This paper explores the US's cyber force structure with special emphasis on the cyber workforce. To achieve that goal, this paper addresses several issues: it characterizes the nature of the cyber security problem; it draws on insights from senior decision-Makers to identify cyber force structure needs; it characterizes current capabilities by summarizing the key initiatives that are being pursued by the US Services and key joint activities; and it identifies a spectrum of actions to mitigate shortfalls in the existing cyber forces structure (i.e. education; higher education and recruitment; certification, retention, professional development, and workforce management; exercises; and security clearance requirements). The paper concludes by identifying actions that NATO might pursue to improve its cyber force structure (e.g. conduct realistic, stressful exercises) and by identifying residual issues to address (e.g. career progression; value of employing "patriotic hackers").
The cyber domain is undergoing extraordinary changes that present both exceptional opportunities to and major challenges for users of cyberspace. The challenges arise from the malevolent actors who use cyberspace and the many security vulnerabilities that plague this sphere. Exploiting opportunities and overcoming challenges will require a balanced body of knowledge on the cyber domain. Cyberpower and National Security assembles a group of experts and discusses pertinent issues in five areas.The first section provides a broad foundation and overview of the subject by identifying key policy issues, establishing a common vocabulary, and proposing an initial version of a theory of cyberpower. The second section identifies and explores possible changes in cyberspace over the next fifteen years by assessing cyber infrastructure and security challenges. The third section analyzes the potential impact of changes in cyberspace on the military and informational levers of power. The fourth section addresses the extent to which changes in cyberspace serve to empower key entities such as transnational criminals, terrorists, and nation-states. The final section examines key institutional factors, which include issues concerning governance, legal dimensions, critical infrastructure protection, and organization.Cyberpower and National Security frames the key issues concerned and identifies the important questions involved in building the human capacity to address cyber issues, balancing civil liberties with national security considerations, and developing the international partnerships needed to address cyber challenges. With more than two dozen contributors, Cyberpower and National Security covers it all.
: During the course of nearly two years, the Center for Technology and National Security Policy (CTNSP), National Defense University (NDU), has conducted extensive research to identify and explore major cyber issues. These activities were performed in response to a request in the 2006 Quadrennial Defense Review (QDR). result of that research is documented in a book entitled and National Security. As part of that research, CTNSP convened several workshops to address challenges in cyberspace, cyberpower, cyberstrategy, and institutional factors. Several representatives from the military Services participated in these workshops. During the workshops, a variety of cyber issues emerged about the roles of the Services in the areas of roles and missions and the creation of needed intellectual capital. When asked if they could contribute to the public debate on these cyber issues, each of the Services identified volunteers who graciously generated white papers to illuminate the cyber debate. These white papers constitute the individual opinions of the contributors who sought to identify and explore the key cyber challenges that the Services must address. To put those contributions in context, Dr. Elihu Zimet and Dr. Charles Barry from CTNSP have written an initial chapter that briefly summarizes the major findings and recommendations from the individual authors. white papers are as follows: Unified Field Theory for Full-Spectrum Operations: Cyberpower and the Cognitive Domain, by Jeffrey G. Smith, Jr.; Operations to Achieve Military Power in Cyberspace: A Draft Concept for Navy Computer Network Operations, by Michael A. Brown; The Air Force in Cyberspace: Five Myths of Cyberspace Superiority, by Forrest B. Hare and Glenn Zimmerman; and Marine Corps Cyberspace in Support of MAGTF C2: By Many a Marine, with a Single Vision, by John L. Cloninger.
In the 2006 Quadrennial Defense Review, a request was made to have the Center for Technology and National Security Policy (CTNSP), National Defense University (NDU), develop a theory of cyberpower. It was noted that there was a need to develop a holistic framework that would enable policy makers to address cyber issues in proper perspective. To satisfy that tasking, CTNSP convened five workshops, drawing on experts from government, industry, academia, and think tanks. Those workshops addressed a broad set of issues related to the evolution of cyberspace, cyberpower, cyberstrategy, and institutional factors that influence those factors (e.g., governance, legal issues). To develop the desired theory, this paper systematically addresses five key areas. First, the paper defines the key terms that are associated with cyber issues. Particular emphasis is placed on the terms “cyberspace”, “cyberpower”, and “cyberstrategy”. Second, the paper categorizes the elements, constituent parts, and factors that yield a framework for thinking about cyberpower. Third, the paper explains the major factors that are driving the evolution of cyberspace and cyberpower. To support that effort, the paper presents strawman principles that characterize major trends. Fourth, the paper connects the various elements of cyberstrategy so that a policy maker can place issues in proper context. Finally, the theory anticipates key changes in cyberspace that are likely to affect decision making. In view of the dramatic changes that are taking place in cyberspace, it is important to stress that this effort must be regarded as a preliminary effort. It is expected that the theory will continue to evolve as key technical, social, and informational trends begin to stabilize.
