The United States National Cyber Strategy and cybersecurity defense
Introduction
Cybersecurity is fast becoming the most important component of national security, especially in an era in which borders have become permeable and in which traditional forms of warfare are becoming outmoded or even obsolete. Malevolence manifests more in cyberterrorism and the destructive potential for cyberterrorism to wreak havoc on global economic, political, and social systems. Moreover, cybercrime is trans-national. It is both akin to non-state terrorist activities and also tightly woven into the methods used by non-state terrorist actors. Building a strong national defense around cybersecurity has therefore become a top priority for any sensible nation in this stage of the 21st century.
Overview
The United States National Cyber Strategy provides a rough outline covering how the federal government protects all “networks, systems, functions, and data” without impeding the free flow of information or finance online (Office of the President of the United States 1). The strategy includes suggestions for how the federal government can work with allied counterparts abroad, as well as domestic and multinational allies in the private sector. In many ways, the National Cyber Strategy reflects core American interests, and the Office of the President overtly states the intent to “expand American influence abroad,” without necessarily indicating what that influence means (1). By joining forces with a global cybersecurity team, the American government can hope to forge the types of coalitions that can prevent and impede cybercrime and cyberterrorism.
Cybercrime is a unique beast. Unlike any type of traditional warfare, cybercrime and cyberterrorism can be conducted asynchronously. A criminal actor or group could, for example, set a malicious code to execute at a future date and time, or triggered by a specific type of event—thereby going undetected until it is too late. Remaining vigilant and one step ahead of the game is of critical importance to cybersecurity strategy. For this reason, the federal government needs to remain dedicated to culling the best minds from around the world to collaborate on an advanced, progressive, and intelligent cybersecurity strategy.
The cybersecurity strategy also needs to include the means by which to design artificially intelligent sentry systems that use algorithmic functions to contribute to a global defense shield that can remain intact under any and all circumstances. Working with the private sector in this regard, the United States government can deploy the best of its resources towards the creation of a worldwide system of support to protect public interests everywhere. An ideal cybersecurity strategy entails “a modus vivendi between the government and private corporations, trying to balance market efficiency, science and technology, basic freedoms, and privacy with IT security,” as in the Israeli cybersecurity model (Adamsky 4). Public utilities, industry, education, business, and every single sector of the economy all need continual protection from intruders and those who seek destruction or disruption.
Centralization is a key area of concern in the national cyber strategy. There are pros and cons, risks and benefits, associated with the centralization of cybersecurity or any other area of security. The Office of the President of the United States declares that centralization is in the best interest of the American people due to the need for aligning risk management and technology activities. Coordinating risk management resources under a common rubric helps all government agencies stay on the same page, aware of threats and the means by which to address them. Collaborating with allied governments will also aid in the protection of critical infrastructure, the protection of critical data, and of the generation of an international intelligence community committed to systematic incident reporting.
Protecting critical national infrastructure is the primary objective for the federal cybersecurity strategy, although this objective is closely connected with ancillary goals. Emergency response services and their information networks, law enforcement databases of all types, power control networks, supervisory control and data acquisition (SCADA), military services, finance, and telecommunications are only a few of the many elements of a delicate digital web woven throughout the nation that requires constant vigilance and ongoing protection (Amoroso 2). A vigorous partnership between the private and public sectors has become absolutely essential in maintaining the federal government’s cybersecurity program. The private sector offers insight, intelligence, feedback, risk assessment, and the means by which to intervene in case of threats and attacks. Yet ultimately it is the federal government that is responsible for creating the means by which to monitor and control massive amounts of data and for enforcing all laws related to the protection of that data. Cybersecurity strategy therefore includes a comprehensive defense structure with surefire, systematic ways of retaliating and/or punishing aggressors.
The cyber domain is recognized, rightly so, as an area of vulnerability in the national defense system overall (Office of the President of the United States). Small-scale cybersecurity measures such as the use of secure networks, firewalls, intrusion detection systems, antivirus software, audit trails, and encryption are insufficient for the large scale needs of national infrastructure protection (Amoroso 2).
