The Federal Communications Commission (FCC) opened the filing window for a cybersecurity authentication related to consumer wireless IoT products.
Applications are now open for entities seeking to be recognized as Cybersecurity Label Administrators (CLAs). CLAs are expected to run a labeling program for such IoT products under the U.S. Cyber Trust Mark (USCTM) Program.
IIA Lab Services and LLC Element Materials Technology Portland – Evergreen were given conditional CLA approval by the FCC’s Public Safety and Homeland Security Bureau (PSHSB).
The FCC noted a CLA automatically loses its authority if it later becomes owned, controlled by, or affiliated with a company producing equipment on the FCC's Covered List, which was recently expanded to include foreign-borne routers, Chinese-affiliated “bad labs,” and IT firms with alleged links to Chinese telecom giants.
The FCC’s focus on IoT security comes as the area remains one of contention due to the blight of legacy devices, according to Alex Leadbetter, chair of TC Cyber at European Telecommunications Standards Institute (ETSI).
"Millions of insecure products remain in circulation, built without patching capabilities. These persistent vulnerabilities will continue to be exploited for years," Leadbetter told SDxCentral.
That risk has led to the rise of distributed denial-of-service (DDoS) attacks leveraging insecure consumer IoT devices, courtesy of notorious botnets such as Aisuru. It has also galvanized deals in the IoT and operational technology (OT) space, including ServiceNow’s $7.75 billion acquisition of cybersecurity firm Armis.
Coinciding with the FCC push, ETSI this week published draft standards developed within the EU Cyber Resilience Act (CRA) framework, including a focus on smart-home security products and general-purpose virtual assistants. The guidelines focus more on consumer safety as opposed to the geopolitical risk underlined by the FCC.
Comments