Answer questions in paragraphs
–––––––––––––––— Summary of a Roundtable Discussion (November 2014)
Cybersecurity, Sovereignty, and U.S. Foreign Policy
Camino Kavanagh
ABSTRACT In the 1990s, many premised that the advent of the information
age would lead to the demise of the nation-state through the erosion of state
power and, as a result, state sovereignty. Moreover, the Internet and a space
many today call ‘‘cyber’’ would enable the emergence of the sovereign
citizen, free of the political, economic, and security demands of the
all-powerful state. Yet, such predictions not only did not transpire—they
became the poster child of the old adage ‘‘be careful what you wish for’’ in
today’s age of global terrorism and sophisticated organized criminal activity.
Certainly cyberspace has empowered individuals around the world, for both
good and bad. Yet, it has also given states a new domain or environment in
which to expand their power and in which to compete with one another.
State sovereignty, while far from undermined, today boasts a more porous
character reminiscent of the eighteenth and nineteenth centuries, when
states were certainly the most powerful actors on the international stage
but not the only actors with influence. Through its three core sessions, the
2014 Roundtable explores many of these dynamics and interplays, highlight-
ing pending policy dilemmas or putting forward a series of recommendations
about the future direction of U.S. foreign policy and strategy in this area.
KEYWORDS cybersecurity; information age; information warfare; Internet;
sovereignty; U.S. foreign policy; United States
INTRODUCTION
Camino Kavanagh and John B. Sheldon
The topic of this year’s cybersecurity Roundtable meeting was
‘‘Cybersecurity, Sovereignty and U.S. Foreign Policy.’’ It was held in tandem
with the publication of a series of articles on the same topic in the National
Committee’s journal, American Foreign Policy Interests.
Why, might you ask, the focus on Cybersecurity, Sovereignty, and
U.S. Foreign Policy? In the 1990s, many premised that the advent of the
Camino Kavanagh is a senior advisor and consultant for a number of organizations, including the ICT4peace Foundation and the National Committee on American Foreign Policy. Camino has more than fifteen years of experience working in conflict and post-conflict settings and on issues relating to international security and development. She is currently a Ph.D. candidate at the Dept. of War Studies, King’s College London, and a senior non- resident fellow at NYU.
American Foreign Policy Interests, 37:100–112, 2015 Copyright # 2015 NCAFP ISSN: 1080-3920 print=1533-2128 online DOI: 10.1080/10803920.2015.1038930
100
information age would lead to the demise of the
nation-state through the erosion of state power
and, as a result, state sovereignty. Moreover, the
Internet and a space many today call ‘‘cyber’’ would
enable the emergence of the sovereign citizen, free
of the political, economic, and security demands of
the all-powerful state. Yet, such predictions not only
did not transpire; they became the poster child of the
old adage ‘‘be careful what you wish for’’ in today’s
age of global terrorism and sophisticated organized
criminal activity. In hindsight, the assumption that
the information age would somehow transmute the
human condition seems rather naı̈ve.
Certainly cyberspace has empowered individuals
around the world, for both good and bad. Yet, it
has also given states a new domain or environment
in which to expand their power and in which to
compete with one another. State sovereignty, while
far from undermined, today boasts a more porous
character reminiscent of the eighteenth and nine-
teenth centuries, when states were certainly the most
powerful actors on the international stage but not the
only actors with influence. As the malicious uses of
information technologies and cyberspace continues
to disrupt social and economic institutions, how
states assert their sovereignty and compete with
one another will continue to change and adapt
as will the role of individuals and private organiza-
tions and actors as they compete for space on the
international stage. Through its three core sessions,
the 2014 Roundtable explores many of these
dynamics and interplays, highlighting pending policy
dilemmas or putting forward a series of recom-
mendations about the future direction of U.S. foreign
policy and strategy in this area.
The first panel, moderated by Melissa E.
Hathaway, frames the problem through the lens of
a number of sovereign dilemmas that policymakers
face today. A core question debated during the panel
and throughout the day centered on whether the
current U.S. strategy is sufficient to handle the
multiple challenges at hand and whether the links
with broader U.S. foreign policy are tight enough.
The second panel, moderated by Rafal
Rohozinski, focused on changes in the military
affairs, questioning whether it is possible to fit
today’s cyber- and information warfare capabilities
into traditional military constructs and doctrine, and
how they these changes might affect the future
character of warfare. The use of special forces for
an ever-widening range of operations is used as a
case study, fitting into a wider debate in the U.S.
national security community about the future of
warfare and whether what we are experiencing is a
new revolution in military affairs (RMA).
Moderated by Dr. Roger Hurwitz, the third and
final panel provided an extensive overview of the
current norms environment: What norms actually
are, how they relate to cyberspace and cybersecurity,
who decides on them, how we implement them, and
so forth. Efforts by the U.S. government in this area
are showcased in this panel—as are those of acade-
mia and the private sector. The core questions raised
in the panel include how we move from the current
cacophonous normative environment to one in
which objectives and roles are more evident, and
how progress against bigger-picture foreign policy
issues can be assessed.
Finally, as with last year’s Roundtable, a recurring
theme throughout the meeting related to whether
the U.S. government and U.S. information and com-
munications technology (ICT) providers can influence
outcomes in a shifting and complex global geopoliti-
cal environment in which normative disintegration
and disengagement are increasing and in which the
United States itself has undermined some of the
normative values it is hoping to promote and project
into cyberspace and the Internet. Again this year, it
is a question that remains unanswered, but one that
requires serious deliberation.
SUMMARY OF DISCUSSIONS
Panel 1
Connected Choices: The Internet and
Sovereign Decision Making
Framing the Problem
Moderated by Melissa E. Hathaway, the panel
kicked off with an introduction to the history of the
Internet from its inception in 1969 as means of trans-
mitting data between two universities through its
strategic inflection point in the late 1980s–early
1990s with the advent of e-commerce and enhanced
military and civilian uses to today with every service
in modern societies connected to the Internet. In this
regard, increased connectivity has become part of
Volume 37, Number 2, 2015 101
the transformation or development agenda of every
country around the world. 1 In developed countries,
participation is no longer opt-in, but rather compul-
sory since almost everything we do is contingent on
connectivity (i.e., it is now the system necessary to
participate in society).
