SECRECY NEWS
from the FAS Project on Government Secrecy
Volume 2014, Issue No. 15
February 20, 2014

Secrecy News Blog: http://blogs.fas.org/secrecy/

ARMY ISSUES GUIDANCE ON CYBERSPACE OPERATIONS

For the first time the U.S. Army has produced official doctrine on military activities in cyberspace, including offensive, defensive and network operations.

A new Army field manual "provides overarching doctrinal guidance and direction for conducting cyber electromagnetic activities (CEMA).... It provides enough guidance for commanders and their staffs to develop innovative approaches to seize, retain, and exploit advantages throughout an operational environment."

It is "the first doctrinal field manual of its kind." See FM 3-38, Cyber Electromagnetic Activities, February 2014.

The manual introduces the fundamentals of cyber operations, or "cyber electromagnetic activities" (CEMA), defining terms and identifying important operational factors and constraints.

"Today's Army must operate in cyberspace and leverage an electromagnetic spectrum that is increasingly competitive, congested, and contested."

However, "execution of CEMA can involve significant legal and policy considerations." Also, "possibilities of unintended or cascading effects exist and may be difficult to predict."

Several years ago, any official discussion of offensive cyber operations was considered classified information. That is no longer the case, and the new Army manual -- which itself is unclassified -- treats the subject as a normal part of military conflict.

"Army forces conduct OCO [offensive cyberspace operations] across the range of military operations by targeting enemy and hostile adversary activity and related capabilities in and through cyberspace," the Field Manual says.

Cyberspace attacks in support of offensive operations "may be directed at information resident in, or in transit between, computers (including mobile phones and personal digital assistants) and computer networks used by an enemy or adversary."

"Cyberspace attacks may employ capabilities such as tailored computer code in and through various network nodes such as servers, bridges, firewalls, sensors, protocols, operating systems, and hardware associated with computers or processors. Tailored computer code is only one example of a cyberspace capability... designed to create an effect in or through cyberspace."

"Cyberspace attacks may employ manipulation which includes deception, decoying, conditioning, and spoofing to control or change information, information systems, and networks."

The Army manual also presents doctrine on defensive cyberspace operations and on information network operations. "[Defensive] countermeasures in cyberspace should not destroy or significantly impede the operations or functionality of the network they are being employed against, nor should they intentionally cause injury or the loss of life."

The manual devotes some attention to the legal framework governing cyber operations, which "depends on the nature of the activities conducted." Under all circumstances, the manual says, "Army forces conducting CO [cyberspace operations] will comply with the law of war."

Ordinarily, the manual states, the U.S. Army should not be conducting offensive cyber operations against U.S. targets. "Unless approved by appropriate authorities, Army assets cannot be used to perform attack or exploit operations on U.S. entities."

"Commanders must ensure that the legal, constitutional, and privacy rights of U.S. citizens are protected throughout the planning and execution of [cyber operations]."

* * *

"Legal Reviews of Cyber Weapons" is one of the topics addressed in the latest issue of the Journal of National Security Law and Policy.

See also "How America's Soldiers Fight for the Spectrum on the Battlefield" by Brendan Koerner, Wired Threat Level, February 18:


INDEPENDENCE OF FINANCIAL REGULATORS, AND MORE FROM CRS

New and updated reports from the Congressional Research Service that have not been made readily available to the public include the following.

Independence of Federal Financial Regulators, February 12, 2014:

Small Business: Access to Capital and Job Creation, February 18, 2014:

U.S.-South Korea Relations, February 12, 2014:

U.S.-Japan Economic Relations: Significance, Prospects, and Policy Options, February 18, 2014:

The U.S.-Colombia Free Trade Agreement: Background and Issues, February 14, 2014:

Latin America and the Caribbean: Key Issues for the 113th Congress, February 15, 2014:

Bahrain: Reform, Security, and U.S. Policy, February 14, 2014:

Visa Waiver Program, February 12, 2014:

FBI Director: Appointment and Tenure, February 19, 2014:

******************************

Secrecy News is written by Steven Aftergood and published by the Federation of American Scientists.

The Secrecy News blog is at:
      http://blogs.fas.org/secrecy/

To SUBSCRIBE to Secrecy News, go to:
     http://blogs.fas.org/secrecy/subscribe/

To UNSUBSCRIBE, go to:
      http://blogs.fas.org/secrecy/unsubscribe/

OR email your request to saftergood@fas.org

Secrecy News is archived at:
      http://www.fas.org/sgp/news/secrecy/index.html

SUPPORT the FAS Project on Government Secrecy with a donation here:
      https://members.fas.org/donate/