On September 29, new rules go into effect requiring broadcasters to secure their EAS equipment and other equipment in their program chain that is connected to the internet – the FCC wanting to avoid false emergency alerts being transmitted on broadcast stations (see our articles providing details of this new obligation here and here). The three-point program (requiring stronger passwords, the updating of equipment and software, and the use of firewalls around EAS equipment) has raised many questions among broadcasters and their technical advisors as to exactly what is required. While the FCC’s Order adopting the rules went into detail about the requirements, as soon as they were published, those in the field had questions that apparently had not been anticipated or addressed. That left the industry wondering exactly what was required. But this week, the FCC issued some helpful Frequently Asked Questions – and provided their answers to many of the open questions – the FAQs available here.
These FAQs address many of the questions that I have received at broadcasters’ meetings around the country in the last few months since these rules were adopted. The FAQs make clear that, if your equipment does not accept the required 15-character passwords, you either need to get new equipment or you need to use one of the alternate security verification options provided in the Order – which include look-up secrets, out-of-band devices, single- or multi-factor one-time passwords, and single- or multi-factor cryptographic authentication. The FAQs also note that even equipment behind a firewall needs to require these secure passwords. And each piece of equipment needs to have its own password or verification procedure – the same password should not be used for multiple devices or systems. The FAQs also clarify the FCC’s prohibition on the use of dictionary words – dictionary words can be part of passwords, but a single dictionary word that is 15 letters or more cannot itself serve as a password because it would be too easy for hackers to crack.
The FAQs also note that if third parties, including program suppliers, who “route, process, or insert content into the transmission of programming on behalf of an EAS Participant as its agent,” must also abide by these requirements. It appears that the Commission is saying that, if the programmer directly inserts its programming into the program stream, they are subject to the rules. But if some intervention by the broadcaster is required before the programming goes into the program stream, then they do not.
Broadcasters need to review these FAQs and study the FCC’s Order. Make any necessary changes now so you are ready for the September 29 effective date of these new EAS security rules. If your system is hacked and you have not done what the FCC requires (or, as we suggested in our article on the upcoming nationwide EAS test, if the FCC forms required in connection with that test reveal unsecured EAS equipment) expect that the Commission will not look kindly on your problems.