Operational Collaboration
   HOME

TheInfoList



OR:

Operational collaboration is a
cyber resilience Cyber resilience refers to an entity's ability to continuously deliver the intended outcome, despite cyber attacks. Resilience to cyber attacks is essential to IT systems, critical infrastructure, business processes, organizations, societies, and ...
framework that leverages public-private partnerships to reduce the risk of cyber threats and the impact of
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
s on United States
cyberspace Cyberspace is an interconnected digital environment. It is a type of virtual world popularized with the rise of the Internet. The term entered popular culture from science fiction and the arts but is now used by technology strategists, security ...
. This operational collaboration framework for cyber is similar to the
Federal Emergency Management Agency The Federal Emergency Management Agency (FEMA) is an agency of the United States Department of Homeland Security (DHS), initially created under President Jimmy Carter by Presidential Reorganization Plan No. 3 of 1978 and implemented by two Exec ...
(FEMA)'s National Preparedness System which is used to coordinate responses to natural disasters, terrorism, chemical and biological events in the physical world. Operational collaboration is one of the six pillars of recommendations put forward by the United States Cyberspace Solarium Commission (CSC) for a strategy of layered cyber
deterrence Deterrence may refer to: * Deterrence theory, a theory of war, especially regarding nuclear weapons * Deterrence (penology), a theory of justice * Deterrence (psychology) Deterrence in relation to criminal offending is the idea or penology, t ...
. The CSC was established in the John S. McCain National Defense Authorization Act for Fiscal Year 2019 to "develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences.""Cyberspace Solarium Commission Final Report". ''United States Cyberspace Solarium Commission''. March 2020. Significant work on the development of an Operational Collaboration Framework has also been done by the Aspen Cybersecurity Group, a cross-sector public-private forum composed of government officials, industry-leading experts, and academic and civil leaders organized by the
Aspen Institute The Aspen Institute is an international nonprofit organization founded in 1949 as the Aspen Institute for Humanistic Studies. It is headquartered in Washington, D.C., but also has a campus in Aspen, Colorado, its original home. Its stated miss ...
. In the US, cyber defense under
President Biden Joseph Robinette Biden Jr. (born November 20, 1942) is an American politician who was the 46th president of the United States from 2021 to 2025. A member of the Democratic Party, he served as the 47th vice president from 2009 to 2017 and re ...
has increasingly taken an operational collaboration approach, following a number of large-scale cyberattacks on US federal agencies and businesses including Solar Winds and the Microsoft Exchange hacks. Homeland Security Secretary
Alejandro Mayorkas Alejandro Nicolas Mayorkas (born November 24, 1959) is an American attorney and government official who was the seventh United States secretary of homeland security, serving from 2021 until 2025. A member of the Democratic Party, Mayorkas previ ...
,
Cybersecurity and Infrastructure Security Agency The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the United States Department of Homeland Security (DHS) responsible for cybersecurity and infrastructure protection across all levels of government, coordinating cyber ...
(CISA) Director
Jen Easterly Jen Easterly is an American cybersecurity expert and former government official who served as the Director of the Cybersecurity and Infrastructure Security Agency in the Biden administration. She was confirmed by a voice vote in the Senate on Jul ...
, National Cyber Director Chris Inglis and other officials met with executives from 13 companies, including
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
, networking vendor
Juniper Networks Juniper Networks, Inc. is an American multinational corporation headquartered in Sunnyvale, California. The company develops and markets networking products, including Router (computing), routers, Network switch, switches, network management so ...
and security firm Mandiant. Mayorkas stated at that time: "This is about taking a spirit of partnership and moving into actual operational collaboration." Recent operational collaboration initiatives under the Biden administration include CISA's new Joint Cyber Defense Collaborative, a forum for cooperative cyber defense planning with companies at the heart of operating and securing the internet's infrastructure. Also, the
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
's new Cybersecurity Collaboration Center, a new platform stood up in the summer of 2021 for public-private cyber threat intelligence sharing on adversaries targeting the National Security System (NSS), Department of Defense (DoD) and Defense Industrial Base (DIB).


