Áñ°Üã±â Ãß°¡     ½ÃÀÛÆäÀÌÁö·Î ¼³Á¤ óÀ½À¸·Î  l  ·Î±×ÀΠ l  È¸¿ø°¡ÀÔ  l  »çÀÌÆ®¸Ê

>
ȸ¿ø°¡ÀÔ   l   ¾ÆÀ̵ð/ºñ¹Ð¹øȣã±â
¡®Á¦38ȸ 2023³â »ó¹Ý±â ...
¡®Á¦37ȸ 2022³â ÇϹݱâ ...
Á¦37ȸ ¡¸2022³â ÇϹݱâ ...
 
HOME > ÇؿܽÃÀåÁ¤º¸ > ÃֽŴº½º
[2024] [¹Ì±¹] »óÇϼöµµ ½Ã½ºÅÛ »çÀ̹ö »ç°í ´ëÀÀ °¡ÀÌµå ¹ßÇ¥
À̸§ °ü¸®ÀÚ waterindustry@hanmail.net ÀÛ¼ºÀÏ 2024.01.26 Á¶È¸¼ö 731
ÆÄÀÏ÷ºÎ

[¹Ì±¹] »óÇϼöµµ ½Ã½ºÅÛ »çÀ̹ö Åë½Å °¡ÀÌµå ¹ßÇ¥

 CISA¡¤FBI¡¤EPA , »óÇÏ ¼öµµ ½Ã½ºÅÛ ¼ÒÀ¯¡¤¿î¿µ ±â°ü¿¡°Ô »çÀ̹ö »ç°í »ç·Ê ¸ð¹ü»ç·Ê¡¤½Ã¼³ÀÇ »ýÈ°Áֱ⠴ëÀÀ µîÀÇ Á¤º¸ Á¦°ø

25°³ ÀÌ»óÀÇ »óÇϼöµµ ½Ã½ºÅÛ ºÐ¾ß ¾÷°è¡¤ºñ¿µ¸® ´Üü ¹× ÁÖ¡¤Áö¹æ Á¤ºÎ ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© °³¹ß

¨çÁغñ ¨èŽÁö ¹× ºÐ¼®ºÀ¼â ¨é±ÙÀý ¹× º¹±¸ ¨ê »ç°í ÈÄ È°µ¿ µî 4´Ü°è ´ëÀÀ Á¦°ø °¡À̵å



¹Ì±¹ÀÇ »çÀ̹ö º¸È£ ¹× ±¹¹æ º¸¾Èû(CISA), Á¦ÇѼö»ç±¹(FBI), ȯ°æûû(EPA) µîÀº »óÇϼöµµ ½Ã½ºÅÛ(WWS) ºÐ¾ßÀÇ º¸È£ °ü¸® ±â°ü¿¡°Ô »çÀ̹ö »ç°í ´ëÀÀÀ» ¸ð¹ü»ç¿Í ±â¼úÀÇ »ýÈ°Áֱ⠴ëÀÀ À» Æ÷¿ËÇÏ´Â ºÎºÐÀº Á¤ºÎÀÇ ¿ªÇÒ, Çظ® ¹× ±ÇÇÑ¿¡ ´ëÇÑ Á¤º¸¸¦ Á¦°øÇÏ´Â °¡À̵带 1¿ù 18ÀÏ °øµ¿À¸·Î ¹ßÇ¥Çß½À´Ï´Ù.  [»çÁøÃâó(»çÁø Ãâó) = ¹Ì±¹ »çÀ̹ö º¸¾È¡¤ÀÎÇÁ¶ó º¸¾È±¹(CISA)]

¹Ì±¹ÀÇ »çÀ̹ö º¸È£ ¹× ±¹¹æ º¸¾Èû(CISA), Á¦ÇѼö»ç±¹(FBI), ȯ°æûû(EPA) µîÀº »óÇϼöµµ ½Ã½ºÅÛ(WWS) ºÐ¾ßÀÇ º¸È£ °ü¸® ±â°ü¿¡°Ô »çÀ̹ö »ç°í ´ëÀÀÀ» ¸ð¹ü»ç¿Í ±â¼úÀÇ »ýÈ°Áֱ⠴ëÀÀ À» Æ÷¿ËÇÏ´Â ºÎºÐÀº Á¤ºÎÀÇ ¿ªÇÒ, Çظ® ¹× ±ÇÇÑ¿¡ ´ëÇÑ Á¤º¸¸¦ Á¦°øÇÏ´Â °¡À̵带 1¿ù 18ÀÏ °øµ¿À¸·Î ¹ßÇ¥Çß½À´Ï´Ù. [»çÁøÃâó(»çÁø Ãâó) = ¹Ì±¹ »çÀ̹ö º¸¾È¡¤ÀÎÇÁ¶ó º¸¾È±¹(CISA)]

