<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<dokAAPp xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="../../../../../../prj/bin/GuidICS/dokAAPp.xsd">
    <author>
        <individual>
            <ind firstName="Robert" ini="RS" msr="Mr" org="NIK" role="draft" surName="Skowroński"/>
            <ind firstName="Paweł" ini="pb" msr="Mr" org="NIK" role="review" surName="Banaś"/>
        </individual>
        <organization>
            <org kraj="USA" nm="US Government Accountability Office" skr="GAO" www="www.gao.gov"/>
        </organization>
    </author>
    <about caseNumber="4" file="cybersecurityWaters" folder="C:\pb\algorytm\SAI_robo\US\2024\cybersecurityWaters" id="US2024cybersecurityWaters" issueYear="2024" waga="247">
        <tyt>
            <tx file="cybersecurityWaters.pdf" l="en" nm="Critical Infrastructure Protection: EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems" typDok="original_document"/>
        </tyt>
        <portfolio>
            <pfl zn="cybersecurity"/>
        </portfolio>
        <ver put="202609181528" stage="final"/>
        <ver put="202501090712" stage="final"/>
        <ver put="202411181052" stage="draft"/>
        <ver put="202411181020" stage="pre-draft"/>
        <ver put="202409190804" stage="pre-draft"/>
    </about>
    <part id="lead">
        <tyt>
            <tx l="en" nm="The water sector faces increasing cybersecurity-related risks"/>
        </tyt>
        <narrative>
            <narr l="en">
                <ak nr="1">The audit asks how exposed the country's water and wastewater systems are to cyber attack, and what the federal government is doing about it; the cases below trace a single problem through four stages. At the operator end, improving cybersecurity is voluntary while delivering clean and safe water is not, so it loses the contest for money, and what investment there is runs into skills gaps and equipment too old to patch. The tool the agency gives systems for assessing their own risk has never been peer reviewed, so the sector's picture of itself rests on an untested instrument. Above that, no sector-wide risk assessment has been made at all, leaving federal action without a risk-informed strategy to aim it. And nobody knows the true extent of what has already happened, because incident reporting is still being designed - and the rules as drafted would exempt most of the sector from it.</ak>
            </narr>
        </narrative>
    </part>
    <part id="background" v="01">
        <tyt>
            <tx l="en" nm="Background"/>
        </tyt>
        <part id="scale">
            <tyt>
                <tx l="en" nm="Scale"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">About 170,000 water and wastewater systems make up the US water sector.</ak>
                    <ak tp="li">Cyber incidents over the past five years have already disrupted system operations.</ak>
                    <ak tp="li">The national incident-reporting rules being developed would exempt almost 80 percent of those systems.</ak>
                </narr>
            </narrative>
        </part>
        <part id="compliance">
            <tyt>
                <tx l="en" nm="Compliance"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">A water infrastructure act requires drinking-water systems to assess risk and resilience and to maintain emergency response plans.</ak>
                    <ak tp="li">Homeland-security and critical-infrastructure statutes, with a national protection plan and a presidential security memorandum, assign responsibility for the sector.</ak>
                    <ak tp="li">A separate act on cyber incident reporting for critical infrastructure is the basis for the reporting rules still being written.</ak>
                </narr>
            </narrative>
        </part>
        <part id="perfromance">
            <tyt>
                <tx l="en" nm="Performance"/>
            </tyt>
            <part id="economy">
                <tyt>
                    <tx l="en" nm="Economy"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">The sector has made limited investment in cybersecurity: systems put funding first toward their regulatory duty to deliver clean and safe water.</ak>
                        <ak tp="li">Improving cybersecurity is voluntary, so it competes for money against obligations that are not.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="efficiency">
                <tyt>
                    <tx l="en" nm="Efficiency"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">Federal and non-federal bodies issue alerts and advisories, run outreach, fund research and distribute best practice - activity not steered by any assessment of where the risk actually sits.</ak>
                        <ak tp="li">The self-assessment tool offered to water systems has never been peer reviewed.</ak>
                        <ak tp="li">Workforce skills gaps and technology too old to update easily slow protection at the operator end.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="effectiveness">
                <tyt>
                    <tx l="en" nm="Effectiveness"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">No comprehensive sector-wide risk assessment exists, and no risk-informed strategy guides federal action.</ak>
                        <ak tp="li">The full extent of incidents and their consequences is unknown, because reporting is not yet required.</ak>
                        <ak tp="li">The reporting rules under development would leave almost 80 percent of systems outside them.</ak>
                    </narr>
                </narrative>
            </part>
        </part>
    </part>
    <part id="cases" v="01">
        <tyt>
            <tx l="en" nm="Cases"/>
        </tyt>
        <ctsy>
            <gr gn="area">
                <cts id="cybersecurity"/>
                <cts id="water-management"/>
            </gr>
            <gr gn="ins">
                <cts id="central-government"/>
                <cts id="government-agency"/>
                <cts id="federated-entity"/>
                <cts id="local-authority"/>
                <cts id="private-company"/>
            </gr>
            <gr gn="control">
                <cts id="guidance"/>
                <cts id="product"/>
                <cts id="testing"/>
                <cts id="goalsetting"/>
                <cts id="design"/>
                <cts id="incident_management"/>
                <cts id="reporting"/>
            </gr>
            <gr gn="value">
                <cts id="human_capital"/>
