Online Filing of CALEA SSI Plans Now Mandatory for Internet Providers
In 2022 the FCC announced they would be launching a new CALEA Electronic Filing System (CEFS) for the filing of CALEA System Security and Integrity (SSI) Plans. They later launched that system and asked Internet Service Providers to begin voluntarily filing their SSI plans in that online system, and also proposed making electronic filing mandatory six months after that. That six month period has passed, and online filing of SSI Plans is now mandatory. Here are some questions you may have.
What is CALEA?
CALEA is the Communications Assistance for Law Enforcement Act. It originally passed in October of 1994, and initially only applied to providers of telephone services. It was put in place due to the increasing use of digital phone switches, and it required that phone companies be able to assist law enforcement in performing electronic surveillance if presented with a valid court order or other lawful intercept authorization. In addition, switch manufacturers needed to ensure that their equipment was CALEA compliant.
In 2006 the law was extended to apply to "all facilities-based broadband Internet access providers and providers of interconnected VoIP service." In other words, if you are an ISP, you must be CALEA compliant and you need to take CALEA seriously. If you receive a CALEA request and are not able to comply, you can be fined up to $10,000 per day by the court until you are able to.
What is a CALEA SSI Plan?
As part of the CALEA, telecommunications companies (including ISPs since 2006) are required to file a System Security and Integrity Plan (SSI plan). This plan documents how the service provider will be complying with CALEA, and has the contact information of the people at the company who will be assisting any law enforcement agency that presents a lawful intercept request under CALEA. Originally SSI plans were paper copies that were sent in to the FCC and filed. As of June 29, 2023, SSI plans must be filed electronically in the CEFS. This is a requirement for every facilities-based Internet Service Provider.
You need to get compliant before you receive a CALEA request, and filing is an important step to let the FCC know that you are compliant and will be able to respond to a CALEA request in a timely manner. Since SSI plans will now be online, it will also make it easier for the FCC to determine which ISPs have filed their plans and which have not.
How do I become CALEA compliant?
CALEA compliance requires the appropriate technology to be placed in the right location in your network so you can enable, mediate and securely deliver a live stream of data from a specified subscriber to the requesting law enforcement agency when presented with a lawful intercept request. You must also have policies in place to ensure that CALEA requests are handled quickly and confidentially. This includes having specified CALEA contacts that law enforcement can get in touch with at any time, that any CALEA-based court orders you receive are fully verified, and that all intercepts that are initiated (and the targets of those intercepts) will be kept confidential and on a need-to-know basis.
There are two options to become compliant. One is to have your own mediation equipment on hand, along with the appropriate staff who can fully verify CALEA requests, deploy the equipment appropriately and securely to isolate the specific information requested from a specific subscriber, and deliver it to the requesting Law Enforcement Agency (LEA). This can be difficult and expensive for all but the largest providers. The other option is to use a Trusted Third Party (TTP). TTPs can act as your CALEA contact, including verifying any lawful intercept requests, sending the required mediation equipment and assisting in its proper deployment, and managing the process of delivering the intercepted data to the LEA in the required format securely and confidentially.
If you are not yet CALEA compliant, ZCorum can act as your CALEA Trusted Third Party. We can provide the services and intercept devices needed so that you are always ready to respond appropriately to a CALEA request in a timely manner, and avoid potential fines for non compliance.
Additional CALEA Resources:
To request a Sample SSI form, which will help you collect and document the information needed for your online SSI filing, go here.
For more information about CALEA and the online filing mandate for SSI plans, watch this video.
Download the CALEA Electronic Filing System (CEFS) User Manual:
You can also find more information about CALEA and SSI plans on the FCC CALEA Website.
About the Author: Rick Yuzzi
Never miss a post.
