Commerce Department proposes rules for implementing Trump’s supply
Full article641 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The proposal is a key step toward making a more stringent national policy governing U.S. supply chains a reality.
The Department of Commerce on Tuesday outlined how it might implement a White House order that gives the department broad leeway to ban foreign parts in U.S. IT and communications supply chains because of security concerns.
Secretary of Commerce Wilbur Ross will “adopt a case-by-case” approach to determining what components will be banned, drawing on assessments from the Department of Homeland Security and the Office of the Director of National Intelligence, the department said in a statement.
Under the proposal, before making a final decision to exclude a foreign company from U.S. software and hardware supply chains, the Commerce Secretary would give the company an opportunity to address U.S. security concerns and avoid a ban. The secretary would send an unclassified ruling to the parties explaining the decision and make that public when appropriate.
The proposal is a key step toward making a more stringent national policy governing U.S. supply chains a reality. The executive order signed by President Donald Trump in May invokes a “national emergency” to close security gaps in the software and hardware that U.S. critical infrastructure companies acquire from other countries.
The policy changes come amid consistent warnings from multiple federal agencies that foreign spies have looked to infiltrate U.S. supply chains.
U.S. officials often call out telecommunications gear from Chinese companies Huawei and ZTE as being potential conduits for Chinese espionage. Those companies deny the claims.
But U.S. concerns go far further than any one company or government. Foreign adversaries are increasingly planting and exploiting vulnerabilities in IT “in order to commit malicious cyber-enabled actions, including economic and industrial espionage” against Americans, the executive order states.
The executive order is one of a series of measures that the Trump administration has taken on supply-chain security. The Department of Homeland Security has a National Risk Management Center working on the issue, and an interagency “acquisition council” warns agencies away from buying insecure products.
The Department of Commerce welcomed an assortment of public comments over the next month on the proposal, just not anything related to what constitutes a “foreign adversary.” That, the department said, is up to Ross.
Sometimes the risks to U.S. government and corporate supply chains are hiding in plain sight.
U.S. prosecutors last month announced charges against a New York company for allegedly selling Chinese-made surveillance equipment with known cybersecurity flaws while falsely claiming the technology was made in the U.S.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/supply-chain-security-commerce-department/