ZTE ban, tucked inside the NDAA, passes the Senate

The $716 billion National Defense Authorization Act passed the U.S. Senate on Monday, including an amendment that kills a deal the Trump administration made with China that effectively saved telecommunications firm ZTE. The bill still has a long way to go. The House of Representatives’ version, which omits the ZTE Ban, has to be reconciled with the Senate version. Additionally, the White House strongly opposes the measure. Despite the process ahead, the amendment’s backers are taking the NDAA’s passage as a victory. “We’re heartened that both parties made it clear that protecting American jobs and national security must come first when making deals with countries like China, which has a history of having little regard for either,”  Sens. Marco Rubio, R-Fla., Tom Cotton, R-Ark, Chuck Schumer, D-N.Y., and Chris Van Hollen, D-Md. said in a statement. “It is vital that our colleagues in the House keep this bipartisan provision in the bill as […]

The post ZTE ban, tucked inside the NDAA, passes the Senate appeared first on Cyberscoop.

Continue reading ZTE ban, tucked inside the NDAA, passes the Senate

Top U.S. counterintelligence official: Kaspersky’s move to Switzerland doesn’t matter

The ongoing fight between the U.S. government and Moscow-based Kaspersky Lab led the company to begin moving “a good part” of its infrastructure to Switzerland in a highly-visible move toward transparency in the face of spying accusations. The U.S.’s top counterintelligence official, however, says Kaspersky’s move to Switzerland makes no difference to him. William Evanina, the Director of the National Counterintelligence and Security Center, looks at the way the U.S. government handles Kaspersky — which is now banned from the U.S. federal government and is losing ground in the private sector — as “an opportunity to create a model,” he said. “This will not be the last time this happens. I think there will be more to come along, I call them ‘nation-state threats that emanate through the global business process.’ ” Kaspersky’s opening of a “Transparency Center” in Switzerland is significant but leaves open a wide range of questions. The company has […]

The post Top U.S. counterintelligence official: Kaspersky’s move to Switzerland doesn’t matter appeared first on Cyberscoop.

Continue reading Top U.S. counterintelligence official: Kaspersky’s move to Switzerland doesn’t matter

Facebook gave user data access to Chinese mobile device makers, too

On Sunday, The New York Times revealed that Facebook has been providing mobile phone and tablet vendors access to user (and users’ friends’) data even though the users did not consent to it and even if they configured their Facebook setting… Continue reading Facebook gave user data access to Chinese mobile device makers, too

House panel rejects call for cyberthreat report on ZTE amid Trump deal

On the heels of a reported U.S. deal with embattled Chinese telecom company ZTE, American lawmakers rejected a Democratic measure that would have directed the Department of Homeland Security to provide more information on any cybersecurity risks posed by the international tech company. The top Republican and Democrat on the House Homeland Security Committee sparred over the utility of the resolution, which would have tasked DHS with providing any documentation it has on cyber risks introduced by the use of ZTE products on federal, state and local government networks. The Republican-led panel voted 16-11 against the measure. Instead, lawmakers will get a classified briefing from officials at DHS, the FBI and the Defense Department on June 13 about the  national security risks posed by ZTE and Huawei, another Chinese technology giant. Texas Republican Michael McCaul, the committee’s chairman, announced the briefing at a committee markup Wednesday on Capitol Hill. U.S. […]

The post House panel rejects call for cyberthreat report on ZTE amid Trump deal appeared first on Cyberscoop.

Continue reading House panel rejects call for cyberthreat report on ZTE amid Trump deal

House defense bill would usher in cybersecurity changes at DOD

The House of Representatives this week overwhelmingly passed a defense policy bill with several cybersecurity measures aimed at better securing Pentagon networks. The legislation — the fiscal 2019 National Defense Authorization Act (NDAA) — seeks closer collaboration between the departments of Defense and Homeland Security in defending against hackers, asks for quick notification of data breaches of military personnel, and continues to crack down on foreign-made telecom products that are deemed security threats. The NDAA is an annual ritual that lawmakers use to shape Pentagon policies and budget plans while throwing in some pet projects to boot. The House bill — a $717 billion behemoth — eventually will be merged with the Senate’s version, which that chamber’s Armed Services Committee also approved this week. It’s unclear when the Senate bill will have floor votes. One key provision of the House bill, according to the Rules Committee print, would set up a pilot program for […]

The post House defense bill would usher in cybersecurity changes at DOD appeared first on Cyberscoop.

Continue reading House defense bill would usher in cybersecurity changes at DOD

NIST wants to the federal government to pay more attention to the supply chain

A federal IT standards body has moved to add key supply-chain provisions to its risk management guidance at a time of growing concern that Russian and Chinese companies pose a threat to national security. The National Institute of Standards and Technology on Wednesday released a draft update to its influential Risk Management Framework, which federal agencies use to assess cyber risk. The provisional update includes measures to guard against untrusted suppliers and the possibility of hackers slipping malicious code into the supply chain. Defining — let alone securing — all the components and systems that organizations get from third parties can be a struggle, according to the document. One answer, NIST says, is building “a chain of trust” with suppliers to ensure that each one of them provides adequate security protections for their products. The new measures are critical because of the globalized nature of the IT supply chain, according to NIST fellow Ron Ross, one of the publication’s authors. […]

The post NIST wants to the federal government to pay more attention to the supply chain appeared first on Cyberscoop.

Continue reading NIST wants to the federal government to pay more attention to the supply chain