FCC Approves New Cybersecurity Rules
The Federal Communications Commission (FCC) has approved new rules to enhance cybersecurity for the nation's emergency alert systems and undersea cables. The rules aim to better protect against hijacking attacks from malicious actors and update security standards for these critical systems.
The Emergency Alert System (EAS) and Wireless Emergency Alerts (WEA) are two national emergency systems that will be overhauled by the new rules. The EAS is a national public warning system used by state and local authorities to disseminate information related to weather events, AMBER alerts, and other emergencies via radio and television broadcasting stations. The WEA handles similar messaging via text.
Consequences of Vulnerabilities
A compromise of either system by a foreign government, cybercriminal group, or other rogue actor could have serious consequences, including sowing chaos and disinformation in calmer times or impeding coordination efforts in the face of a genuine emergency. According to FCC Commissioner Olivia Trusty,
any vulnerability in systems like the Emergency Alert System can have serious consequences. Trusty emphasized the importance of safeguarding the infrastructure that supports the delivery of life-saving alerts.
New Cyber Hygiene Practices
The new rules introduce basic but critical cyber hygiene practices for users accessing and updating the EAS and WEA systems. These practices include using strong passwords, quickly installing security patches from vendors, and using firewalls to limit access to their equipment. Additionally, a new authentication ID system will be implemented to verify alerts before they are submitted, avoiding duplicate or unauthorized alerts from spreading.
Updated Submarine Cable Regulations
Another rule passed by the Commission provides the first comprehensive update to the FCC's submarine cable regulations in decades. The update tightens cybersecurity requirements in some areas while loosening them in others. It exempts some undersea cable providers from submitting to stringent national security licensing reviews needed to land and operate cables that touch U.S. territory.
The review, known as Team Telecom, is an interagency body led by the Department of Justice's Foreign Investment Review Section and other federal agencies that advise the FCC on the national security implications of their telecom policies. The new rules would presumptively exempt applications for undersea cable licensees when the provider can self-certify to high security standards that are structured to increase certainty, predictability, and faster timelines for the licensing process.
Greater Oversight and Updated Safeguards
Other parts of the rule give the FCC greater oversight of critical functions within undersea cable operations. Owners and operators of submarine line terminal equipment, who connect submarine cables to land-based facilities in the U.S., will be subject to a new licensing requirement. The rule also updates safeguards meant to address vulnerabilities related to principal equipment, third-party service providers, and other areas of concern in the undersea cable supply chain.
According to the FCC,
currently, all submarine cable applications get referred to Team Telecom. The changes adopted would exempt applications from applicants that have operated cables without incident, can certify to the highest national security standards, and agree to ongoing oversight and monitoring.
Source: CyberScoop