Building on an essay she wrote for NCAFP’s
journal American Foreign Policy Interests on the
same topic, 2 the moderator addressed the range of
Internet-related vulnerabilities the United States is
facing today from the perspectives of economic,
technical, regulatory, political, and social interests.
She placed these challenges within the broader
challenge of ‘‘multicultural friction’’ revolving around
the realities of digital destruction (Stuxnet 2010),
digital diplomacy and discord (WCIT, Dubai 2012),
digital defiance (Snowden revelations 2013), and digital
dependence (40 percent of the world’s population
connected to the Internet in 2014).
Homing in on the question of national sover-
eignty, panelists noted that there is a clear drive by
some states to reassert their sovereignty over many
aspects of cyberspace. Many of the issues we are
currently dealing with have direct implications
for national sovereignty, but others less so, parti-
cularly because of their transnational or universal=
transcendental character. The latter clearly include
the freedoms and rights generally associated with
the U.S. Bill of Rights, as well as open trade, com-
petition and innovation, and cybersecurity itself.
Another of the panelists insisted on the need to view
the Internet from the perspective of a multilayered
global communications network: its land and under-
sea cable networks telecommunications carriers,
the protocols and governance of domain names and
numbers, the definition of software and hardware,
and so on. The underlying infrastructure—for example,
undersea cables and their landing stations—is
particularly vulnerable. 3 Enhancing protection of
the undersea structure and reducing the time
required to repair damaged cables should thus be
major priorities.
To make sense of these intermingling ideas of
sovereignty and transnationality, one of the panelists
proposed assessing them from six different yet
interrelated perspectives: cultural sovereignty, geo-
graphic sovereignty, data sovereignty, cybersecurity,
human rights, and economic security. The issue of
data sovereignty in particular was emphasized in
light of recent efforts by some countries or regional
groupings to protect data from external surveillance
and keep citizens’ data within territorial boundaries.
Such steps, panelists surmised, would have serious
implications for current trends in data storage and
for international commerce in general. 4
The fact is that we are dealing with a tremen-
dously complex system that, by definition, is unman-
ageable despite efforts to bring it under some form of
formal governance structure. Rules can indeed be
assigned to the system, but a more effective
approach would be to avoid heavy regulation. None-
theless, this very issue is driving serious competition
between states. For the moderator, the current push
and pull between states regarding cyberspace, parti-
cularly ongoing debates and processes surrounding
Internet governance, is part of a broader strategic,
multidimensional competition for money, power,
and control over all aspects of the Internet and the
Internet economy. With technological advantage at
the core of any major power’s strategic posture, she
cautioned that only those states that understand this
multifaceted environment and are willing to make
the right investment of resources and manpower will
‘‘end up on top.’’
In terms of U.S. response to these issues, the
panelists largely agreed that the current approach is
insufficient. In this regard, the United States requires
a much bolder strategy and a much bolder foreign
policy to link it to. A simple narrative defining where
we want to go and how to go about it would suffice.
At present, however, the government does not appear
to have a coherent strategy or any defined ‘‘end game’’
or vision for the Internet and cyberspace around
which the various government entities can coalesce
or around which to work with allies or like-minded
nations. This situation has only become more acute
following the Snowden revelations, exacerbating
existing tendencies to view many of these issues from
an East–West or developed versus developing nation
perspective. It is a key area of U.S. foreign policy and
thus requires serious consideration.
In response to these assertions, some participants
insisted the contrary: that the United States does
have a strategy—the 2011 U.S. International Strategy
on Cyberspace—which forms a core part of the
administration’s foreign policy and that a coherent
vision exists across sectors (for more detail, see Panel
3 below).
102 American Foreign Policy Interests
Pending Policy Issues
Moving forward, panelists and participants slated
a number of questions:
. How can current policy and strategy allay
concerns regarding the fact that the Internet is a
U.S. creation upon which the entire world is
becoming increasingly dependent, thus posing a
serious national security challenge for a number
of states, including many allies and particularly
following the Snowden revelations?
. The process whereby some states are asserting
sovereignty over the system’s infrastructure is a
natural one. Yet, what should the response be
regarding this process, particularly when it affects
content? Do we need to invigorate our current
position on these issues or review it?
. Much of the discussion on Internet governance at
present is related to the Internet as we currently
know it. Yet, it is bound to change. What might
the Internet look like in the future, for example,
some 20 years from now? And what modes of
governance or management might that future
Internet require? Also, how will future policy
and strategy consider a different geopolitical con-
text in which the United States is no longer the
preeminent world power? And is the United States
prepared for the eventuality of a new Internet
governance model emerging from ongoing
discussions within the International Telecommu-
nications Union (ITU) or other fora?
. How will the tensions and trade-offs between
security and privacy be reconciled given the
increase in terrorist and organized crime activity
on the Internet?
Panel 2
Information=Cyber Warfare and
Territorial Sovereignty: The End of
Defense?
Moderated by Rafal Rohozinski of the Canadian
group SecDev, Panel 2 focused on discussing cyber-
space and the changing character of warfare and
what this means specifically for the age-old concept
of defense, a bastion of the territorial sovereign state.
The panel discussed the challenges posed by the fact
that national defense is no longer just defense against
peer nation-states (as has been clear for more than
two decades now) and that defense does not begin
or end with national borders. The Islamic State
(IS)’s use of social media for global recruitment,
financing, and command and control purposes is a
case in point. That the group is openly using social
media for these purposes poses huge challenges to
national security agencies and private tech compa-
nies at a time when the debate on National Security
Agency (NSA) powers vis-à-vis privacy rights is at
an all-time high. What remains unclear is how these
tensions between security, defense, and privacy will
be resolved.
Special Operations Forces: What Shoe
Do They Fit?
