US Government Accountability Office GAO

Critical Infrastructure Protection: EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems

2024 US2024cybersecurityWaters — Categorised against INTOSAI ICS (GuidICS)
SCALE
  • About 170,000 water and wastewater systems make up the US water sector.
  • Cyber incidents over the past five years have already disrupted system operations.
  • The national incident-reporting rules being developed would exempt almost 80 percent of those systems.
COMPLIANCE
  • A water infrastructure act requires drinking-water systems to assess risk and resilience and to maintain emergency response plans.
  • Homeland-security and critical-infrastructure statutes, with a national protection plan and a presidential security memorandum, assign responsibility for the sector.
  • A separate act on cyber incident reporting for critical infrastructure is the basis for the reporting rules still being written.
ECONOMY
  • The sector has made limited investment in cybersecurity: systems put funding first toward their regulatory duty to deliver clean and safe water.
  • Improving cybersecurity is voluntary, so it competes for money against obligations that are not.
EFFICIENCY
  • Federal and non-federal bodies issue alerts and advisories, run outreach, fund research and distribute best practice - activity not steered by any assessment of where the risk actually sits.
  • The self-assessment tool offered to water systems has never been peer reviewed.
  • Workforce skills gaps and technology too old to update easily slow protection at the operator end.
EFFECTIVENESS
  • No comprehensive sector-wide risk assessment exists, and no risk-informed strategy guides federal action.
  • The full extent of incidents and their consequences is unknown, because reporting is not yet required.
  • The reporting rules under development would leave almost 80 percent of systems outside them.
1. Cybersecurity is voluntary, so it loses the funding contest to mandatory water-quality duties Guidance

Federal agencies 'reported challenges such as workforce skills gaps and older technologies that are difficult to update with cybersecurity protections. Further, the sector has made limited investments in cybersecurity protections because water systems prioritize funding to meet regulatory requirements for clean and safe water, while improving cybersecurity is voluntary.' Guidance that asks rather than requires, set against duties that do require, with the gap widened by the Human capital and the ageing Assets available to close it.

  • Function: Security, IT
  • Value: Human capital, Assets
  • Stakeholders: Operator
  • Quality: Adequate resources and competences Appropriate use of technology and automation
2. The self-assessment tool given to the sector was never peer reviewed Product Testing

To help drinking water systems conduct risk and resilience assessments and develop emergency response plans, as required, the agency developed a Vulnerability Self-Assessment Tool. 'However, EPA has not had VSAT peer reviewed to ensure the tool provides systems with sound and credible information.' A Product released into the sector without the Testing that would establish it, so the sector's picture of its own risk rests on an unverified instrument.

  • Function: Product/service delivery
  • Value: Domain knowledge
  • Stakeholders: User
  • Quality: Reliable, integrated information base
3. No sector-wide risk assessment exists, so federal action has nothing to aim at Goal-setting Design

The agency 'has not conducted a comprehensive sector-wide risk assessment or used a risk-informed strategy to guide its actions to improve the water sector's level of cybersecurity'. The audit office had previously found that a risk-informed strategy improves the effectiveness of agency efforts to build critical-infrastructure cybersecurity programmes. A Goal-setting absence upstream of everything else: without the assessment there is no Design basis for choosing what to do first.

  • Function: Strategy
  • Stakeholders: Policy setter
  • Quality: Sound risk management Clear objectives and goal-setting
4. Incident reporting is still being designed, and would exempt most of the sector Incident management Reporting

'Cybersecurity incidents in the U.S. over the past 5 years have disrupted water and wastewater system operations. However, the full extent of such incidents and their consequences are unknown because national level cybersecurity incident reporting requirements are under development, and water and wastewater systems have not yet been required to report incidents to the federal government.' Officials add that the national-level requirements as drafted 'would exempt almost 80 percent of water and wastewater systems from reporting'. Incident management with no Reporting obligation behind it, which leaves the regulator without the evidence its own strategy would need.

  • Function: Security
  • Value: Regulatory system
  • Stakeholders: Policy setter
  • Quality: Reliable, integrated information base Functioning oversight and governance
Control focus
ICS phaseControl functionCases
Initial phaseGuidance1. Cybersecurity is voluntary, so it loses the funding contest to mandatory water-quality duties
Goal-setting3. No sector-wide risk assessment exists, so federal action has nothing to aim at
Design3. No sector-wide risk assessment exists, so federal action has nothing to aim at
Completion of processProduct2. The self-assessment tool given to the sector was never peer reviewed
Work processesTesting2. The self-assessment tool given to the sector was never peer reviewed
Incident management4. Incident reporting is still being designed, and would exempt most of the sector
Functions applied to all stagesReporting4. Incident reporting is still being designed, and would exempt most of the sector
This page is part of CUBE, a knowledge-sharing initiative of the EUROSAI IT Working Group. Its purpose is to make what supreme audit institutions find easier to search, compare and reuse — by auditors, and by the wider public who rarely reach these reports in their original form. It presents an analysis prepared, with AI assistance, by Paweł Banaś (NIK — Najwyższa Izba Kontroli, Poland) on the basis of the publicly available report of US Government Accountability Office, categorised against the internal-control terminology of INTOSAI's Guidance on Auditing Internal Control (ICS), drafted by the Internal Control Standards Subcommittee, which NIK (Poland) chairs. The categorisation and the case selection are ours, not the audit institution's, and so is any error in them. Readers are warmly encouraged to go to the original report, linked above; this page is a way in, never a substitute. Underlying data.