Connect with us

Cybersecurity

Commerce Dept. Recommends Public-Private Partnership on Cybersecurity

WASHINGTON, June 9, 2011 – The Department of Commerce released its Cybersecurity, Innovation and the Internet Economy green paper on Wednesday, advising cooperation between the government and private sector to implement ways to address cybersecurity issues.

The Internet Policy Taskforce, a department-wide group created in April 2010, wrote the green paper with the goal of addressing the pressing issues surrounding cyber security.

Published

on

WASHINGTON, June 9, 2011 – The Department of Commerce released its Cybersecurity, Innovation and the Internet Economy green paper on Wednesday, advising cooperation between the government and private sector to implement ways to address cybersecurity issues.

The Internet Policy Taskforce, a department-wide group created in April 2010, wrote the green paper with the goal of addressing the pressing issues surrounding cyber security.

Global online transactions have grown annually and currently account for $10 trillion in global trade. There has also been an increase in malware; between January 2009 and December 2010 the number of malware attacks doubled. In 2010, there were 55,000 new viruses, worms, and spyware threats.

“Our economy depends on the ability of companies to provide trusted, secure services online. As new cybersecurity threats evolve, it’s critical that we develop policies that better protect businesses and their customers to ensure the Internet remains an engine for economic growth,” said Commerce Secretary Gary Locke in a statement.

The green paper suggests that the government should support the creation of national code of conduct to deal with cybersecurity vulnerabilities. The new code of conduct should be created through a public-private collaboration rather than governmental edict. In addition to a code of conduct, the government hopes that industry will develop a set of standards which can be universally adopted.

“By increasing the adoption of standards and best practices, we are working with the private sector to promote innovation and business growth, while at the same time better protecting companies and consumers from hackers and cyber theft,” said Locke.

To protect consumers and business from the economic damages sustained by cyber-attack, the green paper suggestions the creation of cyber insurance. According to the paper, the market for cyber insurance would range from $450-500 million. Before any cyber insurance product is created however, industry must first determine how best to evaluate the costs of cyber-attacks.

In order to expand knowledge on potential cyber-attacks and vulnerabilities the report recommends the establishment of a National Initiative for Cybersecurity Education that would coordinate and fund research.

In addition to educating the business community about cyber-attacks and threats, the report recommends the addition of cyber protection to current digital literacy programs.

To further knowledge of cyber threats, the green paper recommends that the U.S. expand international collaboration: “The fact that cybersecurity is not defined by national borders and that the United States cannot afford to ignore global consideration…..The importance of engaging with our international partners early and often on matters related to standards development and policies is an essential starting place.”

In order to protect consumers, the report asks Congress to create a law that creates a framework for the notification of customers when electronic records have been breached. This recommendation is very similar to legislation currently proposed by Sen. Patrick Leahy (D-VT), the Personal Data Privacy and Security Act. Leahy’s bill would establish a national standard for the notification to consumers by corporations when data breaches occur.

The full green paper can be found here.

 

Rahul Gaitonde has been writing for BroadbandBreakfast.com since the fall of 2009, and in May of 2010 he became Deputy Editor. He was a fellow at George Mason University’s Long Term Governance Project, a researcher at the International Center for Applied Studies in Information Technology and worked at the National Telecommunications and Information Administration. He holds a Masters of Public Policy from George Mason University, where his research focused on the economic and social benefits of broadband expansion. He has written extensively about Universal Service Fund reform, the Broadband Technology Opportunities Program and the Broadband Data Improvement Act

Cybersecurity

FCC Halts Authorization of Equipment That Threatens National Security

The FCC’s order prevents future authorizations of equipment on the commission’s “Covered List” of national security threats.

Published

on

Photo of FCC Commissioner Brendan Carr

WASHINGTON, November 28, 2022 – The Federal Communications Commission published Friday a modification of certification rules that will bar from United States markets technologies that are considered threats to national security.

The commission’s action seeks to prevent Chinese tech companies deemed to be national security threats – such as Huawei and ZTE – from gathering data on and surveilling American citizens. The Chinese Communist government can force, under law, private companies to hand over data from their products, thus putting Americans at risk, experts and government officials have said.

