AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Apply role-based access, MFA, and least privilege to SCADA, HMIs, and engineering workstations.
- RBAC matrix
- MFA enrollment evidence
- Privileged account list
- Shared operator accounts
- No MFA on jump hosts
Control vendor and operator remote access to control systems via approved, monitored channels with session logging.
- Remote access policy
- Vendor access logs
- Session recordings
- Always-on vendor VPN
- No session timeout
Access Control and Identity Management
Implement access controls based on least privilege principles for both IT and operational technology environments.
- Joiner mover leaver records and access review evidence
- MFA enforcement screenshots from IdP
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Privileged accounts lack just in time elevation
- Quarterly access reviews not completed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Deploy strong authentication mechanisms including multi-factor authentication for remote access to control systems.
- Joiner mover leaver records and access review evidence
- MFA enforcement screenshots from IdP
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Privileged accounts lack just in time elevation
- Quarterly access reviews not completed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Establish procedures for provisioning, reviewing, and revoking user accounts including shared and service accounts.
- Joiner mover leaver records and access review evidence
- MFA enforcement screenshots from IdP
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Privileged accounts lack just in time elevation
- Quarterly access reviews not completed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Implement physical access controls at facilities housing critical control systems and network infrastructure.
- Joiner mover leaver records and access review evidence
- MFA enforcement screenshots from IdP
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Privileged accounts lack just in time elevation
- Quarterly access reviews not completed
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Architecture
Segment IT and OT networks using firewalls, DMZs, and unidirectional gateways where feasible.
- Segmentation diagram
- Firewall rulesets
- DMZ design
- Flat network
- Remote access bypasses DMZ
Asset Management
Maintain a current inventory of IT and OT assets including SCADA, PLCs, HMIs, sensors, and supporting networks.
- Asset register
- SCADA inventory
- Network diagrams
- OT assets missing
- No criticality rating
Configuration
Manage changes to PLC logic, HMI screens, network devices, and firewall rules through documented change control.
- CAB records
- Baseline configs
- Change tickets
- No PLC logic versioning
- Emergency changes undocumented
Governance
Establish a documented cybersecurity program with executive sponsorship covering IT and OT environments at the water utility.
- Cybersecurity charter
- Executive sponsorship memo
- Org chart
- No OT scope
- No board reporting
Improvement
Review the cybersecurity program annually and after material incidents to update controls and priorities.
- Annual review report
- Action plan
- Board readout
- No annual review evidence
Incident Response
Maintain an incident response plan addressing cyber events with potential to impact water quality or service delivery.
- IR plan
- Playbooks
- Exercise reports
- CISA reporting procedure
- No manual operations procedure
- No coordination with state primacy agency
Monitoring
Collect and retain logs from IT, OT, network, and physical access systems sufficient to support investigation.
- Log sources inventory
- Retention schedule
- SIEM dashboards
- OT logs not collected
- Retention too short
Monitor IT and OT network boundaries for malicious activity using IDS/IPS or passive OT monitoring.
- IDS/IPS config
- OT passive monitor reports
- SOC playbooks
- No OT visibility
- Alerts not triaged
Network and Communications Security
Segment IT and operational technology networks to limit lateral movement and contain potential compromises.
- Network segmentation diagram with trust zones
- Firewall ruleset review evidence
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Flat network between OT and IT
- Stale firewall rules without owners
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Secure remote access connections to SCADA and control systems with encryption and monitoring.
- Network segmentation diagram with trust zones
- Firewall ruleset review evidence
- OT asset inventory and network diagram
- ICS specific incident playbook
- Process owner attestation
- Tooling configuration export
- Flat network between OT and IT
- Stale firewall rules without owners
- IT and OT response teams not aligned
- ICS forensics tooling not in place
- Evidence is point in time rather than ongoing
Implement security controls for wireless communications used in water utility operations.
- Network segmentation diagram with trust zones
- Firewall ruleset review evidence
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Flat network between OT and IT
- Stale firewall rules without owners
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Apply encryption to protect data in transit and at rest for sensitive operational and customer data.
- Data classification scheme and inventory
- Encryption key management procedure
- Network segmentation diagram with trust zones
- Firewall ruleset review evidence
- OT asset inventory and network diagram
- ICS specific incident playbook
- Data inventory misses shadow IT stores
- Encryption key rotation evidence missing
- Flat network between OT and IT
- Stale firewall rules without owners
- IT and OT response teams not aligned
Personnel
Conduct background screening for personnel with access to treatment and SCADA systems and monitor for insider risk.
- Background check policy
- Access revocation log
- Insider threat indicators
- No revocation on termination
- No periodic re-check
Physical
Protect physical access to control rooms, network closets, RTUs, and field cabinets from tampering.
- Access logs
- CCTV
- Tamper alarms
- Cabinet inspection records
- Unlocked field cabinets
- No tamper alerting
Protection
Deploy and maintain anti-malware on IT endpoints and approved application allowlisting on OT endpoints.
