Showing posts with label Cyber Sanctions. Show all posts
Showing posts with label Cyber Sanctions. Show all posts

Thursday, March 21, 2019

HR 1493 Introduced – Cyber Sanctions


Earlier this month Rep. Yoho (R,FL) introduced HR 1493, the Cyber Deterrence and Response Act of 2019. The bill is very similar to S 602 introduced last month in the Senate and less similar to HR 5567 introduced last session by Yoho; which was passed by the House, but not taken up by the Senate.

Differences


This bill contains the same additions to HR 5567 that I mentioned were seen in S 602. The Senate bill did contain a reference {§3(d)(2)(D)} to Export Control Reform Act of 2018 {50 USC 4813(a)(1))} that could not have been included in HR 5567 since the Act had not been passed when the bill was introduced. That reference is not included in this bill. This means that any successor munitions control list created in accordance with §4813 provisions would not automatically be included in the sanctions applicable under this bill.

Paragraph (f) from S 602 that provided for the applicability of penalties under the Emergency Economic Powers Act {50 USC 1705(b) and (c)} to violations of §3(b)(2)(H) of this bill was not included in S 602. This may be because Yoho’s staff considered those provisions to be included by reference in §3(b)(2)(H). Or, it may just have been an oversight.

Moving Forward


As with last year with HR 5567, Yoho and his cosponsors are influential, bipartisan members of the committees to which this bill was assigned for consideration. Last session this influence was enough to ensure consideration in a Republican controlled House, both in the Foreign Affairs Committee and on the floor of the House. In both places it received strong bipartisan support.

Similar bipartisan support would be expected this year, but it remains to be seen if the priorities of the Democratic leadership will allow for the same consideration of this bill.

Commentary


I still have the same problems with this bill that I had with S 602; the lack of definition of the term ‘cyber activities’ that could trigger the designation of ‘a critical cyber threat’. While I understand that a certain amount of latitude should be allowed for in that definition as cyber technologies and attack methodologies evolve, but I do think that a definition is required to constrain actions of the President.

Having said that, it is probably incumbent upon me to provide a suggested definition. I would suggest the following changes to the definition of ‘state sponsored cyber activities’:

“The term ‘‘state-sponsored cyber activities’’ means any malicious cyber-enabled activities incident (as defined in 6 USC 659(a) [proposed here]) that directly affected government information systems, a critical infrastructure information system or a control system that affected public safety and was caused by  
“(A) are carried out by a government of a foreign state or an agency or instrumentality of a foreign state; or
“(B) are carried out by a foreign person that is aided, abetted, or directed by a government of a foreign state or an agency or instrumentality of a foreign state.

Monday, March 18, 2019

S 602 Introduced – Cyber Sanctions


Last month Sen. Gardner (R,CO) introduced S 602, the Cyber Deterrence and Response Act of 2019. The bill would require the President to identify foreign persons or agencies of a foreign state that are ‘critical cyber threats’ and impose sanctions on such persons or agencies. The bill is very similar to S 3378 that was introduced by Gardner during the 115th Congress; no action was taken on that bill.

Differences


This new version of the bill makes a large number of relatively minor wording and phrasing changes that would be of interest only to an English teacher. There are, however, two sanction additions found in S 602:

• Allows for the withdrawal, limitation, or suspension of non-humanitarian development assistance from the United States to the foreign state under chapter 1 of part I of the Foreign Assistance Act of 1961 {§3(b)(2)(B)}; and
Allows the President to direct Overseas Private Investment Corporation, the United States International Development Finance Corporation, or any other Federal agency not to provide assistance to a designated critical cyber threat {§3(b)(2)(D)};

Additionally, there are two procedural measures added in the latest version of the proposed bill:

• Instead of publishing a notice in the Federal Register listing the designation of a critical cyber threat, S 602 requires a report to Congress {§3(a)(2)}; and
• Spells out actions that President should take to coordinate sanctions with allies and partners of the United States {§3(g)(2)}.

Moving Forward


Both Gardner and his cosponsor {Sen. Coons (D,DE)} are influential members of the Senate Foreign Affairs Committee, the Committee to which this bill was assigned for consideration. One would normally expect that this would mean that the bill could be expected to be considered in Committee. Last session, S 3378 did not see the light of day after introduction. This may mean that the bill will face a similar fate in this session.

