Document

Promoting the Sharing of Supply Chain Security Risk Information Between Government and Communications Providers and Suppliers

Section 8 of the Secure and Trusted Communications Network Act of 2019 (Act) directs the National Telecommunications and Information Administration (NTIA), in cooperation with o...

Department of Commerce
National Telecommunications and Information Administration
  1. [Docket No. 200609-0154]
  2. RIN 0660-XC046

AGENCY:

National Telecommunications and Information Administration, U.S. Department of Commerce.

( printed page 35920)

ACTION:

Notice, request for public comment.

SUMMARY:

Section 8 of the Secure and Trusted Communications Network Act of 2019 (Act) directs the National Telecommunications and Information Administration (NTIA), in cooperation with other designated federal agencies, to establish a program to share supply chain security risk information with trusted providers of advanced communications service and suppliers of communications equipment or services. Through this Notice and in accordance with the Act, NTIA is requesting comment on ways to facilitate the sharing of security risk information with such trusted providers. These comments will inform the program that NTIA establishes under the Act.

DATES:

Comments are due on or before July 13, 2020.

ADDRESSES:

Written comments may be submitted by email to . Written comments also may be submitted by mail to the National Telecommunications and Information Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW, Room 4725, Attn: Evelyn L. Remaley, Associate Administrator, Office of Policy Analysis and Development, Washington, DC 20230. For more detailed instructions about submitting comments, see the “Instructions for Commenters” section at the end of this Notice.

FOR FURTHER INFORMATION CONTACT:

Megan Doscher, National Telecommunications and Information Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW, Room 4725, Washington, DC 20230; telephone (202) 482-2503; . Please direct media inquiries to NTIA's Office of Public Affairs, (202) 482-7002, or at .

SUPPLEMENTARY INFORMATION:

Section 8 of the Secure and Trusted Communications Network Act of 2019 (Act) directs NTIA, in cooperation with the Office of the Director of National Intelligence, the Department of Homeland Security (DHS), the Federal Bureau of Investigation, and the Federal Communications Commission (FCC), to establish a program to share “supply chain security risk” information with trusted providers of “advanced communications service” and suppliers of communications equipment or services.[1] As part of that program, NTIA must “conduct regular briefings and other events” to share information with trusted providers and suppliers and “engage” with such providers and suppliers, particularly those that are small businesses or that primarily serve rural areas.[2] NTIA must also develop, and submit to Congress, a plan for declassifying material, when feasible, and expediting and expanding the provision of security clearances to facilitate information sharing from the Federal government to trusted providers and suppliers.[3] Therefore, we request comments on several key terms in the Act, as well as on steps that should be taken to best achieve the purposes of the Act.

1. Key Terms:

NTIA seeks information to clarify key terms in the Act.

Supply Chain Security Risk Information

The Act defines “supply chain security risk” information to include “specific risk and vulnerability information related to equipment and software.” [4] NTIA's identification of supply chain security risk information will be aided by other ongoing U.S. Government activities to detect potential security risks to information and communications technology (ICT) supply chains. For example, this effort will be informed by all relevant activities of the National Strategy to Secure 5G, which focuses not only on the identification of information security risks, but on broader strategic risks to the U.S. economy and national security, including risks to the global 5G market, capabilities and infrastructure. Defining “supply chain security risk” to encompass national security and economic risk will reinforce the Act's purpose to safeguard the economy and national critical infrastructure against these risks.[5]

NTIA will also be informed by key terms established by the Federal Acquisition Supply Chain Security Act of 2018, which established the Federal Acquisition Security Council (FASC), which is developing, within the Federal government, risk information sharing policies and procedures comparable to those that the Act contemplates for interactions between the Federal government and the private sector.[6] That legislation defines “supply chain risk” by reference to 41 U.S.C. 4713, which in turn defines the term to mean “the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement of covered articles so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of covered articles or information stored or transmitted on the covered articles.” [7]

NTIA will also consider key terms defined by other bodies, such as the DHS ICT Supply Chain Risk Management Task Force (DHS Task Force), which provides a forum for government-private sector collaboration on supply chain issues and provides advice and recommendations on ways to assess and mitigate risks to the ICT supply chain.[8] One of the DHS Task Force's working groups is identifying and categorizing supply chain threats, as well as providing background information on such threats, their significance, and potential impact on the ICT supply chain.[9]

Trusted Providers and Suppliers

(1) Any executive branch interagency body with appropriate national security expertise, including the Federal Acquisition Security Council; ( printed page 35921)

(2) the Department of Commerce pursuant to Executive Order No. 13873;

(3) the equipment or service being covered is telecommunications equipment or services, as defined in section 889(f)(3) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232; 132 Stat. 1918); or

(4) an appropriate national security agency.