 

¹Ì±¹ÀÇ »çÀ̹ö º¸¾È ¹× °¨½Ã º¸¾Èû(Cybersecurity and Infrastructure Security Agency, CISA), ºÎºÐ¼ö»ç±¹(Federal Bureau of Investigation, FBI), ȯ°æ º¸È£Ã»(Environmental Protection Agency, EPA) µîÀº »óÇÏ ±³È¯ ½Ã½ºÅÛ(Water and Wastewater Systems, WWS) ¹üÀ§ÀÇ º¸°ü°ú ¿î¿µ ±â°ü¿¡°Ô »çÀ̹ö »ç°í ´ëÀÀÀ» ¸ð¹üÀûÀÎ »ç·Ê¿Í ½Ã¼³ÀÇ ¼ö¸íÁֱ⠴ëÀÀÀ» Ãà¼Ò ºÎºÐ Á¤ºÎÀÇ ¿ªÇÒ, ¸®¼Ò½º(ÀÚ¿ø) ¹× Ã¥ÀÓ¿¡ ´ëÇÑ Á¤º¸¸¦ Á¦°øÇÏ´Â °¡À̵带 1¿ù 18ÀÏ¿¡ Á¦°øÇß½À´Ï´Ù. ÀÌ °¡À̵带 ÀÌÇØÇÏ°í »ç¿ëÇϱâ À§Çؼ­´Â Àü¹®ÀûÀÎ Áö½ÄÀ» ÇÊ¿ä·Î ÇÏ´Â Âü°¡ÀÚÀÔ´Ï´Ù.


¾Æ¸Þ¸®Ä­ ¿öÅÍ(American Water), ÁÖ ½Ä¼ö°ü¸®ÀÚÇùȸ(Association of State Drinking Water Administrators, ASDWA), ¹°È¯°æ¿¬¸Í(Water Environment Federation), ¹Ì±¹¼öµµÇùȸ(Individuals from American Water Works Association, AWWA), Ä÷³ºñ¾Æ »óÇϼöµµÃ»(District of Columbia Water, DC Water), ±¸±Û/¸Çµð¾ðÆ®(Google/Mandiant), ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®(Microsoft), ÀÚÀÏ·³(Xylem) µî 25°³ ÀÌ»óÀÇ »óÇϼöµµ ½Ã½ºÅÛ ºÎ¹® ¾÷°è, ºñ¿µ¸® ´Üü, ÁÖÁ¤ºÎ ¹× Áö¹æ Á¤ºÎ ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© °³¹ßµÈ ÀÌ ¸®¼Ò½º(ÀÚ¿ø)´Â »ç°í ´ëÀÀ ¼ö¸íÁÖ±âÀÇ 4´Ü°è·Î ³ª´©¾î ´Ù·ç¾ú´Ù.


¨ç Áغñ(Preparation)  WWS(»óÇϼöµµ ½Ã½ºÅÛ) ºÐ¾ß Á¶Á÷Àº »ç°í ´ëÀÀ °èȹÀ» ¸¶·ÃÇÏ°í, »çÀ̹ö ±âÁØÀ» ³ôÀ̱â À§ÇØ »ç¿ë °¡´ÉÇÑ ¼­ºñ½º¿Í ¸®¼Ò½º¸¦ ±¸ÇöÇÏ°í, WWS ºÎ¹® »çÀ̹ö Ä¿¹Â´ÏƼ¿Í Çù·ÂÇØ¾ß ÇÑ´Ù.


¨è ŽÁö ¹× ºÐ¼®(Detection and analysis)  »çÀ̹ö »ç°íÀÇ Àüü ¹üÀ§¿Í ¿µÇâÀ» ÀÌÇØÇÏ·Á¸é Á¤È®ÇÏ°í ½ÃÀÇÀûÀýÇÑ º¸°í¿Í ½Å¼ÓÇÑ Áý´Ü ºÐ¼®ÀÌ ÇʼöÀûÀÌ´Ù. ÀÌ ÁöħÀº »ç°í °ËÁõ, º¸°í ¼öÁØ, »ç¿ë °¡´ÉÇÑ ±â¼ú ºÐ¼® ¹× Áö¿ø¿¡ ´ëÇÑ Á¤º¸¸¦ Á¦°øÇÑ´Ù.


