AWIA Section 2013 requires covered community water systems to address cybersecurity as part of their Risk and Resilience Assessments and Emergency Response Plans. Use this checklist to review key cybersecurity controls and the types of evidence that may help support your assessment and planning, including remote access, third-party access, OT network boundaries, session logging, and documentation.
This checklist is provided for informational purposes only and should not be considered an AWIA certification, legal opinion, or determination of compliance. The practices listed are not individual AWIA statutory requirements unless the applicable law or EPA guidance specifically supports that statement.