Showing posts with label Communications Cybersecurity. Show all posts
Showing posts with label Communications Cybersecurity. Show all posts

Saturday, March 11, 2017

HR 1335 Introduced – Communications Cybersecurity

Last week Rep. Clarke (D,NY) introduced HR 1335, the Cybersecurity Responsibility Act of 2017. The bill would require the FCC to issue rules providing cybersecurity requirements for communications networks.

Communications Security


Section 2 of the bill would require the FCC to “issue rules to secure communications networks through managing, assessing, and prioritizing cyber risks and actions to reduce such risks” {§2(a)}. It also requires that those rules would establish that communications networks would be considered critical infrastructure and that information submitted to the FCC and DHS about such networks would be protected as Critical Infrastructure Information.

The key term in this bill is ‘communication network’. The bill provides a broadly inclusive definition: “a network for the provision of wireline or mobile telephone service, Internet access service, radio or television broad casting, cable service, direct broadcast satellite service, or any other communications service” {§2(c)}.

Moving Forward


Clarke is a fairly senior member of the House Energy and Commerce Committee to which the bill was assigned for consideration. This means that she may have the influence necessary to have the bill be considered in Committee.

Since the bill, however, provides relatively broad regulatory powers to the FCC there will be a great deal of push back from industry. This means that there would be substantial Republican opposition to this bill. It is unlikely that there would be much support for moving this bill forward.

Commentary



The ‘any other communications service’ provisions of the communication network definition could provide FCC authority to regulate the communications networks associated with physically distributed control systems like SCADA networks. Initially, it would be unlikely that the FCC would exercise that sort of authority; developing regulations for more traditional communications networks would take up a great deal of time for the FCC.

Thursday, March 9, 2017

HR 1324 Introduced – Communications Cybersecurity

Last week Rep. McNerney (D,CA) introduced HR 1324, the Securing the Internet of Things (IOT) Act of 2017. The bill would require the Federal Communications Commission (FCC) to establish cybersecurity standards for radio frequency equipment regulated by the FCC.

Cybersecurity Standards


Section 2 of the bill would amend 47 USC 303; adding a new paragraph (cc). It would require the FCC to establish cybersecurity standards for radio frequency equipment regulated under 47 CFR Part 2, Subpart J. Those standards would apply “throughout the lifecycle of the equipment, including design, installation, and retirement”.

The bill would require the FCC to establish the regulations implementing these cybersecurity requirements within 180 days of the adoption of the bill. The standards would apply “to radio frequency equipment for which an application for certification is submitted after the date that is 1 year after the date of the enactment of this Act” {§2(c)}.

Moving Forward


McNerney is a member of the House Energy and Commerce Committee two which this bill was referred. He is a relatively low ranking Democrat on the Committee, so it is possible that he may have enough influence to have the bill considered by the Committee.

The bill is likely to engender a great deal of opposition from a wide variety of manufacturers. This would ensure that there was extensive Republican (and at least some Democratic) opposition to the bill. This bill is unlikely to be considered in the 115th Congress.

Commentary


While the title of the bill would seem to indicate that McNerney intended this to address IOT security issues, it is written with a much larger brush. Any piece of equipment that has radio frequency emissions would be subject to the cybersecurity standards required by this bill.

The lack of any definitions in the bill and the short rulemaking deadline make establishing any effective cybersecurity standards extremely unlikely. Without limiting definitions, the FCC would be required to either come up with some very generic standards that applied to all RF emitting equipment, or attempt to establish workable subcategories of cyber vulnerable equipment for which reasonable standards could be written. The first option would be totally ineffective, but would still require costly compliance activities. The second option would be very time consuming for the FCC (completely missing the 180-day deadline) and would require a very large expansion of cybersecurity engineering professionals to meet the compliance requirements.


The most interesting portion of the legislation is the requirement to include cybersecurity requirements through the retirement of devices. I would assume that this is an attempt to ensure the privacy protection of information stored on a device after it is retired from service. While trying to define ‘retirement’ could prove problematic, the process standard could be something as simple as providing an effective erase mechanism for any information storage device. How that final erasure would be initiated (and protected from inadvertent activation) could prove to be an expensive engineering problem.
 
/* Use this with templates/template-twocol.html */