USCG Subpart F Mandatory Standard Title 33 CFR § 101.650(g)(2) Maritime Cyber Incident Response Plan Master Implementation Guidance Author & Contact: Joe Shenouda (LinkedIn)
USCG Subpart F • Final Rule 90 FR 6447 • Effective July 16, 2025

Cyber Incident Response Plan (CIRP) Master Guidance

Full implementation documentation, IT/OT technical playbooks, USCG/NRC reporting scripts, exercise frameworks, forms suite, and inspection audit checklists to satisfy 33 CFR § 101.650(g)(2) for U.S.-flagged vessels (Part 104), waterfront facilities (Part 105), and Outer Continental Shelf facilities (Part 106).

eCFR Citation 33 CFR 101.650(g)(2)
NRC Emergency Line 1-800-424-8802
Mandatory Officer CySO / CSO / FSO
Plan Location Plan Sec. 3 & Sec. 9
Part I

Foundations, Statutory Authority & Regulatory Frame

Sections 0 through 5: Regulatory basis, applicability, mapping, timeline, and authoritative definitions.

Section 0 — How to Use This Guide & Document Conventions

The CIRP is one of a small number of documents that Subpart F requires you to actually operate, not merely write. The four verbs in 33 CFR § 101.650(g)(2) are cumulative, and each is separately auditable:

DEVELOP

Write a discrete, controlled, approved document with owners and version control.

IMPLEMENT

Put into force: named people, trained, tooled, 24/7 reachable, usable procedures.

MAINTAIN

Keep current: reviews, amendments, contact re-validation, lessons learned.

EXERCISE

Prove it: drills, tabletops, functional tests, documented with corrective actions.

Section 1 — Regulatory Basis & Statutory Authority

eCFR Operative Text — 33 CFR § 101.650(g):
"(g) Resilience. Each owner or operator or designated CySO of a U.S.-flagged vessel, facility, or OCS facility must ensure the following measures for resilience are in place and documented in Sections 3 and 9 of the Cybersecurity Plan:
(1) For entities that have not reported to the Coast Guard pursuant to, or not subject to, 33 CFR 6.16-1, report reportable cyber incidents to the NRC without delay;
(2) In addition to other plans mentioned in this subpart, develop, implement, maintain, and exercise the Cyber Incident Response Plan;
(3) Periodically validate the effectiveness of the Cybersecurity Plan through annual exercises, annual reviews of incident response cases, or post-cyber-incident review, as determined by the owner or operator; and
(4) Perform backup of critical IT and OT systems, with those backups being sufficiently protected and tested frequently."

Statutory Authority Chain: 46 U.S.C. 70101–70104, 70124 (Maritime Transportation Security Act - MTSA); Executive Order 12656; 33 CFR 1.05-1, 6.04-11, 6.14, 6.16, 6.19 (COTP Port Security Authority); DHS Delegation 00170.1; Final Rule 90 FR 6447 (Jan. 17, 2025).

Section 2 — Applicability & Scoping Decisions

Covered Entity Category Governing Security Subchapter Records Retention Citation
U.S.-Flagged Vessels subject to MTSA 33 CFR Part 104 (VSP) 33 CFR 104.235
Waterfront Facilities (ports, terminals) 33 CFR Part 105 (FSP) 33 CFR 105.225
Outer Continental Shelf (OCS) Facilities 33 CFR Part 106 (OCS FSP) 33 CFR 106.230

Section 3 — Where the CIRP Lives: Cybersecurity Plan Crosswalk

§ 101.650 Measure Measure Group Required Plan Section CIRP Operational Relevance
(a) Account SecurityCredentials & MFASection 7Mass password reset, token revocation, account disable.
(b) Device SecurityInventories & MapsSection 6Hardware/software whitelists, network maps, OT baselines.
(c) Data SecuritySecure LoggingSection 4Privileged log access, forensic log preservation.
(d) TrainingPersonnel ReadinessSection 2 & 4Threat recognition, incident reporting to CySO, role training.
(e) Risk ManagementAssessment & KEVsSection 11 & 12Annual assessment, KEV patching "without delay".
(f) Supply ChainVendor ConnectionsSection 4Vendor incident notification, 24/7 remote monitoring.
(g) Resilience (CIRP)CIRP, Backups, NRCSection 3 & 9The CIRP document (Sec 9), exercise schedule (Sec 3).
(h) SegmentationIT/OT BoundarySection 7 & 8IT/OT boundary isolation, conduit logging for traversal.
(i) Physical SecurityHMI & Media ProtectionSection 7 & 8HMI access logs, physical port disabling, media blocking.