Overview

Security weaknesses in the
computer network A computer network is a collection of communicating computers and other devices, such as printers and smart phones. In order to communicate, the computers and devices must be connected by wired media like copper cables, optical fibers, or b ...
s that run
critical infrastructure Critical infrastructure, or critical national infrastructure (CNI) in the UK, describes infrastructure considered essential by governments for the functioning of a society and economy and deserving of special protection for national security. ...
sectors—banking, energy, healthcare, telecommunications, shipping, and more—allow sophisticated actors to attack and disrupt essential elements of society. Many of these sectors depend on the others to function. These interdependencies create a systemic cyber risk where a large-scale attack on one sector could trigger a
cascading failure A cascading failure is a failure in a system of interconnection, interconnected parts in which the failure of one or few parts leads to the failure of other parts, growing progressively as a result of positive feedback. This can occur when a singl ...
in other key sectors, potentially resulting in significant destabilizing effects on public health, public safety, economic security or national security. Because this systemic cyber risk is shared across public and private entities, an operational collaboration framework is needed to coordinate action between government and industry to secure cyberspace. Operational collaboration builds on past progress with information sharing to plan and execute public-private actions to create a strategic deterrent and defend US cyberspace.


History

The concept of operational collaboration originated in the
financial services Financial services are service (economics), economic services tied to finance provided by financial institutions. Financial services encompass a broad range of tertiary sector of the economy, service sector activities, especially as concerns finan ...
sector with the establishment of the Financial Systemic Analysis & Resilience Center (FSARC) in 2016. The FSARC is a subsidiary of the Financial Services Information Sharing and Analysis Center (FS-ISAC). It was established to deepen public-private collaboration between U.S. financial institutions and government agencies to improve the resilience of the critical functions that underpin the financial sector. The FSARC was initiated by eight large U.S. banks –
Bank of America The Bank of America Corporation (Bank of America) (often abbreviated BofA or BoA) is an American multinational investment banking, investment bank and financial services holding company headquartered at the Bank of America Corporate Center in ...
,
BNY Mellon The Bank of New York Mellon Corporation, commonly known as BNY, is an American international financial services company headquartered in New York City. It was established in its current form in July 2007 by the merger of the Bank of New York an ...
,
Citigroup Citigroup Inc. or Citi (Style (visual arts), stylized as citi) is an American multinational investment banking, investment bank and financial services company based in New York City. The company was formed in 1998 by the merger of Citicorp, t ...
,
Goldman Sachs The Goldman Sachs Group, Inc. ( ) is an American multinational investment bank and financial services company. Founded in 1869, Goldman Sachs is headquartered in Lower Manhattan in New York City, with regional headquarters in many internationa ...
,
JPMorgan Chase JPMorgan Chase & Co. (stylized as JPMorganChase) is an American multinational financial services, finance corporation headquartered in New York City and incorporated in Delaware. It is List of largest banks in the United States, the largest ba ...
,
Morgan Stanley Morgan Stanley is an American multinational investment bank and financial services company headquartered at 1585 Broadway in Midtown Manhattan, New York City. With offices in 42 countries and more than 80,000 employees, the firm's clients in ...
, State Street and
Wells Fargo Wells Fargo & Company is an American multinational financial services company with a significant global presence. The company operates in 35 countries and serves over 70 million customers worldwide. It is a systemically important fi ...
. It facilitates operational collaboration between financial institutions and U.S. government partners in the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
,
Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior, home, or public security ministries in other countries. Its missions invol ...
, and the Department of Treasury."New Financial System Analysis & Resilience Center Formed". ''Dark Reading.'' October 24, 2016. Together, they conduct analysis of critical financial sector systems and jointly monitor and warn against threats to those systems. JPMorgan's Greg Rattray was the main driver of the operational collaboration concept, and he served as the FSARC's Co-President alongside Bank of America's Siobhan MacDermott when the center was first established.


