Showing posts with label Cyberwar. Show all posts
Showing posts with label Cyberwar. Show all posts

Tuesday, May 17, 2016

HR 5220 Introduced – Cyberwar

Last week Rep. Himes (D,CT) introduced HR 5220, the Cyber Act of War Act of 2016. This bill is very similar to S 2905 that was introduced earlier last week. A minor wording difference could result in significantly different consequences.

Differences


The only significant difference between the two bills is found in four words in §2(a)(1). The Senate bill requires the President to develop a policy for “determining when an action carried out in cyberspace constitutes an act of war against the United States”. The House version substitutes ‘a use of force’ for the words ‘an act of war’. The House version allows the US government much more leeway in how it would be expected to reply to the base cyberspace action by an adversary.

Moving Forward


Neither Himes, or his co-sponsor {Rep. Westmorland, (R,GA)} is a member of either the House Foreign Affairs Committee or the Armed Services Committee. Thus it is unlikely that either committee will take up consideration of the bill.

The House version of this bill would be more likely to be passed by Congress because it provides much more leeway in the expected response to serious cyber attacks. It is, however, unlikely that the bill would ever make it to a committee vote, much less a vote before either body.

Commentary


This version of the bill is a much less strident political message and seems to be less of an attempt to specifically make President Obama look bad. It appears to be a more reasonable attempt to address the place of cyber-attacks on the homeland within the conventional force response playbook of the United States military. The inclusion of the Armed Services Committee in the list of considering committees reflects this fact.


Still this bill is unnecessary as the current version of the Law of War Manual already adequately addresses this policy issue.

Saturday, May 14, 2016

S 2905 Introduced – Cyberwar

Earlier this week Sen. Rounds (R,SD) introduced S 2905, the Cyber Act of War Act of 2016. The bill would require the development of a policy describing when an action in cyberspace constituted an act of war.

Policy Requirement


Section 2 of the bill would require the President to {§2(a)}:

• Develop a policy for determining when an action carried out in cyberspace constitutes an act of war against the United States; and
• Revise the Department of Defense Law of War Manual accordingly.

Moving Forward


Rounds is not a member of the Senate Foreign Relations Committee, the committee to which this bill was referred for consideration, so he is unlikely to have adequate influence to get the bill considered by that Committee.

The bill is written broadly enough that there really is nothing in the bill that should drive any significant objections to the bill. It would seem that the easiest way for this bill to be considered would be to include the bill as an amendment to either an appropriations or authorization bill.

Commentary


What constitutes an ‘act of war’ is an inherently political decision. Such a decision would be based on a totality of circumstances rather than a characteristic action. This may be why the current Law of War Manual does not include a discussion of what constitutes an ‘act of war’ nor does it actually mention the term ‘act of war’.

Drawing lines in the sand, and defining what constitutes an ‘act of war’ is probably the ultimate line in the sand, sets up an administration for all sorts of potential problems. It provides an adversary with an artificial construct that says that you can push to this line without risking a military response. This could actively encourage an adversary wishing to embarrass the United States to take actions just short of the ‘act of war’ standards to prove that it can act with impunity.

Similarly, a creative adversary could press pass the limits of the definition of an ‘act of war’, but do so in a manner that would make a military response incompatible with other US foreign or domestic policy. These types of actions would be similar to the continued use of chemical weapons by Syrian forces after the President drew a line in the sand about the continued use of chemical weapons, or the North Korean’s ignoring of international sanctions in its testing of nuclear weapons and long-range delivery means.


In this case it would appear that Rounds is deliberately trying to force the President to draw a line in the sand that would either force a military reaction against your cyber opponent of choice (Iran, North Korea, ISIS, China, Russia and so on) or embarrass the current administration by failing to react to an ‘act of war’. I say this because the 2015 version of the DOD Law of Warfare Manual already includes a relatively comprehensive discussion of how cyber operations relate to the law of warfare. A careful reading of Chapter 16 provides more than enough guidance on how to determine when an offensive cyber operation is the equivalent to a more conventional military operation.

Friday, May 13, 2016

Bills Introduced – 05-12-16

With both the House and Senate in session yesterday there were a total of 37 bills introduced. Of those four may be of specific interest to readers of this blog:

HR 5205 To require ingredient labeling of certain consumer cleaning products, and for other purposes. Rep. Israel, Steve [D-NY-3]

HR 5220 To direct the President to develop a policy on when an action in cyberspace constitutes a use of force against the United States, and for other purposes. Rep. Himes, James A. [D-CT-4] 

HR 5222 To impose sanctions with respect to persons responsible for knowingly engaging in significant activities undermining cybersecurity on behalf of or at the direction of the Government of Iran, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

H Res 727 Supporting the Commission on Enhancing National Cybersecurity. Rep. Langevin, James R. [D-RI-2]

It will be interesting to see what chemical safety information is going to be required by HR 5205. I would hope to see information on hazardous chemical reactions from mixing different cleaning products.

It will be interesting to see if HR 5220 is a companion bill to S 2905 that was introduced earlier this week. Still waiting on that language to be published.

According to a Ratcliffe press release this is almost identical to S 2756 that was introduced last month. It will be interesting to see if that ‘almost’ is due to cleaning up some of the problems with that bill.


I don’t normally cover ‘supporting’ resolutions, but since this one says ‘cybersecurity’ in the title I will mention it. I have actually read it and I doubt that I’ll mention it again.

Tuesday, May 10, 2016

Bills Introduced – 05-09-16

With just the Senate in session, the House returns today, there were a dozen bills introduced yesterday. Of those one may be of specific interest to readers of this blog:

S 2905 A bill to require the President to develop a policy for determining when an action carried out in cyberspace constitutes an act of war against the United States, and for other purposes. Sen. Rounds, Mike [R-SD]


This bill is almost certainly political grandstanding, but it is does have potentially serious cybersecurity implications if it does move forward. It will be interesting to see how the bill is actually worded.
 
/* Use this with templates/template-twocol.html */