Wyden legislation would mandate FCC cybersecurity rules for telecoms
Full article602 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It would go beyond the FCC’s own proposal to regulate telecommunications carriers under federal wiretapping law.
Listen to this article
0:00
Learn more.
Sen. Ron Wyden, D-Ore., introduced legislation Tuesday that would require the Federal Communications Commission to regulate the cybersecurity of telecommunications companies under federal wiretapping law.
Wyden’s proposal is the latest response to the breach of telecom firms by Salt Typhoon, the Chinese government-connected hackers who carried out a potentially yearslong espionage campaign by infiltrating telecom networks. Those hackers as of last week still hadn’t been fully evicted from the systems.
“It was inevitable that foreign hackers would burrow deep into the American communications system the moment the FCC decided to let phone companies write their own cybersecurity rules,” Wyden said in a news release. “Telecom companies and federal regulators were asleep on the job and as a result, Americans’ calls, messages, and phone records have been accessed by foreign spies intent on undermining our national security. Congress needs to step up and pass mandatory security rules to finally secure our telecom system against an infestation of hackers and spies.”
The FCC itself last week proposed such rules under the 1994 Communications Assistance for Law Enforcement Act (CALEA). Salt Typhoon reportedly targeted communications accumulated by way of that law, which dictates how telecommunications carriers comply with federal law enforcement requests.
Wyden’s legislation would mandate that the FCC regulate telecommunications cybersecurity under CALEA within one year, in consultation with the Cybersecurity and Infrastructure Security Agency and the Office of the Director of National Intelligence.
Going beyond the FCC proposal, the legislation would also require annual testing of the telecommunications companies’ systems to determine whether they “are susceptible to the interception of communications or access to call-identifying information without lawful authorization by any person or entity, including by an advanced persistent threat.” It would also require them to contract with independent auditors to assess compliance with the FCC rules.
Wyden has taken numerous measures in response to the Salt Typhoon breaches, hailed as the worst in U.S. telecommunications history. Among them is a letter last week with Sen. Eric Schmitt, R-Mo., pressuring the Defense Department to shore up the cybersecurity of its telecommunications carriers.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/wyden-legislation-would-mandate-fcc-cybersecurity-rules-for-telecoms/