ShipCalculators.com

Integrated Bridge System (IBS) Cyber Risk

E1. Maritime security, geopolitics and risk

Definition

Networked navigation systems exposing attack surface.

Integrated Bridge System (IBS) cyber risk is the attack surface created by networking the bridge’s navigation and control functions, ECDIS, radar, AIS, GPS, conning, autopilot, and alarm management, onto shared data links. A compromise of one node, or a spoofed sensor feed, can propagate across the bridge and mislead the watch. Many IBS components run legacy software with infrequent patching and accept updates via removable media. IMO MSC-FAL.1/Circ.3 and BIMCO call for segmentation, controlled media, and access control around these systems; IEC 61162 governs the maritime data interfaces that tie them together.

Source: IEC 61924 (Integrated Bridge Systems) and IEC 61162 (maritime navigation data interfaces); IMO MSC-FAL.1/Circ.3, 5 July 2017