Foundations, Statutory Authority & Regulatory Frame
Sections 0 through 5: Regulatory basis, applicability, mapping, timeline, and authoritative definitions.
Section 0 — How to Use This Guide & Document Conventions
The CIRP is one of a small number of documents that Subpart F requires you to actually operate, not merely write. The four verbs in 33 CFR § 101.650(g)(2) are cumulative, and each is separately auditable:
Write a discrete, controlled, approved document with owners and version control.
Put into force: named people, trained, tooled, 24/7 reachable, usable procedures.
Keep current: reviews, amendments, contact re-validation, lessons learned.
Prove it: drills, tabletops, functional tests, documented with corrective actions.
Section 1 — Regulatory Basis & Statutory Authority
"(g) Resilience. Each owner or operator or designated CySO of a U.S.-flagged vessel, facility, or OCS facility must ensure the following measures for resilience are in place and documented in Sections 3 and 9 of the Cybersecurity Plan:
(1) For entities that have not reported to the Coast Guard pursuant to, or not subject to, 33 CFR 6.16-1, report reportable cyber incidents to the NRC without delay;
(2) In addition to other plans mentioned in this subpart, develop, implement, maintain, and exercise the Cyber Incident Response Plan;
(3) Periodically validate the effectiveness of the Cybersecurity Plan through annual exercises, annual reviews of incident response cases, or post-cyber-incident review, as determined by the owner or operator; and
(4) Perform backup of critical IT and OT systems, with those backups being sufficiently protected and tested frequently."
Statutory Authority Chain: 46 U.S.C. 70101–70104, 70124 (Maritime Transportation Security Act - MTSA); Executive Order 12656; 33 CFR 1.05-1, 6.04-11, 6.14, 6.16, 6.19 (COTP Port Security Authority); DHS Delegation 00170.1; Final Rule 90 FR 6447 (Jan. 17, 2025).
Section 2 — Applicability & Scoping Decisions
| Covered Entity Category | Governing Security Subchapter | Records Retention Citation |
|---|---|---|
| U.S.-Flagged Vessels subject to MTSA | 33 CFR Part 104 (VSP) | 33 CFR 104.235 |
| Waterfront Facilities (ports, terminals) | 33 CFR Part 105 (FSP) | 33 CFR 105.225 |
| Outer Continental Shelf (OCS) Facilities | 33 CFR Part 106 (OCS FSP) | 33 CFR 106.230 |
Section 3 — Where the CIRP Lives: Cybersecurity Plan Crosswalk
| § 101.650 Measure | Measure Group | Required Plan Section | CIRP Operational Relevance |
|---|---|---|---|
| (a) Account Security | Credentials & MFA | Section 7 | Mass password reset, token revocation, account disable. |
| (b) Device Security | Inventories & Maps | Section 6 | Hardware/software whitelists, network maps, OT baselines. |
| (c) Data Security | Secure Logging | Section 4 | Privileged log access, forensic log preservation. |
| (d) Training | Personnel Readiness | Section 2 & 4 | Threat recognition, incident reporting to CySO, role training. |
| (e) Risk Management | Assessment & KEVs | Section 11 & 12 | Annual assessment, KEV patching "without delay". |
| (f) Supply Chain | Vendor Connections | Section 4 | Vendor incident notification, 24/7 remote monitoring. |
| (g) Resilience (CIRP) | CIRP, Backups, NRC | Section 3 & 9 | The CIRP document (Sec 9), exercise schedule (Sec 3). |
| (h) Segmentation | IT/OT Boundary | Section 7 & 8 | IT/OT boundary isolation, conduit logging for traversal. |
| (i) Physical Security | HMI & Media Protection | Section 7 & 8 | HMI access logs, physical port disabling, media blocking. |
Section 4 — Codified Compliance Timeline
Subpart F Effective Date. Immediate mandatory NRC reporting active.
Personnel cybersecurity training complete (§ 101.650(d)(4)).
First Cybersecurity Assessment complete & CySO designated in writing.
CIRP maintained, exercised annually (g)(3), backups tested frequently (g)(4).
Section 5 — Key Regulatory Definitions (§ 101.605)
An occurrence that jeopardizes without lawful authority the confidentiality, integrity, or availability of information or an information system.
An incident resulting in substantial loss of CIA, operational disruption, public safety impact, or nonpublic personal data access. Triggers NRC notification without delay.
The qualified individual designated in writing by the owner/operator with authority to implement cybersecurity measures and serve as official contact.
IT: Enterprise data systems.
OT: Programmable systems monitoring/controlling physical processes (ECDIS, SCADA, PLCs, cargo pumps, propulsion).
Building the Cyber Incident Response Plan
Sections 6 through 8: Pre-work, document architecture, and chapter-by-chapter drafting guidance.
Section 6 — Pre-Work & Mandatory Inputs
A CIRP written without these 10 inputs will fail both operationally and on Coast Guard inspection. Conveniently, each input is already mandated elsewhere in § 101.650:
Unique ID, location, IT/OT tier, business/safety function, IP/VLAN, patch owner.