In addition, the moderator and panelists discussed
new trends in cyber- and information warfare, ques-
tioning whether the current emphasis on reaching
agreement on norms to shape state behavior and as
a means to achieve stability in cyberspace is suited
to the actual operational environment. According to
the panelists, these kinds of norm-setting efforts have
rarely taken into consideration the fact that today
most conflicts, which increasingly involve the use
of cyber-capabilities (i.e., weaponized code), or
information warfare are seldom declared and that
the use of force (still largely undefined in this area)
occurs under a number of executive titles and
authorities and is increasingly implemented by
special forces.
For example, the panel discussed how recent
events in Ukraine and elsewhere demonstrate how
tactical uses of cyber-=information warfare (IW) capa-
bilities are critical to special force operations—and
not just those of the United States. 5 In this regard,
even what might be viewed as traditional intelligence
operations implemented under intelligence authorities
look more like special forces operations, with
Operation Olympic Games (more commonly known
as Stuxnet) being a possible case in point. Arguably,
cyber-capabilities and special operations forces go
hand in hand—many of the requisites of special
forces operations, such as speed, agility, stealth,
force of action, 6 are dependent on an operating
environment where intelligence is paramount and
operations security must be preserved. Therefore,
understanding cyberspace and the multifold uses of
Volume 37, Number 2, 2015 103
ICTs is key for the intelligence preparation of the
operational battle space. It is also key for targeting
purposes, for operations security, 7 and for achieving
the shaping effects required both for the insertion of
special forces and the successful implementation of
operations. In this sense, perhaps it would be more
useful to view cyber-capabilities more as ‘‘employ-
able capabilities’’ within the framework of special
forces operations rather than how we have been
framing them to date (i.e., as a strategic capability).
Related to the discussion of cyber- (or weaponized
code) as an ‘‘employable capability,’’ participants
also discussed the challenges of applying traditional
arms control constructs to such capabilities—not
least because of the challenges such efforts might
pose to broader questions of interoperability and
free flow of information. Yet, as noted by one of
the participants, some progress has been made at
least in terms of mitigating the export of surveillance
technologies (for their use, for example, by
authoritarian governments) through the Wassenaar
Arrangement’s 8 agreement in December 2013 to
include changes establishing new controls relating
to intrusion software and Internet Protocol (IP) net-
work surveillance systems. 9 The question, however,
remains whether these changes will be applicable
to the world we are moving toward, not least
because not every country or company shares the
same values.
The Transition
Within a broader discussion on the transition the
international system is currently undergoing—that
is, from the unipolar, post–cold war order premised
on liberal democratic ideals to a multipolar one in
which these ideals are increasingly contested and
where deception and opaqueness figure signifi-
cantly—panelists questioned the capacity of the
state-based international system to respond to
today’s challenges. In the past, we have persistently
established institutions to deal with all the uncertain-
ties prevalent in the international system, yet with
these changes in scale, proximity, and precision dri-
ven by developments in the sphere of information
technology, we have helped undermine the
international system’s presumptions about conflict.
Furthermore, it will be possible to establish borders
in cyberspace over time—some countries are already
doing so. In this regard, one of the panelists
suggested that our current notion of territorial
borders would eventually be overtaken by a form
of ‘‘cyber Westphalia’’ in which information flows
will be highly unpredictable, with deep implications
across sectors. 10
In this regard, states, while still core actors, are not
the only ones. Cyberspace, a man-made complex
system perhaps better understood as a substrate of
existing domains (land, air, sea, and space), is, in
part, driving the transition the international system
is undergoing, particularly if considered from the
perspectives of scale, proximity, and precision. 11 It
is precisely these issues that we need to bear in mind
when thinking about strategy and warfare moving
forward.
A Revolution in Military Affairs?
Discussions also focused on how the use of spe-
cial forces for an ever-widening range of operations
is part of a wider debate in the U.S. national security
community about the future of warfare and whether
what we are experiencing is a new RMA. Some part-
icipants cautioned that it will be important not to
overreact to current developments in the field of
information technology, since what we are ultimately
witnessing is an adaptation of warfare (as well as the
human condition) to these developments as well as
new circumstances. Moreover, over-emphasizing
the power of cyber-capabilities in warfare (as some
have done by suggesting a revolution in cyber-
affairs) might lead us down the same dangerous path
blazed by RMA-evangelists in the 1990s—the one
that obviated politics and the human dimension
altogether.
Pending Policy Issues
Key questions remain, however. For example:
. If we accept the proposition that ICTs are an
employable military capability, what does this
represent? Something revolutionary (i.e., does it
force us to redefine how we look at national
security and national defense)? Or is it evol-
utionary (i.e., more of the same with different
characteristics)? Or both evolutionary and
revolutionary? If so, what does this represent for
the way the military is currently organized?
104 American Foreign Policy Interests
. More specifically, how can national security and
national defense postures adapt to the dynamic
character of warfare today, especially given their
objective of protecting key strategic interests, but
also given (1) existing and emerging political
and legal norms aimed at placing limitations on
states’ exercise of cyber-power and (2) the
geopolitical shifts we are currently witnessing in
which the United States is no longer the sole
global power?
. More specifically, how can we frame cyber-=IW
operations in this shifting context? Do they fall
more appropriately within the realm of hybrid or
unconventional warfare? Under law enforcement
operations? Should they be dealt with on a case-
by-case basis as suggested by one of the panelists?
. In this regard, is the current focus on taming
cyber-power through the application of existing
or new norms, including the laws of armed con-
flict, erroneous? What are the alternatives? Is it
possible to take a two-pronged approach? One
aimed at shaping state behavior regarding the uses
of cyber-capabilities and cyberspace at the
strategic level; the other ensuring that tactical uses
of cyber-capabilities (i.e., weaponized code) for
operations other than war are framed through
policies and authorities in a manner that protects
basic rights and establishes inter alia clear command
and control duties and responsibilities?