                <cts id="asset"/>
                <cts id="domain_knowledge"/>
                <cts id="regulatory_system"/>
            </gr>
            <gr gn="fun">
                <cts id="security"/>
                <cts id="IT"/>
                <cts id="productServiceDelivery"/>
                <cts id="strategy"/>
            </gr>
            <gr gn="quality">
                <cts id="adequateResourcesCompetences"/>
                <cts id="appropriateUseOfTechnology"/>
                <cts id="reliableInformationBase"/>
                <cts id="soundRiskManagement"/>
                <cts id="clearObjectives"/>
                <cts id="functioningOversight"/>
            </gr>
            <gr gn="sta">
                <cts id="operator"/>
                <cts id="user"/>
                <cts id="policy-setter"/>
            </gr>
        </ctsy>
        <part id="cybersecurityVoluntarySoIt">
            <tyt>
                <tx l="en" nm="Cybersecurity is voluntary, so it loses the funding contest to mandatory water-quality duties"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="2" ref="draft draft" tp="xm" zn="US2024cybersecurityWaters">Federal agencies 'reported challenges such as workforce skills gaps and older technologies that are difficult to update with cybersecurity protections. Further, the sector has made limited investments in cybersecurity protections because water systems prioritize funding to meet regulatory requirements for clean and safe water, while improving cybersecurity is voluntary.' Guidance that asks rather than requires, set against duties that do require, with the gap widened by the Human capital and the ageing Assets available to close it.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="guidance"/>
                </gr>
                <gr gn="value">
                    <cts id="human_capital"/>
                    <cts id="asset"/>
                </gr>
                <gr gn="fun">
                    <cts id="security"/>
                    <cts id="IT"/>
                </gr>
                <gr gn="quality">
                    <cts id="adequateResourcesCompetences"/>
                    <cts id="appropriateUseOfTechnology"/>
                </gr>
                <gr gn="sta">
                    <cts id="operator"/>
                </gr>
            </ctsy>
        </part>
        <part id="selfAssessmentToolGiven">
            <tyt>
                <tx l="en" nm="The self-assessment tool given to the sector was never peer reviewed"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="3" ref="draft draft" tp="xm" zn="US2024cybersecurityWaters">To help drinking water systems conduct risk and resilience assessments and develop emergency response plans, as required, the agency developed a Vulnerability Self-Assessment Tool. 'However, EPA has not had VSAT peer reviewed to ensure the tool provides systems with sound and credible information.' A Product released into the sector without the Testing that would establish it, so the sector's picture of its own risk rests on an unverified instrument.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="product"/>
                    <cts id="testing"/>
                </gr>
                <gr gn="value">
                    <cts id="domain_knowledge"/>
                </gr>
                <gr gn="fun">
                    <cts id="productServiceDelivery"/>
                </gr>
                <gr gn="quality">
                    <cts id="reliableInformationBase"/>
                </gr>
                <gr gn="sta">
                    <cts id="user"/>
                </gr>
            </ctsy>
        </part>
        <part id="sectorWideRiskAssessment">
            <tyt>
                <tx l="en" nm="No sector-wide risk assessment exists, so federal action has nothing to aim at"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="4" ref="draft draft" tp="xm" zn="US2024cybersecurityWaters">The agency 'has not conducted a comprehensive sector-wide risk assessment or used a risk-informed strategy to guide its actions to improve the water sector's level of cybersecurity'. The audit office had previously found that a risk-informed strategy improves the effectiveness of agency efforts to build critical-infrastructure cybersecurity programmes. A Goal-setting absence upstream of everything else: without the assessment there is no Design basis for choosing what to do first.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="goalsetting"/>
                    <cts id="design"/>
                </gr>
                <gr gn="fun">
                    <cts id="strategy"/>
                </gr>
                <gr gn="quality">
                    <cts id="soundRiskManagement"/>
                    <cts id="clearObjectives"/>
                </gr>
                <gr gn="sta">
                    <cts id="policy-setter"/>
                </gr>
            </ctsy>
        </part>
        <part id="incidentReportingBeingDesigned">
            <tyt>
                <tx l="en" nm="Incident reporting is still being designed, and would exempt most of the sector"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="5" ref="draft draft" tp="xm" zn="US2024cybersecurityWaters">'Cybersecurity incidents in the U.S. over the past 5 years have disrupted water and wastewater system operations. However, the full extent of such incidents and their consequences are unknown because national level cybersecurity incident reporting requirements are under development, and water and wastewater systems have not yet been required to report incidents to the federal government.' Officials add that the national-level requirements as drafted 'would exempt almost 80 percent of water and wastewater systems from reporting'. Incident management with no Reporting obligation behind it, which leaves the regulator without the evidence its own strategy would need.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="incident_management"/>
                    <cts id="reporting"/>
                </gr>
                <gr gn="value">
                    <cts id="regulatory_system"/>
                </gr>
                <gr gn="fun">
                    <cts id="security"/>
                </gr>
                <gr gn="quality">
                    <cts id="reliableInformationBase"/>
                    <cts id="functioningOversight"/>
                </gr>
                <gr gn="sta">
                    <cts id="policy-setter"/>
                </gr>
            </ctsy>
        </part>
    </part>
</dokAAPp>
