> ## Content Index
> Fetch the complete content index at: https://julius-shin.ghost.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# [System Study_004] Crude Oil Washing: The System That Rules Built
- URL: https://julius-shin.ghost.io/crude-oil-washing-cow-system/
- Published: 2026-09-09T12:54:50.000Z
- Updated: 2026-09-10T17:38:39.000Z
- Description: An engineering and cyber analysis of the crude oil washing system — five BOM rows, four typologies, and a safety case owned by a neighbouring system.
- Author: Julius Shin
- Tags: Engineering Intelligence, Cargo Systems, Tankers, MARPOL, IACS UR E26, OT Security, SYS-012

Crude oil washing is one of the few shipboard systems whose existence is written directly into an international convention. MARPOL Annex I Regulation 33 requires it on every crude oil tanker of 20,000 tonnes deadweight and above delivered after 1 June 1982, and IMO Res. A.446(XI) specifies clause by clause how it must be designed, operated and verified. Read those rules in the order they were actually made, however, and something unusual appears: **the system was permitted only because a different system had already made it safe.**

In the bill of materials COW is five rows — two valves, one machine, one pressure instrument, one control panel. Three of those rows hold no firmware, no network port and no accounts, and those same three rows perform the entirety of the physical action inside the tank. The one row that holds all of the software never touches crude oil. Counting components and counting risk are two different jobs here.

Key point

COW does not own its own safety case. The inert atmosphere that makes it permissible to spray crude oil at high pressure inside a cargo tank is produced, measured and alarmed by the inert gas system, and COW’s obligation under A.446 §6.6 is only to confirm the value and stop if it is out of limits. **You can collapse this system’s safety case without touching a single COW component.**

> Connectivity is not authority — and in this system the most violent physical action of all carries none.

What follows is a typology-based analysis of SYS-012 in four parts: what the system is for and how it works, what it is made of, what authority and physical effect each of its connections carries, and what security follows from that. Statements are tagged with the evidence grade of the typology doctrine they rest on, and nothing is asserted above that ceiling.

Part I — Engineering

## 1\. Why This System Exists

Crude oil does not leave a cargo tank clean. Long after the pumps have started drawing air, a sticky layer of wax and asphaltene remains on the tank walls, the girders, the stringers and the bottom plating. Class and P&I material puts the quantity of this clingage at around 1,000 tonnes for a VLCC, though it varies widely with tank structure and crude properties, so the figure is better read as an order of magnitude than as a number. Typical (UK P&I Club, *Carefully to Carry* — bulk oil cargo shortage claims.) The problems it creates are not one but three.

The first is **commercial**. What the owner and charterer contracted for is the delivery at the discharge port of what was loaded at the load port, and oil stuck to the tank is cargo that was not delivered. The physical origin of ship–shore difference and of ROB (remaining on board) disputes sits here.

The second is **operational**. Crude carriers ballast into some of their cargo tanks. Put seawater into a tank that still holds residue and that seawater becomes oily ballast, which has to go somewhere before the next load port.

The third is **environmental**, and it is where regulation enters. The traditional way of handling oily ballast was Load-on-Top: water-wash, collect in the slop tank, let it settle, decant the water from above. That reduces the total discharged. It does not eliminate the discharge.

Crude cargo discharged
        |
        v
   Clingage remains on tank steel
        |
        +--> Cargo not delivered  -> ship-shore difference / ROB dispute
        |
        +--> Ballast into dirty tank -> oily ballast -> operational discharge to sea
        |
        +--> Sludge accumulation -> tank entry, manual removal, occupational risk

That is the engineering problem. But the route by which COW — the **solution** — became standard equipment on merchant ships follows the order of accidents and rules, not the order of engineering. Reverse that order and you will misread the system's entire safety case.

Between 12 and 30 December 1969, three VLCCs of about 210,000 DWT — **Marpessa**, **Mactra** and **Kong Haakon VII** — were severely damaged by cargo tank explosions. Marpessa sank on the ballast leg of her maiden voyage and two crew members died; the other two survived with much of their main decks blown away. Verified **All three were cleaning empty cargo tanks at the time.** The intensive research the owners launched concluded that the high-pressure water jets then in standard use were building up electrostatic charge inside the large cargo tanks as they struck the steel, and that in a space full of hydrocarbon vapour this discharged as a spark. Verified The response was to fill the cargo tanks with inert gas during cleaning, and that became today's mandatory inert gas system (IGS).

Then in February 1978 the **TSPP Conference** (International Conference on Tanker Safety and Pollution Prevention) convened by IMO adopted the **1978 Protocol**, which amended MARPOL 73 and brought COW inside the rules. Verified New crude tankers above 20,000 DWT were required to fit COW; existing tankers above 40,000 DWT had to choose between segregated ballast tanks (SBT) and COW, with clean ballast tanks permitted during the transition. The clause number at adoption was Annex I **Reg. 13(6)**; after the 2004 wholesale revision of Annex I, the operative provision is **MARPOL Annex I Regulation 33.1** — every crude oil tanker of 20,000 tonnes deadweight and above delivered after 1 June 1982 shall be fitted with a cargo tank cleaning system using crude oil washing. Verified

1969  Water washing in a gas-filled tank -> static discharge -> 3 VLCC explosions
        |
        v
1970s Inert gas system mandated  (O2 kept low inside cargo tanks)
        |
        v      [precondition now exists]
1978  TSPP Protocol -> COW required as cargo-tank cleaning method
        |
        v
1979  Res. A.446(XI) -> design, operation and control specification
        |
        v
1982+ MARPOL Annex I Reg. 33 / Reg. 35 -> installation + operation obligations

The order matters. **COW could only become a rule after the inert atmosphere had already been secured as a precondition.** Spraying crude oil at high pressure is not electrostatically more benign than spraying water. The only reason it is permitted is that the inside of the tank is not a combustible atmosphere — and that fact is produced not by COW but by IGS. We return to it in section 14, but **the COW system does not own its own safety case**, and that structure is the single most important fact in analysing it.

## 2\. What the System Does

The function of COW is defined in one sentence: **spray the crude oil currently being discharged, at high pressure, onto the internal surfaces of the cargo tank, so that clingage dissolves and leaves with the cargo stream.**

Every peculiarity of this system is contained in that definition. There is no dedicated washing medium. There is no dedicated storage. In principle there is not even a dedicated pump — the discharge of the cargo pumps is branched off. Much of the piping is shared with the cargo system. IMO Res. A.446(XI) §4.1.2 requires the COW system to be a permanent installation, independent of the fire main, while explicitly allowing parts of the cargo system to be incorporated provided the requirements are met. Verified

![Operational context diagram of the crude oil washing system: a deck-mounted COW machine sprays the inside of a cargo tank; dissolved clingage falls to the tank bottom and is stripped back into the cargo pump, whose discharge goes to shore and is also branched upward as the COW main; an inert gas system outside the COW boundary supplies the O2 not greater than 8 vol% precondition; side panels list which functions COW owns versus those owned by other systems, and the three non-instrumented verifications required by A.446 clauses 4.2.12, 4.4.4 and 4.2.10.](https://github.com/MaritimeCyber/General/blob/main/Asset/img/ei/crude-oil-washing-cow-system/context-v2.jpg?raw=true) 

Figure 1\. COW has no operating window of its own. The medium is the cargo, drawn from the cargo pump discharge, and the inert atmosphere that makes the operation permissible is produced by IGS — another system. Three of the verifications required by IMO Res. A.446(XI) sit outside the instrumentation path altogether.

The system-level functional decomposition looks like this.

| Function                   | Content                                                                            | Owner                                        |
| -------------------------- | ---------------------------------------------------------------------------------- | -------------------------------------------- |
| F1 Supply the medium       | Branch cargo pump discharge into the COW main, hold the specified driving pressure | Cargo pumps (**external**) + COW line valves |
| F2 Distribute              | Route the medium per tank or tank group, isolate the rest                          | COW supply isolation valves                  |
| F3 Apply                   | Fixed machines strike the walls on a defined pattern (vertical arc + rotation)     | COW machines                                 |
| F4 Recover                 | Strip the dissolved oil off the tank bottom back into the cargo stream             | Stripping system (**external**)              |
| F5 Monitor                 | Indicate driving pressure, machine operation, stripping rate, level                | Pressure instrumentation + control panel     |
| F6 Sequence                | Advance the programme according to the approved manual                             | COW control panel + **person**               |
| F7 Verify the precondition | Confirm tank oxygen and pressure are within limits, stop if not                    | **Person** (information from IGS)            |

Note that F1 and F4 belong to **external systems**, and that the information source for F7 is also external. What COW actually owns is F2, F3, F5 and F6 — which is why only five component rows in the bill of materials are attributed to it.