Friday’s action bars the commission from issuing further authorizations for covered technologies, without which those technologies may not be imported to or marketed in the United States. The action also closes loopholes that would allow certain products to skirt the authorization process.

“That does not make any sense,” said FCC Chairwoman Jessica Rosenworcel in a statement. “After all, there is little benefit in having these lists and these bans in place just to leave open other opportunities for this equipment to be present in our networks. So today we are taking action to align our equipment authorization procedures with the rest of our national security policies.”

The FCC already publishes a list of entities and products, on the advice of Public Safety and Homeland Security,  that pose national security risks. The commission has long shown skepticism toward such risky technologies, notably disallowing the use of universal service funds to buy certain products in 2019.

The rule covers many types of equipment, including base stations, phones, cameras, and Wi-Fi routers.

With this decision, the FCC has fulfilled a congressional mandate to enact a moratorium on equipment on the covered list within 12 months. The statute followed a notice of proposed rulemaking it issued last year.

Congress in 2017 forbade the Department of Defense from using telecommunications equipment or services from Huawei or ZTE. Building on that effort, Congress the next year expanded prohibitions on federal use of technology from those companies and three others. In 2019, in response to concerns over the integrity of communications networks and supply chains, the White House declared a national emergency.

In March 2020, then-President Donald Trump signed into law the Secure Networks Act, requiring the FCC to prohibit the use of moneys it administers for the acquisition of designated communications equipment. The act promoted the removal of existing compromised equipment through a reimbursement program – called Rip and Replace – and further directed the commission to create and maintain the covered list.

FCC Commissioner Brendan Carr, outspoken on national security issues, celebrated Friday’s decision, but called for further action.

“We must also vigilantly monitor compliance with the rules we’ve established today, including by ensuring that entities do not make an end run around our decision by ‘white labeling’ covered gear – a process that involves putting a benign or front group’s name on equipment that would otherwise be subject to our prohibitions,” Carr said in a statement.

Rosenworcel said in her statement that the order covers “re-branded or ‘white label’ equipment that is developed for the marketplace. In other words, this approach is comprehensive.”

Carr also once again called for federal action against TikTok, the Chinese built social media app. The video-sharing app gathers extensive data on users, and despite protestations to the contrary, the platform routinely feeds Americans’ information to the Chinese government, reports say.

“Secure networks mean little if insecure applications are allowed to run, sweep up much of the same sensitive data, and send it back to Beijing,” Carr said.

Continue Reading

China

Report Urges States, Local Governments Follow Federal Rules on Prohibited Equipment Purchases

Only a handful of states have crafted their purchasing decisions after federal rules banning certain companies’ equipment.

Published

on

Members of the Center for Security and Emerging Technology at Georgetown University

WASHINGTON, November 14, 2022 – A think tank is recommending state and local governments align their rules on buying technology from companies with federal guidelines that prevent agencies from purchasing certain prohibited foreign technology, such as ones from Chinese companies.

The Center for Security and Emerging Technology at Georgetown University notified the Federal Communications Commission late last month of a report released that month regarding what it said was a concerning trend of state and local governments having outdated procurement policies that are seeing them purchase equipment banned for federal purchase.

“State and local policymakers should not be expected to independently analyze and address the threats posed by foreign technology, but it would behoove them to align their own procurement practices with the rules set by the federal government,” the report recommends.

The FCC has a list of companies, as required by the Secure and Trusted Communications Networks Act of 2019, that it updates on a rolling basis through commission votes that it says pose a national security threat to the country’s networks. It last updated the list in September, when it added Pacific Network Corp. and China Unicom Operations Ltd. to the growing list that already includes Huawei and ZTE.

Chinese companies and following Communist Party directions

U.S. officials and experts have warned that Chinese companies operating anywhere in the world must follow directions of the Chinese Communist Party, which they say could mean anything from surveillance to American data falling into the hands of that government.

