Showing posts with label NSCS. Show all posts
Showing posts with label NSCS. Show all posts

Thursday, September 13, 2012

Defence Reforms and Naresh Chandra Task Force Review


Vinod Anand
Senior Fellow, VIF

In May last year the government appointed a Task Force lead by Naresh Chandra and composed of 14 members to go into the recommendations and reassess the reforms required for improving the national security system. Over a decade back Kargil Review Committee had made many recommendations regarding defence reforms, revamping of India’s intelligence set up, internal security and border management. A large number of recommendations have been implemented over the years. However, some of the key recommendations like creating a Chief of Defence Staff have not been implemented; other recommendations like integrating Service HQs with the Ministry of Defence have only been paid a lip service to. The impetus for the defence reforms and some other reforms connected with intelligence and internal security had petered out when another strategic shock in the shape of Mumbai terror attacks of 26/11 was delivered. The Parliament’s Standing Committee on Defence (SCD) in their report of February 2009 had lamented upon the lack of unified concept of command and lack of integration of intelligence effort besides making a host of other observations.

It also needs to be noted that the government has as yet not declassified the Naresh Chandra report. However, brief details of some of the recommendations made by the panel have appeared in the media.

Is Permanent Chairman of COSC an optimal Solution?

The Naresh Chandra panel has recommended a permanent chairman for the Chiefs of Staff Committee which is expected to bring a certain degree of stability to this post as the senior most chief used to be in the chair with, on many occasions, a limited tenure in his job. The post is to be staffed by a four star general for two years. This recommendation is definitely a climb down from the earlier GOM recommendation of the Chief of Defence Staff. The UPA government has been mentioning that a political consensus is being obtained after having written to all the political parties regarding instituting the post of CDS. The SCD of 15th Lok Sabha in their second report (2009-2010) had again dwelt upon the need for CDS. Some relevant excerpts from the report are given below:

“ In the light of the fact that the Chairman of the COSC has no command and control authority over the Services other than his own, the Committee had expressed doubts over the efficacy of the system in emergent situations by ensuring quick response and coordinated action…. The Committee had recommended to take timely and appropriate steps to revise the composition of the COSC by creating a post of CDS to act as Chairman of COSC by evolving consensus on the issue. .. The Committee had also recommended to give appropriate authority to the Chairman COSC in the present set up to command and control the resources of the Defence Services whenever the situation so demands till such time the post of CDS is created.”

Therefore, it is quite evident that Naresh Chandra report’s recommendation should be treated only as an interim recommendation as the ultimate goal as suggested by SCD and earlier GOM report is to install a CDS. On the other hand there is also a view that due to lack of political consensus the recommendation for CDS can not be implemented in times to come and a permanent Chairman Chiefs of Staff Committee would be an optimal solution. However, as the Naresh Chandra report is not in the open domain and it is not clear as to what powers would be entrusted to the incumbent of the new post. Unless the permanent Chairman has appropriate budgetary and certain other command, control and coordination powers, giving a fixed tenure of two years may not serve much purpose. Further, the SCD had also observed that merely writing of letters by the Defence Minister to political parties was not enough; the issue could also be deliberated in the Parliament through various mechanisms available under the rules.

Integration of Services with the MOD merely Cosmetic

The Naresh Chandra Committee (NRC) has also recommended deputation of Army, Navy and Air Force officers to the MOD. This is by no means a new suggestion; this suggestion was given by the GOM Report and has been time and again pushed by the SCD. However, the record for the implementation such a recommendation has been less than satisfactory. For instance, the SCD of 14th Lok Sabha (currently it is 15th Lok Sabha) had ‘strongly’’ recommended the change in MOD staffing patterns to ensure armed forces were ‘‘intrinsically involved in national security management and apex decision-making process’’.