## 3\. Core Functions and Operating Modes

COW has no operating window of its own. It is performed **inside the discharge operation itself**, while the cargo is flowing out. That fact defines its modes.

**Top wash.** While the level in the tank is still high, the machine arc is restricted to the upper sector, cleaning the structure and shell exposed above the liquid surface. There is no point spraying below the surface, so the arc programme follows the level down.

**Bottom wash.** Once the level is low enough, the arc extends downward to cover the bottom and lower structure. This is the phase in which the stripping load is heaviest.

**Single-stage / multi-stage.** Depending on what the approved manual specifies, the full arc is swept in one pass or the work is divided into several stages that track the falling level. Either way, **the mode is not a free parameter but an item in an approved procedure**. MARPOL Annex I Reg. 35.3 requires the COW system to be operated in accordance with the Operations and Equipment Manual, except where the cargo is unsuitable. Verified

**Ballast-voyage preparation.** Reg. 35.2 requires a sufficient number of cargo tanks to be crude oil washed before each ballast voyage so that **ballast water is put only into tanks that have been washed**. Verified In other words, which tanks get washed is decided not by the convenience of the washing operation but by **the ballast plan for the next voyage**. The COW programme is logically coupled to cargo and ballast planning — and that coupling is the path by which the propagation chain in section 13 reaches a regulatory outcome.

**Verification modes.** A.446(XI) requires separate acts that confirm the result and the functioning of the equipment. §4.2.10 requires visual confirmation, after COW and before water washing, that the tank is essentially free of clingage and deposits, and sets the oil content of the departure ballast at not more than 0.00085 by volume as the criterion of stripping effectiveness. §4.2.12 requires deck-mounted machines to have a means of indicating rotation and arc movement **from outside the tank**. §4.2.13 accepts, for submerged machines, external indication, characteristic operating sound, or periodic verification at intervals of not more than six uses or twelve months. §4.4.4 requires hand dipping facilities at the aftermost point of the tank and at three other locations. Verified

Every one of those verification items is **something a human being does with their eyes, ears and hands**. The clauses were drafted two decades before the concept of cyber security existed, and yet the result is that this system carries **out-of-band integrity verification mandated by rule**, independent of any instrumentation signal. Section 12 returns to that property.

## 4\. How the System Works

The washing result — how clean the tank actually got — is not the output of any single piece of equipment. It is a product of several physical quantities.

Wash effectiveness
   = f( driving pressure          [pump discharge, throttled at COW line]
       x nozzle throughput        [machine size, nozzle bore]
       x arc programme            [vertical sector + rotation, per stage]
       x machines run simultaneously  [hydraulic balance limit]
       x tank geometry            [shadow from girders, stringers, bulkheads]
       x stripping rate           [must exceed wash throughput]
       x crude properties         [wax / asphaltene content, temperature]
     )
   subject to  O2 <= 8 vol%  and  positive tank pressure     [external precondition]

A.446(XI) puts a quantitative constraint on each term of that product. §4.2.8 requires that the area shadowed from direct impingement not exceed 10% on horizontal surfaces and 15% on vertical ones — meaning the arrangement, number and arc of the machines has to be verified together with the internal geometry of the tank. §4.4.3 requires the stripping arrangement to remove oil at 1.25 times the total throughput of the machines running simultaneously — a physical inequality stating that oil must be taken off the bottom faster than washing puts it there. §4.3.3 requires the system to remain operable **with one pump out of service**; §4.1.3 requires pressure relief to discharge to the pump suction side; §4.1.9 requires the piping to be tested at 1.5 times working pressure after installation. Verified

ENGINEERING NOTE — the thing to protect is not one executable.

Of the variables that determine COW performance, the ones that live in software are the arc programme, the step sequence, and the range settings of the pressure instrumentation. Driving pressure is set by the pump and valve opening; nozzle throughput by machined dimensions; shadow by the structural drawing of the tank; stripping capability by pump specification. Imagining compromise of this system purely as "changing the control programme" misses half of it. The cheaper route is not to change the physical quantity but **to change what people believe the physical quantity to be**. Change the range of one pressure instrument and the wash fails without a single valve moving incorrectly — and the failure stays hidden until somebody enters the tank and looks. That is scenario 1 in section 16.

The physical chain resolves as follows.

Cargo pump discharge -> COW main line -> COW supply isolation valve (per tank group)
        -> COW line valve -> Fixed tank washing machine (deck-mounted or submerged)
        -> High-pressure crude jet -> Tank steel surface -> Clingage dissolved
        -> Falls to tank bottom -> Stripping suction -> Back into cargo discharge line -> Ashore

   [monitoring]  COW line pressure transmitter -> COW control panel -> CCR mimic
   [verification] External rotation/arc indicator (A.446 4.2.12) -> Operator eye
   [precondition] IGS -> O2 <= 8 vol% + positive pressure (A.446 6.6) -> Operator decision

Part II — Composition

## 5\. What the System Is Made Of

Viewed as a component list, COW is five rows. But listing five rows is not analysis. Which **typology** each row belongs to is what determines its authority, its physical effect and its attack surface — and each typology already carries confirmed doctrine.

**\[Table 1\] Typology Composition**

| Typology | Equipment kind                         | Components                                       | Purdue                | CBS (UR E26)          | Evidence |
| -------- | -------------------------------------- | ------------------------------------------------ | --------------------- | --------------------- | -------- |
| TYP-A04  | Shutoff / isolation valve              | 2 — COW supply isolation valves, COW line valves | L0 — physical process | N                     | Typical  |
| TYP-A05  | Mechanical machine / tool              | 1 — COW machines                                 | L0 — physical process | N                     | Typical  |
| TYP-B02  | Process transmitter / sensor (Cargo)   | 1 — COW pressure monitoring instruments          | L1 — sensing          | Y — within parent CBS | Inferred |
| TYP-B08  | HMI / operator console / panel (Cargo) | 1 — COW control panel                            | L2 — supervisory      | Y — list separately   | Typical  |

**TYP-A04 — COW supply isolation valves and COW line valves.** The physical switch that decides which tank group receives washing medium. Neither the valve body nor its on/off actuator holds logic, a setpoint or a state machine. Pilot hydraulic pressure arrives and it opens; the pressure is cut and it closes.

**TYP-A05 — COW machines.** The equipment that actually does the work. Permanently mounted rotating nozzles, driven either by the energy of the crude flow itself or by a separate drive, tracing a pattern that combines a vertical arc with rotation. A.446 §4.2.1 requires the machines to be permanently mounted and of a type accepted by the Administration. Verified

**TYP-B02 — COW line pressure instrumentation.** The only measurement point that reports whether the driving pressure is within its specified band. This single row is the carrier of the "belief about a physical quantity" described in section 4.

**TYP-B08 — COW control panel.** Commands the programme steps and displays progress. All of this system's software lives here.

**What is not a row.** Cargo pumps, stripping pumps and eductors, IGS, tank level gauging, and the internal tank structure that genuinely governs the washing result are not booked as COW items. COW is a textbook case of a system whose **functional boundary and procurement boundary do not coincide**, and section 7 deals with that mismatch.

## 6\. Typology Profiles

Five attributes have to be unpacked per typology before analysis can start.

**TYP-A04 (valve).** Programmable: N. Network interface: none (hardwired to the parent CBS). Purdue: L0\. Consequence of loss: mostly Operational. Supply boundary: within the parent package. The majority finding for this family is unambiguous — **the intelligence sits in the solenoid valve cabinet and the control console; what the field valve offers is one solenoid coil and one position feedback contact.** In the family BOM profile 41 of 49 entries are L0 and only 8 are programmable, and most of those 8 are solenoid cabinets and consoles rather than valves. Typical

**TYP-A05 (machine).** Programmable: N (33 of 41). Network interface: N (33). Purdue: L0 (33). The doctrine here is simpler still — driven machines such as workshop machines, mixers and agitators are electromechanical; they neither generate nor relay information and issue no command to any other equipment. The exception is the 8 programmable entries absorbed into a parent PLC sequence, and **the programmable washing pattern of a COW machine is named in the register as an example of exactly those 8.** Typical COW machines may therefore belong to the **exceptional subset rather than the base case** of this typology — which feeds directly into the architecture judgement in section 8.

