Recently, the U.S. EPA’s Office of Water finalized a report describing how it plans to provide voluntary cybersecurity technical support to drinking water systems, the second of two cyber-related actions that were mandated by Congress last year as part of the Bipartisan Infrastructure Law.
The infrastructure law first required EPA to develop a “prioritization framework” to identify public water systems that “if degraded or rendered inoperable due to an incident, would lead to significant impacts on the health and safety of the public.” The Association of Metropolitan Water Agencies described that framework, which was released in May, and outlined how EPA would prioritize delivering technical cybersecurity aid to water systems during a scenario where the demand for such aid outstripped the agency’s near-term capacity to provide it. The framework explained that EPA would prioritize delivering aid based on factors such as the risk to downstream critical infrastructure and national security assets, the capabilities of water systems to address vulnerabilities without federal support, and the risk reduction benefits that would be achieved as a result of the support.
Continue Reading
This archived story is available after you provide your email address and accept our Privacy Policy.








Leave a Reply