AWWA Risk Assessment and Mitigation 2 — Questions and Answers
Question 1: Which framework is most commonly used by water utilities to assess and prioritize security risks?
- ISO 9001 Quality Management
- AWWA Risk and Resilience Management standard (ANSI/AWWA J100) (Correct answer)
- OSHA 1910.119 Process Safety
- EPA RCRA Hazardous Waste Rules
Correct answer: AWWA Risk and Resilience Management standard (ANSI/AWWA J100)
ANSI/AWWA J100 provides the RAM-W methodology specifically designed for water sector risk and resilience assessments.
Question 2: In a consequence analysis for a water system attack, which outcome is ranked MOST severe?
- Loss of revenue for one billing cycle
- Public health impact causing mass casualties (Correct answer)
- Increased customer complaints
- Minor equipment damage under $10,000
Correct answer: Public health impact causing mass casualties
Public health impacts involving mass casualties represent the highest severity consequence category in water system risk assessments.
Question 3: What is the purpose of a Vulnerability Assessment (VA) under America's Water Infrastructure Act (AWIA) 2018?
- To certify operator training hours
- To identify and evaluate vulnerabilities and resilience of the water system (Correct answer)
- To audit financial records of the utility
- To establish water quality monitoring schedules
Correct answer: To identify and evaluate vulnerabilities and resilience of the water system
AWIA 2018 requires community water systems to assess system vulnerabilities, resilience, and consequences of malevolent acts or natural hazards.
Question 4: A water utility identifies that its SCADA system uses default vendor passwords. This is classified as what type of risk factor?
- Natural hazard
- Residual risk
- Vulnerability (Correct answer)
- Threat agent
Correct answer: Vulnerability
Default passwords represent a vulnerability—a weakness in the system that a threat actor could exploit.
Question 5: When evaluating likelihood of a threat scenario, which factor primarily drives the probability estimate for an intentional attack?
- Rainfall patterns in the service area
- Adversary capability and intent (Correct answer)
- Pipe age and material
- Treatment chemical costs
Correct answer: Adversary capability and intent
For intentional threats, the likelihood is primarily determined by whether an adversary has the capability and intent to carry out the attack.
Question 6: Which mitigation measure best addresses the risk of unauthorized physical access to a water treatment facility?
- Installing advanced oxidation treatment
- Implementing layered perimeter security with access control systems (Correct answer)
- Increasing chemical dosing redundancy
- Expanding the distribution pressure zone
Correct answer: Implementing layered perimeter security with access control systems
Layered perimeter security with access controls directly reduces the vulnerability of unauthorized physical entry.
Question 7: Under AWIA 2018, how frequently must community water systems serving more than 50,000 people certify completion of their updated risk and resilience assessments?
- Every year
- Every 3 years
- Every 5 years (Correct answer)
- Every 10 years
Correct answer: Every 5 years
AWIA 2018 requires covered utilities to certify updated risk and resilience assessments to EPA every five years.
Which framework is most commonly used by water utilities to assess and prioritize security risks?