Further, even the new SCD (of 15th Lok Sabha) in its first report of December 2009 (after the current UPA government had taken over) had passed strictures against the non-representative nature of the cross-staffing pattern in the structure of HQ IDS which too is non-represented from Department of Defence (DoD), DRDO and MEA.
The staffing pattern in the MOD was recommended to be suitably modified so that the Armed Forces personnel of requisite expertise at the level of Joint Secretary/ Additional Secretary could be appointed. This was to ensure so that the Service HQs become intimately involved in national security management at the apex decision making processes. Thus NC report has merely repeated what has been earlier recommended many times. The moot point is whether the ‘babudom’ would implement this recommendation in letter and spirit. It also needs to be noted that a MOD official deposing before the SCD had categorically remarked that “Renaming of Army and Naval Headquarters as Integrated Headquarters is merely cosmetic, in the absence of posting of DoD cadre officers to Service Headquarters and vice versa, for participation in policy formulation.

The NC panel has also stressed on the need for IAS and other officers running the MoD, the National Security Council and other departments responsible for internal and external security being specially trained for the purpose. The practice of generalist officers running everything under the sun needs to be stopped. This recommendation is full of merit and needs to be seriously put into practice.

Defence Planning; the Problems Persist

The NCR has made a number of recommendations regarding defence procurement, defence preparedness and connected issues, however most of the details of such suggestions have not been revealed to the public as yet. In April 2012, the Defence Acquisition Council headed by the Defence Minister, for the first time had approved the 12th Services Capital Acquisition Plan (SCAP) and 15 years Long Term Integrated Perspective Plan (LTTIP, 2012-2027) for the modernization of the armed forces. It needs to be noted that 10th and 11thFYDP had lapsed without being approved and the LTIPP approvals were also not forthcoming. Since the previous Army Chief brought to notice the lack of defence preparedness to include deficiencies in equipment and ammunition, the government shifted gear and embarked on plan approvals and has planned for fast track acquisitions of artillery guns, helicopters and other equipment and ammunition. The pressure on the government was also felt in the Parliament when both the Opposition Leader and ruling party leaders expressed similar views on the need for shoring up the national security and defence acquisitions.

However, the above measures do not absolve the government/MOD from the charge of resorting to ad hocism in defence planning. The SCD in its report of August 2011 had expressed its unhappiness over the adhocism in the whole planning process in Defence Ministry; the Committee had strongly recommended that LTIPP should be finalized without any further delay.

Further, the Defence Minister and MOD had averred that a National Security Strategy document would be made from which would flow out Defence Guidance and thereafter a National Military Strategy would be formulated that would be reflected in our defence plans. But this promise remains only on the paper; the SCD of 14th Lok Sabha had deliberated on the issue however, now even the current SCD of 15th Lok Sabha has gone silent on it.

Another issue which has not been paid attention to is the question of an ‘integrated’ perspective plan as it is well known that LTIPP is not an integrated plan but merely an aggregation of different services’ plans. Integration would mean sacrificing one service’s budget perhaps for the other service which cannot really happen given the current organizational structures. That is why a CDS with suitable authority has been talked about. As mentioned earlier, even the NC report’s recommendation of permanent COSC could be useful if he was given appropriate budgetary and coordination powers. For instance, a proposal for raising a Mountain Strike Corps in the North East by the Army has been recently sent back (after one year of consideration at the MOD/government level) for reappraisal by the COSC so that requirements of other services can also be taken into account. Under the present system there is bound to cause further delay and again delay would be further compounded by the fact that there is no common view on NSS and threat perceptions; every service considers its own media to be important and it is only in some rare case that there could be some via media or agreement.

Defence Procurement: Bedevilled by Delays

Our defence procurement system which has been modified and improved many times without resulting into any appreciable improvements on the ground. Our procurement system, organisations, procedures and mechanisms have not been able to fast track the acquisitions which the armed forces need to narrow the capability gap which exists with our potential adversaries. Last year, Comptroller and Auditor General castigated the entire arms procurement process and cited several incidents of inordinate delays. There have been unacceptable delays in obtaining critical air defence equipment and spares for damaged Israeli aerostat radars; the weapon packages for MIG-29Ks meant for our aircraft carrier were not finalised as a result they were delivered without weapon systems and because of poor monitoring and inadequate attention to contracts clauses additional problems arose in acquisition of Low-Level Transportable Radars.