The report notes at least six state governments had their networks breached by a state-sponsored Chinese hacking group between May 2021 and February 2022.

The only states that have enacted local regulations aligned with federal provisions are Florida, Georgia, Louisiana, Texas, and Vermont, the report said. Provisions in Georgia and Texas prohibit private companies from entering into agreements with the covered companies. Vermont, Texas and Florida provisions block state entities from purchasing equipment from countries like China, Russia, Iran, North Korea, Cuba, Venezuela and Syria. Louisiana and Georgia provisions ban public-funded schools from buying prohibited technology.

The remaining 45 states do not explicitly target the equipment and services they produce, nor are they directly responsible for following federal provisions, the report said, leaving state entities vulnerable in obtaining equipment from third party contractors that could pose a security risk.

“Many government entities also lack the in-house technical expertise and procedures to understand and address such threats in the first place, and those that do may prioritize addressing immediate threats like ransomware over the more abstract risks posed by foreign ICTS,” the report said.

Section 889 of the 2019 National Defense Authorization Act is one out of four federal provisions addressing the issue, prohibiting federal agencies from using equipment and services from Huawei, ZTE, Hikvision, Dahua and Hytera as well as working with contractors that use the equipment.

Prohibited products finding their way in

In some cases, the report said, the listed companies will sell their products to third party contractors that are not listed on Section 889 to bypass regulations, according to the report. Due to the low cost of Chinese equipment, public schools and local governments will purchase from the third-party entities that are unknowingly selling prohibited equipment, it added.

“These ‘middle-man’ vendors can mask the origin of their products, which creates major challenges for organizations aiming to keep certain equipment and services off their networks”, the report reads.

“Currently, contractors are responsible for self-certifying that their products and internal networks do not contain covered [products]” and “… inspecting the IT infrastructure—equipment, services, and components – of every contractor that does business with the federal government would require a staggering level of resources, making it difficult for agencies to conduct effective oversight.”

Continue Reading

Cybersecurity

Internet of Things Devices May Provide a Weak Point for Cybersecurity, Says CableLabs

But every device is a potential way into its network, and the recent explosion of IoT devices presents security risks.

Published

on

Screenshot of Brian Scriber, vice president of security and privacy technologies at CableLabs.

WASHINGTON, November 9, 2022 – Since Internet-of-Things appliances are prime “landing spot[s]” for cyber-attackers looking for network access, industry standards and open-source resources are important to maintaining cybersecurity at the device level, said Brian Scriber, vice president of security and privacy technologies at CableLabs, a non-profit the innovation arm of the cable industrylab.

“The mark that we’re really shooting for is how do we get some industry-led initiatives to really make a difference on the… supply” (of IoT devices),” Scriber said Tuesday on during a cybersecurity panel at the American Enterprise Institute, a conservative think tank.

IoT refers to network-connected devices that can interact with their environments. IoT devices can be refrigerators, thermostats, home-security systems, health-monitoring devices, and much else. But every device is a potential way into its network, and the recent explosion of IoT devices presents security risks.

“If you are an attacker, finding a vulnerable device like a lightbulb is fantastic because it has power constantly, it has the computational ability to be able to engage, you gave it network credentials when you brought it on your network,” Scriber argued. And e

Even a secure network can’t protect against the cyber risks associated with vulnerable devices, he added.

In addition to device security, overall network security is crucial and can be enhanced by limiting communication between devices, suggested said Katerina Megas, program manager of the Cybersecurity for Internet of Things Program at the National Institute of Standards and Technology, a federal agency responsible for technical calibration and standard-setting.

“There has to be an ecosystem approach,” Megas said.

In October, President Joe Bidens administration announced preliminary steps towards a cybersecurity labeling system for IoT devices.

By developing and rolling out a common label for products that meet by U.S. Government standards and are tested by vetted and approved entities, we will help American consumers easily identify secure tech to bring into their homes,” the White House said.

Continue Reading

Signup for Broadband Breakfast

Get twice-weekly Breakfast Media news alerts.
* = required field

Broadband Breakfast Research Partner

Trending