Sea Control - Sea Control 385 - Navy Cyber Workforce

Episode Date: October 6, 2022

Links1. “Develop Separate Navy Cyber and Signal Warfare Communities,” by Chris Landis, Proceedings, July 2022.2. “The Air Force Isn’t Doing Information Technology Right," by Don Lewis, War on ...the Rocks, December 20, 2021.3. “Navy Cryptologic Warfare Officers Cannot Do Cyber," by Derek S. Bernsen, Proceedings, January 2022.4. “Cybersecurity Readiness Review," directed by Secretary of the Navy, 2019.

Transcript
Discussion (0)
Starting point is 00:00:00 Hello all, I'm Nathan Miller. I'm filling in for Jared this week. Today, we have Anna McNeil hosting Commander Chris Landis. They discussed Commander Landis' recent Proceedings article calling for distinct cyber and signal warfare communities. I edited and produced today's podcast. I would like to plug our local chapters. If you're in South Korea, Egypt, Singapore, France, New York, India, or in the Caribbean, Odds are that there's a local chapter near you. For a full listing of our chapters, please visit simsec.org.
Starting point is 00:00:33 Finally, I highly recommend our partners in the SimSec podcast network, The Bilge Pumps. You can find Alex, Jamie, Drack, and a pile of Iron Brew bottles wherever you download your podcasts. On that note, I'll turn it over to Kimber's men. You're listening to Sea Control, hosted by the Center for International Maritime Security. Hey folks, thanks for tuning back in to Sea Control. Today we're talking with Commander Christopher Landis, U.S. Navy, about his recently published article, Develop Separate Navy Cyber and Signal Warfare Communities, which was published online in Proceedings Magazine's July 2022 edition. Commander Landis received the AFSIA Copernicus Award in 2021 for sustained superior performance in C4IT
Starting point is 00:01:23 and has experience in defensive cyber operations. Commander, thank you for joining us today. Would you please tell our audience a bit about yourself and your background? Thank you, Anna, for such a warm welcome here on the Sea Control Podcast. I'm glad to be here. I started out in the Navy as a 2007 graduate of the U.S. Naval Academy with a surface warfare service assignment. After that first tour aboard a destroyer, I executed my IP option
Starting point is 00:01:49 to transfer to the Navy's information professional community so that I could align my career more with my bachelor's degree in information technology and space operations. As an IP officer, I served as the electronics material officer aboard a littoral combat ship, completed a master's degree in information technology strategy from Carnegie Mellon University, served at the U.S. Naval Computer and Telecommunication Station in Naples, Italy, served as a combat systems information officer aboard an aircraft carrier, and served at JFHU Doden, which spells out as Joint Force Headquarters Department of Defense Information Network, and is the joint component of U.S. Cyber Command responsible for the secure,
Starting point is 00:02:30 operate, and defend mission set on the Doden. I recently started working on a PhD in computer science at the Naval Postgraduate School in preparation for becoming a permanent military professor at the U.S. Naval Academy. In the context of my proceedings article, you can see that I have experience operating in multiple domains, including the cyber domain and the electromagnetic spectrum. And it's these experiences and discussions with others working across these domains that motivated me to write about it. Thank you. And as a reminder to our listeners, all views expressed are our own and not representative of any institution with which we might be otherwise associated. It has been over 10 years now since U.S. Cybercom first stood up
Starting point is 00:03:12 and has been at the helm of the growing community of operational cyberspace forces. But this does not mean that doing cyber missions has been standardized across the military services. Truly, the differences in how each service man, train, and equip their cyberspace forces is a fascinating reflection on service culture. So how has the Navy built out their cyber operations? At first, the Navy's involvement in the cyber domain, which was long before we recognized it as a domain, of course, was like many organizations at the time. That is, ad hoc, no one was in charge of orchestrating the whole effort. And we were vulnerable. Over time, the systems commands were resourced to create programs of record, enlisted ratings evolved, including with the data processing
Starting point is 00:03:56 technician or DP rating that later merged with radio men or RM that later merged again with information systems technician, which is an IT rating, and then the cryptologic technician rating, specifically the networking branch known as the CTN rating. And the Navy commands were established merged, and developed, including Fleet Cyber Command and U.S. 10th Fleet, with its Task Force 10 organization to lead the Navy's operational efforts in the cyber domain, and Navy Cyber Forces, later renamed to Navy Information Forces, to serve as the manned, trained, and equipped leader, also known as a type commander, for the newly established Information Dominance Corps. Of course, the Information Dominance Corps was subsequently renamed as the Information Warfare
Starting point is 00:04:39 community, and the intent there was to merge the information-related communities into a combined community of multiple designators and ratings to lead in dominating the information domain. The intent was that each community would remain distinct, while all would learn more about how they can be a force multiplier by supporting each other's strengths and capabilities. The Navy has three communities that contribute primarily to cyberspace operations. The cryptologic warfare community, the information professional community, and the cyber warfare engineer community. Within the cyber domain, the IP community focuses primarily on acquiring, securing, defending, operating, maintaining information systems. The cryptologic warfare
Starting point is 00:05:24 community focuses primarily on exploiting, attacking, and defending in the cyber domain. The cyber warfare engineer community focuses primarily on advanced tool and technique development to improve offense and defensive cyber capabilities. You may have noticed that with the IP and CW communities, I stipulated that these are their primary functions within the cyber domain. Each of these communities has other duties within the electromagnetic spectrum too. The Navy has very strong operational warfare communities, for example, air, submarine, or surface warfare. So why is it that you say that cyber operations are too much for any one community? I made that claim there in the introduction of the article in the context of adding cyber to a community's existing workload.