As mentioned above the SCAP and LTIPP have been approved in April this year along with enhancing of financial powers of acquisition authorities in order to inject speed and flexibility in the procurement process. Defence Minister has also stated on the floor of Parliament that functionaries at Service HQ level have been delegated with financial powers to process procurement cases upto Rs.50 crore, Capital Cases above Rs.50 crore and upto Rs.75 crore are approved by Defence Secretary. There is a proposal also to increase the amount further

It is yet to be seen how the above proposals will fast track the proposed acquisitions.

However, in one of the controversial recommendations by the Naresh Chandra Committee it was proposed that the practice of blacklisting firms of suppliers should be discontinued. It has also suggested that the Prevention of Corruption Act be modified to give a certain degree of protection to officers dealing in defence purchases as there are possibilities of making 'an error of judgement'. This flies in the face of the procurement procedures which are based on the principles of probity, integrity and transparency and so on. Without doubt there is a need to streamline the procedures but including the above provisions would only add to more flaws and possibilities of wrong doing in the defence purchases.

NC Task Force has also recommended that situation where we need to import 70 percent of our military hardware needs to be rectified. These include a greater role in indigenous production of the private sector. The Defence Research and Development Organisation should work in closer cooperation with the armed forces than is the case at present. Not that these are original recommendations but nevertheless being a report to the government reiteration of such requirements possibly would motivate the decision makers earmark funds and efforts for achieving such long term goals.

Special Operations Command

Naresh Chandra panel has also recommended forming of a Special Operations Command to take under its wing the special forces of Army, Navy and Air Force. The objective is to have a synergetic application of forces for strategic tasks by bringing them together in a unified command and control structure; the SOC would be placed under the COSC. NC panel is of the view that India needs to enhance its unconventional and special warfare capabilities to execute poitico-military and connected operations to meet unconventional challenges. According to the report the full potential of the Special Forces is not being utilised, there fore the need for bringing them together and employing them for effective covert operations including counter-terror tasks. After the raid by the American Navy Seals on Osama Bin Laden’s hideout some of our military leaders had mentioned that similar raid could be carried out by our Special Forces. Perhaps with better training, technical and special equipment, weapon systems and ISR support our forces would be in a position to carry out such tasks.

Revamp of Intelligence and Cyber Space Protection

Coordination of intelligence and presenting one joint intelligence picture to the to the apex decision makers has been the bane of our intelligence processes, procedures and organizations. Naresh Chandra report has recommended a post of intelligence adviser to assist the National security Adviser; in addition it has recommended a National Intelligence Board (NIB) for coordination of intelligence. It needs to be noted that erstwhile Joint Intelligence Committee had been merged with the National Security Council Secretariat (NSCS). The moot point is how would the functioning of new NIB be different from the existing set up in the NSCS?

Another issue which is acquiring alarming proportions is the question of cyber security with our critical infrastructure and other systems having already faced many cyber attacks over the last one year or so. The National Technical Research Organisation, Defence Intelligence Agency and Computer Emergency Response Teams at various levels need to be strengthened to face the challenges of Cyber War which goes on even during peace time. Cyber Jihad launched by some of the Pakistani based militant and terror groups in July-August 2012 to spread hate campaign against the people of North-East working in rest of India created panic and turmoil. Our response was slow and limited. While the need for a Cyber Command (on the similar lines to that of U.S. Cyber Command) to look after the military aspects of Cyber warfare has been felt there is also a requirement of a central entity/organization to coordinate the civilian efforts to protect the cyber space. At present there are over a dozen entities/organizations like Ministry for Home Affairs, Ministry of Communications and information Technology, the National Disaster Management Authority, National Information Board and Computer Emergency Response Teams at various levels besides some other have been tasked with looking after cyber security. They are inadequately staffed and insufficiently funded; needless to say there are turf battles and their mandate is inadequately defined. Thus, coordination of their efforts would lead to efficient management of and timely response to challenges in the cyber space.

