CISA guidance targets water sector security, open source AI and more
The Cybersecurity and Infrastructure Security Agency is pushing a bevvy of new cyber guidance to federal agencies, contractors and critical infrastructure organizations, amid concerning reports of cyber attacks on municipal water systems and ongoing debates about open source artificial intelligence systems.
CISA over the past week released five advisories or pieces of guidance, in addition to updating a tool that helps agencies securely adopt cloud services.
On Thursday, CISA urged the water and wastewater sector to protect their operational technology (OT) systems from threat activity targeting programmable logic controllers (PLCs).
“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses,” CISA wrote. “This activity has resulted in boil water notices and sustained manual operations.”
CISA has warned about such threat activity in the past. But the advisory – which does not attribute the activity to any threat group – comes as multiple news reports say U.S. officials are investigating whether Iran is behind cyber attacks on water systems in at least seven states.
“These threat actors are targeting water entities of all sizes,” CISA’s advisory states. “Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.”
The confirmed hacks into U.S. water utilities put a finer point on another piece of CISA guidance released this week, “Advice for Isolating Vital Systems.” Released in conjunction with the Australian Signals Directorate and other international partners, the guidance tells critical infrastructure owners and operators how to protect essential OT systems from threats.
“As part of our CI Fortify Initiative, CISA, with our partners, provides this timely, collaborative resource that helps critical infrastructure ensure resilience during a crisis,” CISA acting Executive Assistant Director for Cybersecurity Chris Butera said in a statement. “CISA urges OT owners and operators to maintain robust isolation and recovery plans so that essential services can continue under degraded conditions, enabled through either manual or alternative [Supervisory Control and Data Acquisition] paths. Through proactive planning and practice, we can strengthen critical infrastructure defenses against state-sponsored threat actors.”
CISA wades into open source
CISA also released a new guide tailored specifically to federal agencies. The “Open Source Software: Security Principles and Practices” is meant to provide agencies with a process to review and approve open-sources software that meets their needs while managing risks.
“CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public,” Butera said in a news release.
The guide is notable as it comes amid a raging policy debate over the risks of open source AI systems. Some officials in the Trump administration are reportedly in favor of banning cutting edge foreign open-source AI models to address security concerns.
Many big tech companies are urging the administration not to take that step, arguing in a letter that a ban could backfire and “openness may be one of the most important paths to AI safety and security.”
CISA doesn’t come close to wading into that fractious policy debate. But the agency’s guide does address how agencies should approach open source AI.
“For open source AI systems, the guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes,” CISA states. “Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks.”
SBOM and SCuBA
CISA also released new guidance and updates on two niche but closely tracked issues for federal agencies and contractors.
First, the agency released the first update to the “minimum elements” required in a Software Bill of Materials (SBOM) in five years. CISA’s guide builds on the foundational 2021 document released by the National Telecommunications and Information Administration.
And importantly, the SBOM guide applies to all software, including open-source software, AI software, and software-as-a-service (SaaS), according to CISA.
“With these updated minimum elements, organizations are better positioned to make stronger risk-informed decisions, enhance their cybersecurity posture, and leverage scalable, machine-readable supply chain management processes,” CISA said.
While agencies don’t generally require SBOMs from software vendors – despite a strong push to make that a requirement over the last several years – the Trump administration’s latest software security guidance still gives agencies leeway to include SBOM rules in their own procurements.
Meanwhile, CISA also released a new update to its Secure Cloud Business Applications project, known as “SCuBA.” The program released an updated configuration baseline for Google Workspace products, as well as a major update to an associated assessment tool known as “ScubaGoggles.”
The goal of the nearly four-year old SCuBA program is to help ensure agencies use standard security configurations for widely used cloud collaboration tools and avoid the misconfigurations that so often lead to cybersecurity problems in the cloud.
The new configuration baselines should also help agencies meet federal security requirements, like a CISA binding operational directive on secure practices for cloud collaboration platforms.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.