Module C Primer 113-SCCCC01
Learning objective and standard
Learning objectiveIdentify the Cyberspace and Electromagnetic Activity module requirements and schedule
StandardIdentify the Cyberspace and Electromagnetic Activity module requirements and schedule by completing the following - Identify the topics being covered during the Cyberspace Electromagnetic Activity (CEMA) module in a clear and concise manner; without error. - Identify the Cyberspace Electromagnetic Activity (CEMA) module schedule in a clear and concise manner; without error.
The administrative front door to Module C, and the one place the module's vocabulary is laid out in a single list. The primer sets three blocks of instruction - CEMA Basics, Cybersecurity, and CEMA in LSCO and Multinational Operations - and then front-loads the definitions those three blocks assume you already know. Learn the definitions here and the three lessons that follow become much easier, because each one opens by using them rather than teaching them. The primer also carries the two things a student can fail on before instruction even starts: the JKO courses that must be complete before 113-SCCCC03, and 138 pages of assigned reading.
Doctrinal sets to know cold
The three blocks of instruction in Module C
- CEMA Basics - doctrine, definitions, planning, threat capabilities, and electromagnetic protection TTPs
- Cybersecurity - the cyberspace half of CEMA and the BN S6 role in defending it
- CEMA in LSCO and Multinational Operations - interoperability and signal support to coalition formations
What CEMA is comprised of
- Cyberspace operations
- Electromagnetic warfare
- Spectrum management operations
The five domains
- Land
- Maritime
- Air
- Space
- Cyberspace
The three dimensions of the operational environment
- Physical
- Information
- Human
Module C read-ahead sources (138 pages)
- FM 3-0, Chapter 6
- FM 3-12, Chapter 1
- FM 6-02, Appendix A
- Defense of Battle Position Duffer - the first three dreams
- CALL Command Post Survivability
- CALL Pacific Theater Insights
- Ukraine Battalion Commander Interview
- Training for Electromagnetic Spectrum Dominance: Preparing the US Army for Future Conflicts
Where Module C knowledge is assessed
- Practical exercises throughout the module
- The Mission Command Exercise
- The Signal Branch Specific Comprehensive Exam
- The Capstone assessment
- Minimum passing score on all assessments: 70 percent
Key terms
- Cyberspace Electromagnetic Activities (CEMA)
- The process of planning, integrating, and synchronizing cyberspace operations and electromagnetic warfare operations in support of unified land operations. (FM 3-12) CEMA is a process, not a capability - it is how the staff ties together cyberspace operations, electromagnetic warfare, and spectrum management operations.
- Cyberspace operations
- The employment of cyberspace capabilities where the primary purpose is to achieve objectives in or through cyberspace. Also called CO. The Module C primer attributes this definition to JP 3-0.
- Spectrum management operations (SMO)
- The interrelated functions of spectrum management, frequency assignment, host-nation coordination, and policy that together enable the planning, management, and execution of operations within the electromagnetic operational environment during all phases of military operations. (FM 6-02)
- Electromagnetic interference (EMI)
- Any electromagnetic disturbance, induced intentionally or unintentionally, that interrupts, obstructs, or otherwise degrades or limits the effective performance of electromagnetic spectrum-dependent systems and electrical equipment. (JP 3-85) The phrase "or unintentionally" is what separates EMI from electromagnetic attack.
- Interoperability
- 1. The ability to operate in synergy in the execution of assigned tasks. (JP 3-0) 2. The condition achieved among communications-electronics systems or items of communications-electronics equipment when information or services can be exchanged directly and satisfactorily between them and/or their users. (JP 6-0)
- Liaison
- That contact or intercommunication maintained between elements of military forces or other agencies to ensure mutual understanding and unity of purpose and action. (JP 3-08)
- Mission Partner Environment (MPE)
- A capability framework that improves partner information-sharing, data exchange and integrated execution through common standards governance and agreed-to procedures. MPE supports commanders' execution of critical joint warfighting functions: C2, information, intelligence, fires, movement and maneuver, protection, and sustainment. (DoDI 8110.01)
- Large-scale combat operations (LSCO)
- Extensive joint combat operations in terms of scope and size of forces committed, conducted as a campaign aimed at achieving operational and strategic objectives. LSCO is the operating context Module C assumes throughout - every CEMA problem in the module is posed against a peer threat, not a permissive environment.
- Domain
- A physically defined portion of an operational environment requiring a unique set of warfighting capabilities and skills. The five domains are land, maritime, air, space, and cyberspace. Module C's first group task is to define all five and explain how the cyberspace domain interacts with the other four.
- Dimensions of the operational environment
- The three dimensions are physical, information, and human. Module C's second group task is to define the three and explain how cyberspace interacts with them - cyberspace is unusual in that it is a domain running through all three dimensions at once.
- Read ahead
- Assigned reading that must be complete before instruction, not a reference to consult afterward. Module C assigns 138 pages across eight sources, including chapter extracts from FM 3-0, FM 3-12, and FM 6-02.
Testable points
- Module C is Cyberspace and Electromagnetic Activities (CEMA). Its stated purpose is to give company grade Signal officers a working understanding of CEMA capabilities and how they are incorporated into planning and operations.
- The module has three blocks of instruction: CEMA Basics, Cybersecurity, and CEMA in LSCO and Multinational Operations.
- Students must score at least 70 percent on all assessments to pass the module.
- Module C knowledge is assessed in four places, not one: the practical exercises, the Mission Command Exercise, the Signal Branch Specific Comprehensive Exam, and the Capstone.
- Two JKO courses must be complete before 113-SCCCC03: J3O P-US1277 and J3O P-US1278. Both cover the Mission Partner Environment, which is why MPE appears in the primer's key terms.
- The read-ahead requirement is 138 pages total across eight sources.
- Read-ahead sources include FM 3-0 Chapter 6, FM 3-12 Chapter 1, FM 6-02 Appendix A, Defense of Battle Position Duffer (the first three dreams), CALL Command Post Survivability, CALL Pacific Theater Insights, the Ukraine Battalion Commander Interview, and Training for Electromagnetic Spectrum Dominance.
- The module's risk assessment level is Low, with no major safety considerations and no environmental considerations.
- CEMA is a process of planning, integrating, and synchronizing. The definition names three verbs and none of them is "executing" - the S6 integrates, and the S3 formalizes.
- CEMA covers cyberspace operations and electromagnetic warfare operations. Spectrum management operations is the third leg the module treats alongside them.
- Cyberspace is a domain, not a synonym for the Internet. The JP 3-12 definition explicitly includes telecommunications networks, computer systems, and embedded processors and controllers - which is why tactical radios are inside cyberspace, not adjacent to it.
- Interoperability has two doctrinal definitions in the primer, from JP 3-0 and JP 6-0. The JP 3-0 sense is about operating in synergy; the JP 6-0 sense is about systems exchanging information satisfactorily.
- MPE is defined in DoDI 8110.01, not in an Army field manual - a reminder that multinational information sharing is governed at the DoD level.
- The MPE definition names seven joint warfighting functions it supports: command and control, information, intelligence, fires, movement and maneuver, protection, and sustainment.
- The module reference list spans Army, joint, and DoD publications, including ADP 3-37, AR 25-1, AR 25-2, AR 380-5, ATP 3-12.3, FM 3-0, FM 3-12, FM 6-02, JP 3-12, JP 3-85, and the DoD 8140 and 8500 series.
- The module reference list cites FM 3-0 dated 21 March 2025 - the current edition - so Module C is anchored to current operations doctrine rather than the 2022 version.
- Three of the primer's group tasks preview the whole module: define the five domains and the three dimensions; define six cyberattack vectors and describe five cyberattacks; and identify multinational problems in CNR, network, and command post operations.
- The CEMA Planning Exercise runs across the back half of the module schedule and is the practical assessment that ties the three teaching blocks together.
- The schedule includes a lesson on EMS Signature Reduction in a Tactical Environment. No deck for it sits in the Module C files - the lesson is 113-SCCCE11, and it is taught on this site under Module E, where both released versions of the deck were read in on 2026-09-09. It is no longer reachable only through the CEMA Basics electromagnetic protection material.
References
FM 3-0FM 3-12FM 6-02JP 3-0JP 3-12JP 3-85DoDI 8110.01
CEMA Basics 113-SCCCC10
Learning objective and standard
Learning objectiveDefine the concepts of Cyberspace Electromagnetic Activities (CEMA) as a BN S6 in Large Scale Combat Operations (LSCO)
StandardDefine the following concepts of Cyberspace Electromagnetic Activities (CEMA) as a BN S6 in Large Scale Combat Operations (LSCO) to include the following: Define the operational framework in a clear and concise manner, without error. Define cyberspace and CEMA in a clear and concise manner, without error. Employ CEMA planning considerations in a clear and concise manner, without error. Identify potential adversarial electromagnetic warfare and cyberspace capabilities in a clear and concise manner, without error. Produce electromagnetic protection tactics, techniques, and procedures in a clear and concise manner, without error.
The longest lesson in Module C and the one carrying most of its testable weight. It moves in five steps: what the battlefield looks like in LSCO, what cyberspace and CEMA actually are, who plans CEMA and where it enters MDMP, what Chinese and Russian electromagnetic warfare can do to you, and what you do about it. The through-line is a single uncomfortable claim: at battalion level, the S6 is responsible for all of CEMA. There is no CEMA cell below brigade, so the coordination that a division staff distributes across a section is one officer's job. Learn the numbers in the operational framework, the three layers of cyberspace, the four buckets of S6 CEMA tasks, and the emissions arithmetic from the practical exercise - those four things account for most of what this lesson can ask.
Doctrinal currencyThe lesson's reference list and its own speaker notes disagree about which joint publication defines electromagnetic warfare, because the FM 3-12 text quoted in the notes predates the change. Both citations are on the same slide deck. Answer JP 3-85 unless a question quotes the FM 3-12 passage directly.