**TYP-B02 (instrumentation).** Programmable: model-dependent. Network interface: 34 of 42 are "Likely" — that is, **unconfirmed**. Purdue: L1 throughout. CBS: 31 of 42 within a parent CBS. Supply boundary: 38 within the parent package. This typology's register is not yet populated, and the present doctrine is inherited from sibling typologies and overwritten with cargo context. Hence the evidence tag is Inferred, **and nothing in this article that rests on this row exceeds that ceiling.**

**TYP-B08 (panel).** Programmable: **all 17** entries. Network interface: all 17\. Purdue: L2 throughout. CBS: all 17 listed separately. Supply boundary: 15 within the parent package, 2 with **their own control cubicle**. This family sits closest to the cargo control loop while holding executable code and sequence logic that can be replaced.

KEY DISTINCTION — component count is not a measure of cyber relevance.

Of COW's five rows, **three (two valves plus one machine) are non-programmable Purdue L0 equipment** with no firmware, no network port and no accounts. Those three rows have no logical attack surface at all. As long as the UR E26 §2 definition of a Computer Based System reads "a programmable electronic device, or interoperable set of programmable electronic devices", the valve body and the machine body do not fall inside it. Verified And yet those three rows perform **the entirety of the physical action inside the tank**. Conversely, the one row that holds all the software never touches crude oil. In this system, counting components and counting risk are two different jobs.

The asymmetry is unusually sharp in COW. Two of the five rows are CBS candidates (one instrument, one panel), and only **one row** is to be listed separately. When an inventory author decides whether to strike "the COW system" from the CBS list, the thing actually being judged is not COW as a whole but that one row and the upstream cabinet that governs it.

## 7\. Where the Supply Boundary Falls

COW's typical supply is a **maker package**. The yard does not assemble it from parts; a vendor delivers it as a package and the yard connects the interfaces.

Administrative ownership, privilege and update path all change at once at that line. It is a trust boundary that exists regardless of where a firewall sits.

+---------------------------- YARD / OWNER SCOPE ----------------------------+
|  Cargo pumps    Stripping system    Tank structure    IGS    Cargo piping   |
+-------------------------------+--------------------------------------------+
                                |  hydraulic + electrical interface
+-------------------------------v----- MAKER PACKAGE (COW) ------------------+
|  COW machines   COW line valves   Pressure instrument   COW control panel   |
|                                                                            |
|  ?? control cubicle: own enclosure, or absorbed into cargo control package? |
+----------------------------------------------------------------------------+
                                |
                                v  vendor service laptop / removable media
                        [ inbound A3 / A6 / A7 ]

**A common trap.** Of the 17 entries in the TYP-B08 family, 15 have a supply boundary of "within parent package" and only 2 have their own control cubicle. If COW falls on the side of those 15, **the COW control cubicle is absorbed into the cargo control package and appears independently in no component row at all.** Search the CBS inventory for a "COW control panel" and you will not find one; the controller that actually executes the COW sequence is counted as part of the cargo control CBS. The inventory is not wrong — **the boundary was drawn differently** — and the problem arises only when that fact is not recorded anywhere.

**The legitimate inbound windows: approval, test and verification.** The supply boundary matters in cyber terms because it decides *when, and by whom, this system may legitimately be touched*. COW is one of the rare systems where those windows are written into the rules.

| Window                  | Clause                                                                                                            | Cyber meaning                                                                                             |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| Equipment approval      | MARPOL Annex I Reg. 33.2 — compliant with Administration requirements, referencing the IMO-adopted Specifications | The design configuration is subject to regulatory approval; arbitrary change is a departure from approval |
| Procedure approval      | Reg. 35.1 — Operations and Equipment Manual, to the satisfaction of the Administration                            | **The operating sequence is fixed in a document.** This is the crux of section 17                         |
| Installation test       | A.446 §4.1.9 — piping tested at 1.5x working pressure                                                             | The moment at which vendor access is legitimised during commissioning                                     |
| Periodic verification   | A.446 §4.2.13 — submerged machines checked at not more than six uses or twelve months                             | A recurring window of physical access                                                                     |
| Personnel qualification | A.446 §5.2 — one year tanker service, participation in at least two COW programmes                                | The authority to operate is gated on a human credential                                                   |

Collapsing these windows into the phrase "remote access" destroys the analysis. Stated precisely, this is **a schedule on which inbound authority is opened**, and to anyone who knows the schedule it is also a plan.

## 8\. Architecture Patterns

COW's real topology varies by ship and is not settled in this system's brief. Which specific components make up the 8 programmable entries in TYP-A05, and the real values behind the 4 "Likely" network interfaces in TYP-A04 and the 34 in TYP-B02, are all unconfirmed. Rather than assert one, three conceptual variants are presented.

TYPICAL ARCHITECTURE — disclaimer.

A, B and C below are not the configuration of any particular ship or manufacturer. They are conceptual patterns derived from typology profiles and rule requirements. A real vessel is one of the three or somewhere between them, and which one can be established **only from drawings and vendor confirmation.**

**Variant A — Standalone.** The COW control panel stands on its own in the cargo control room with machine-running lamps, pressure gauges and valve switches. There is no connection to a higher-level network beyond a few alarm contacts. A person executes each step from the manual.

[A] Operator -> COW panel (local, hardwired) -> Solenoid cabinet -> COW valves
                     ^                                                  |
                     +---- pressure gauge / rotation indicator ---------+
    (no IP interface; attack surface = physical access to CCR and cabinets)

**Variant B — Monitored / Online.** The COW panel reports status to a higher-level IAS or cargo control console. Pressure, step progress and alarms appear on the CCR mimic, and washing records flow into a CTMS or electronic log. Outbound stops at A2, but **as soon as tag databases, alarm limits and display templates come down from above, inbound A3 exists.**

[B] Operator -> COW panel -> Solenoid cabinet -> COW valves
                   |  ^
          status A2|  | A3 tag/alarm-limit distribution (inbound)
                   v  |
             IAS / cargo mimic ----> CTMS record ----> shore (commercial)
    (attack surface adds: cargo control network, tag DB distribution, IP conduit to shore)

**Variant C — Control-Integrated.** The COW sequence is implemented as a programme of the cargo control system, and valve lineup and pump speed setpoints issue from the same console. The washing pattern becomes a software configuration item, and the programmable subset of TYP-A05 belongs here.

[C] Operator -> Cargo control console (L2) -> Cargo controller (L1)
                        |                          |
                        |                          +-> COW valve solenoids -> COW valves
                        |                          +-> Pump speed setpoint  -> driving pressure
                        |                          +-> Machine sequence      -> arc programme
                        v
                  Vendor service laptop / USB  [ inbound A3 / A6 / A7 ]
    (attack surface adds: executable and sequence replacement with persistence)

How the attack surface differs across the three:

| Axis                      | A Standalone         | B Monitored                            | C Control-Integrated                     |
| ------------------------- | -------------------- | -------------------------------------- | ---------------------------------------- |
| Logical entry             | None (physical only) | Cargo control network                  | Cargo control network + service tools    |
| Highest inbound authority | A5 (local operation) | A3 (configuration distribution)        | **A7 (executable replacement)**          |
| Persistence               | None                 | Configuration level                    | **Survives restart and watch handover**  |
| What can be manipulated   | Valve open/close     | Indication, alarm limits               | Sequence, arc, driving-pressure setpoint |
| Detection path            | Physical indicator   | Physical indicator + mimic cross-check | Physical indicator only                  |

One fact runs through all three. **In every variant, the external rotation indicator of A.446 §4.2.12 and the hand dipping of §4.4.4 remain in place.** However deeply software gets involved, those two verification means sit outside the instrumentation signal path. That the detection path in variant C shrinks to "physical indicator only" is bad news; that what remains is **guaranteed by rule** is good news.

Part III — Authority and Physical Effect

## 9\. What Information and Commands Flow Through It

Mixing information and commands together under the word "signal" makes authority analysis impossible. Split what flows through COW in two.