Commentary


The most critical definition in this bill is for the term ‘state-sponsored cyber-activities’ since this is the key to determining whether a person or agency should be designated ‘a critical cyber threat’. Unfortunately, that term ‘state-sponsored cyber-activities’ is essentially defined as a cyber-activity that is state-sponsored. No attempt was made to establish a definition of ‘cyber-activity’.

Tuesday, August 28, 2018

S 3378 Introduced – Cyber Sanctions


Last week Sen. Gardner (R,CO) introduced S 3378, the Cyber Deterrence and Response Act of 2018. This bill is very similar to HR 5576 which was introduced in the House in May; no action has taken place on that bill.

Deletions


Most of the changes are grammatical or structural and are of little interest anyone but legal scholars. There are, however, some significant provisions from HR 5576 that did not make it into this bill.

The last two sub-paragraphs from §3(a)(1) did not make it into the senate bill. They allowed the President to take action against governments or persons that attempted to engage in any of the sanctioned activities listed in the bill.

The Senate bill does not include some of the sanctions provided in the House bill. These include prohibiting:

• Non-humanitarian United States development assistance under chapter 1 of part I of the Foreign Assistance Act of 1961 {§3(b)(2)(A)};
• Approval of the issuance of any guarantees, insurance, extensions of credit, or participations in the extension of credit {§3(b)(2)(D)};
• Transactions in foreign exchange that are subject to the jurisdiction of the United States and in which the government of the foreign state has any interest {§3(d)(2)(E)}; and
Transfers of credit or payments between one or more financial institutions or by, through, or to any financial institution, to the extent that such transfers or payments are subject to the jurisdiction of the United States {§3(d)(2)(F)};

The Senate bill also removes the limited Congressional oversight provision of initial briefing to Congress required by §3(f) in the House bill.

Moving Forward


Both Gardner and his single cosponsor {Sen. Coons (D,DE)} are members of the Senate Foreign Relations Committee to which this bill was referred for consideration. Gardner is a sub-committee chair so he should have enough influence to see this bill considered in Committee. However, seeing the lack of action in the House, I suspect that the chances for this bill being considered during this session are rather remote.

Friday, August 24, 2018

Bills Introduced – 08-23-18


Yesterday with just the Senate in session there were 22 bills introduced. Of those one may be of specific interest to readers of this blog:

S 3378 A bill to impose sanctions with respect to state-sponsored cyber activities against the United States, and for other purposes. Sen. Gardner, Cory [R-CO]

I will be watching this bill for language specifically identifying industrial control system issues.

Tuesday, May 8, 2018

HR 5576 Introduced – Cyber Sanctions


Last month Rep. Yoho (R,FL) introduced HR 5567, the Cyber Deterrence and Response Act of 2018. The bill would require the President to identify foreign persons or agencies of a foreign state that are ‘critical cyber threats’ and impose sanctions on such persons or agencies.

Definitions


Section 3(g) of the bill provides a lengthy list of definitions of terms used in the bill. The only ‘cyber’ related definition in that list is “state sponsored cyber activities”. That is defined as any cyber-enabled activities that are carried out by an agency or instrumentality of a foreign state; or are carried out by a foreign person that is aided, abetted, or directed by a foreign state or an agency or instrumentality of a foreign state {§3(g)(9)}.

That definition is expanded in §3(a)(1)(A) by a listing of the types of cyber activities “that are reasonably likely to result in, or have contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States”. They would include events that have the purpose or effect of:

• Causing a significant disruption to the availability of a computer or network of computers;
• Harming, or otherwise significantly compromising the provision of service by, a computer or network of computers that support one or more entities in a critical infrastructure sector;
• Significantly compromising the provision of services by one or more entities in a critical infrastructure sector;
• Causing a significant misappropriation of funds or economic resources, trade secrets, personal identifiers, or financial information for commercial or competitive advantage or private financial gain;
• Destabilizing the financial sector of the United States by tampering with, altering, or causing a misappropriation of data; or
Interfering with or undermining election processes or institutions by tampering with, altering, or causing misappropriation of data.

