Federal
Understanding Cybersecurity of Mobile Networks Act
Source: Congress.gov ·
1,682 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
117TH CONGRESS
1ST SESSION H. R. 2685
IN THE SENATE OF THE UNITED STATES
DECEMBER 2, 2021
Received; read twice and referred to the Committee on Commerce, Science,
and Transportation
AN ACT
To direct the Assistant Secretary of Commerce for Commu-
nications and Information to submit to Congress a report
examining the cybersecurity of mobile service networks,
and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
2
HR 2685 RFS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Understanding Cyber-
2
security of Mobile Networks Act’’.
3
SEC. 2. REPORT ON CYBERSECURITY OF MOBILE SERVICE
4
NETWORKS.
5
(a) IN GENERAL.—Not later than 1 year after the
6
date of the enactment of this Act, the Assistant Secretary,
7
in consultation with the Department of Homeland Secu-
8
rity, shall submit to the Committee on Energy and Com-
9
merce of the House of Representatives and the Committee
10
on Commerce, Science, and Transportation of the Senate
11
a report examining the cybersecurity of mobile service net-
12
works and the vulnerability of such networks and mobile
13
devices to cyberattacks and surveillance conducted by ad-
14
versaries.
15
(b) MATTERS TO BE INCLUDED.—The report re-
16
quired by subsection (a) shall include the following:
17
(1) An assessment of the degree to which pro-
18
viders of mobile service have addressed, are address-
19
ing,
or
have
not
addressed
cybersecurity
20
vulnerabilities (including vulnerabilities the exploi-
21
tation of which could lead to surveillance conducted
22
by adversaries) identified by academic and inde-
23
pendent researchers, multistakeholder standards and
24
technical organizations, industry experts, and Fed-
25
eral agencies, including in relevant reports of—
26
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
3
HR 2685 RFS
(A) the National Telecommunications and
1
Information Administration;
2
(B) the National Institute of Standards
3
and Technology; and
4
(C) the Department of Homeland Security,
5
including—
6
(i) the Cybersecurity and Infrastruc-
7
ture Security Agency; and
8
(ii) the Science and Technology Direc-
9
torate.
10
(2) A discussion of—
11
(A) the degree to which customers (includ-
12
ing consumers, companies, and government
13
agencies) consider cybersecurity as a factor
14
when considering the purchase of mobile service
15
and mobile devices; and
16
(B) the commercial availability of tools,
17
frameworks, best practices, and other resources
18
for enabling such customers to evaluate cyber-
19
security risk and price tradeoffs.
20
(3) A discussion of the degree to which pro-
21
viders of mobile service have implemented cybersecu-
22
rity best practices and risk assessment frameworks.
23
(4) An estimate and discussion of the preva-
24
lence and efficacy of encryption and authentication
25
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
4
HR 2685 RFS
algorithms and techniques used in each of the fol-
1
lowing:
2
(A) Mobile service.
3
(B) Mobile communications equipment or
4
services.
5
(C) Commonly used mobile phones and
6
other mobile devices.
7
(D) Commonly used mobile operating sys-
8
tems and communications software and applica-
9
tions.
10
(5) A discussion of the barriers for providers of
11
mobile service to adopt more efficacious encryption
12
and authentication algorithms and techniques and to
13
prohibit the use of older encryption and authentica-
14
tion algorithms and techniques with established
15
vulnerabilities in mobile service, mobile communica-
16
tions equipment or services, and mobile phones and
17
other mobile devices.
18
(6) An estimate and discussion of the preva-
19
lence, usage, and availability of technologies that au-
20
thenticate legitimate mobile service and mobile com-
21
munications equipment or services to which mobile
22
phones and other mobile devices are connected.
23
(7) An estimate and discussion of the preva-
24
lence, costs, commercial availability, and usage by
25
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
5
HR 2685 RFS
adversaries in the United States of cell site simula-
1
tors (often known as international mobile subscriber
2
identity-catchers) and other mobile service surveil-
3
lance and interception technologies.
