The Federal Communications Commission (FCC) is to vote on repealing security regulations on internet service providers (ISPs), with voluntary assurances to replace Democrat-era directives on securing network cybersecurity.
A Halloween-themed message from FCC Chairman Brendan Carr revealed a vote was due this month to help place the U.S. “on a stronger cybersecurity footing.”
“Following extensive FCC engagement with carriers, the item announces the substantial steps that providers have taken to strengthen their cybersecurity defenses,” wrote Carr. “In doing so, we will also reverse [a] ruling reached by the prior FCC [that] exceeded the agency’s authority.”
The January ruling in question was enforced prior to the start of the current Trump administration, addressing a Communications Assistance for Law Enforcement Act (CALEA) tenet that telecommunications carriers are required “to secure their networks from unlawful access or interception of communications” across both their equipment and network management.
Originally dating from 1994, the requirement was imposed after last year’s Salt Typhoon attack on the likes of AT&T, Verizon, and Lumen Technologies. In its fact sheet on the upcoming vote, the FCC called current regulations “an ineffective response” to the exploit.
An attempt to repeal the FCC decision was filed in February by various telecom lobby groups, including CTIA-The Wireless Association, NCTA-The Internet & Television Association, and USTelecom-The Broadband Association.
The organizations argued that “CALEA’s plain text demonstrates that it is not a general cybersecurity statute” and that “Congress enacted [the directive] to impose a narrow obligation on providers to facilitate lawful intercepts from law enforcement – regardless of what technical standards providers used to secure their networks.”
The groups also claimed the 1994 directive only allowed for “the government to intervene when such standards are deficient,” without establishing the definitions of such deficiency.
“In other words, Congress entrusted the private sector, not the Commission, to set technical standards for networks as a default matter … [and envisioned the rules adopted by the FCC] would relate solely to the supervision and control of the employee authorized to initiate the intercept on behalf of law enforcement and related recordkeeping matters – not to the imposition of broader cybersecurity mandates on providers,” they wrote.
In its fact sheet on November’s vote, the Commission agreed with these claims, adding it was satisfied that “through a collaborative approach, providers have agreed to implement additional cybersecurity controls to harden their networks.”
The Commission’s pivot comes after Ribbon Communications revealed it was the victim of a months-long nation-state hack by an unnamed actor.
The stealth attack saw intruders access Ribbon’s systems for around nine months, according to a Securities and Exchange Commission (SEC) filing made by the firm last week.
Meanwhile, recently published analysis from cybersecurity firm Darktrace claimed a European telecoms organisation was targeted by Salt Typhoon in July.
Affiliated with the People’s Republic of China (PRC), Salt Typhoon’s exploit from last year was dubbed the worst telecom hack in U.S. history to date.
With its new approach, the FCC intends to “pursue an agile and collaborative approach to cybersecurity” on a federal and private level, while offering “more targeted, legally sound rulemaking and enforcement.”
Comments