Education, Training, Recruitment and HR
This pillar of the national cybersecurity program has a number of different dimensions to it. The first is training, wherein the key attack vectors are addressed at the granular level. In the 2018 fiscal year, there were 31,107 cyberattacks on US government targets recorded. Of these, the most common attack vectors were improper usage, other/unknown, e-mail/phishing, web and loss/theft of equipment (Clement, 2020). Vectors like improper usage, theft/loss of equipment and email/phishing all relate directly back to the end user. This is where training comes into play. Establishing a program wherein federal employees and contractors receive a consistent standard of training, implemented regularly, will help keep all federal employees up to date on how to manage the risk that they themselves pose. Such training can include password management techniques, phishing simulations, proper storage and care of hardware and more. The Department of Homeland Security currently offers cybersecurity training and exercises via the NCCIC, the National Cybersecurity and Communications Integration Center (CISA.gov, 2020).
Education, recruitment and human resources forms the other part of this pillar. In order for the United States to be as safe as possible from cybersecurity threats, the nation must be ahead of rivals in terms of technological proficiency. Any area where rivals are more advanced is an attack vector that is difficult to defend. Thus, the United States needs to have the world’s highest standards of cybersecurity education, and then be able to recruit the most talented individuals into federal service with CISA and other relevant agencies. As part of this endeavor, the Department of Homeland Security provides educators with the resources necessary to empower students to become digitally literate. By building the largest pool of people possible who have high cybersecurity education, the US government will have a larger pool of talent from which to recruit.
The National Cybersecurity Workforce Framework forms the basis for “increasing the size and capability of the US cybersecurity workforce”, in order that all stakeholders in national cybersecurity have a system for “organizing the way we think about cybersecurity work, and what is required of the cybersecurity workforce” (CISA.gov, 2020). Having this level of national leadership and coordination strengthens the overall cybersecurity knowledge of the nation, and puts more resources into both the public and private sectors, the latter allowing for high levels of innovation and the former leveraging the brightest talents in the field to help design and maintain the nation’s cybersecurity infrastructure.
Cross-Agency Links
The Department of Homeland Security, through CISA and other agencies, is the main driver of the national cybersecurity policy. However, in order to implement this policy consistently across government, there needs to be a high level of coordination among agencies. For example, while CISA plays a role in education and administration of cybersecurity policy, the military and law enforcement play critical roles in the actual defense of the nation from digital threats, and whatever responses that might be required as the result of specific threats and attacks from malicious actors.
This coordination is led by CISA, but brings in other agencies where needed, along with the military and the private sector. The objective is that CISA will drive a “whole of nation” response, rather than allowing response to be the responsibility of one single agency. This approach allows for the most appropriate response to be brought forth, using whatever tools might be available anywhere in the nation, public sector or private. One example of this cooperation is the recent memorandum of understanding signed by the Departments of Energy, Homeland Security and Defense. This initiative extends the Pathfinder information sharing critical infrastructure sectors between these agencies. This high level of inter-agency cooperation is necessary to utilize the full resources of the United States government and bring about the needed whole of nation response to cybersecurity threats (Rockwell, 2020).
It has been argued, however, that the Department of Homeland Security is not necessarily properly equipped to manage the cybersecurity portfolio. The DHS has a number of different initiatives, and cybersecurity is clearly a matter of homeland security, but there is a case being made for a separate cybersecurity agency. The response to cybersecurity threats, outside of DHS, is a patchwork of federal, state and local approaches, with limited coordination between them, and this challenges the notion of whole of nation responses. A lack of coordination and resources lays at the heart of the challenges, and some believe that these challenges could be addressed with a dedicated department, one that would recognize the importance of cybersecurity in the 21st century (Petraeus & Sridhar, 2018).