: The term information and communication technologies (ICTs) encompasses the range of technologies for gathering, storing, retrieving, processing, analyzing, and transmitting information that are essential to prospering in a globalized economy. Advances in ICTs have reduced the costs of managing information and introduced innovations in products, processes, and organizational structures that, in turn, have generated new ways of working, market development, and livelihood practices. Internationally, ICTs are viewed as a basic enabler of informal social and economic discourse, leading to a strengthening of civil society and the promotion of economic activity. The importance the United Nations (UN) attaches to ICTs as enablers of economic, governance, security, education, health care, and social well-being reconstruction and development is evident in sponsorship of two international summits, the 2003 and 2005 World Summit on the Information Society (WSIS). These summits documented steps on how to establish and organize the Information Society, and their reports referenced the importance of ICT by frequently citing the phrase, ICTs as a tool for social and economic development. 1 While there is little doubt that ICTs are an engine for social and economic development, quantifying their impact is difficult. Evidence remains largely anecdotal, and the link between ICT deployment and reconstruction and development remains vague. The National Defense University (NDU) Center for Technology and National Security Policy (CTNSP) recently completed a study, known as the I-Power study, which looked at using information and ICTs to achieve success in stability and reconstruction (S&R) operations. The study results suggest that the strategic use of information and ICTs can increase significantly the likelihood of success in affected-nation, cross-sector reconstruction and development if they are engaged at the outset as part of an overall strategy that coordinates actions.
: Information and information technology (I/IT) can significantly increase the likelihood of success in stability operations if they are engaged as part of an overall strategy that coordinates the actions of outside intervenors and focuses on generating effective results for the host nation. Properly utilized, I/IT can help create a knowledgeable intervention, organize complex activities, and integrate stability operations with the host nation, making stability operations more effective. Key to these results is a strategy that requires that 1) the U.S. Government gives high priority to such an approach and ensures that the effort is a joint civilian-military activity; 2) the military makes I/IT part of the planning and execution of the stability operation; 3) preplanning and the establishment of I/IT partnerships are undertaken with key regular participants in stability operations, such as the United Nations and the World Bank; 4) the focus of the intervention, including the use of I/IT, is on the host nation, supporting host-nation governmental, societal, and economic development; and 5) key information technology capabilities are harnessed to support the strategy. Implementing the strategy will include 1) development of an information business plan for the host nation so that I/IT is effectively used to support stabilization and reconstruction; 2) agreements among intervenors on data-sharing and collaboration, including data-sharing on a differentiated basis; and 3) use of commercial IT tools and data provided on an unclassified basis.
Abstract : Recent United States (US) government experiences with failed-state interventions suggests that telecommunications (telecoms) and information technology (IT) reconstruction initiatives continue to suffer from a lack of adequate understanding of the affected nation information culture and telecoms and IT business cultures. A coherent telecoms and IT-related civil-military strategy and plan for intervening nations and responding international organizations (IO) and non-governmental organizations (NGO) is lacking as well and there are no agreed mechanisms and procedures to enable effective civil-military coordination and information sharing among participants and with the affected nation. National Defense University, Center for Technology and National Security Policy studies suggest that information and IT can significantly increase the likelihood of success in failed-state interventions and subsequent reconstruction if they are engaged from the outset as part of an overall strategy and plan that coordinates the actions of outside interveners and focuses on generating effective results for the affected nation. This paper examines Afghanistan telecoms and IT as a case study of its use as an enabler of sector reconstruction. Some of the successes and related coordination and information sharing challenges encountered by the multinational civil-military responders and affected nation telecoms and IT organizations are illuminated as well.
During the course of the Department of Defense’s (DoD) 2006 Quadrennial Defense Review, it was observed that DoD lacks a coherent, holistic framework to formulate and assess policy issues associated with cyberspace and cyberpower. To redress that shortfall, the Under Secretary of Defense (Policy) directed the Center for Technology and National Security Policy (CTNSP), National Defense University (NDU), to undertake a cyberpower study. As stated in the study’s Terms of Reference, “... there is a compelling need for a comprehensive, robust and articulate cyber power theory that describes, explains and predicts how our nation should best use cyber power in support of US national and security interests”. Consistent with that goal, this paper addresses four issues. First, it provides a holistic framework for addressing cyberpower issues and it summarizes the major findings of several studies that are being developed to characterize that framework. Second, it identifies and discusses potential Measures of Merit (MoMs) that can be applied to layers of that holistic framework. Third, to illustrate the types of analyses that are being pursued, a framework for tactical Influence Operations is introduced and applied. The paper concludes with some broad observations on the nature of the cyberpower problem.