Other Recommendations by Naresh Chandra TF

The report recommends many other measures to be taken to improve the internal security mechanisms. For counter terrorism it has recommended a National Counter Terrorism Centre (already recommended by the MHA), a National Intelligence Grid, strengthening of policing and distributed deployment of NSG.
The TF has emphasized on early setting up of much delayed project of establishing India’s National Defence University (INDU) and creation of a separate think-tank for internal security. Kargil Review Committee and GOM Report had also made similar recommendations for INDU; despite allotment of funds and land for the project nothing substantive seems to have been achieved so far even after lapse of over a decade.

Conclusion

Largely the Naresh Chandra Committee has made recommendations which have already been made by either the KRC or GOM or by the Standing Committee on Defence. Possibly there are other recommendations which are new but as the report is not in the public domain it would be difficult to evaluate the new aspects included in the report. However, the record of implementation of the recommendations by the government has been mixed. The report does serve the purpose of bringing into focus once again the inadequacies in our national defence and security system and thus the imperatives to rectify them. At the geo-political and geo-strategic level it does talk about challenges being posed by China and Pakistan on the military and security front and thus the need to be fully prepared to meet such challenges and threats arising from that direction. Periodical review of our defence preparedness and formulating our National security Strategy, Defence Planning Guidance and National Military Strategy in a formalized manner along with reappraisal of all the processes, structures and associated aspects is a must. Strengthening our military capabilities and internal security efforts are intricately linked with our broader political and economic objectives. If India has to survive as a modern and progressive nation that wishes to achieve its long-cherished goal of strategic autonomy, defence and security reforms have to be ushered in at a faster pace than hitherto before.

Thursday, July 26, 2012

Preparing for Cyberwar - A National Perspective


Commander Mukesh Saini (Retd.)

On November 12th, 2011 Maj. Gen. Moghaddam, the "architect" of Iran's missile program, was showing a new type of warhead for nuclear weapon capable missile Sejil 2, to a group of experts for their comments, at a site about 50 Kms from Tehran. Warhead was connected to computer for simulation which was being watched on a big screen. And instead of simulation the actual warhead went off pulverising the site. Explosion was so powerful that it could be heard in Tehran. Initially Iranian government refused to accept that there was any such explosion however later conceded that in the explosion 17 officers of Revolutionary Guards have lost lives (though 36 funerals took place). Explosion was so powerful that no one was alive to narrate the incident and nothing was left at the site to provide evidence. Revolutionary Guards (IRGC) investigation pointed at two probabilities; (a) infiltration by a Mossad operative or (b) computer controlling the missile was infected with Stuxnet (like) worm. The second probability was considered much more likely after two well-known cyber infiltrations using Stuxnet and Duqu to stall Iran’s nuclear ambition. Probably this incident is historic as for the first time cyber weapon was used to cause real world explosion or kinetic attack. (Israel Insider, 2011)

Introduction

Cyberspace has changed many old concepts. In this globalised world everyone is neighbour of other. There is no established concept of boundaries. Identification of targets and what is under threat or need to be attacked in case of Cyberwar is important to segregate the facet of Cyberwar from wars using other form of attacks on ground, air and as Sea. What needs to be secured is what needs protection. Therefore definition of Cyber security will give fair idea about the scope of Cyberwar and its targets. The Information Technology Act 2000 (India) defines Cyber Security which means protecting information, equipment, devices computer, computer resource, communication device and information stored therein from unauthorized access, use, disclosure, disruption, modification or destruction. Richard A. Clark in his book Cyber War defines "cyberwarfare" as "actions by a nation-state to penetrate another nation's computers or networks for the purposes of causing damage or disruption. However things are not as simplistic and materialist but a game of mind and perception also.