What this course teaches — answer this on the exam
- The CEMA Basics reference list includes both JP 3-13.1 Electronic Warfare (8 February 2012) and JP 3-85 Joint Electromagnetic Spectrum Operations (22 May 2020)
- The slide notes quote FM 3-12 paragraph 1-103, which attributes the electromagnetic warfare definition to JP 3-13.1
- The reference list also carries JP 1-02, DoD Dictionary of Military and Associated Terms, dated 31 October 2009
What the current publications say
- The lesson's own definition slides cite JP 3-85 for electromagnetic warfare, electromagnetic attack, and electromagnetic interference - that is the current source and the safer answer
- JP 3-85 (22 May 2020) superseded JP 3-13.1; the older publication's title also uses "electronic warfare" rather than the current term "electromagnetic warfare"
- The DOD Dictionary of Military and Associated Terms is no longer numbered JP 1-02; it is maintained as a standalone reference, so a JP 1-02 citation dates a document rather than pointing at anything current
Doctrinal sets to know cold
The operational framework by echelon - distance, planning horizon, and CP displacement
- Division: 20 to 40 km, 24 to 48 hour planning horizon, CPs displace every 24 to 48 hours
- Brigade: 5 to 25 km, 12 to 24 hour planning horizon, CPs displace every 12 to 24 hours
- Battalion: FLOT out to 10 km, 6 to 12 hour planning horizon, CPs displace every 6 to 12 hours
The three layers of cyberspace
- Physical network layer - geographic and physical network components, including the physical location of network elements
- Logical network layer - components related to one another in ways abstracted from the physical network
- Cyber-persona layer - the people who use the network and the identities that can be identified, attributed, and acted upon
The three components of CEMA
- Cyberspace operations
- Electromagnetic warfare
- Spectrum management operations
The four functions of spectrum management operations
- Spectrum management - planning, coordinating, and managing use of the electromagnetic spectrum
- Frequency assignment - requesting and issuing authorizations to use frequencies for specific equipment
- Host-nation coordination - coordinating with sovereign nations for spectrum use by US forces
- Policy - establishing and enforcing command policy on spectrum use in the area of responsibility
The three divisions of electromagnetic warfare and what falls under each
- Electromagnetic attack - jamming, directed energy, electromagnetic deception, chaff and decoys, and destructive means such as antiradiation missiles
- Electromagnetic protection - emission control, electromagnetic hardening, spectrum management, protection from enemy EW, protection from friendly EW
- Electromagnetic support - threat warning, direction finding, collection supporting EW
Staff sections with a stake in CEMA
- S6 - PACE, SMO, DODIN operations, information operations, task organization, battle rhythm, orders
- S2 - enemy assessment, detection assets, information collection
- Fires - target worksheets, target nominations, kill chain, target submissions
- Legal - law of armed conflict, rules of engagement, authorities, policy
- S3 - EMCON, command post locations, tasking, collection assets, restricted frequencies
CEMA in MDMP - mission analysis
- Identify systems vulnerable to CEMA denial
- Include enemy CEMA on the doctrinal, situation, and event templates
- Put enemy CEMA capabilities on the high-value and high-payoff target lists
- Ensure the information collection plan accounts for the CEMA threat in time and space
- Identify communications systems and capabilities by warfighting function
- Establish a method for tracking the status of each system and who is trained on it
- Communicate the CEMA threat to subordinates
- Analyze the terrain for line of sight, red and blue
CEMA in MDMP - course of action development, wargaming, and rehearsals
- COA development: account for enemy CEMA effects in COAs; determine lines of contact and integrate into PACE and targeting; identify enemy CEMA denial as an information requirement; align the information collection plan to find it
- Wargaming: enemy action includes CEMA denial; refine the information collection and PACE plans by warfighting function; refine the process to maintain COMSTAT; refine graphic control measures and the fires plan
- Rehearsals: include CEMA in the combined arms and fires rehearsals; current operations rehearses the react-to-jamming battle drill; rehearse COMSEC compromise; rehearse system compromise
The four buckets of S6 CEMA tasks and who supports them
- DODIN operations - user and device network access, COMSEC. Supported by the brigade cyber defense cell, helpdesk and NETOPS, the network enterprise center, upper tactical internet from the division signal battalion, the regional hub node, and key management
- Defensive cyberspace operations - maintaining compliance, reporting cyber events. Supported by the above plus the regional cyber center
- Spectrum management operations - requesting frequencies, creating and maintaining the communications card, spectrum authorization requests. Supported by the 25E spectrum manager, the host-nation FCC equivalent, and the regional hub node
- Electromagnetic warfare - EW team and asset management, electromagnetic deception, EMCON, mission analysis, SOPs, command post operations, PACE, communications security support. Supported by the above plus the CEMA cell
Chinese EW - the PLA combined arms brigade in depth
- Frontal blocking zone: hybrid RF jammer and direction-finding platforms disrupt enemy VHF and UHF communications while locating command and communications nodes
- Frontier defense zone: RF jammers disrupt precision-guided munition signals and target radar sensors and missile guidance systems
- Depth defense zone: multi-spectrum jammers target RF and electro-optical or infrared sensors using dazzling, spoofing, obscurants, and RF jamming, co-located with command posts, air defense, and artillery
- Four EW missions: RF communications jamming, radio direction finding, PGM jamming, sensor neutralization
Chinese strategic objectives
- Maintain internal security and stability
- Secure and protect land borders and coastlines
- Maintain regional stability
- Maintain freedom of navigation
- Resolve maritime territorial disputes
- Establish positive conditions for potential hostilities
Russian strategic objectives
- Regional dominance
- Protection and security
- Countering foreign interference
- Recognition as a world power
Techniques for minimizing emissions
- Establish communications and power windows
- Ensure that all transmissions are necessary
- Preplan messages before transmitting them
- Create, disseminate, and use prowords
- Transmit as quickly and precisely as possible
- Use an alternate means of communications when possible
- Use as little power as possible to still communicate
- Use concealment for equipment
- Use mobile antennas
- Use decoy antennas
- Use steerable null antenna processors
- Use electromagnetic deception methods
- Select a site and use obstacles that mask transmitted signals from enemy interception
- Select the proper antenna - shortest range that works, and directional if feasible
Defeating GPS jamming
- Encrypt your GPS receivers, for example the DAGR, which receives two GPS signals and is more resistant to jamming
- Watch for JAMMING DETECTED on the DAGR screen - the receiver is also a sensor
- Block the jamming signal with terrain, vehicles, buildings, or your own body
- Maintain traditional navigation skills - map and compass, distance and direction, dead reckoning, terrain association
- Develop a PACE plan
Duffer's cyber lessons - the first three dreams
- Commanders at all echelons are responsible for all domains, including cyberspace, within their areas of responsibility. Do not assume it is echelons above you
- Every device is a potential vulnerability - anything that emits a signature or processes software can become a staging area for enemy attack
- Anticipate, withstand, recover, evolve - anticipate attacks and prepare to detect them, work around and through problems, prepare and communicate recovery ahead of time, and adapt faster than the enemy
- A command post that gets destroyed is worse than useless
- Cell phones introduce a plethora of vulnerabilities; the commander must control their use
- Enemy forces will attack the vulnerable rear, including using social media against family members
- Social media is a key intelligence source, for the enemy and for the brigade
- In a high cyber threat environment, assume even the most secure networks may be penetrated; position location and automated features should not be trusted without verification
- Cell phones are emitters and present targets for enemy SIGINT and ELINT
- Command posts are vulnerable to detection even when small - survivability is the top priority, and better to have no TOC than a destroyed one
- The enemy will target personally identifiable information from deployed soldiers
- The C4 operations cell can do far more than enforce compliance, particularly on connections with allies and smaller partners
- Cell phones are everywhere whether you bring them or not; OPSEC and cybersecurity must account for them throughout
- Command and control systems are high-value targets for hacking and physical infiltration
- Media personnel are vulnerable to cyberattack and must be inoculated against false reports
Key terms
- Cyberspace
- A global domain within the information environment consisting of the interdependent networks of information technology infrastructures and resident data, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers. (JP 3-12)
- Physical network layer
- The layer of cyberspace that includes the geographic and physical network components - the actual hardware and the physical location of network elements. It is the foundation the other two layers rest on.
- Logical network layer
- The layer of cyberspace consisting of the components of the network that are related to one another in ways abstracted from the physical network. A website hosted across several servers in several countries exists as one thing at this layer. It is the least intuitive of the three.
- Cyber-persona layer
- The layer of cyberspace consisting of the people who use the network and therefore have one or more identities that can be identified, attributed, and acted upon. This layer links cyberspace directly to a user - an individual, group, organization, or nation state.
- Cyberspace Electromagnetic Activities (CEMA)
- The process of planning, integrating, and synchronizing cyberspace operations and electromagnetic warfare operations in support of unified land operations. (FM 3-12) CEMA ensures information availability, protection, and delivery, and provides the means to deny, degrade, or disrupt the enemy's use of its command-and-control systems and other cyber capabilities.
- Department of Defense information network (DODIN)
- The set of information capabilities and associated processes for collecting, processing, storing, disseminating, and managing information on demand to warfighters, policy makers, and support personnel, whether interconnected or stand-alone. The Army's portion is the DODIN-A.
- Layered defense
- The Army's approach to securing the DODIN-A: multiple physical, policy, and technical controls that integrate people, technology, and operational capabilities to establish security barriers across multiple layers. Tactical satellite assemblages and radio networks are extensions of the DODIN-A and get the same layered treatment.
- Spectrum management operations (SMO)
- The interrelated functions of spectrum management, frequency assignment, host-nation coordination, and policy that enable planning, management, and execution of operations within the electromagnetic operational environment during all phases of military operations. (FM 6-02)
- Host-nation coordination
- The SMO function that recognizes a sovereign nation's rights to its own electromagnetic spectrum. US forces do not simply take frequencies in another country; spectrum supportability is coordinated with the host nation, and operating without that coordination is bootlegging.
- Bootlegging
- Using a frequency without a valid assignment or authorization. It risks electromagnetic fratricide, damages host-nation relationships, and can interfere with safety of life frequencies.
- Electromagnetic warfare (EW)
- Military action involving the use of electromagnetic and directed energy to control the electromagnetic spectrum or to attack the enemy. (JP 3-85) EW comprises electromagnetic attack, electromagnetic protection, and electromagnetic support.
- Electromagnetic attack (EA)
- Division of EW involving the use of electromagnetic energy, directed energy, or antiradiation weapons to attack personnel, facilities, or equipment with the intent of degrading, neutralizing, or destroying enemy combat capability, and considered a form of fires. (JP 3-85) Includes destructive means such as antiradiation missiles and non-destructive means such as jamming, directed energy, electromagnetic deception, chaff and decoys.
- Electromagnetic protection (EP)
- The division of EW that protects personnel, facilities, and equipment from friendly and enemy EW effects. Its measures include emission control, electromagnetic hardening, spectrum management, and protection from both friendly and enemy EW.
- Electromagnetic support (ES)
- The division of EW that searches for, intercepts, identifies, and locates sources of radiated electromagnetic energy. Its products include threat warning, direction finding, and collection supporting EW.
- Noise
- All undesired radio signals, manmade or natural. Noise masks and degrades useful information reception. Signal-to-noise ratio, not raw signal strength, is the important quantity in a receiving system - increasing receiver amplification does not improve it, because amplification raises signal and noise together.
- Atmospheric noise
- Natural noise generated by thunderstorms. It is dominant from 0 to 5 MHz, which is why low frequency transmitters must generate very strong signals to be heard over it.
- Galactic noise
- Natural noise generated by stars. It is the more important natural noise source at higher frequencies, where atmospheric noise falls off.
- Manmade noise
- Noise generated anywhere there is an electric arc - vehicles, power lines, motors, fluorescent lights. Individually small but collectively capable of hiding a weak signal. Waves near a source tend to be vertically polarized, so a horizontally polarized receiving antenna generally receives less of it.
- Radio direction finding (RDF)
- Determining the bearing to a transmitting emitter. Two or more bearings that cross produce a fix. A fix is not required for effective enemy action - a single line of bearing plus a UAS can be enough to cue fires.
- Fix
- A location derived from the intersection of two or more lines of bearing on an emitter. On the CEMA Basics emissions exercise, a fix is acquired against the battalion main command post once it transmits at 5 watts or above.
- Radio electronic battle (REB)
- The Russian equivalent of electromagnetic warfare. REB units support the Russian Ground Forces with both offensive and defensive capabilities, providing jamming of communication networks as well as direction finding, ranging, and monitoring.
- Active defense
- The People's Liberation Army's basic warfighting philosophy: a fundamentally defensive political and strategic stance, enabled when required by operational and tactical offense. Strategically defensive, operationally offensive.
- Information operations (Chinese usage)
- In PLA usage, a blanket term covering many battlefield activities focused on winning the fight in the information domain. The PLA categorizes electromagnetic warfare under information operations, and Chinese CEMA and military information support units are the same organizations.
- GPS spoofing
- Transmitting false satellite navigation signals so a receiver computes a wrong position or time. Spoofing degrades more than navigation - because networks depend on GPS timing, spoofing also degrades communications devices.
- Frequency hopping
- Rapidly changing transmit frequency across hundreds of frequencies in a pattern known to friendly receivers. It makes an emitter far harder to jam or fix than a single-channel transmission.
