Framework

The Center for Cybersecurity Policy and Law brings together leaders from government, industry, and the broader security community to advance policies that strengthen United States and allied cybersecurity while promoting legal clarity, strategic stability, and responsible Cyber Operations. While Cyber Defense remains an essential component of national cybersecurity, policymakers are increasingly confronting questions that extend beyond defending individual systems to the governance of Collective Cyber Operations involving government and the private sector.

As malicious cyber activity becomes more frequent, sophisticated, and integrated into geopolitical competition, policymakers are increasingly examining the legal, strategic, and operational frameworks that govern Cyber Operations. Questions surrounding Authorization, oversight, accountability, public-private coordination, international law, and international norms have become central to national security policy.

At the same time, the community involved in Cyber Operations remains fragmented. Government agencies, private-sector organizations, managed service providers, researchers, legal experts, and other stakeholders often engage policymakers independently, despite sharing common policy challenges. As a result, critical policy discussions risk becoming siloed, inconsistent, or disconnected from operational realities. This fragmentation can lead to inconsistent policy discussions and missed opportunities to develop informed, durable approaches.

The Cyber Operations Policy Coalition (COPC) will build on the Center’s established track record of convening diverse stakeholders to create a trusted, consensus-driven forum for engagement with U.S. and international policymakers. Coalition members will collaborate to inform policy development, clarify legal and regulatory frameworks, and promote approaches that enhance national security while supporting responsible and effective Collective Cyber Operations.

The coalition will focus on improving legal and policy frameworks, promoting responsible and lawful cyber operations, and ensuring policymakers have access to diverse operational, technical, and legal perspectives.

Mission & Purpose

The Cyber Operations Policy Coalition advances responsible, lawful, and strategically aligned approaches to Collective Cyber Operations by convening government and industry leaders to inform policy, strengthen public-private coordination, and improve the legal and governance frameworks that enable Cyber Operations in support of national security.

The coalition exists to help close the gap between rapidly evolving Cyber Capabilities and the policies that govern their use. It provides a structured forum where stakeholders can develop common perspectives, identify shared policy priorities, and engage constructively with policymakers.

Scope & Focus Areas

The coalition focuses exclusively on policy, governance, and legal frameworks related to Collective Cyber Operations.

Core areas of focus include:

  • Legal authorities, Authorization, and oversight
  • Public-private coordination
  • International norms and governance
  • Cyber Capability development and the policy environment supporting responsible use

The coalition does not engage in:

  • Operational planning or operational execution
  • Unlawful or reckless cyber responses to a cyber incident
  • Sharing operational techniques, vulnerabilities, or targeting information

Policy Agenda

The coalition's agenda will be established by its members and evolve alongside legislative, regulatory, and international developments.

Initial areas of focus may include:

  • Legal and regulatory clarity for Collective Cyber Operations
  • Public-private coordination frameworks
  • International engagement and norm development
  • Responsible use, oversight, and accountability
  • Policy issues affecting Cyber Capability development

Coalition Lexicon

TermCoalition DefinitionSource Basis
Cyber Operation(s)The use of cyber capabilities to cause cyber effects in or through cyberspace.Adapted from the current NATO CCDCOE-based definition of cyber operations. Integrated with the coalition’s recommended definitions of Cyber Capability and Cyber Effect.
Cyber CapabilityA tool, technique, service, system, or combination of software, firmware, hardware, or infrastructure used to create cyber effects.Adapted from Joint Publication 3-12. Revised to align with the recommended coalition definition of Cyber Effect. Broadened for a public-private policy context.
Cyber EffectAccessing, altering, disrupting, impairing, or destroying data, hardware, software, an information system, or a digital service in or through cyberspace.Adapted from the current NATO CCDCOE-based “effect” definition. Aligned with the existing lexicon’s treatment of cyber operations and cyber capability.
Collective Cyber OperationsCyber operations coordinated among multiple public and/or private entities to address a shared cyber threat or common cybersecurity objective.Coalition working definition adapted from CIS definition of “Collective Cyber Defense,” NATO description of cyber defence, and member feedback.
AuthorizationPermission granted to an individual, organization, system, or process to access, alter, impair, disrupt, or destroy data, hardware, software, an information system, or a digital service.Adapted from the NIST Glossary definition of authorization, revised based on feedback to cover activities beyond access, including alteration, impairment, disruption, and destruction.
Cyber DefenseActions taken in or through cyberspace to prevent, detect, disrupt, respond to, mitigate, or recover from malicious cyber activity that has caused, or threatens to cause, cyber effects without authorization.Coalition working definition adapted from Joint Publication 3-12 definition of cyber defense and member feedback. This definition keeps the substance of defensive action but translates it into plainer language for the coalition’s audience.
Cyber AttackMalicious cyber activity that attempts to collect, disrupt, deny, degrade, manipulate, or destroy information system resources or the information itself.Following the NIST definition.
Cyber IncidentAn event that actually or imminently threatens the confidentiality, integrity, or availability of information or an information system, or that violates or threatens to violate law, security policies, security procedures, or acceptable use policies.Adapted from FISMA (44 U.S.C. 3552(b)(2)) definition.