Sanctions


The President would then be required to impose one or more sanctions from of a lengthy list of travel and non-travel related sanctions on the designated critical cyber threats. The President is allowed to waive the imposition of sanctions if it is certified to Congress that one or more of the following requirements has been met {§3(e)(2)}:

• The waiver is important to the economic or national security interests of the United States.
• The waiver will further the enforcement of this Act or is for an important law enforcement purpose.
• The waiver is for an important humanitarian purpose.

Moving Forward


Yoho is a member of the House Foreign Affairs Committee, one of the four committees to which this bill was assigned for consideration. Cosponsors that are also members of that Committee include:

• Rep. Sherman (D,CA);
• Rep. Royce (R,CA);
• Rep. Engle (D,NY);
• Rep. Chabot (R,OH) (Chair of the Judiciary Committee to which the bill was also assigned);
• Rep. Poe (R,TX);
• Rep. Fitzpatrick (R,PA);
• Rep. Meadows (R,NC) (also on Oversight and Government Reform Committee to which this bill was also assigned);
• Rep. Castro (D,TX); and
• Rep. Lieu (D,CA)

This would seem to indicate that there is a good possibility that the Foreign Affairs Committee, which would be the primary committee of jurisdiction for this bill, will consider the bill. The bill would certainly garner bipartisan support within the Committee and probably before the full House.

Commentary


In many ways this bill can be seen as an expansion of HR 3364, the Countering America’s Adversaries Through Sanctions Act, which passed in both the House and Senate and was ultimately signed by President Trump (PL 115-44, not yet published by GAO). That earlier bill was targeted at cyber operations by three countries; Russia, Iran and North Korea and in many ways codified the provisions of EO 13694. This bill would expand the countries and agencies to which the President could apply sanctions.

The lack of technical definitions in this bill or such terms as ‘computer or network of computers’ or ‘compromising the provisions of service’ is a two-edged sword. A broad interpretation by the President would certainly allow attacks against industrial control systems to be covered by the sanctions requirements of the bill. A narrow interpretation, on the other-hand would allow the President to ignore such attacks with impunity.

This bill has the same deficiency that I noted in my post on the introduction of HR 3364, there are no provisions for moving beyond sanctions or even requiring the President to report on the success of sanctions in preventing additional adverse ‘cyber activities’ by the sanctioned parties. This is a common failing with sanctions legislation. This allows Congress to show that they have ‘taken action’ to prevent cyber attacks (in this case) without ever having to consider the efficacy of those actions.

The bill needs some sort of reporting requirement to ensure that reports on the efficacy of the sanctions are made to Congress. Additionally, there needs to be some sort of escalatory language for subsequent adverse cyber activities by sanctioned parties. At the very least, the President should be required to impose additional sanctions beyond the minimum required (1 of the listed sanctions) in this bill.

One other problem needs to be addressed by this bill. This bill limits the sanction authority to only “state sponsored cyber activities”. The increasing cyber sophistication of non-state actors such as international terrorist or transnational criminal organizations means that these types of groups are becoming a threat to our increasingly cyber-centric society. Adding those organizations to the coverage of this bill would provide the President with additional tools to deal with those emerging threats.

Friday, July 28, 2017

Senate Passes HR 3364 – Cyber Sanctions

Yesterday the Senate passed HR 3364, the Countering America’s Adversaries Through Sanctions Act by a vote of 98 to 2 (page S 4387). While the bill is generally addressed at Russia, Iran and Korea, it does contain specific sanction requirements based upon reported Russian cyber-attacks.

There has not yet been an official statement from the White House as to whether or not the President will sign or veto the legislation. There were, however, certainly sufficient votes in both the House and Senate to overturn any presidential veto.


As I mentioned in my earlier post, even if/when the bill becomes law there are sufficient provisions in the bill to allow the President to avoid placing any sanctions on the Russian Federation if he so desires.

Thursday, July 27, 2017

HR 3364 Introduced – Foreign Sanctions

Earlier this week Rep. Royce (R,CA) introduced HR 3364, the Countering America’s Adversaries Through Sanctions Act. The bill provides for a variety of sanctions in response to actions taken (and future actions that may be taken) by Russia, Iran and North Korea. The bill specifically includes sanctions to be taken against Russia for cybersecurity related actions. These actions are outlined in:

§222. Codification of sanctions relating to the Russian Federation.
§224. Imposition of sanctions with respect to activities of the Russian Federation undermining cybersecurity.
§235. Sanctions described.

Imposing Sanctions


Section 222 of the bill continues in effect existing cybersecurity related sanctions under EO 13694 “relating to blocking the property of certain persons engaging in significant malicious cyber enabled activities), and Executive Order 13757” {§222(a)}.

Section 224 of the bill requires the President to impose sanctions upon any person the President determines that {§224(a)(1)}:

• Knowingly engages in significant activities undermining cybersecurity against any person, including a democratic institution, or government on behalf of the Government of the Russian Federation; or
• Is owned or controlled by, or acts or purports to act for or on behalf of, directly or indirectly, a person described above.

The required sanctions include {§224(b)}:

• Asset blocking;
• Exclusion from the united states and revocation of visa or other documentation;

Additionally, the President is directed to {§224(a)(2)}:

• Impose 5 or more of the sanctions described in §235 with respect to any person that the President determines knowingly materially assists, sponsors, or provides financial, material, or technological support for, or goods or services (except financial services) in support of, a cybersecurity activity described above; and
• Impose 3 or more of the sanctions described in 22 USC 8923(c) with respect to any person that the President determines knowingly provides financial services in support of a cybersecurity activity described above.

The “significant activities undermining cybersecurity” mentioned in this section include significant efforts to {§224(d)}:

• To deny access to or degrade, disrupt, or destroy an information and communications technology system or network; or
• To exfiltrate, degrade, corrupt, destroy, or release information from such a system or network without authorization for purposes of:
Conducting influence operations; or
Causing a significant misappropriation of funds, economic resources, trade secrets, personal identifications, or financial information for commercial or competitive advantage or private financial gain;
• Significant destructive malware attacks; and
• Significant denial of service activities.

New Sanctions


Section 235 of the bill describes a new set of sanctions available to the President for imposition in response to significant activities undermining cybersecurity and other non-cybersecurity regimes described in the bill. Those sanctions include {§235(a)}:

• Export-import bank assistance for exports to sanctioned persons;
• Export sanction;
• Loans from united states financial institutions;
• Loans from international financial institutions;
• Prohibitions on financial institutions;
• Procurement sanction;
• Foreign exchange;
• Banking transactions;
• Property transactions;
• Ban on investment in equity or debt of sanctioned person;
• Exclusion of corporate officers;
• Sanctions on principal executive officers.

Moving Forward


As I mentioned earlier this week, this bill passed in the House on Tuesday with a strongly bipartisan vote. I suspect that it will be taken up quickly in the Senate where it will pass with broad support (possibly under the unanimous consent process).

I have seen one report that the President may veto the bill if/when it gets to his desk. If the vote in the House is any indicator of support in the Senate (and that is never a perfect predictor) then there are probably more than enough votes available to override any veto on this bill.

Commentary


One of the reasons that this bill is getting bipartisan support is that it provides Democrats an apparent opportunity to hold the President’s feet to the political fire with regards to cyber operations by Russia. While the bill does require the President to impose sanctions, there are two necessary weasel word provisions that provide potential escape hatches.

First the bill only requires the President to impose sanctions when he “determines” that the sanctioned activity has taken place. Given Trump’s public statements about the inability to really know who is responsible for cyber activities (a statement with which, to some extent at least, many cyber professionals would agree), this may be a very substantial loop hole.

The second is a very real recognition of the President’s prerogatives with respect to foreign affairs and national defense. In every instant where the bill requires the President to impose sanctions it specifically provides the President to avoid that requirement by certifying to Congress that an exception is needed due to ‘vital national security interests of the United States’ or that failure to impose sanctions will further enforcement of the provisions of this bill. Interestingly, the crafters of this bill added an additional requirement to these certifications; the President also has to certify that the “that the Government of the Russian Federation has made significant efforts to reduce the number and intensity of cyber intrusions conducted by that Government” {§224(c)(2) for example}.

Neither of these necessary loopholes detracts from the seriousness of the provisions of this bill. While economic sanctions like those outlined in this bill do not have a strong history of success, they are a necessary step to notify opponents (like Russia, Iran and North Korea) that their actions have consequences without the necessity of employing physical (military) or (increasingly more likely) cyber force to get the opponent to modify their behavior.


