ZeroHour
CyberScooppublished ()ingested @WatermanReports

FCC looks to tackle IoT cybersecurity through 5G regulation

criticalPolicy & legal exploited in the wildimportance 60
Full article945 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Having abandoned one regulatory approach this year, the FCC is now looking to 5G rules to provide security standards-setting authority for the internet of things.

Getty

The Federal Communication Commission’s Bureau of Public Safety and Homeland Security has released a wide-ranging set of questions for industry about the cybersecurity of 5G — the next generation of cellular networks promising to provide connectivity for the coming wave of billions of IoT devices.

The Notice of Inquiry released last week poses 130 questions about 5G cybersecurity — covering a huge variety of topics from encryption, authentication and security-by-design, to the availability of remote software upgrades, defense against DDoS attacks and network awareness.

Comments are due within 90 days of the Dec. 16 publication date and replies to those comments by 120 days after publication.

The notice comes on the heels of an FCC decision earlier this month to drop another more controversial effort aimed at IoT regulation using different powers. And follows an agency order in July allocating spectrum for 5G cellular and fixed broadband networks, which required successful licensees to submit network security plans to the commission. That security reporting provision is under protest by telcos and industry.

The agency said in the notice that it was trying to get ahead of security threats as the technology standards that will define 5G are developed — and companies start testing, perhaps as soon as 2018.

“While the Commission is moving quickly to make the spectrum needed for 5G available in the near term, it is also seeking to accelerate the dialogue around the critical importance of the early incorporation of cybersecurity protections in 5G networks, services, and devices,” states the notice.

One of the issues raised: Who should be responsible for cybersecurity? It’s germane because there may well be six or seven different companies involved in manufacturing, programming, assembling, marketing, and connecting an IoT device. And for each different kind of device, there might be different kinds of companies involved.

“Devices and other network elements may be furnished by the service provider, third parties, and consumers themselves. Who should be responsible for cyber protections for a device, or should responsibility be shared in some recognizable manner across the 5G ecosystem?” the notice asks.

A notice of inquiry often is the first step in a regulatory process, but it’s obviously unclear at this stage how the FCC will proceed next year. Although the agency is independent, its chairman is appointed by the president and the current incumbent, Tom Wheeler, has indicated he will step down Jan. 20.

In a letter earlier this month, Wheeler told Congress he was abandoning a plan to use the FCC’s unilateral authority to regulate wireless devices as a lever to set standards for IoT cybersecurity.

In that letter, Wheeler referenced the ongoing work of the Interagency Cybersecurity Forum for Independent and Executive Branch Regulators that he heads — a body where the FCC and other agencies work to coordinate their rule-making activity.

Within the forum, a work-plan attached to the letter states, a task-force should be created of officials to “assess the full scope of IoT cyber threats to critical infrastructure, existing regulatory authorities and mitigation recommendations within those authorities, as well as those authorities requiring statutory change.”

And the notice also references the work of other government agencies, saying, “We are not conducting this NOI in a vacuum. We intend this inquiry to complement the important work on cybersecurity that is already taking place within the government and private sector.”

More Scoops

FCC Chairwoman Jessica Rosenworcel attends the Paley International Council Summit at Paley Museum on Nov. 8, 2022 in New York City. Rosenworcel spoke with CyberScoop about her tenure as FCC Chair, which will end Jan. 20, 2025. (Photo by Steven Ferdman/Getty Images)

Exit interview: FCC’s Jessica Rosenworcel discusses her legacy on cybersecurity, AI and regulation

The outgoing chair weighs in on how the FCC has addressed newer technologies, efforts to respond to Chinese intrusions into U.S. telecom networks, and regulating AI in…

Consumers are increasingly adopting smart home devices, such as internet-connected coffee machines, that are also at risk of being hacked. (Getty Images)

FCC approves cybersecurity label for consumer devices

Deputy National Security Advisor for Cyber and Emerging Tech Anne Neuberger speaks during a press briefing at the White House on February 18, 2022 in Washington, DC. (Alex Wong/Getty Images)

Biden administration wants to avoid 5G mistakes in race to beat China on 6G

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fcc-iot-5g-cybersecurity/