Section 4 — Codified Compliance Timeline

July 16, 2025

Subpart F Effective Date. Immediate mandatory NRC reporting active.

January 12, 2026

Personnel cybersecurity training complete (§ 101.650(d)(4)).

July 16, 2027

First Cybersecurity Assessment complete & CySO designated in writing.

Continuous / Annual

CIRP maintained, exercised annually (g)(3), backups tested frequently (g)(4).

Section 5 — Key Regulatory Definitions (§ 101.605)

Cyber Incident

An occurrence that jeopardizes without lawful authority the confidentiality, integrity, or availability of information or an information system.

Reportable Cyber Incident

An incident resulting in substantial loss of CIA, operational disruption, public safety impact, or nonpublic personal data access. Triggers NRC notification without delay.

Cybersecurity Officer (CySO)

The qualified individual designated in writing by the owner/operator with authority to implement cybersecurity measures and serve as official contact.

IT System vs. OT System

IT: Enterprise data systems.
OT: Programmable systems monitoring/controlling physical processes (ECDIS, SCADA, PLCs, cargo pumps, propulsion).

Part II

Building the Cyber Incident Response Plan

Sections 6 through 8: Pre-work, document architecture, and chapter-by-chapter drafting guidance.

Section 6 — Pre-Work & Mandatory Inputs

A CIRP written without these 10 inputs will fail both operationally and on Coast Guard inspection. Conveniently, each input is already mandated elsewhere in § 101.650:

1. Network Asset Inventory (§ 101.650(b)(3))

Unique ID, location, IT/OT tier, business/safety function, IP/VLAN, patch owner.

2. Network Map & OT Configurations (§ 101.650(b)(4))

IT/OT conduits, firewalls, jump hosts, satcom links, vendor remote access paths.

3. Approved Software/Hardware List (§ 101.650(b)(1))

Baseline used during incidents to detect unauthorized executables or rogue hardware.

4. Secure Logging Architecture (§ 101.650(c)(1))

Privileged-only access logs, time synchronization source, tamper-proof retention.

Section 7 — CIRP Document Architecture (15 Chapters)

Ch 1: Purpose & Authority Ch 2: Definitions Ch 3: Roles & RACI Ch 4: Protected Assets Ch 5: Severity & Escalation
Ch 6: Internal Triage Gate Ch 7: Regulatory Reporting Ch 8: 4-Phase Lifecycle Ch 9: OT Manual Operations Ch 10: Battle Rhythm Comms
Ch 11: Forensics & Custody Ch 12: Recovery & Backups Ch 13: Post-Incident AAR Ch 14: Exercises & Drills Ch 15: Revision Control

Section 8 — Detailed Chapter Drafting Guidance & Model Text

Chapter C1 Model Drafting Text (Copy-Paste Template)

================================================================================
CHAPTER 1: PURPOSE, REGULATORY AUTHORITY & PLAN SCOPE
================================================================================
1.1 PURPOSE: This Cyber Incident Response Plan (CIRP) provides predetermined
    operational instructions to identify, report, contain, eradicate, and
    recover from cyber incidents affecting IT and OT systems on [ASSET NAME].
1.2 STATUTORY BASIS: Mandated under United States Coast Guard regulations in
    33 CFR § 101.650(g)(2) (Subpart F). Documented in Sections 3 and 9 of the
    Cybersecurity Plan.
1.3 PRECEDENCE: Physical safety of navigation, human life, and environmental
    protection outrank all cyber containment actions. The Master / FSO retains
    overriding authority per 33 CFR Parts 104/105/106.
                            

C5: Two-Axis Incident Severity & Classification Scheme

Severity Level Qualifying Criteria Operational Actions Regulatory Reporting Trigger
SEV-1 Critical Tier 1 OT impact, safety/navigation risk, active ransomware across critical IT/OT. Activate full CIRT, switch OT to local manual control, sever IT/OT boundary. NRC WITHOUT DELAY (< 2 Hours)
SEV-2 High Compromise of critical IT or remote OT session without immediate safety impact. Isolate hosts, disable compromised domain accounts, engage IR retainer. Within 4 Hours (CISA / CySO)
SEV-3 Moderate Contained single-host malware on non-critical IT, rapidly reset credential phishing. Standard IT remediation, re-image system, log in incident register. Internal Tracking (24 Hours)
SEV-4 Minor Blocked port scans, spam, failed brute-force login attempts within lockout. Automated logging, roll up into monthly logs for annual review. Monthly Log Review

C6: Internal CySO Triage Decision Gate (Logic Sequence)

STEP 1: Incident report received -> Assign Incident ID -> Open Form B-2 Log.