. To what extent can discussions on the use of
cyber-capabilities be linked to ongoing discus-
sions on the weaponization of automized tech-
nologies=robotics? 12 For now, these discussions
seem to be completely siloed, with limited
participation of experts across thematic areas.
Can lessons be shared across these thematic areas?
. What are the national security implications of our
increasing reliance on special forces (including
specialized units with enhanced cyber- and auton-
omous capabilities) for tactical purposes (i.e., as
employable capability) in foreign theaters where
we are not at war in the traditional sense?
. What challenges or opportunities does the deploy-
ment of special forces represent for the exercise
of other instruments of national power and for
ensuring stability in the international system?
. What are the implications of the deployment
of special operations forces on state-society
relations?
Panel 3
The Play of States: Norms and Security in
Cyberspace
Panel 3, moderated by Dr. Roger Hurwitz and
building on the essay he penned under the same title
for American Foreign Policy Interests,13 discussed
how the norms of cyberspace that seemingly
held two decades ago have been outmoded by the
Internet’s own success—a thousandfold growth in
users across the globe and millions of applications.
The fabrics of our individual and collective lives have
become digital. The use of digital networks to man-
age and integrate information, transactions, and
infrastructure has grown so pervasive and complex
that the dependencies among them and our
dependence on them might only be known if they
unraveled. For the moderator, these changes have
created opportunities for state, non-state actors,
and ephemeral groups suddenly empowered
through social media, and even individuals to do
perhaps as much mischief as good in cyberspace.
Terms like cybercrime, cyberwarfare, cyber–Pearl
Harbor, or cyberterrorism have pitched us against
an ocean of uncertainty and instability.
The legacy of the Edward Snowden revelations
still reverberates; states are openly at odds on what
the lines for appropriate behavior are; the challenges
industry faces are well-documented; and the robust
markets—black, white, or gray—for buying and
selling malware are thriving—and we seem to be
witnessing a normalization of cyber-insecurity.
Yet, despite a common sense of vulnerability and
many discussions on the need for new norms, states
and other relevant actors have reached, at best,
limited agreement on what norms should apply.
With this background in mind, the panel discussed
current efforts by states and other actors such as
transnational companies and groups in civil society
to define and promote norms, the strategies and
frameworks for these efforts, and the obstacles they
encounter.
Cacophony or Concert? Thinking about Norms in
the Context of Cyberspace and Cybersecurity
Many of the aforementioned efforts were cap-
tured in a detailed overview of the current norm
environment described as neither ‘‘cacophony nor
Volume 37, Number 2, 2015 105
concert.’’14 In accordance with the standard defi-
nition, a norm is a collective expectation for the
proper behavior of actors with a given identity. 15
This definition can be broken down into four core
elements: identity, behavior, propriety, and collec-
tive expectations. In cyberspace, each of these ele-
ments exhibits a broad range of candidates that,
taken together, produce the cacophony image.
. Identity: Who do the norms apply to? At present,
a broad number of cybersecurity norm
entrepreneurs exist, with little consensus on
which deserve attention or how to prioritize them.
States are the most obvious community to which
the norms apply. Efforts like the 2012 World
Congress on Information Technology (WCIT)
regarding Internet governance or the ongoing
talks within the framework of the UN Group of
Governmental Experts (GGE) aim to do this.
Different groups of states can form smaller com-
munities around regional affiliations, like-minded
groupings or membership in international organi-
zations like NATO or the OECD. The important
point to bear in mind is that states are not the only
entities that matter in cyberspace. Dozens of other
groups can either shape or be the object of cyber
norms. For example, the Budapest (Council of
Europe) Convention on Cybercrime is aimed at
developing norms to shape or mitigate the beha-
vior of non-state actors—individuals, criminals
and criminal organizations, etc. Industry affilia-
tions play a role in shaping cyber-security norms.
These include for example, Internet Service
Providers (ISPs), the undersea cable community,
those companies involved in the manufacture of
hardware, software, or critical infrastructure (for
example, the National Institute of Standards and
Technology [NIST] cybersecurity framework). 16
White-hat groupings such as Community Emerg-
ency Response Teams (CERTs) also develop
norms, so, too, do black hat groupings (e.g.,
Anonymous). Even victims as a group can be
subject to cybersecurity norms in terms of
expectations about certain types of behavior, for
example, disclosure of data breaches as the
Securities and Exchanges Commission (SEC)
currently requires for certain publicly traded U.S.
companies. This list does not even touch on the
array of multi-stakeholder groups, affiliations,
and associations that stress the importance of uni-
versal norms and their applicability to cyberspace.
. Behavior: This is the functional element of norms
aimed at prohibiting certain actions, encouraging
specific behavior etc., at varying levels of speci-
ficity. When thinking of behavior, we generally
think of norms that proscribe behavior. This is
the essential function of rules on crime or warfare.
Cybersecurity norms can also dictate what states
or other actors have to do, for example, the duty
to assist in the face of cybersecurity threats. 17
There may also be norms that empower actors
or encourage behavior—a point that scholars such
as Jonathan Zittrain argue is fundamental to the
generative nature of the Internet. Beyond deter-
mining which kind of behavior should be
regulated is the level of specificity at which we
regulate. Some norms are very specific. For
example, the norm that now favors using Unicode
character sets, encoding HTML since it includes
every language in contrast to the prior English-
only standard of ASCII. It is important to assess
this variation of specificity and how it affects
behavior.
