18706_Authority_Oct
municipalauthorities.org | 41 The required SDWA risk and resilience assessments (RRA) and emergency response plans (ERP) for community water suppliers serving greater than 3,300 persons must address cybersecurity and the physical security of IT and OT assets. These requirements repeat every five years with deadlines coming in 2025-2026. CWS Size R&R Assessment Certification ERP Certification >100,000 March 31, 2025 September 30, 2025 50,000 - 99,999 December 31, 2025 June 30, 2026 3,301 - 49,999 June 30, 2026 December 31, 2026 Full details on these requirements and resources to complete an assessment and ERP and how to certify to EPA these actions have been completed can be found at AWIA/SDWA section 2013 (epa.gov/waterresilience/awia-section-2013) . Other ideas for preparedness, response and recover can be found on the Cybersecurity Incident Action Checklist (IAC) (epa.gov/sites/default/files/2017-11/documents/171013-incidentactionchecklist-cybersecurity_form_508c.pdf) . As an aside, these IACs cover many other natural events from wildfires to flooding to tornados and hurricanes and provide ideas for enhancing your ERP with planning, response and recovery actions (epa.gov/ waterutilityresponse/incident-action- checklists-water-utilities) . As you consider accessing these resources and modifying existing plans for training staff and responding to incidents, let’s also remember that PADEP has created a cybersecurity webpage [www.pa.gov/ agencies/dep/programs-and-services/water/ bureau-of-safe-drinking-water/cybersecurity ]. A key aspect of responding to cyber incidents is reporting to PADEP under the 1-hour reporting requirement. PADEP can support you by working with partners to investigate the incident. Water quality and quantity concerns will also be addressed with PADEP to ensure public health is protected. See text box for more details on reporting requirements in the Commonwealth and at the federal level. With all of these resources available, you should be able to train staff, develop plans, train and exercise on these plans, be ready to quickly respond to cyber intrusions to minimize disruptions and safely recover. Don’t be overwhelmed by the amount of materials, simply take a few moments to consider your current A good place to start at your utility is with an evaluation either by the utility performing a self-assessment or requesting EPA assistance. How to Report Cyber Incidents in Pennsylvania PA DEP A cyber-attack qualifies as a situation with the potential to affect water quality or quantity requiring notification to the Department within one hour of learning of an attack, according to §109.701(a)(3)(iii). PUC Regulated water utilities Emergency AREP 717-941-0003 Cyber event reporting is a requirement per 52 Pa. Code Chapter 65.2: pacodeandbulletin.gov/Display/pacode?file=/secure/pacode/ data/052/chapter65/chap65toc.html&d=#65.2 PA Criminal Intelligence Center for suspicious activity including cybersecurity events. 888-292-1919 pa.gov/agencies/homelandsecurity/report-possible-criminal-or- terrorist-activity.html State Police See this fact sheet for when and how to report to the Federal Government Cyber Incident Reporting Process (epa.gov/system/ files/documents/2023-02/230202-CyberIncidentReportingProcess_ 21118.pdf) EPA Cybersecurity article continued from page 21.
Made with FlippingBook
RkJQdWJsaXNoZXIy MjY5OTU3