01 · Questionnaire

Questionnaire

Answer per control. Each answer feeds the evaluation and the traceability chain Actor → Vector → Component → Effect → Audit.

C-4.1 · L4
Medium

Telemetry to SOC

Does the platform stream signed telemetry to a SOC capable of OT analysis?

Evidence required:Data flow diagram, SOC runbook.
Why it matters ▾

Without telemetry there is no monitoring. The SOC must receive signed (tamper-evident) operational and security telemetry, and must be staffed and tooled for OT analysis — IT-only SOCs miss protocol-level and physical-process anomalies entirely.

C-4.2 · L4
Medium

Cyber Threat Intelligence feed

Is maritime-specific CTI integrated into detection rules and review cadence?

Evidence required:CTI provider contract, rule update log.
Why it matters ▾

Generic IT threat intelligence misses maritime-specific actors, malware families and TTPs. Maritime-focused CTI fed into detection rules at a defined cadence keeps detections relevant against the actual threat environment.

C-4.3 · L4
High

Cyber incident as mission event

Are cyber compromise events declared and handled as mission-assurance events?

Evidence required:Incident playbook, exercise after-action report.
Why it matters ▾

A cyber compromise is not only an IT incident; it is a mission-assurance event that can affect whether the platform can complete its task safely. The incident playbook must include mission-side decisions (continue / abort / hand back) alongside technical containment.

C-4.4 · L4
High

OT-aware detection rules

Do detection rules cover OT-specific anomalies (protocol misuse, set-point drift, unexpected mode change)?

Evidence required:Rule catalogue, tuning log, false-positive rate.
Why it matters ▾

OT anomalies look different from IT anomalies — a valid-looking command at the wrong time, a slow set-point drift, an unexpected mode change. Detection rules must encode operator and process knowledge, not just signature matching.

C-4.5 · L4
Medium

Operator alerting and response workflow

Is there a documented operator alerting workflow with defined escalation, acknowledgement and mission-abort criteria?

Evidence required:Workflow diagram, exercise log, abort criteria.
Why it matters ▾

An alert with no defined escalation path or abort criteria is noise. Operators need a clear workflow: who acknowledges, who escalates, at what threshold the mission is aborted, and how that decision is recorded.

C-4.6 · L4
Medium

Detection coverage exercise cadence

Are purple-team / detection-coverage exercises run at least annually against maritime scenarios?

Evidence required:Exercise schedule, after-action reports.
Why it matters ▾

Detections that have never been tested against a realistic attacker are assumptions. Annual purple-team or detection-coverage exercises against maritime scenarios are the only way to know whether the SOC actually sees what it claims to see.