Thank you.
Anyone who has worked inside a data system knows that security gaps do not only come from outside attackers. Every time a service provider adds a third-party program, every time two systems get connected and every time a new software link gets built in to meet a requirement like the one this bill creates, a potential gap opens. The interception architecture, SAAIA, will not be built once and left alone. It will be patched, updated and connected to other systems by providers of very different technical capacity, and each of those moments is an opportunity for a gap to open that nobody anticipated.
Does this bill require any ongoing security testing of the interception infrastructure after it is built, or does the obligation end at construction?