The Intelligence Community
The intelligence community also plays a key role in combatting cybercrime. Since most cybercrime against government targets is likely the work of foreign governments or their proxies, the intelligence community can play a key role in the nation’s cybersecurity strategy. First, by the nature of its work, the intelligence community is a choice target for malicious foreign governments. Thus, one of the pillars of the national cybersecurity strategy is to improve cybersecurity among intelligence officials and employees (DNI.gov, 2019).
The intelligence community is also responsible for some incident response. The Snowden affair appears to have been a catalyst for the intelligence community to pay much greater attention to cybersecurity and one of the big initiatives therein is that Western intelligence agencies are helping themselves and other organizations better protect themselves. This is done by providing free tools, being more visible in public, recruiting drives, and working with partners around the world to identify threats and bring about more effectively, multinational responses to critical incidents, in part to contain any damage that might occur. Modern cybersecurity, for example, is being built into new systems that come on board to replace legacy systems that were not designed with cybersecurity in mind (Schwartz, 2019).
For the intelligence community, the use of artificial intelligence is another means by which it is engaging cybersecurity on the front lines. AI is already being used in the private sector to assist with cybersecurity. For example, there are AI technologies that are used to replicate the thought processes of a cybersecurity analyst, essentially providing an additional low cost warning system by using the same spotting processes that a human analyst would use (Bernard, 2020). By using AI for this and other roles, intelligence agencies and other federal government actors have the ability to counter the limitations on their resources significantly. However, the main caveat is that they will be contending with AI being used against US interests, and this is really a race to build the best AI.
Private Sector Engagement
There are a few roles that the private sector can play in the nation’s cybersecurity program. First, some private entities are contractors that have some access to sensitive federal information. So these entities must, by virtue of that fact, be brought into the national cybersecurity program. But the private sector has something to teach the government as well. Essentially, a lot of cybersecurity technology and knowledge develops in the private sector on a separate track from the public sector technology development that occurs. Industries that perform very well on cybersecurity measures can teach the government, and industries that perform poorly, on cybersecurity best practices. One of the main challenges is actually identifying the industries and companies that perform well on cybersecurity issues, as for example only around one-third of software applications in critical infrastructure technology pass basic OWASP standards (Wysopal, 2018). But where private companies excel, they may develop that knowledge that, given the right channels to transmit information between the private sector and government, can help to bolster government cybersecurity practices and protocols. The FBI is also involved in this regard, as that agency has a program to work with the private sector to educate private companies about the threats that exist and how they should respond to an incident – especially valuable given that 95% of the country’s infrastructure is controlled by private companies (Thornton, 2019). This educational role serves as a supplement to the role that CISA plays doing much the same thing – but all hands on deck makes sense for a whole of nation response.
Among the initiatives that target the private sector are a number that focus on government contractors. Even contractors that deal with unclassified information are subject to attacks, and the threat is apparently growing (DoD, 2018). As such, there have been recent changes to improve security for government contractors, even those that only have access to unclassified information. These new guidelines include, for example, small businesses doing business with the government to certify that their data security standards are being met (Crawford, 2020). This Cybersecurity Maturity Model Certification (CMMC) program is “the Pentagon’s attempt to create a simpler, more consistent framework for the cyber demands it imposes on contractors and subcontractors (Ogrysko, 2019).
International Coordination
In a world with multiple powerful malicious actors, the United States cannot simply go it alone on cybersecurity. As such, there are multiple initiatives by which the US engages its allies in common cybersecurity defense. The reality is that in our interconnected world, the weakest link is the most likely attack vector, and that means working closely with allies that all the world’s free democracies are strong enough to deflect cyberattacks by malicious actors. International bodies such as the Council of Europe, INTERPOL, the International Telecommunications Union, the UN Office on Drugs and Crime, the Anti-Phishing Working Group, the Internet Watch Foundation and the Rand Corporation all play important roles in the digital defense of the free world, and therefore are stakeholders with the US government on helping to defend and neutralize threats, often before those threats have reached US targets (Georgetown Law Library, 2020).