- EDR coverage report
- Allowlisting policy
- HMI exception list
- No OT allowlisting
- Signature updates lag
Recovery
Back up SCADA configurations, PLC logic, historian data, and HMI projects with tested restoration procedures.
- Backup schedule
- Restoration test logs
- Offline copy verification
- No PLC logic backup
- No offline copy
- Restore never tested
Regulatory
Conduct and certify Risk and Resilience Assessment and Emergency Response Plan under America's Water Infrastructure Act Section 2013.
- RRA report
- ERP
- EPA certification records
- Not refreshed every 5 years
- Cyber section thin
Reporting
Report cyber incidents to CISA, EPA, and WaterISAC and participate in sector information sharing.
- WaterISAC membership
- CIRCIA reporting procedure
- Incident notifications
- No CIRCIA awareness
- No WaterISAC account
Resilience
Document and exercise procedures to operate critical water functions manually during a cyber event.
- Manual ops procedures
- Operator drill records
- Bypass procedures
- No documented manual mode
- Operators not trained
Risk
Conduct risk assessments addressing threats to source water, treatment, distribution, and customer systems including cyber-physical impacts.
- Risk assessment report
- Threat scenarios
- Consequence ratings
- No cyber-physical scenario
- No public health consequence rating
Security Management and Governance
Establish and maintain a cybersecurity policy with defined roles, responsibilities, and management oversight.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Signed and dated policy set with version history
- Annual review and approval records
- Process owner attestation
- Tooling configuration export
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Policies past their review date
- No evidence policies were communicated to staff
- Evidence is point in time rather than ongoing
Conduct risk assessments to identify threats and vulnerabilities to water utility control systems and IT infrastructure.
- Risk register with likelihood, impact, and treatment plans
- Risk assessment methodology document
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Process owner attestation
- Tooling configuration export
- Risk register not refreshed on a defined cadence
- Inherent vs residual risk scoring not documented
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Evidence is point in time rather than ongoing
Implement a security awareness programme for all personnel including role-based training for operational technology staff.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Training completion records by role
- Phishing simulation results
- Process owner attestation
- Tooling configuration export
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Role based training not delivered to high risk teams
- Training metrics not reported to leadership
- Evidence is point in time rather than ongoing
Align cybersecurity practices with NIST CSF and AWIA Section 2013 requirements for water infrastructure security.
- Board or executive committee charter with security or risk remit
- RACI matrix for accountable owners
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Board reporting cadence not formalised
- Roles overlap without clear accountable owner
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Supply Chain
Assess cybersecurity risk of vendors providing control system hardware, software, integration, and remote support.
- Vendor risk register
- Contract clauses
- SBOM where available
- No vendor risk tier
- No SBOM requirements
System Security and Operations
Deploy and maintain anti-malware solutions on IT systems and where feasible on operational technology endpoints.
- Patch SLAs and exception register
- Vulnerability scan reports with remediation tickets
- OT asset inventory and network diagram
- ICS specific incident playbook
- Process owner attestation
- Tooling configuration export
- Critical patches exceeding SLA
- Hardening baselines not enforced through configuration management
- IT and OT response teams not aligned
- ICS forensics tooling not in place
- Evidence is point in time rather than ongoing
Establish a patch management process for timely application of security updates to IT and OT systems.
- Patch SLAs and exception register
- Vulnerability scan reports with remediation tickets
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Critical patches exceeding SLA
- Hardening baselines not enforced through configuration management
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Maintain secure baseline configurations for all systems and monitor for unauthorised changes.
- Patch SLAs and exception register
- Vulnerability scan reports with remediation tickets
- Process owner attestation
- Tooling configuration export
- Meeting minutes referencing the control
- Training material referencing the control
- Critical patches exceeding SLA
- Hardening baselines not enforced through configuration management
- Evidence is point in time rather than ongoing
- Control owner unclear or vacant
- No metric tracks control effectiveness
Implement logging and monitoring to detect security events across IT and operational technology environments.
- Incident response plan with playbooks per scenario
- SIEM log retention and alerting configuration
- Internal audit programme and findings log
- Management review meeting minutes with actions
- Process owner attestation
- Tooling configuration export
- Tabletop exercises not run in last 12 months
- Detection coverage not mapped to MITRE ATT&CK
- Audit findings without closure dates
- Management review skipped one or more cycles
- Evidence is point in time rather than ongoing
Training
Provide role-specific cybersecurity training to IT staff, operators, and engineers including phishing awareness.
- Training matrix
- Phishing test results
- Operator-specific modules
- Generic training only
- Operators excluded
Vulnerability
Identify, prioritize, and remediate vulnerabilities in IT and OT systems with vendor coordination for OT patches.
- Vuln scan reports
- Patch records
- OT change calendar
- OT systems unpatched for years
- No compensating controls documented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) framework page.