15.2 Vulnerability Assessments & Routine Security Checks

Key Takeaways

  • Assess threats and hazards against critical wastewater services and dependencies.
  • Use layered physical and OT controls with tested response.
  • Document and escalate anomalies without destroying evidence.
  • Follow applicable local requirements; do not invent a nationwide wastewater AWIA threshold.
Last updated: September 2026

15.2 Vulnerability Assessments & Routine Security Checks

2025 WPI alignment: This section teaches establishing/updating vulnerability-assessment procedures and conducting routine security checks in Security, Safety, and Administrative Procedures, the 15-question area containing 9 recall, 6 application, and 1 calculation item.

Why this responsibility matters

Security work identifies critical assets, plausible hazards or threats, consequences, existing controls, and practical improvements. The 2025 WPI outline requires vulnerability assessment and security checks but does not make the drinking-water AWIA Section 2013 mandate a universal wastewater requirement.

Core program elements

ElementClass III responsibility
All-hazards viewNatural hazards, accidents, cyber events, vandalism, insider actions, supply interruption, and utility failure can disrupt treatment.
Critical assetConsequence and recovery time determine priority; a small component can be critical if no bypass or spare exists.
Layered securityPerimeter, access control, lighting, locks, cameras, detection, inventories, staff practices, and response provide defense in depth.
Operational technologyAccounts, remote access, backups, segmentation, change control, logging, and manual fallback protect SCADA/PLC functions.
Routine checkA defined route verifies gates, doors, hatches, chemical areas, power, communications, tamper evidence, and abnormal activity.
Sensitive informationAssessment details and system diagrams are shared only with authorized roles and stored under applicable policy.

Work sequence

  1. Define system boundaries, essential services, critical assets, dependencies, credible hazards/threats, and consequence categories.
  2. Walk down physical and cyber controls with operations, maintenance, IT/OT, safety, laboratory, management, and emergency partners.
  3. Rank gaps using the approved method and assign owners, interim controls, funding, and completion dates.
  4. Create daily/shift security rounds with expected condition, escalation criteria, and tamper-preserving documentation.
  5. On anomaly, avoid disturbing evidence, protect people/process, notify security/management/law enforcement or cyber response as applicable, and use fallback operations.
  6. Test improvements and response through drills, restore/recover, capture lessons, and update the assessment after material changes.

Warning signs and response

FindingMeaningDefensible response
Gate open without work recordAccess control or turnover failedSecure if safe, preserve evidence, and notify under the plan.
New remote connection unlistedAsset inventory/change control is incompleteIsolate or review through authorized cyber response.
Camera works but area is unlitDetection and identification may fail at nightCorrect the layered control rather than counting device presence.
Same critical spare remains unavailableSupply-chain vulnerability is unresolvedEscalate alternate sourcing, redundancy, or contingency operation.

Calculation, decision, or documentation connection

Risk-ranking methods may combine likelihood, consequence, detectability, or recovery time, but use the method supplied by the question or facility. A score is a prioritization aid, not proof that low-ranked hazards need no control. Emergency-power duration can be estimated from usable fuel and verified consumption, with reserve and load assumptions documented. Do not claim a universal federal wastewater population threshold that WPI does not publish.

Worked supervisory scenario

A wastewater operator discovers an unfamiliar remote-access device on the control network. The correct response is not to explore it from a production HMI or assume AWIA paperwork covers the issue. The operator preserves the condition, follows the OT incident plan, notifies authorized cyber/management staff, isolates access when directed, and maintains treatment through approved fallback controls.

Common exam traps

  • AWIA Section 2013’s community-water-system population mandate must not be presented as a universal wastewater requirement.
  • A vulnerability assessment is not a public checklist of exploitable details.
  • A camera or locked gate is only one layer and requires testing and response.
  • Cybersecurity includes availability and safe process control, not just data secrecy.

Field-to-exam checklist

  • Assess threats and hazards against critical wastewater services and dependencies.
  • Use layered physical and OT controls with tested response.
  • Document and escalate anomalies without destroying evidence.
  • Follow applicable local requirements; do not invent a nationwide wastewater AWIA threshold.

Recovery as part of security

Protection is incomplete without a tested way to restore treatment. Keep offline or otherwise protected backups of critical control configurations, current contact lists, manual operating instructions, and prioritized restart sequences. Test restoration on an authorized nonproduction basis and record the time and dependencies. A backup that cannot be read, a spare that lacks firmware, or a manual procedure for obsolete equipment is not recovery capability.

Frameworks, segmentation, and what actually applies

Know exactly what the AWIA requirement covers. America's Water Infrastructure Act Section 2013 requires risk and resilience assessments and emergency response plans for community drinking-water systems serving more than 3,300 people. It does not, by itself, impose that statutory requirement on a wastewater utility. Wastewater security obligations come instead from state programs, permit conditions, local policy, and voluntary frameworks — and a Class III operator should be able to say that plainly rather than repeating a drinking-water threshold as though it were universal.

Useful voluntary references include the NIST Cybersecurity Framework, CISA's water and wastewater sector guidance and no-cost vulnerability scanning services, EPA's Vulnerability Self-Assessment Tool, and WaterISAC advisories. None is a mandate; all provide a defensible structure for an assessment.

The operational-technology controls that repeatedly matter are unglamorous:

  • unique named accounts with no shared operator login, so an action can be attributed;
  • multi-factor authentication on every remote-access path;
  • network segmentation between the business network and the control network, with a controlled boundary rather than a flat network;
  • removal of default vendor passwords on PLCs, HMIs, drives, and network gear;
  • unused physical and logical ports disabled;
  • configuration and program backups kept offline and periodically restored on a test basis.

Real incidents in this sector have overwhelmingly involved exposed remote-access tools and unchanged default credentials, not sophisticated intrusion — which means the highest-value work is also the least glamorous.

A security round only produces value if a deviation triggers a response. Recording "all normal" without physically checking a hatch, a chemical-storage gate, or a control cabinet is a paperwork control. Define the expected condition, the escalation criterion, and how evidence is preserved before the round is written.

Test Your Knowledge

Does the 2025 WPI Class III outline establish a universal AWIA Section 2013 population threshold for wastewater facilities?

A
B
C
D
Test Your Knowledge

An unknown remote-access device appears on the plant control network. What is the defensible first response?

A
B
C
D