To understand the real meaning of Cyberwar, it is necessary to understand the meaning of War and its import on governance and diplomacy. The British Parliamentary Committee in its report after Iraq war noted that “War” is a term that has both popular and legal connotations. Colloquially, “war” embraces conflicts between the armed forces of states and, occasionally, major internal conflicts such as the British or American Civil wars. “War” as a legal institution is a feature of both international and national law. In international law, the distinguishing characteristic of “war” is the legal equality of the belligerents and the special status of those states not taking part in the conflict (“neutral” states). The condition of “war” could be brought about by a declaration of war but one was not necessary (nor, where there was a declaration of war, were hostilities inevitable). Additionally, states could choose to regard a conflict between them as “war” and apply the legal rules accordingly, or neutrals could insist on respect for their rights. “War” as an institution of domestic law did require a declaration, made in the Monarch’s name but by the Prime Minister, acting under the prerogative. This action triggered domestic consequences—nationals of the opponent state became “enemy aliens”, liable to measures of restraint including detention. Property of enemy aliens was liable to seizure. Statute provided for emergency measures—for the call up of troops, the sequestration of property and so on. (Constitution, 27 July 2006)

To fit this definition of War the only Operation Orchard fits the bill were Air Defence System of Syria was made ineffective by Israel during their attack on alleged nuclear plant of Syria. In all other cases be it cyber-attack on Estonia, Georgia or Operations Titan Rain, Night Dragon Shady Rats etc may not be termed as the acts of war. The case of explosion at Iran’s missile site lacks affirmation and evidence.

War has International Ramifications

Various international laws and treaties especially of Paris and also Charter of United Nations prohibit use of threat or use of force in international relations. Prior to these developments post 1945, declaration of war was a standard practice, but today no one officially declares war to the international community. This is nothing but just masking because internally a nation state has to declare war, whether limited in scope or a full-fledged war. This is necessary to activate appropriate structures; authorisation to force commanders to use Rules of Engagement (R.o.E) for ‘conflict’; activate provisions of War-Book; freezing of assets of enemy aliens; mobilisation of resources; suspension of local laws against the enlisted personnel engaged in war; and even enforcing ‘Emergency’ in the country. Thus a war whether declared or otherwise is a ‘structured-response’ to a conflict which is expected to result in subjugating the enemy to the will of a nation.

National Information Security Policy & Doctrine of Cyberwar

It is necessary to define what would constitute an “attack” serious enough to precipitate into military counter offensive. It is necessary to define this line in an open stated policy, so that in case of any military retaliation, the international community can be with India. However defining this Lakshman Rekha is not easy. If the threshold is kept too law then breaches will be norm and finding exception where counter offensive becomes necessary in a transparent manner would be difficult. If the threshold is kept too high then nation can be bled by thousand wounds rather than massive attack and no formal retaliatory force can be used.

Another challenge is attribution. Cyber-attack may appear to be originated from one or multiple countries but actual culprit may be a third country. Recently in April 2012, National Informatics Centre has told the press that some unknown third country has used its servers to attack other countries including China. (Joseph, 2011) This statement had two immediate adverse effects on our cyber war preparedness, firstly it has exposed our vulnerabilities that we do not have sufficient capacity to identify originating country despite servers and logs are under our control and secondly it has provided a perfect alibi to our enemies to attack us and deny ownership of such attacks. Can we now blame China for attacks on Indian cyberspace?

