FCC Issues Order on Security Reviews Ahead of U.S.-China Engagement

JHVEPhoto/istockphoto

The commission’s new rule on foreign ownership and investment comes amid an industry call for international alignment on the use of voluntary standards to secure the supply chain of information and communications technology

The Federal Communications Commission unanimously refused requests from telecommunications carriers seeking to escape regulations aimed at securing U.S. supply chains from foreign adversaries based on the location of their operations and the classification of some equipment as “commercial.”

“We reject USTelecom’s request to remove Network Operations Center (NOC) facilities from the definition of 'Domestic Communications Infrastructure,'” the FCC wrote in a final document to implement new rules for their approval of entities operating in the United States with a certain level of foreign investment or control. 

The commission voted Thursday on the order that lays out a series of questions companies with at least 5% foreign ownership interest will have to answer when applying for FCC licenses. Applicants would need to submit extensive personally identifiable information for all non-U.S. persons with access to submarine cable facilities, among other information.

USTelecom, the main trade association for the telecommunications industry, argued such information would change too quickly and prove challenging to obtain given the laws in some foreign jurisdictions. The group said NOC’s located abroad should not count as domestic critical infrastructure and therefore shouldn’t be applicable under the new rule. The FCC disagreed. 

“Although a NOC can be located outside of the United States, a foreign NOC can control an entity’s Domestic Communications Infrastructure, and is therefore appropriately included within this definition,” the agency wrote. “Information concerning an NOC located outside the United States, including information regarding the individuals and entities with access to that NOC, is critical information to assess the national security and law enforcement concerns of the foreign NOC.”

According to ex parte filings leading up to the vote, USTelecom also asked for exemptions for commercial-off-the-shelf equipment described in the rule for submarine cable licenses to apply more broadly to applications involving common carriers’ wireless and earth station licenses.

In a press conference after Thursday’s vote, FCC officials said the final order did not include any such substantive changes. 

These aspects of the FCC’s decision could have implications for other suppliers of information and communications technology, such as major cloud providers like Microsoft and other big tech companies as the U.S. promotes a tough-on-China approach to resuming trade negotiations with Beijing.

“For too long, China’s lack of adherence to global trading norms has undercut the prosperity of Americans and others around the world,” U.S. Trade Representative Katherine Tai said Monday during remarks at the Center for Strategic and International Studies. “We will use the full range of tools we have and develop new tools as needed to defend American economic interests from harmful policies and practices.”

Among the issues of contention is the security of intellectual property, which U.S. officials say China acquires through cyberattacks and by further intertwining state-supported enterprises with U.S. companies via mergers or financial investments.  

One high-profile example of the U.S. government’s efforts to curb China’s alleged intellectual property theft is the Defense Department’s Cybersecurity Maturity Model Certification initiative. Like the FCC’s rule for submarine cables, CMMC rules exclude contracts made solely for commercial-off-the-shelf, or COTS, equipment. And like telecommunications companies did with the FCC, big tech companies asked for a broader application of those exceptions.  

The Information Technology Industry Council, or ITI, which represents more than 70 major tech companies, also argued for DOD officials to void the requirement for companies that have already gotten security certifications for standards like those offered by the International Organization for Standardization, or ISO.

But certification to ISO standards can be obtained from accreditation bodies all over the world, including China, and officials like National Security Agency Cyber Director Rob Joyce and other cybersecurity professionals are highlighting the growing use of commercial equipment as a vector for cyberattacks. Renewed engagement with China is also coming after a sweeping attack on Microsoft Exchange servers, which the company ties to Beijing. 

Senior administration officials briefing reporters on plans for the renewed China talks Sunday highlighted engagement with European allies as one of the main differences between its approach and that of former President Donald Trump. They noted agreements to review and enforce limits on foreign investments, among a host of other commitments toward aligning on trade and technology policies. 

European officials have reportedly declined to associate a new U.S.-EU Trade and Technology Council with China. Bringing the U.S. and Europe closer together could arguably mean tougher enforcement of tech companies on issues such as competition and consumer protection, but according to ITI, the TTC was their idea.