**Information**

| Item                                   | Source                                                | Recipient                         | Character                                             |
| -------------------------------------- | ----------------------------------------------------- | --------------------------------- | ----------------------------------------------------- |
| COW line driving pressure              | Pressure transmitter (TYP-B02)                        | Control panel → CCR mimic         | The only instrumented indicator of wash effectiveness |
| Machine rotation / arc indication      | Mechanical indicator outside the tank (A.446 §4.2.12) | **The operator's eye**            | Outside the instrumentation path. Not substitutable   |
| Stripping rate / stroke counter        | Stripping system (external)                           | Remote indication in CCR (§4.4.8) | The means of monitoring the 1.25x inequality          |
| Valve position feedback                | Limit switch / positioner                             | Console                           | Open/closed state indication                          |
| Tank level and ullage                  | Gauging system (external)                             | CCR                               | The criterion for arc stage transitions               |
| **Tank oxygen content, tank pressure** | **IGS (external system)**                             | Person                            | **Precondition for starting and continuing**          |
| Hand dipping result                    | **The operator's hand**                               | Person                            | Outside the instrumentation path. §4.4.4              |

**Commands**

| Item                                  | From                     | To                       | Result                                            |
| ------------------------------------- | ------------------------ | ------------------------ | ------------------------------------------------- |
| COW supply isolation valve open/close | Console / local          | Solenoid cabinet → valve | Which tank receives crude at pressure             |
| COW line valve open/close             | Console / local          | Solenoid cabinet → valve | System isolation and path selection               |
| Programme step start/stop             | COW control panel        | Sequence logic           | Arc stage transition                              |
| Pump speed / discharge setpoint       | Cargo control (external) | Cargo pump               | Driving pressure                                  |
| Stop washing                          | **A person**             | Whole system             | The mandatory action when §6.6 preconditions fail |

Put the two tables side by side and the character of the system emerges. **Half the information originates in external systems or in human senses, and the most important item in the command list — stop washing — is not an automatic trip but a human obligation.** A.446 §6.6 requires washing to be stopped if the oxygen content of the inert gas being delivered exceeds 8% or the tank is not at positive pressure, but it does not require the final element that performs that stop to live inside the COW system. Verified 33 CFR 157.164 likewise stops at requiring a crew member to monitor the instrumentation, or an alarm to sound in the cargo control room when oxygen exceeds 8% by volume, and requires COW to be terminated when the condition is not met — **an alarm, not a trip.** Verified

The most important safety action in COW therefore depends entirely on **information reaching a person**. That is the basis of scenario 3 in section 16.

## 10\. What Authority Does Each Connection Carry

**\[Table 2\] Authority Matrix** — rows are the source, columns the destination. Each cell is the authority exercised in that direction.

| Source \\ Destination                   | COW machine                                               | COW valve                                                           | Pressure Tx                                             | COW panel                                        | Cargo controller              | CCR / IAS              | Shore record          |
| --------------------------------------- | --------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------ | ----------------------------- | ---------------------- | --------------------- |
| **COW machine**                         | —                                                         | NO                                                                  | NO                                                      | NO                                               | NO                            | NO                     | NO                    |
| **COW valve**                           | NO                                                        | —                                                                   | NO                                                      | **Provide Info (A2)** position feedback          | Provide Info (A2)             | Provide Info (A2)      | NO                    |
| **Pressure Tx**                         | NO                                                        | NO                                                                  | —                                                       | **Provide Info (A2)**                            | Provide Info (A2)             | Observe / Info (A1–A2) | NO                    |
| **COW panel**                           | **Command (A4)** CONDITIONAL — programmable machines only | **Command (A4)** indirect, via controller                           | **Configure (A3)** CONDITIONAL — smart instruments only | —                                                | Command / Configure (A4 / A3) | Provide Info (A2)      | **Provide Info (A2)** |
| **Cargo controller / solenoid cabinet** | Command (A4)                                              | **Control (A5)**                                                    | NO                                                      | Configure (A3) tag and limit distribution        | —                             | Provide Info (A2)      | NO                    |
| **Local operator (field)**              | **Control (A5)** manual                                   | **Control (A5)** handwheel                                          | Observe (A1)                                            | Command (A4)                                     | Command (A4)                  | —                      | —                     |
| **Vendor service laptop**               | UNKNOWN                                                   | NO (base type) / **A3 + A7** CONDITIONAL (integrated actuator spec) | **Configure + Update (A3, A7)** HART / DTM              | **Configure + Administer + Update (A3, A6, A7)** | A3 / A6 / A7                  | —                      | —                     |

Summarised by direction, the system envelope is:

- **Outbound: A0 – A5.** The maximum, A5, is what a local operator exercises on a valve; the practical ceiling for equipment acting on equipment is the panel's **A4 COMMAND**. The outbound authority of the COW machines and the valve bodies is **A0 NONE** — they command nothing.
- **Inbound: A0 – A7.** The maximum, A7 UPDATE\_EXECUTABLE, is what a vendor service tool exercises on the control panel. Because all 17 entries of the TYP-B08 family are programmable, the replaceability of executable code and sequence logic is not a guess but a fact of the profile. Typical

**This system's inbound authority is larger than its outbound authority.** And the place where they diverge is precisely the place where the software is. The principle that the security-relevant direction is usually inbound is, in COW, confirmed numerically.

KEY DISTINCTION — connectivity is not authority.

There is bidirectional wiring between a COW valve and the console. Solenoid energisation goes down; a limit switch contact comes back up. But **two-way communication does not mean two-way operational authority.** In the valve → console direction the authority stops at A2 PROVIDE\_INFORMATION. The valve makes the console do nothing. The other direction is A5 CONTROL. The same cable, opposite authority. Counting cables is not counting risk.

Go one step further and you can also see here that **A3 CONFIGURE can be more dangerous than A4 COMMAND.** A vendor tool's A3 on a pressure transmitter is quieter, longer-lived and harder to reverse than "open this valve now". Changing a range with HART Command 35 leaves no command in a log — only a measured value.

## 11\. Can the System Affect the Physical Process

Physical effect is a **separate axis** from authority. It asks how directly something touches the physical world — not how severe the outcome is, and not how much authority is held.

**\[Table 3\] Authority–Effect Matrix**

| Interaction                                     | Authority (by direction) | Physical Effect                               | Human Gate                  | Security significance                            |
| ----------------------------------------------- | ------------------------ | --------------------------------------------- | --------------------------- | ------------------------------------------------ |
| Console → solenoid cabinet → COW valve          | inbound to valve: **A5** | **P4** DIRECT                                 | EXECUTION                   | The last link where a bit becomes flow           |
| COW valve → process fluid                       | outbound: **A0**         | **P4** DIRECT                                 | —                           | **The site of the A0 + P4 asymmetry**            |
| COW machine → tank wall                         | outbound: **A0**         | **P0** base type / **P4** programmable subset | EXECUTION                   | The most violent physical action, zero authority |
| Pressure Tx → panel → person                    | outbound: A1–A2          | **P1 / P2**                                   | EXECUTION                   | The judgement-contamination path                 |
| Vendor tool → pressure Tx (range)               | inbound: **A3, A7**      | **P1**                                        | REVIEW (calibration record) | Quiet and persistent                             |
| COW panel → cargo controller → valves and pumps | outbound: **A4, A3**     | **P3** INDIRECT                               | EXECUTION / SUPERVISION     | A sequence changes the physical lineup           |
| Vendor tool → COW panel                         | inbound: **A3, A6, A7**  | **P3** (via downstream)                       | REVIEW                      | Highest inbound, with persistence                |
| IGS → person → decision to stop washing         | outbound (IGS): A2       | **P2**                                        | **EXECUTION (human only)**  | A safety action that depends on information      |

KEY DISTINCTION — A0 outbound and P4 hold at the same time.

The COW machine performs the most violent physical action in this system. A high-pressure crude jet strikes steel, strips residue, and its reaction spins the nozzle. Yet this equipment's outbound authority is **A0 NONE**. It commands nothing, generates no information and holds no state machine. The same is true of the COW valves — outbound A0, physical effect P4\. **Authority is upstream; the physical contact is downstream.** The asymmetry is normal, not anomalous, and failing to recognise it produces two errors: (1) concluding that zero authority means the item can be ignored, striking it from the inventory and **striking the cabinet that governs it along with it**; or (2) conversely, scoring high risk from the large physical effect and **attaching access-control requirements to a non-programmable valve**, which is an unimplementable control.

**⚠ A judgement on P5 — this article departs from the system envelope.**

Mechanically unioning this system's typology envelope puts **P5 SAFETY\_CRITICAL\_EFFECT** in the physical effect list. But it is worth asking where that P5 came from.

- TYP-A04's P5 is assigned not to the whole family but to the **subset used as the final element of a safety function** — specifically **fuel oil quick-closing valves and ESD valves**.
- TYP-B02's P5 is limited to **independent overfill / high-level alarm arrangements** (95/98% independent level switches and overfill alarm panels), on the authority of IBC Code 15.19.5–15.19.7.
- TYP-A05 and TYP-B08 are assigned no P5 at all.

**None of COW's five component rows belongs to those subsets.** A COW supply isolation valve is neither a fuel oil quick-closing valve nor an ESD valve, and COW line pressure instrumentation is not an independent overfill switch. This article therefore **does not assign P5 to the COW system.** The P5 in the envelope is inherited from other subsets of the typology families; it is not this system's.