Thus attribution is critical for appropriate response. In fact noting this fact, Annual Report 2011-2012 by Intelligence and Senator Committee of UK has termed cyber attack as a ‘Tier One threat to UK and has direct to government to inter-alia develop capabilities of cyber-attack without detection ( or at least without attribution). The UK government has been allocation of funds equivalent to Rs. 5720 Crores over next 3 years for National Cyber Security Program to prepare for cyber-attack. The committee has also advised the intelligence agencies to not to use such technologies against own citizens except with specific approval. (Intelligence and Security Committee, UK, 2012)
In 2005, after 2 years of extensive deliberations between 21 ministry/departments of the government and industry confederations, National Information Board under NSA Sh. JN Dixit had approved the draft National Information Security Policy (NISP), it is yet to be approved by the government. In the mean while Department of Electronics & IT drafted another NISP (apparently without wider consultation) and sought public opinion in 2011. Nothing has been heard of new NISP since then. Due to this intervening period on this front we moved from leader to laggard. Without such policy defining Information Warfare Doctrine for nation (not a doctrine by Armed forces) will be distant dream. Therefore to fight as well defend against future cyber-attacks, it is paramount that a good quality and well consulted over-arching NISP is finalized and formally declared. And based on this IW Doctrine for India (inclusive of Intelligence Services as well as private sector) be developed.

Amendment to National War book

Once as a policy India declares the existence of cyber war and its contours, and also develop cyber war doctrine, the war book required to be amended accordingly. The role and responsibility required to analyze and articulated to prevent confusion and fratricide at the time of war. It is also essential for efficient and effective conduct of war including cyber-war. The war book therefore needs to specify as how to maintain no-contact cyber war and when the government decide to go for full-contact or partial-contact war then how cyber war will be integrated to meet overall war objectives. The war is the only place which mandates the change in command and control structure and transfer of certain powers to military. It is the war-book which will clarify the intra-government relationship and any failure to do so can lead to turf war and chaos at the time of crisis.

Rule of Engagement

The offensive Cyber operations by the enemy will be swift and paralyzing. Therefore central control of conduct of cyber war may not be the good idea. It is necessary to define as unambiguously as possible Rule of Engagement for cyber warriors (whether uniformed or militia). Uncontrolled offensive can not only hurt in retaliatory fire against unplanned defensive measures but also can isolate us in community of nations. The role of diplomatic cadre can therefore never to be underestimated in events leading up to full scale cyber war. The National Internet Exchange (NIXI) is up and running to defend our intra-India Internet in case of worst situation, isolation but poor defensive mechanism, lack of capacity can paralyze us and can cause loss of our will to fight back. Therefore it is necessary to coordinate not only with in the government and armed forces but also with private sector as well as patriotic hackers outside the government and RoE for everyone should be articulated. While preparing RoE the issues highlighted in following paragraphs must be addressed.

According to RoE of most of the Armed Forces of the world, Line of Communication and nodes which directly or indirectly supports military operations of belligerent nations are valid military targets. By this Rule of Engagement all telecommunication and internet service providers are legitimate targets during any Cyber war. However when the Hague rule (1923) of Air warfare article 24(2) was prepared the dependency of life of masses on communication structures was not as heavy as it is today. Not even at the time when in 1956 New Delhi Draft rules were prepared, which clearly established that “The objectives belonging to the following categories are those considered to be of generally recognized military importance: ... (7) The installations of broadcasting and television stations; telephone and telegraph exchanges of fundamental military importance.” there was no Internet. Now technically it is possible to mount unbearable misery on masses through attacking on Critical Information Infrastructure. The question is that if such an attack is undertaken, will it amount to war-crime?