Another reason for international engagement is that US companies, some of which serve at high levels of the federal government, also operate in other countries. As such “US companies are most effective when they can rely on the same cybersecurity standards overseas as they do in the United States” (Daniel, 2015), thereby ensuring that overseas offices of US companies are not attack vendors of note. For the most part, these standards are developed by non-governmental organizations, as the White House believes that this approach “yields standards of better technical rigor and industry uptake, helps support innovation and enables the rapid adaptation and evolution of standards” (Daniel, 2015), essentially relying on the private sector to understand foreign country situations better than the US government, which is a reasonable approach as a complement to the work of DHS.
Money Laundering
In terms of dealing with cybercrime perpetrated against the US government, it is often the case that the actors involved are not necessarily easy to determine immediately. This means that the infrastructure for determining the source of an attack has to be worked out via things like studying money laundering patterns, or trade in state secrets on the dark web. The FBI, for example, relies on private companies that specialize in dark web intelligence to help with investigations into malicious or criminal activity that targets US interests. The use of private sector firms that specialize is consistent with other federal departments, all of which face resource constraints that might prevent them from developing these competencies internally (Bing, 2017).
Recommendations
One of the most important recommendations is that the federal government needs to ensure that its agencies, particularly the DHS, have sufficient resources. It can be a difficult task to coordinate between different agencies, and then subsequently educate federal employees and contractors, and ensure that best practices for hardware and software are also adopted. This complex task requires substantial resources. There is always the concern in government that the needed resources will not exist, but this needs to not be the case. If what is required is the creation of a dedicated cybersecurity agency, then that is what should be on the table. As the world has changed, the country’s response to cybersecurity and the threat it poses should change as well.
Furthermore, another recommendation is to invest in AI, but not just at the governmental level, but to ensure that the private sector has the tools that it needs to build the best cybersecurity AI. Foreign companies cannot be relied upon for this, and furthermore it may be necessary for safeguards to be put into place that ensure that work private companies do remains proprietary. Just as the approach with dark web intel firms is to build backchannels to use those companies to do government work in secret, so there must also be efforts with leading AI firms to ensure that the US government is the beneficiary of their work on cybersecurity AI and that such technology is not easily replicable. The reality is that we are in a cybersecurity arms race, with AI as the key component of that arms race, and all steps must be undertaken to ensure that the US develops and retains the best AI cybersecurity technology.
Otherwise, many of the existing programs are actually quite strong. The educational component may not be moving quickly, but it is there and it has been somewhat successful thus far. Building on this will be important to reduce the threat posed via the human vector, which unfortunately remains one of the most significant attack vectors used against the US government and its interests.
Lastly, it is recommended that a small circle of foreign allies are going to be brought into the cybersecurity program recommended here. This can be something like the five eyes cold war program, wherein the friendliest nations work with us to ensure that there are no weak links in the chain but that we are in a position to share knowledge and technology, taking advantage of each nation’s unique approaches. The threats to Western democracies are tending to come from the same rogue nations, and therefore it is possible and reasonable to leverage a higher degree of international coordination between allies to greater good, to put more resources in the hands of good people.
Conclusions
While there are certainly critiques that can be laid down at the feet of the federal government with cybersecurity policy is concerned – primarily concerned with the resources shortfalls that appear in key departments from time to time – there is little doubt that the United States has some of the most developed cybersecurity infrastructure in the world. The lead department is Homeland Security, largely through CISA, but there are key roles played by the FBI, the DoD, the Department of Energy and others. These agencies all work with the private sector to ensure that there are consistent standards for cybersecurity training, for technology, and to ensure that there is a high level of cooperation between key agencies, the private sector, other branches of government and the international community.
The holistic approach that seeks to engage whole of nation defense and responses appears to be a critical component of cybersecurity at the government level. This approach allows for the engagement of any stakeholder that has something to offer. The coordination role is then applied to DHS, which seeks to build the bridges needed to ensure that the US continues to have the most robust cybersecurity infrastructure in the world.
