DOD looks for extension on Huawei ban

The 2021 must-pass defense policy bill could be a prime vehicle to give the Defense Department and its contractors more time to comply with a governmentwide ban on Huawei and other China-made telecommunications equipment.

DOD's acquisition head, Ellen Lord, said DOD needed more time and worried about "unintended consequences" in implementing the ban on contracts with companies that use products or services like Huawei in August.

"The thought that somebody in six or seven levels down in the supply chain could have one camera in a parking lot, and that would invalidate one of our major primes being able to do business with us gives us a bit of pause," Lord testified at a House Armed Services Committee hearing on the defense industry base June 10.

Lord said that while she thinks a "majority" of compliance could be achieved, "it is a heavy lift to find all of this equipment everywhere" within two years, and potentially "shutting down major portions of our defense industrial base because of one infraction of a Hikvision camera in a parking lot somewhere, at a level-four supplier."

The issue comes as the Defense Department, and government agencies broadly, have become more reliant on information systems and telecommunications services amid the coronavirus pandemic -- an issue that's sure to be included in the National Defense Authorization Act, making the bill a suitable avenue for deadline modification.

Wesley Hallman, the National Defense Industry Association's senior vice president for strategy and policy, told FCW that as is, Section 889, which was passed in the 2019 NDAA, was basically unimplementable, approaching crisis-level concerns.

"The bottom line is, we don't even have a draft rule to comment on and it's supposed to be implemented on Aug. 13," Hallman said. "As written, it's very near impossible to certify that you are free of this in your supply chain."

Supply chain concerns will likely be a mainstay in the NDAA. The COVID-19 pandemic "exposed and exacerbated supply chain deficiencies across the government, and the FY21 NDAA takes numerous steps to secure the supply chain -- both from over-reliance on foreign nations and from infiltration by our adversaries," the Senate Armed Services Committee indicated in its summary of its version of the 2021 NDAA.

Moreover, it requires DOD to "report on the risk to DOD personnel, equipment, and operations due to Huawei 5G architecture in host countries and possible steps for mitigation." DOD also has to consider security risks with 5G and 6G when using vendors like Huawei and ZTE.

David Berteau, the president and CEO for the Professional Services Council, said Lord's testimony was DOD's "strongest" support of an extension, which has "huge dollar implications" for a requirement that doesn't have a rule and is less than two months away from an implementation date.

PSC and the NDIA are pushing for an extension to February 2021 "to allow contractors time to recover from the effects of COVID-19 and effectively comply," according to a March 31 letter to House and Senate Armed Services Committee leaders.

"Postponement of the deadline will provide the government with better assurance of achieving its supply chain security objectives with the least disruption and harm to the vendor and supplier base," the letter states.

Without it, Berteau said it could be problematic for DOD's thousands of contracts, potentially leaving compliance up to individual companies, which could make it harder for contract officers to verify that banned equipment and services are removed.

"Because we don't know what the procurement rules are, businesses can't begin to budget or prepare," he said. "The government regulation needs to set precise standards and give companies time to plan for and build compliance.”

About the Author

Lauren C. Williams is a staff writer at FCW covering defense and cybersecurity.

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3