AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
System Security and Operations

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) AWWA-4.4: Audit Logging and Monitoring

Implement logging and monitoring to detect security events across IT and operational technology environments.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 108 controls across 71 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • BE-CF-28 Audit event logging and storage
  • BE-CF-29 Audit record review and analysis
  • BE-CF-31 Audit log protection and retention

NIST SP 800-53 Rev 5 · 3 controls

  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC

MARS-E · 2 controls

API 1164 · 1 control

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

GHG Protocol · 1 control

HITECH Act · 1 control

IEC 62443 · 1 control

IEEE 1686 · 1 control

ISMAP (Japan) · 1 control

ISO 13485 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27019 · 1 control

ISO 27043 · 1 control

ISO 27799 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

  • NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-4 Security Status Reporting and Risk Score Aggregation

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

NIST SP 800-61 · 1 control

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

OpenSSF Scorecard · 1 control

  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity

PTES · 1 control

  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in System Security and Operations

Query this from an agent

The graph holds this control, the 108 it maps to, and the evidence behind each claim, over MCP and REST.