- Brevity code
- A prearranged word or short phrase that carries a longer meaning, so a transmission can be shortened to a second or two. Single channel with brevity is far harder to exploit than single channel without it, because there is less time on the air and less content to analyze.
- Prowords
- Procedure words that carry a standard meaning on a radio net. Creating, disseminating, and using prowords is one of the listed techniques for minimizing emissions.
- Steerable null antenna processor
- An antenna system that places a null in its reception pattern in the direction of an interfering source, reducing the effect of a jammer without moving the antenna.
- DAGR
- Defense Advanced GPS Receiver. Encrypted, receives two GPS signals, and is more resistant to adversary jamming than a civilian receiver. It displays JAMMING DETECTED when it senses interference, which makes it a sensor as well as a receiver.
- COMSTAT
- Communications status. Maintaining and refining the process for tracking COMSTAT during an operation is a wargaming output for the S6 in the CEMA-in-MDMP construct.
Testable points
- The operational framework in LSCO is echeloned by both distance and time. The division manages assets out to 20 to 40 km with a planning horizon of 24 to 48 hours, and displaces its command posts on that same 24 to 48 hour cycle.
- The brigade manages 5 to 25 km, plans on a 12 to 24 hour horizon, and displaces its command posts every 12 to 24 hours.
- The battalion manages from the forward line of own troops out to about 10 km, plans on a 6 to 12 hour horizon, and displaces its command posts every 6 to 12 hours. The lesson calls this a knife fight - limited assets and limited time.
- The division is the Army's unit of action in this framework, although the course notes that some argue for the corps.
- Division headquarters and expeditionary signal battalion-enhanced units have absorbed many communications assets traditionally found at brigades and battalions, while every echelon is still expected to communicate under significant CEMA threat.
- Cyberspace has three layers: physical network, logical network, and cyber-persona. Analysis by layers is what lets a planner understand the target and node environment.
- Cyberspace operations require links and nodes located in other physical domains to perform logical functions, creating effects in cyberspace that then permeate the physical domains through both wired networks and the electromagnetic spectrum.
- Analysis of cyberspace has an operational aspect and a technical aspect. The operational aspect - targets, high-value individuals, high-payoff targets, named and targeted areas of interest - matters most to the commander and the S3. The technical aspect - nodes, embedded processors, devices - matters most to the cyberspace planner and the S6.
- CEMA is comprised of electromagnetic warfare, cyberspace operations, and spectrum management operations.
- At the battalion, the S6 is responsible for all CEMA actions. Coordination outside the S6's direct responsibility is still typically initiated by the S6 and formalized by the S3.
- The staff sections with a stake in CEMA are the S6, S3, S2, fires, and legal. Legal is not optional - law of armed conflict, rules of engagement, and authorities all constrain what may be done in the spectrum and in cyberspace.
- The traditional Army role in cyber defense is protecting the DODIN-A, and that extends beyond user and device compliance in garrison. Tactical satellite assemblages and radio networks are extensions of the DODIN-A and must be defended with the same layered approach.
- A single vulnerability in the DODIN-A can place units and operations at risk and potentially cause mission failure. Understanding how to operationalize cyberspace and the electromagnetic spectrum is described as a fundamental staff proficiency and a commander's priority.
- Spectrum management operations breaks into four functions: spectrum management, frequency assignment, host-nation coordination, and policy.
- Policy establishes and enforces how the spectrum is used in an area of responsibility, based on host-nation coordination. In the United States, the FCC governs civilian spectrum and NTIA governs federal use.
- Electromagnetic warfare divides into electromagnetic attack, electromagnetic protection, and electromagnetic support.
- Electromagnetic attack has destructive means, such as antiradiation missiles, and non-destructive means, such as jamming, directed energy, electromagnetic deception, chaff and decoys.
- Electromagnetic protection includes emission control, electromagnetic hardening, spectrum management, protection from enemy EW, and protection from friendly EW - the last one matters because friendly jamming degrades friendly nets too.
- Electromagnetic support includes threat warning, direction finding, and collection supporting EW.
- CEMA enters MDMP at mission analysis, course of action development, wargaming, and rehearsals. Trying to shape a course of action after the S3 has finished it produces frustration and nothing else - the S6 must be in the planning from the start.
- In mission analysis the S6 identifies systems vulnerable to CEMA denial, gets enemy CEMA onto the doctrinal, situation, and event templates, gets enemy CEMA capabilities onto the high-value and high-payoff target lists, ensures the information collection plan accounts for the CEMA threat in time and space, identifies communications systems by warfighting function with a method for tracking status and trained personnel, communicates the CEMA threat to subordinates, and analyzes terrain for line of sight for both red and blue.
- In course of action development the S6 accounts for enemy CEMA effects in each course of action, determines lines of contact and integrates them into the PACE plan and targeting, identifies enemy CEMA denial as an information requirement, and aligns the information collection plan to identify that enemy CEMA.
- In wargaming the S6 makes enemy action include CEMA denial, refines the information collection plan and PACE plans by warfighting function, refines the process for maintaining COMSTAT during the operation, and refines graphic control measures and the fires plan.
- In rehearsals CEMA actions belong in the combined arms rehearsal and the fires rehearsal, current operations rehearses the react-to-jamming battle drill, and the unit rehearses COMSEC compromise and system compromise. The lesson points out that units routinely rehearse the first two and almost never rehearse the last two.
- The four buckets of S6 CEMA tasks, from the practical exercise answer key, are DODIN operations, defensive cyberspace operations, spectrum management operations, and electromagnetic warfare - each with its own external supporting organizations.
- The PLA's basic warfighting philosophy is active defense: strategically and politically defensive, enabled when required by operational and tactical offense.
- The PLA combined arms brigade fights electromagnetic warfare in depth, with different jamming missions in the frontal blocking zone, the frontier defense zone, and the depth defense zone, and deploys similarly for both offensive and defensive operations.
- In the frontal blocking zone, hybrid PLA jammer and direction-finding platforms disrupt enemy VHF and UHF communications while locating enemy command and communications nodes.
- In the frontier defense zone, PLA jammers disrupt precision-guided munition signals and target the radar sensors and missile guidance systems of helicopters, fixed-wing aircraft, and land-based launchers.
- In the depth defense zone, PLA multi-spectrum jammers target sophisticated sensors both radio frequency and electro-optical or infrared, using dazzling, spoofing, advanced obscurants, and RF jamming, and are co-located with command posts, air defense, and artillery.
- The PLA combined arms brigade has four electromagnetic warfare missions: radio frequency communications jamming, radio direction finding, precision-guided munition jamming, and sensor neutralization.
- PLA doctrine employs EW against specific high-value assets and messages rather than indiscriminately, deliberately allowing lower-value traffic to continue so the enemy does not detect the attack before it matters.
- The PLA places a very high priority on electromagnetic defense, encrypts as many tactical communications as possible, hardens data networks, and runs dedicated protection cells at brigade and group army echelons.
- Russia's four stated strategic objectives are regional dominance, protection and security, countering foreign interference, and recognition as a world power.
- Russia has created dedicated REB brigades within each military district, each with four battalions, equipped with its most modern and powerful electromagnetic warfare systems.
- GPS spoofing degrades and denies communications devices as well as navigation, because of network timing dependencies. Ukrainian forces have been spoofed into maneuvering well behind enemy lines.
- Russian electromagnetic warfare has proven to be the most effective counter-unmanned aerial system capability observed in the Ukraine conflict.
- Russian forces detect cell phone emissions, often through unmanned aircraft, and rapidly follow with artillery. Combining a non-kinetic detection with a kinetic strike is the pattern to remember.
- Ukraine's lack of robust spectrum management protocols has produced a high rate of electromagnetic fratricide - a reminder that a rigid spectrum management policy is a combat capability, not administrative overhead.
- Ukrainian air defense crews have kept PATRIOT and other systems working in GPS-contested conditions by falling back on analog emplacement methods, which is the argument for training US crews the same way.
- In the first 48 hours of the 2022 invasion, Russian electromagnetic attack jammed Ukrainian military radios and radars, neutralizing tactical communications and reducing battlefield awareness. The mitigation named is communications redundancy training - a real PACE plan plus leaders comfortable with decentralized execution during extended outages.
- Jammers are mostly line of sight. Terrain that masks a jammer protects the receivers behind it, which makes terrain analysis an electromagnetic protection technique and not only a maneuver one.
- GPS jammers target the receiver, not the satellite. That is why blocking the jamming signal with terrain, vehicles, buildings, or even your own body can restore a fix.
- On the emissions practical exercise, a battalion main command post transmitting at 1 milliwatt or 100 milliwatts is not fixed, while the same command post at 5 watts or at 50 watts through a power amplifier is fixed. The detecting receiver is annotated at minus 132 dBm throughout.
- On the same exercise, a company command post at 1 milliwatt gets SAY AGAIN, OVER - the message does not get through - while at 100 milliwatts the call is understood. The teaching point is that there is a power setting that communicates without being fixed, and finding it is the S6's job.
- It is usually the transmitting station that suffers electromagnetic interference, as opposed to electronic attack, in relation to the forward line of own troops.
- Once EMI or electromagnetic attack is discovered, the impact to operations is reported to the operations cell. Electromagnetic warfare and space staff officers can help mitigate and diagnose EMI, per ATP 6-02.53.
- The check on learning for this lesson asks three questions: what CEMA consists of, the difference between EMI and EA, and how you defeat jamming.
References
FM 3-12FM 3-0FM 6-02JP 3-85JP 3-12ATP 3-12.3ATP 6-02.53ATP 6-0.5ADP 3-37ATP 7-100.1ATP 7-100.3
CEMA and Cybersecurity 113-SCCCC11
Learning objective and standard
Learning objectiveIdentify the cybersecurity capabilities of a BN S6 within a contested cyberspace
StandardIdentify the cybersecurity capabilities of a BN S6 within a contested cyberspace by completing the following requirements: LSA 1: Define the fundamentals of cybersecurity in a clear and concise manner without error. LSA 2: Define endpoint security in a clear and concise manner without error. LSA 3: Identify the management of cybersecurity programs in a clear and concise manner without error. LSA 4: Identify cyberspace policies in a clear and concise manner without error. LSA 5: Identify common cyberattacks in a clear and concise manner without error. LSA 6: Define cyber incident management without error in a clear and concise manner without error.
The cyberspace half of CEMA, taught from the battalion S6's chair. Six learning step activities: the fundamentals, endpoint security, managing cybersecurity programs, cyberspace authorities and policy, common attack vectors and attacks, and incident management. Two things in this lesson are worth flagging before you study it. First, the deck teaches five fundamentals of cybersecurity while its own check on learning asks for three - know both the classic confidentiality-integrity-availability triad and the five-item version the slides use. Second, the authorities section is where officers most often carry a wrong assumption into a unit: a battalion commander has no offensive cyberspace authorities, and very few cyberspace authorities are delegated even to the combatant command level.
Doctrinal currencyThe deck contradicts itself on the number of RMF steps. One slide describes DoDI 8510.01 as a six-step process; the speaker notes on the RMF slide walk through seven. Seven is right for the edition of DoDI 8510.01 the deck itself cites.
