The Department’s cyberspace objectives are:
1. Ensuring the Joint Force can achieve its missions in a contested cyberspace environment;
2. Strengthening the Joint Force by conducting cyberspace operations that enhance U.S.
military advantages;
3. Defending U.S. critical infrastructure from malicious cyber activity that alone, or as part
of a campaign, could cause a significant cyber incident;31
4. Securing DoD information and systems against malicious cyber activity, including DoD
information on non-DoD-owned networks; and
5. Expanding DoD cyber cooperation with interagency, industry, and international partners.
DEFENDING CIVILIAN ASSETS THAT ENABLE U.S. MILITARY ADVANTAGE
The Department must be prepared to defend non-DoD-owned Defense Critical Infrastructure
(DCI) and Defense Industrial Base (DIB) networks and systems. Our chief goal in maintaining an
ability to defend DCI is to ensure the infrastructure’s continued functionality and ability to support
DoD objectives in a contested cyber environment. Our focus working with DIB entities is to protect
sensitive DoD information whose loss, either individually or in aggregate, could result in an
erosion of Joint Force military advantage. As the Sector Specific Agency (SSA) for the DIB and
a business partner with the DIB and DCI, the Department will: set and enforce standards for
cybersecurity, resilience, and reporting; and be prepared, when requested and authorized, to
provide direct assistance, including on non-DoD networks, prior to, during, and after an incident.
1
“Defense Critical Infrastructure” refers to the composite of DoD and non-DoD assets essential to project, support,
and sustain military forces and operations worldwide (Department of Defense Directive 3020.40).
2
“Defense Industrial Base” refers to the Department, Government, and private sector worldwide industrial complex
with capabilities to perform research and development, design, produce, and maintain military weapon systems,
subsystems, components, or parts to satisfy military requirements (32 CFR Part 236).
3
“Significant cyber incident” refers to an event occurring on or conducted through a computer network that is (or a
group of related events that together are) likely to result in demonstrable harm to the national security interests, foreign
relations, or economy of the United States or to the public confidence, civil liberties, or public health and safety of the
American people (Presidential Policy Directive 41).
3
DOD CYBER STRATEGY