¨é ºÀ¼â, ±ÙÀý ¹× º¹±¸(Containment, eradication, and recovery)  WWS ºÎ¹® À¯Æ¿¸®Æ¼°¡ »ç°í ´ëÀÀ °èȹÀ» ¼öÇàÇÏ´Â µ¿¾È ¿¬¹æ ÆÄÆ®³Ê´Â Á¶Á¤µÈ ¸Þ½Ã¡ ¹× Á¤º¸ °øÀ¯, ±³Á¤ ¹× ¿ÏÈ­ Áö¿ø¿¡ ÁßÁ¡À» µÎ°í ÀÖ´Ù.


¨ê »ç°í ÈÄ È°µ¿(Post-incident activities)  ¼öÁýµÈ »ç°í µ¥ÀÌÅ͸¦ »ç¿ëÇÏ´Â Áõ°Å º¸Á¸°ú ÇнÀµÈ ±³ÈÆÀº »ç°í¿Í ´ëÀÀÀÚ°¡ »ç°í¸¦ ó¸®ÇÑ ¹æ¹ýÀ» ¸ðµÎ ÀûÀýÇÏ°Ô ºÐ¼®Çϱâ À§ÇÑ °¡Àå Áß¿äÇÑ ¿ä¼ÒÀÌ´Ù.

 


CISA(»çÀ̹öº¸¾È ¹× ÀÎÇÁ¶ó º¸¾È±¹)ÀÇ »çÀ̹ö º¸¾È´ã´ç Ã¥ÀÓÀÚÀÎ ¿¡¸¯ °ñµå½ºÅ¸ÀÎ(Eric Goldstein)Àº ¡°Á¤¼öÀå ¹× Çϼöó¸®Àå µî »óÇϼöµµ½Ã½ºÅÛÀº ¾ÇÀÇÀûÀÎ »çÀ̹ö ÇàÀ§ÀڷκÎÅÍ Áö¼ÓÀûÀÎ À§ÇùÀ» ¹Þ°í ÀÖ´Ù. À̹ø¿¡ ¹ß°£µÈ ½ÃÀÇÀûÀýÇÏ°í ½ÇÇà °¡´ÉÇÑ ÁöħÀº »óÇϼöµµ ½Ã½ºÅÛ ºÐ¾ßÀÇ Çʼö ºÎ¹®À» Áö¿øÇϱâ À§ÇØ EPA, FBI ¹× CISA¿Í Âü¿©ÇÑ »ê¾÷°è, ºñ¿µ¸® ¹× Á¤ºÎ ÆÄÆ®³Ê°£ÀÇ Å¹¿ùÇÑ ÆÄÆ®³Ê½ÊÀ» ¹Ý¿µÇß´Ù. ¿ì¸®´Â ¸ðµç WWS ´Üü ¹× ±â°üÀÌ ÀÌ °øµ¿ °¡À̵带 °ËÅäÇÏ°í ±ÇÀå Á¶Ä¡¸¦ ÀÌÇàÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù¡±°í ¸»Çß´Ù.


¿¡¸¯ °ñµå½ºÅ¸ÀΠåÀÓÀÚ´Â ÀÌ¾î ¡°»õÇØ¿¡µµ CISA´Â ½ÇÇà °¡´ÉÇÑ ¸®¼Ò½º¸¦ Á¦°øÇÏ°í ¸ðµç Á¶Á÷ÀÌ »çÀ̹ö »ç°í¸¦ º¸°íÇϵµ·Ï Àå·ÁÇÔÀ¸·Î½á WWS À¯Æ¿¸®Æ¼¿Í °°Àº ¡®Ç¥ÀûÀÌ ½±°í º¸¾ÈÀÌ ºó¾àÇÑ(target-rich, cyber-poor)¡¯ ±â°üÀ» Áö¿øÇϱâ À§ÇØ °¡´ÉÇÑ ¸ðµç Á¶Ä¡¸¦ ÃëÇÏ´Â µ¥ °è¼Ó ÁýÁßÇÒ °Í¡±À̶ó¸é¼­ ¡°¹Ì±¹ Àü±¹ÀÇ Áö¿ª ÆÀ¿øµéÀº °è¼ÓÇؼ­ WWS ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© Ãë¾àÁ¡ °Ë»ö µî·Ï°ú °°Àº CISAÀÇ ÀÚ¹ßÀû ¼­ºñ½º¿¡ ´ëÇÑ ¾×¼¼½º(access)¸¦ Á¦°øÇÏ°í Áö¼ÓÀûÀÎ °³¼±À» À§ÇÑ ¸®¼Ò½º(ÀÚ¿ø) ¿ªÇÒÀ» ÇÒ °Í¡±À̶ó°í °­Á¶Çß´Ù.