While dealing with IHL /LOAC, the British Parliamentary Committee felt, “The situation is different, however, in the case of breaches of IHL. The Minister of State for the armed forces told us that “once a conflict actually begins, whatever the legal basis for this participation, it is conduct by all participants as required by the body of law in rules known as the International Humanitarian Law. The four Geneva Conventions of 1949 are a part of that IHL. The United Kingdom is also bound by a number of other conventions and protocols, such as the first additional protocol to the Geneva Conventions ... Those are not our laws. We apply them. Those have been defined elsewhere and we simply live within them, so to speak”. Mr. Ingram added that “all of our personnel are so trained in understanding the basis upon which they are having to conduct themselves in a conflict situation and it is very much part of the whole training process”. Individuals (and in some cases their commanders) suspected of violations of IHL such as killing prisoners of war, the ill-treatment of detainees in occupied territory or the use of prohibited weapons must be considered for prosecution in national courts. The Government has said, in the context of the ICC, that all allegations of this kind would be stringently investigated and, where appropriate, criminal proceedings instigated. This duty, which mainly derives from the Geneva Conventions, has gained in importance following the United Kingdom’s acceptance of the Statute of the ICC. The prosecution of those alleged to be responsible for serious violations of IHL is within the jurisdiction of the ICC, but only where the proceedings in national law have been unsatisfactory or non-existent. The Government’s position has been that there will never be prosecutions against British servicemen before the ICC because there always will be adequate national investigations, followed, where required, by prosecutions. (Constitution, 27 July 2006)

Need for Coordination and Control

The cyber-attack on Iran in form of Stuxnet, Duqu and Flamer are just peek into the future. US President has repeatedly stated that cyber-attacks are most serious economic and national security challenge that America faces. To meet this challenge US has introduced Cyber security Act 2012 in Senate on 20th July 2012. (BBC, 2012). US conducts exercise ‘Cyber Strom’ every alternate year. NATO, Australia and many European countries undertake extensive cyber security exercises to improve command, control and coordination. A formal Cyber command and control structures have been established in most of the first world countries and China.

Unlike military war, the non-state actors such as terrorist organization, large corporate houses, hacktivist, cyber privateer and cyber insurgents have capacity and will to take on nation states. Wikileaks, Anon, Luzesec were some of the non-state players who have challenged the might on nations including the United States of America. Large organizations such as Intel, Microsoft, Huawei, etc can also play role to support their respective government. In case of ‘Flamer’ virus original Microsoft Digital Signature was misused. (Adhikari, 2012; Adhikari, 2012).

It is myth that hackers will win or lose the cyber war. Hackers (with due respect) are just foot soldiers, and wars are fought by General who are visionary, know their forces, understand enemy forces as well as mind of their commander, can coordinate with other wings of the government and first of all finest leader who draws respect from his soldiers (Hackers).

In India we are yet to formally recognize the dangers, not because it is not so recognized in the power circle but just because it is so recognized as one of the most powerful tool that everyone wants to play the lead role and turf war has broken out. Institute of Defence Studies and Analyses has attempted to give some course correction to this rudderless situation through its recently released book ‘India’s Cyber Security Challenges’. (IDSA, 2012; IDSA Task Force, March 2012) However overall paralysis is continuing and well planned structure such as CERT-IN, NTRO and NSCS are being consistently undermined. It is therefore necessary the National Information Board (a board of score of secretary ranked officer) be resuscitated and board meeting be held at least every quarter till things stabilise and we as nation become competent to defend our cyberspace.

Role of Defence Forces

Role of defence forces in case of Cyber war is limited. They are required to protect only its own domain and at the most government domain such as .gov.in, .mil.gov.in, army.in etc. But if this control is not practiced in peace time same cannot be undertaken in war time. In fact probably intelligence agencies and CERTs are better positioned to take on such tasks. However IHL and LOAC neither cover nor envisaged to cover the activities of Intelligence agencies. Similarly for offensive operations, intelligence agencies that had undertaken surveillance of enemy networks and probably placed backdoors and spybots in the target network may be more suitable for offensive action. For example if National Security Agency of US have deployed the launch pads of cyber weapons then NSA alone will be in better position to arm and launch cyber weapons from these pads. In case of Duqu probably some intelligence agency was controlling the Command & Control centres of Duqu. Non applicability of IHL / LOAC on such agencies is a glaring flaw in scheme of things for containing any Cyberwar. And also launching Cyberwar on other nation without adequately protecting own cyberspace will be similar to MAD (Mutually Assured Destruction / Disruption) of nuclear war.