STEP 2: Is safety, navigation, propulsion, or cargo stability threatened? YES -> Notify Master/FSO immediately. Execute manual override.

STEP 3: Apply 33 CFR § 101.605 Reportable Cyber Incident definition. Document determination in Form B-3.

STEP 4: If REPORTABLE or UNCLEAR -> Execute National Response Center (1-800-424-8802) notification WITHOUT DELAY.

C8.2: The Cardinal OT Containment Rule

Mandatory Rule: Never take a containment action on an Operational Technology (OT) system without explicit OT Lead / Chief Engineer concurrence and a verified safe state. Disconnecting or powering down an OT controller can induce the exact physical safety consequence the threat actor intends.

Part III

Operational Incident Playbook Library (PB-01 to PB-12)

Predetermined technical response procedures tailored for Maritime IT and OT environments

PB-01: Ransomware Attack on IT or OT Network

SEV-1 Critical
  1. Isolate Hosts Immediately: Disconnect infected workstations/servers from Ethernet and Wi-Fi. Do NOT power off systems to preserve volatile memory RAM forensics.
  2. Sever IT/OT Boundary: Unplug or disable the firewall gateway bridging IT and OT networks (§ 101.650(h)(1)).
  3. Revoke Domain Credentials: Disable compromised user accounts and terminate active Active Directory/VPN sessions (§ 101.650(a)).
  4. Execute NRC Reporting: Notify National Response Center at 1-800-424-8802 without delay.
  5. Verify Backup Integrity: Confirm offline air-gapped backups (§ 101.650(g)(4)) are uncorrupted before restoring.
Part IV

Operations, Maintenance, Exercises & Records

Sections 10 through 14: Implementation proof, exercise program, and records retention.

Section 10 — Implementation Checklist & Evidence Artifacts

✔ Written CySO Designation Letter

Signed by owner/operator with explicit 24/7 authority to order containment and disconnection.

✔ 24/7 Hotline & Out-of-Band Channel

Tested satellite phone numbers and pre-printed call trees distributed on bridge/control room.

✔ Printed Offline CIRP Copies

Physical binder verified present aboard vessel/at facility during power/network outages.

✔ Vendor Notification Addenda

Contracts carrying mandatory vendor incident reporting duties without delay (§ 101.650(f)(2)).

Section 12 — Exercise Program, 12 Maritime Scenarios & Safety Rules

Under 33 CFR § 101.650(g)(3), entities must validate CIRP effectiveness through annual exercises, annual case reviews, or post-incident reviews.

12 Maritime Exercise Scenario Bank Ideas

1. Terminal Operating System Ransomware
2. ECDIS GNSS Spoofing & Chart Corruption
3. Compromised Vendor OT Maintenance Session
4. Phishing with Privileged OT Credential Theft
5. Rogue USB Device Inserted into HMI Panel
6. Ballast Control SCADA Manipulated at Sea
7. Loss of Satcom / VSAT During Cargo Transfer
8. Unpatched KEV Exploited on Gate System
9. Disgruntled Crew Member Tampering with Engine OT
10. Supply Chain Compromise of Radar Firmware
11. Mass Active Directory Ransomware Lockout
12. Concurrent Cyber Incident & Physical Breach
EXERCISE SAFETY RULE: Prefix every exercise communication with "THIS IS AN EXERCISE". Never place a live report to the National Response Center (1-800-424-8802) during a drill. Simulate all regulatory calls.

Section 13 & 14 — Records Retention & Plan Amendment Process

Records must be retained per 33 CFR 104.235 (Vessels), 105.225 (Facilities), or 106.230 (OCS Facilities) for at least 2 years. Material changes flowing from exercises or incidents must be processed as formal Cybersecurity Plan amendments under 33 CFR § 101.630(e).

Part V

Assurance, Self-Audit & Standards Crosswalk

Sections 15 through 17: Audit readiness checklist, framework mapping, and common inspector findings.

Section 15 — USCG Inspection Audit Readiness Checklist

Section 16 — International Standards Crosswalk

CIRP Chapter NIST CSF 2.0 NIST SP 800-61 / 800-82 IEC 62443 / IMO / IACS UR E26/E27
Roles & RACI (C3) GV.RR, RS.MA NIST SP 800-61 Sec 2 IMO Resolution MSC.428(98)
Detection & Triage (C6) DE.AE, DE.CM NIST SP 800-92 Logging IEC 62443-3-3 System Security
NRC Notification (C7) RS.CO-02 USCG Subpart F (g)(1) 33 CFR 6.16-1 / CIRCIA
OT Containment (C8/C9) PR.IR, RS.MI NIST SP 800-82r3 OT Security IACS UR E26 / E27 Cyber Resilience
Backups & Restore (C12) RC.RP, PR.DS NIST SP 800-34 Contingency BIMCO Guidelines Onboard Ships

Section 17 — Common Inspection Deficiencies & Corrective Fixes

❌ Common Defect: Generic IT Plan

Plan only covers corporate email with no mention of OT, SCADA, ECDIS, or manual machinery overrides.