Starting point is 00:06:14 For example, the cryptologic warfare community has a rich 80-year history in exploiting signals and conducting electronic warfare, only picking up cyber in the most recent fourth of its lifespan. Cyber is too much for any one community to add onto its list of responsibilities. I cited this idea from another proceedings article entitled, Navy Cryptologic Warfare Officers Cannot Do Cyber by Derek Bernson. Building on this idea, the position that I take in my article is that the Navy needs separate communities, one each dedicated to cyberspace operations in the cyber domain, and one dedicated to electromagnetic maneuver warfare in the electromagnetic spectrum, if the Navy wants to increase its warfighting effectiveness in these two domains. Continually stationing personnel and jobs focused on one domain and then switching them to jobs in the other domain hinders the Navy's ability to develop community-wide proficiency and expertise in each of these domains. In other words, we need to realign these domains within the information warfare community. Would you agree that cyber is a subset of electromagnetic maneuver warfare? No.
Starting point is 00:07:27 Cyberspace operations and electromagnetic maneuver warfare are executed in different domains. So I do not agree that cyber is a subset of EMW. I have two examples that come to mind to explain this. First, in our maritime environment, some might counter argue by asking, doesn't RF connect to the network? It seems logical on the surface that EMS overlaps network operations, especially for a float unit.
Starting point is 00:07:52 Digging deeper into the technological mechanisms, though, you will find that there is a line of demarcation dividing these two domains. Joint Publication 6-TAC-01 recognizes this distinction by explaining that they are two separate functions and are planned, managed, and executed independently. In other words, in cases when the network medium consists of an RF transmission, cyber personnel need to work with signal personnel to ensure end-to-end network operation. You can consider the presence of an RF hop in the network path to be transparent to the network, and this is because, theoretically, we could replace the RF path with a cable of equivalent length and experience similar latencies as we do with RF. As a second example, consider the pervasive nature of cyber and how it can seem like everything is headed toward cyber. The EMW, EW, that's electronic warfare, combat systems, cyber warfare, and information operations are all converging. Of course, there is some truth to this line of thought, but all of these systems still depend on the foundational principles of their respective domains. This is like digitizing a fire control system. Even though we could have a supercomputer calculating
Starting point is 00:09:07 the firing solution and the terminal guidance of the weapon, the system still depends on using and the effective management of the electromagnetic spectrum. Or, from the opposite perspective, we still need to be proficient at detecting and exploiting the signals emanating from our enemy's cyber-enabled fire control systems. While cyber is more often becoming the means of mission enablement, one must still understand the fundamentals of the electromagnetic spectrum in order to employ these cyber-enabled capabilities to their fullest effect. What solution would you propose to help assure the focus needed to maintain the CNMF skills? For the more advanced cyber skills that build upon lots of education and practical coding,
Starting point is 00:09:55 command line and shell experience, like folks working at the Cyber National Mission Force, the cyber warfare engineer or CWE community comes to the forefront of my mind. Although I didn't have enough space for this in my published article, in my draft, I explained that CWEs are a great asset to the Navy cyber warfare capability and continued growth of the CWE population is necessary. In this new cyber signal alignment, I envisioned that CWEs would serve within the cyber warfare community as the advanced operators, distinguished by an AQD, which we call advanced qualification designation, representing their specialized training and experience. Specific billets requiring these advanced skill sets would have the AQD coded as a prerequisite to fill the
Starting point is 00:10:42 billet. In its career progression expectations, the cyber community, though, would need to accommodate these advanced cyber specialists staying in their specialized billets over and over again, but still being viable for due course promotions. Can you please tell us a bit about DCWF work roles? How do these distinctions shape the cyber workforce? And where do you think the Navy places their cyber operators within DCWF work roles? I am familiar with the DoD Cyber Workforce Framework, or DCWF. And for anyone that would like to learn more about it, I recommend taking a look at the public DOD cyber exchange website at public.cyber.mil slash CW, CW in this case being for cyber workforce. My proposed realignment of the Navy's information warfare
