Cybersecurity

White House: No 'red lines' in responding to cyber threats

Image from Shutterstock.

Top White House cybersecurity adviser Michael Daniel said he is looking for a "flexible response with no necessarily pre-defined red lines" in countering cyber threats that he said are steadily besieging U.S. computer networks.

"We want to keep our options open," Daniel said April 2 at a conference hosted by AFCEA’s Washington, D.C., chapter. "We don't want to define thresholds and tell the bad guys exactly how far they can go before we will respond."

When asked whether the administration's recent cyber policies covered offensive operations, Daniel deflected the question and said the administration was committed to network defense.

Offensive cyber operations are a sensitive subject for an administration trying to build international norms that discourage cyberattacks. Yet U.S. Cyber Command's mandate includes offensive operations and its commander, Adm. Michael Rogers, told Congress last month that the government must "think about how can we increase our capacity on the offensive side."

The administration's latest tool for combatting cyber threats is an April 1 executive order enabling sanctions on foreign perpetrators of "significant, malicious" cyber activities. Some have questioned the order's inclusion of distributed denial-of-service attacks as potentially overly broad, given the ubiquity of that intrusion technique.

Daniel sought to clarify the directive's coverage of DDOS attacks. "It's not the activity of the DDOS; it's the impact," he told reporters after his speech. "[I]f you had a DDOS that was actually sufficiently large, sufficiently well-organized to actually disrupt services, that’s what we would be talking about."

Asked whether DDOS attacks on financial institutions more than two years ago, which U.S. officials have blamed on Iran, would have triggered sanctions under the order, Daniel declined to speculate, but said: "That is certainly the class of scale that we are talking about."

The new sanctions tool could work in tandem with a nascent agency the administration created in February to fuse cyber threat intelligence. The Cyber Threat Intelligence Integration Center, to be set up in the Office of the Director of National Intelligence, could strengthen the sanctions tool by feeding intelligence to policymakers to attribute cyberattacks to specific foreign actors. Daniel said he expects the center to be operating within the next few months.

The cyber "czar" ended his speech with a warning: While cyberspace has been a "strategic asset" for the country over the last half century, without strong action to defend computer networks, "we risk cyberspace becoming a strategic liability toward the United States." 

About the Author

Sean Lyngaas is an FCW staff writer covering defense, cybersecurity and intelligence issues. Prior to joining FCW, he was a reporter and editor at Smart Grid Today, where he covered everything from cyber vulnerabilities in the U.S. electric grid to the national energy policies of Britain and Mexico. His reporting on a range of global issues has appeared in publications such as The Atlantic, The Economist, The Washington Diplomat and The Washington Post.

Lyngaas is an active member of the National Press Club, where he served as chairman of the Young Members Committee. He earned his M.A. in international affairs from The Fletcher School of Law and Diplomacy at Tufts University, and his B.A. in public policy from Duke University.

Click here for previous articles by Lyngaas, or connect with him on Twitter: @snlyngaas.


Featured

  • Telecommunications
    Stock photo ID: 658810513 By asharkyu

    GSA extends EIS deadline to 2023

    Agencies are getting up to three more years on existing telecom contracts before having to shift to the $50 billion Enterprise Infrastructure Solutions vehicle.

  • Workforce
    Shutterstock image ID: 569172169 By Zenzen

    OMB looks to retrain feds to fill cyber needs

    The federal government is taking steps to fill high-demand, skills-gap positions in tech by retraining employees already working within agencies without a cyber or IT background.

  • Acquisition
    GSA Headquarters (Photo by Rena Schild/Shutterstock)

    GSA to consolidate multiple award schedules

    The General Services Administration plans to consolidate dozens of its buying schedules across product areas including IT and services to reduce duplication.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.