FAS

Information Operations: It Takes a Thief

01.06.17 | 1 min read | Text by Steven Aftergood

At a Senate Armed Services Committee hearing yesterday on foreign cyber threats to the U.S., there were several references to the saying that “people who live in glass houses should not throw stones.” The point, made by DNI James Clapper, was that the U.S. should not be too quick to penalize the very espionage practices that U.S. intelligence agencies rely upon, including clandestine collection of information from foreign computer networks.

But perhaps a more pertinent saying would be “It takes a thief to catch a thief.”

U.S. intelligence agencies should be well-equipped to recognize Russian cyber threats and political intervention since they have been tasked for decades to carry out comparable efforts.

A newly disclosed intelligence directive from 1999 addresses “information operations” (IO), which are defined as: “Actions taken to affect adversary information and information systems while defending one’s own information and information systems.”

“Although still evolving, the fundamental concept of IO is to integrate different activities to affect [adversary] decision making processes, information systems, and supporting information infrastructures to achieve specific objectives.”

The elements of information operations may include computer network attack, computer network exploitation, and covert action.

See Director of Central Intelligence Directive 7/3, Information Operations and Intelligence Community Related Activities, effective 01 July 1999.

The directive was declassified (in part) on December 2 by the Interagency Security Classification Appeals Panel, and was first obtained and published by GovernmentAttic.org.

publications
See all publications
Government Capacity
Blog
What the Metascience Community Should Learn From the Federal Evidence Movement Before Making Our Mistakes

The emerging federal metascience community is asking fascinating questions that are equally vital for democratic legitimacy: beyond “did this program work” to “how does the federal R&D enterprise itself work, and how could it work better?” 

06.03.26 | 12 min read
read more
Environment
Blog
I Want to Talk About Solar Geoengineering and You Should Too!

If you’re new to the climate intervention space, welcome! The TL;DR: if we can’t stop the most catastrophic impacts of climate change with current tools quickly enough, then we need a bigger toolbox.

06.02.26 | 6 min read
read more
Environment
Blog
Disaster Policy Nerds Explain the Good, Bad, and Ugly in FEMA Review Council Report

After months of delay, the council tasked by President Trump to review the FEMA released its final report. Our disaster policy nerds have thoughts.

05.21.26 | 8 min read
read more
Global Risk
Press release
Federation of American Scientists, Future of Life Institute Present Converging Risks Report, AI Impact Awards at Gala

FAS and FLI partnered to build a series of convenings and reports across the intersections of artificial intelligence (AI) with biosecurity, cybersecurity, nuclear command and control, military integration, and frontier AI governance. This project brought together leaders across these areas and created a space that was rigorous, transpartisan, and solutions-oriented to approach how we should think about how AI is rapidly changing global risks.

05.20.26 | 9 min read
read more