Cyberwar also challenges some of the basic tenet of armed conflict. What is use of fighting personnel to wear uniform when the opposing forces are not going to be physically present in front of each other? How would belligerent forces know that attacking party is enlisted or a civilian? Suppose all major data of one of the belligerent nations are encrypted and made unusable, will the data which may be very vital for the survival of the population amount to prisoner-of-war? If collision of train takes place due to intentional malfunctioning of signalling system leading to death of masses, will it amount to War Crime?

Conclusion

War is serious matter which involves lives of all citizens. Even if external declaration of war has become redundant, this is required internally to divert resources for fighting the war. When war get (internally) declared there are changes in organisational structure of governance; War Book comes into force; Rules of Engagement changes; financial allocation made; civilian criminal laws stand suspended for actions taken in pursuance of war; and National Emergency may be declared. These are too profound changes which cannot be taken lightly. Therefore every cyber-attack does not amount to cyber war. Involvement of defence forces along with enlisting of hackers and allocation of cyber-targets for proper coordination is required. The international treaties and conventions such as IHL and LOAC come into force. Wars are not limited to action on ground but diplomatic struggle also begins. Non-state actors have the ability to stand winnable chance against a nation state. Therefore it recommended that Cyberwar be looked at with all seriousness and following steps should be take-up in double quick time to prepare our nation for Cyberwar:

a. Declare National Information Security Policy after wide consultation with all stake holders. Such policy should be as much as possible technology neutral, overarching and long lasting;

b. Evolve Cyber warfare doctrine and develop capacity to implement such doctrine;

c. Modify National War-Book to include this new form of war and its peculiar characteristics such as no-contact war and role of non-actors;

d. Define Rule-of-engagement for Cyberwar to prevent unintended escalation of war and unintended Human Rights violations;

e. Establish command and control structures for efficient and effective conduct of Cyberwar and prevent turf war within during the period of crisis.

f. And to do all this and much more, National Information Board should meet at frequent interval; else Cabinet Committee on Security should find an alternative.

Bibliography

Adhikari, R., 2012. Flame Singes Microsoft Security Certificates. [Online]
Available at: http://www.technewsworld.com/story/75289.html [Accessed 20 June 2012].

BBC, 2012. News Technology. [Online]
Available at: http://www.bbc.co.uk/news/technology-18928854 [Accessed 21 July 2012].

Constitution, S. C. o. t., 27 July 2006. Waging war: Parliament's role and responsibility Volume I: Report,London: HOUSE OF LORDS.
Hague Convention V, 18 October 1907. Hague Convention V. [Online]
Available athttp://avalon.law.yale.edu/20th century/hague05.asp [Accessed 05 May 2012].

IDSA Task Force, March 2012. India's Cyber Security Challenges, New Delhi: Institute of Defence Studies and Aanlysis. IDSA, 2012. India's Cyber Security Challenge. First ed. New Delhi: IDSA.

Intel Technology Brief , 2011. Protect Laptops and Data with Intel® Anti-Theft Technology. [Online] Available at: http://www.intel.com/technology/anti-theft/anti-theft-tech-brief.pdf [Accessed 24 May 2012].

Intelligence and Security Commitee, UK, 2012. Annual Report 2011-2012, London: Controller of Her Majesty's Stationery Office.
Israel Insider, 2011. Suspicion in Iran that Stuxnet caused Revolutionary Guards base explosions. [Online]

Joseph, J., 2011. Govt servers used for cyber attacks on China, other countries' networks. [Online] Available at: http://timesofindia.indiatimes.com/tech/news/internet/Govt-servers-used-for-cyber- attacks-on-China-other-countries-networks/articleshow/10760699.cms [Accessed 24 July 2012].

Quintin, K. J. a. A., 18 November 2011. The Internet in Bello: Cyber War Law, Ethics & Policy. Berkeley, UC Berkeley School of Law.