This is the "highest value is not a risk score" principle in live use. An envelope is the union across the whole population a typology covers, not the profile of this system. One honest caveat remains: if on a particular ship a COW supply isolation valve is wired as the final element of cargo ESD logic, then that valve is P5\. **It has not been confirmed, so it goes to Open Questions.**

One more point: withholding P5 does **not** mean the risk is low. What happens when high-pressure crude is sprayed inside a tank that has lost its inert atmosphere was demonstrated in 1969\. But the severity of that outcome is a value on the severity axis, while whether a COW component has a path to defeating a safety function is a question on the physical effect axis. **Mix the two axes and the classification scheme loses its descriptive power.**

## 12\. Human Gate

COW's human gate is dominantly **EXECUTION**. Cargo work advances only when a person executes each step at the console, and watches the washing pattern progress. But in COW this gate is not a custom — it is **a structure built by rule**.

MARPOL Annex I Reg. 35.3 requires the system to be operated in accordance with the approved Operations and Equipment Manual. Verified The procedure binds the person into the loop. And A.446(XI) specifies, clause by clause, what that person must do with their own senses.

Human gate points mandated by rule
   |
   +-- A.446 5.2   Person in charge qualification (1 yr tanker, 2+ COW programmes)
   |                  -> authority to operate is gated on a human credential
   |
   +-- A.446 6.6   Verify O2 at 1 m below deck AND mid-ullage, both <= 8 vol%
   |                  -> gate BEFORE start; continuous during; stop condition
   |
   +-- A.446 4.2.12 Watch external rotation/arc indicator
   |                  -> gate DURING; outside the instrumentation path
   |
   +-- A.446 4.4.4  Hand dipping at aftermost point + 3 locations
   |                  -> gate AFTER; physical, out-of-band
   |
   +-- A.446 4.2.10 Visual inspection: essentially free of clingage and deposits
                      -> gate AFTER; human sensory verification of the physical result

Read the character of that list precisely. **Three of those items — §4.2.12, §4.4.4 and §4.2.10 — do not pass through the instrumentation path at all.** The indicator is mechanical, hand dipping is a hand, and the visual inspection is an eye. The clauses were written two decades before cyber security existed as a concept, and the result is that this system carries **verification means that software cannot forge, mandated by rule**.

The principle that a gate disappears once the same equipment is placed in an automatic loop holds here too. When the COW sequence is absorbed into the cargo control programme, as in variant C of section 8, the character of the human role shifts from **EXECUTION to SUPERVISION**. The person who used to press each step becomes a person watching progress, and a person watching progress watches a screen. Whether the mechanical indicator of §4.2.12 actually gets checked at that point decides the integrity of the system — it is **where a rule-mandated gate quietly becomes an omitted custom**.

One contrast is worth setting down. The doctrine of the sibling typology TYP-B02 contains paths with **no human gate at all** — the overflow-control system of IBC Code 15.19.7 raises an alarm and sequentially shuts down pumps and valves, and the oil discharge monitoring and control system of MARPOL Annex I Reg. 31 together with the 15 ppm automatic stopping device of Reg. 14.7 cut discharge automatically on a measured value. **But those are not COW's paths.** COW's §6.6 stop obligation has no automatic trip; a person stands in that place. Same cargo area, same instrumentation family, opposite gate structure.

## 13\. Authority Escalation and Propagation

There is a path in this system by which low authority at entry produces a high-consequence outcome downstream. And in COW that path **runs through a person rather than through machinery.**

PROPAGATION CHAIN 1 — through human judgement (no CONTROL anywhere)

  Vendor/service tool at cargo-area junction box
        | A3 CONFIGURE  (HART Command 35: range / span / unit)
        v
  COW line pressure transmitter          [authority of device itself: A1 OBSERVE]
        | A2 PROVIDE_INFORMATION (now false)
        v
  COW control panel / CCR mimic  -- shows 10 bar while line is at 6 bar
        | operator sees nominal driving pressure
        v
  Operator decides the wash is proceeding to the approved programme   [EXECUTION gate passed on false data]
        v
  Actual jet energy below design -> effective shadow exceeds A.446 4.2.8 limits (10% / 15%)
        v
  Clingage remains -> tank recorded as crude-oil-washed
        v
  Ballast admitted to that tank        [MARPOL Reg. 35.2 satisfied on paper only]
        v
  Departure ballast oil ratio exceeds A.446 4.2.10 limit (0.00085)
        v
  CONSEQUENCE: oily ballast, discharge exceedance, ORB entries false without anyone lying

Read the character of that chain carefully. **At no step is A5 CONTROL exercised.** The highest authority the attacker obtained is A3 on an A1 device. And the outcome is a regulatory breach and an environmental discharge. This is where the judgement "sensors have no control authority, so they are low priority" goes wrong. **Authority propagates through human paths as well as machine paths, and the human path leaves no log.**

PROPAGATION CHAIN 2 — through the sequence (machine path, with persistence)

  Vendor service laptop / removable media at COW or cargo control panel
        | A6 ADMINISTER + A7 UPDATE_EXECUTABLE
        v
  COW control panel  [TYP-B08: 17/17 programmable]
        | A3 CONFIGURE persists across restart and watch change
        v
  Washing programme altered: more machines simultaneous, arc limits changed, step interlock removed
        | A4 COMMAND to cargo controller
        v
  Cargo controller (L1) -> valve solenoids + pump speed setpoint
        | A5 CONTROL on valves,  P4 at the valve seat
        v
  Wash throughput exceeds stripping capacity   [A.446 4.4.3: stripping must be 1.25x throughput]
        v
  CONSEQUENCE: oil accumulates on tank bottom during washing; free surface and overpressure margins
               eroded; the officer's screen shows a programme that is running normally

Side by side the contrast is clear. Chain 1 propagates **indirectly through a person with no direct control at all** and is very hard to detect. Chain 2 propagates **directly through machinery** and has persistence, but entry requires physical access or a legitimate service window. The common line of defence for both is the non-instrumented verification of section 12 — the §4.2.12 rotation indicator, §4.4.4 hand dipping and §4.2.10 visual inspection. **When the instrumentation path is contaminated, those are the only things still telling the truth.**

Part IV — Uncertainty and Security

## 14\. Trust Boundaries and Dependencies

A trust boundary is not where a firewall sits. It is **where an assumption changes** — where administrative ownership changes, or exposure, or privilege level, or physical accessibility, or where vendor control begins. COW has five such lines, and one of them is of a different kind from the other four.

TRUST BOUNDARIES AROUND THE COW SYSTEM

  +==========================================================================+
  |  TB-1  SAFETY PRECONDITION BOUNDARY   (owner of the safety case: IGS)    |
  |                                                                          |
  |    IGS  --O2 reading, tank pressure-->  Operator  --stop/continue-->  COW |
  |    COW holds NO instrument, NO interlock and NO trip of its own here.     |
  +==========================================================================+
             |
  +----------v---------------------------------------------------------------+
  |  TB-2  SUPPLY BOUNDARY        yard/owner scope  |  maker package (COW)    |
  |        who may open the cabinet, who ships the firmware, who holds source |
  +--------------------------------------------------------------------------+
             |
  +----------v---------------------------------------------------------------+
  |  TB-3  ZONE BOUNDARY          cargo control zone  |  navigation & comms   |
  |        UR E26 Rev.1 4.2.1.3 forbids the same zone for these two           |
  +--------------------------------------------------------------------------+
             |
  +----------v---------------------------------------------------------------+
  |  TB-4  PHYSICAL ACCESS BOUNDARY       CCR door  =  the actual credential  |
  |        UR E26 Rev.1 4.2.4.4.1 authentication exemption rests on 4.2.4.3.2 |
  |        During discharge the CCR is not a closed room: terminal reps,      |
  |        surveyors and charterer's staff pass through it.                   |
  +--------------------------------------------------------------------------+
             |
  +----------v---------------------------------------------------------------+
  |  TB-5  MAINTENANCE BOUNDARY   service laptop / USB  ->  COW panel         |
  |        UR E26 Rev.1 4.2.4.3.4 removable-media policy is the only gate     |
  +--------------------------------------------------------------------------+

**TB-1 is the top-level fact of this analysis.** COW's safety case rests on the proposition that the inside of the tank is not a combustible atmosphere — and not one piece of equipment that makes that proposition true is inside COW. IGS produces the inert gas, IGS instrumentation measures the oxygen, and COW's obligation under A.446 §6.6 is merely **to confirm the value and stop if it is out of limits.** Verified

Why that matters in cyber terms: conventional safety analysis asks what could defeat this system's safety function. In COW the answer lies outside the system. **You can collapse COW's safety case without touching a single COW component** — distort the IGS oxygen measurement, or break the path by which that value reaches the person. Conversely, defending every COW component does not defend that path. When a zone design places the COW panel and the IGS instrumentation in different zones, if this dependency is not recorded, the zone boundary ends up **cutting across the direction in which the safety case flows**.