IT/OT conduits, firewalls, jump hosts, satcom links, vendor remote access paths.
Baseline used during incidents to detect unauthorized executables or rogue hardware.
Privileged-only access logs, time synchronization source, tamper-proof retention.
Section 7 — CIRP Document Architecture (15 Chapters)
Section 8 — Detailed Chapter Drafting Guidance & Model Text
Chapter C1 Model Drafting Text (Copy-Paste Template)
================================================================================ CHAPTER 1: PURPOSE, REGULATORY AUTHORITY & PLAN SCOPE 1.1 PURPOSE: This Cyber Incident Response Plan (CIRP) provides predetermined operational instructions to identify, report, contain, eradicate, and recover from cyber incidents affecting IT and OT systems on [ASSET NAME]. 1.2 STATUTORY BASIS: Mandated under United States Coast Guard regulations in 33 CFR § 101.650(g)(2) (Subpart F). Documented in Sections 3 and 9 of the Cybersecurity Plan. 1.3 PRECEDENCE: Physical safety of navigation, human life, and environmental protection outrank all cyber containment actions. The Master / FSO retains overriding authority per 33 CFR Parts 104/105/106. ================================================================================
C5: Two-Axis Incident Severity & Classification Scheme
| Severity Level | Qualifying Criteria | Operational Actions | Regulatory Reporting Trigger |
|---|---|---|---|
| SEV-1 Critical | Tier 1 OT impact, safety/navigation risk, active ransomware across critical IT/OT. | Activate full CIRT, switch OT to local manual control, sever IT/OT boundary. | NRC WITHOUT DELAY (< 2 Hours) |
| SEV-2 High | Compromise of critical IT or remote OT session without immediate safety impact. | Isolate hosts, disable compromised domain accounts, engage IR retainer. | Within 4 Hours (CISA / CySO) |
| SEV-3 Moderate | Contained single-host malware on non-critical IT, rapidly reset credential phishing. | Standard IT remediation, re-image system, log in incident register. | Internal Tracking (24 Hours) |
| SEV-4 Minor | Blocked port scans, spam, failed brute-force login attempts within lockout. | Automated logging, roll up into monthly logs for annual review. | Monthly Log Review |
C6: Internal CySO Triage Decision Gate (Logic Sequence)
STEP 1: Incident report received -> Assign Incident ID -> Open Form B-2 Log.
STEP 2: Is safety, navigation, propulsion, or cargo stability threatened? YES -> Notify Master/FSO immediately. Execute manual override.
STEP 3: Apply 33 CFR § 101.605 Reportable Cyber Incident definition. Document determination in Form B-3.
STEP 4: If REPORTABLE or UNCLEAR -> Execute National Response Center (1-800-424-8802) notification WITHOUT DELAY.
C8.2: The Cardinal OT Containment Rule
Mandatory Rule: Never take a containment action on an Operational Technology (OT) system without explicit OT Lead / Chief Engineer concurrence and a verified safe state. Disconnecting or powering down an OT controller can induce the exact physical safety consequence the threat actor intends.
Operational Incident Playbook Library (PB-01 to PB-12)
Predetermined technical response procedures tailored for Maritime IT and OT environments
PB-01: Ransomware Attack on IT or OT Network
SEV-1 Critical- Isolate Hosts Immediately: Disconnect infected workstations/servers from Ethernet and Wi-Fi. Do NOT power off systems to preserve volatile memory RAM forensics.
- Sever IT/OT Boundary: Unplug or disable the firewall gateway bridging IT and OT networks (§ 101.650(h)(1)).
- Revoke Domain Credentials: Disable compromised user accounts and terminate active Active Directory/VPN sessions (§ 101.650(a)).
- Execute NRC Reporting: Notify National Response Center at 1-800-424-8802 without delay.
- Verify Backup Integrity: Confirm offline air-gapped backups (§ 101.650(g)(4)) are uncorrupted before restoring.
Operations, Maintenance, Exercises & Records
Sections 10 through 14: Implementation proof, exercise program, and records retention.
Section 10 — Implementation Checklist & Evidence Artifacts
Signed by owner/operator with explicit 24/7 authority to order containment and disconnection.
Tested satellite phone numbers and pre-printed call trees distributed on bridge/control room.
Physical binder verified present aboard vessel/at facility during power/network outages.
Contracts carrying mandatory vendor incident reporting duties without delay (§ 101.650(f)(2)).
Section 12 — Exercise Program, 12 Maritime Scenarios & Safety Rules
Under 33 CFR § 101.650(g)(3), entities must validate CIRP effectiveness through annual exercises, annual case reviews, or post-incident reviews.
12 Maritime Exercise Scenario Bank Ideas
Section 13 & 14 — Records Retention & Plan Amendment Process
Records must be retained per 33 CFR 104.235 (Vessels), 105.225 (Facilities), or 106.230 (OCS Facilities) for at least 2 years. Material changes flowing from exercises or incidents must be processed as formal Cybersecurity Plan amendments under 33 CFR § 101.630(e).