4
(c) CONSULTATION.—In preparing the report re-
5
quired by subsection (a), the Assistant Secretary shall, to
6
the degree practicable, consult with—
7
(1) the Federal Communications Commission;
8
(2) the National Institute of Standards and
9
Technology;
10
(3) the intelligence community;
11
(4) the Cybersecurity and Infrastructure Secu-
12
rity Agency of the Department of Homeland Secu-
13
rity;
14
(5) the Science and Technology Directorate of
15
the Department of Homeland Security;
16
(6) academic and independent researchers with
17
expertise in privacy, encryption, cybersecurity, and
18
network threats;
19
(7) participants in multistakeholder standards
20
and technical organizations (including the 3rd Gen-
21
eration Partnership Project and the Internet Engi-
22
neering Task Force);
23
(8) international stakeholders, in coordination
24
with the Department of State as appropriate;
25
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
6
HR 2685 RFS
(9) providers of mobile service, including small
1
providers (or the representatives of such providers)
2
and rural providers (or the representatives of such
3
providers);
4
(10) manufacturers, operators, and providers of
5
mobile communications equipment or services and
6
mobile phones and other mobile devices;
7
(11) developers of mobile operating systems and
8
communications software and applications; and
9
(12) other experts that the Assistant Secretary
10
considers appropriate.
11
(d) SCOPE OF REPORT.—The Assistant Secretary
12
shall—
13
(1) limit the report required by subsection (a)
14
to mobile service networks;
15
(2) exclude consideration of 5G protocols and
16
networks in the report required by subsection (a);
17
(3) limit the assessment required by subsection
18
(b)(1) to vulnerabilities that have been shown to
19
be—
20
(A) exploited in non-laboratory settings; or
21
(B) feasibly and practicably exploitable in
22
real-world conditions; and
23
(4) consider in the report required by sub-
24
section (a) vulnerabilities that have been effectively
25
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
7
HR 2685 RFS
mitigated by manufacturers of mobile phones and
1
other mobile devices.
2
(e) FORM OF REPORT.—
3
(1) CLASSIFIED INFORMATION.—The report re-
4
quired by subsection (a) shall be produced in unclas-
5
sified form but may contain a classified annex.
6
(2) POTENTIALLY EXPLOITABLE UNCLASSIFIED
7
INFORMATION.—The Assistant Secretary shall re-
8
dact potentially exploitable unclassified information
9
from the report required by subsection (a) but shall
10
provide an unredacted form of the report to the
11
committees described in such subsection.
12
(f) AUTHORIZATION OF APPROPRIATIONS.—There is
13
authorized to be appropriated to carry out this section
14
$500,000 for fiscal year 2022. Such amount is authorized
15
to remain available through fiscal year 2023.
16
(g) DEFINITIONS.—In this section:
17
(1) ADVERSARY.—The term ‘‘adversary’’ in-
18
cludes—
19
(A) any unauthorized hacker or other in-
20
truder into a mobile service network; and
21
(B) any foreign government or foreign
22
nongovernment person engaged in a long-term
23
pattern or serious instances of conduct signifi-
24
cantly adverse to the national security of the
25
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
8
HR 2685 RFS
United States or security and safety of United
1
States persons.
2
(2) ASSISTANT SECRETARY.—The term ‘‘Assist-
3
ant Secretary’’ means the Assistant Secretary of
4
Commerce for Communications and Information.
5
(3) ENTITY.—The term ‘‘entity’’ means a part-
6
nership, association, trust, joint venture, corpora-
7
tion, group, subgroup, or other organization.
8
(4) INTELLIGENCE
COMMUNITY.—The term
9
‘‘intelligence community’’ has the meaning given
10
that term in section 3 of the National Security Act
11
of 1947 (50 U.S.C. 3003).
12
(5) MOBILE COMMUNICATIONS EQUIPMENT OR
13
SERVICE.—The term ‘‘mobile communications equip-
14
ment or service’’ means any equipment or service
15
that is essential to the provision of mobile service.
16
(6) MOBILE SERVICE.—The term ‘‘mobile serv-
17
ice’’ means, to the extent provided to United States
18
customers, either or both of the following services:
19
(A) Commercial mobile service (as defined
20
in section 332(d) of the Communications Act of
21
1934 (47 U.S.C. 332(d))).
22
(B) Commercial mobile data service (as de-
23
fined in section 6001 of the Middle Class Tax
24
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
9
HR 2685 RFS
Relief and Job Creation Act of 2012 (47 U.S.C.
1
1401)).
2
(7) PERSON.—The term ‘‘person’’ means an in-
3
dividual or entity.
4
(8)
UNITED
STATES
PERSON.—The
term
5
‘‘United States person’’ means—
6
(A) an individual who is a United States
7
citizen or an alien lawfully admitted for perma-
8
nent residence to the United States;
9
(B) an entity organized under the laws of
10
the United States or any jurisdiction within the
11
United States, including a foreign branch of
12
such an entity; or
13
(C) any person in the United States.
14
Passed the House of Representatives December 1,
2021.
Attest:
CHERYL L. JOHNSON,
Clerk.
VerDate Sep 11 2014
06:06 Dec 03, 2021
Jkt 029200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H2685.RFS
H2685
pbinns on DSKJLVW7X2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.