Drinking Water Utilities Amendments
What changed between versions
Added clear definitions for 'authorized employee,' 'control system,' 'operational technology,' and 'secure area' to establish what systems and personnel are covered by security requirements.
Added specific cybersecurity requirements including software updates, secure passwords, annual cybersecurity training, internal vulnerability assessments, and procedures for removing access when employees leave.
Established staggered deadlines for security plan completion: systems serving 10,000+ people must complete plans by July 1, 2025, while smaller systems have until July 1, 2026.
Added requirement to report security breaches to the Utah Cyber Center within two hours of discovery, with the center required to notify the Division of Drinking Water within one day.
Added Section 63G-2-305 to classify community water system security plans as protected records, preventing public disclosure of sensitive security information.
Removed a study requirement about water provider efficiencies that was in the original version, focusing instead on the security plan implementation.