TB-4 is the boundary that most often fails in practice. UR E26 Rev.1 §4.2.4.4.1 permits user identification and authentication to be waived, subject to physical access control, for operator HMIs requiring immediate access. Verified The cargo control console is the device class most likely to receive that waiver, precisely because the operating requirement of not leaving the screen during discharge collides head-on with UR E27 Rev.1 §4.1 Table 1 item 12 (SR 2.5, session lock). Verified But the physical control on which the waiver rests is the visitor access control of §4.2.4.3.2, and during discharge the CCR is a space through which terminal representatives, surveyors and charterer's staff pass. **If the door is the credential instead of an account, then the length of time that door stands open under discharge schedule pressure is the effective strength of the authentication.** Typical

Set out as dependencies:

| What COW depends on            | Provided by                            | Nature                     | Effect on COW if it fails                                                 |
| ------------------------------ | -------------------------------------- | -------------------------- | ------------------------------------------------------------------------- |
| Inert atmosphere (O2 ≤ 8 vol%) | IGS (external)                         | **Safety precondition**    | Washing is not permitted at all. Continue and you have the 1969 condition |
| Driving pressure               | Cargo pumps + cargo control (external) | Performance precondition   | Shadow limits exceeded, wash fails                                        |
| Stripping capacity (1.25x)     | Stripping system (external)            | Performance precondition   | Oil accumulates on the bottom, recovery fails                             |
| Level and ullage               | Gauging system (external)              | Sequence input             | Arc stage transitions mistimed                                            |
| Approved manual                | Administration + operator              | **Configuration baseline** | The only authoritative copy of the operating configuration is gone        |
| Qualified person in charge     | Operator's crewing                     | Authority gate             | A.446 §5.2 not satisfied                                                  |

Four of six lines are **external systems**, one is **a document** and one is **a person**. COW owns essentially no trust asset of its own. The notion of defending this system independently barely holds — which is why most of its security requirements are absorbed into **the requirements of the cargo control zone**.

## 15\. What Happens When the System Fails

Engineering failure comes before cyber failure. And COW's failures are mostly **silent** — a property that becomes the premise of the threat analysis that follows.

⚠ **To state it plainly first:** this research **did not find** a public investigation report (MAIB, NTSB, ATSB, TSB Canada, DMAIB, KMST) attributing a casualty to the COW operation itself. Unknown The failure modes below are therefore derived not from demonstrated accidents but from **the states A.446(XI) is designed to prevent** and from typology failure doctrine. Blurring that distinction would make the claim stronger than its evidence.

| Failure                   | Cause                                                     | What is observed                                                                              | Operational outcome                                                           |
| ------------------------- | --------------------------------------------------------- | --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------- |
| Machine rotation stops    | Hydro-motor seizure, drive failure, nozzle blockage       | **Nothing is observed** (revealed only if the §4.2.12 external indicator is actually watched) | That tank is unwashed. On paper the wash is complete                          |
| Driving pressure falls    | Pump degradation, insufficient valve opening, line losses | Pressure indication (only if the instrument is honest)                                        | Jet energy short of design → shadow limits exceeded                           |
| Stripping shortfall       | Stripping pump performance, eductor cavitation            | §4.4.8 remote counter indication                                                              | Oil accumulates on the bottom, 1.25x inequality breached                      |
| Valve passing             | Seat and disc wear, debris trapped                        | **Console shows CLOSED**                                                                      | Washing medium into an unintended tank, cross-contamination                   |
| Valve stops mid-travel    | Hydraulic pilot leak, air ingress                         | Neither open nor closed lamp lit                                                              | Lineup time increases, system response degrades                               |
| Limit switch misalignment | Contact oxidation, mechanical misalignment                | **Actual position and indication disagree**                                                   | Pump started on a wrong lineup → deadhead or overpressure                     |
| Pressure instrument drift | Sensor ageing, blocked impulse line                       | **Diverges slowly with no alarm**                                                             | The programme proceeds on contaminated judgement                              |
| Loss of inert atmosphere  | IGS failure, poor deck seal, inadequate purging           | IGS oxygen indication and alarm                                                               | **The §6.6 stop obligation triggers. Continue and the atmosphere can ignite** |

FAILURE CHAIN — the characteristic COW failure is silent

  Nozzle blocked / rotor stalled   [no electrical signal exists for this]
        |
        v
  Panel programme step advances on a timer, not on measured coverage
        |
        v
  CCR mimic shows "TANK 3P  WASH COMPLETE"
        |
        v
  Tank entered in the Operations and Equipment Manual record as washed
        |
        v
  Ballast admitted to that tank        [MARPOL Reg. 35.2 satisfied on paper]
        |
        v
  Departure ballast oil layer exceeds 0.00085 by volume   [A.446 4.2.10 limit]
        |
        v
  Either: illegal discharge at sea, or an unplanned slop handling problem in port
        |
        v
  Discovered on tank entry -- weeks later, if at all

What stands out in that chain is the **detection delay**. There is, in principle, no electrical signal that tells anyone a washing machine has stopped turning. That is why A.446 §4.2.12 requires a mechanical means, outside the tank, of indicating rotation and arc for deck-mounted machines, and why §4.2.13 accepts external indication, characteristic operating sound, or periodic verification for submerged machines. Verified The requirement exists not because instrumentation signals are distrusted but because **no such instrumentation signal exists in the first place**.

Here is the bridge from section 15 to section 16\. In a system whose failures are silent, **attacks are silent too.** An attacker needs no separate concealment technique — the system's normal failure mode is already covert.

## 16\. Attack Surface and Credible Threat Scenarios

### Attack surface

| Surface          | What it is in COW                                                                            | Present?          |
| ---------------- | -------------------------------------------------------------------------------------------- | ----------------- |
| Local (physical) | CCR console, COW control panel, solenoid cabinet, cargo-area junction boxes                  | **Always**        |
| Removable media  | Programme and configuration updates by service laptop and USB (E26 §4.2.4.3.4)               | **Always**        |
| Connected OT     | Cargo control network / IAS in variants B and C                                              | Variant-dependent |
| Ship–shore       | Shore transfer path for CTMS quantity data (E26 §1.3.2 b) IP interface)                      | Variant-dependent |
| Vendor           | Maker package vendor's commissioning, retrofit and remote diagnostic access (E26 §4.2.6.3.2) | **Always**        |
| Supply chain     | Executable code, sequences and tag databases supplied by the package vendor                  | **Always**        |

⚠ The valve bodies and machine bodies have **no logical attack surface**. No firmware, no network port, no accounts. Recording that honestly is what justifies removing those three rows from a CBS inventory. But as sections 6 and 11 noted, **striking the valve and striking the cabinet that governs the valve are two different acts.**

### Scenario 1 — Pressure transmitter re-ranging (maximum harm with no escalation)

Entry Interaction    Physical access to a cargo-area junction box during a port stay,
                     HART handheld or DTM-equipped laptop on the 4-20 mA loop
Initial Authority    A3 CONFIGURE on a device whose own authority is A1 OBSERVE
Mechanism            HART Command 35 changes range/span so that 6 bar reads as 10 bar
Authority Gained     NONE. No escalation occurs anywhere in the chain.
Affected Interaction Pressure Tx -> COW panel -> CCR mimic -> operator judgement
Physical Effect      P1 INDIRECT_DECISION_EFFECT (the jet energy is never commanded down;
                     it was already low, and the display now conceals it)
Consequence          Shadow exceeds A.446 4.2.8 (10% horizontal / 15% vertical);
                     tanks recorded as washed are not washed; ballast admitted under
                     Reg. 35.2 on a false premise; departure ballast exceeds the
                     4.2.10 limit of 0.00085. No alarm, no log entry, no lie told.

The point of this scenario is that it **reaches the deepest consequence from the lowest authority**. No valve moved incorrectly, no command was forged, no account was stolen. What changed was **one configuration value on one device**. This is the principle that A3 CONFIGURE can outrank A4 COMMAND in danger, made concrete — and detection is harder still because in HART-family devices a range change leaves no command in a log, only a measured value. Inferred — whether this path is implemented depends on TYP-B02's network interface being 34/42 "Likely", so this description does not exceed the INFERRED ceiling.

The line of defence is not inside the instrumentation path. Only the three non-instrumented verifications — §4.2.12 rotation indicator, §4.4.4 hand dipping, §4.2.10 visual inspection — catch this scenario.