: During the course of the Department of Defense's (DoD) 2006 Quadrennial Defense Review, it was observed that DoD lacks a coherent, holistic framework to formulate and assess policy issues associated with cyberspace and cyberpower. To redress that shortfall, the Under Secretary of Defense (Policy) directed the Center for Technology and National Security Policy (CTNSP), National Defense University (NDU), to undertake a cyberpower study. As stated in the study's Terms of Reference, there is a compelling need for a comprehensive, robust and articulate cyber power theory that describes, explains and predicts how our nation should best use cyber power in support of US national and security interests. Consistent with that goal, this paper addresses four issues. First, it provides a holistic framework for addressing cyberpower issues and it summarizes the major findings of several studies that are being developed to characterize that framework. Second, it identifies and discusses potential Measures of Merit (MoMs) that can be applied to layers of that holistic framework. Third, to illustrate the types of analyses that are being pursued, a framework for tactical Influence Operations is introduced and applied. The paper concludes with some broad observations on the nature of the cyberpower problem.
Overview Information and information technology (I/IT) can significantly increase the likelihood of success in stability operations--if they are engaged as part of an overall strategy that coordinates the actions of outside intervenors and focuses on generating effective results for the host nation. Properly utilized, I/IT can help create a knowledgeable intervention, organize complex activities, and integrate stability operations with the host nation, making stability operations more effective. Key to these results is a strategy that requires that 1) the U.S. Government gives high priority to such an approach and ensures that the effort is a joint civilian-military activity; 2) the military makes I/IT part of the planning and execution of the stability operation; 3) preplanning and the establishment of I/IT partnerships are undertaken with key regular participants in stability operations, such as the United Nations and the World Bank; 4) the focus of the intervention, including the use of I/IT, is on the host nation, supporting host-nation governmental, societal, and economic development; and 5) key information technology capabilities are harnessed to support the strategy. Implementing the strategy will include 1) development of an information business plan for the host nation so that I/IT is effectively used to support stabilization and reconstruction; 2) agreements among intervenors on data-sharing and collaboration, including data-sharing on a differentiated basis; and 3) use of commercial IT tools and data provided on an unclassified basis. Over the past 30 years, the information revolution has had an important impact on the conduct of military operations. In the United States, it has produced what is often called "netcentric warfare" or "netcentric operations" (1)--the combination of shared communications, key data, analytic capabilities, and people schooled in using those capacities--that has enabled enhanced joint activities, integrated distributed capabilities, much greater speed, and more effective maneuver. The result has been that the United States and its allies have been able to conduct very effective combat operations under a range of conditions, including quick insertion (Panama), maneuver warfare (major combat operations in Iraq), an all-air campaign (Kosovo), and a Special Forces-led effort (Afghanistan). At the same time that major combat operations have proceeded so successfully, the United States and its allies have undertaken a variety of stability operations in Somalia, Haiti, Bosnia, Kosovo, East Timor, several African countries, Afghanistan, and Iraq. (2) These stability operations generally have included both economic and governance reconstruction and have spanned the full security gamut from nonviolent peacekeeping to full-blown counterinsurgency. Not one of these operations has approached the success achieved in combat operations undertaken in the same period. This paper analyzes whether a strategic use of information and information technology (I/IT) in stability operations could lead to more successful operations. Certainly, the information revolution has been a dynamic and positive factor in business, government, and social arenas in the Western world. The combination of technology, information content, and people schooled in the use of each has reshaped enterprises and activities of all types. This paper concludes that utilizing the elements of the information revolution in a strategic approach to stability operations would have positive results and sets forth the strategic and operational parameters of such an effort. Problems of Stability Operations Utilizing the fruits of the information revolution for effective stability operations requires a prior understanding of what makes a stability operation effective. As noted above, stability operations have security, economic, and governance reconstruction elements. Yet while it is widely recognized that stability operations go far beyond purely military actions--encompassing security, humanitarian, economic, and governance/ rule of law issues--no one has set forth an actual strategic or operational doctrine that promises success in stability operations. …
In 2004, Congress directed the Center for Technology and National Security Policy (CTNSP) to develop a pilot program "to find practical ways in which the defense IT community can gain a mutual understanding of defense needs and industry capabilities and identify opportunities to integrate IT innovations in the U.S. military strategy." As context, this paper summarizes the nature of the problem, current Department of Defense (DoD) guidance on the issue, and current DoD methods to capture commercial IT. Subsequently, the paper identifies and discusses the major obstacles that impede DoD's use of commercial IT: non-attractiveness; non-transparency; non-agility; non-dominance; an isolating market; and attitudes of primes. In order to ameliorate these obstacles, a balanced mix of initiatives is recommended: 1) Enhance communications/organization (e.g., create a new organization at JFCOM to coordinate DoD's use of commercial IT); 2) Increase resource flexibility(e.g., provide combatant commands appropriate limited acquisition authority); 3) Decrease barriers (e.g., change DoD rules on intellectual property rights); 4) Stimulate cultural change(e.g., increase DoD education and training for commercial IT procurement); 5) Review testing (e.g., evaluate expanding "underwriter lab " testbeds); 6) Adapt requirements for specific missions(e.g.,undertake studies on the use of commercial IT in stabilization and reconstruction operations).