. Propriety: This is the core of the norm concept in
that there is something out there on which we
base the expectation of behavior—the permissible
and the impermissible. The basis of the norm can
be legal or political or cultural. Domestic law, for
example, offers a range of norms from cyber
crime to cybersecurity. Examples include India’s
law on authorized access; China’s legal require-
ments obliging users to accept government super-
vision of their use of the Internet. In international
law, the Tallinn Manual seeks to elaborate
international legal norms applicable to cyber
warfare. 18 At the same time, international law in
this area is not all about warfare. Legal norms
and regimes also emerge in relation to inter-
national trade, international telecommunications,
or human rights—for example, the UN General
Assembly’s recent Resolution on the Right to
Privacy19 or the European Court of Justice’s recent
articulation of ‘‘a right to be forgotten.’’20 As
noted, political processes also form the basis of
norms, many of which are state-centric, for
example, the London process on cyberspace; the
Organization for Security and Co-operation in
Europe (OSCE)’s 2013 parliamentary declaration
106 American Foreign Policy Interests
and resolution on cybersecurity and confidence
building measures (CBMS); or the 2011 Russia-China
proposal for an International Code of Conduct
for Information Security. Other international pro-
cesses involve non-state actors, for example, the
Global Commission on Internet governance (also
known as the Bildt Commission); 21 the tech
grouping that led to the Montevideo Statement
on the Future of Internet institutions. 22 Regarding
cultural norms, these can emerge from partici-
pation in a specific community. For example, the
Internet Engineering Task Force (IETF) or ICANN
have become acculturated, setting out expecta-
tions of behavior. Other technical communities
such as international humanitarian lawyers,
intellectual property experts, or even the cyber-
security community share that approach. Finally,
we should not forget Lawrence Lessing’s lesson
that ‘‘code is law,’’ i.e., that how the technology’s
architecture is set up has normative implications
in the sense that it affects what we can or cannot
do on the Internet.
. Collective expectations: This is the existential
element of a norm, the concept that the norm
involves some form of shared consciousness or
unconsciousness; the belief in the norm’s exist-
ence and that behavior will be expected to occur
not just now, but going forward. This is the area in
which most disagreement has emerged to date.
Today, it is often hard to determine when and
where actions or inactions are the product of
a shared collective expectation of a cybersecurity
norm. Even if we think that something might be
related to a specific norm, the tools to contextua-
lize it (i.e., when, where, how the norm will
operate in a world of so many other norms), are
limited. What also remains unclear is which of
the norms are default norms and which are
peremptory (i.e., the norms we are not supposed
to violate); how we should relate norms to one
another; which should be prioritized; and which
should fall away.
This overview demonstrates the current level of
cacophony within the concept of cybersecurity
norms itself, but that current cacophony is also
evident at the next level up (i.e., the norms on
norms, the secondary rules involving the ‘‘who
decides who decides’’ question). The norms on norms
in cyberspace are highly contested, most obviously in
debates over Internet governance—with some arguing
that the Internet should be controlled like other IT
resources in the past and others who stress a more
bottom-up approach. Both camps presume that some
authority or process can dictate norm formation, but
it is precisely here where the sociological aspect comes
to bear, that is to say, this is not how norms always
work. They are not always so neat. Certainly, some
authority can dictate them, but they can also emerge
organically over long periods of time without any clear
sense of why. In between are a great number of norm
entrepreneurs who want to break the status quo and
change things, but there is limited consensus as to
who should get a fair hearing and which entrepreneur
we should listen to and which we should ignore.
The combination of these factors (i.e., the variation
in norms in terms of identity, behavior, propriety,
collective expectations and the norms on norms ques-
tion), is what gives the impression of a cacophonous
environment, posing serious theoretical challenges for
arriving at what might be called a ‘‘concert’’—a more
harmonious environment. As was obvious throughout
the meeting, serious issues remain unresolved and
important questions unanswered—for example, the
discussion on the stewards versus the sovereigntists, 23
in turn linked to the discussion on how to define or
characterize what cyberspace actually is and what
it is for (for the overall good of society vs. the security
of the state). The absence of mechanisms for sorting
out behaviors or theories for resolving conflicts
among norms for cyberspace poses important
challenges for prioritization in policy.
Despite the manifold challenges, the panel
discussion focused on how, moving forward, norma-
tive progress might be made in three specific areas:
. Consolidation: The process of dictating norms is
going to have to consolidate sometime soon. We
are in the year of infinite meetings: At some point,
the transaction costs will narrow down the list of
where and when these conversations on norms
are held.
. Incompletely theorized agreements: There is
the possibility that we might get to some form of
global midlevel cyber-norms even if we cannot
agree on what cyberspace is for or what it is. Cass
Sunstein’s theory of ‘‘incompletely theorized
agreements’’ can help us understand what this
Volume 37, Number 2, 2015 107
means (i.e., we can, at minimum, agree on some-
thing being good or bad, something we should do
or not do, even if we do not agree on the why). 24
. Siloing: In certain areas, we are already seeing a
degree of siloing, for example, through the 2013
changes to the Wassenaar Arrangement, the
Tallinn Manual, and so on. A next step might
involve groups of states moving beyond discuss-
ing whether X or Y is a norm to discussing how
to contextualize it: What it means, how to
prioritize it, and so on. Maturation of norms might
also become evident in some areas, for example,
international telecommunications or human
rights regarding cyberspace; security, and so on.
The challenge, however, is that there are limited
mechanisms for cross-silo talk that could, in turn,
pose additional problems if decisions are made
about norms in one area without regard for how
such decisions will impact other areas.
The Government Response: Give Strategy
a Chance!
In response to some of the assertions tabled in
Panels 1 and 2 regarding the existence of, the effec-
tiveness of the U.S. government’s foreign policy and
strategy for cyberspace, and the deployment of cyber-
capabilities, the government representative on the
panel provided a detailed overview of government
efforts to date, many of which have been aimed at
establishing norms for appropriate state behavior in
cyberspace. These efforts include:
. The 1998 PDD-63 with guidance from Richard
Clarke, former U.S. National Coordinator for
Security, Infrastructure Protection, and Counter-
Terrorism to commence working with like-
minded and friendly states.
. Also in 1998 and following from PDD-63, an
inter-agency strategy paper was penned, resulting
in a four-track plan that was used for some 11
years. The strategy was aimed at engaging with
other states on cybersecurity due diligence with
like-minded states (i.e., all states would build up
a capacity to defend their own networks under a
four-pillar system organized nationally and aimed
at modernizing substantial procedural law, build-
ing CERTs, fostering public–private partnerships,
and building a public culture of awareness.
