Water ISAC’s 15 Cybersecurity Fundamentals for Water and Wastewater Utilities
Last week WaterISAC released its 15 Cybersecurity Fundamentals for Water and Wastewater Utilities. This is a completely updated guide of the 2012 version that addresses the expanding threats to the water sector. The guide organizes several best practices into 15 categories, which water utilities can use to mitigate security risks in information and operational technology. Within this guide are links to technical resources, allowing users to further investigate issues as needed.
Additionally, the updated guide will be helpful for utilities in preparation of risk and resilience assessments required under AWIA. The 15 Fundamentals are also beneficial for informing emergency response plans that address mitigation and resilience options under AWIA.
The 15 Fundamentals:
- Perform Asset Inventories
- Assess Risks
- Minimize Control System Exposure
- Enforce User Access Controls
- Safeguard from Unauthorized Physical Access
- Install Independent Cyber-Physical Safety Systems
- Embrace Vulnerability Management
- Create a Cybersecurity Culture
- Develop and Enforce Cybersecurity Policies and Procedures
- Implement Threat Detection and Monitoring
- Plan for Incidents, Emergencies, and Disasters
- Tackle Insider Threats
- Secure the Supply Chain
- Address All Smart Devices (IoT, IIoT, Mobile, etc.)
- Participate in Information Sharing and Collaboration Communities