Start a free trial
Menu

AJP-3.20

AJP-3.20 Allied joint doctrine for cyberspace operations

NATO commanders, staffs and forces planning and conducting cyberspace operations, not a commercial supplier

AJP-3.20 is NATO's Allied joint doctrine for planning, conducting and assessing cyberspace operations within Alliance joint operations, binding nations through STANAG 6514.

Edition
A
Published
2020-01

What it is

AJP-3.20 is NATO's Allied Joint Doctrine for Cyberspace Operations: the doctrine "to plan, execute and assess cyberspace operations (CO) in the context of Allied joint operations." It "is a part of NATO’s operations architecture and derives its authority from and complements AJP-3, Allied Joint Doctrine for the Conduct of Operations." Edition A, Version 1, was promulgated 29 January 2020 and is "effective upon receipt." Nations record their agreement to use it through STANAG 6514, so this is guidance for a military chain of command, not a requirement written for a company. It is "intended primarily as guidance for NATO commanders, staffs and forces," though it extends further, to "a coalition of NATO member states, partners, non-NATO nations and other organisations," and provides "a reference for NATO civilian and non-NATO civilian actors." The single mention of industry anywhere in the text is as a target of adversary espionage, "government departments and the defence industry," never as someone the doctrine directs.

What cyberspace is, and how a cyberspace operation is built

The doctrine defines cyberspace as "the global domain consisting of all interconnected communication, information technology and other electronic systems, networks and their data, including those which are separated or independent, which process, store or transmit data," and describes it through a three-layer model: a physical layer of hardware tied to a geographic location, a logical layer of firmware, operating systems, protocols and data, and a cyber-persona layer of virtual identities that do not map one-to-one onto real people or organisations. A cyberspace operation is "actions in or through cyberspace intended to preserve friendly freedom of action in cyberspace and/or to create effects to achieve commanders’ objectives," and "COs are always conducted at the logical layer, encompassing direct effects to software, data and protocols," even where indirect effects land elsewhere. The doctrine sets out the threat picture, state actors, non-state actors (including proxies), criminals and insiders, and works through how cyberspace operations support each of the other joint functions: manoeuvre, fires, command and control, intelligence, information, sustainment, force protection and civil-military cooperation.

Command: the Cyberspace Operations Centre

Day-to-day responsibility for NATO's communication and information systems sits with AJP-6, but cyberspace operations additionally answer to the Cyberspace Operations Centre (CyOC), which "serves as the primary point for coordination of NATO COs." The CyOC is tasked to optimise the employment of cyberspace effects, advise SACEUR and NATO's command and force structure, and facilitate the integration of Sovereign Cyber Effects Provided Voluntarily by Allies (SCEPVA), the mechanism through which a nation offers its own cyber capabilities to an Alliance operation. Command of those forces "remains with the contributing nation" throughout; a nation lends effects, not authority over them.

Two types of operation, one dividing line

The doctrine splits cyberspace operations into defensive cyberspace operations (DCOs), aimed at preserving NATO's own freedom of action and force protection, and offensive cyberspace operations (OCOs). Any OCO "will be conducted through the SCEPVA mechanism in accordance with the principles agreed to by NATO," and during an armed conflict any OCO "will come through the Sovereign Cyber Effects Provided Voluntarily by Allies (SCEPVA) mechanism and only in the context of a NAC approved operation or mission." A deviation from that general rule "would require the express approval of the NAC." The characteristics that set cyberspace apart from the other domains run through both operation types: reach that is "largely unaffected by the boundaries and limitations that generally apply to other domains," an asymmetric potential for a small actor to create a disproportionate effect, anonymity that means "many incidents are likely to be deniable and some untraceable," and effects that can arrive within milliseconds or after a long, deliberately extended preparation period. The effects a cyberspace operation can create, adapted from STANAG 2287, span secure, isolate, contain, neutralise, recover, manipulate, exfiltrate, degrade, disrupt and destroy, each given an operational meaning of its own; disruption, for instance, is treated as "a special case of degradation where the degradation level selected is 100 percent for a period of time."