. In 2008, under the direction of Melissa Hathaway,
the government undertook an exercise similar to
Eisenhower’s Solarium Project 25 aimed at promot-
ing deterrence in cyberspace. 26 The project led to
a broader strategy premised on building defenses
as high as possible to keep out general malfeas-
ance. Anything else would be treated as actions
or threats emanating from traditional adversaries
for which the government had sufficient experi-
ence in knowing how to deter and influence
them. The strategy also demonstrated that there
is no single bullet for deterrence; rather, what
are needed are mutually overlapping international
strategies that include promoting norms of appro-
priate state behavior in cyberspace supported by
building confidence and security measures to
ensure that states can operate with connectivity
and collectively against disruptions and rogue
states or non-state actors.
. The 2008 strategy was further developed in
the 2011 International Strategy for Cyberspace.
A principal objective of the strategy is to build
a framework of principles of expected behavior
supported by confidence- and security-building
measures to which most nations, not all, will
abide because it is in their ultimate security
interest to do so.
Promoting Norms and Confidence-Building
Measures at the International Level
With the help of allies, as well as Russia and China,
key steps have been taken on this difficult road,
particularly within the UN Group of Governmental
Experts (GGE), the first of which was established in
2005 pursuant to a Resolution tabled by the Russian
Federation in 1998. Despite a difficult trajectory, in
2013, a third GGE finally reached agreement on the
applicability of international law, particularly the
UN Charter and Law of Armed Conflict (LOAC), to
cyberspace, as well as the principles of sovereignty
and state responsibility. The group also agreed
that proxies used by states should be banned and
it affirmed human rights. This was a significant
achievement.
The United States has also focused on promoting
and supporting transparency and confidence-building
measures. In terms of transparency measures, the
initial challenges of guaranteeing some form of
108 American Foreign Policy Interests
predictability regarding cyberspace (key to trans-
parency) was later overcome by the publication of
U.S. 2011 International Strategy for Cyberspace and
the 2011 Department of Defense Strategy for Operat-
ing in Cyberspace (DSOC) (unclassified version).
Emphasis has also been placed on promoting the
outcome of the UN GGEs in regional fora such as
the OSCE, which, in December 2013, agreed on an
initial set of confidence-building measures (CBMs)
(11 in total). 27 While most of the CBMs relate to
transparency measures, CBM 3 mandates mediated
discussions between an aggressor and a victim
(within the OSCE area of responsibility). At the North
Atlantic Treaty Organization (NATO) Wales summit
earlier this year, all NATO members (28 of which
are also OSCE members) affirmed that international
law applies to state-on-state activity. CBMs have also
been discussed within the Association of South East
Asian Nations (ASEAN) Regional Forum.
Finally, the current U.S. submission to the 2014
UNGGE provides a detailed examination of exactly
how the UN Charter and the LOAC apply to cyber-
space, including countermeasures and state uses of
proxies. It also includes a vision of state sovereignty
from the U.S. perspective. In addition, it advances
three new norms of state behavior that the United
States believes should apply to that spectrum of
activity below the threshold of the use of force and
for which there is no existing international legal
precedent or source, but many. 28 Moreover, despite
what was discussed in Panel 2, the government is
promoting these norms as a means to advance the
fact that most cyber-tools are used by non-state and
state actors across a spectrum of conflict—most
notably below the threshold of armed conflict.
Regardless of how they are defined (norms or
confidence- and security-building activities or mea-
sures of self-restraint), it is evident that we are moving
up a pyramid from transparency measures to
cooperative measures and from there to measures of
self-restraint, with these last measures the ones that
will provide stability in the international environment.
At the same time, it is important to bear in mind
that CBMs and norms can only go so far. Russia’s
violations of norms applicable to the kinetic world
in the Ukraine is a case in point.
Where to next then? The speaker suggested
establishing an initiative similar to the Proliferation
Security Initiative (PSI), a voluntary organization of
like-minded states focused on interdicting the spread
of fissile material. The idea would be to establish
a similar voluntary organization made up of like-
minded states that observe appropriate international
norms, cooperate seamlessly against common
cyber-threats, refrain from destabilizing activity, and
also come together in the future to sanction bad
actors and to aid each other in mitigation and reme-
diation. Establishing such an initiative is unlikely to
happen any time soon, but that is the current vision.
Views from the Private Sector
From the perspective of the private sector rep-
resentative on the panel, focus was placed on the
need to work toward more comprehensive planning
for insecurity (i.e., to help determine the most effec-
tive kind of contingency planning for dealing with
the environment we are working in, to manage risk,
now and in the future). Cyberspace challenges the
traditional policy construct, not least because it
changes so rapidly. And these changes are happen-
ing within a globally interconnected society, making
it even more difficult to manage change. Some of the
current issues regarding Internet governance might
break that interconnectivity (at the domestic level),
but the global connected nature of society will not
change.
Participants discussed how, within that global
interconnected society, government actors and a
range of non-state actors, including the private sec-
tor, are involved in counter-risk operations, many
of which have resulted in successful joint public–
private operations. 29
Conversely, today, the number of actors operating
in cyberspace means that the potential for
unintended consequences is significant. In this
sense, norms are actually being set by actions, rather
than just through the kinds of state-centric delibera-
tions discussed earlier. This is problematic. Certainly,
considerable progress is being made, as noted with
regard to the work of the Group of Governmental
Experts, the OSCE work on CBMs, and so on. Yet,
that progress is being made at the high-end space
of the United Nations. In reality; however, and as
discussed by Panel 2 and above (regarding the U.S.
submission to the 2014 GGE), the vast majority of
the activity we are seeing now is below the threshold
of armed conflict. Some of that activity can be
Volume 37, Number 2, 2015 109
addressed through standard response processes, but
some requires more advanced response because
of the urgency and severity of the risk to users.
The vast majority of attacks requiring advanced
response today are nation-state–sponsored.
