The Importance of Type Approval — Part Ⅰ: From Identify to Protect

How UR E27 Type Approval Reduces Commissioning-Phase Demonstration for Shipyards and System Suppliers under IACS UR E26

Sheep
Sheep
Senior Maritime Engineering Lead · Concept & Basic Design
Technical Advisor: shippauljobs.com — Crew Behind ShipJobs

Shipyards require a significant number of man-hours depending on commissioning times and days, which directly leads to increased ship building costs. Accordingly, reducing the time required for ship cybersecurity testing is an essential factor. Therefore, it is expected that shipyards will prefer suppliers holding UR E27-related type approval.

The following summarizes the definitions of the Identify and Protect sections of UR E26, together with the corresponding demonstration (test) requirements — especially at the Commissioning phase. Where a supplier holds UR E27 Type Approval, certain Commissioning-phase demonstration items may be exempted or reduced; these are marked with a teal ✅ E27 Type Approval card below. Where a test may be omitted entirely if already performed during CBS certification, this is marked with an orange ⚠️ note. I hope this serves as a helpful reference.


Ⅰ. Identify

NIST CSF

Develop an organizational understanding to manage cybersecurity risk to onboard systems, people, assets, data, and capabilities.

Requirement — Vessel Asset Inventory

  • An inventory of hardware and software of CBSs.
  • The inventory is essential for management of cyber resilience of the ship.
  • The inventory shall be kept updated during the entire life of the ship.
  • The vessel inventory shall include at least the information in UR E27 Sec. 3.1.1.
Demonstration

Design Phase: The vessel asset inventory that incorporates the inventories of all CBSs shall be submitted to the Society.

Construction Phase: The vessel asset inventory shall be kept updated.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Vessel asset inventory is updated and completed at delivery.
  2. CBSs are correctly represented by the vessel asset inventory.
  3. Software of the CBS has been kept updated.

Ⅱ. Protect

NIST CSF

Develop and implement appropriate safeguards to protect the ship against cyber incidents and maximize continuity of shipping operations.

P1 Security Zones and Network Segmentation

  • All CBSs shall be grouped into security zones with well-defined security policies and capabilities.
  • The benefit of security zones and network segmentation is to reduce the attack surface.
  • The security zone inventory shall be kept updated during the entire life of the ship.
  • A security zone shall be logically or physically segmented from other zones.
  • Safety systems shall be grouped into separate security zones with physical segmentation.
  • Nav. and communication systems shall not be in the same security zone as machinery or cargo systems.
  • Wireless devices shall be in dedicated security zones.
  • Networks considered untrusted shall be physically segmented from security zones.
Demonstration

Design Phase: Zone and conduit diagram and Cyber Security Design Description (CSDD) to be submitted to the Society, including:

  • Zone and conduit diagram illustrating how CBSs are grouped into security zones — indication of security zone, each CBS with physical location, and network communications.
  • CSDD including a short description of the CBSs, network communication in the same/different/untrusted networks with purpose and characteristics, and zone boundary devices with firewall rules.

Construction Phase: The zone and conduit diagram shall be kept updated.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. The security zones on board are implemented in accordance with the approved documents — verified by physical inspection or network scanning.
  2. Security zone boundaries allow only traffic documented in the approved document — verified by evaluation of firewall rules or port scanning.

P2 Network Protection Safeguards

  • Security zones shall be protected by firewalls or equivalent means.
  • The network shall be protected against events that impair the quality of service of network resources.
  • The CBS shall be configured to provide only essential capabilities and restrict the use of non-essential functions.
  • The network shall include means that minimize the risk of denial of service (DoS) and network storms.
Demonstration

Design & Construction Phase: Nothing required.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Test DoS attacks targeting the zone boundary device.
  2. Test DoS originating from inside each network segment.
  3. Test that unnecessary functions, ports, protocols, and services are removed or prohibited.
⚠️ The 2nd and 3rd tests may be omitted if performed during the certification of CBSs.

P3 Antivirus, Antimalware, Antispam & Other Protections from Malicious Code

  • CBS shall be protected against malicious code.
  • Any unwanted program that performs unwanted and malicious actions is considered malware.
  • Malware protection shall be implemented on CBSs.
  • When protection software cannot be installed, malware protection shall be implemented via operational procedures and physical safeguards, in accordance with suppliers' recommendations.
Demonstration

Design Phase: The CSDD shall include:

  • Summary of approved protection mechanisms of each CBS.
  • How to keep the anti-malware software updated.
  • Any operational conditions or necessary physical safeguards to be implemented in the shipowner's management system.