Starting point is 00:11:33 community would position the vast majority of DCWF within one cyber community, covering cradle to grave life cycle management, day-to-day operation, maintenance, security analysis, and incident investigations, defense, offense, and governance, pretty much the whole lot. Personnel involved in my proposed signal community, on the other hand, would not be part of the DCWF because the electromagnetic spectrum is a different domain than the cyber domain. Using your proposed realignment of duties in the ratings, who might you see performing operational technology system security in the Navy? I see the responsibility for the security of operational technology to be with two primary
Starting point is 00:12:16 parties. First, the systems command that developed and fielded the system must provide a secure system and provide the second party, that is the sailors, with the means to maintain adequate levels of security for those systems. This is all that should be needed. However, if a malicious cyber actor discovers that the system is not as secure as it should be, the DoD has at least one cyber protection team available for deployment to respond. It sounds like you see Navy cyber warfare and signals as divided and distinct. Is that true? Divided and distinct. Yes, definitely. But that doesn't stop them from continuing to work together, just like all of the communities within the IWC do already today. For example, there may be a need to work together for some
Starting point is 00:13:05 signals intelligence missions. Some may even claim that SIGINT and cyberspace operations, or CO, are one and the same. Let's take a step back to look at this, just like we did earlier regarding the RFHOP and the network path. Intelligence is both enabled by CO and Intel supports CO. Specifically, Computer Network Exploitation, which is an OCO discipline, and Dodon Ops, enable SIGINT. Whereas traditional SIGINT involves intercepting signals mid-course in the electromagnetic spectrum, SIGINT has involved to incorporate intercepting signals at rest, that is, digitally stored in information systems, which are, of course, in the cyber domain.
Starting point is 00:13:45 In this context, cyber warfare is similar to other warfare areas. For example, intelligence supports air warfare, and air warfare provides a platform from which intelligence can gain collections. Marine Corps Captain Jesse Thompson expressed this frustration in his 2018 Proceedings article, Focus on Offensive Cyberspace Operations. He explained that the confused intermingling of CO and intelligence, and the attempt to have cyber mission teams act as SIGINT teams, has hindered the development of OCO doctrine and tactics. So you can see through this and the previous examples that I've shared here today, the nuanced distinction between cyberspace operations as its own discipline and as an enabler of other disciplines.
Starting point is 00:14:35 You hinted the challenges for operators trying to integrate into their own service culture outside of U.S. cyber, which reminds me of an editorial by a Space Force officer in which he proposes leaving the OCO and DCO airmen under the Air Combat Command and moving the IT airmen to the Air Force Installation and Mission Support Center. Would you like to weigh in on his underlying assumption that the Dodin ops workforce is necessarily separate and distinct from the OCO and DCO workforce? So I did read that article that the colonel wrote as a Space Force officer, And I disagree with his premise. As you explained, he insisted that Doden Ops, which he defined as IT services, is separate and distinct from OCO and DCO. But in my conclusion, I claimed those who exploit a domain and operate in it consistently are better poised for success than those who exploit both or operate in both. so i'll ask the rhetorical question here who knows how to attack a vulnerable system more than the
Starting point is 00:15:38 expert in the securing of the system and keeping it patched the maintenance of it is one line of defense in the defense in depth strategy if we have individuals that are highly knowledgeable on their specific systems and how their organization their unit their command uses these systems and you want to attack those systems who knows better where the vulnerabilities are that are still being worked out is the person who is in fact defending it. As another perspective, consider if there is some major cybersecurity incident on the network and the DoD deploys a cyber protection team, a CPT, to go respond to it. The network administrator by default has the mindset, are you crazy? You want a domain admin account on my network? You don't understand my
Starting point is 00:16:27 organization, you just showed up because of higher authority orders to do so. That is, you showed up to help us. So help us. We can help avoid these conflicts between the IT service providers doing dotan ops and the DCO teams, especially the more advanced teams that do the major incident responses. If there is already a synergistic link between them, a common background to say, hey, yes, we are all in the same family. Yes, I know I'm on a CPT, but I have been an admin before at a different place. And I understand your perspectives as a domain admin for protecting the integrity of your network for your organization's mission. Your suggestions for improving the service's deconfliction and realignment of cyber specialties