»óÇϼö ½Ã½ºÅÛ ¾ß »çÀ̹ö »ç°í ´ëÀÀ °¡À̵å´Â 25°³ ÀÌ»ó »óÇϼöµµ ½Ã½ºÅÛ ºÐ¾ß ¾÷°è¡¤ºñ¿µ¸® ´Üü ¹× ÁÖ¡¤Á¤ºÎ ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© °³¹ßµÇ¾ú½À´Ï´Ù.  [»çÁøÃâó(»çÁøÃâó) = ¹Ì±¹È¯°æº¸È£Ã»(EPA) ]

»óÇϼö ½Ã½ºÅÛ ¾ß »çÀ̹ö »ç°í ´ëÀÀ °¡À̵å´Â 25°³ ÀÌ»óÀÇ »óÇϼöµµ ½Ã½ºÅÛ ºÐ¾ß ¾÷°è¡¤ºñ¿µ¸®´Üü ¹× ÁÖ¡¤Áö¹æÁ¤ºÎ ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© °³¹ßµÆ´Ù. [»çÁøÃâó(Photo source) = ¹Ì±¹ ȯ°æº¸È£Ã»(EPA)]

 

FBI(¿¬¹æ¼ö»ç±¹) »çÀ̹ö±¹ÀÇ ºê¶óÀ̾𠺻µå¶õ(Bryan Vorndran) ºÎ±¹ÀåÀº ¡°»óÇϼöµµ ½Ã½ºÅÛ ºÎ¹®Àº ¿ì¸®ÀÇ Áß¿ä ÀÎÇÁ¶ó¿¡¼­ Áß¿äÇÑ ºÎºÐÀ¸·Î, FBI´Â À̸¦ À§ÇùÇÏ´Â »çÀ̹ö ÇàÀ§ÀÚµé°ú °è¼ÓÇؼ­ ½Î¿ï °Í¡±À̶ó¸é¼­ ¡°»çÀ̹ö °ø°Ý¿¡ ´ëÀÀÇÒ Àü·«ÀÇ ÇÙ½É ºÎºÐÀº °ø°ÝÀ» ¹Þ±â Àü¿¡ Áß¿äÇÑ ÀÎÇÁ¶óÀÇ ¼ÒÀ¯ÀÚ ¹× ¿î¿µÀÚ¿Í °­·ÂÇÑ ÆÄÆ®³Ê½ÊÀ» ±¸ÃàÇÏ°í À§Çù Á¤º¸¸¦ °øÀ¯ÇÏ´Â °Í¡±À̶ó°í ¸»Çß´Ù.


EPA(ȯ°æº¸È£Ã»)ÀÇ ¶óµðÄ« Æø½º(Radhika Fox) ¹° ºÐ¾ß º¸Á¶ °ü¸®ÀÚ´Â ¡°¹° ºÎ¹®¿¡ ´ëÇÑ »çÀ̹ö À§ÇùÀº ¹Ì±¹ÀÌ ÀÇÁ¸ÇÏ´Â ¾ÈÀüÇÑ ½Ä¼ö ¹× Çϼö ¼­ºñ½º¿¡ ´ëÇÑ Çö½ÇÀûÀÌ°í ±ä±ÞÇÑ À§ÇèÀ» ³ªÅ¸³»°í ÀÖ´Ù¡±¶ó¸é¼­ ¡°»ç°í ´ëÀÀ °¡À̵å´Â ¹Ì±¹ÀÇ »óÇϼöµµ ½Ã½ºÅÛÀÇ »çÀ̹ö °ø°Ý À§ÇèÀ» ³·Ãß±â À§ÇØ ¿¬¹æ ±â°ü°ú Çù·ÂÇϱâ À§ÇÑ Á¢±Ù ¹æ½ÄÀ» ÅëÇØ À¯Æ¿¸®Æ¼¸¦ Áö¿øÇÏ°í ÀÖ´Ù¡±°í ¸»Çß´Ù. 