The legal framework commanders work within

NATO Allies "recognise that international law applies in cyberspace," and cyberspace operations "must be conducted in accordance with international law, including the United Nations (UN) Charter, Law of Armed Conflict (LOAC) and human rights law, as applicable." The doctrine works through when effects might amount to a use of force or an armed attack, how dual-use objects such as airports, electrical systems and network infrastructure complicate identifying a lawful military objective, collateral damage estimation, the principle of distinction, the law of neutrality, and collective self-defence, noting that "a decision to invoke Article 5 of the North Atlantic Treaty would be taken by the NAC on a case-by-case basis." Before conducting a cyberspace operation, "commanders, planners and operators must understand the relevant legal framework and authorities under which they are operating to comply with applicable laws, treaties and policies," and the doctrine adds that it is essential to consult legal counsel familiar with cyberspace operations during planning and execution.

Planning, conduct and targeting

Planning for cyberspace operations follows NATO's normal operations planning sequence, initiation, mission analysis, course of action development, analysis, validation and comparison, and the commander's decision, with cyberspace-specific inputs feeding each stage, including a recognised cyberspace picture that supports situational awareness. Risk management runs throughout: "Since cyberspace is a global domain, there is a risk of COs having an impact outside the joint operations area." Conduct covers pre-deployment training and preparing the joint operations area, then execution: command and control arrangements, battlespace management, the battle rhythm boards a cyberspace input feeds, and assessment, which the doctrine says "is integrated into all phases of the planning and execution processes" using measures of effectiveness and measures of performance that "need to be objective." Cyberspace operations are considered in the joint targeting process alongside every other capability, and AJP-3.9, Allied Joint Doctrine for Joint Targeting, "provides guidance for integrating targeting into operations, and the fundamentals on how to integrate COs into the targeting process."

How you get it

AJP-3.20 is published by the NATO Standardization Office and, like every NATO standardization document, carries no charge: "NATO does not charge any fee for its standardization documents at any stage, which are not intended to be sold." The NSDD listing for AJP-3.20 is the authoritative source, and national standardization authorities can also supply a copy. We credit NATO for the catalogue and neither sell nor host a copy ourselves.

How we help

AJP-3.20 is doctrine addressed to NATO commanders, staffs and forces, and it names no channel at all for a company to participate directly, no collaborator role, no scheme a business is measured against, no evidence a supplier is asked to produce. There is nothing here for a company to build a management system around.

Where this doctrine is relevant to a ComplyTrain customer is as background: it explains the command and legal framework NATO uses to plan, conduct and assess cyberspace operations, which is context for why a defence customer's own security or contractual requirements are shaped the way they are. What ComplyTrain supports is the work a defence contractor does regardless of which document a contract names: holding the procedures, training records, corrective actions and audit trail that a specific quality or security clause requires.

What we do not do: we do not conduct or advise on cyberspace operations, and we do not interpret the legal or targeting questions this doctrine describes. We make no claim to implement, align with or map to AJP-3.20, because the document itself names no scheme to map to. What applies to a specific contract is set by that contract and the customer's own quality clause, not by this page. The standards explorer shows what else sits in the catalogue alongside AJP-3.20, and we are glad to talk through what your contract actually requires.

Standards it references

Questions

Does AJP-3.20 apply to my company?

Not directly. AJP-3.20 is guidance for NATO commanders, staffs and forces planning and conducting cyberspace operations; it never names a supplier, manufacturer or contractor as its audience, and the single mention of industry in the text is as a target of adversary espionage, not as an actor the doctrine directs. A company's obligations, if any, come from a specific contract or security requirement, not from AJP-3.20 itself.

Is AJP-3.20 a STANAG?

No. AJP-3.20 is the Allied Joint Publication, the doctrine itself. STANAG 6514 is the Standardization Agreement by which NATO nations record their agreement to use it. The STANAG is the cover; AJP-3.20 is what it covers.

What is the difference between defensive and offensive cyberspace operations?

Defensive cyberspace operations preserve NATO's own freedom of action and force protection in cyberspace. Offensive cyberspace operations project power to create effects that achieve military objectives, and any offensive cyberspace operation is conducted through the Sovereign Cyber Effects Provided Voluntarily by Allies (SCEPVA) mechanism, with a nation retaining command of the forces it contributes.

Does ComplyTrain map to AJP-3.20?

No. AJP-3.20 has no certification, audit or accreditation scheme for a company to map a product against, and ComplyTrain makes no claim to implement or align with it. Where ComplyTrain helps is with the internal procedures, training records and audit trail a defence contract's own quality or security clause requires, whatever standard that clause names.

How current is this edition?

This page describes Edition A, Version 1, promulgated 29 January 2020 and effective upon receipt. The document names no earlier edition it supersedes.