DOD looks for extension on Huawei ban

The 2021 must-pass defense policy bill could be a prime vehicle to give the Defense Department and its contractors more time to comply with a governmentwide ban on Huawei and other China-made telecommunications equipment.

DOD's acquisition head, Ellen Lord, said DOD needed more time and worried about "unintended consequences" in implementing the ban on contracts with companies that use products or services like Huawei in August.

"The thought that somebody in six or seven levels down in the supply chain could have one camera in a parking lot, and that would invalidate one of our major primes being able to do business with us gives us a bit of pause," Lord testified at a House Armed Services Committee hearing on the defense industry base June 10.

Lord said that while she thinks a "majority" of compliance could be achieved, "it is a heavy lift to find all of this equipment everywhere" within two years, and potentially "shutting down major portions of our defense industrial base because of one infraction of a Hikvision camera in a parking lot somewhere, at a level-four supplier."

The issue comes as the Defense Department, and government agencies broadly, have become more reliant on information systems and telecommunications services amid the coronavirus pandemic -- an issue that's sure to be included in the National Defense Authorization Act, making the bill a suitable avenue for deadline modification.

Wesley Hallman, the National Defense Industry Association's senior vice president for strategy and policy, told FCW that as is, Section 889, which was passed in the 2019 NDAA, was basically unimplementable, approaching crisis-level concerns.

"The bottom line is, we don't even have a draft rule to comment on and it's supposed to be implemented on Aug. 13," Hallman said. "As written, it's very near impossible to certify that you are free of this in your supply chain."

Supply chain concerns will likely be a mainstay in the NDAA. The COVID-19 pandemic "exposed and exacerbated supply chain deficiencies across the government, and the FY21 NDAA takes numerous steps to secure the supply chain -- both from over-reliance on foreign nations and from infiltration by our adversaries," the Senate Armed Services Committee indicated in its summary of its version of the 2021 NDAA.

Moreover, it requires DOD to "report on the risk to DOD personnel, equipment, and operations due to Huawei 5G architecture in host countries and possible steps for mitigation." DOD also has to consider security risks with 5G and 6G when using vendors like Huawei and ZTE.

David Berteau, the president and CEO for the Professional Services Council, said Lord's testimony was DOD's "strongest" support of an extension, which has "huge dollar implications" for a requirement that doesn't have a rule and is less than two months away from an implementation date.

PSC and the NDIA are pushing for an extension to February 2021 "to allow contractors time to recover from the effects of COVID-19 and effectively comply," according to a March 31 letter to House and Senate Armed Services Committee leaders.

"Postponement of the deadline will provide the government with better assurance of achieving its supply chain security objectives with the least disruption and harm to the vendor and supplier base," the letter states.

Without it, Berteau said it could be problematic for DOD's thousands of contracts, potentially leaving compliance up to individual companies, which could make it harder for contract officers to verify that banned equipment and services are removed.

"Because we don't know what the procurement rules are, businesses can't begin to budget or prepare," he said. "The government regulation needs to set precise standards and give companies time to plan for and build compliance.”

About the Author

Lauren C. Williams is a staff writer at FCW covering defense and cybersecurity.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3