Skip to content

Evidence request lists

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

AWWA-G430-5
Access Control for SCADA and Control Systems

Apply role-based access, MFA, and least privilege to SCADA, HMIs, and engineering workstations.

Artefacts an auditor will ask for
  • RBAC matrix
  • MFA enrollment evidence
  • Privileged account list
Where this commonly fails
  • Shared operator accounts
  • No MFA on jump hosts
AWWA-G430-6
Remote Access Management

Control vendor and operator remote access to control systems via approved, monitored channels with session logging.

Artefacts an auditor will ask for
  • Remote access policy
  • Vendor access logs
  • Session recordings
Where this commonly fails
  • Always-on vendor VPN
  • No session timeout

Access Control and Identity Management

AWWA-2.1
User Access Management

Implement access controls based on least privilege principles for both IT and operational technology environments.

Artefacts an auditor will ask for
  • Joiner mover leaver records and access review evidence
  • MFA enforcement screenshots from IdP
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Privileged accounts lack just in time elevation
  • Quarterly access reviews not completed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-2.2
Authentication Mechanisms

Deploy strong authentication mechanisms including multi-factor authentication for remote access to control systems.

Artefacts an auditor will ask for
  • Joiner mover leaver records and access review evidence
  • MFA enforcement screenshots from IdP
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Privileged accounts lack just in time elevation
  • Quarterly access reviews not completed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-2.3
Account Management

Establish procedures for provisioning, reviewing, and revoking user accounts including shared and service accounts.

Artefacts an auditor will ask for
  • Joiner mover leaver records and access review evidence
  • MFA enforcement screenshots from IdP
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Privileged accounts lack just in time elevation
  • Quarterly access reviews not completed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-2.4
Physical Access Controls

Implement physical access controls at facilities housing critical control systems and network infrastructure.

Artefacts an auditor will ask for
  • Joiner mover leaver records and access review evidence
  • MFA enforcement screenshots from IdP
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Privileged accounts lack just in time elevation
  • Quarterly access reviews not completed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Architecture

AWWA-G430-4
Network Segmentation IT/OT

Segment IT and OT networks using firewalls, DMZs, and unidirectional gateways where feasible.

Artefacts an auditor will ask for
  • Segmentation diagram
  • Firewall rulesets
  • DMZ design
Where this commonly fails
  • Flat network
  • Remote access bypasses DMZ

Asset Management

AWWA-G430-2
Asset Inventory and Classification

Maintain a current inventory of IT and OT assets including SCADA, PLCs, HMIs, sensors, and supporting networks.

Artefacts an auditor will ask for
  • Asset register
  • SCADA inventory
  • Network diagrams
Where this commonly fails
  • OT assets missing
  • No criticality rating

Configuration

AWWA-G430-18
Configuration and Change Management for OT

Manage changes to PLC logic, HMI screens, network devices, and firewall rules through documented change control.

Artefacts an auditor will ask for
  • CAB records
  • Baseline configs
  • Change tickets
Where this commonly fails
  • No PLC logic versioning
  • Emergency changes undocumented

Governance

AWWA-G430-1
Cybersecurity Program Governance

Establish a documented cybersecurity program with executive sponsorship covering IT and OT environments at the water utility.

Artefacts an auditor will ask for
  • Cybersecurity charter
  • Executive sponsorship memo
  • Org chart
Where this commonly fails
  • No OT scope
  • No board reporting

Improvement

AWWA-G430-21
Cybersecurity Program Review

Review the cybersecurity program annually and after material incidents to update controls and priorities.

Artefacts an auditor will ask for
  • Annual review report
  • Action plan
  • Board readout
Where this commonly fails
  • No annual review evidence

Incident Response

AWWA-G430-10
Incident Response for Water Utilities

Maintain an incident response plan addressing cyber events with potential to impact water quality or service delivery.

Artefacts an auditor will ask for
  • IR plan
  • Playbooks
  • Exercise reports
  • CISA reporting procedure
Where this commonly fails
  • No manual operations procedure
  • No coordination with state primacy agency

Monitoring

AWWA-G430-16
Logging and Audit

Collect and retain logs from IT, OT, network, and physical access systems sufficient to support investigation.