Construction Phase: The malware protection is kept updated.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Approved anti-malware software or other compensating countermeasures are effective.
⚠️ The test may be omitted if performed during the certification of CBSs.

P4 Access Control

  • CBSs shall provide physical and/or logical measures to selectively limit the ability and means to communicate with the system itself.
  • Physical and logical access controls to cyber assets, networks, etc. should be implemented.
  • Access to CBSs and networks shall only be allowed to authorized personnel.
  • Physical access control: CBSs of CAT 2 and 3 shall normally be located in locked spaces; however, access shall remain straightforward for crew and stakeholders who need it, so as not to hamper effective and efficient operation of the ship.
  • Physical access control for visitors: Visitors shall be restricted regarding access to CBSs, such as under supervision.
  • Physical access control of network access points: Access points to onboard networks connecting Cat 2 and Cat 3 CBSs shall be physically and/or logically blocked, except when connection occurs under supervision or according to documented procedures (e.g. for maintenance).
  • Removable media controls: A policy for the use of removable media devices shall be established with procedures.
  • Management of credentials: Accounts for onboard and onshore personnel shall be left active only for a limited period according to the role and responsibility of the account holder, and shall be removed when no longer needed.
  • Least privilege principle: Any human user allowed to access CBSs and networks shall have only the minimum privileges necessary to perform their function.
Demonstration

Design Phase: The CSDD shall include:

  • Location and physical access controls for the CBS.
  • Devices needing immediate access, such as HMI for operators, that need not enforce user identification and authentication if located in an area with physical access control, shall be specified.

Construction Phase: Unauthorized access to the CBSs shall be prevented during the construction phase.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Components of the CBSs are located in areas or enclosures where physical access can be controlled to authorized personnel.
  2. User accounts are configured according to the principles of segregation of duties and least privilege, and temporary accounts have been removed.
⚠️ The 2nd test may be omitted based on certification of CBSs.

P5 Wireless Communication

  • Cryptographic mechanisms such as encryption algorithms and key lengths in accordance with industry standards and best practices shall be applied to ensure integrity and confidentiality of information transmitted on the wireless network.
  • Devices on the wireless network shall only communicate on the wireless network (i.e. they shall not be "dual-homed").
  • Wireless networks shall be designed as separate segments in accordance with 4.2.1 and protected as per 4.2.2.
  • Wireless access points and other devices in the network shall be installed and configured such that access to the network can be controlled.
  • The network device or system utilizing wireless communication shall provide the capability to identify and authenticate all users (humans, software processes, or devices) engaged in that communication.
Demonstration

Design Phase: The CSDD shall include:

  • Description of wireless networks in scope and how they are implemented as separate security zones, including zone boundary devices and permitted traffic (e.g. firewall rules).
  • Summary of mechanisms to prevent unauthorized access and protect integrity/confidentiality of information on the wireless network, with references to the product supplier's documentation for each CBS (UR E27 Sec. 6.2.5).

Construction Phase: The shipyard shall prevent unauthorized access to the wireless networks during construction.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. The shipyard shall demonstrate, e.g. by use of a network protocol analyzer tool, that the wireless communication protocol corresponds with the approved documentation from the respective product supplier.

P6 Remote Access Control & Communication with Untrusted Networks

  • CBSs shall be protected against unauthorized access and other cyber threats from untrusted networks.
  • Onboard CBSs are increasingly digitalized and connected to the internet to perform a wide variety of legitimate functions, which makes them vulnerable to cyber incidents.
  • Not all cyber incidents are the result of a deliberate attack.
  • A user's manual shall be delivered for control of remote access to onboard IT and OT systems, with clear guidelines that identify roles, permissions, and functions.
  • IP addresses shall not be exposed to untrusted networks.
  • Communication with or via untrusted networks requires a secure connection.
  • The system shall have the capability to terminate a connection, and remote access shall not be possible until permitted by a responsible person on board.
  • The system shall be capable of managing interruptions during remote sessions.
  • A logging function shall be provided to record all remote access events for offline review of a cyber incident.
Demonstration

The product supplier shall demonstrate security capabilities supporting these requirements by following the process specified in UR E27 Sec. 6.

Design Phase: The CSDD shall include:

  • Identification of each CBS that can be remotely accessed or that otherwise communicates through the security zone boundary with untrusted networks.
  • A description of compliance with remote access control requirements for each CBS.

