FAS

Army Issues Guidance on Cyberspace Operations

02.20.14 | 3 min read | Text by Steven Aftergood

For the first time the U.S. Army has produced official doctrine on military activities in cyberspace, including offensive, defensive and network operations.

A new Army field manual “provides overarching doctrinal guidance and direction for conducting cyber electromagnetic activities (CEMA)…. It provides enough guidance for commanders and their staffs to develop innovative approaches to seize, retain, and exploit advantages throughout an operational environment.”

It is “the first doctrinal field manual of its kind.” See FM 3-38, Cyber Electromagnetic Activities, February 2014.

The manual introduces the fundamentals of cyber operations, or “cyber electromagnetic activities” (CEMA), defining terms and identifying important operational factors and constraints.

“Today’s Army must operate in cyberspace and leverage an electromagnetic spectrum that is increasingly competitive, congested, and contested.”

However, “execution of CEMA can involve significant legal and policy considerations.” Also, “possibilities of unintended or cascading effects exist and may be difficult to predict.”

Several years ago, any official discussion of offensive cyber operations was considered classified information. That is no longer the case, and the new Army manual — which itself is unclassified — treats the subject as a normal part of military conflict.

“Army forces conduct OCO [offensive cyberspace operations] across the range of military operations by targeting enemy and hostile adversary activity and related capabilities in and through cyberspace,” the Field Manual says.

Cyberspace attacks in support of offensive operations “may be directed at information resident in, or in transit between, computers (including mobile phones and personal digital assistants) and computer networks used by an enemy or adversary.”

“Cyberspace attacks may employ capabilities such as tailored computer code in and through various network nodes such as servers, bridges, firewalls, sensors, protocols, operating systems, and hardware associated with computers or processors. Tailored computer code is only one example of a cyberspace capability… designed to create an effect in or through cyberspace.”

“Cyberspace attacks may employ manipulation which includes deception, decoying, conditioning, and spoofing to control or change information, information systems, and networks.”

The Army manual also presents doctrine on defensive cyberspace operations and on information network operations. “[Defensive] countermeasures in cyberspace should not destroy or significantly impede the operations or functionality of the network they are being employed against, nor should they intentionally cause injury or the loss of life.”

The manual devotes some attention to the legal framework governing cyber operations, which “depends on the nature of the activities conducted.”  Under all circumstances, the manual says, “Army forces conducting CO [cyberspace operations] will comply with the law of war.”

Ordinarily, the manual states, the U.S. Army should not be conducting offensive cyber operations against U.S. targets. “Unless approved by appropriate authorities, Army assets cannot be used to perform attack or exploit operations on U.S. entities.”

“Commanders must ensure that the legal, constitutional, and privacy rights of U.S. citizens are protected throughout the planning and execution of [cyber operations].”

    *    *    *

“Legal Reviews of Cyber Weapons” is one of the topics addressed in the latest issue of the Journal of National Security Law and Policy.

Brendan Koerner reported on “How America’s Soldiers Fight for the Spectrum on the Battlefield” in Wired Threat Level, February 18.

publications
See all publications
Emerging Technology
day one project
Policy Memo
Strategies to Accelerate and Expand Access to the U.S. Innovation Economy

With targeted policy interventions, we can efficiently and effectively support the U.S. innovation economy through the translation of breakthrough scientific research from the lab to the market.

11.27.24 | 16 min read
read more
Government Capacity
day one project
Policy Memo
Collaborative Intelligence: Harnessing Crowd Forecasting for National Security

Crowd forecasting methods offer a systematic approach to quantifying the U.S. intelligence community’s uncertainty about the future and predicting the impact of interventions, allowing decision-makers to strategize effectively and allocate resources by outlining risks and tradeoffs in a legible format.

11.27.24 | 5 min read
read more
Clean Energy
day one project
Policy Memo
The Energy Transition Workforce Initiative

The energy transition underway in the United States continues to present a unique set of opportunities to put Americans back to work through the deployment of new technologies, infrastructure, energy efficiency, and expansion of the electricity system to meet our carbon goals.

11.27.24 | 5 min read
read more
Clean Energy
day one project
Policy Memo
Promoting Fusion Energy Leadership with U.S. Tritium Production Capacity

The United States has the only proven and scalable tritium production supply chain, but it is largely reserved for nuclear weapons. Excess tritium production capacity should be leveraged to ensure the success of and U.S. leadership in fusion energy.

11.26.24 | 12 min read
read more