FAS

Information Operations: It Takes a Thief

01.06.17 | 1 min read | Text by Steven Aftergood

At a Senate Armed Services Committee hearing yesterday on foreign cyber threats to the U.S., there were several references to the saying that “people who live in glass houses should not throw stones.” The point, made by DNI James Clapper, was that the U.S. should not be too quick to penalize the very espionage practices that U.S. intelligence agencies rely upon, including clandestine collection of information from foreign computer networks.

But perhaps a more pertinent saying would be “It takes a thief to catch a thief.”

U.S. intelligence agencies should be well-equipped to recognize Russian cyber threats and political intervention since they have been tasked for decades to carry out comparable efforts.

A newly disclosed intelligence directive from 1999 addresses “information operations” (IO), which are defined as: “Actions taken to affect adversary information and information systems while defending one’s own information and information systems.”

“Although still evolving, the fundamental concept of IO is to integrate different activities to affect [adversary] decision making processes, information systems, and supporting information infrastructures to achieve specific objectives.”

The elements of information operations may include computer network attack, computer network exploitation, and covert action.

See Director of Central Intelligence Directive 7/3, Information Operations and Intelligence Community Related Activities, effective 01 July 1999.

The directive was declassified (in part) on December 2 by the Interagency Security Classification Appeals Panel, and was first obtained and published by GovernmentAttic.org.

publications
See all publications
Emerging Technology
Blog
International Collaboration to Strengthen Domestic Critical Minerals Efforts

As Congress considers broader packages to advance critical minerals production and supply chain resilience, science diplomacy vehicles must be part of that conversation, not as an afterthought, but as an intentional and foundational pillar of any strategy.

07.24.26 | 5 min read
read more
Emerging Technology
Policy Statement
Endorsement of the Strategic Technology and Resilient Alliances Act

“Structured partnerships with our allies on critical minerals innovation can ensure that the best science and the best talent are working together towards shared security and economic prosperity.”

07.24.26 | 1 min read
read more
Emerging Technology
Policy Statement
Pass S.3306/H.R.2985 – Modernizing Government Technology Reform Act

This is a bipartisan, commonsense measure to reauthorize the Technology Modernization Fund (TMF) before it expires in September 2026.

07.23.26 | 1 min read
read more
Emerging Technology
New Jersey, Virginia Can Lead the Nation By Building ‘AI Resilience Cohorts’ to Develop Early-Career, State Talent Pipelines

Many states are introducing AI policies and task forces, but lack the “AI-native” personnel to build and maintain initiatives. To address this in the short term, states should establish AI Resilience Cohorts to embed early-career technologists in key offices to support state AI initiatives. Right now, Virginia and New Jersey have the opportunity to take […]

07.22.26 | 7 min read
read more