±×´Â ÀÌ¾î ¡°EPA´Â ¿¬¹æ, ÁÖ, ¼öÀÚ¿ø ºÎ¹® ÆÄÆ®³Ê¿Í Çù·ÂÇÏ¿© ÇØ´ç ºÎ¹®ÀÇ Åº·Â¼ºÀ» ³ôÀÌ°í »çÀ̹ö ź·Â¼º °üÇàÀ» °³¼±Çϱâ À§ÇØ ÃÖ¼±À» ´ÙÇÏ°í ÀÖ´Ù¡±°í µ¡ºÙ¿´´Ù.


CISA, FBI, EPA´Â ¹Ì±¹ÀÇ ¸ðµç »óÇϼöµµ ½Ã½ºÅÛ ¿î¿µ¡¤°ü¸® °ø°ø±â°ü¿¡°Ô »ç°í ´ëÀÀ °¡À̵带 »ç¿ëÇÏ¿© »çÀ̹ö »ç°í ÀÌÀü, »çÀ̹ö »ç°í Áß ¹× ÀÌÈÄ¿¡ ¿¬¹æÁ¤ºÎ ÆÄÆ®³Ê ¹× WWS¿ÍÀÇ »ç°í ´ëÀÀ °èȹ ¹× Çù¾÷À» °­È­ÇÒ °ÍÀ» ±ÇÀåÇÏ°í ÀÖ´Ù. 


ÀÌ °¡À̵带 ¼÷ÁöÇϸé WWS À¯Æ¿¸®Æ¼°¡ »çÀ̹ö »ç°í¿¡ ´ëÀÀÇÏ°í º¹±¸ÇÒ ¼ö ÀÖµµ·Ï ÁغñÇÏ´Â °ÍÀÌ ÁÁ´Ù.


ÀÚ¼¼ÇÑ Á¤º¸¿Í ¸®¼Ò½º¸¦ º¸·Á¸é WWS À¯Æ¿¸®Æ¼°¡ CISAÀÇ »óÇϼö ½Ã½ºÅÛ »çÀ̹ö º¸¾È À¥ÆäÀÌÁö(http://Water and Wastewater Cybersecurity | CISA)¸¦ ¹æ¹®ÇÏ´Â °ÍÀÌ ÁÁ´Ù.


ÀÌ °¡À̵忡 ±â¿©ÇÑ ÆÄÆ®³Ê´Â ´ÙÀ½°ú °°´Ù.


- ¾Ë·º½º¸®´º(AlexRenew) 

- ¾Æ¸Þ¸®Ä­ ¿öÅÍ(American Water)

- ÁÖ ½Ä¼ö°ü¸®ÀÚÇùȸ(Association of State Drinking Water Administrators, ASDWA)

- »çÀ̹ö±â¼úÇõ½Å¼¾ÅÍ(Center on Cyber and Technology Innovation, CCTI)

- µµ¹ö½Ã(City of Dover)

- »çÀ̹ö Áغñ ¿¬±¸¼Ò(Cyber Readiness Institute, CRI)

- ±¹Åä¾Èº¸ºÎ »êÇÏ Á¤º¸ºÐ¼®½Ç(Department of Homeland Security¡¯s Office of Intelligence and Analysis)

- Ä÷³ºñ¾Æ »óÇϼöµµÃ»(District of Columbia Water, DC Water)

- µå¶ó°í½º(Dragos )

- À̽ºÆ® º£ÀÌ ½ÃÀ¯Æ¿¸®Æ¼ Áö±¸(East Bay Municipal Utility District)

- EMA ÁÖ½Äȸ»ç(EMA Inc.)

