AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
The American Water Works Association (AWWA) provides comprehensive cybersecurity guidance for water and wastewater utilities. Key publications include: AWWA Cybersecurity Risk & Responsibility in the Water Sector (2019), Process Control System Security Guidance for the Water Sector, and collaboration with WaterISAC. AWWA serves 50,000+ members representing water utilities, treatment plants, and suppliers. The guidance addresses unique challenges of water sector OT systems including SCADA, PLCs, and chemical dosing systems. Aligned with NIST Cybersecurity Framework, EPA requirements, and America's Water Infrastructure Act (AWIA) Section 2013.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit awwa.orgFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Access Control
| Code | Title |
|---|---|
| AWWA-G430-5 | Access Control for SCADA and Control Systems |
| AWWA-G430-6 | Remote Access Management |
Access Control and Identity Management
| Code | Title |
|---|---|
| AWWA-2.1 | User Access Management |
| AWWA-2.2 | Authentication Mechanisms |
| AWWA-2.3 | Account Management |
| AWWA-2.4 | Physical Access Controls |
Architecture
| Code | Title |
|---|---|
| AWWA-G430-4 | Network Segmentation IT/OT |
Asset Management
| Code | Title |
|---|---|
| AWWA-G430-2 | Asset Inventory and Classification |
Configuration
| Code | Title |
|---|---|
| AWWA-G430-18 | Configuration and Change Management for OT |
Governance
| Code | Title |
|---|---|
| AWWA-G430-1 | Cybersecurity Program Governance |
Improvement
| Code | Title |
|---|---|
| AWWA-G430-21 | Cybersecurity Program Review |
Incident Response
| Code | Title |
|---|---|
| AWWA-G430-10 | Incident Response for Water Utilities |
Incident Response and Recovery
Monitoring
| Code | Title |
|---|---|
| AWWA-G430-16 | Logging and Audit |
| AWWA-G430-9 | Boundary Protection and Monitoring |
Network and Communications Security
| Code | Title |
|---|---|
| AWWA-3.1 | Network Segmentation |
| AWWA-3.2 | Remote Access Security |
| AWWA-3.3 | Wireless Security |
| AWWA-3.4 | Encryption and Data Protection |
Personnel
| Code | Title |
|---|---|
| AWWA-G430-14 | Personnel Security and Insider Threat |
Physical
| Code | Title |
|---|---|
| AWWA-G430-17 | Physical Security of Cyber Assets |
Protection
| Code | Title |
|---|---|
| AWWA-G430-8 | Malware Protection |
Recovery
| Code | Title |
|---|---|
| AWWA-G430-12 | Backup and Recovery for Control Systems |
Regulatory
| Code | Title |
|---|---|
| AWWA-G430-19 | AWIA Risk and Resilience Assessment Compliance |
Reporting
| Code | Title |
|---|---|
| AWWA-G430-20 | Information Sharing and Reporting |
Resilience
| Code | Title |
|---|---|
| AWWA-G430-11 | Manual Operations Capability |
Risk
| Code | Title |
|---|---|
| AWWA-G430-3 | Risk Assessment for Water Systems |
Security Management and Governance
| Code | Title |
|---|---|
| AWWA-1.1 | Security Policy and Governance |
| AWWA-1.2 | Risk Assessment |
| AWWA-1.3 | Security Awareness and Training |
| AWWA-1.4 | Compliance and Regulatory Alignment |
Supply Chain
| Code | Title |
|---|---|
| AWWA-G430-13 | Supply Chain and Vendor Risk |
System Security and Operations
| Code | Title |
|---|---|
| AWWA-4.1 | Malware Protection |
| AWWA-4.2 | Patch Management |
| AWWA-4.3 | Configuration Management |
| AWWA-4.4 | Audit Logging and Monitoring |
Training
| Code | Title |
|---|---|
| AWWA-G430-15 | Cybersecurity Training for Operators |
Vulnerability
| Code | Title |
|---|---|
| AWWA-G430-7 | Patch and Vulnerability Management |
Your Compliance Coverage
If you comply with AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), you already cover:
NIST Cybersecurity Framework 2.0
43%
16 controls mapped
Compare →South Korea ISMS-P
35%
13 controls mapped
Compare →NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
32%
12 controls mapped
Compare →+ 497 more: TISAX - Trusted Information Security Assessment Exchange (32%), PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments (32%)
See all 500 mapped frameworks ↓Maps to 500 other frameworks
Frequently Asked Questions
What is AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)?
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) is a compliance framework from United States (AWWA) with 24 domains and 37 controls. The American Water Works Association (AWWA) provides comprehensive cybersecurity guidance for water and wastewater utilities. Key publications include: AWWA Cybersecurity Risk & Responsibility in the Water Sector (2019), Process Control System Security Guidance for the Water Sector, and collaboration with WaterISAC. AWWA serves 50,000+ members representing water utilities, treatment plants, and suppliers. The guidance addresses unique challenges of water sector OT systems including SCADA, PLCs, and chemical dosing systems. Aligned with NIST Cybersecurity Framework, EPA requirements, and America's Water Infrastructure Act (AWIA) Section 2013. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) have?
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) has 37 controls organised across 24 domains. The largest domains are Access Control and Identity Management (4 controls), Network and Communications Security (4 controls), Security Management and Governance (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) map to?
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) maps to 500 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (43% coverage), South Korea ISMS-P (35% coverage), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) compliance?
Start your AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required