IndustrialCyber

Warner, Cruz propose voluntary telecom cybersecurity framework and third-party certification after Salt Typhoon


Two U.S. Senators introduced a bipartisan legislative bill in response to the Salt Typhoon hacks that widely compromised U.S. and global telecommunications infrastructure. Senator Mark Warner, a Virginia Democrat and Ted Cruz, a Texan Republican, introduced the Telecommunications Cybersecurity and Resilience Act that proposes to establish a voluntary framework for telecom cybersecurity, bringing providers, suppliers, cybersecurity experts and relevant state, local and federal agencies together to develop practical, risk-based security practices focused specifically on the telecommunications sector. 

The bill would also establish a voluntary certification process based on independent third-party assessment and certification of companies’ adoption of the practices. The bill would review and update the proposed cybersecurity practices at least every two years and after major cyber incidents or significant changes in the threat landscape. Warner and Cruz said the framework is intended to strengthen communications networks while keeping security practices responsive to evolving threats.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way. If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient,” Warner said in a media statement. “This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”

“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” according to Cruz. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated. As Commerce Committee chairman, I will continue working to strengthen the networks Americans rely on while preserving the innovation needed to protect them.”

The Telecommunications Cybersecurity and Resilience Act would create a telecommunications cybersecurity working group among providers, suppliers, cybersecurity experts, and relevant state, local, and federal agencies to develop practical, risk-based cybersecurity best practices focusing on the telecommunications sector. It would also create a voluntary certification process that puts real accountability behind adopting best practices through independent third-party assessment and certification.

The bill also requires reviewing and updating best practices at least every two years and after major cyber incidents or significant changes in the threat landscape.

The bill prescribes that the Telecommunications Cybersecurity Working Group would be set up within the National Telecommunications and Information Administration (NTIA). The public-private advisory body would develop industry best practices, along with adoption instructions and supporting materials; create a network of independent third-party assessors eligible to certify implementation and maintenance of those practices; and provide technical feedback and implementation guidance.

The Working Group would include representatives from NTIA, CISA, NIST, ODNI, ONCD, NSA, and the Federal Communications Commission, as well as industry members. Industry representation would include national telecommunications carriers; regional and rural carriers, including small and medium-sized providers; communications-sector suppliers such as network infrastructure and equipment manufacturers; software and systems providers offering cloud services, network management or cybersecurity tools; state and local government communications or emergency network operators; independent cybersecurity experts and academia; and other relevant supply-chain stakeholders.

Industry members would serve terms of up to two years and could be reappointed for one successive term. The Working Group would establish procedures for replacing members whose terms end or who leave for other reasons. Members who fail to comply with the Working Group’s conflict-of-interest policy would be removed. The Working Group would have two co-chairs. One would be the NTIA assistant secretary, while the other would be selected by a majority vote of the industry members.

The Working Group would adopt and enforce a written conflict-of-interest policy requiring members to act in the Working Group’s interest, report conflicts of interest, including the appearance of a conflict, and refrain from deliberations or votes in which they or their employers would directly and materially benefit. Members would be required to publicly disclose relevant financial and employment relationships, with recusal procedures when conflicts arise. The Working Group’s designated federal officer would maintain records of these disclosures and provide summaries to NTIA.

The Office of the Director of National Intelligence, in coordination with other appropriate federal entities, would ensure that the Working Group has access to relevant cybersecurity threat information. This could include closed or classified briefings for members who are eligible to receive such information when appropriate.

The Working Group could hold closed or restricted-access sessions when the NTIA assistant secretary determines that discussions involve classified information, sensitive cybersecurity vulnerabilities, threat information, proprietary business information or other information exempt from public disclosure.

The NTIA assistant secretary would publish industry best practices, implementation guidance and criteria for third-party assessors. NTIA would also publish the Working Group’s bylaws, membership and procedures on its website and submit them to relevant congressional committees. In addition, NTIA would publish a memorandum of understanding or equivalent written coordination agreement among NTIA, CISA, NIST and the FCC outlining their respective roles, coordination and procedures to avoid duplication under the legislation. The bill would also exempt the Working Group from the general termination provision for federal advisory committees.

The bill would require the Telecommunications Cybersecurity Working Group to develop and maintain voluntary cybersecurity best practices within 18 months of enactment. The practices would apply to telecommunications carriers, communications-sector suppliers and other eligible supply-chain participants, focusing on identifying, preventing, responding to, mitigating and remediating cybersecurity incidents and vulnerabilities. They would be risk-based and aligned with existing federal frameworks, including the NIST Cybersecurity Framework and Risk Management Framework, while avoiding duplication of existing processes and reflecting current threat intelligence, federal advisories and technology developments.

The practices could address applying security updates to network devices, decommissioning devices that no longer receive security updates or applying secure alternatives, maintaining hardware, software and firmware configuration-management practices, and implementing appropriate multifactor authentication or identity and access controls. The Working Group would review practices at least every two years, with interim updates possible following significant cybersecurity incidents or material changes in threat conditions.

NTIA would publish the practices and implementation guidance to promote transparency and voluntary adoption across the telecommunications sector. Detailed guidance could be withheld from public release when necessary to reduce cybersecurity risks but would remain available to eligible entities and cybersecurity assessors involved in certification. Information provided by eligible entities to inform the guidance could not be used in regulatory or enforcement proceedings, and the bill would not expand the FCC’s authority to impose cybersecurity regulations or require adoption of the voluntary practices.

The assistant secretary would be required to submit an annual report to relevant congressional committees and publish a public version on NTIA’s website, beginning one year after the Industry Best Practices are published. The report would cover the development and updates of the practices, participation in the certification process, early reassessment activity, adoption of the practices, and their effectiveness in improving cybersecurity across the telecommunications sector.

The bill would also require an event-triggered report within 90 days of a substantial revision to the Industry Best Practices or a significant telecommunications-sector cyber incident. The report would include, to the greatest extent practicable, the Working Group’s consensus views and recommendations for improving cybersecurity across the sector.



Source link