- ±¸±Û/¸Çµð¾ðÆ®(Google/Mandiant)

- ±¹Á¦ÀÚµ¿È­ÇÐȸ(International Society of Automation, ISA)

- ¸ÞÀÎÁÖ DHHS CDC ½Ä¼ö ÇÁ·Î±×·¥(Maine DHHS CDC Drinking Water Program)

- ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®(Microsoft)

- ´ºÀúÁö »çÀ̹öº¸¾È ¹× Åë½ÅÅëÇÕ¼¿(New Jersey Cybersecurity & Communications Integration Cell, NJCCIC)

- Ç÷¡Æ® ij³â ¼öÀÚ¿ø ¹× À§»ý Áö±¸»÷ÇÁ¶õ½Ã½ºÄÚ °ø°ø À¯Æ¿¸®Æ¼ À§¿øȸ(Platte Canyon Water & Sanitation DistrictSan Francisco Public Utilities Commission, SFPUC)

- ½´³ªÀÌ´õ ÀÏ·ºÆ®¸¯(Schneider Electric)

- Å׳ªºí(Tenable)  

- Å×Æ®¶ó Å×Å©(Tetra Tech)

- Åػ罺 Æ®¸®´ÏƼ°­Ã»(Trinity River Authority of Texas)

- ¹°È¯°æ¿¬¸Í(Water Environment Federation)

- ¹°Á¤º¸°øÀ¯ºÐ¼®¼¾ÅÍ(Water Information Sharing and Analysis Center, WaterISAC)

- ¿þ½ºÆ® ¿ä½ºÆ® ÁÖ½Äȸ»ç(West Yost Inc.)

- ÀÚÀÏ·³(Xylem )

- ¹Ì±¹¼öµµÇùȸ(Individuals from American Water Works Association, AWWA)


[¿ø¹®º¸±â]


CISA, FBI and EPA Release Incident Response Guide for Water and Wastewater Systems Sector 

With WWS Sector contributions, guide provides recommended actions and available resources throughout cyber incident response lifecycle 



WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Environmental Protection Agency (EPA) published a guide today to assist owners and operators in the Water and Wastewater Systems (WWS) Sector with best practices for cyber incident response and information about federal roles, resources and responsibilities for each stage of the response lifecycle. Technical expertise is not required to understand and use this guide.   


Developed in collaboration with over 25 WWS Sector industry, nonprofit, and state/local government partners, this resource covers the four stages of the incident response lifecycle:  


Preparation: WWS Sector organizations should have an incident response plan in place, implement available services and resources to raise their cyber baseline, and engage with the WWS Sector cyber community.  


Detection and analysis: Accurate and timely reporting and rapid collective analysis are essential to understand the full scope and impact of a cyber incident. The guidance provides information on validating an incident, reporting levels, and available technical analysis and support.   


Containment, eradication, and recovery: While WWS Sector utilities are conducting their incident response plan, federal partners are focusing on coordinated messaging and information sharing, and remediation and mitigation assistance.  


Post-incident activities: Evidence retention, using collected incident data, and lessons learned are the overarching elements for a proper analysis of both the incident and how responders handled it.  


¡°The Water and Wastewater Systems sector is under constant threat from malicious cyber actors. This timely and actionable guidance reflects an outstanding partnership between industry, nonprofit, and government partners that came together with EPA, FBI and CISA to support this essential sector. We encourage every WWS entity to review this joint guide and implement its recommended actions,¡± said CISA Executive Assistant Director for Cybersecurity, Eric Goldstein. 


¡°In the new year, CISA will continue to focus on taking every action possible to support ¡®target-rich, cyber-poor¡¯ entities like WWS utilities by providing actionable resources and encouraging all organizations to report cyber incidents. Our regional team members across the country will continue to engage with WWS partners to provide access to CISA¡¯s voluntary services, such as enrollment in our Vulnerability Scanning, and serve as a resource for continued improvement.¡±  


"The Water and Wastewater Systems Sector is a vital part of our critical infrastructure, and the FBI will continue to combat cyber actors who threaten it,¡± said Assistant Director Bryan Vorndran of the FBI¡¯s Cyber Division. ¡°A key part of our cyber strategy is building strong partnerships and sharing threat information with the owners and operators of critical infrastructure before they are hit with an attack.¡±   


¡°Cyber threats to the water sector represent a real and urgent risk to safe drinking water and wastewater services that our nation relies on. The incident response guide assists utilities with approaches for collaboration with federal entities on lowering cyber risk in our nation¡¯s drinking water and wastewater systems,¡± said EPA Assistant Administrator for Water, Radhika Fox. ¡°EPA is committed to working with our federal, state, and water sector partners to increase the sector¡¯s resilience and improve cyber-resilience practices.¡± 


All WWS utilities are encouraged to use this incident response guide to augment their incident response planning and collaboration with federal partners and the WWS before, during, and following a cyber incident. Familiarity with this guide will better prepare WWS utilities to respond to?and recover from?a cyber incident.  


