SAFETY MATTERS:PVA Cyber Risk SAFETYAssessment Tools ERIC CHRISTENSEN PVA DIRECTOR OF REGULATORY AFFAIRS & RISK MANAGEMENTC ybersecuritycontinuestobeanTheU.S.CoastGuard,asyouwillreadeff orts by developing cyber guidelines and a cyber emergingtopicwithinthemaritimeelsewhereinthisissueofFOGHORN,hasassessmentformaspartoftheCoastGuard-industry.TherearenumeroussteppedupnotonlytherequirementsforapprovedAlternateSecurityProgram(ASP). workshopsandseminarsavailablethatWhile optional documents in the 2017 approved provideinsightintothelatestthreatsandPVAASP,theCyberRiskManagementBest countermeasures. As we have seen in the lastPVA has beenPracticesGuidelinesandaCyberAssessment year,domesticpassengervesseloperationsWorksheet can be used to meet the Coast Guard arenotimmunetoaransomwareorotherdeveloping cyberrequirementsdiscussedbelow.Thecyber cyber attack. Remote work has opened otherguidelines and aassessment tools can be found under security tools avenues of attack by hackers or other threatin the member download area of the PVA website. actors. While most of the cyber attacks havecyber assessmentSinceeveryvesseloperationisdiff erent,the focused on ransomware and gaining access toform as part ofevaluationofvulnerabilitiessubjecttocyber customer fi nancial information, there are alsothreats and the development of countermeasures risks to navigational and security equipment. the Coast Guard- willbebasedonhowacompanyusesand appliestechnology.Operatorsshouldinventory PVAsworkingdefi nitionofacybersecurityapproved Alternateallthecyber-dependentsystems,including breachistheunauthorizedaccesstodata,Security Program. bothhardwareandsoftware,whichsupport applications,services,networksand/orcriticalsafetyandsecuritysystems.Financial devices,bypassingtheirunderlyingsecuritysystems are not required to be assessed for Coast mechanisms. A cybersecurity breach may rise toGuard requirements.the level of a reportable transportation securitycyber assessments of facilities and vessels, but incident,whichoccurswhenanindividual,also outreach to support the maritime industryTheprocessofevaluatingcyberriskissimilar entity,orapplicationillegitimatelyentersaas part of their overall cyber strategy. toreviewingthepotentialimpactofanyother private or confi dential information technologysecurityvulnerabilityatyouroperation.PVAs perimeter of a Marine Transportation SecurityPVA TOOLS industrybestpracticessuggestfollowing Act (MTSA)-regulated facility or vesselPVA has been responsive to the Coast Guardsthese steps:Assessment Inventory systems, reviewtheir interdependence. Identifi cation Evaluate risk levels, detect vulnerabilities.MitigationDevelop countermeasures and implement in company security policies.The PVA ASP is up for re-approval in the summerof2022.Weanticipateupdatingthecyber assessmentguidancetomeetallCoastGuard mandates.FACILITY SECURITYIn2020,theCoastGuardreleasedguidance oncybersecurityatfacilitiesintheformofa Navigation and Vessel Inspection Circular (NVIC) titled Guidelines For Addressing Cyber Risks at MaritimeTransportationSecurityAct(MTSA) RegulatedFacilities(NVIC01-20).TheNVIC SAFETY MATTERS 32 FOGHORN