Skip to main content
Please wait...

Inventory: IACS E26/E27 standards

To comply with the IACS E26/E27 standards, maritime organizations must create detailed asset inventories for both ship-wide and onboard systems and equipment. Here's a breakdown of the key inventory requirements from the IACS E26 and E27 specifications:

IACS UR E26: Cyber Resilience of Ships

For E26, the inventory must cover:

  1. Vessel Asset Inventory: This includes all OT (Operational Technology) and IT (Information Technology) equipment throughout the vessel’s lifecycle. The inventory should detail:
    • Equipment type and specifications
    • Location on the vessel
    • Network connections and configurations
    • Cybersecurity features and compliance status
  2. Zones and Conduit Diagram: A comprehensive mapping of the vessel's zones and conduits, identifying network segments and communication pathways.
  3. Cyber-Security Design Description: Documentation of the cybersecurity measures implemented during the design and construction phases.

IACS UR E27: Cyber Resilience of Onboard Systems and Equipment

For E27, the inventory must cover:

  1. CBS (Computer-Based Systems) Asset Inventory: Detailed information on all computer-based systems, particularly those interfacing with untrusted networks. This includes:
    • System identification and specifications
    • Interface descriptions
    • Security capabilities and compliance status
  2. CBS Topology Diagrams: Network diagrams showing the interconnections and communications between CBSs.
  3. Description of Security Capabilities: Detailed descriptions of the security capabilities for each CBS, particularly for systems interfacing with untrusted networks.
  4. Security Configuration Guidelines: Documentation outlining the security configurations and best practices for each system.

Excel Inventory Template

Here's an expanded Excel table template for your inventory, with detailed descriptions for each column:

Asset TypeEquipment/System NameLocationSpecificationsNetwork ConnectionsCybersecurity FeaturesCompliance Status
OT EquipmentEngine Control SystemEngine RoomManufacturer, Model, Version, Serial Number, Performance Specs, Environmental SpecsIP Address, MAC Address, Protocols Used, Connected Systems, Physical ConnectionsAntivirus, Firewalls, Encryption, Access Controls, Intrusion DetectionCompliant, Non-compliant, Pending
IT EquipmentShip's ServerServer RoomManufacturer, Model, OS Version, CPU, RAM, Storage, Network Interface Cards (NICs)IP Address, MAC Address, Protocols Used, Connected Systems, Physical ConnectionsAntivirus, Firewalls, Encryption, Access Controls, Intrusion DetectionCompliant, Non-compliant, Pending
CBSNavigation SystemBridgeManufacturer, Model, Version, Serial Number, Functional Specs, Redundancy FeaturesIP Address, MAC Address, Protocols Used, Connected Systems, Physical ConnectionsAntivirus, Firewalls, Encryption, Access Controls, Intrusion DetectionCompliant, Non-compliant, Pending

Column Descriptions:

  1. Specifications:
    • Manufacturer: The company that made the equipment.
    • Model: The specific model number or name.
    • Version: The version of the software or firmware installed.
    • Serial Number: Unique identifier for the equipment.
    • Performance Specs: Details on the equipment's capabilities (e.g., processing speed, memory capacity).
    • Environmental Specs: Operational limits (e.g., temperature range, humidity tolerance).
  2. Network Connections:
    • IP Address: The IP address assigned to the equipment.
    • MAC Address: The Media Access Control address.
    • Protocols Used: Network protocols the equipment uses (e.g., TCP/IP, UDP).
    • Connected Systems: Other systems or devices to which the equipment is connected.
    • Physical Connections: Physical network connections (e.g., Ethernet ports, wireless connections).
  3. Cybersecurity Features:
    • Antivirus: Information on antivirus software installed.
    • Firewalls: Details about firewall configurations and rules.
    • Encryption: Types of encryption used for data protection.
    • Access Controls: Measures in place to control access (e.g., passwords, multi-factor authentication).
    • Intrusion Detection: Systems or software used to detect unauthorized access.
  4. Compliance Status:
    • Compliant: Equipment meets the required cybersecurity standards.
    • Non-compliant: Equipment does not meet the standards.
    • Pending: Compliance status is under review or pending updates.