Setting Norms for Below-the-Threshold Conflict
In an environment involving many different
actors, tensions, and objectives operating below the
threshold, it will be important to prioritize and think
about an appropriate framework to guide both
policymakers and the technical community. Such
a framework can be centered on four components:
understanding whom the actors are (principally
governments), as well as the objectives, actions,
and impacts as well as the global acceptance of the
latter. 30
For example, one of the difficulties in understand-
ing impacts in cyberspace is that there is a tendency
to group everything together (impact to users,
national security, etc.). A more effective approach
might be to break down the impact component even
further. For example, when applying the concepts of
distinction, discrimination, and reuse and managing
the reuse of weapons (capabilities), those concepts
do not actually look equal across the different tech-
nology environments. 31 Hence, it is important to be
clear whether we are talking about commercial
off-the-shelf technology, government off-the-shelf
technology, operational technology, public cloud,
private cloud, and so on. And, when thinking about
impacts and how to define norms that limit harm, it is
also important to think about the information secur-
ity attributes of the asset that may be affected (i.e.,
what is going to happen if the confidentiality, integ-
rity, or availability of data is undermined). This focus
is premised on the importance of trust—once trust in
the data is lost (and it is unclear when it was lost) it is
very difficult to regain.
The Private Sector: A Role in Norm-Setting?
The panel discussed the importance of increasing
participation of the private sector in different discus-
sions on norms. Who is involved obviously depends
on the issue, but in the context of international security
and stability, a significant number of ICT providers
focused on infrastructure (ISPs, those building servers
and databases), financial services organizations, oil
and natural gas—all are operating on a multinational
basis and all are key to ensuring stability. From an
ICT provider perspective, certain things can be done,
for example, working to reduce the attack surplus
through secure engineering and working to manage
supply-chain risk; coordinate and responsively disclose
vulnerabilities within industry (i.e., reporting vulner-
ability to the vendor; cooperating to address open-
source vulnerabilities; share information that helps
limit the scope and impact of incidents that do occur;
and participate in response and recovery activities).
Pending Policy Issues
A core dilemma relates to U.S. capacity to influ-
ence outcomes at a time when the reputation of
the U.S. government and U.S. ICT providers in their
uses of cyberspace and ICTs is at an all-time low.
This is occurring at a time of complex geopolitical
shifts in which normative disintegration and disen-
gagement is affecting many areas and many contexts,
not just cyberspace and cybersecurity.
. Does this place the United States at a strategic
disadvantage in terms of being able to influence
normative outcomes with regard to cyberspace?
. Will pragmatism be the way forward? Pragmatism,
it was suggested, does not imply the cancellation
of vision, objectives, or goals, but rather shifts focus
to the definition of the acceptable futures we can
live with. It can allow us to think along the lines
of converging interests—that is, where things are
coming together (e.g., the converging interests of
the United States and China in the area of financial
stability). Is this a viable way forward? Is it conson-
ant with current strategy and foreign policy?
. Within this shifting geopolitical context, what are
the opportunities and challenges of establishing
a PSI-like initiative to support the propagation and
implementation of norms for state behavior in cyber-
space as suggested during the panel discussion?
Notes
1. According to the moderator, for many of the G20 countries, integrating access to the Internet holds a promise of at least 4 percent of Gross Domestic Product growth. For developing economies, that promise can be as high as 10 percent.
110 American Foreign Policy Interests
2. Melissa E. Hathaway, ‘‘Connected Choices: How the Internet Is Challenging Sovereign Decisions,’’ American Foreign Policy Interests 36, no. 5 (2014): 300–313.
3. For example, India has three landing stations. If they are damaged, India would be off the grid for at least six weeks. And India would not be the only country affected. A growing number of U.S. corporations run their back offices from India and would thus be equally affected.
4. For further insights into issues pertaining to data sovereignty, see Tim Maurer et al., Technological Sovereignty: Missing the Point? An Analysis of European Proposals after June 5, 2013. Transatlantic Dialogues on Security and Freedom in the Digital Age, http://www.newamerica.org/downloads/ Technological_Sovereignty_Report.pdf.
5. According to the moderator, some 107 states field special oper- ation forces that lean on cyber- and IW capabilities for a range of missions, including strategic reconnaissance, intelligence, unconventional warfare, and direct action=special warfare.
6. See, in particular, William H. McRaven, Spec Ops: Case Studies in Special Operations Warfare: Theory and Practice (New York: Random House, 1996).
7. Regarding how cyberspace is key to operational security, the operation to bring down Osama bin Laden is an interesting example. Preparations for the operation had covered every aspect of the electromagnetic spectrum as part of the oper- ational security plan; yet they had overlooked Twitter. As the helicopters were hovering over bin Laden’s residence in Abbotabbad, Pakistan, a Voice of America stringer, who happened to be in the area of operations tweeted nine times the presence of U.S. troops in the area.
8. The Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies is a forum for states to agree on which specific technologies should be subject to export control for regional and international security and stability purposes. See http://www. wassenaar.org.
9. See Tim Maurer, Edin Omanovic, and Ben Wagner, ‘‘Uncontrolled Global Surveillance Updating Export Controls to the Digital Age,’’ 2014, New America Foundation, http:// oti.newamerica.net/publications/policy/uncontrolled_global_ surveillance_updating_export_controls_to_the_digital_age.
10. See Chris C. Demchak and Peter Dombrowski, ‘‘Rise of a Cybered Westphalian Age,’’ Strategic Studies Quarterly, Spring 2011.
11. For a deeper discussion on these points of scale, proximity, and precision, see Peter Dombrowski and Chris C. Demchak, ‘‘Cyber War, Cybered Conflict, and the Maritime Domain,’’ Naval War College Review 67, no. 2 (Spring 2014).
12. See, for example, ‘‘Framing Questions on the Weaponization of Increasingly Autonomous Technologies,’’ UNIDIR, 2014, http://www.unidir.org/files/publications/pdfs/framing- discussions-on-the-weaponization-of-increasingly-autonomous- technologies-en-606.pdf.
