CISA guidance targets water sector security, open source AI and more | Federal News Network

The Cybersecurity and Infrastructure Security Agency rolled out a flurry of advisories and technical guidance this week, zeroing in on threats to municipal water systems, the safe adoption of open-source software (including AI), and standardized security practices for cloud collaboration platforms. In total, CISA published five advisories or guidance documents and refreshed a cloud security tool used widely across the federal enterprise.

Water utilities warned: Lock down exposed OT and PLCs

In a sector-specific alert to water and wastewater operators, CISA urged urgent steps to secure operational technology—particularly programmable logic controllers (PLCs)—from active threat activity. The agency said adversaries have changed PLC passwords to lock out operators and altered device IP settings, causing service disruptions that have led to boil-water advisories and prolonged periods of manual operation.

While CISA has flagged PLC-focused attacks before, the new advisory lands amid reports that U.S. officials are probing possible Iranian involvement in intrusions at water systems across at least seven states. Without attributing the activity to a specific group, CISA emphasized that utilities of all sizes are being targeted—and that even mature organizations need to recheck external connections, including undocumented cellular modems installed by operators, vendors, or integrators that might evade routine attack-surface scans.

The takeaway for the sector: inventory and monitor all remote access paths; harden PLC interfaces; enforce strong authentication; and ensure backups and manual contingencies are ready if operators lose supervisory control.

“Isolating Vital Systems” offers crisis playbook for OT resilience

To complement the water-sector alert, CISA—working with the Australian Signals Directorate and other international partners—published Advice for Isolating Vital Systems, guidance aimed at keeping essential operational technology functioning during cyber crises. The document outlines pragmatic steps to establish robust isolation and recovery plans so critical services can continue under degraded conditions, whether through manual procedures or alternative supervisory control paths.

Framed as part of CISA’s CI Fortify Initiative, the guidance stresses pre-crisis planning, drills, and clear decision points for when and how to segment, isolate, or switch to backup control modes. The message is clear: plan and practice now to blunt the impact of state-sponsored and criminal actors targeting lifeline infrastructure.

CISA steps into the open-source conversation—AI included

CISA also published Open Source Software: Security Principles and Practices, a federal-facing guide to help agencies vet, approve, and manage open-source software (OSS) with a structured risk framework. The document promotes consistent processes for evaluating maturity, community health, licensing, code provenance, and vulnerability remediation paths—key steps to safely leverage OSS at scale.

The timing is notable as a broader policy debate intensifies over open-source AI. Reports indicate some officials are weighing restrictions on advanced foreign open-source AI models, while several major tech firms argue that openness can improve AI safety and security. CISA’s guide avoids that policy fight, but it does address how agencies should approach open-source AI specifically.

The agency urges agencies to demand transparency into all relevant components of AI systems—including training data and model documentation—before classifying a product as OSS for risk management. Without sufficient transparency and access, agencies cannot meaningfully assess vulnerabilities, test for risks, or remediate issues in a timely manner. In short: treat open-source AI with the same due diligence applied to other OSS, but insist on deeper insight into the AI supply chain.

SBOM “minimum elements” refreshed—and applied broadly

In a long-awaited update, CISA released the first revision in five years to the “minimum elements” of a Software Bill of Materials (SBOM). Building on the 2021 baseline from the National Telecommunications and Information Administration, the refreshed guidance clarifies the metadata, formats, and practices that make SBOMs reliable, scalable, and machine-readable.

Critically, CISA states that the updated minimum elements apply across the board—to traditional software, open-source components, AI-enabled software, and software-as-a-service (SaaS). That broad applicability reflects the way modern applications are assembled: from deep dependency chains to hosted services and model weights, transparency across the entire software supply chain is now table stakes for risk-informed decision-making.

While federal agencies do not uniformly require SBOMs in procurements today, the latest administration guidance allows agencies to include SBOM provisions in contracts as needed. CISA’s update could help standardize expectations and pave the way for more consistent SBOM adoption in both federal acquisition and industry best practices.

SCuBA program updates: Google Workspace baseline and ScubaGoggles

CISA’s Secure Cloud Business Applications (SCuBA) project—now nearing its fourth year—released an updated configuration baseline for Google Workspace and a significant new version of its assessment utility, ScubaGoggles. The SCuBA program’s mission is to help agencies apply secure, standardized configurations to popular cloud collaboration suites, reducing the misconfigurations that often lead to breaches.

The refreshed Google Workspace baseline provides prescriptive settings and policy guardrails aligned with federal requirements, including a CISA binding operational directive on secure practices for cloud collaboration tools. ScubaGoggles, the companion assessment tool, gives administrators an automated way to check their environments against SCuBA baselines and highlight gaps to remediate.

For agencies under pressure to accelerate cloud adoption without sacrificing security, these updates deliver concrete, actionable measures—particularly important as collaboration platforms continue to expand features and permissions that can introduce risk if left ungoverned.

Key actions for agencies and critical infrastructure

  • Water and wastewater operators: inventory and secure all external connections, including cellular modems and vendor-installed links; lock down PLCs; enforce MFA and strong credentials; and rehearse manual operations and recovery.
  • All OT owners: adopt the “Isolating Vital Systems” playbook—define isolation triggers, practice crisis procedures, and validate alternative control paths.
  • Federal agencies adopting OSS and AI: apply CISA’s OSS principles; require transparency into AI components and training data sufficient for vulnerability analysis and risk assessment.
  • Software buyers and builders: align with the updated SBOM minimum elements; ensure SBOMs are comprehensive, machine-readable, and maintained across the full software lifecycle, including OSS, AI, and SaaS dependencies.
  • Cloud administrators: implement SCuBA baselines for Google Workspace; use ScubaGoggles to assess configuration drift and close compliance gaps.

Why this matters

From ransomware to nation-state operations, adversaries are exploiting exposed control systems, sprawling software supply chains, and misconfigured cloud apps. CISA’s latest guidance set offers a coherent set of defensive plays: reduce attack surface on OT, ensure services can operate under duress, demand supply chain transparency via SBOMs, vet OSS and AI with rigorous criteria, and harden collaboration platforms with tested baselines.

Agencies and critical infrastructure operators have no shortage of checklists. What’s valuable here is the integration: combining immediate sector-specific alerts (water utilities) with cross-cutting frameworks (isolation planning, OSS/AI security, SBOMs) and hands-on tools (SCuBA and ScubaGoggles). Together, these moves can help organizations prioritize the fixes that matter most—and prove they’re secure by design, not just by aspiration.

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Exploring ChatGPT: Key Updates, Milestones, and Challenges in 2024

ChatGPT: Everything you need to know about the AI chatbot ChatGPT, the…

Exploring AI Humor: 50 Amusing Questions to Ask ChatGPT and Google’s AI Chatbot

50 Funny Things To Ask ChatGPT and Google’s AI Chatbot In the…

From Controversy to Resilience: Noel Biderman’s Post-Scandal Journey after Ashley Madison Data Breach

Exploring the Aftermath: Noel Biderman’s Journey Post-Ashley Madison Data Breach In 2015,…

Essential Update: Protect Your Plex Server from New Security Vulnerability

Update Your Plex Server Now to Fix This Security Vulnerability Bug bounty…