Artefacts an auditor will ask for
  • Log sources inventory
  • Retention schedule
  • SIEM dashboards
Where this commonly fails
  • OT logs not collected
  • Retention too short
AWWA-G430-9
Boundary Protection and Monitoring

Monitor IT and OT network boundaries for malicious activity using IDS/IPS or passive OT monitoring.

Artefacts an auditor will ask for
  • IDS/IPS config
  • OT passive monitor reports
  • SOC playbooks
Where this commonly fails
  • No OT visibility
  • Alerts not triaged

Network and Communications Security

AWWA-3.1
Network Segmentation

Segment IT and operational technology networks to limit lateral movement and contain potential compromises.

Artefacts an auditor will ask for
  • Network segmentation diagram with trust zones
  • Firewall ruleset review evidence
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Flat network between OT and IT
  • Stale firewall rules without owners
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-3.2
Remote Access Security

Secure remote access connections to SCADA and control systems with encryption and monitoring.

Artefacts an auditor will ask for
  • Network segmentation diagram with trust zones
  • Firewall ruleset review evidence
  • OT asset inventory and network diagram
  • ICS specific incident playbook
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Flat network between OT and IT
  • Stale firewall rules without owners
  • IT and OT response teams not aligned
  • ICS forensics tooling not in place
  • Evidence is point in time rather than ongoing
AWWA-3.3
Wireless Security

Implement security controls for wireless communications used in water utility operations.

Artefacts an auditor will ask for
  • Network segmentation diagram with trust zones
  • Firewall ruleset review evidence
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Flat network between OT and IT
  • Stale firewall rules without owners
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-3.4
Encryption and Data Protection

Apply encryption to protect data in transit and at rest for sensitive operational and customer data.

Artefacts an auditor will ask for
  • Data classification scheme and inventory
  • Encryption key management procedure
  • Network segmentation diagram with trust zones
  • Firewall ruleset review evidence
  • OT asset inventory and network diagram
  • ICS specific incident playbook
Where this commonly fails
  • Data inventory misses shadow IT stores
  • Encryption key rotation evidence missing
  • Flat network between OT and IT
  • Stale firewall rules without owners
  • IT and OT response teams not aligned

Personnel

AWWA-G430-14
Personnel Security and Insider Threat

Conduct background screening for personnel with access to treatment and SCADA systems and monitor for insider risk.

Artefacts an auditor will ask for
  • Background check policy
  • Access revocation log
  • Insider threat indicators
Where this commonly fails
  • No revocation on termination
  • No periodic re-check

Physical

AWWA-G430-17
Physical Security of Cyber Assets

Protect physical access to control rooms, network closets, RTUs, and field cabinets from tampering.

Artefacts an auditor will ask for
  • Access logs
  • CCTV
  • Tamper alarms
  • Cabinet inspection records
Where this commonly fails
  • Unlocked field cabinets
  • No tamper alerting

Protection

AWWA-G430-8
Malware Protection

Deploy and maintain anti-malware on IT endpoints and approved application allowlisting on OT endpoints.

Artefacts an auditor will ask for
  • EDR coverage report
  • Allowlisting policy
  • HMI exception list
Where this commonly fails
  • No OT allowlisting
  • Signature updates lag

Recovery

AWWA-G430-12
Backup and Recovery for Control Systems

Back up SCADA configurations, PLC logic, historian data, and HMI projects with tested restoration procedures.

Artefacts an auditor will ask for
  • Backup schedule
  • Restoration test logs
  • Offline copy verification
Where this commonly fails
  • No PLC logic backup
  • No offline copy
  • Restore never tested

Regulatory

AWWA-G430-19
AWIA Risk and Resilience Assessment Compliance

Conduct and certify Risk and Resilience Assessment and Emergency Response Plan under America's Water Infrastructure Act Section 2013.

Artefacts an auditor will ask for
  • RRA report
  • ERP
  • EPA certification records
Where this commonly fails
  • Not refreshed every 5 years
  • Cyber section thin

Reporting

AWWA-G430-20
Information Sharing and Reporting

Report cyber incidents to CISA, EPA, and WaterISAC and participate in sector information sharing.