✔ Fix: Add OT Playbooks (PB-02) and Chief Engineer manual control procedures.
❌ Common Defect: Gated NRC Reporting

Plan requires prior legal or executive approval before calling NRC, causing unlawful reporting delay.

✔ Fix: Pre-authorize CySO in writing to report to NRC without delay.
Part VI

Annexes: Forms Suite, Scripts, Quick-Card & Glossary

Annexes A through E: Operational recording forms, notification scripts, bridge card, and verification notes.

Annex A — Interactive Form Suite (Forms B-1 to B-8)

FORM B-1: CYBER INCIDENT INITIAL REPORT (Submit to CySO Immediately)
================================================================================
Reporter Name / Rank: ________________________ Date/Time (UTC): ________________
Vessel / Facility Location: ___________________ System Affected: _______________
Description of Anomaly: _______________________________________________________
Is Safety, Navigation, or Cargo Stability Impaired? [ ] YES  [ ] NO
Initial Severity Assigned: [ ] SEV-1  [ ] SEV-2  [ ] SEV-3  [ ] SEV-4
CySO Acknowledgment Signature: __________________ Date: _______________________
                            

Annex B — External Notification Scripts (Scripts 1 to 4)

SCRIPT 1: MANDATORY INITIAL USCG NRC NOTIFICATION CALL (1-800-424-8802)
================================================================================
"This is [NAME], designated Cybersecurity Officer for [COMPANY].
I am reporting a cyber incident affecting [VESSEL NAME / OFFICIAL ID or FACILITY NAME / ID], located at [POSITION / ADDRESS] in the [COTP ZONE] Captain of the Port Zone.

We have determined this to be a reportable cyber incident under 33 CFR § 101.650(g)(1). Discovered at [TIME UTC]. Determination made at [TIME UTC].

Summary of Incident: [NATURE OF INCIDENT]. Systems affected: [IT / OT / BOTH]. Critical systems affected: [YES/NO]. Operational status: [NORMAL / DEGRADED / LOST]. Safety status: [NO INJURIES / NO POLLUTION / VESSEL SAFE]. Actions taken: [ISOLATION / MANUAL CONTROL / OPERATIONS SUSPENDED].

My 24/7 callback number is [PHONE]. May I please have the official NRC Case Reference Number?"
                            

Annex C — Bridge / Control Room Emergency Quick-Reference Card

🚨 BRIDGE / ENGINE ROOM / CONTROL ROOM EMERGENCY CARD
  1. SAFETY FIRST: Vessel navigation and crew safety outrank cyber containment. Revert OT to local manual control.
  2. REPORT IMMEDIATELY: Call CySO 24/7 Hotline: [INSERT PHONE].
  3. DO NOT: Do not power off PLCs/HMIs, do not delete logs, do not insert USBs.
  4. ISOLATE NETWORK: Disconnect Ethernet cable from affected workstation or open IT/OT boundary firewall switch.
  5. NOTIFY NRC: CySO calls National Response Center at 1-800-424-8802 without delay.

Annex D & E — Glossary of Abbreviations & Source Verification

Glossary: AIS (Automatic Identification System), BCP (Business Continuity Plan), CDC (Certain Dangerous Cargo), CIRP (Cyber Incident Response Plan), CIRT (Cyber Incident Response Team), CISA (Cybersecurity & Infrastructure Security Agency), COTP (Captain of the Port), CySO (Cybersecurity Officer), ECDIS (Electronic Chart Display), HMI (Human-Machine Interface), KEV (Known Exploited Vulnerability), MTSA (Maritime Transportation Security Act), NRC (National Response Center), OT (Operational Technology), PLC (Programmable Logic Controller), SCADA (Supervisory Control and Data Acquisition), TSI (Transportation Security Incident), VTS (Vessel Traffic Service).

Verification Notes: Quoted regulations drawn from eCFR Title 33 Subchapter H Part 101 Subpart F (Final Rule 90 FR 6447, Jan. 17, 2025). Verify binding interpretations with cognizant Captain of the Port (COTP).