### Scenario 2 — Washing programme replacement via the maker package (persistence)

Entry Interaction    Vendor service laptop or USB at the COW / cargo control panel
                     during a scheduled retrofit or terminal-driven procedure change
Initial Authority    A6 ADMINISTER + A7 UPDATE_EXECUTABLE  (TYP-B08: 17/17 programmable)
Mechanism            Washing programme and step interlocks replaced: more machines run
                     simultaneously, arc limits widened, a step-completion interlock removed
Authority Gained     A3 CONFIGURE persisting across restart and watch handover;
                     downstream A4 COMMAND to the cargo controller
Affected Interaction COW panel -> cargo controller (L1) -> valve solenoids + pump setpoint
Physical Effect      P3 INDIRECT_PHYSICAL_CONTROL at the panel, P4 at the valve seat
Consequence          Wash throughput exceeds stripping capacity, breaching the A.446 4.4.3
                     inequality (stripping >= 1.25x simultaneous throughput). Oil accumulates
                     on the tank bottom during washing. Free-surface and pressure margins
                     erode while the officer's screen shows a programme running normally.

This scenario is strongest in variant C (control-integrated) and weakest in variant A (standalone). And it **arrives through a legitimate window** — the approval, test and verification regime tabulated in section 7 is precisely the schedule of those windows. Commissioning, the 1.5x pressure test, the twelve-month verification, a procedure change driven by a terminal. Each is a normal activity required by rule, and each is a moment when inbound authority opens.

Persistence is the essence of this scenario. Scenario 1 is undone by a recalibration, but replaced executable code survives a restart and a watch handover. That is exactly why UR E26 Rev.1 §4.1.1.1 and §4.1.1.3.2 require hardware and software inventories — application programs, operating systems and firmware — to be maintained across the life of the ship. Verified **And do not miss that the approved Operations and Equipment Manual is a detection means for this scenario** — the fact that the running programme differs from the manual's procedure surfaces only if the manual is maintained as the authoritative copy and compared against the actual configuration. What MARPOL Reg. 35.1 and 35.3 require is not an administrative document but **a configuration baseline**.

### Scenario 3 — Suppression of the inert-atmosphere precondition (information as safety function)

Entry Interaction    Cargo control network or IGS monitoring path (variant B / C),
                     or physical access to the O2 indication / alarm circuit
Initial Authority    A2 PROVIDE_INFORMATION -- suppressed or falsified, not commanded
Mechanism            The O2 value shown in the CCR is held at a nominal figure, or the
                     high-O2 alarm is inhibited at the display layer
Authority Gained     NONE
Affected Interaction IGS -> operator -> A.446 6.6 stop decision
Physical Effect      P2 OPERATIONAL_STATE_EFFECT (the washing operation continues in a
                     state in which the rules require it to stop)
Consequence          High-pressure crude spraying inside a tank whose atmosphere is no
                     longer verified inert. This is the 1969 condition. The system has
                     no automatic trip for it -- A.446 6.6 and 33 CFR 157.164 both stop
                     at monitoring and alarm, and place the stop action on the person.

This is the most important of the three. As section 9 established, COW's most important safety action is **a human obligation rather than an automatic trip**, and a person needs information to discharge that obligation. In this system, therefore, **the integrity of the information path is the integrity of the safety function.** Classifying information as A2 does not make it less important — when the recipient is a person and that person is the only final element, A2 is the input stage of a safety function.

At the same time, one honest note. This path lies not in a COW component but in **IGS and its indication path**. The scenario is invisible inside a COW CBS inventory, no matter how well that inventory is built. The consequence of TB-1 in section 14 appears here as a concrete risk.

## 17\. Security Architecture and Standards

Controls come from threats, and standards attach after the controls. Start instead from "we comply with E26" and you cannot tell what this system actually needs.

| Scenario                        | Control derived                                                                                                                                                                                  | Standard basis (clause level)                                                                               |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------- |
| S1 instrument re-ranging        | Physical access control on cargo-area instrument loops; cross-check calibration records. Fix **periodic cross-verification of instrumented values against non-instrumented checks** in procedure | A.446 §4.2.12 / §4.4.4 / §4.2.10 (non-instrumented verification); UR E26 Rev.1 §4.2.4.3.2 (visitor control) |
| S1 detection                    | Independent confirmation of the washing result against the pressure indication — retain visual inspection results alongside instrument records                                                   | A.446 §4.2.10; MARPOL Reg. 35.1 (manual records)                                                            |
| S2 executable replacement       | Maintain software inventory and a configuration baseline. **Operate the approved manual as the authoritative configuration copy**                                                                | UR E26 Rev.1 §4.1.1.1, §4.1.1.3.2; MARPOL Reg. 35.1, 35.3                                                   |
| S2 entry window                 | Removable media policy — malware scanning and digital signature verification before use                                                                                                          | UR E26 Rev.1 §4.2.4.3.4                                                                                     |
| S2 vendor access                | Control of remote diagnostic and maintenance connections                                                                                                                                         | UR E26 Rev.1 §4.2.6.3.2                                                                                     |
| S3 information suppression      | Zone separation of cargo systems from navigation and communication systems; only explicitly permitted traffic crosses the boundary                                                               | UR E26 Rev.1 §4.2.1.1, §4.2.1.3                                                                             |
| S3 last line                    | Perform the oxygen check as the **two-point measurement** §6.6 specifies, not from a single displayed value                                                                                      | A.446 §6.6; 33 CFR 157.164                                                                                  |
| Common — console authentication | Document the conflict between session lock and the operating requirement, and actually maintain the physical control on which the waiver rests                                                   | UR E27 Rev.1 Table 1 item 1 (SR 1.1), item 12 (SR 2.5); UR E26 Rev.1 §4.2.4.4.1                             |
| Common — malicious code         | Prevention, detection, mitigation, and updating of protection mechanisms                                                                                                                         | UR E27 Rev.1 Table 1 item 18 (SR 3.2)                                                                       |
| Common — behaviour on fault     | Define valve behaviour on console fault as a predetermined state                                                                                                                                 | UR E27 Rev.1 Table 1 item 20 (SR 3.6)                                                                       |
| Scope determination             | Document the judgement that excludes valves and machines from the CBS boundary                                                                                                                   | UR E26 §6 (risk assessment for exclusion)                                                                   |
| Category                        | Liquid cargo transfer control systems are exemplified as Category II                                                                                                                             | UR E22 Rev.3 §3.3                                                                                           |

Three points deserve emphasis.

**First, the strongest control in this system is not a cyber control.** The external rotation indicator of A.446 §4.2.12, the hand dipping of §4.4.4 and the visual inspection of §4.2.10 were written in 1979, and they are **verification means that software cannot forge**. Two of the three scenarios are caught by them. The job of cyber security design here is not to invent new controls but **to bind those three verifications into procedure and records so they are not quietly omitted**. When the human role drops from EXECUTION to SUPERVISION in variant C, they are the first things to go.

**Second, the approved Operations and Equipment Manual functions as a configuration management control.** MARPOL Reg. 35.1 requires a manual describing the system and equipment and prescribing operational procedures, to the satisfaction of the Administration, and Reg. 35.3 requires the system to be operated in accordance with it. Verified Translate those two clauses into cyber language and they read: **an approved baseline exists, and actual operation must match it.** That purpose overlaps with the software inventory requirement of UR E26 §4.1.1.3.2 — and in COW the regulatory document already performs the role. The implementable design is not to create a new document but **to connect the existing regulatory document to the configuration baseline**.

**Third, avoid unsupported compliance claims.** UR E27 Rev.1 §1.3 states that E27 applies to "computer based systems specified in UR E26". Verified Of COW's five rows, therefore, E27 requirements attach only to those judged to be CBS, and attaching E27 Table 1 items to a non-programmable valve or machine is not a requirement but a misapplication. Conversely, UR E26 §6 requires a risk assessment before a CBS is **excluded** from the application of the requirements — so "the valve is not a CBS" is not a judgement to be made casually either, but a documented one. Verified

## 18\. Open Questions, Takeaways and References

### 18.1 Open Questions

What this article could not settle. None of it has been filled in by inference.