Foreign Adversaries

NTIA directs commenters to the Act's definition of “foreign adversary,” which is identical to that in Executive Order 13873, “Securing the Information and Communications Technology and Services Supply Chain” (E.O. 13873).[11] E.O. 13873 directs the Secretary of Commerce to review, and where necessary, prohibit transactions involving entities owned, controlled, or subject to foreign adversaries that pose unacceptable risks to the U.S. ICT and services supply chain.[12] NTIA notes that the determination of “foreign adversary” for purposes of implementing E.O. 13873 is a matter of executive branch discretion and will be made by the Secretary in consultation with the other agencies identified in the E.O.. To ensure consistency of action across the Federal government, in identifying the providers and suppliers that are eligible under the Act to receive supply chain security risk information, NTIA will rely on pertinent decisions by the Secretary of Commerce under E.O. 13873, as well as other relevant federal determinations.

Advanced Communications Service

Finally, NTIA seeks comment on the term, “advanced communications service.” The Act directs NTIA to share risk information only with trusted providers of “advanced communications service,” which the legislation equates with “advanced telecommunications capability” as defined in section 706 of the Telecommunications Act of 1996.[13] As for mobile services, the FCC has determined that 4G Long Term Evolution services offering transmission speeds between 5Mbps/1Mbps and 10Mbps/3Mbps are the “best proxy” for advanced mobile service.[14]

Questions:

2. Information Sharing Policies and Procedures:

As noted, the Act requires NTIA to share security risk information with trusted providers and suppliers via “regular briefings and other events.” It also requires NTIA to “engage” with trusted parties, particularly small businesses or those serving rural areas. Although the Act mentions small and rural providers and suppliers only in the context of engagements with the Federal government, NTIA believes those entities should be the principal focus of the information sharing program. The Act's overarching goal is the establishment of an FCC program to reimburse smaller providers for removing from their networks and replacing equipment and services that threaten national security.[15] Congress deemed reimbursement for such entities appropriate because it believed that smaller providers did not receive a sufficient “heads-up by our government” about the security risks posed by certain equipment and services and thus made procurement decisions based on the “bottom line.” [16] The information sharing program mandated by Section 8 of the Act was intended to “fix this information gap by ensuring that [small, rural providers] have access to the information they need to keep their networks and Americans secure.” [17] Accordingly, NTIA plans to structure that program primarily to promote the flow of risk information from the government to small and rural providers and suppliers. We request comment on that approach.

Because much security risk information is also highly sensitive, caution must be exercised in disseminating it. Briefings and events involving multiple participants or attendees, for example, risk exposing sensitive information or placing it in the wrong hands. NTIA seeks to balance the need to safeguard this information with the Act's requirement to share it with trusted providers and suppliers. NTIA notes that security risk information is available either publicly or from non-government sources on various terms.[18] For example, Congress and the Executive Branch raised concerns about the security risks posed by certain Chinese equipment suppliers as early as a decade ago.[19]

Questions:

3. Information Declassification and Security Clearances:

NTIA's information sharing program must include a plan for declassifying materials, where feasible, and expanding and expediting the provision of security clearances to facilitate the dissemination of security risk information to trusted providers and suppliers. Because both actions potentially risk compromising the confidentiality of sensitive government information, NTIA is seeking additional information.

