H. R. 2685
IN THE HOUSE OF REPRESENTATIVES
April 20, 2021
Ms. Eshoo (for herself and Mr. Kinzinger) introduced the following bill; which was referred to the Committee on Energy and Commerce
To direct the Assistant Secretary of Commerce for Communications and Information to submit to Congress a report examining the cybersecurity of mobile service networks, and for other purposes.
This Act may be cited as the
Understanding Cybersecurity of Mobile Networks Act.
Report on cybersecurity of mobile service networks
Not later than 1 year after the date of the enactment of this Act, the Assistant Secretary, in consultation with the Department of Homeland Security, shall submit to Congress a report examining the cybersecurity of mobile service networks and the vulnerability of such networks and mobile devices to cyberattacks and surveillance conducted by adversaries.
Matters To be included
The report required by subsection (a) shall include the following:
An assessment of the degree to which providers of mobile service have addressed, are addressing, or have not addressed cybersecurity vulnerabilities (including vulnerabilities the exploitation of which could lead to surveillance conducted by adversaries) identified by academic and independent researchers, multistakeholder standards and technical organizations, industry experts, and Federal agencies, including in relevant reports of—
the National Telecommunications and Information Administration;
the National Institute of Standards and Technology; and
the Department of Homeland Security, including—
the Cybersecurity and Infrastructure Security Agency; and
the Science and Technology Directorate.
A discussion of—
the degree to which customers (including consumers, companies, and government agencies) consider cybersecurity as a factor when considering the purchase of mobile service; and
the commercial availability of tools, frameworks, best practices, and other resources for enabling such customers to evaluate risk and price tradeoffs.
A discussion of the degree to which providers of mobile service have implemented cybersecurity best practices and risk assessment frameworks.
An estimate and discussion of the prevalence and efficacy of encryption and authentication algorithms and techniques used in each of the following:
Mobile communications equipment or services.
Commonly used mobile phones and other mobile devices.
Commonly used mobile operating systems and communications software and applications.
Barriers for providers of mobile service to adopt more efficacious encryption and authentication algorithms and techniques and to prohibit the use of older encryption and authentication algorithms and techniques with established vulnerabilities in mobile service, mobile communications equipment or services, and mobile phones and other mobile devices.
The prevalence, usage, and availability of technologies that authenticate legitimate mobile service and mobile communications equipment or services to which mobile phones and other mobile devices are connected.
The prevalence, costs, commercial availability, and usage by adversaries in the United States of cell site simulators (often known as international mobile subscriber identity-catchers) and other mobile service surveillance and interception technologies.
In preparing the report required by subsection (a), the Assistant Secretary shall, to the degree practicable, consult with—
the National Institute of Standards and Technology;
the intelligence community;
the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security;
the Science and Technology Directorate of the Department of Homeland Security;
academic and independent researchers with expertise in privacy, encryption, cybersecurity, and network threats;
participants in multistakeholder standards and technical organizations (including the 3rd Generation Partnership Project and the Internet Engineering Task Force);
international stakeholders, in coordination with the Department of State as appropriate;
providers of mobile service;
manufacturers, operators, and providers of mobile communications equipment or services and mobile phones and other mobile devices;
developers of mobile operating systems and communications software and applications; and
other experts that the Assistant Secretary considers appropriate.
Scope of report
The Assistant Secretary shall—
limit the report required by subsection (a) to mobile service networks;
exclude consideration of 5G protocols and networks in the report required by subsection (a);
limit the assessment required by subsection (b)(1) to vulnerabilities that have been shown to be—
exploited in non-laboratory settings; or
feasibly and practicably exploitable in real-world conditions; and
consider in the report required by subsection (a) vulnerabilities that have been effectively mitigated by manufacturers of mobile phones and other mobile devices.
Form of report
The report required by subsection (a) shall be produced in unclassified form but may contain a classified annex.
Authorization of appropriations
There is authorized to be appropriated to carry out this section $500,000 for fiscal year 2021. Such amount is authorized to remain available through fiscal year 2022.
In this section:
any unauthorized hacker or other intruder into a mobile service network; and
any foreign government or foreign nongovernment person engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons.
Assistant Secretary means the Assistant Secretary of Commerce for Communications and Information.
entity means a partnership, association, trust, joint venture, corporation, group, subgroup, or other organization.
intelligence community has the meaning given that term in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).
Mobile communications equipment or service
mobile communications equipment or service means any equipment or service that is essential to the provision of mobile service.
mobile service means, to the extent provided to United States customers, either or both of the following services:
Commercial mobile service (as defined in section 332(d) of the Communications Act of 1934 (47 U.S.C. 332(d))).
Commercial mobile data service (as defined in section 6001 of the Middle Class Tax Relief and Job Creation Act of 2012 (47 U.S.C. 1401)).
person means an individual or entity.
United states person
United States person means—
an individual who is a United States citizen or an alien lawfully admitted for permanent residence to the United States;
an entity organized under the laws of the United States or any jurisdiction within the United States, including a foreign branch of such an entity; or
any person in the United States.