Laserfiche WebLink
Scope of Services for Preparation of egtommIHC <br /> AWIA-Compliance Documents <br /> City of Pleasanton pLEASANTON. <br /> Task 5.2. Run AWWA Cybersecurity Tool— Meeting <br /> West Yost will meet with the City to complete the American Water Works Association <br /> Cybersecurity Risk Management Tool. This workshop will require City personnel from Process <br /> Control and Information Technology teams. The output of the tool is designed to support utilities <br /> in developing their cybersecurity risk management strategy while also facilitating compliance with <br /> the cybersecurity provisions in §2013 of America's Water Infrastructure Act (AWIA) of 2018. <br /> Other Priority 1 and Priority 2 controls that do not focus on technology, along with the Priority 3 <br /> and Priority 4 controls, will be reviewed in more detail during the future AWIA Cyber Risk and <br /> Resiliency Assessment (RRA) workshop (see Task 5.6) that West Yost will coordinate with City <br /> personnel. <br /> West Yost will introduce Idaho National Lab's Consequence Informed Engineering (CIE) <br /> framework to the City. This will include a discussion of how to leverage CIE within the context <br /> of water sector best practices(e.g. J100,AWWA Tool,etc.)to produce engineering-based risk and <br /> resilience management strategies specifically targeted to improve cyber-resilience. <br /> Task 5.3. Develop Draft Technology Design Recommendations and Conduct Review Workshop <br /> West Yost will develop draft list of technology design recommendations based on the design <br /> review findings and output from the AWWA cybersecurity tool. West Yost will conduct a review <br /> workshop (Workshop 2A) with the City for final review and input. <br /> Task 5.4. Develop Final Technology Design Recommendations <br /> West Yost will incorporate comments from the City into the final technology design <br /> recommendations. <br /> Task 5.5. Cyber-RRA Kick-Off, Interviews, and Site Visits <br /> West Yost will conduct a cyber-RRA specific introductory meeting during the same week as the <br /> project Kick-Off meeting. Topics will be focused on the IT and SCADA components of the <br /> AWIA compliance requirements. Cyber-RRA site visits will follow the introductory meeting.This <br /> will allow us to integrate interviews into the site visits. During these site visits, West Yost staff <br /> will develop a high-level understanding of the City's IT system and supplement information <br /> gained in prior tasks regarding SCADA systems to support further evaluation. <br /> Task 5.6. Workshop 28— Cybersecurity Controls Assessment <br /> Following the site visits and interviews, West Yost will facilitate Workshop 2B — Cyber-RRA. <br /> The AWWA Tool output generated as part of West Yost's review of the City's SCADA design <br /> upgrades will be reviewed under this task. Other Priority 1 and Priority 2 controls that do not focus <br /> on technology, along with the Priority 3 and Priority 4 controls, that were identified under Task <br /> 5.2 will be reviewed in more detail during this workshop. <br /> A review workshop will be held with stakeholders and the output will be compared to the actual <br /> completed technology and associated controls. Recommended controls that are not in place or <br /> require improvements will be identified. <br /> WEST Y O S T ASSOCIATES 6 City of Pleasanton <br /> November 2019 <br /> n\m\s\cityp\\2019 AWIA Scope and Budget <br />