13. Roger Hurwitz, ‘‘The Play of States: Norms and Security in Cyberspace,’’ American Foreign Policy Interests 34, no. 5 (2014): 322–331.
14. See Duncan Hollis, ‘‘Neither Cacophony nor Concert: Minor Notes on Metanorms for Cyberspace,’’ https://prezi.com/ l2rzahogaatm/neither-cacophony-nor-concert-minor-notes- on-metanorms-for-cyberspace/?utm_source=prezi-view&
utm_medium=ending-bar&utm_content=Title-link&utm_ campaign=ending-bar-tryout.
15. See Peter Katzentein, ed., The Culture of National Security: Norms and Identity in World Politics (New York: Columbia University Press, 1996).
16. National Institute of Standards and Technology, ‘‘Framework for Improving Critical Infrastructure Cyberse- curity’’ of February 2014. This was developed following President Obama’s Executive Order 13636 on Improving Critical Infrastructure Cybersecurity, of February 2013.
17. Hollis, op. cit. 18. Michael N. Schimtt, ed., Tallinn Manual on the International
Law Applicable to Cyberspace (Cambridge: Cambridge University Press, 2013).
19. UN General Assembly Resolution ‘‘The Right to Privacy in the Digital Age,’’ A=RES=68=1670 of January 21, 2014, http:// www.un.org/en/ga/search/view_doc.asp?symbol=A/RES/68/ 167&referer=http://www.un.org/depts/dhl/resguide/r68_en. shtml&Lang=E.
20. See European Commission, ‘‘Factsheet on the ‘Right to Be Forgotten’ Ruling,’’ http://ec.europa.eu/justice/data-protection/ files/factsheets/factsheet_data_protection_en.pdf.
21. See Global Commission on Internet Governance, https:// www.ourinternet.org/#about.
22. ICANN, ‘‘Montevideo Statement on the Future of Internet Cooperation,’’ https://www.icann.org/news/announcement- 2013-10-07-en.
23. For an insight into the stewards versus sovereigntist debate, see the Munk School of Global Affairs 2012 Cyber Dialogue, http://www.cyberdialogue.ca/previous-dialogues/ 2012-about/papers/.
24. See Cass R. Sunstein, ‘‘Incompletely Theorized Agreements,’’ Harvard Law Review 108, no. 7 (May 1995): 1733–1772. The panelist noted in particular Sunstein’s emphasis on the norm of religious liberty. Some people favor it because of their own religious beliefs, others for utilitarian reasons, security officials because it preserves the social peace, and so on. We do not have to agree on why religious liberty is a norm; we just accept it and move on.
25. See William B. Pickett, ed., George F. Kennan and the Origins of Eisenhower’s New Look: An Oral History of Project Solarium, Princeton Institute for International and Regional Studies, Monograph Series, no. 1 (Princeton, NJ: Princeton University, 2004).
26. For a discussion on the outcome of the exercise, see John Markoff, David E. Sanger, and Thom Shanker, ‘‘In Digital Combat, U.S. Finds No Easy Deterrent,’’ New York Times, January 25, 2010.
27. For an overview of the OSCE CBMs and other related processes, see Camino Kavanagh et al., ‘‘Baseline Review of ICT-Related Processes and Events: Implications for International and Regional Security,’’ ICT for Peace Foundation, http://ict4peace.org/baseline-review-of-ict-related- processes-and-events-implications-for-international-and- regional-security/.
28. The three new norms advanced by the U.S. government include:
(1). States should not conduct or knowingly support online activity that intentionally damages critical infrastructure
Volume 37, Number 2, 2015 111
or otherwise impairs the use of critical infrastructure that provides services to the public.
(2). States should not conduct or knowingly support activity intended to prevent national C-CERTs from responding to cyber-incidents and a state should not use C-CERTs to enable online activity that is intended to do harm.
(3). States should cooperate in a manner consistent with international law and its international obligations with requests for assistance from states in investigating cyber- crimes and collecting electronic evidence and mitigating malicious cyber-activity emanating from its territory. States must take immediate and robust action to investi- gate criminal activity by non-state actors.
29. For example, in response to the 2012 distributed denial-of- service (DDoS) attacks against U.S. banks, the government and private sector worked together using both tech and
diplomatic channels to address and stem the threat. In 2013 and 2014, we witnessed several successful international and domestic Botnet takedowns with massive implications for users.
30. Building on an initial framework presented at the 2013 RSA Convention, Microsoft presented a paper at the EastWest Institute Cyber Summit in Berlin in December 2014, proposing six specific norms aimed at limiting conflict in this space. See ‘‘International Security Norms: Reducing Conflict in an Inter-Dependent World,’’ Microsoft, December 2014.
31. For example, when a vulnerability is exploited in commercial off-the-shelf technology for national security purposes, the possibility of reuse of that vulnerability is very high. When looked at from the perspective of government off-the-shelf technology, it will be more narrow. If a public cloud is attacked, the consequences will probably be very high; a private cloud, less so.
112 American Foreign Policy Interests
Copyright of American Foreign Policy Interests is the property of Routledge and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.
- INTRODUCTION
- Camino Kavanagh and John B. Sheldon
- SUMMARY OF DISCUSSIONS
- Panel 1
- Connected Choices: The Internet and Sovereign Decision Making
- Framing the Problem
- Pending Policy Issues
- Panel 2
- Information/Cyber Warfare and Territorial Sovereignty: The End of Defense?
- Special Operations Forces: What Shoe Do They Fit?
- The Transition
- A Revolution in Military Affairs?
- Pending Policy Issues
- Panel 3
- The Play of States: Norms and Security in Cyberspace
- Cacophony or Concert? Thinking about Norms in the Context of Cyberspace and Cybersecurity
- The Government Response: Give Strategy a Chance!
- Promoting Norms and Confidence-Building Measures at the International Level
- Views from the Private Sector
- Setting Norms for Below-the-Threshold Conflict
- The Private Sector: A Role in Norm-Setting?
- Pending Policy Issues
- Notes