Questions:

Instructions for Commenters: NTIA invites comment on the full range of issues that may be presented in this Notice, including issues that are not specifically raised in the above questions. Commenters are encouraged to address any or all of the above questions. Comments that contain references to studies, research, and other empirical data that are not widely available should include copies of the referenced materials with the submitted comments. Comments submitted by email should be machine-readable and should not be copy-protected. Responders should include the name of the person or organization filing the comment, which will facilitate agency follow up for clarifications as necessary, as well as a page number on each page of their submissions. All comments received are a part of the public record and will generally be posted on the NTIA website, www.ntia.gov/​, without change. All personal identifying information (for example, name, address) voluntarily submitted by the commenter may be publicly accessible. Do not submit confidential business information or otherwise sensitive or protected information.

Dated: June 9, 2020.

Kathy Smith,

Chief Counsel, National Telecommunications and Information Administration.

Footnotes

1.  Secure and Trusted Communications Network Act of 2019, Public Law 116-124, 8, 134 Stat. 158, 168 (2020) (codified at47 U.S.C. 1607).

Back to Citation

2.   See id. § 8(a)(2)(A), (B).

Back to Citation

3.   See id. § 8(a)(2)(C).

Back to Citation

4.   Id. § 8(c)(3).

Back to Citation

5.   See Executive Office of the President, National Strategy to Secure 5G of the United States of America, March 2020, available at www.whitehouse.gov/​wp-content/​uploads/​2020/​03/​National-Strategy-5G-Final.pdf.

Back to Citation

6.   See Federal Acquisition Supply Chain Security Act of 2018, Public Law 115-390, Tit. II, § 202, 132 Stat. 5173, 5180-81 (2018) (codified at 41 U.S.C. 1323(a)).

Back to Citation

8.   See DHS, Cybersecurity and Infrastructure Security Agency, Information and Communications Technology Supply Chain Risk Management Task Force: Interim Report, at iii (Sept. 2019) ( DHS Task Force Interim Report), available at www.cisa.gov/​sites/​default/​files/​publications/​ICT%20Supply%20Chain%20Risk%20Management%20Task%20Force%20Interim%20Report%20%28FINAL%29_​508.pdf. For a list of Task Force members and contributors, see id. at v-vi.

Back to Citation

9.   See id. at 17-18.

Back to Citation

10.  Act, § 8(c)(4).

Back to Citation

11.  Executive Order 13873, “Securing the Information and Communications Technology and Services Supply Chain,” 84 FR 22,689 (2019).

Back to Citation

12.   Compare id. § 8(c)(2) withExecutive Order 13873, § 3(b), 84 FR 22,689, 22,691 (2019).

Back to Citation

13.   See Act, § 9(1). Advanced telecommunications capability “is defined, without regard to any transmission media or technology, as high-speed, switched, broadband telecommunications capability that enables users to originate and receive high-quality voice, data, graphics, and video telecommunications using any technology.” Public Law 104-104, 706(c)(1), 101 Stat. 56, 153 (1996) ( codified at47 U.S.C. 1302(d)(1)).

Back to Citation

14.  Inquiry Concerning Deployment of Advanced Telecommunications Capability to All Americans in a Reasonable and Timely Manner, 2019 Broadband Deployment Report, 34 FCC Rcd 3857, 3863-64, ¶ 16 (2019). Act, § 8(c)(4).

Back to Citation

16.   See 165 Cong. Rec. H10286 (daily ed. Dec. 16, 2019) (remarks of Rep. Doyle).

Back to Citation

17.   Id. (remarks of Rep. Latta).

Back to Citation

18.   See, e.g.,DHS Task Force Interim Report at 14-15.

Back to Citation

19.   See Protecting Against National Security Threats to the Communications Supply Chain Through FCC Programs, Report and Order, Further Notice of Proposed Rulemaking, and Order, 34 FCC Rcd 11423, 11425-26, ¶¶ 6-9 (2019).

Back to Citation

[FR Doc. 2020-12780 Filed 6-11-20; 8:45 am]

BILLING CODE 3510-60-P

Legal Citation

Federal Register Citation

Use this for formal legal and research references to the published document.

85 FR 35919

Web Citation

Suggested Web Citation

Use this when citing the archival web version of the document.

“Promoting the Sharing of Supply Chain Security Risk Information Between Government and Communications Providers and Suppliers,” thefederalregister.org (June 12, 2020), https://thefederalregister.org/documents/2020-12780/promoting-the-sharing-of-supply-chain-security-risk-information-between-government-and-communications-providers-and-supp.