AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Network and Communications Security

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) AWWA-3.4: Encryption and Data Protection

Apply encryption to protect data in transit and at rest for sensitive operational and customer data.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 418 controls across 175 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

ISO 13485 · 5 controls

ISO 27799 · 5 controls

MARS-E · 5 controls

ISO 27018 · 4 controls

ISO 27043 · 4 controls

ISO/IEC 27011:2024 · 4 controls

ISO/SAE 21434 · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

FDA 21 CFR Part 11 · 3 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

GDPR · 3 controls

ISO 27017 · 3 controls

ISO/IEC 27400:2022 · 3 controls

Mauritius DPA · 3 controls

Mexico LFPDPPP · 3 controls

  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 3 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 3 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 3 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 3 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Saudi Arabia PDPL · 3 controls

  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer

Uruguay DPL · 3 controls

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • BE-DPA-14 Criminal penalties
  • BE-DPA-7 Processing of criminal conviction and offence data
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

India DPDP Act · 2 controls

Indonesia PDP Law · 2 controls

LGPD · 2 controls

Liechtenstein DPA · 2 controls

MDS2 (Medical Device) · 2 controls

MTCS (Singapore) · 2 controls

Malaysia PDPA 2010 · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4

NIST SP 800-122 · 2 controls

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 2 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations

OWASP MASVS · 2 controls

PTES · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO

Peru DPL · 2 controls

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • PERU-7 DPO, Records, Retention, Marketing, Training

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication

Taiwan PDPA · 2 controls

Turkey KVKK · 2 controls

Vietnam PDPD · 2 controls

Virginia CDPA · 2 controls

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data
  • BE-CF-08 Cryptographic protection of data

FIDO2 / WebAuthn · 1 control

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters

GLBA · 1 control

HITECH Act · 1 control

HKMA SPM · 1 control

  • 62351-9 Cyber security key management

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 19011 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO 26000:2010 · 1 control

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27010:2015 · 1 control

Japan AI Guidelines · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-61 · 1 control

  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification

NIST SP 800-88 · 1 control

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 1 control

South Korea PIPA · 1 control

  • STUDPRV-2 Data Subject Rights for Students and Parents
  • UKAI-2 Sector-Specific Regulator Engagement
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Network and Communications Security

Query this from an agent

The graph holds this control, the 418 it maps to, and the evidence behind each claim, over MCP and REST.