About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



3 J. Cybersecurity 1 (2017)

handle is hein.journals/jnlocybrs3 and id is 1 raw text is: 







CYBERSECUFUTY


        Journal of Cybersecurity, 3(1), 2017, 1-5
                   doi: 10.1093/cybsec/tyx002
Advance Access Publication Date: 2 March 2017
                                   Editorial


Introduction to the special issue on strategic dimensions of offensive

cyber operations


Nations around the world recognize cybersecurity as a critical issue
for public policy. They are concerned that their adversaries could
conduct cyberattacks against their interests-damaging their mili-
tary forces, their economies, and their political processes. Thus, their
cybersecurity efforts have been devoted largely to protecting import-
ant information technology systems and networks against such at-
tacks. Recognizing this point, the Oxford Dictionaries added in
2013  a new word  to its lexicon-it defined cybersecurity as the
state of being protected against the criminal or unauthorized use of
electronic data, or the measures taken to achieve this.
   But a nation can also conduct cyberattacks against other nations
as deliberate instruments of policy, and many nations around the
world  are also exploring the use of offensive cyber operations in
such a manner. In the USA, such operations have become  increas-
ingly prominent in US policy. For example:


• The  deployment and use of Stuxnet against Iranian centrifuges is
  widely credited with complicating Iranian progress toward a nu-
  clear weapon.
• Presidential Policy Directive 20 (PPD-20), which established US
  policy for cyber operations, both offensive and defensive, was
  leaked  by  Edward   Snowden   in  2013.2  According  to  the
  Guardian's reporting on PPD-20, offensive cyber capabilities can
  be used broadly to advance U.S. national objectives around the
  world.
• The  Department  of Defense (DOD)  Cyber Strategy [8] (released
  in April 2015)  focuses on  building capabilities for effective
  cybersecurity and cyber operations to... support operational and
  contingency plans [as one of three objectives].



  1  See, e.g. [1, 2]. According to Albright et al. [3], Stuxnet
     delayed the Iranian nuclear program   by about  a year.
 2   The leaked  PPD-20  can  be read in full at: https://fas.org/
     irp/offdocs/ppd/ppd-20.pdf.   PPD-20   has  also been  the
     subject of several news articles and editorials, including
     [4-7] . Because   those with  clearances  are allowed   to
     read press  stories reporting on  leaked  classified docu-
     ments  but not to read  these documents   themselves  out-
     side of cleared  facilities, references to PPD-20  in this
     introduction  should   be understood as being derived
     from these articles and not from  the original document.
     In addition, papers in this collection written by individ-
     uals who   have  had  proper  access  to classified cyber-
     related documents   have  passed  through  DOD security
     review; these papers  contain  no  references to PPD-20,
     and no  individuals with  security clearances had  any in-
     put into this introduction.


• In a speech given at Stanford University releasing the April 2015
  cyber strategy, Secretary of Defense Ashton Carter noted that one
  mission of the DOD  is to provide offensive cyber options that, if
  directed by the President, can augment our other military sys-
  tems [9].
• Today,  DOD   publicly acknowledges using cyber weapons in its
  fight against the Islamic State (ISIL). For example, in February
  2016, Secretary of Defense Carter said that US Cyber Command
  is conducting offensive cyber operations to cause ISIL to lose
  confidence in their networks, to overload their networks so that
  they can't function, and do all of these things that will interrupt
  their ability to command and  control forces[10]. At the same
  time, he also noted that Cyber Command   was devised specific-
  ally to make the United States proficient and powerful in this tool
  of war.  In April 2016, Deputy  Secretary of Defense  Robert
  Work  said regarding ISIL, We are dropping cyber bombs.  We
  have never done that before, and Just like we have an air cam-
  paign, I want to have a cyber campaign [11].

  To   date, academics and analysts have paid much more attention
to cyber defense than to cyber offense. One important reason under-
lying this imbalance is a high degree of classification about nearly
every aspect of US  offensive cyber capabilities. Indeed, Michael
Hayden,  former director of both the NSA and CIA, has noted that
as recently as the early 2000s, even the phrase offensive cyber oper-
ations was classified. Not what it might mean, or what the targets
would  be, or what  technologies would be  involved-merely  the
phrase itself.
   High  levels of classification and excessive secrecy are especially
problematic when policy makers try to understand a new domain of
conflict because secrecy inhibits learning across traditional bounda-
ries and new  types of conflict necessarily require learning across
traditional boundaries. Again, quoting Michael Hayden,
   [d]eveloping policy for cyberops is hampered by excessive se-
   crecy (even for an intelligence veteran). I can think of no
   other family of weapons  so anchored in the espionage ser-
   vices for their development (except perhaps armed drones).
   And  the habitual secrecy of the intelligence services bled over
   into cyberops in a way that has retarded the development -
   or at least the policy integration - of digital combat power. It
   is difficult to develop consensus views on things that are
   largely unknown or only rarely discussed by a select few. [12]
   Over  the years, a few scholars have ventured into the realm of
strategy and doctrine around offensive cyber operations without ac-
cess to classified materials, but the vast majority has found it easier
to stay away from the subject matter entirely. The result is a deep
loss for strategic thought, and a stark contrast from the roles that


OThe Author 2017. Published by Oxford University Press.


This is an Open Access article distributed under the terms of the Creative Commons Attribution Non-Commercial License (http://creativecommons.org/licenses/by-nc/4.0/),
which permits non-commercial re-use, distribution, and reproduction in any medium, provided the original work is properly cited. For commercial re-use, please contact
journals.permissions@oup.com