Example Entry:

Asset TypeEquipment/System NameLocationSpecificationsNetwork ConnectionsCybersecurity FeaturesCompliance Status
OT EquipmentEngine Control SystemEngine RoomManufacturer: Siemens, Model: S7-1500, Version: 2.0, Serial Number: 1234567890, Performance Specs: 1 GHz CPU, Environmental Specs: 0-60°CIP Address: 192.168.1.10, MAC Address: 00:1A:2B:3C:4D:5E, Protocols Used: TCP/IP, Connected Systems: PLC Network, Physical Connections: EthernetAntivirus: McAfee, Firewalls: Cisco ASA, Encryption: AES-256, Access Controls: Password Protected, Intrusion Detection: SnortCompliant

IT or OT Inventory Excel Table Columns

  1. Asset ID: Unique identifier for each asset.
  2. Asset Type: IT or OT.
  3. Asset Name: Name of the system or device.
  4. Description: Brief description of the asset.
  5. Manufacturer: Name of the manufacturer or vendor.
  6. Model: Model number or name.
  7. Serial Number: Serial number of the device.
  8. Location: Physical location on the vessel (e.g., Bridge, Engine Room).
  9. IP Address: Network IP address, if applicable.
  10. MAC Address: MAC address for network devices.
  11. Operating System/Firmware: Version of the operating system or firmware.
  12. Function: Purpose of the asset (e.g., Navigation, Communication, Control).
  13. Connectivity: Type of connectivity (e.g., Ethernet, Wi-Fi, Serial).
  14. Network Segment: Segment of the network where the device is connected (e.g., VLAN, Subnet).
  15. Security Level: Classification of security importance (e.g., Critical, High, Medium, Low).
  16. Owner: Person or department responsible for the asset.
  17. Vendor Support: Contact information for vendor support.
  18. Warranty Expiry Date: Date when the warranty expires.
  19. Last Maintenance Date: Date of the last maintenance or inspection.
  20. Next Maintenance Date: Scheduled date for the next maintenance.
  21. End of Life (EOL): Expected end-of-life date for the asset.
  22. Compliance: Compliance with specific standards or regulations (e.g., IACS E26/E27, IMO).
  23. Risk Level: Risk assessment level (e.g., High, Medium, Low).
  24. Redundancy: Availability of backup or redundant systems.
  25. Criticality: How critical the asset is to vessel operations.
  26. Comments/Notes: Additional notes or comments.

Download the Inventory template file here

Instructions

  1. Asset Identification: Use a consistent naming convention for Asset IDs.
  2. Regular Updates: Regularly update the inventory to reflect changes in assets, maintenance, or compliance status.
  3. Security and Compliance: Ensure that all critical and high-risk assets are properly documented, maintained, and compliant with relevant standards.
  4. Backup: Keep a secure backup of this inventory in a location accessible to key personnel.

This inventory template will help you manage and monitor the IT and OT assets on your vessel effectively. You can customize the columns based on your specific needs and vessel operations.

You can create this table in an Excel file, ensuring each column has appropriate space for detailed entries. This structured approach will help ensure comprehensive documentation and easier management of compliance with the IACS E26 and E27 standards.

This table format can be expanded and customized according to the specific needs and equipment of your vessel.

This inventory template and guidance will help ensure your maritime operations align with the IACS E26 and E27 standards, enhancing your vessel's cyber resilience.

About

As certified providers recognized by Lloyds Register of Shipping, we specialize in inspection and testing of Lifting Appliances and loose gear. Compliance with the Code for Lifting Appliances in a Marine Environment is ensured through thorough annual testing and examination by our competent professionals. Trust HBMS technicians as your advisors for compliance and peace of mind.