The second line of effort is oriented toward identifying and assessing risks and vulnerabilities to 5G
infrastructure, building on existing capabilities in assessing and managing supply chain risk. This work
will also involve the development of criteria for trusted suppliers and the application of a vendor supply
chain risk management template to enable security-conscious acquisition decision-making. Several
agencies have responsibilities for assessing threats as the United States’ manages risks associated with
the global and regional adoption of 5G network technology as well as developing mitigation strategies to
combat any identified threats. These threat assessments take into account, as appropriate, requirements
from entities such as the Committee on Foreign Investment in the United States (CFIUS), the Executive
Order (E.O.) on Establishing the Committee for the Assessment of Foreign Participation in the United
States Telecommunications Services Sector (Team Telecom), and the Federal Acquisition Security
Council (FASC). In addition, this line of effort will identify security gaps in United States and
international supply chains and an assessment of the global competitiveness and economic
vulnerabilities of United States manufacturers and suppliers. Finally, this set of activities will include
working closely with the private sector and other stakeholders to identify, develop, and apply core
security principles for 5G infrastructure. These efforts will include leveraging the Enduring Security
Framework (ESF), a working group under the Critical Infrastructure Partnership Advisory Council
(CIPAC). These emerging security principles will be synchronized with or complementary to other 5G
security principles, such as the “Prague Proposals” from the Prague 5G Security Conference held in
May 2019.
Line of Effort Three: Address Risks to United States Economic and National Security during
Development and Deployment of 5G Infrastructure Worldwide
The third line of effort involves addressing the risks to United States economic and national security
during the development and deployment of 5G infrastructure worldwide. As a part of this effort, the
United States will identify the incentives and policies necessary to close identified security gaps in close
coordination with the private sector and through the continuous evaluation of commercial, security, and
technological developments in 5G networks. A related activity is the identification of policies that can
ensure the economic viability of the United States domestic industrial base, in coordination with the
private sector through listening sessions and reviews of best practices. An equally important activity
relates to the identification and assessment of “high risk” vendors in United States 5G infrastructure,
through efforts such as the Implementation of E.O. 13873, on “Securing the Information and
Communications Technology and Services Supply Chain.” These efforts will build on the work of the
CFIUS, the FASC, and Team Telecom reviews of certain Federal Communications Commission (FCC)
licenses involving foreign ownership. This element of the implementation plan will also involve more
intense engagement with the owners and operators of private sector communications infrastructure,
systems equipment developers, and other critical infrastructure owners and operators. The engagements
will involve sharing information on 5G and future generation wireless communications systems and
infrastructure equipment. Such work will be conducted through the Network Security Information
Exchange, the IT and Communications Sector and Government Coordinating Councils, the National
Security Telecommunications Advisory Committee, and NTIA’s Communications Supply Chain Risk
Information Partnership (C-SCRIP).
Line of Effort Four: Promote Responsible Global Development and Deployment of 5G
4