The US has done a high quality job, and there does appear to be awareness of the greatest opportunities for improvement that exist. If the US can continue to build on its approaches thus far, it can not only limit the number of attacks that are successful, but also build better strategies for response as well. The whole of nation approach is effective, and the right choice, and if this can be augmented by presenting a united front across the major Western democracies, all the better for everybody involved, and the overall strength of the nation’s cybersecurity defenses.
References
Bernard, A. (2020) Exploring the cutting edge of AI in cybersecurity. ZD Net. Retrieved April 12, 2020 from https://www.zdnet.com/article/exploring-the-cutting-edge-of-ai-in-cybersecurity/
Bing. C. (2017) How the FBI relies on dark web intel firms as frontline investigators. CyberScoop Retrieved April 12, 2020 from https://www.cyberscoop.com/dark-web-intelligence-fbi-investigations/
CISA.gov (2020) Cybersecurity training and exercises. Cybersecurity and Infrastructure Security Agency. Retrieved April 12, 2020 from https://www.cisa.gov/cybersecurity-training-exercises
Clement, J. (2020) Number of reported cyberattacks directed against the US government in FY 2018, by attack vector. Statista Retrieved April 12, 2020 from https://www.statista.com/statistics/697279/us-government-attacks-cyber-security-vector/
Crawford, S. (2020) Federal contractors face new cybersecurity mandates in 2020. TMC.net Retrieved April 12, 2020 from https://www.tmcnet.com/topics/articles/2020/01/07/444172-federal-contractors-face-new-cybersecurity-mandates-2020.htm
Daniel, J. (2015) Engaging the international community on cybersecurity standards. The White House. Retrieved April 12, 2020 from https://obamawhitehouse.archives.gov/blog/2015/12/23/engaging-international-community-cybersecurity-standards
DNI.gov (2019) Improving cybersecurity for the intelligence community: information environment implementation plan. DNI.gov. Retrieved April 12, 2020 from https://www.dni.gov/files/documents/CIO/Improving_Cybersecurity-IC_IE_ImpPlan-August_2019_reduced_web.pdf
DoD.gov (2018) Cybersecurity: What small businesses need to know. Department of Defense. Retrieved April 12, 2020 from https://business.defense.gov/Small-Business/Cybersecurity/
Georgetown Law Library (2020) International and foreign cyberspace law research guide. Georgetown Law Library. Retrieved April 12, 2020 from https://guides.ll.georgetown.edu/c.php?g=363530&p=4821480
Ogrysko, N. (2019) DoD unveils new cybersecurity certification model for contractors. Federal News Network. Retrieved April 12, 2020 https://federalnewsnetwork.com/defense-main/2019/09/dod-unveils-new-cybersecurity-certification-model-for-contractors/
Petraues, D. & Sridhar, K. (2018) The case for a national cybersecurity agency. Politico. Retrieved April 12, 2020 from https://www.politico.com/agenda/story/2018/09/05/cybersecurity-agency-homeland-security-000686/
Rockwell, M. (2020) Three agencies team on cyber defense of energy infrastructure. FCW Magazine. Retrieved April 12, 2020 from https://fcw.com/articles/2020/02/05/energy-dod-dhs-infrastructure.aspx
Schwartz, M. (2019) Cybersecurity drives intelligence agencies in from the cold. Bank Info Security. Retrieved April 12, 2020 from https://www.bankinfosecurity.com/blogs/cybersecurity-drives-intelligence-agencies-in-from-cold-p-2742
Thornton, D. (2019) FBI building relationships with private sector to improve cybersecurity responses. Federal News Network. Retrieved April 12, 2020 from https://federalnewsnetwork.com/all-news/2019/04/fbi-building-relationships-with-private-sector-to-improve-cybersecurity-responses/
Wysopal, C. (2018) What government organizations can learn from the private sector about cybersecurity. Forbes. Retrieved April 12, 2020 from https://www.forbes.com/sites/forbestechcouncil/2018/08/29/what-government-organizations-can-learn-from-the-private-sector-about-cybersecurity/#24b448cb2d9d
Create your account
Always verify citation format against your institution’s current style guide requirements.