For more information and resources, WWS utilities are encouraged to visit CISA¡¯s Water and Wastewater Systems Cybersecurity webpage.  


Partners that contributed to this guide include:  


- AlexRenew  

- American Water  

- Association of State Drinking Water Administrators (ASDWA)  

- Center on Cyber and Technology Innovation (CCTI)  

- City of Dover  


- Cyber Readiness Institute (CRI)  

- Department of Homeland Security¡¯s Office of Intelligence and Analysis 

- District of Columbia Water (DC Water)  

- Dragos 

- East Bay Municipal Utility District  

- EMA Inc.  

- Google/Mandiant 

- International Society of Automation (ISA)  

- Maine DHHS CDC Drinking Water Program 

- Microsoft  

- New Jersey Cybersecurity & Communications Integration Cell (NJCCIC)  

- Platte Canyon ¼öÀÚ¿ø ¹× À§»ý Áö±¸»÷ÇÁ¶õ½Ã½ºÄÚ °ø°ø À¯Æ¿¸®Æ¼À§¿øȸ (SFPUC) 

- ½´³ªÀÌ´õ ÀÏ·ºÆ®¸¯ 

- Å×³Êºí  

- ±â¼ú  

- Åػ罺 Æ®¸®´ÏƼ¸®¹ö ´ç±¹  

- ¹°È¯°æ¿¬¸Í  

- ¹°Á¤º¸°øÀ¯ºÐ¼®¼¾ÅÍ(WaterISAC)  

- ¿þ½ºÆ® ¿ä½ºÆ® ÁÖ½Äȸ»ç  

- ½Ç·½ 

- ¹Ì±¹¼öµµÇùȸ(AWWA) °ü°èÀÚ 


CISA ¼Ò°³ 


±¹°¡ÀÇ »çÀ̹ö ¹æ¾î ±â°üÀÌÀÚ Áß¿ä ÀÎÇÁ¶ó º¸¾ÈÀ» À§ÇÑ ±¹°¡ Á¶Á¤ÀÚÀÎ »çÀ̹ö º¸¾È ¹× ÀÎÇÁ¶ó º¸¾È ±â°üÀº ¹Ì±¹ÀεéÀÌ ¸ÅÀÏ ¸Å½Ã°£ ÀÇÁ¸ÇÏ´Â µðÁöÅÐ ¹× ¹°¸®Àû ÀÎÇÁ¶ó¿¡ ´ëÇÑ À§ÇèÀ» ÀÌÇØ, °ü¸® ¹× ÁÙÀ̱â À§ÇÑ ±¹°¡Àû ³ë·ÂÀ» À̲ø°í ÀÖ½À´Ï´Ù.


[Ãâó = ¹Ì±¹ »çÀ̹ö º¸¾È¡¤ÀÎÇÁ¶ó º¸¾È±¹(CISA) ( https://www.cisa.gov/news-events/news/cisa-fbi-and-epa-release-incident-response-guide-water-and- Æó¼öó¸®ºÐ¾ß ) / 2024³â 1¿ù 18ÀÏ]

¨Ï±Û·Î¹ú¹°»ê¾÷Á¤º¸¼¾ÅÍ(www.waterindustry.co.kr) ¹«´ÜÀüÀç ¹× Àç¹èÆ÷±ÝÁö
ÀÌÀü±Û [Áß±¹] JA Solar, PV ModuleTech ±ÝÀ¶Áö¿ø Ÿ´ç¼º ¼øÀ§¿¡¼­ AAA µî±Þ À¯Áö
´ÙÀ½±Û [¹Ì±¹] EPA¡¤HUD¡¤DOE, Àú¼Òµæ °¡±¸ ¿¡³ÊÁö¡¤¹° Àý¾à À§ÇÑ µ¥ÀÌÅÍ Á¦°ø ¿äû
±Û·Î¹ú¹°»ê¾÷Á¤º¸¼¾ÅÍ.   ¼¾ÅÍÀå : ¹èö¹Î
ÁÖ¼Ò : ¼­¿ï½Ã ¼ÛÆı¸ »ïÀüµ¿ 72-3 À¯¸²ºôµù 5Ãþ TEL (02) 3431-0210   FAX (02) 3431-0260   E-mail waterindustry@hanmail.net
COPYRIGHT(C) 2012 ±Û·Î¹ú¹°»ê¾÷Á¤º¸¼¾ÅÍ. ALL RIGHT RESERVED.