Defense lawyers sought legal path to launch information attacks without declaring war

By Harlan Pryce ·

Sovereignty was treated as a hurdle to be bypassed in a 1999 effort to sanitize digital intrusions, leaving the exact laws the military decided to ignore still blacked out.

In November 1999, the Office of General Counsel for the Department of Defense produced a document that attempted to draw a map for the coming century of conflict. It was not a tactical manual or a deployment order, but a legal assessment. The file's catalogue entry records that this second edition of the report focused on the international legal issues surrounding "information operations."

For the military, the term "information operations" is not a vague nod to public relations. According to the public record, these are integrated actions taken to affect an adversary's information and systems while defending one's own. This includes a toolkit of electronic warfare, computer network operations, psychological operations, military deception, and operations security. It is the art of manipulating the environment so the enemy sees what you want them to see, or sees nothing at all.

Information Attack

The catalogue description of the 1999 assessment highlights a specific, nested hierarchy of aggression. The introduction to the document notes that "information operations includes information attack which, in turn, includes computer network attack."

This linguistic nesting is significant. By placing "computer network attack" inside the broader category of "information attack," the Department of Defense was categorizing the act of hacking, disrupting, or destroying digital infrastructure not as a fringe technical activity, but as a formal instrument of military force. It transforms a line of code into a weapon system.

When a state defines a digital intrusion as an "attack," it is usually searching for a legal justification to do one of two things: to launch such an attack without triggering a formal declaration of war, or to justify a kinetic response to a digital provocation. The 1999 assessment was the effort to find where those lines were drawn in the sand.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

Domestic and International Treaties

The file's catalogue entry states that the assessment went on to "consider the implications of a variety of domestic and international laws and treaties with regard to information operations."

Which treaties? The summary does not say. Which domestic laws were viewed as hurdles—or as permissions? The record is silent on the specifics. However, the timing is telling. In 1999, the world was adjusting to a post-Cold War reality where the primary threats were no longer monolithic blocs, but fragmented networks and non-state actors. The US was already pivoting toward the "critical infrastructures" mentioned in other reports from that era, such as the 1997 report by the President's Commission on Critical Infrastructure Protection.

The challenge for the General Counsel was likely the definition of sovereignty. Traditional international law is based on borders—lines on a map that separate one jurisdiction from another. A computer network attack ignores those lines. It originates in one hemisphere, bounces through servers in a third, and strikes a target in a second. To conduct these operations "legally," the Department of Defense had to reconcile the physical reality of the nation-state with the borderless reality of the internet.

November 1999

That this document was a "Second Edition" suggests that the first attempt to codify the legality of information attacks was insufficient. The rules were being rewritten in real-time. The military was not merely observing the digital revolution; it was attempting to colonize it with a legal framework that would allow for maximum flexibility.

This effort to sanitize the "attack" through legal assessment is a recurring theme in US operations. Related files held by the National Security Archive and the State Department's FRUS volumes—such as memos regarding special operations and the emergence of new threats—show a consistent pattern of the US government seeking to define the boundaries of "acceptable" covert action just before expanding them.

By framing the disruption of foreign networks as a legal question of "information operations," the state moves the conversation away from the morality of aggression and toward the technicality of compliance. It is the process of turning a violation of sovereignty into a permissible operational procedure.

We do not have the specific legal conclusions reached by the Office of General Counsel in this 1999 assessment. We only have the record that they were searching for them. The document leaves open the most critical question: which international laws did the Department of Defense decide were obstacles, and which did they decide could be bypassed through a change in definition?