What this course teaches — answer this on the exam
- Slide 31 describes DoDI 8510.01 as outlining "a six-step process for managing cybersecurity risk throughout the lifecycle of DoD IT systems, from initial development to disposal"
- Six is the count from the earlier RMF construct, before a preparation step was added at the front
What the cited publication actually contains
- The same deck's RMF slide notes walk seven steps: prepare, categorize, select, implement, assess, authorize, monitor
- The deck cites DoDI 8510.01 dated 19 July 2022 on its reference list, which is the edition carrying the seven-step process
- If a question asks you to list the RMF steps, list seven and start with prepare. Only answer six if the question quotes the slide's description of DoDI 8510.01 verbatim
Doctrinal sets to know cold
The three fundamentals of cybersecurity - the CIA triad, what/why/how
- Confidentiality - protect sensitive information from unauthorized access; maintain secrecy; encryption
- Integrity - ensure accuracy and completeness of data; keep information valid; hashing
- Availability - ensure data and systems are accessible and usable; have access even in disasters; continuity and recovery of operations
The two extended fundamentals - what/why/how
- Authentication - verify the identity of users and systems; only allow in those you want; digital certificates
- Nonrepudiation - prevent individuals from denying an action; maintain transparency; digital signatures
Eight common endpoint security tools
- Antivirus and anti-malware software
- Endpoint detection and response (EDR)
- Firewall
- Data loss prevention (DLP)
- Intrusion detection and prevention systems (IDS/IPS)
- Email security - spam filters, phishing protection, email encryption
- Vulnerability scanning and patch management
- Security awareness training
CSfC endpoint security requirements
- Data at rest encryption on laptops and smartphones
- Data in transit protection using VPNs and other encryption
- Strong multi-factor authentication before access to classified information or systems
- Application whitelisting so only pre-approved software runs
- Continuous monitoring through endpoint detection and response
The seven RMF steps
- Prepare - set context and priorities for privacy and security risk management at organization, mission and business process, and system levels
- Categorize - categorize the system per CNSSI No. 1253 based on the information handled and the impact of a loss of confidentiality, integrity, and availability
- Select - choose an initial set of controls and tailor them to reduce risk to an acceptable level based on a risk assessment
- Implement - implement the controls and describe how they are employed within the system and its operating environment
- Assess - determine whether controls are correctly implemented, operating as intended, and producing the desired outcomes
- Authorize - determine whether the risk is acceptable and cyberspace operational commanders' requirements are met
- Monitor - continuously monitor control effectiveness, document changes, conduct risk assessments and impact analyses, and report
Cybersecurity roles, cells, and military occupational specialties
- Network operators - helpdesk and NETOPS - 25B, 25H, 255N - continuous monitoring, security configurations, maintenance
- Cyber security analysts - cyber defense cell - 25D, 255S - threat analysis and sharing, compliance and vulnerability assessments, log collection and reporting for investigation
- Access control officers - network administration - 25A, 25B, 255A - user access management and training, permissions and privilege levels, recovery operations with regular backups
The cybersecurity architecture
- Firewalls and routers - screening and deep packet inspection
- IDS/IPS - prevent network attacks such as denial of service and port scans
- PKI certificates and ICAM - trust between user and system for authentication, email encryption, and digital signature
- Encryption - TRANSEC and IPsec using KIV-7M, KG-175D, AES-256
- HBSS - the DoD antivirus solution, with DLP waivers for NIPR and SIPR burn rights
- SIEM - detect, monitor, analyze, and respond to security incidents in real time
- IAVM and IAVA - vulnerability management and alerts
- ACAS - vulnerability scanning
- SCCM - hardware and software updates and patches
The five stages of ICAM access
- Identification - a user or device requests access and presents credentials
- Authentication - the system verifies the identity using those credentials
- Authorization - the system determines what the identity may access based on policy
- Access granted or denied
- Auditing - all access activity is logged and monitored for security and compliance
Cyberspace authorities by title
- Title 10, The Armed Forces - organize, train, equip, and provide land, cyberspace, and EW units; 10 USC 394 gives the Secretary of Defense authority to conduct military cyber operations
- Title 32, the National Guard - state military units equipped and trained under federal authorization, able to conduct state missions federally funded when the Secretary of Defense determines it is in DoD interests
- Title 50, War and National Defense - authorities for military and intelligence activities; Executive Order 12333 frames the intelligence community and names NSA as the lead for SIGINT
Title 10 cyber operations versus Title 50 intelligence activities
- Approach and intent - Title 10: degrade, disrupt, deny, destroy, attack infrastructure. Title 50: achieve the smallest intervention consistent with desired operations
- Operations agency - Title 10: US Cyber Command. Title 50: the National Security Agency
- Main advocate - Title 10: the Services. Title 50: the Director of National Intelligence
- Interaction with tactical operations - Title 10: based on inclusion in battle plans and military operations. Title 50: based on intelligence reporting
- Characterization of personnel - Title 10: warfighters. Title 50: intelligence community
The six cyberattack vectors
- Network - exploiting weaknesses in network infrastructure, such as an unsecured Wi-Fi connection
- Application - targeting vulnerabilities in software, such as SQL injection against flawed website code
- Human - manipulating people, such as phishing emails
- Physical - gaining physical access, such as a stolen laptop or a malicious USB drive
- Cloud - targeting cloud environments, such as misconfigured cloud storage
- IoT - exploiting Internet of Things devices, such as a compromised security camera
Five common cyberattacks and their variants
- Social engineering - phishing, spear phishing, whaling; also pretexting, baiting, quid pro quo, tailgating
- SQL injection - error based, union based, blind
- Cross-site scripting - stored, reflected, DOM-based
- Denial of service - volumetric, protocol, application layer; distributed when many sources are used
- Ransomware - crypto, locker; with scareware and leakware as related threats
The four cybersecurity headings in the lesson summary
- Cybersecurity posture - integrate internal and external defensive measures to protect the DODIN
- Cybersecurity architecture - leverage DODIN cybersecurity technology to protect the network
- Cybersecurity coordination - coordinate DODIN operations and defensive cyberspace operations, maintain threat situational awareness, and ensure rapid incident response and reporting to higher
- Cybersecurity criteria - adhere to compliance standards, continuous training, and regular reporting
Key terms
- Cyberspace security
- Actions taken within protected cyberspace to prevent unauthorized access to, exploitation of, or damage to computers, electronic communications systems, and other information technology, including platform information technology, as well as the information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation. (FM 3-12)
- Confidentiality
- Protecting sensitive information from unauthorized access. Why: to maintain secrecy. How: encryption. Roughly equivalent to privacy - data is classified by the damage its disclosure would cause, and controls follow that categorization.
- Integrity
- Ensuring the accuracy and completeness of data. Why: to keep information valid. How: hashing. Integrity is the assurance that data has not been altered or modified in an unauthorized way.
- Availability
- Ensuring that data and systems are accessible and usable. Why: to have access even in disasters. How: continuity and recovery of operations.
- Authentication
- Verifying the identity of users and systems. Why: to only allow in those you want. How: digital certificates. Authentication is the process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources.
- Nonrepudiation
- Preventing individuals from denying having performed a certain action. Why: to maintain transparency. How: digital signatures. Nonrepudiation assures the integrity and origin of data such that a third party can verify it originated from a specific entity in possession of the private key.
- Endpoint security
- Security focused on individual access points, minimizing the risk of a breach even if an attacker bypasses network defenses. If the network perimeter is a castle wall, endpoints are the windows, doors, and tunnels within it - laptops, desktops, smartphones, servers, and Internet of Things devices.
- Endpoint detection and response (EDR)
- Tools that continuously monitor endpoint activity, detect suspicious behavior, and provide the means for incident response. EDR is distinct from antivirus in that it watches behavior rather than matching signatures.
- Data loss prevention (DLP)
- Controls that stop sensitive data from leaving an endpoint, intentionally or accidentally, by blocking unauthorized file transfers, emails, or website uploads.
- Commercial Solutions for Classified (CSfC)
- An NSA program providing a framework for US government agencies and authorized contractors to access classified information using commercially available products. It works by layering solutions rather than relying on one highly specialized product.
- Risk Management Framework (RMF)
- The process for managing lifecycle cybersecurity risk to DoD systems, established by DoDI 8510.01. The lesson walks seven steps: prepare, categorize, select, implement, assess, authorize, and monitor.
- Categorize (RMF step 2)
- Categorizing the system in accordance with CNSSI No. 1253 based on the information it analyzes, stores, and relays, and on the impact of a potential loss of confidentiality, integrity, and availability.
- Authorize (RMF step 6)
- Authorizing the system based on a determination of whether the risk to organizational operations and assets, individuals, agencies, commands, and the Nation is acceptable, and whether cyberspace operational commanders' requirements are met.
- Identity, Credential, and Access Management (ICAM)
- A comprehensive framework for managing digital identities and controlling access to digital resources. Consists of identity management, credential management, and access management - who's who, what they hold to prove it, and what they may reach.
- Identity management (IdM)
- The ICAM component managing the lifecycle of digital identities for users, devices, and systems - creating, storing, updating, and deleting identities and ensuring each entity has a unique and verifiable one.
- Credential management (CredM)
- The ICAM component dealing with the tools users use to prove identity - passwords, smart cards, biometrics - and covering their issuance, management, and revocation.
- Access management (AM)
- The ICAM component controlling which resources each identity can reach, enforcing policies based on identity, role, location, and time of day through authentication, authorization, and auditing.
- Information Assurance Vulnerability Alert (IAVA)
- A high-priority DoD cybersecurity announcement notifying system administrators and cybersecurity personnel of a critical vulnerability. IAVAs require immediate attention and carry specific remediation actions with strict compliance deadlines.
- Information Assurance Vulnerability Management (IAVM)
- The DoD program that identifies and publishes vulnerabilities quickly and provides a way to work with IT support to manage patches and minimize downtime. It includes IAVAs, IA Vulnerability Bulletins, and IA Technical Advisories.
- Assured Compliance Assessment Solution (ACAS)
- The DoD vulnerability scanning capability. It is the tool that tells you which of your systems are out of compliance with published vulnerability guidance.
- Security Information and Event Management (SIEM)
- A capability that detects, monitors, analyzes, and responds to security incidents in real time by aggregating log and event data.
- Host-Based Security System (HBSS)
- The DoD antivirus and host protection solution named in the lesson, used alongside data loss prevention waivers for NIPR and SIPR burn rights.
- Intrusion detection and prevention system (IDS/IPS)
- Capabilities that monitor network traffic for suspicious activity, log it, and attempt to block or stop it. In the cybersecurity architecture they are the layer that prevents network attacks such as denial of service and port scans.
- Cyberattack vector
- The path or method an attacker uses to gain unauthorized access to a system or network in order to steal or compromise data. The lesson names six: network, application, human, physical, cloud, and Internet of Things.
- Social engineering
- A broad category of attacks that exploit human psychology and trust to manipulate victims into giving up information or performing actions that benefit the attacker. It targets people rather than technology.
- Phishing
- Attackers impersonate a trustworthy entity by email, SMS, or another channel to trick victims into revealing sensitive information or clicking malicious links. Spear phishing is the targeted version; whaling targets high-profile individuals such as senior executives.
- SQL injection (SQLi)
- Exploiting vulnerabilities in a web application's handling of user input to insert malicious SQL into database queries, allowing an attacker to read, modify, or delete data, bypass authentication, or take control of the database server. Variants include error based, union based, and blind.
- Cross-site scripting (XSS)
- Injecting malicious scripts into websites viewed by other users, so the script executes in their browsers - stealing session cookies, redirecting to malicious sites, or taking over accounts. Variants are stored, reflected, and DOM-based.
- Denial of service (DoS)
- Attacks that overwhelm a server, network, or service with traffic so it is unavailable to legitimate users. Categories are volumetric, protocol, and application layer. A distributed denial of service uses many compromised devices, which makes it far harder to mitigate than a single-source attack.
- Ransomware
- Malicious software that blocks access to a victim's data or system and demands payment for its release. Crypto ransomware encrypts files; locker ransomware locks the whole system; leakware adds the threat of publishing stolen data; scareware uses deception to sell fake remedies without encrypting anything.
- Cyber incident
- An occurrence that results in actual or potential jeopardy to the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits, or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. (CNSSI 4009-2015)
- DoD Cyberspace Workforce Framework (DCWF)
- Established by DoDD 8140.01 as the DoD authoritative reference for identifying, tracking, and reporting cyberspace positions, and the foundation for enterprise baseline cyberspace workforce qualifications.
Testable points
- There are THREE fundamentals of cybersecurity - confidentiality, integrity and availability, the CIA triad. Authentication and nonrepudiation are extended fundamentals: real, examinable, and not part of the three. Each of the five is presented as a what, a why and a how.
- This is why the deck's check on learning asks for three while its slides walk five: the slides cover the triad plus the two extended fundamentals without labelling the split. If a stem says "the three fundamentals", answer confidentiality, integrity and availability. If it asks what else the lesson covers, that is authentication and nonrepudiation, which come from the FM 3-12 cyberspace security definition.
- Confidentiality is achieved through encryption, integrity through hashing, availability through continuity and recovery of operations, authentication through digital certificates, and nonrepudiation through digital signatures. The how column is the most quizzable part of that slide.
- Endpoint security secures individual access points so that a breach is still contained even if an attacker gets past network defenses.
- The lesson lists eight common endpoint security tools, and the eighth is security awareness training - the human element is called the weakest link.
- Three reasons endpoint security matters: a growing and more diverse device population, remote work placing endpoints outside the traditional perimeter, and modern attacks targeting endpoints directly to bypass network security.
- Endpoint security is not a one-time fix but an ongoing process requiring regular updates to tools and strategies.
- CSfC is built on layering commercially available products rather than relying on a single specialized and expensive product.
- CSfC endpoint requirements are data at rest encryption, data in transit protection, strong multi-factor authentication, application whitelisting, and continuous monitoring through endpoint detection and response.
- The RMF as walked through in this lesson has seven steps: prepare, categorize, select, implement, assess, authorize, and monitor.
- RMF step 2, categorize, is performed in accordance with CNSSI No. 1253.
- RMF step 7, monitor, is continuous - it includes monitoring control effectiveness, documenting system and environment changes, conducting risk assessments and impact analyses, and reporting on security and privacy.
- Cybersecurity roles are taught in three groups. Network operators are the helpdesk and NETOPS - 25B, 25H, and 255N - and they monitor traffic and system activity, implement security configurations, and perform maintenance.
- Cyber security analysts sit in the cyber defense cell - 25D and 255S - and conduct threat analysis, share threat information, run compliance and vulnerability assessments, and collect, analyze, retain, and report system logs for incident investigation.
- Access control officers work in network administration - 25A, 25B, and 255A - and oversee user access management and training, ensure appropriate permissions and privilege levels, and plan and employ recovery operations with regular backups.
- The cybersecurity architecture slide names nine capability groups: firewalls and routers, IDS/IPS, PKI and ICAM, encryption, HBSS, SIEM, IAVM and IAVA, ACAS, and SCCM.
- Encryption examples named in the architecture are TRANSEC and IPsec using the KIV-7M, the KG-175D, and AES-256.
- ICAM manages access through five stages: identification, authentication, authorization, access granted or denied, and auditing.
- The IAVM program includes three products: IA Vulnerability Alerts, IA Vulnerability Bulletins, and IA Technical Advisories. IAVAs are the highest priority of the three.
- An IAVA contains a severity assessment with an explanation of the vulnerability, remediation guidance with strict deadlines, and serves as a centralized DoD source for coordinated response.
- Cyberspace authority ultimately comes from the President. Few cyberspace authorities are granted down to the combatant command level, and a battalion commander will not have offensive cyber authorities.
- USC Title 10 enables the Army to organize, train, equip, and provide land, cyberspace operations, and EW units and headquarters, and provides the foundation for how the Secretary of Defense directs military cyberspace operations.
- 10 U.S. Code section 394 gives the Secretary of Defense the authority to conduct military cyber operations, including clandestine operations in response to cyberattacks by foreign powers.
- USC Title 32 covers the National Guard. Army National Guard units are state military units equipped and trained under federal statutory authorization, and may conduct state missions paid for federally when the Secretary of Defense determines the mission is in DoD interests.
- USC Title 50 covers war and national defense and provides authorities for both military and intelligence activities. Executive Order 12333 establishes the framework and organization of the intelligence community and identifies the National Security Agency as the lead for signals intelligence.
- The Title 10 and Title 50 comparison is a likely exam item. Title 10 cyber operations are run by US Cyber Command with warfighters as personnel and are driven by inclusion in battle plans; Title 50 intelligence activities are run by NSA with intelligence community personnel and are driven by intelligence reporting.
- Title 10 cyber operations aim to degrade, disrupt, deny, destroy, or attack infrastructure. Title 50 intelligence activities aim to achieve the smallest intervention consistent with the desired operations.
- DoDD 8140.01 outlines DoD responsibilities for managing cybersecurity personnel, training, and qualifications, and establishes the DoD Cyberspace Workforce Framework.
- DoDI 8140.02 establishes policy for identifying, tracking, and reporting cyberspace workforce requirements. DoDM 8140.03 is the qualification and management program that uses the DCWF to standardize qualifications.
- DoDI 8500.01 is the DoD cybersecurity policy. DoDI 8510.01 is the RMF. DoDI 8520.02 governs public key infrastructure and public key enabling.
- AR 25-1 is Army Information Technology, AR 25-2 is Army Cybersecurity, AR 380-5 is the Army Information Security Program, and AR 380-53 is Communications Security Monitoring.
- AR 380-5 develops Army policy for the classification, downgrading, declassification, transmission, transportation, and safeguarding of information requiring protection in the interests of national security - the answer to the check-on-learning question about storage and physical security standards for classified material.
- AR 380-53 covers COMSEC monitoring, information operations Red Team activities, and the Computer Defense Association Program.
- The six cyberattack vectors are network, application, human, physical, cloud, and Internet of Things.
- Vector examples: an unsecured Wi-Fi connection is a network vector, SQL injection is an application vector, a phishing email is a human vector, a stolen laptop or malicious USB drive is a physical vector, misconfigured cloud storage is a cloud vector, and a compromised smart camera is an IoT vector.
- Social engineering techniques include phishing, pretexting, baiting, quid pro quo, and tailgating. Tailgating is physical - following an authorized person through a controlled door.
- Whaling is a highly targeted spear-phishing attack aimed at high-profile individuals such as chief executives or chief financial officers.
- The most effective defense against SQL injection is prepared statements, also called parameterized queries, which separate SQL code from user input so data is never treated as executable code.
- The most crucial defenses against cross-site scripting are input validation and output encoding, supported by a content security policy and HttpOnly cookies.
- The difference between DoS and DDoS is the source count: a DoS attack comes from a single source and is easier to identify and block, while a DDoS attack uses many compromised devices, often a botnet, and is much harder to mitigate.
- Paying a ransomware ransom does not guarantee data recovery. The defense named is robust backups stored offline or in a separate location.
- Scareware is grouped as a similar threat rather than true ransomware, because it does not typically encrypt files - it deceives the user into buying fake security software or calling a fraudulent support line.
- Time-sensitive action is required on a cyber incident to limit damage or access. Cybersecurity personnel must notify the personnel security manager of incidents potentially requiring personnel action, per DA PAM 25-2-17.
- Incident reporting follows Army regulations for the specific incident, ARCYBER published procedures, the applicable continuity of operations plan under AR 500-3, IT contingency plans under DA PAM 25-1-2, incident response plans, and organizational policies.
- The lesson states plainly that the incident management slides show one way to do it, and that there is a classified Army standard the unit must actually meet.
- The distinction the lesson draws between an incident and an event is nuanced: the incident is what happens, and the event is what is reported and acted upon.
- The summary organizes everything under four headings that all begin with the same word: cybersecurity posture, cybersecurity architecture, cybersecurity coordination, and cybersecurity criteria.
References
FM 3-12FM 6-02JP 3-12AR 25-1AR 25-2AR 380-5AR 380-53AR 500-3DA PAM 25-1-2DA PAM 25-2-17DoDD 8140.01DoDI 8140.02DoDM 8140.03DoDI 8500.01DoDI 8510.01DoDI 8520.02CNSSI 4009-2015CNSSI 1253ATP 6-02.71
CEMA in LSCO and Multinational Operations 113-SCCCC12
Learning objective and standard
Learning objectiveIdentify Multinational signal assets deployed in support of Large-Scale Combat Operations (LSCO)
StandardIdentify Multinational signal assets deployed in support of Large-Scale Combat Operations (LSCO) by completing the following. - Identify multinational interoperability requirements and standards in a clear and concise manner without error. - Identify signal support requirements to LSCO in a clear and concise manner without error.
Interoperability, taught as three domains rather than one problem. The procedural domain is doctrine and SOPs, the technical domain is equipment and bridging, and the human domain is liaison officers and language. The lesson's central argument is that the technical domain is the one signal officers instinctively attack and the one that matters least on its own - a fully interoperable radio still fails when "clear the forest" means something different to each army. The JMRC assessment framework, which grades a partnership from not interoperable through de-conflicted and compatible to integrated across all three domains, is the tool that ties the lesson together and is the single most likely exam item in it.
Doctrinal currencyThis deck's reference list is a version behind the rest of Module C on operations doctrine. The primer and CEMA Basics both cite the current FM 3-0; this lesson's list does not.
What this course teaches — answer this on the exam
- The 113-SCCCC12 reference list cites FM 3-0 Operations dated 1 October 2022
What the rest of Module C cites
- FM 3-0 Operations, 21 March 2025, is the current edition and is what the Module C primer and 113-SCCCC10 CEMA Basics both list
- The 2025 edition is also the copy assigned as a Module C read-ahead, so it is the version you will actually have read
- Nothing this lesson teaches depends on the difference - the interoperability content comes from DoDI 8330.01, the JMRC framework, and joint publications - but cite the 2025 edition if you are asked for FM 3-0
Doctrinal sets to know cold
The three domains of interoperability
- Procedural - doctrine, SOPs, common operational terms and graphics, shared training background
- Technical - equipment compatibility and the bridging solutions between dissimilar systems
- Human - liaison officers, language, and command relationships
The four levels of the JMRC Interoperability Assessment Framework
- Not interoperable (0) - no commonality of procedure, no compatible equipment, no LNOs, no common language, no command relationships; coordination is personalities and chance contact
- De-conflicted (1) - human intervention at the point of friction; SOPs exchanged but not drilled; communications only through LNO equipment; LNO is an RTO; tight control
- Compatible (2) - standardized procedures and temporary technical bridging; common SOP for the situational mission; LNOs embedded in warfighting functions as a parallel staff chain; common language; mission command face to face only
- Integrated (3) - common doctrine and SOPs; permanent technical bridging; LNOs are members of the gaining staff in CUOPS and FUOPS roles; fluent common language; mission command through directive control
The five multinational best practices
- Effective liaison packages - expertise, rapport, full PACE communications, 24-hour manning
- Understand capabilities - detailed capabilities briefs shared between adjacent, higher, and lower units, and articulated during mission analysis
- Detailed preparation - confirmation brief, back brief, and rehearsals; over-articulate the plans to current operations transition
- Critical standard operating procedures - a releasable tactical SOP published before the exercise, adapted and rehearsed by subordinates, with applicable STANAGs reviewed and disseminated
- Complete common operating picture - digital and analog at every echelon, sustained by critical reports defined before execution
What a releasable tactical SOP should cover
- Reporting procedures
- Vehicle marking, day and night
- Adjacent unit coordination
- Forward and rearward passage of lines
- Call for fire
- Casualty evacuation
The five priority focus areas
- Knowledge management and information management
- Communication and information systems
- ISR and intelligence fusion
- Digital fires
- Sustainment
The interoperability policy stack
- CJCSI 5123.01 - Joint Capabilities Integration and Development System
- DoDI 8310.01 - Information Technology Standards in the DoD
- DoDI 8330.01 - Interoperability of Information Technology, Including National Security Systems
- DoD Interoperability Process Guide v3.0
- Federated Mission Networking - the NATO coalition networking construct
- Multinational Interoperability Tactical Guidebook
The three-step checklist for solving an interoperability issue
- Find a pre-existing solution - you are not the first to have this problem
- Request assistance from your higher headquarters
- Implement the solution incrementally, testing with each step
Organizations that can assist with interoperability
- JITC - joint interoperability testing and solutions, Fort Huachuca
- USAREUR-AF G6 - constant MPE connection, integration assistance, and a routinely updated Europe Playbook
- PEO C3N - equipment fielding and training, and interoperability solutions
- NSA - the Commercial Solutions for Classified program, useful for LNOs with classified requirements and for operating on non-classified networks
- US Space Force CSCO - PLEO contracts that can provide network access for an LNO at your command post
Multinational considerations the S6 must plan for
- PACE, including non-verbal near and far recognition signals
- Communications outside of power windows
- Common tactical tasks and orders, understood the same way at every echelon
- Reporting and addressing suspected COMSEC or network compromise, including what the partner does and how they will tell you
- Partner equipment held in limited quantities - compatible at battalion does not mean compatible at company
Tactical voice bridge configurations
- Ten radio ports for HF, VHF, UHF, and 700 to 900 MHz; one dual-function satellite phone and acoustic coupler or land mobile radio port; one four-wire cellphone or desk telephone port; a two-wire handset station emulator; four talk group recording and amplified speaker jacks
- A five-radio-port configuration with the same feature set at smaller scale
- A two-port version for HF, VHF, and UHF radios that runs on AA batteries and is small and mobile
Key terms
- Interoperability (JP 3-0)
- The ability to operate in synergy in the execution of assigned tasks.
- Interoperability (JP 6-0)
- The condition achieved among communications-electronics systems or items of communications-electronics equipment when information or services can be exchanged directly and satisfactorily between them and/or their users.
- IT interoperability (DoDI 8330.01)
- The ability of systems, units, or forces to provide data, information, materiel, and services to, and accept the same from, other systems, units, or forces, and to use what is exchanged to operate effectively together. It includes both the technical exchange of information and the end-to-end operational effectiveness of that exchange, including appropriate cybersecurity aspects. Interoperability is more than information exchange - it includes systems, processes, procedures, organizations, and missions.
- Procedural domain
- The interoperability domain covering doctrine, standard operating procedures, common operational terms and graphics, and shared training background. Measured by whether partners share doctrine, whether SOPs are exchanged and drilled, and whether a common doctrinal framework supports combined operations.
- Technical domain
- The interoperability domain covering equipment compatibility and the bridging solutions that connect dissimilar systems. Measured by whether equipment can interface directly, only through temporary bridges, or only through the liaison officer's own equipment.
- Human domain
- The interoperability domain covering liaison officers, language, and command relationships. Measured by whether liaison officers are present, how deeply they are integrated into the staff, whether a common language exists, and whether mission command is possible at all.
- Not interoperable (level 0)
- The JMRC framework's lowest level. No demonstrated capability for interoperability - no commonality of procedure, no compatibility of equipment, no liaison officers, no common language, no ability for higher headquarters to command and control lower. Coordination is a matter of personalities and chance contact.
- De-conflicted (level 1)
- Human intervention at the point of friction aligns dissimilar procedures and technical capabilities. Procedural and technical friction is solved by the liaison package. SOPs are exchanged but not drilled, communications work only through liaison equipment, and the liaison officer functions as a radio operator relaying between units. Command is characterized by tight control.
- Compatible (level 2)
- Human interaction produces standardized procedures and temporary technical bridging, synchronizing dissimilar capabilities into situational operating norms. A common SOP is established for the mission, indirect equipment compatibility works through temporary bridges, liaison officers push and pull orders information and sit in warfighting functions as a parallel staff chain, and a common language exists. Command mixes tight and directive control.
- Integrated (level 3)
- The JMRC framework's highest level. Common doctrine and SOPs reduce the need for liaison officers as human interfaces, permanent technical bridging assimilates partner equipment, liaison officers function as members of the gaining unit's staff in current and future operations roles, and communication uses fluent common language. Command is mission command through directive control.
- Liaison officer package (LO/LNO)
- A team with the guidance, manning, and equipment to overcome the friction of multinational operations. The lesson calls it the most effective single method. An effective package has technical and tactical expertise to advise commanders and staffs on capabilities, gaps and procedures, the interpersonal skills to build rapport, the ability to communicate across the whole PACE plan, and the manning to support 24-hour operations.
- Common operating picture (COP)
- A shared display of relevant information that facilitates shared understanding, reduces miscommunication and fratricide, and enables effective integration of fires. In multinational formations, headquarters maintain both a digital and an analog COP, because subordinate units may not have complete digital systems.
- Mission Partner Environment (MPE)
- A capability framework improving partner information sharing, data exchange, and integrated execution through common standards governance and agreed procedures. The lesson calls MPE a known solution for the upper tactical internet - a cloud multi-enclave, multi-releasability environment.
- Federated Mission Networking (FMN)
- The NATO construct for a persistent capability enabling command and control and information sharing across coalition partners. The lesson names supporting the ECNS contribution as an FMN-compliant nation as an MPE objective.
- Information exchange requirement (IER)
- A stated requirement for information to move between specific participants. MPE's purpose is expressed in terms of enabling IERs with Army units, joint units, and unified action partners across digital fires, sensor to shooter, intelligence, logistics, and a coalition air and ground common operating picture.
- Tactical voice bridge (TVB)
- A device that patches dissimilar radio networks together by converting each side to unencrypted analog voice at the bridge. The lesson calls it a known solution for the lower tactical internet. Its critical limitation is exactly how it works - traffic crossing the bridge is in the clear.
- Joint Interoperability Test Command (JITC)
- The DISA organization at Fort Huachuca that supports and tests joint interoperability requirements and creates solutions for them. Contact is a public web page and a support line, and JITC is the joint interoperability certification authority for DoD IT.
- PEO C3N
- Program Executive Office Command, Control, Communications - Network. Responsible for fielding and training on equipment, and a source of solutions for interoperability requirements.
- USAREUR-AF G6
- The US Army Europe and Africa G6, which maintains a constant connection to MPE, can assist units with integration, and publishes a routinely updated Europe Playbook.
- Commercial Satellite Communications Office (CSCO)
- The US Space Force Space Systems Command office that holds the Proliferated Low Earth Orbit contracts. A unit can acquire PLEO service through CSCO to fit a requirement - the lesson's example is giving a liaison officer network access at your command post.
- Proliferated Low Earth Orbit (PLEO)
- Commercial low earth orbit satellite communications acquired through CSCO's contract suite. Presented in this lesson as an accessible way to give a coalition liaison team connectivity without waiting on a program of record fielding.
- Layer 8
- Informal shorthand for the human being above the seven layers of the OSI model. The lesson's point is that layer 8 is still the most error-prone part of a multinational network, and that technical solutions to information sharing are not always sufficient.
- Power window
- A scheduled period during which generators run and systems are powered. Communications outside power windows must be planned for, because a partner unit that is dark on schedule is not a partner unit that has been destroyed.
- Standardization agreement (STANAG)
- A NATO agreement establishing common processes, procedures, terms, or conditions. The lesson directs that units review and rehearse applicable STANAGs and ensure they are disseminated to the lowest tactical levels.
Testable points
- The lesson divides interoperability into three domains: procedural, technical, and human. Do not confuse these with the three dimensions of the operational environment - physical, information, and human - which share only one word.
- The JMRC Interoperability Assessment Framework grades a partnership at four levels: not interoperable (0), de-conflicted (1), compatible (2), and integrated (3).
- The framework's purpose is unit self-assessment of interoperability preparedness before operations, so systems improvement or risk mitigation can be targeted.
- Command relationship changes with the interoperability level: no command relationships at level 0, tight control at level 1, a situational mix of tight and directive control at level 2, and mission command through directive control at level 3.
- The liaison officer's role changes at each level. At level 1 the LNO is a radio operator relaying information. At level 2 the LNO pushes and pulls orders information and is embedded in warfighting functions as a parallel chain to the organic staff. At level 3 the LNO is a member of the gaining unit's staff in both current operations and future operations roles.
- Language tracks the levels too: no common language at level 0, communication through interpreters only at level 1, a common language that may be the second language of both partners at level 2, and fluent usage of a common language at level 3.
- At level 2 mission command is possible only through face-to-face interaction. At level 3 it becomes possible through direct and indirect interaction - by order or over the radio.
- The framework's five priority focus areas are knowledge management and information management; communication and information systems; ISR and intelligence fusion; digital fires; and sustainment.
- Liaison teams are described as the most effective single method of overcoming the inherent friction of multinational operations.
- An effective liaison package needs three things at once: technical and tactical expertise, interpersonal skills to build rapport, and the manning and equipment to communicate across the PACE plan and support 24-hour operations.
- Allies and partners should maintain and share detailed capabilities briefs between adjacent, higher, and lower units, and liaison teams articulate those capabilities during mission analysis.
- Shared understanding between commanders is achieved during the prepare phase through the confirmation brief, back brief, and rehearsals. Units should over-articulate transitions between plans and current operations cells and over-emphasize rehearsals.
- A releasable tactical SOP should be published before the exercise and should cover reporting procedures, vehicle marking day and night, adjacent unit coordination, forward and rearward passage of lines, call for fire, and casualty evacuation.
- Subordinate units adapt and rehearse the SOP and provide feedback before operations begin - an SOP that is exchanged but never drilled is the definition of level 1, de-conflicted.
- Headquarters at echelon maintain both a digital and an analog common operating picture, because subordinate coalition units may not have complete digital systems.
- Higher headquarters maintain the COP by defining critical reports before execution and receiving them through the standardized communication plan and through the liaison teams, to ensure accuracy, completeness, and timeliness.
- The lesson's checklist for solving an interoperability problem has three steps in order: find a pre-existing solution because you are not the first; request assistance from your higher headquarters; then implement the solution incrementally, testing at each step.
- Five organizations are named as sources of interoperability help: JITC, USAREUR-AF G6, PEO C3N, NSA through the Commercial Solutions for Classified program, and the US Space Force CSCO through PLEO.
- NSA is on that list because CSfC can be useful both for liaison officers with classified information requirements and for anyone who has to operate on a non-classified network.
- The Space Force is on that list because CSCO's PLEO contracts can be an easy way to provide network access for a liaison officer at your command post.
- MPE is the known solution for the upper tactical internet: a cloud multi-enclave, multi-releasability environment intended to expand in step with mission, Department of the Army, DoD, Joint Staff, and combatant command guidance.
- The two required JKO courses, J3O P-US1277 and J3O P-US1278, exist because of MPE - the lesson says so directly.
- The tactical voice bridge is the known solution for the lower tactical internet. The larger configuration provides ten radio ports for HF, VHF, UHF, and 700 to 900 MHz, plus a dual-function satellite phone and acoustic coupler port, a four-wire cellphone or desk telephone port, a two-wire handset station emulator, and four individual talk group recording and amplified speaker jacks. A five-port configuration offers the same feature set at smaller scale, and a two-port version running on AA batteries is small and mobile.
- The tactical voice bridge works by converting encrypted RF from one nation, keyed with its own key, to unencrypted analog voice at the bridge, and then re-encrypting to the other nation's key. Anything crossing the bridge is unencrypted analog voice at that point.
- Technical solutions to information sharing are not always sufficient. The lesson states that layer 8 - the human - is still the most prone to errors.
- The four multinational planning considerations the lesson raises are the PACE plan with non-verbal near and far recognition, communications outside of power windows, common tactical tasks and orders, and reporting and addressing suspected COMSEC or network compromise.
- The lesson's historical example: in Vietnam, US forces asked British forces to clear a forest for a command post. The British reported completion and US forces came under attack, because the two armies did not share a common tactical task - to the British, clear meant to move through quickly.
- A second example: the British term "crash out" activates their quick reaction force, which is meaningless to a US soldier at 0300. These failures happen between two armies that share a native language, which is why they are worse across languages.
- Allies often acquire interoperable equipment in limited quantities. A partner battalion may report having a compatible radio family but hold only enough for the battalion command post, which breaks any plan that assumes parity down to company level.
- COMSEC and network compromise procedures must be planned with partners in advance. You need to know what a partner does when they suspect compromise, and how they will tell you, before you are in combat.
- The lesson's check on learning asks for two organizations that can assist with interoperability and one technical solution for information sharing.
- The practical exercises for this lesson are the two largest in Module C: a command post layout problem at two hours and forty minutes, and a standard operating procedures problem at three hours - each run against an IBCT with CS21, an SBCT with CS23, and an ABCT with legacy equipment.
- The SOP practical exercise requires two communications-specific battle drills, a unit-specific EMCON plan, a communications windows plan, and retransmission operations.
References
DoDI 8330.01DoDI 8310.01CJCSI 5123.01JP 3-0JP 6-0FM 3-0FM 6-02FM 3-12ADP 3-37ATP 6-0.5
CEMA Planning Exercise 113-SCCCC08
Learning objective and standard
Learning objectiveApply basic CEMA and Cybersecurity knowledge to complete the CEMA Planning Exercise
StandardComplete the CEMA Planning Exercise with a score of 70% or better
Module C's graded practical application, and the only place the three teaching lessons are used together. Students work as the battalion S6 for one of four battalions in the RAK HAMMER scenario and build a six-part brief that runs from framing the operational environment through enemy CEMA capabilities to the mitigations they will actually enforce. The exercise is worth studying even as a written product, because its six deliverables are a compact restatement of what CEMA planning is: know your ground, know what the enemy can do to your spectrum and your network, decide what must be defended, predict how the enemy will come at it, layer the defense, and name the measures the unit will live by. The framing case is 25th Infantry Division's Warfighter 17-04, the first division exercise where the G6 defended the network against a cyber opposing force.
Doctrinal sets to know cold
The six required parts of the CEMA planning brief
- Identify the area of operations, area of interest, and friendly forces
- Identify and discuss the enemy CEMA capabilities
- Defended assets list
- Develop the enemy most likely course of action and most dangerous course of action with regard to CEMA
- Emplacement of obstacles - establish a defense in depth of the network
- Mitigation factors to be enforced throughout the operation with regard to CEMA
The four battalions students plan for
- 1-187 IN
- 2-506 IN
- 3-187 IN
- 21 BEB
Required reading and reference for the exercise
- News from the CTC - Cyber Defense Insights, 25ID Warfighter 17-04
- The RAK HAMMER brigade operations order and product set
- The Worldwide Equipment Guide on the ODIN website, for the CEMA assets named in the OPORD
Warfighter 17-04 - the framing case
- 25th Infantry Division, executed 3 to 11 April 2017
- The first division exercise where the G6 collectively defended the network from a cyber opposing force
- An inadequate defense of the network could have had direct impacts on the division's ability to accomplish its mission
- The resulting product covers both the methodical preparation and the lessons learned during execution
How the six deliverables map onto CEMA in MDMP
- AO, AI, and friendly forces, plus enemy CEMA capabilities - mission analysis, where enemy CEMA goes onto the templates and target lists
- Enemy most likely and most dangerous courses of action - COA development and wargaming, where enemy action must include CEMA denial
- Defended assets list and network defense in depth - the protection decisions that come out of wargaming
- Mitigation factors enforced throughout - what the combined arms rehearsal, the react-to-jamming drill, and the COMSEC and system compromise rehearsals are supposed to test
What to have ready before the exercise
- The four buckets of S6 CEMA tasks - DODIN operations, defensive cyberspace operations, spectrum management operations, and electromagnetic warfare - and who supports each
- Threat equipment ranges and bands from the Worldwide Equipment Guide for the assets named in the OPORD
- A PACE plan by warfighting function, not a single unit-wide PACE
- The emissions arithmetic from CEMA Basics - the lowest power that still communicates without being fixed
- The layered defense concept from the cybersecurity lesson, restated as obstacles in depth
Key terms
- PLANNEX
- Planning exercise. The Module C PLANNEX tests knowledge gained across the module and must be completed with a score of 70 percent or better.
- Area of operations (AO)
- The geographic area assigned to a commander, within which they have the authority and responsibility to conduct operations. The first deliverable of the exercise requires identifying the AO, the area of interest, and friendly forces.
- Area of interest (AI)
- The area of concern to the commander beyond the area of operations, including areas occupied by enemy forces that could affect mission accomplishment. For CEMA, the area of interest extends as far as the enemy's jammers and collection assets can reach, which is usually well beyond the AO.
- Defended asset list (DAL)
- The prioritized list of assets the commander has decided must be protected. In the CEMA context this drives which network nodes, command posts, retransmission sites, and emitters get protection resources first, and it is the third deliverable of the exercise.
- Enemy most likely course of action (EMLCOA)
- The course of action the enemy is assessed as most probable to adopt. The exercise requires an EMLCOA specifically with regard to CEMA - what the enemy will most likely do to your network and your emissions.
- Enemy most dangerous course of action (EMDCOA)
- The enemy course of action that would cause the greatest harm to the friendly mission if adopted. In CEMA terms this is usually the timing and combination that collapses your PACE plan at the decisive point rather than the one that jams the most.
- Defense in depth
- Arranging mutually supporting defensive positions in depth so an attacker must penetrate successive layers. Applied to the network, it means layering physical, policy, and technical controls so that a single compromise does not yield the whole system - the same layered defense concept CEMA Basics applies to the DODIN-A.
- Obstacle emplacement (network analogy)
- The exercise deliberately borrows maneuver vocabulary: emplacing obstacles means establishing the defense in depth of the network. Framing controls as obstacles forces the S6 to think about where they slow an attacker down and where they are simply decoration.
- Cyber opposing force (cyber OPFOR)
- A trained opposing force that attacks the friendly network during an exercise. Warfighter 17-04 was the first 25th Infantry Division exercise where the G6 collectively defended the network against one.
- Command post exercise (CPX)
- An exercise that stresses staff functions, processes, and communications without moving the full force. 25th Infantry Division runs division CPXs throughout the year that stress communications, functions, and processes within the G6.
- RAK HAMMER
- The brigade operations order and product set used as the scenario for the CEMA Planning Exercise. Students build the CEMA portion of their battalion's plan against it.
- ODIN
- The Operational Environment Data Integration Network, the Army site hosting threat data. Teams are directed to it to understand the CEMA assets listed in the operations order.
- Worldwide Equipment Guide (WEG)
- The reference on ODIN that describes threat equipment and capabilities. It is how a student turns an enemy CEMA asset named in the OPORD into a range, a frequency band, and an effect.
- Mitigation
- A measure enforced throughout the operation to reduce the effect of an assessed threat. The exercise's final deliverable is CEMA mitigation factors, and the wording matters - they are to be enforced throughout the operation, not named once in an annex and forgotten.
Testable points
- The CEMA Planning Exercise is 113-SCCCC08, and its stated purpose is to test the knowledge gained in the CEMA module.
- The standard is explicit and numeric: complete the CEMA Planning Exercise with a score of 70 percent or better.
- Students work in their MDMP-as-an-S6 groups, acting as the battalion S6 for 1-187 IN, 2-506 IN, 3-187 IN, or 21 BEB.
- Two documents must be read before the exercise: News from the CTC - Cyber Defense Insights, 25ID Warfighter 17-04, and the RAK HAMMER operations order.
- Teams are recommended to use the Worldwide Equipment Guide on the ODIN website to understand the CEMA assets listed in the operations order.
- The brief has six required parts, and they are graded as a set - a strong enemy assessment does not compensate for a missing defended asset list.
- Deliverable one is identifying the area of operations, area of interest, and friendly forces.
- Deliverable two is identifying and discussing enemy CEMA capabilities.
- Deliverable three is the defended assets list.
- Deliverable four is developing the enemy most likely course of action and most dangerous course of action with regard to CEMA.
- Deliverable five is emplacement of obstacles, framed as establishing a defense in depth of the network.
- Deliverable six is the mitigation factors to be enforced throughout the operation with regard to CEMA.
- The scenario framing comes from 25th Infantry Division's Warfighter 17-04, executed 3 to 11 April 2017.
- Warfighter 17-04 was unique for the division because it was the first exercise where the G6 collectively defended the network from a cyber opposing force.
- The stated stakes of that exercise are the point of the whole module: an inadequate defense of the network could have direct impacts on the division's ability to accomplish its mission.
- The 25th Infantry Division case study is described as highlighting both a methodical approach to preparing for cyber defense and the lessons learned during execution - preparation and hotwash, not one or the other.
- The exercise runs across the back half of the Module C schedule, occupying most of the final days rather than a single block.
- The exercise is followed by a review block in which the CEMA planning exercise is walked through with the students.
- The six deliverables map directly onto the CEMA-in-MDMP material from CEMA Basics - AO and AI framing and enemy capability assessment are mission analysis products, the enemy courses of action belong to COA development and wargaming, and mitigations are what the rehearsals test.
- Because the exercise is scored, it is one of the four places the Module C primer says CEMA knowledge is assessed, alongside the Mission Command Exercise, the Signal Branch Specific Comprehensive Exam, and the Capstone.
References
FM 3-12FM 3-0FM 3-90ATP 3-12.3ATP 6-02.71
Reference Publications and Support Organizations Module C
Learning objective and standard
Learning objectiveIdentify the governing publications and support organizations behind Module C's cyberspace workforce, interoperability certification, operations security, and commercial satellite requirements
StandardIdentify the purpose and scope of the policy publications distributed with Module C, and identify the organization and process that governs each, in a clear and concise manner.
Module C ships four policy publications and two commercial satellite documents that no slide teaches beyond a title line on a reference list. They are gathered here because each answers a question the lessons raise but do not close. DoDD 8140.01 is where the cybersecurity workforce roles in the cybersecurity lesson actually come from. DoDI 8330.01 is what makes JITC an authority rather than a helpline, and it contains the rule most likely to surprise a new S6 - that IT does not connect to a DoD network without a joint interoperability certification, an interim certificate to operate, or an approved waiver. JP 3-13.3 supplies the OPSEC process that every emissions control decision in CEMA Basics implicitly runs on. And the PLEO material is the concrete route behind the multinational lesson's suggestion to get a liaison team online through the Space Force.
