15.2 Vulnerability Assessments & Routine Security Checks
Key Takeaways
- Assess threats and hazards against critical wastewater services and dependencies.
- Use layered physical and OT controls with tested response.
- Document and escalate anomalies without destroying evidence.
- Follow applicable local requirements; do not invent a nationwide wastewater AWIA threshold.
15.2 Vulnerability Assessments & Routine Security Checks
2025 WPI alignment: This section teaches establishing/updating vulnerability-assessment procedures and conducting routine security checks in Security, Safety, and Administrative Procedures, the 15-question area containing 9 recall, 6 application, and 1 calculation item.
Why this responsibility matters
Security work identifies critical assets, plausible hazards or threats, consequences, existing controls, and practical improvements. The 2025 WPI outline requires vulnerability assessment and security checks but does not make the drinking-water AWIA Section 2013 mandate a universal wastewater requirement.
Core program elements
| Element | Class III responsibility |
|---|---|
| All-hazards view | Natural hazards, accidents, cyber events, vandalism, insider actions, supply interruption, and utility failure can disrupt treatment. |
| Critical asset | Consequence and recovery time determine priority; a small component can be critical if no bypass or spare exists. |
| Layered security | Perimeter, access control, lighting, locks, cameras, detection, inventories, staff practices, and response provide defense in depth. |
| Operational technology | Accounts, remote access, backups, segmentation, change control, logging, and manual fallback protect SCADA/PLC functions. |
| Routine check | A defined route verifies gates, doors, hatches, chemical areas, power, communications, tamper evidence, and abnormal activity. |
| Sensitive information | Assessment details and system diagrams are shared only with authorized roles and stored under applicable policy. |
Work sequence
- Define system boundaries, essential services, critical assets, dependencies, credible hazards/threats, and consequence categories.
- Walk down physical and cyber controls with operations, maintenance, IT/OT, safety, laboratory, management, and emergency partners.
- Rank gaps using the approved method and assign owners, interim controls, funding, and completion dates.
- Create daily/shift security rounds with expected condition, escalation criteria, and tamper-preserving documentation.
- On anomaly, avoid disturbing evidence, protect people/process, notify security/management/law enforcement or cyber response as applicable, and use fallback operations.
- Test improvements and response through drills, restore/recover, capture lessons, and update the assessment after material changes.
Warning signs and response
| Finding | Meaning | Defensible response |
|---|---|---|
| Gate open without work record | Access control or turnover failed | Secure if safe, preserve evidence, and notify under the plan. |
| New remote connection unlisted | Asset inventory/change control is incomplete | Isolate or review through authorized cyber response. |
| Camera works but area is unlit | Detection and identification may fail at night | Correct the layered control rather than counting device presence. |
| Same critical spare remains unavailable | Supply-chain vulnerability is unresolved | Escalate alternate sourcing, redundancy, or contingency operation. |
Calculation, decision, or documentation connection
Risk-ranking methods may combine likelihood, consequence, detectability, or recovery time, but use the method supplied by the question or facility. A score is a prioritization aid, not proof that low-ranked hazards need no control. Emergency-power duration can be estimated from usable fuel and verified consumption, with reserve and load assumptions documented. Do not claim a universal federal wastewater population threshold that WPI does not publish.
Worked supervisory scenario
A wastewater operator discovers an unfamiliar remote-access device on the control network. The correct response is not to explore it from a production HMI or assume AWIA paperwork covers the issue. The operator preserves the condition, follows the OT incident plan, notifies authorized cyber/management staff, isolates access when directed, and maintains treatment through approved fallback controls.
Common exam traps
- AWIA Section 2013’s community-water-system population mandate must not be presented as a universal wastewater requirement.
- A vulnerability assessment is not a public checklist of exploitable details.
- A camera or locked gate is only one layer and requires testing and response.
- Cybersecurity includes availability and safe process control, not just data secrecy.
Field-to-exam checklist
- Assess threats and hazards against critical wastewater services and dependencies.
- Use layered physical and OT controls with tested response.
- Document and escalate anomalies without destroying evidence.
- Follow applicable local requirements; do not invent a nationwide wastewater AWIA threshold.
Recovery as part of security
Protection is incomplete without a tested way to restore treatment. Keep offline or otherwise protected backups of critical control configurations, current contact lists, manual operating instructions, and prioritized restart sequences. Test restoration on an authorized nonproduction basis and record the time and dependencies. A backup that cannot be read, a spare that lacks firmware, or a manual procedure for obsolete equipment is not recovery capability.
Frameworks, segmentation, and what actually applies
Know exactly what the AWIA requirement covers. America's Water Infrastructure Act Section 2013 requires risk and resilience assessments and emergency response plans for community drinking-water systems serving more than 3,300 people. It does not, by itself, impose that statutory requirement on a wastewater utility. Wastewater security obligations come instead from state programs, permit conditions, local policy, and voluntary frameworks — and a Class III operator should be able to say that plainly rather than repeating a drinking-water threshold as though it were universal.
Useful voluntary references include the NIST Cybersecurity Framework, CISA's water and wastewater sector guidance and no-cost vulnerability scanning services, EPA's Vulnerability Self-Assessment Tool, and WaterISAC advisories. None is a mandate; all provide a defensible structure for an assessment.
The operational-technology controls that repeatedly matter are unglamorous:
- unique named accounts with no shared operator login, so an action can be attributed;
- multi-factor authentication on every remote-access path;
- network segmentation between the business network and the control network, with a controlled boundary rather than a flat network;
- removal of default vendor passwords on PLCs, HMIs, drives, and network gear;
- unused physical and logical ports disabled;
- configuration and program backups kept offline and periodically restored on a test basis.
Real incidents in this sector have overwhelmingly involved exposed remote-access tools and unchanged default credentials, not sophisticated intrusion — which means the highest-value work is also the least glamorous.
A security round only produces value if a deviation triggers a response. Recording "all normal" without physically checking a hatch, a chemical-storage gate, or a control cabinet is a paperwork control. Define the expected condition, the escalation criterion, and how evidence is preserved before the round is written.
Does the 2025 WPI Class III outline establish a universal AWIA Section 2013 population threshold for wastewater facilities?
An unknown remote-access device appears on the plant control network. What is the defensible first response?