Framework overlap

Does GDPR cover IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)?

You hold GDPR and have been told to do IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2). Here is how much overlaps, control by control.

63% of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) you already have

GDPR already covers about 63% of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), leaving 3 of 8 controls as genuinely new work.

Already covered 1 Likely covered 4 New work 3

What is genuinely new work

Nothing in GDPR reaches these. This is the list to scope.

IMO-MSC-FAL-FrameworkAlignment-NISTCSF-Identify-Protect-Detect-Respond-Recover-IndustryGuidelinesV4-IEC62443
IMO MSC-FAL Framework Alignment - 5 Functional Elements Map to NIST CSF + Industry Guidelines on Cyber Security Onboard Ships v4 + IEC 62443 + ISO 27001 + USCG NVIC + EU NIS2 + Cla
IMO-MSC-FAL-Govern-ThirdParty-SupplyChain-Manufacturer-Yard-PortFacility-IACS-E26-E27
IMO MSC-FAL Govern - Third Party Cyber Risk + Supply Chain + Equipment Manufacturer + Yard + Port Facility + IACS UR E26/E27 + Continuous Improvement + Audit
IMO-MSC-FAL-Scope-MSC-FAL1Circ3Rev2-MSC42898-2017-1Jan2021-ISMCode-SMS
IMO Maritime Cyber Risk Management Scope - MSC-FAL.1/Circ.3 + Rev.2 + Resolution MSC.428(98) + ISM Code Safety Management System Integration + 1 January 2021 Effective + Senior Man
Show the 5 you already have
IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities
IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA
IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms
IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation
IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity
IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media
IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills
IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience
IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC
IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT

How this is calculated

Already covered means a mapping runs from a control in GDPR to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition