IP address leaves the interface electrically and logically active. Risks such as discovery via scanning tools and exploitation remain, so it is still considered part of the attack surface.
"Logical disabling" under the Rules refers to stopping the function of the interface itself through OS or firmware settings.
Note that this does not preclude changing IP addresses as part of defense-in-depth measures, for instance, to prevent accidental connection.
Q128 Do the requirements of E26/E27 (Part X, Chapters 5/4 of the Rules) include countermeasures against GPS spoofing or jamming?
No. E26/E27 do not directly require countermeasures against GPS spoofing or jamming themselves.
These requirements mainly address cyber risks related to on-board computer-based systems and equipment, and their interfaces, including measures such as network protection, access control, response, and recovery.
GPS spoofing and jamming concern the authenticity or availability of satellite positioning signals received from outside the ship, and are not direct subjects of these requirements.