IT Audit based on the CMMM |
|
OT Audit (Operationnal Technology) |
|
Audit report with findings discribing the levels of current IT and OT cyber security |
|
Recommendations for cybersecurity development |
|
The theoretical frameworks
Cyber security is a mature and standardized field with many ready-to-use frameworks.
The ISM code requires to implement a cybersecurity approach. From ISO standards to NIST and GPRD, including their specific variations to the maritime industry produced by DNV or BV, the cybersecurity frameworks are our basic working tools. With these frameworks we help you to situate yourself objectively on your practices compare to official references.
The audit methods
Audit methods allows to gather and organize the collected information.
These methods are referencing the theoretical frameworks and provides ready-to-use tools. Many are availlable, each ones with their pros and cons, from the french MEHARI method made by Clusif to EBIOS made by ANSSI or the american Cybersecurity Maturity Model Certification(CMMC). They mainly vary on the way to plan and execute the audit steps. The CMMC offers the advantage of providing finer granularity on intermediate levels of cyber security.
Our solution, the CMMM.
An audit method based on the CMMC and adapted to the needs of maritime IT.
We made an adaptation of the CMMC to the maritime sector constraints in a version we call CMMM : Cybersecurity Maturity Model Maritime. This method allows you to situate yourself and correctly prioritize corrective actions - because cybersecurity must be seen as an evolution and not as a revolution.