Assurance, Self-Audit & Standards Crosswalk
Sections 15 through 17: Audit readiness checklist, framework mapping, and common inspector findings.
Section 15 — USCG Inspection Audit Readiness Checklist
Section 16 — International Standards Crosswalk
| CIRP Chapter | NIST CSF 2.0 | NIST SP 800-61 / 800-82 | IEC 62443 / IMO / IACS UR E26/E27 |
|---|---|---|---|
| Roles & RACI (C3) | GV.RR, RS.MA | NIST SP 800-61 Sec 2 | IMO Resolution MSC.428(98) |
| Detection & Triage (C6) | DE.AE, DE.CM | NIST SP 800-92 Logging | IEC 62443-3-3 System Security |
| NRC Notification (C7) | RS.CO-02 | USCG Subpart F (g)(1) | 33 CFR 6.16-1 / CIRCIA |
| OT Containment (C8/C9) | PR.IR, RS.MI | NIST SP 800-82r3 OT Security | IACS UR E26 / E27 Cyber Resilience |
| Backups & Restore (C12) | RC.RP, PR.DS | NIST SP 800-34 Contingency | BIMCO Guidelines Onboard Ships |
Section 17 — Common Inspection Deficiencies & Corrective Fixes
Plan only covers corporate email with no mention of OT, SCADA, ECDIS, or manual machinery overrides.
✔ Fix: Add OT Playbooks (PB-02) and Chief Engineer manual control procedures.Plan requires prior legal or executive approval before calling NRC, causing unlawful reporting delay.
✔ Fix: Pre-authorize CySO in writing to report to NRC without delay.Annexes: Forms Suite, Scripts, Quick-Card & Glossary
Annexes A through E: Operational recording forms, notification scripts, bridge card, and verification notes.
Annex A — Interactive Form Suite (Forms B-1 to B-8)
FORM B-1: CYBER INCIDENT INITIAL REPORT (Submit to CySO Immediately) Reporter Name / Rank: ________________________ Date/Time (UTC): ________________ Vessel / Facility Location: ___________________ System Affected: _______________ Description of Anomaly: _______________________________________________________ Is Safety, Navigation, or Cargo Stability Impaired? [ ] YES [ ] NO Initial Severity Assigned: [ ] SEV-1 [ ] SEV-2 [ ] SEV-3 [ ] SEV-4 CySO Acknowledgment Signature: __________________ Date: _______________________
Annex B — External Notification Scripts (Scripts 1 to 4)
SCRIPT 1: MANDATORY INITIAL USCG NRC NOTIFICATION CALL (1-800-424-8802) "This is [NAME], designated Cybersecurity Officer for [COMPANY]. I am reporting a cyber incident affecting [VESSEL NAME / OFFICIAL ID or FACILITY NAME / ID], located at [POSITION / ADDRESS] in the [COTP ZONE] Captain of the Port Zone. We have determined this to be a reportable cyber incident under 33 CFR § 101.650(g)(1). Discovered at [TIME UTC]. Determination made at [TIME UTC]. Summary of Incident: [NATURE OF INCIDENT]. Systems affected: [IT / OT / BOTH]. Critical systems affected: [YES/NO]. Operational status: [NORMAL / DEGRADED / LOST]. Safety status: [NO INJURIES / NO POLLUTION / VESSEL SAFE]. Actions taken: [ISOLATION / MANUAL CONTROL / OPERATIONS SUSPENDED]. My 24/7 callback number is [PHONE]. May I please have the official NRC Case Reference Number?"
Annex C — Bridge / Control Room Emergency Quick-Reference Card
- SAFETY FIRST: Vessel navigation and crew safety outrank cyber containment. Revert OT to local manual control.
- REPORT IMMEDIATELY: Call CySO 24/7 Hotline: [INSERT PHONE].
- DO NOT: Do not power off PLCs/HMIs, do not delete logs, do not insert USBs.
- ISOLATE NETWORK: Disconnect Ethernet cable from affected workstation or open IT/OT boundary firewall switch.
- NOTIFY NRC: CySO calls National Response Center at 1-800-424-8802 without delay.
Annex D & E — Glossary of Abbreviations & Source Verification
Glossary: AIS (Automatic Identification System), BCP (Business Continuity Plan), CDC (Certain Dangerous Cargo), CIRP (Cyber Incident Response Plan), CIRT (Cyber Incident Response Team), CISA (Cybersecurity & Infrastructure Security Agency), COTP (Captain of the Port), CySO (Cybersecurity Officer), ECDIS (Electronic Chart Display), HMI (Human-Machine Interface), KEV (Known Exploited Vulnerability), MTSA (Maritime Transportation Security Act), NRC (National Response Center), OT (Operational Technology), PLC (Programmable Logic Controller), SCADA (Supervisory Control and Data Acquisition), TSI (Transportation Security Incident), VTS (Vessel Traffic Service).
Verification Notes: Quoted regulations drawn from eCFR Title 33 Subchapter H Part 101 Subpart F (Final Rule 90 FR 6447, Jan. 17, 2025). Verify binding interpretations with cognizant Captain of the Port (COTP).