What might have made this bill more effective in countering the explicated actions of these three adversaries would have been included some sort of reference to possible future application of more expansive responses. It would have been easy to add a requirement for the President to report on the effectiveness of the required sanctions 18 months after they were applied along with a recommendation to Congress as to what escalative measures, up to and including military force if necessary, may be required to stop the sanctioned behavior.

Tuesday, July 25, 2017

House Passes HR 3364 – Cyber Sanctions

Today the House passed HR 3364, the Countering America’s Adversaries Through Sanctions Act by a nearly unanimous vote of 419 to 3. The bill includes provisions requiring the President to enforce various economic sanctions against anyone in Russia whom the President determines “knowingly engages in significant activities undermining cybersecurity against any person, including a democratic institution, or government on behalf of the Government of the Russian Federation” {§224(a)(1)(A)}.


I’ll be doing a more thorough review of this bill in the near future.

Thursday, January 5, 2017

BIS Extends Russian Cyber Sanctions

Yesterday the DOC’s Bureau of Industry and Security (BIS) published a final rule in the Federal Register (82 FR 722-725) adding the five organizations identified in the President’s recent amendment of EO 13694 to the Entity List of the Export Administration Regulations (EAR). This rule “imposes on these entities a license requirement for exports, reexports, or transfers (in-country) of all items subject to the EAR and a license review policy of presumption of denial”.


There were some comments made about the EO 13694 actions having little impact on the identified personnel and organizations because they were unlikely to have any assets in the US that could be frozen. This action by the BIS could potentially have more practical effects because it would affect third party vendors dealing with the organizations if they were attempting to sell US sourced items covered by the EAR to those organizations.

Friday, May 13, 2016

Bills Introduced – 05-12-16

With both the House and Senate in session yesterday there were a total of 37 bills introduced. Of those four may be of specific interest to readers of this blog:

HR 5205 To require ingredient labeling of certain consumer cleaning products, and for other purposes. Rep. Israel, Steve [D-NY-3]

HR 5220 To direct the President to develop a policy on when an action in cyberspace constitutes a use of force against the United States, and for other purposes. Rep. Himes, James A. [D-CT-4] 

HR 5222 To impose sanctions with respect to persons responsible for knowingly engaging in significant activities undermining cybersecurity on behalf of or at the direction of the Government of Iran, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

H Res 727 Supporting the Commission on Enhancing National Cybersecurity. Rep. Langevin, James R. [D-RI-2]

It will be interesting to see what chemical safety information is going to be required by HR 5205. I would hope to see information on hazardous chemical reactions from mixing different cleaning products.

It will be interesting to see if HR 5220 is a companion bill to S 2905 that was introduced earlier this week. Still waiting on that language to be published.

According to a Ratcliffe press release this is almost identical to S 2756 that was introduced last month. It will be interesting to see if that ‘almost’ is due to cleaning up some of the problems with that bill.


I don’t normally cover ‘supporting’ resolutions, but since this one says ‘cybersecurity’ in the title I will mention it. I have actually read it and I doubt that I’ll mention it again.

Thursday, April 7, 2016

Bills Introduced – 04-06-16

With just the Senate in session there were 10 bills introduced yesterday. Of those only one may be of specific interest to readers of this blog:

S 2765 A bill to impose sanctions with respect to Iranian persons responsible for knowingly engaging in significant activities undermining cybersecurity, and for other purposes. Sen. Rounds, Mike [R-SD]

This sounds like a reaction to the recent federal indictment of the hackers who allegedly ‘breached’ the control system of a small dam in in New York. If that is the target, the bill will serve little purpose since such folks are unlikely to have actionable assets outside of Iran. Having said that, Rounds is a member of the Senate Banking, Housing and Urban Affairs Committee which has jurisdiction over sanctions bills like this, so we may have to take this seriously.


As a side note the government already has the ability to apply sanctions to cyber attackers like this under EO 13694 that was recently renewed. See my closing comment in that blog post.

Wednesday, April 1, 2015

Retaliation for Cyber Attacks; A new Executive Order

Today President Barack Obama signed his latest executive order on cybersecurity issues; this time outlining at least one method by which the Administration intends to respond to significant cyber attacks. This executive order (the number will be made available when the order is officially published in the Federal Register on Friday or Monday) is entitled: “Blocking the Property of Certain Persons Engaging in Significant Malicious Cyber-Enabled Activities”.

