The Trump administration has
vowedto “take every measure to safeguard our national security secrets and systems” given that “[c]yberwarfare is an emerging battlefield.” As such the administration “will make it a priority to develop defensive and offensive cyber capabilities at our U.S. Cyber Command, and recruit the best and brightest Americans to serve in this crucial area.”
As it is still very early days in the Trump administration, key executive positions are still being filled. While the administration has named several cabinet secretaries, there are still additional positions under the secretary level still vacant. Here are the top positions within the administration that will affect cyber policy both from a tool of national power and a deterrent.
White House
Chief adviser on homeland security, counterterrorism and cybersecurity matters:
Filled
President Trump
announcedin December the selection of Thomas Bossert to serve in the White House as his cybersecurity advisor, a position that is not Senate confirmable.
Bossert, previously served as deputy assistant to the President for Homeland Security in the Bush administration. His appointment was lauded by many cybersecurity experts as he enjoys great respect within this community.
Shortly before taking the oath of office, President Trump announced that former New York City mayor and close Trump advisor Rudy Giuliani would serve as an informal advisor “sharing his expertise and insight as a trusted friend concerning private sector cyber security problems and emerging solutions developing in the private sector,” a
statementfrom the transition team said.
Additionally, the National Security Council, top advisors to the president and the Treasury Department, though through no officials in particular, have used sanctions as a tool to deter malicious cyber behavior. This was a major component of the previous administration’s cyber deterrence policy, though it remains to be seen if the Trump administration will view this tool in the same light.
State Department
Coordinator for Cyber Issues:
Filled
Christopher Painter, a career official, is continuing to serve this role from the Obama administration, a State Department spokesperson confirmed to C4ISRNET.
This position is the tip of the spear in coordinating U.S. efforts with other nations to “promote an open, interoperable, secure, and reliable information and communications infrastructure that supports international trade and commerce, strengthens international security, and fosters free expression and innovation,” State
said.
The roles of this position include global diplomatic engagements on cyber issues, serving as State’s liaison to the White House on global cyber issues, advising the Secretary of State on cyber issues and working across the government in coordinating cyber policy and responses to issues.
This post also works to help establish
cyber normswithin the international community, which will affect the way in which the U.S. employs cyber capabilities within an international construct.
Defense Department
Undersecretary for Defense Policy:
Vacant
Theresa Whelan is currently performing the duties of the Under Secretary of Defense for Policy.
The Undersecretary of Defense Policy advises the Defense Secretary on the development and execution of national defense policy and strategy.
Deputy Assistant Secretary of Defense for Cyber Policy:
Vacant
Kate Charlet is currently acting DASD for Cyber Policy.
This position is responsible for support the Under Secretary of Defense for Policy, which currently has no occupant, developing and overseeing the implementation cyber-related policies, strategies, and plans ensuring stability and achieving certain objectives.
CIO:
Filled
Terry Halvorsen, a holdover from the Obama administration, will continue serving in this role until he
retireseffective Feb. 28.
The CIO is responsible for managing DoD’s IT infrastructure and policy. In this role, Halvorsen has spearheaded the Joint Information Environment, which he
described as a concepttoward standardizing IT across the military with a shared operational network picture. A key pillar of this effort is the Joint Regional Security Stacks, which will make DoD networks and transport of information more secure by shrinking the global attack surface of the network.
This role is more responsible for cybersecurity rather than generating cyber effects, though, cybersecurity plays an important role in overall deterrence through deterrence by denial – hardening systems to the point that adversaries will not succeed in penetrating and thus making intrusion attempts futile.
Department of Justice
Assistant Attorney General and Principal Deputy Assistant Attorney General for National Security:
Vacant
Mary B. McCord has been acting Assistant Attorney General and Principal Deputy Assistant Attorney General for National Security since October of 2016 when her predecessor, John Carlin, departed (
get confirmation).
Carlin made this post a critical component within the government’s cyber architecture and deterrence strategy by establishing a regime to indict foreign officials that have conducted malicious cyber operations against the United States. The most high profile cases of these indictments include members of the Chinese People’s Liberation Army, Syrian Electronic Army, Iranian hackers and Ardit Ferizi, a Kosovar, who was extradited and
convicted of cyber terrorism, the first such case.
“The challenge we face in investigating cyber crime is that cyber criminals often think that it’s a freebee to reach into the United States to do harm to steal what matters to us to wreak havoc. They think it’s a freebee because they’re halfway around the world and trying to use anyonomyzation techniques,” FBI director James Comey said in a March 2016 news conference following the indictments of Iranian hackers. “The message of this case is that we will work together to shrink the world and impose costs on those people so that no matter where they are we will try to reach them and no matter how hard they work to hide their identity and their tradecraft, we will find ways to pierce that shield and identify them.”
“I think that there’s a whole-of-government approach to this and I think that we actually have seen some significant changes in our interactions with the Chinese government in terms of cybersecurity norms and in terms of the way in which they have come to agreement with the U.S on the parameters of how countries should use cyber activity with each other,” former Attorney General Loretta Lynch said of the effect of these indictments against the Chinese in the face of criticism that they will never be extradited to face justice and thus are futile.
Indictments was a major pillar of the previous administration’s cyber deterrence policy, though it is unclear if the new administration will use this as a tool in its toolbox.
Intelligence Community
Director of National Intelligence:
Vacant
Former Indiana Senator Dan Coats was nominated by President Trump to serve as the Director of National Intelligence.
In this role, Coats will serve as a coordinator across the intelligence community. As was seen with the previous DNI, James Clapper, as it related to the influence operation and hacking of U.S. political institutions attributed to Russia, the intelligence community has an important role to play in offering attribution to the White House identifying parties responsible for further actions. These further actions could include sanctions, indictments, diplomatic responses such as demarches, overt responses in cyberspace or the physical world with the use of the military, or covert response. Without the attribution capabilities of the intelligence community to identify those responsible, these response options would be moot.



