For the first time the U.S. Army has produced official doctrine on military activities in cyberspace, including offensive, defensive and network operations.
A new Army field manual “provides overarching doctrinal guidance and direction for conducting cyber electromagnetic activities (CEMA)…. It provides enough guidance for commanders and their staffs to develop innovative approaches to seize, retain, and exploit advantages throughout an operational environment.”
It is “the first doctrinal field manual of its kind.” See FM 3-38, Cyber Electromagnetic Activities, February 2014.
The manual introduces the fundamentals of cyber operations, or “cyber electromagnetic activities” (CEMA), defining terms and identifying important operational factors and constraints.
“Today’s Army must operate in cyberspace and leverage an electromagnetic spectrum that is increasingly competitive, congested, and contested.”
However, “execution of CEMA can involve significant legal and policy considerations.” Also, “possibilities of unintended or cascading effects exist and may be difficult to predict.”
Several years ago, any official discussion of offensive cyber operations was considered classified information. That is no longer the case, and the new Army manual — which itself is unclassified — treats the subject as a normal part of military conflict.
“Army forces conduct OCO [offensive cyberspace operations] across the range of military operations by targeting enemy and hostile adversary activity and related capabilities in and through cyberspace,” the Field Manual says.
Cyberspace attacks in support of offensive operations “may be directed at information resident in, or in transit between, computers (including mobile phones and personal digital assistants) and computer networks used by an enemy or adversary.”
“Cyberspace attacks may employ capabilities such as tailored computer code in and through various network nodes such as servers, bridges, firewalls, sensors, protocols, operating systems, and hardware associated with computers or processors. Tailored computer code is only one example of a cyberspace capability… designed to create an effect in or through cyberspace.”
“Cyberspace attacks may employ manipulation which includes deception, decoying, conditioning, and spoofing to control or change information, information systems, and networks.”
The Army manual also presents doctrine on defensive cyberspace operations and on information network operations. “[Defensive] countermeasures in cyberspace should not destroy or significantly impede the operations or functionality of the network they are being employed against, nor should they intentionally cause injury or the loss of life.”
The manual devotes some attention to the legal framework governing cyber operations, which “depends on the nature of the activities conducted.” Under all circumstances, the manual says, “Army forces conducting CO [cyberspace operations] will comply with the law of war.”
Ordinarily, the manual states, the U.S. Army should not be conducting offensive cyber operations against U.S. targets. “Unless approved by appropriate authorities, Army assets cannot be used to perform attack or exploit operations on U.S. entities.”
“Commanders must ensure that the legal, constitutional, and privacy rights of U.S. citizens are protected throughout the planning and execution of [cyber operations].”
* * *
“Legal Reviews of Cyber Weapons” is one of the topics addressed in the latest issue of the Journal of National Security Law and Policy.
Brendan Koerner reported on “How America’s Soldiers Fight for the Spectrum on the Battlefield” in Wired Threat Level, February 18.
When properly structured — with specific numeric targets, secured financial obligations, independent monitoring, and meaningful enforcement — CBAs transform data center deals into durable community partnerships.
Protecting the public from the tech industry’s predatory business models and the next wave of AI harms is an enormous challenge, but we have the evidence that trying to build a healthier digital culture is absolutely worth the effort.
Opaque and insufficiently tested tools are increasingly shaping student outcomes without consistent transparency, civil rights review, or technical safeguards. States and the U.S. Department of Education can address these risks using procurement and oversight tools already within their authority.
Commercial artificial intelligence tools have recently emerged that are able to produce police reports. If the resulting reports are inaccurate, incomplete or biased, or if the process leaks confidential information, this could undermine the criminal justice system and harm citizens.