| #   | Unconfirmed item                                                                                                                            | What changes when it is settled                                                           |
| --- | ------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Q1  | Whether the COW control cubicle is its own cubicle or absorbed into the cargo control package (only 2 of 17 TYP-B08 entries have their own) | The item count in the CBS inventory, zone placement, whether a maintenance conduit exists |
| Q2  | Whether COW machines are in fact among the 8 programmable entries of TYP-A05                                                                | The variant judgement in section 8; whether P4 applies in section 11                      |
| Q3  | The real values behind TYP-B02's 34/42 "Likely" network interfaces                                                                          | Whether scenario 1 can rise above the INFERRED evidence grade                             |
| Q4  | Whether a COW supply isolation valve is wired as a final element of cargo ESD logic                                                         | If so, that valve alone becomes a P5 candidate (currently not assigned)                   |
| Q5  | What interface the COW panel has with the cargo ESD system                                                                                  | The same judgement. No basis in the present BOM                                           |
| Q6  | Whether the solenoid valve cabinet's controller is relay logic or a PLC                                                                     | The CBS boundary of the whole valve family                                                |
| Q7  | The actual protocol of the cargo control panel (Modbus RTU/TCP or a vendor fieldbus)                                                        | Conduit design and whether E27 Table 2 applies                                            |
| Q8  | The CTMS shore data transfer path (terminal link, satellite, USB export)                                                                    | Whether E26 §1.3.2 b) IP interfaces apply                                                 |
| Q9  | Which CCR consoles are **specified** as exempt under E26 §4.2.4.4.1                                                                         | Whether the exemption is valid at all                                                     |
| Q10 | How session lock (E27 item 12) is actually configured during discharge                                                                      | The effective inbound control level of this typology                                      |
| Q11 | Whether any official COW casualty or defect investigation report exists                                                                     | Sections 15 and 16 would move from rule-derived to incident-derived                       |
| Q12 | TYP-B02's unpopulated register state                                                                                                        | Whether descriptions resting on this typology can rise from INFERRED to TYPICAL           |

### 18.2 Fourteen questions to ask first on a real project

Questions to put to vendors and owners on a newbuilding or retrofit project. The answers close the open questions above.

COMPOSITION AND BOUNDARY
 1. Is the COW control panel an independent cubicle or inside the cargo control package?
    Answer with a drawing number.
 2. Under which CBS item is the controller that executes the COW washing programme listed?
 3. Do the COW machines have position, arc or rotation feedback? If so, into which I/O?
 4. Is the machine arc programme a hardware cam or a software parameter?

AUTHORITY AND INTERFACE
 5. What kind of controller is in the COW valve solenoid cabinet - relay logic or a PLC?
 6. Is the COW line pressure transmitter HART-capable? Is write protection enabled?
 7. Provide the signal list exchanged between the COW panel and the cargo ESD system.
    (Does it participate in a trip path?)
 8. What is the COW panel's communication protocol, and what are its peer nodes?

MAINTENANCE AND SUPPLY
 9. By what medium, and under whose signature, is the washing programme updated?
10. Does vendor remote diagnostic access exist? If so, over which conduit?
11. Who retains the software configuration record for this package after commissioning?

SAFETY CASE AND HUMAN GATE
12. From which instrument and which indication is the 8 vol% oxygen check made? Is there a
    means of confirming it independently of the IGS system?
13. Does the A.446 4.2.12 external rotation indicator physically exist? Show the most
    recent verification record.
14. In automatic sequence phases, is the human role EXECUTION or SUPERVISION? Where in the
    procedure is that stated?

### 18.3 Engineering Takeaways

1. **COW is a system built by regulation, and that regulation stands on a precondition created by a different system.** 1969 explosions → IGS mandated → inert atmosphere secured → 1978 TSPP → COW mandated. In the reverse order this system could not have been approved.
2. **The washing medium is the cargo itself.** No dedicated fluid, pump or storage. That is what puts the functional boundary out of step with the procurement boundary, and why only five rows appear in the BOM.
3. **Component count is not a measure of cyber relevance.** Three of the five rows are non-programmable L0, and only one row is listed separately as a CBS. Yet those three rows perform all of the physical action.
4. **Inbound authority exceeds outbound authority.** The envelope is outbound A0–A5, inbound A0–A7, and the place they diverge is exactly the place where the software is.
5. **A0 + P4 is normal.** The machines and valves perform the most violent physical action with zero authority. Authority is upstream, physical contact downstream.
6. **This article does not assign the envelope's P5 to this system.** That P5 is inherited from other subsets — fuel oil QCV/ESD valves and independent overfill switches — and none of COW's five rows belongs to them.
7. **The cheapest attack path is not the physical quantity but the belief about it.** A path exists from the lowest authority (A3 on an A1 device) to a regulatory breach and an environmental discharge, and it leaves no log.
8. **The rules mandate out-of-band verification.** §4.2.12 external rotation indicator, §4.4.4 hand dipping, §4.2.10 visual inspection — written two decades before cyber security existed and unforgeable by software.
9. **The approved manual is the configuration baseline.** Rendered in cyber language, MARPOL Reg. 35.1 and 35.3 overlap in purpose with the software inventory requirement of UR E26 §4.1.1.3.2.
10. **COW does not own its own safety case.** That single sentence is the most important fact in analysing this system, and the zone design, the inventory boundary and scenario 3 all follow from it.

FINAL ANALYTICAL CHAIN — Crude Oil Washing System

 System        Crude oil washing (SYS-012, MARPOL Annex I origin)
   -> Function    dissolve clingage with the cargo itself during discharge
   -> Component   5 BOM rows only (2 valves, 1 machine, 1 instrument, 1 panel)
   -> Typology    A04 valve / A05 machine / B02 transmitter / B08 panel
   -> Interaction supply lineup, jet application, pressure indication, step sequencing
   -> Info/Cmd    info half-sourced outside the system; the critical command is human
   -> Authority   outbound A0-A5  |  inbound A0-A7   (inbound is the larger set)
   -> Phys Effect P0-P4  (P5 NOT assigned -- inherited from other typology subsets)
   -> Human Gate  EXECUTION, mandated by rule, with three out-of-band verifications
   -> Dependency  IGS inert atmosphere, cargo pumps, stripping, gauging, approved manual
   -> Trust       the safety case is owned by a neighbouring system
   -> Failure     silent: no electrical signal exists for a stalled washing machine
   -> Consequence unwashed tanks recorded as washed -> oily ballast -> Reg. 35.2 breach
   -> Threat      S1 re-ranging (A3 on A1)  S2 programme replacement (A7)  S3 info suppression
   -> Requirement configuration baseline, media control, zone separation, physical access
   -> Control     tie the three rule-mandated out-of-band verifications to records
   -> Assurance   UR E26 4.1.1.3.2 inventory + MARPOL Reg. 35.1 approved manual
   -> Evidence    A.446 clause numbers, MARPOL Reg. 33/35, 33 CFR 157.164, UR E26/E27/E22

### 18.4 References

**Standards and regulations**

- MARPOL Annex I Regulation 33 — Crude oil washing requirements. Verified
- MARPOL Annex I Regulation 35 — Crude oil washing operations. Verified
- IMO Res. A.446(XI), as amended by A.497(XII) and A.897(21) — Specifications for the Design, Operation and Control of Crude Oil Washing Systems. Verified
- IMO Res. MEPC.3(XII), as amended by MEPC.81(43) — Standard format for the Crude Oil Washing Operations and Equipment Manual.
- 33 CFR 157.164 — Crude oil washing: inert gas requirements (US domestic cross-check). Verified
- IACS UR E26 (Apr 2022; Rev.1 Nov 2023) — Cyber resilience of ships. §1.3, §2, §4.1.1.1, §4.1.1.3.2, §4.2.1.1, §4.2.1.3, §4.2.4.3.2, §4.2.4.3.4, §4.2.4.4.1, §4.2.6.3.2, §6.
- IACS UR E27 Rev.1 (Sep 2023) — Cyber resilience of on-board systems and equipment. §1.3, §4.1 Table 1 items 1, 12, 18, 20.
- IACS UR E22 Rev.3 §3.3 — On-board use and application of programmable electronic systems.
- IBC Code 15.19.5–15.19.7 — Overfill control (cited only for typology contrast).

**Historical**

- December 1969, cargo tank explosions aboard Marpessa, Mactra and Kong Haakon VII — static discharge during tank cleaning. Per-ship detail rests on secondary sources. Verified (multiple concurring sources)
- February 1978, TSPP Conference, 1978 Protocol to MARPOL 73\. Verified
- UK P&I Club, *Carefully to Carry* — bulk oil cargo shortage and contamination claims (clingage quantity, order of magnitude only). Typical

**Not established**

- Any public casualty investigation report attributing a casualty to the COW operation itself — not found. Unknown

Article classification

Analysis unit: **Interaction** (not interface)

Typology coverage: 4/4 confirmed; 5/5 component rows explained by confirmed doctrine

Evidence ceiling: TYP-A04 Typical / TYP-A05 Typical / TYP-B02 Inferred / TYP-B08 Typical

Authority envelope: outbound A0–A5, inbound A0–A7

Physical effect: P0–P4 (**P5 not assigned** to this system — see §11)

Architecture: UNKNOWN → presented as variants A / B / C

Accident evidence: none found → §15 and §16 are rule-derived, not incident-derived