Construction Phase: Any communication with untrusted networks is only temporarily enabled and used in accordance with the requirements.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Secured in accordance with UR E27 Sec. 4.2, and communication protocols cannot be negotiated to a less secure version — demonstrated e.g. by use of a network protocol analyzer tool.
  2. Multifactor authentication of the remote user is required.
  3. A limit on unsuccessful login attempts is implemented, and a notification message is provided to the remote user before the session is established.
  4. Remote connection must be granted by responsible personnel on board.
  5. Remote sessions can be manually terminated by personnel on board, or the session will be terminated automatically after a period of inactivity.
  6. Remote sessions are logged.
Instructions or procedures are provided by the respective suppliers.

P7 Use of Mobile and Portable Devices

  • Use of mobile and portable devices shall be limited to only necessary activities and controlled in accordance with UR E27 Sec. 4.1 item 10. For any CBS that cannot fully meet these requirements, the interface ports shall be physically blocked.
  • CBSs can be impaired due to malware infection via a mobile or portable device.
  • Mobile equipment required for the operation and maintenance of the ship should be under the control of the shipowner.
  • Only authorized devices may be connected to the CBSs.
  • All use of such devices shall be in accordance with the shipowner's policy for use of mobile and portable devices, taking into account the risk of introducing malware into the CBS.
Demonstration

Design Phase: The CSDD shall identify any CBSs that do not meet the requirements in UR E27 Sec. 4.1 item 10 — i.e. that require protection of interface ports by physical means such as port blockers.

Construction Phase: Use of physical interface ports is controlled in accordance with UR E27 Sec. 4.1 item 10, and any use of such devices follows procedures to prevent malware from being introduced into the CBS.

Commissioning Phase: The ship cyber resilience test procedure shall be submitted for the following demonstration:

✅ E27 Type Approval — Commissioning Demonstration
  1. Use of mobile and portable devices is restricted to authorized users.
  2. Interface ports can only be used by specific device types.
  3. Files cannot be transferred to the system from such devices.
  4. Files on such devices will not be automatically executed (autorun disabled).
  5. Network access is limited to specific MAC or IP addresses.
  6. Unused interface ports are disabled.
  7. Unused interface ports are physically blocked.

This is Part Ⅰ of a multi-part series on IACS UR E26/E27 Type Approval, covering the Identify and Protect functions. Part Ⅱ will continue with Detect, Respond, and Recover.

About the Author

Sheep is a maritime engineering professional with deep expertise in conceptual and basic design across diverse vessel types. Sheep brings comprehensive knowledge of global mechanical, electrical & electronics, and cybersecurity system specifications — combined with proven design and project management capability for large-scale maritime and offshore platform construction, and a track record of steering complex programmes with market stability. Technical domains include naval architecture & concept design, mechanical systems engineering, electrical & electronics systems, cybersecurity system spec analysis, offshore & large platform construction, maritime project management, and global system integration.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

  1. Excellent article. Many people think Type Approval is simply about obtaining a certificate, but in reality it is the starting point for ensuring consistent quality, safety, and cybersecurity throughout the vessel lifecycle.

    As ship systems become increasingly software-defined and interconnected, Type Approval should evolve beyond hardware compliance to include secure-by-design principles, software integrity, and cyber resilience.

    I look forward to Part II and the discussion on how this evolution will shape the future of maritime compliance. Great work!

    ReplyDelete
  2. Thank you for an excellent article.

    Many professionals tend to view Type Approval primarily as a certification or compliance requirement. What I particularly appreciated in this article is the engineering perspective—that Type Approval can significantly improve commissioning efficiency and reduce project risk, rather than simply serving as a regulatory obligation.

    In my opinion, the greatest value of UR E27 Type Approval lies not merely in reducing repeated testing, but in enabling verified Engineering Evidence to be reused across multiple projects.

    Ultimately, Type Approval is more than a mechanism for minimizing testing activities. It provides a structured foundation for preserving, reusing, and continuously improving design rationale, verification results, and accumulated engineering knowledge.

    As this Engineering Evidence becomes more closely connected with the system-level engineering approach required by IACS UR E26, I believe both shipyards and equipment suppliers will be able to deliver projects more efficiently, consistently, and predictably.

    Thank you again for sharing these valuable insights.

    ReplyDelete

Post a Comment

Top Ranked · All Posts

Popular Posts