Mission Areas

Operational collaboration should occur in five mission areas: Protect, Mitigate, Prevent, Respond and Recover. This is similar to the National Preparedness System established under Homeland Security Presidential Directive-8 that is used to coordinate responses to
natural disaster A natural disaster is the very harmful impact on a society or community brought by natural phenomenon or Hazard#Natural hazard, hazard. Some examples of natural hazards include avalanches, droughts, earthquakes, floods, heat waves, landslides ...
s,
terrorism Terrorism, in its broadest sense, is the use of violence against non-combatants to achieve political or ideological aims. The term is used in this regard primarily to refer to intentional violence during peacetime or in the context of war aga ...
,
chemical emergencies A chemical accident is the unintentional release of one or more hazardous chemicals, which could harm human health and the environment. Such events include fires, explosions, and release of toxic materials that may cause people illness, injury, or ...
in the physical world. As the linkage between the cyber and physical realms increases, using similar organizing constructs for both environments would make coordination between the two realms more seamless. * ''Steady state'': The Protect, Mitigate, and Prevent missions constitute the collaboration areas in a "steady state" environment or the normal operating state of the world. * ''Incident Response'': When a cyber incident occurs that has a broad impact on our
digital ecosystem A digital ecosystem is a distributed, adaptive, open socio-technical system with properties of self-organization, scalability and sustainability inspired from natural ecosystems. Digital ecosystem models are informed by knowledge of natural ec ...
(whether from a national security, economic, or public health and safety point of view), then the action shifts to the Response and Recovery missions.


Protect and Mitigate

Relevant actors collaborate to raise the level of cybersecurity across the digital ecosystem and to mitigate the potential impact of cyber threats. Key activities include risk management to identify critical systems and lower risk appropriately, addressing vulnerabilities, developing and sharing information and intelligence on emerging threats, developing a deep understanding of threats and the ability to warn of attacks, implementing cybersecurity best practices, conducting research on interdependencies, establishing contingency plans, and conducting exercises.


Prevent

Relevant actors synchronize actions to disrupt the activities of malicious cyber actors prior to and outside of a response to a specific incident. Key activities include exposing malicious cyber campaigns publicly,
botnet A botnet is a group of Internet-connected devices, each of which runs one or more Internet bot, bots. Botnets can be used to perform distributed denial-of-service attack, distributed denial-of-service (DDoS) attacks, steal data, send Spamming, sp ...
take-downs, law enforcement actions against companies,
economic sanctions Economic sanctions or embargoes are Commerce, commercial and Finance, financial penalties applied by states or institutions against states, groups, or individuals. Economic sanctions are a form of Coercion (international relations), coercion tha ...
, and other cyber and non-cyber government counter measures against malicious cyber actors. Private sector actors will only operate on their own networks; government actors may conduct offensive cyber operations on other networks to prevent and deter attacks, when appropriate.


Respond and Recover

The relevant actors are responding to and/or recovering from an incident that is either on-going or has already occurred. Progress has been made in this mission area, including improved information sharing to ensure that adversary tactics, techniques, and procedures (TTPs) have a limited effective lifespan and the development of plans and policies such as the National Cyber Strategy,
Presidential Policy Directive National security directives are presidential directives issued for the United States National Security Council, National Security Council (NSC). Starting with Harry Truman, every president since the founding of the National Security Council in 1 ...
41 and the National Cyber Incident Response Plan. Key activities include rapidly identifying the incident's underlying cause, sharing and implementing effective defensive measures to contain or prevent further damage, and synchronizing specific response actions, such as dropping packets or re-routing traffic.


Examples

Trickbot takedown before the 2020 presidential election. Response to Solarwinds by FireEye/Mandiant + federal cyber defenders in early 2020 REvil ransomware takedown


References

{{reflist Cyberwarfare in the United States