JCS and the 1999 Shield for Offensive Cyber-Ops
By Miriam Adler ·
While the Joint Chiefs established a public rulebook for digital security, secret cables to North Korea and Afghanistan show the real war was already being fought in the shadows.
The cost of a secure line is the blindness of the person on the other end. When the state masters the art of information assurance, the casualty is not a piece of hardware, but the sovereignty of whoever believes their secrets are safe.
In August 1999, the Joint Chiefs of Staff—the body of the most senior uniformed leaders within the United States Department of Defense, which advises the president and the secretary of defense on military matters—published a guide to the rules of the digital road. What survives of this record is a catalogue description rather than the original pages. This description establishes that the document was designed "to highlight the legal, regulatory, policy, organizational, technical, and threat issues associated with IA and to serve as a reference document." It is an unclassified manual, a textbook for the bureaucracy, divided into chapters on policy, doctrine, and standards.
On its face, it is a manual for defense. But the timing of its release, when laid against the secret traffic of the same summer, suggests it was actually a map for an offense.
"A Reference Document"
The manual claims to address "threat issues," but it does so in the vacuum of an unclassified environment. The record shows the document covers "legal and regulatory" considerations, establishing a sterile baseline for how the military handles data. This is the public face of the Joint Chiefs of Staff, presented as a transparent exercise in administrative hygiene.
However, the desk's reading is that this manual provided a sanitized legal baseline for defensive information assurance to provide a veneer of regulatory compliance for concurrent, classified offensive cyber operations. By publishing a set of "unclassified" rules for how the military protects its own data, the Joint Chiefs created a bureaucratic firewall. If the military's official doctrine is purely defensive and regulatory, any offensive operation conducted in the dark is not a violation of policy—it is simply a separate, unrecorded activity.
Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu
North Korea and the Ariana Gap
The contrast becomes stark when you look at what the Joint Chiefs were not writing about in their reference manual. While the manual discussed "threat issues" in generic terms, the National Security Council—the president's primary forum for coordinating foreign policy and national security—was holding Secret meetings on July 21, 1999, specifically focused on North Korea, the isolated state under the Kim dynasty whose nuclear and cyber-capabilities were a priority for the administration.
Ten days after that meeting, the CIA's Office of Transnational Issues—the arm of the CIA tasked with tracking non-state actors and cross-border threats—was filing intelligence reports on Ariana Afghan Airlines, the state-owned carrier of Afghanistan, which the intelligence community monitored for clandestine activities. By August 4, the State Department was exchanging Secret cables regarding the noncommittal nature of requests from that same airline.
The connection is a matter of synchronization. In the same window that the Joint Chiefs were publishing a generic guide to "Information Assurance," the intelligence community was engaged in hyper-specific, clandestine monitoring of assets in North Korea and Afghanistan. The manual’s broad thematic scope is a deliberate decoupling. The pattern suggests the "threat issues" section was kept intentionally generic to separate formal military doctrine from the high-priority targets then occupying the CIA and the National Security Council.
August 1999
The summer of 1999 was a pivot point for the American security state. The Joint Chiefs were pushing a 4th edition policy manual for digitalization just as the field operators were bypassing those very policies to maintain operational security. On September 7, 1999, the U.S. Embassy in Jakarta was sending a 17-page Secret situation report on East Timor, the territory fighting for independence from Indonesia that was gripped by violent unrest. By September 15, the administration was conducting a Senior Executive Intelligence Briefing on matters that never touched the "standards and technology" outlined in the JCS manual.
This is the irony of the record: the only unclassified document in this stream of intelligence is the one that tells us how the military handles information. The Joint Chiefs of Staff were defining the rules of the house while the CIA and State Department were operating in the street.
If this file is shaped the way it looks, the "organizational considerations" chapter in the JCS manual is a fiction. It treats information assurance as a bureaucratic function of the Department of Defense, omitting the actual mechanisms of intelligence sharing between the military and the clandestine services. The manual presents a world of checklists and regulatory compliance, but the accompanying cables from Jakarta and Kabul describe a world of raw power and secret intercepts. The manual describes the fence; the cables describe the people climbing over it.
The Hidden Annex
Military reference documents are rarely complete in their unclassified forms. They are built as a core of public rules supported by classified annexes—the "exceptions" where the rules are waived for national security imperatives. The JCS manual lists "legal and regulatory" considerations, but it does not list the legal justifications for breaching the information assurance of a foreign state carrier or a nuclear-armed regime.
The desk's reading is that the withheld or redacted portions of the full release contain these exception protocols. These are the pages that authorize the military to ignore the very standards of "assurance" they preach to the public. The manual serves as the shield; the annexes are the sword.
This document represents a pivot toward a digitalization that the intelligence community was already bypassing via clandestine means in the field. The Joint Chiefs were building a digital fortress for the record, while the CIA was already inside the walls of its targets. The manual was not written to secure the network; it was written to ensure that when the offensive operations were eventually discovered, the military could point to a published, unclassified manual and claim they were following a defensive doctrine.
The pattern is clear. The Joint Chiefs of Staff created a public-facing regulatory environment to mask a private-facing operational reality. The people who paid for this were the targets of those early cyber-interventions in North Korea and Afghanistan—nations that were breached while the U.S. military was busy publishing a manual on how to follow the rules. A full release of the classified annexes would show that the "standards" of 1999 were never meant to be universal; they were meant to be a cloak.
Sources
- Joint Chiefs of Staff,Information Assurance: Legal Regulatory, Policy and Organizational Considerations, 4thedition, August 1999. Unclassified. — National Security Archive (GWU)
- Document PDF (Joint Chiefs of Staff,Information Assurance: Legal Regulatory, Policy and Organizational Considerations, 4thedition, August 1999. Unclassified.)
- Background: Joint Chiefs of Staff — Wikipedia