Doctrinal sets to know cold
What DoDD 8140.01 establishes
- Authorizes the DoD Cyberspace Workforce Management Board as the governing body
- Establishes the DoD Cyberspace Workforce Framework as the authoritative reference for identifying, tracking, and reporting cyberspace positions
- Unifies the cyberspace workforce and establishes specific workforce elements aligned under the CWMB
The cyberspace workforce elements named in DoDD 8140.01
- Information technology
- Cybersecurity
- Cyberspace effects
- Intelligence
- Enablers
- The directive introduces these with "e.g.", so treat them as the named elements rather than a closed set
The three ways IT may lawfully connect to a DoD network under DoDI 8330.01
- A joint interoperability certification
- An interim certificate to operate (ICTO)
- An approved waiver to policy, or an established exemption from joint interoperability certification
The five steps of the OPSEC process
- Identify critical information - what answers the key questions an adversary would ask about friendly intentions, capabilities, and activities
- Threat analysis - research and analysis of intelligence, counterintelligence, and open-source information to identify likely adversaries
- Vulnerability analysis - identify where the adversary can collect critical information, correctly analyze it, and act on it in time
- Risk assessment - analyze vulnerabilities and identify countermeasures, estimate the impact to operations, and select countermeasures for execution
- Apply countermeasures - implement the selected countermeasures, or include them in the plan for future operations
What the OPSEC process is designed to achieve
- Identify actions that may be observed by adversary intelligence systems
- Determine what specific indications could be collected, analyzed, and interpreted to derive critical information in time to be useful to adversaries
- Select countermeasures that eliminate or reduce vulnerability or indicators to observation and exploitation
- Preserve the commander's decision cycle and allow options for military action
The two PLEO service categories
- Connection-oriented services - continuous, always-on, low latency packet network connectivity, with a committed information rate and a maximum information rate
- Message-oriented services - pickup and delivery, store and forward, of discrete data blocks; includes SMS and texting, broadcast alert, and asset monitoring
What every PLEO service level agreement covers
- Near real-time usage, monitoring, and fault, incident, and outage reporting
- Routine reporting of service availability, activation, quarterly usage, faults, information assurance, and task order status
- Customer service support for technical and billing questions
- Reporting sufficient to account accurately for services provided
- User terminals where necessary for operational use
- Gateway and backhaul capability sufficient to move data between terminals and the commercial internet
- Continuous monitoring of information assurance compliance against IA-PRE or the COMSATCOM Information Assurance Questionnaire
Where each Module C reference publication answers a question the slides leave open
- DoDD 8140.01 - where the cybersecurity workforce roles and qualification standards in 113-SCCCC11 come from
- DoDI 8330.01 - why JITC is an authority and not just a helpline, and what it takes to put a system on a DoD network
- JP 3-13.3 - the process behind every EMCON and emissions decision in 113-SCCCC10
- PLEO brochure and service request form - the concrete route behind the suggestion in 113-SCCCC12 to get a liaison team online through the Space Force
- JITC DevSecOps guidebook - how continuously delivered software is tested and evaluated, which is the environment most Army software now ships in
- Defense of Battle Position Duffer - narrative cyber and command post lessons, covered with 113-SCCCC10 CEMA Basics
Key terms
- DoDD 8140.01
- Cyberspace Workforce Management, 5 October 2020. Issued under the Federal Cybersecurity Workforce Assessment Act of 2015, it unifies the DoD cyberspace workforce, authorizes the Cyberspace Workforce Management Board, and establishes the DoD Cyberspace Workforce Framework.
- Cyberspace Workforce Management Board (CWMB)
- The governing body authorized by DoDD 8140.01 to ensure the requirements of the issuance are met, and under which the cyberspace workforce elements are aligned and managed.
- Cyberspace workforce elements
- The specific workforce elements DoDD 8140.01 establishes to unify the overall cyberspace workforce: information technology, cybersecurity, cyberspace effects, intelligence, and enablers.
- Total force management perspective
- The DoDD 8140.01 policy stance that qualified government civilian and military personnel fill identified and authorized cyberspace positions, augmented where appropriate by contracted services support, functioning as one integrated workforce with complementary skill sets.
- DoDI 8330.01
- Interoperability of Information Technology, Including National Security Systems, 27 September 2022. It establishes how DoD IT interoperability requirements are stated, tested, certified, and enforced.
- Joint interoperability certification
- The certification, granted by JITC as the certification authority for DoD IT with joint interoperability requirements, that a system meets its interoperability requirements. Under DoDI 8330.01, IT does not connect to a DoD network without one, an interim certificate to operate, or an approved waiver to policy.
- Interim certificate to operate (ICTO)
- The time-limited alternative to a full joint interoperability certification that permits a system to operate on a DoD network while certification is pursued. Naming it is what separates a student who has read DoDI 8330.01 from one who has read the slide.
- Information Support Plan (ISP)
- The document through which a program states its information and interoperability requirements. ISPs go through joint review, and the DoD CIO assesses them for compliance with architecture, cybersecurity, spectrum, and related requirements.
- Net-ready requirements
- The interoperability content a program must carry in its requirements documentation. The net-ready performance attribute is what supports joint interoperability test, evaluation, and certification.
- JP 3-13.3
- Operations Security. The joint publication that defines the OPSEC process and its relationship to intelligence, information operations, cover, and cyberspace.
- Operations security (OPSEC)
- A capability that employs a process. Its purpose is to reduce the vulnerability of US and multinational forces to successful adversary exploitation of critical information. OPSEC is not a collection of rules and instructions - it is an analytical, planning, and executional process applicable to any operation or activity.
- Critical information
- Information that answers key questions likely to be asked by adversaries about specific friendly intentions, capabilities, and activities. Identifying it is the first step of the OPSEC process.
- OPSEC vulnerability
- A condition that exists when the adversary is capable of collecting critical information, correctly analyzing it, and then taking timely action to exploit it for advantage. All three parts must be true - collectible but unanalyzable information is not a vulnerability.
- OPSEC assessment
- An intensive application of the OPSEC process to an existing operation or activity. Distinct from an OPSEC survey, which is conducted by a team.
- Commercial Satellite Communications Office (CSCO)
- The US Space Force Space Systems Command office that holds the DoD's commercial satellite communications contracts, including the Proliferated Low Earth Orbit suite, and issues task orders in response to funded requirements from DoD elements.
- PLEO IDIQ contract
- A multiple-award indefinite delivery, indefinite quantity suite of contracts for proliferated low earth orbit satellite communications, with a ten-year period of performance - a five-year base and one five-year option.
- Service level agreement (SLA)
- The performance commitment incorporated into every PLEO task order, covering near real-time usage and outage reporting, routine availability and activation reporting, customer service support, accounting for services provided, user terminals where necessary, gateway and backhaul capability, and continuous information assurance compliance monitoring.
- Connection-oriented service
- PLEO service category providing continuous, always-on, low latency packet network connectivity. Distinguished from message-oriented service by the fact that the link stays up.
- Message-oriented service
- PLEO service category providing pickup and delivery - store and forward - of discrete data blocks rather than a continuous connection. Includes SMS and texting, broadcast alert, and asset monitoring.
- Committed information rate (CIR)
- The minimum data rate a PLEO subscription guarantees. Distinct from the maximum information rate, which is the peak rate the service may reach but does not promise.
- DevSecOps
- A software engineering culture and practice unifying software development, security, and operations, whose aim is to automate, monitor, and apply security at all phases of the software lifecycle. JITC published a guidebook for DevSecOps test and evaluation, version 1.0, July 2021.
- Software factory
- A software assembly plant containing multiple pipelines that develop, build, test, release, and deliver software, and that audits and logs system events. A software factory supports multiple tenants.
Testable points
- DoDD 8140.01 is dated 5 October 2020 and was approved by the Deputy Secretary of Defense.
- DoDD 8140.01 is issued in accordance with Sections 303 and 304 of Public Law 114-113, the Federal Cybersecurity Workforce Assessment Act of 2015.
- DoDD 8140.01 does three things: authorizes the Cyberspace Workforce Management Board, establishes the DCWF, and unifies the cyberspace workforce into specific workforce elements.
- DoDD 8140.01 introduces the workforce elements by example rather than as a closed list - it reads: specific workforce elements (e.g., information technology (IT), cybersecurity, cyberspace effects, intelligence, and enablers). Learn those five, but do not answer that the list is exhaustive.
- Under DoDD 8140.01, the appropriate mix of military positions, government civilian positions, and contracted support performing cyberspace work roles is determined in accordance with DoDI 1100.22.
- Civilian and military personnel performing cyberspace work roles must meet the qualification standards in DoD cyberspace workforce policy in addition to other applicable requirements, and these do not modify or replace Office of Personnel Management occupational qualification requirements.
- DoD component compliance with DoDD 8140.01 is monitored through authoritative manpower and personnel systems as an element of mission readiness.
- DoDI 8330.01 is dated 27 September 2022 and governs interoperability of information technology including national security systems.
- Under DoDI 8330.01, IT does not connect to a DoD network without a joint interoperability certification, an interim certificate to operate, or an approved waiver to policy. This is the rule most likely to catch a unit trying to field a locally procured solution.
- JITC serves as the joint interoperability certification authority for DoD IT with joint interoperability requirements.
- Programs must provide net-ready content in their requirements documentation, and the net-ready performance attribute is what supports joint interoperability test, evaluation, and certification.
- The DoD CIO assesses Information Support Plans for compliance with architecture, cybersecurity, and spectrum requirements, and designates certain ISPs affecting DoD enterprise strategic initiatives for special interest oversight.
- JP 3-13.3 states that the purpose of OPSEC is to reduce the vulnerability of US and multinational forces to successful adversary exploitation of critical information.
- OPSEC's most important characteristic is that it is a capability that employs a process. It is not a collection of specific rules and instructions.
- The OPSEC process consists of five steps: identify critical information, threat analysis, vulnerability analysis, risk assessment, and apply countermeasures.
- Risk assessment in the OPSEC process has three components: analyze the vulnerabilities and identify possible countermeasures, estimate the impact to operations, and select specific countermeasures for execution.
- OPSEC is an operations function, not a security function. OPSEC planning guidance should be provided as part of the commander's planning guidance and applied throughout the planning process.
- JP 3-13.3 states that attempting to deny all information about a friendly operation or activity is seldom cost-effective or realistic - which is why OPSEC identifies critical information rather than all information.
- Joint intelligence preparation of the operational environment, tailored to the OPSEC process, is a useful methodology for intelligence professionals supporting the OPSEC planner.
- The PLEO contract suite is a multiple-award indefinite delivery, indefinite quantity vehicle with a ten-year period of performance - five years base plus one five-year option.
- PLEO services are divided into connection-oriented services, which are continuous and always on, and message-oriented services, which store and forward discrete data blocks.
- Every PLEO service is covered by a service level agreement incorporated into each task order, including near real-time usage and fault reporting, routine availability reporting, customer service support, accounting for services provided, user terminals where necessary, and gateway or backhaul capability.
- PLEO information assurance compliance is continuously monitored against the Infrastructure Asset Pre-Assessment program or the established COMSATCOM Information Assurance Questionnaire.
- PLEO services are purchased through CSCO's normal Working Capital Fund reimbursable program, the same mechanism used for all CSCO contracts.
- The PLEO service request form is for government use only and is explicitly not to be shared or discussed with PLEO service providers, because task orders may be competed.
- Providers on the PLEO IDIQ include SpaceX, OneWeb, Iridium, Hughes, Intelsat General, Inmarsat Government, and more than a dozen others, which is why the request form captures requirements rather than naming a vendor.
- The JITC Guidebook for DevSecOps Test and Evaluation is version 1.0, dated July 2021, and was produced by the Joint Interoperability Test Command at Fort Huachuca, Arizona.
- The guidebook defines DevSecOps as a software engineering culture and practice that unifies development, security, and operations, with the aim of automating, monitoring, and applying security at all phases of the software lifecycle.
References
DoDD 8140.01DoDI 8330.01DoDI 8310.01DoDM 8140.03DoDI 1100.22JP 3-13.3CJCSI 5123.01