FCC looks to tackle IoT cybersecurity through 5G regulation
Full article945 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Having abandoned one regulatory approach this year, the FCC is now looking to 5G rules to provide security standards-setting authority for the internet of things.
The Federal Communication Commission’s Bureau of Public Safety and Homeland Security has released a wide-ranging set of questions for industry about the cybersecurity of 5G — the next generation of cellular networks promising to provide connectivity for the coming wave of billions of IoT devices.
The Notice of Inquiry released last week poses 130 questions about 5G cybersecurity — covering a huge variety of topics from encryption, authentication and security-by-design, to the availability of remote software upgrades, defense against DDoS attacks and network awareness.
Comments are due within 90 days of the Dec. 16 publication date and replies to those comments by 120 days after publication.
The notice comes on the heels of an FCC decision earlier this month to drop another more controversial effort aimed at IoT regulation using different powers. And follows an agency order in July allocating spectrum for 5G cellular and fixed broadband networks, which required successful licensees to submit network security plans to the commission. That security reporting provision is under protest by telcos and industry.
The agency said in the notice that it was trying to get ahead of security threats as the technology standards that will define 5G are developed — and companies start testing, perhaps as soon as 2018.
“While the Commission is moving quickly to make the spectrum needed for 5G available in the near term, it is also seeking to accelerate the dialogue around the critical importance of the early incorporation of cybersecurity protections in 5G networks, services, and devices,” states the notice.
One of the issues raised: Who should be responsible for cybersecurity? It’s germane because there may well be six or seven different companies involved in manufacturing, programming, assembling, marketing, and connecting an IoT device. And for each different kind of device, there might be different kinds of companies involved.
“Devices and other network elements may be furnished by the service provider, third parties, and consumers themselves. Who should be responsible for cyber protections for a device, or should responsibility be shared in some recognizable manner across the 5G ecosystem?” the notice asks.
A notice of inquiry often is the first step in a regulatory process, but it’s obviously unclear at this stage how the FCC will proceed next year. Although the agency is independent, its chairman is appointed by the president and the current incumbent, Tom Wheeler, has indicated he will step down Jan. 20.
In a letter earlier this month, Wheeler told Congress he was abandoning a plan to use the FCC’s unilateral authority to regulate wireless devices as a lever to set standards for IoT cybersecurity.
In that letter, Wheeler referenced the ongoing work of the Interagency Cybersecurity Forum for Independent and Executive Branch Regulators that he heads — a body where the FCC and other agencies work to coordinate their rule-making activity.
Within the forum, a work-plan attached to the letter states, a task-force should be created of officials to “assess the full scope of IoT cyber threats to critical infrastructure, existing regulatory authorities and mitigation recommendations within those authorities, as well as those authorities requiring statutory change.”
And the notice also references the work of other government agencies, saying, “We are not conducting this NOI in a vacuum. We intend this inquiry to complement the important work on cybersecurity that is already taking place within the government and private sector.”
More Scoops
Exit interview: FCC’s Jessica Rosenworcel discusses her legacy on cybersecurity, AI and regulation
The outgoing chair weighs in on how the FCC has addressed newer technologies, efforts to respond to Chinese intrusions into U.S. telecom networks, and regulating AI in…
FCC approves cybersecurity label for consumer devices
Biden administration wants to avoid 5G mistakes in race to beat China on 6G
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fcc-iot-5g-cybersecurity/