A sanitary survey is a routine review of a public water system to check whether it is operating safely and meeting required standards. In this context, the EPA is expanding the survey to include cybersecurity items such as vulnerabilities, defensive measures, and patching practices.
What a sanitary survey is checking
A sanitary survey is a structured review of a water system’s operating condition, treatment, storage, distribution, monitoring, and maintenance practices. Its job is to confirm that the system is being run in a way that protects public health and meets required standards.
For water utilities, the value of the survey is not just inspection, but system-level assurance. It looks for weak points that can affect water quality, service continuity, and operational control before they become incidents.
Because the EPA is expanding the survey to include cybersecurity items, the concept now also covers whether digital dependencies, defensive controls, and patching practices are strong enough to support safe operation.
How the survey works as an operational control
A sanitary survey is usually periodic and evidence-based. It does not replace continuous monitoring, but it gives operators and regulators a way to assess whether the system’s design and day-to-day practices still match the risk it faces.
The survey can surface issues that are easy to miss in routine operations, such as aging assets, poor maintenance discipline, incomplete documentation, or control gaps between field equipment and back-office systems. That makes it a practical governance tool, not just an inspection checklist.
In the cybersecurity-expanded version, the review may also need to consider asset visibility, segmentation, remote access, account hygiene, and recovery readiness. Those items matter because a water system can be physically sound but still be exposed through its connected operational technology and support environment. For control context, see NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST Cybersecurity Framework 2.0.
Why cybersecurity now belongs in the review
The expanded survey reflects a simple reality: water systems are increasingly cyber-dependent. Even when the physical process is stable, compromised visibility, weak patching, or poor defensive configuration can undermine the reliability of treatment and distribution operations.
This is especially important for connected operational environments where control systems, monitoring tools, and remote support paths create additional exposure. Strong identity and access controls, along with good configuration hygiene, help keep those pathways from becoming attack paths. Related identity and access practices are also reflected in NIST AI Risk Management Framework only where AI support systems are part of the operating environment; for the water survey itself, the more direct control references are NIST SP 800-207 Zero Trust Architecture and CIS Benchmarks.
That is why cybersecurity items in a sanitary survey are not a separate topic bolted on at the end, they are part of whether the utility can continue to operate safely under stress, failure, or malicious activity.
What good survey findings should lead to
A useful sanitary survey should end with a clear picture of the system’s highest-risk weaknesses and the operational follow-up they require. In practice, that means the survey should support maintenance priorities, remediation sequencing, and accountability for fixes rather than producing only a compliance record.
Where the survey identifies cyber gaps, the follow-up should focus on the controls that actually change operational risk: patching discipline, configuration hardening, recovery testing, access review, and segmentation of critical systems. The most relevant external control references here are OWASP Non-Human Identity Top 10 for machine and service access hygiene, and NIST SP 800-53 Rev 5 Security and Privacy Controls for the control families that map to monitoring, configuration, and access protection.
Used well, the sanitary survey becomes a bridge between operational inspection and resilience management, helping owners see whether the system is safe not only in theory, but under real-world operating conditions.
Risk and Threat Considerations
When cybersecurity is added to a sanitary survey, the main risk is that a water system can appear operationally healthy while still carrying hidden digital exposure. Weak patching, unmanaged remote access, or poor visibility into connected equipment can create a path for service disruption even when the physical plant looks fine.
Failure mechanism: Attackers or accidental failures exploit outdated software, exposed support paths, or weak segmentation to reach operational systems, interrupt monitoring, or alter system behavior.
Impact: The result can be degraded water service, delayed response, loss of control over critical processes, and a broader public-confidence problem if the utility cannot prove it has effective safeguards.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CM-2 — Baseline Configuration | Sanitary surveys now assess whether systems are maintained in secure, known states. |
| SI-2 — Flaw Remediation | Patch status is a stated survey focus and maps directly to flaw remediation. | |
| AC-17 — Remote Access | Survey cybersecurity items include defensive measures around remote support paths. | |
| Recommendation — Verify and maintain approved baselines for water-system assets and supporting cyber systems. Track and remediate patches on operating and support systems within defined timeframes. Restrict and monitor remote access used for water-system operations and maintenance. | ||
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Sanitary survey cyber review depends on hardened, current configurations. |
| CIS-7 — Continuous Vulnerability Management | The survey explicitly includes vulnerabilities and patching practices. | |
| Recommendation — Harden water-system hosts and software to approved secure configurations. Continuously identify, prioritize, and remediate vulnerabilities on critical assets. | ||
Practitioner Guidance
Why practitioners should care: Treat the expanded sanitary survey as an assurance mechanism for both plant condition and cyber readiness. The review should produce evidence that the system’s technical controls are current enough to support safe operation, not just that the paperwork is complete.
What to watch for: Pay attention to missing asset inventories, long patch windows, unmanaged vendor access, weak recovery assumptions, and control dependencies that are not visible to operations staff. Those are often the conditions that turn a routine inspection finding into an operational incident.
Practitioner takeaway: A strong sanitary survey should tell you where the water system is fragile, where cyber control gaps matter most, and what must be fixed first to reduce real operational risk.
Related resources from NHI Mgmt Group
- How should identity teams use survey findings to prioritise the next phase of IAM and compliance work?
- How should teams prevent survey fraud without crushing legitimate response rates?
- Why do fake survey responses create more than just data quality noise?
- What are the signs that survey fraud is already affecting a dataset?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org