Declaration of National Emergency

This Executive Order is an exercise of presidential authority granted under 50 USC 1701. That authorizes the President to react to a declared national emergency. The preamble to this Executive Order is a declaration that “the increasing prevalence and severity of malicious cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States constitute an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States”. While not as expansive as many other declarations, this should satisfy the requirements of §1701.

Authorization for use of Economic Sanctions

In this exercise of presidential authority the president is allowed {§1702(a)} to investigate, regulate or prohibit:

∙ Any transactions in foreign exchange;
∙ Transfers of credit or payments between, by, through, or to any banking institution, to the extent that such transfers or payments involve any interest of any foreign country or a national thereof; and
∙ The importation or exportation of currency or securities.

This authorization extends to any person or property subject to the jurisdiction of the United States.

Defining the People Affected

The EO provides a fairly comprehensive description of the people and organizations that will be affected by these sanctions. Section 1 of the EO provides that the Secretary of the Treasury is responsible for identifying people that are “responsible for or complicit in, or to have engaged in, directly or indirectly, cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States”.

The activities are further described as being “reasonably likely to result in, or have materially contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States”. Specifically identified are activities that {§1(a)(i)}:

∙ Harm, or otherwise significantly compromise the provision of services by, a computer or network of computers that support one or more entities in a critical infrastructure sector;
∙ Significantly compromise the provision of services by one or more entities in a critical infrastructure sector;
∙ Cause a significant disruption to the availability of a computer or network of computers; or
∙ Cause a significant misappropriation of funds or economic resources, trade secrets, personal identifiers, or financial information for commercial or competitive advantage or private financial gain.

Additionally, the President intends to take action against anyone that {§1(a)(i)}:

∙ Receives or uses for commercial or competitive advantage or private financial gain, or by a commercial entity, outside the United States of trade secrets misappropriated through cyber-enabled means;
∙ Has materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services in support of, any activity described in this order;
∙ Is owned or controlled by, or to have acted or purported to act for or on behalf of, directly or indirectly, any person whose property and interests in property are blocked pursuant to this order; or
∙ Has attempted to engage in any of the activities described in this order.

Maximizing the Sanctions

Normally 50 USC 1702 prohibits sanctions from affecting “donations, by persons subject to the jurisdiction of the United States, of articles, such as food, clothing, and medicine, intended to be used to relieve human suffering” {§1702(b)(2)}. The President, however, evoked the exception to that rule by declaring {§2} that allowing those types of donations “would seriously impair my ability to deal with the national emergency declared in this order”. Thus, strictly humanitarian may also be restricted from being provided to the persons or organizations identified by the Secretary of the Treasury.

Additionally, the President has opted to {§4} “suspend entry into the United States, as immigrants or nonimmigrants” for any of the people designated by the Secretary.

The remainder of the EO is essentially housekeeping; providing authorization for various federal agencies to undertake the necessary work to make this order effective.

Commentary

This EO is largely targeted at economically inspired cyber-attacks on the United States. This was at least partially clarified by Lisa Monaco, the chief counterterrorism advisor to the President; who said in a National Security Council blog post today:

Malicious cyber activity — whether it be stealing sensitive information, including personal identifiers, or trade secrets — is often profit-motivated. Because those responsible want to enjoy the ill-gotten proceeds of their activities, sanctions can have a significant impact. By freezing assets of those subject to sanctions and making it more difficult for them to do business with U.S. entities, we can remove a powerful economic motivation for committing these acts in the first place. With this new tool, malicious cyber actors who would target our critical infrastructure or seek to take down Internet services would be subject to these costs when designated for sanctions.

These types of tools have not been enormously successful in countering drug cartels, for instance. And their utility against foreign governments has been almost completely inconsequential (except for the residents of those nations). It is hard to understand how anyone expects this to have any serious consequence in reducing, much less stopping foreign based cyber-attacks against this country.


It does provide the government with the ability to ‘take action’ short of direct counter-attacks by cyber, cyber-physical or conventional military forces. The fact that this action can be corrected in kind if the attribution about the source of the original attack turns out to be mistaken will allow actions to be taken with less thought of consequences of mis-attribution. To that extent this is probably a good (if ineffective) tool to have available; it will allow for political cover while further investigation takes place.
 
/* Use this with templates/template-twocol.html */