WASHINGTON — The Senate Armed Services Committee has included a provision in its annual defense policy bill to authorize a pilot program allowing civilian contractors to conduct limited cyber access operations under U.S. Cyber Command's authority.
The pilot program aims to assess the feasibility of using civilian contractors, with their own infrastructure, to gain access to systems for cyber operations. These proposed operations would remain under the operational direction and authority of U.S. Cyber Command. The provision specifies that contractors would not be authorized to conduct cyber effects, such as denying, degrading, disrupting, destroying, or manipulating targeted systems.
Charlie Moore, a distinguished visiting professor at Vanderbilt University and former deputy commander of CYBERCOM, expressed optimism about the development. "I am hopeful this is indicative that inside the Department of War, but also up on Capitol Hill, people understand that we need to move towards a much closer relationship with the private sector," Moore said. "We have to move beyond what we typically call partnerships and into becoming true teammates." Moore added, "The only way we're going to scale to meet the qualitative and quantitative capabilities that we need against the likes of China is through close teamwork with the private sector." He also stated, "These are cyber operations conducted under direct oversight and control of Title 10 operators."
Herbert Lin, a senior research scholar at the Center for International Security and Cooperation at Stanford University, said, "The solution to that problem is let's just penetrate everything that the president might want to attack, and that's a big deal because that's a lot of targets." Lin explained, "Cyber Command clearly can't do all of that. So the question is, how do you do it? And this seems to be a way." Lin compared the access operations to a country digging a tunnel without sending in troops. "It's analogous to [saying], 'let's have the North Koreans dig a tunnel under the DMZ into South Korea,' but they don't send any troops in, they just dig a hole," Lin said. "Now, nobody believes they're going to send people with flowers, but they haven't done anything. Does that count as an attack? It certainly counts as unfriendly, but is it an attack? As I say, that's for lawyers to decide."
Kurt Sanger, formerly CYBERCOM's deputy general counsel, said, "It's not the same as intel gathering because you've taken a step towards having a cyber effect." Sanger added, "But given the nature of the effects most US cyber operations cause, contractors won't be connected to anything traditionally considered a provocative activity, and certainly [this] isn't the type of kinetic activity that has led to escalation."
Cyber effects are currently not permitted for contractors under U.S. law. Implementing such actions would require changes in department policy and congressional action. According to Gary Brown, conducting cyber operations on their own infrastructure could make civilian contractors legitimate military targets. Before becoming law, the Senate and House must reconcile their versions of the National Defense Authorization Act, pass both chambers, and receive the president's signature.
forum Comments (0)
No comments yet. Be the first to comment.