b'PVA WORKING FOR YOU:COAST GUARD toMEMBERSHIPFOCUS on CYBER RISKat Your Next Security InspectionJEN WILK // PVA DIRECTOR, PUBLIC AFFAIRS & DEVELOPMENTS tartingnextmonth,January2021,youHERE ARE THE FOLLOWING QUESTIONS shouldanticipatepersonnelfromtheU.S. CoastGuardaskingquestionsatyournextMARINE INSPECTORS WILL BE ASKING securityinspectionabouthowyouaremanagingAT YOUR NEXT VESSEL SECURITY INSPECTION:cybersecurity risk.PVA is working for you by keeping youinformedandprepared.Toassistyouasyou prepare for a security inspection, heres some helpfulDoes your Vessel Security Plan (VSP) address measures insight into what the Coast Guard will be looking fortaken to address cybersecurity vulnerabilities?and the tools you need to be ready.VESSEL INSPECTION IF YES:IF NO:Recently, the Coast Guards Office of CommercialAre these measures in place? Have you communicated VesselComplianceissuedguidancetovesselthat issue to your Company operatorsoncybersecurityentitledVesselCyberSecurity Officer (CSO)?RiskManagementWorkInstruction(CVCWork Order: CVC-WI-027(1)).This guidance document applies to vessels that are required to have a Vessel Security Plan in compliance with the regulations ofHas the vessel experienced any cybersecurity events the Maritime Transportation Security Act (MTSA),withing the past 12 months?typically those that carry more than 150 passengers. Thoseoperationswhichsatisfythisrequirement by utilizing the PVA Alternative Security ProgramIF YES: IF NO:are subject to this policy as well.Additionally, thisHave you reported theseNo further action/question directionalsoappliestoanyvesselusingaSafetycybersecurity incidents torequired.ManagementSystem(SMS),includingthoseyour CSO? companies using PVAs Flagship SMS program.Itisimportanttorememberthatthese questions will only be asked regarding areas ofoperationaltechnologyofavessel,not RELAX. THIS JOURNEYSofbusinesstechnologysuchaspayment processing or accounting systems.POWERED BY CATERPILLAR. Tomoreclearlyunderstandacyberthreat, PVAs working definition of a Cybersecurity When your cargo can talk, the stakes are high. WhenBreach istheunauthorizedaccesstodata, you choose Caterpillar, you dont have to worry aboutapplications,services,networksand/or meeting your passengers high expectations for reliable, safe, clean operation. Our engines set thedevices,by-passingtheirunderlyingsecurity standard, so everyone can sit back and enjoy the ride. mechanisms. A cybersecurity breach may rise tothelevelofareportableMTSAsecurity breach(calledaTransportationSecurity Learn more about our Ferry and Cruise solutions Incident)whichoccurswhenanindividual, anentity,oranapplicationillegitimately entersaprivateorconfidentialInformation TechnologyperimeterofaMTSA-regulated facilityorvessel. (AsdefinedintheCoast For more information, visit www.cat.com/marine GuardapprovedPVAAlternateSecurity2020 Caterpillar. All Rights Reserved. CAT, CATERPILLAR, LETS DO THE WORK, their respective logos, Caterpillar Yellow, the Power Edge and CatProgram)Modern Hex trade dress as well as corporate and product identity used herein, are trademarks of Caterpillar and may not be used without permission.PVA WORKING FOR YOU 34 FOGHORN'