Enter your email to subscribe:
- Ask an Expert (12)
- Blog (12)
- Technology (11)
- Hot Topics (8)
- ask a broadband expert (8)
- DOCSIS (7)
- PNM (7)
- proactive network maintenance (7)
- Industry Perspectives (5)
- BEAD (4)
- Broadband Funding (4)
- Customer Service (4)
- FCC (4)
- IIJA (4)
- PreEqualization Analyzer (4)
- correlation groups (4)
- fiber broadband (4)
- fiber optics (4)
- fiber troubleshooting (4)
- interview (4)
- CGNAT (3)
- Carrier Grade NAT (3)
- DDoS Attacks (3)
- DOCSIS pre-equalization (3)
- Diagnostics (3)
- Distributed Denial of Service Attacks (3)
- GPoN (3)
- IPv4 Conservation (3)
- Purchase IPv4 Addresses (3)
- What is DOCSIS PNM (3)
- broadband infrastructure funding (3)
- fiber (3)
- 5G (2)
- CALEA (2)
- CALEA Compliance (2)
- Codeword Errors (2)
- DOCSIS 3.1 (2)
- Distributed Access Architecture (2)
- Group Delay (2)
- ICFR (2)
- IP traffic (2)
- IPv6 migration (2)
- In Channel Frequency Response (2)
- Main Tap Compression (2)
- Marketing (2)
- Micro Reflections (2)
- Millimeter Wave (2)
- OTT (2)
- Rural Broadband (2)
- Types of DDoS Attacks (2)
- Voice Service (2)
- XGS-PON (2)
- broadband data collection (2)
- customer service (2)
- internet issues (2)
- mid-band spectrum (2)
- mmWave (2)
- network traffic (2)
- network virtualization (2)
- state broadband (2)
- state broadband program (2)
- weather-related Internet issues (2)
- 10G (1)
- BDC (1)
- BDC Availability Data Specification (1)
- BDC User Guide (1)
- BEAD Funding (1)
- Broadband Providers (1)
- Broadband Serviceable Location Fabric (1)
- Broadband Serviceable Locations (1)
- C-Band (1)
- CA Certificate Expiration (1)
- CAF II Requirements (1)
- CAF II Testing (1)
- CALEA SSI Plan (1)
- CBRS (1)
- Carpet Bombing (1)
- Citizens Broadband Radio (1)
- Communications Assistance for Law Enforcement Act (1)
- Connect America Fund (1)
- DAA (1)
- DOCSIS 4.0 (1)
- DOCSIS CA Certificate Expiration (1)
- DPoE (1)
- DPoG (1)
- EPoN (1)
- Excel Text Matching (1)
- Extended Spectrum DOCSIS (1)
- Extending HFC Life (1)
- FCC Broadband Map (1)
- FCC data (1)
- FTTH (1)
- FTTx (1)
- Fidelity Communications (1)
- Full Duplex (1)
- Greenfield Broadband (1)
- Hosted VoIP (1)
- IPTV (1)
- IPv4 (1)
- IPv6 (1)
- IPv6 Transition Plan (1)
- LTE (1)
- Low Latency DOCSIS (1)
- MAC/PHY (1)
- Mobile (1)
- Monitoring (1)
- Motivation for DDoS Attacks (1)
- Multi-Vector DDoS Attacks (1)
- NG-PON2 (1)
- NIST (1)
- NIST Cybersecurity Framework (1)
- NIST requirements (1)
- NetFlow (1)
- Network Traffic Management, (1)
- OTT video streaming (1)
- Private Access License (PAL) (1)
- RDOF Auction (1)
- RDOF Voice Requirements (1)
- Remote MAC/PHY (1)
- Remote PHY (1)
- Robocalls (1)
- Rural Broadband Network Advancement Act (1)
- Rural Digital Opportunity Fund (1)
- SSI (1)
- STIR/SHAKEN (1)
- Small Cells (1)
- Streaming (1)
- System Security and Integrity Plan (1)
- TV Viewership Analytics (1)
- TWDM-PON (1)
- TruVizion (1)
- Underserved Locations (1)
- Unserved Locations (1)
- Upstream Analyzer (1)
- Videos (1)
- VoIP (1)
- VoIP revenue (1)
- Wired Broadband (1)
- broadband data collection program (1)
- broadband deployment (1)
- broadband support (1)
- cableLabs (1)
- caf ii (1)
- case study (1)
- cloud-based VoIP (1)
- commercial VoIP (1)
- commercial VoIP revenue (1)
- cpe spectrum capture (1)
- customer service tip (1)
- cyber attacks (1)
- cybersecurity (1)
- dhcp (1)
- downstream spectrum issues (1)
- dual stack implementation (1)
- dynamic spectrum sharing (1)
- electric membership cooperatives (1)
- fiber Internet (1)
- fiber deployment (1)
- forward path monitoring (1)
- free download (1)
- full band capture (1)
- holiday customer service (1)
- holiday tech support (1)
- ingress (1)
- middle mile grant program (1)
- net neutrality (1)
- open access fiber (1)
- open access fiber network (1)
- open access networks (1)
- pppoa (1)
- pppoe (1)
- pre-equalization (1)
- reduced maintenance costs (1)
- remote spectrum analyzer (1)
- return path (1)
- scott helms (1)
- technical paper (1)
- technical support (1)
- vTDR (1)
.
About the Blog
Bloggers
Comments Policy
Guest Blogging
Privacy Policy
Leave a comment: