FierceCIOFierceCIOTechWatchFierceMobileITFierceContentManagementFierceGovernmentIT   FierceVoIPFierceHealthITFierceFinanceIT

Time for public debate on cyber warfare policies

Tools
Tags
Robert Gates
Nsa
Dennis Blair
government cyber security
Cyber Warfare
cyber attacks


There is little doubt that the military and intelligence communities in the U.S. are in full preparation mode for cyber warfare, and seeking to enhance this country's defensive and offensive capabilities. For starters, a new military cyber command has been established, the National Security Agency has been aggressively recruiting talent and ratcheting up its efforts, and funding levels have been increased across the board.

Secretary of Defense Robert Gates testified before Congress in April that that the military spent $100 million on cybersecurity in the previous six months alone, responding to attacks. There have been reports that the Pentagon's most technologically advanced fighter aircraft had been infiltrated by hackers, as had the electrical grid.

Also earlier this year, Director of National Intelligence Dennis Blair warned Congress that the government computer systems are being targeted for espionage by foreign nations such as China and Russia.

Amid all this activity, though, has been a lack of clear government strategy and policy to deal with these threats. How aggressive should this country be in attacking, probing and infiltrating other nation's computer systems? How should the United States respond to attacks, and what would be the consequence of various actions?

This week, we report on a study by the RAND Corp., a well-known think tank that seeks to put some perspective on the issue. The study said that warfare in cyberspace must not be viewed in the traditional sense, but instead "must be understood in its own terms."  Attempts to transfer policy constructs from other forms of warfare will not only fail according to the study, but will also hinder policy and planning.

In offering advice to the Air Force, the report makes a number of salient points. It says, for starters, that the U.S. may be better off playing defense and pursuing diplomatic, economic, and prosecutorial efforts against cyber attackers, rather than making strategic cyber warfare an investment priority. The report recommends that the government focus on shoring up cyber defenses of critical infrastructure like the nation's telecommunications networks, banking systems, and power grid that may be vulnerable to attack.

"Operational cyber war has an important niche role, but only that," the report said.  It added that cyber warfare operations "can confuse and frustrate operators of military systems, and then only temporarily."

The report also called for cyber attacks to be used sparingly and precisely, noting that cyber attacks often have ambiguous sources that make them difficult to retaliate against. Such attacks also could create new enemies if a source is misidentified, and the situation can be further complicated by involvement of non-state actors.

The study provides many useful insights that deserve the attention of policymakers. As we rush ahead to prepare our defenses, protect our essential computer networks and plot military cyber strategy, there should be a broader public debate in Congress, and a much clearer understanding of options, the risks and the challenges. - Judi

Bookmark and Share
Get Your FREE FierceGovernmentIT Email Newsletter:
Comments (1) | Post a comment

Comments

The United States is clearly behind in its cyberdefense capabilities, but is working hard to catch up fast. I believe it is vital for not just our military, intelligence and government decision makers, but also the American people to pay close attention to the RAND's study recommendation, that "warfare in cyberspace must not be viewed in the traditional sense, but instead 'must be understood in its own terms.' Attempts to transfer policy constructs from other forms of warfare will not only fail according to the study, but will also hinder policy and planning."

Like any new challenge, before we start asking for opinions in the open forum, we need to find a way to educate that same open forum - the American people - how truly vulnerable we have become against all the various forms and threats of cyber warfare.

I believe Congress and the American people will have a difficult time truly hearing and "understanding the options, the risks and the challenges" our military, intelligence, government and public face against these threats, because far too many people believe that the US government is either making these threats up or greatly exaggerating their potential impact.

In fact, cyber warfare has been seen used openly over the past several years. Further, variations on the same methods and technologies are growing exponentially on the open internet and being used by organized crime, since these have proven business profitable for these groups. Why? Because the threat, and the potential costs, of getting caught are so much lower than the profitable gains to be had in money, power and political leverage by using forms of cyber warfare.

The rules of engagement have changed, and I agree with the RAND study that we need to consider new means, policies and standards for defending our country from these new forms of attack. We may need to reconsider how and when and how quickly multiple government agencies can work together and share information, which is currently one of our country's stumbling blocks to effective defense. We may need to find a new balance between how we defend and whom is responsible for each layer/level of security - not only for our military and government entities, and critical infrastructure, but also for our critical and near-critical industries. Else, we risk potential threats to our near-critical industries, designed to bully and delay our American response, while more critical assets are attacked.

Read more: http://www.fiercegovernmentit.com/story/time-public-debate-cyber-warfare-policies/2009-10-18#ixzz0Ugb6MpSF

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

To combat spam, please enter the code in the image.