For years, cyber professionals, researchers, military and elected officials on the front lines have asked for a clear definition as to just what cyber actions constitute an act of war. Recently, calls for a definition have increased and become more public.

The Senate Armed Services Committee decided to include a cybersecurity "act of war" requirement in the fiscal 2017 defense authorization bill. The requirement calls for the president to "develop a policy for determining when an action carried out in cyberspace constitutes an act of war against the United States."

This is tricky, because, as one source explained, this requirement would lock the country into a specific definition and that could be dangerous. And she's right. Given the pace of change within the global digital environment, any definition must be broad enough or vague enough to include all the scenarios that will undoubtedly accompany all of the rapidly evolving technologies like the Internet of Things, connected vehicles, wearable technology, and robotics – just to name a few.

But the last thing the United States needs to do is draw a line that gets crossed and there be no consequences. A line in the sand is not helpful. Another aspect to consider is that if a line is drawn, adversaries such as criminals, terrorists and rogue nation-states may launch attacks right up to that line without crossing it.

While these are all interesting discussions, the big question on many people's minds is this: What prompted the increased level of discussion at this time?

Share:
More In Net Defense Blogs