“ITI proposed and supported the creation of the TTC,” Robert Strayer, ITI’s executive vice president for policy, said after the council’s first meeting Wednesday. “We commend the U.S. and EU for achieving this significant milestone and appreciated the opportunity to participate in the inaugural meeting today.” 

A press release from ITI in reaction to the council’s commitments pointed to the group’s efforts in January to form the council and its short-term goals for the forum. One such goal was for the U.S. and EU to “establish a commitment to base regulatory or procurement requirements on international, industry-driven, voluntary technical standards.”

“This will be especially important to facilitate forward-looking international regulatory compatibility in areas where governments necessarily depend on technical standards to fully realize the benefits of and inform approaches to new technology (e.g., artificial intelligence, cybersecurity, data portability, IoT products, sustainability and climate),” the association said.

According to the White House, the council “identified a shared interest in using voluntary and multi-stakeholder initiatives to complement regulatory approaches in some areas” related to data governance and technology platforms, including on the role of cloud infrastructure and services.

But White House officials on the Sunday call stressed the administration’s focus on securing the supply chain from foreign influence, and Europe’s commitment to similar efforts, including through joint principles for investment screening and export controls.

“We've been robustly screening Chinese direct investments in the U.S. via the [Committee for Foreign Investment in the United States] process,” one senior administration official said.

The FCC’s decision Thursday cited agreement with a committee made up of representatives from the departments of Homeland Security, Justice, Defense and others, including the intelligence agencies, that also make up CFIUS. That body—commonly referred to as Team Telecom when informing FCC decisions—will have the last word domestically on how to manage supply chain security by controlling foreign investments.

“The Committee staff …  [stated] that submarine cables are U.S. critical infrastructure and that applicants should provide PII and other details about non-U.S. individuals with access to either U.S. or foreign facilities (e.g., cable landing stations, Network Operations Centers, etc.) related to the submarine cable as it is necessary for the Committee’s national security and law enforcement analysis. We agree,” the FCC wrote. “We also agree with Committee staff that submarine cable operators should have in place access control policies for these critical facilities that will enable them to provide details concerning the individuals with access to their facilities, whether they are located in the United States or in a foreign country.”

For some, those concerns should also apply in the case of certain providers of commercial-off-the-shelf services, regardless of foreign ownership.

“Look, companies build software. It's incredibly complex. There are millions of lines of code. Mistakes are made. That happens, it's expected. But when it happens 100 times a month, and when it happens critically, where 70% of the mistakes are critical and we ... are watching those critical vulnerabilities being exploited, over and over and over and over again by adversaries, that's shocking to me,” a former FBI official told Nextgov regarding attacks via Microsoft products.

“This technology is spread throughout the entire world, throughout the U.S. government, it’s constantly being exploited and nobody's saying anything about it,” the former FBI official said. “I don't understand.”

The former official pointed to the hundreds of Microsoft engineers physically based in China and expressed disbelief that U.S. officials aren’t making more of a connection to the security risk that implies. Microsoft is hardly the only major company with such connections to China, but former DHS official Paul Rosenzweig recently amplified concerns around Microsoft in particular, due to what he called a monoculture risk within the federal government. 

CFIUS’ deliberations on related issues could also form precedent for other government bodies—such as the Federal Acquisition Security Council led by the Office of Management and Budget and DHS—which is trying to determine how to more comprehensively secure the supply chain for information and communications technology.

It could be a while before it’s clear whether the new U.S.-EU TTC will succeed in bringing the U.S. and EU together where previous iterations of the forum have failed. For now, action from a united commission suggests cloud providers, along with the rest of the information and communications technology ecosystem, can soon expect to hear more from the FCC. 

“Our work here is obviously far from over,” Brendan Carr, the FCC’s senior Republican, said before the commission’s vote. “We need to close the loophole in our equipment authorization process to ensure that equipment from entities that pose a national security risk will no longer be eligible for FCC approval, and we need to continue our review of all threats to the security of our communications infrastructure, whether those threats come from carriers or service providers, hardware or software.”

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.