Artefacts an auditor will ask for
  • WaterISAC membership
  • CIRCIA reporting procedure
  • Incident notifications
Where this commonly fails
  • No CIRCIA awareness
  • No WaterISAC account

Resilience

AWWA-G430-11
Manual Operations Capability

Document and exercise procedures to operate critical water functions manually during a cyber event.

Artefacts an auditor will ask for
  • Manual ops procedures
  • Operator drill records
  • Bypass procedures
Where this commonly fails
  • No documented manual mode
  • Operators not trained

Risk

AWWA-G430-3
Risk Assessment for Water Systems

Conduct risk assessments addressing threats to source water, treatment, distribution, and customer systems including cyber-physical impacts.

Artefacts an auditor will ask for
  • Risk assessment report
  • Threat scenarios
  • Consequence ratings
Where this commonly fails
  • No cyber-physical scenario
  • No public health consequence rating

Security Management and Governance

AWWA-1.1
Security Policy and Governance

Establish and maintain a cybersecurity policy with defined roles, responsibilities, and management oversight.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Signed and dated policy set with version history
  • Annual review and approval records
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Evidence is point in time rather than ongoing
AWWA-1.2
Risk Assessment

Conduct risk assessments to identify threats and vulnerabilities to water utility control systems and IT infrastructure.

Artefacts an auditor will ask for
  • Risk register with likelihood, impact, and treatment plans
  • Risk assessment methodology document
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Risk register not refreshed on a defined cadence
  • Inherent vs residual risk scoring not documented
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Evidence is point in time rather than ongoing
AWWA-1.3
Security Awareness and Training

Implement a security awareness programme for all personnel including role-based training for operational technology staff.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Training completion records by role
  • Phishing simulation results
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Role based training not delivered to high risk teams
  • Training metrics not reported to leadership
  • Evidence is point in time rather than ongoing
AWWA-1.4
Compliance and Regulatory Alignment

Align cybersecurity practices with NIST CSF and AWIA Section 2013 requirements for water infrastructure security.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Supply Chain

AWWA-G430-13
Supply Chain and Vendor Risk

Assess cybersecurity risk of vendors providing control system hardware, software, integration, and remote support.

Artefacts an auditor will ask for
  • Vendor risk register
  • Contract clauses
  • SBOM where available
Where this commonly fails
  • No vendor risk tier
  • No SBOM requirements

System Security and Operations

AWWA-4.1
Malware Protection

Deploy and maintain anti-malware solutions on IT systems and where feasible on operational technology endpoints.

Artefacts an auditor will ask for
  • Patch SLAs and exception register
  • Vulnerability scan reports with remediation tickets
  • OT asset inventory and network diagram
  • ICS specific incident playbook
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Critical patches exceeding SLA
  • Hardening baselines not enforced through configuration management
  • IT and OT response teams not aligned
  • ICS forensics tooling not in place
  • Evidence is point in time rather than ongoing
AWWA-4.2
Patch Management

Establish a patch management process for timely application of security updates to IT and OT systems.

Artefacts an auditor will ask for
  • Patch SLAs and exception register
  • Vulnerability scan reports with remediation tickets
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Critical patches exceeding SLA
  • Hardening baselines not enforced through configuration management
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-4.3
Configuration Management

Maintain secure baseline configurations for all systems and monitor for unauthorised changes.

Artefacts an auditor will ask for
  • Patch SLAs and exception register
  • Vulnerability scan reports with remediation tickets
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Critical patches exceeding SLA
  • Hardening baselines not enforced through configuration management
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
AWWA-4.4
Audit Logging and Monitoring

Implement logging and monitoring to detect security events across IT and operational technology environments.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing

Training

AWWA-G430-15
Cybersecurity Training for Operators

Provide role-specific cybersecurity training to IT staff, operators, and engineers including phishing awareness.

Artefacts an auditor will ask for
  • Training matrix
  • Phishing test results
  • Operator-specific modules
Where this commonly fails
  • Generic training only
  • Operators excluded

Vulnerability

AWWA-G430-7
Patch and Vulnerability Management

Identify, prioritize, and remediate vulnerabilities in IT and OT systems with vendor coordination for OT patches.

Artefacts an auditor will ask for
  • Vuln scan reports
  • Patch records
  • OT change calendar
Where this commonly fails
  • OT systems unpatched for years
  • No compensating controls documented
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) framework page.