Starting point is 00:17:16 is all driven by one clear guiding light, the focus on the warfighter. Why is this? I've found in the years of service that I've had and many sailors that I've interacted with that sailors want to do their jobs well, and they want to have a sense of accomplishment for having done their jobs well and in contributing to their units and our national defense. When we detail our sailors to cyber jobs, they strive to learn the intricacies of the cyber domain and do a good job there, which is good. A couple of years later, we detail them to a signal-related job, where they strive to learn the intricacies of the electromagnetic spectrum and to do a good job there, too, which is good. That's what we expect. But then we detail
Starting point is 00:18:03 them back to the cyber job and expect them to do well in a cyber domain because they've been there before. But the state of the art in the cyber domain has changed a lot in the two or three years when they were doing their signal job. So given those circumstances, I'll ask, are we setting up our sailors for engendering job satisfaction when we don't give them the requisite time to hone their skills in a domain throughout their career? You noticed that you bring back the radio man rating. Where did that come from and why is it important to you? Through my tours as an IP officer, both afloat and ashore at the NCTS, information systems technicians, I worked with them. Some were great at understanding the cyber
Starting point is 00:18:52 domain. Some were great at understanding the electromagnetic spectrum, and they could tune radios all day, and it'd be great. Others, relatively few others, had a good mastery of both. And I saw that struggle and that challenge internally within my sailors. They saw that in order to do well on their advancement exam, they had to do well at both. And often they didn't have the career experience to do well at both because with the what we call the push button advancement, because they're highly technical ratings, they get advanced more quickly than non-technical ratings. And before they know it, they're already a first class petty officer and they've only had cyber tours or a cyber tour or they've only had a signal related tour. There's a potential that sailors could self assess as being inadequate for the job or for the career field because they haven't had both experiences. But at the same time, I don't want to say that because that's not the case with everybody. And I don't want to bring anybody down by a comment like that. Does that make sense?
Starting point is 00:20:05 That does. And I think there's something that's going on with entry-level cybersecurity jobs everywhere. Imposter syndrome is a big thing, that that's not unique or exclusive to civilian organizations and that that happens at the military entry level as well. Yes, it certainly can. especially in highly technical fields where the Navy expects mastery from someone who's rating is the information systems technician. So because there's two domains there, an entire palette or spectrum of possible functions
Starting point is 00:20:42 to be executed within each of those domains, I thought it best to separate them again from the information system technician. And in order to do that, the most sensible way would be to reestablish the Radioman rating. I know that from several with whom I've worked personally, usually they're senior enlisted that started out as Radioman, have always not appreciated being an information systems technician. There's a lot of pride there. Absolutely. Yes. Yes, there is. Can you tell us a bit about what current professional projects you have coming up? Yes, certainly. Been working with a few other officers in the CW, IP, and CWE communities on a bottom-up effort to bring this proposal into reality. We've received a lot of feedback from junior officers so far across these three communities and have recently been socializing it at the 05 and 06 level.
Starting point is 00:21:39 Of course, we don't know where this effort will go, but with the likelihood of Congress, that is in the House version of the FY23 NDAA draft, the likelihood of Congress directing the Navy to create a cyber officer designator, an enlisted rating, we are hoping to shape the discussion on cyber warfare and signal warfare organization so as to help all of us be prepared with a potential solution in hand. if and or when this provision becomes law. Separately, Vice Admiral Aschbach, she's the commander of Navy Information Forces. She recently announced that, quote, billet level analysis is ongoing to support improved training, specialization tracks, and the establishment of a cyber designator and enlisted cyber rating. I will be sure to provide updates as they are available, end quote. And that was in a recent communique to the information warfare community.
Starting point is 00:22:41 Thank you, Commander Landis, for joining us today. And to our listeners, thanks for tuning back in to Sea Control. Thank you. Help me, Paul, I'm put in the alley. Put it out and ship them all out.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.