Patch Management
E1. Maritime security, geopolitics and riskDefinition
Cyber-control practice for shipboard systems.
Patch management is the disciplined process of tracking, testing, and applying software and firmware updates that close known vulnerabilities, indexed by CVE identifiers. On ships it is harder than ashore: many OT components run unsupported operating systems, vendors must approve changes to type-approved navigation equipment, and patches often arrive on removable media over a thin satellite link. Programs therefore prioritize by exploitability and criticality, test offline, and document deferrals. Sound patch management is a named control under IMO MSC-FAL.1/Circ.3, the BIMCO guidelines, and ISO/IEC 27001, and is what turns vulnerability awareness into reduced risk.
Source: IMO MSC-FAL.1/Circ.3, 5 July 2017; ISO/IEC 27001:2022 Annex A technical-vulnerability management