惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
WordPress大学
WordPress大学
爱范儿
爱范儿
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
博客园_首页
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
MyScale Blog
MyScale Blog
IT之家
IT之家
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
人人都是产品经理
人人都是产品经理

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
White House Memorandum Establishes Framework for Governme...
2026-08-20 · via Privacy & Cybersecurity Law Blog

White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations

On August 12, 2026, President Trump issued a memorandum directing the creation of a federal program (the “Program”) under which vetted U.S. companies may be authorized to conduct certain cyber operations against foreign cyber-enabled transnational criminal organizations (“CE-TCOs”) under U.S. government control and oversight. The memorandum assigns joint leadership to the Department of Justice (“DOJ”) and Department of Homeland Security (“DHS”), requires implementing procedures within 60 days, and sets out the basic structure, approval requirements, operational definitions, and safeguards for the Program.The memorandum states that the Program is intended to expand federal efforts to combat cyber-enabled crime, fraud, and related schemes targeting Americans by incorporating private-sector cyber capabilities into government operations.

Program Structure

The memorandum directs the National Coordination Center (“NCC”), established pursuant to Executive Order 14159, to create, manage, and maintain the Program.

The Program will authorize private “Participating Companies” to conduct Cyber Surveillance Operations and Cyber Effects Operations. The memorandum states that these operations are to be conducted exclusively on behalf of, and under the supervision of, the federal government as part of lawful investigatory, protective, or intelligence operations carried out by federal law enforcement.

The Program is to be overseen by two co-Executive Directors, one from the DOJ, designated by the Attorney General, and one from DHS, designated by the Secretary of Homeland Security. These officials may approve cyber operations after coordinating with one another, except for operations resulting in defined “Critical Outcomes.”

Participating Companies

The memorandum defines “Participating Companies” as private U.S. companies accepted into the Program and authorized to conduct cyber operations under government direction. Participating Companies must enter into contracts with the DOJ or DHS to ensure rigorous vetting of Participating Companies and adherence to operational procedures established in implementing guidance.

The memorandum also permits Participating Companies to enter into commercial agreements with private sector entities and with federal, state, local, tribal, and territorial agencies. Private sector entities may provide to Participating Companies threat information collected in the course of those entities’ normal business activities for the purpose of proposing responsive cyber operations to the NCC. Government agencies may identify CE-TCO threats to Participating Companies in a manner that enables them to propose responsive cyber operations to the NCC.

Required Implementing Procedures

Within 60 days, the Program Executive Directors, in coordination with the Homeland Security Council, must establish operating procedures for the Program. The memorandum provides that no operation may be approved unless it complies with such operating procedures.

According to the memorandum, the operating procedures must address: (1) minimum eligibility and performance standards; (2) participation by large and smaller specialized companies; (3) disclosure of certain contractual relationships; (4) operational workflows (5) target-identification processes; (6) reporting requirements; (7) DOJ review where an operation implicates a U.S. person or other constitutional, statutory, or international law considerations; (8)cessation and notification procedures if operations exceed approved parameters; (9) annual evaluation of Participating Companies; and (10) written approval and direction before any cyber operation may proceed. The memorandum also authorizes DOJ and DHS to require Participating Companies to maintain a bond or escrow of at least $1 million as a condition of participation in the Program.

Covered Activity

The memorandum identifies two types of cyber operations that Participating Companies may conduct: (1) “Cyber Surveillance Operation,” which is defined as an activity conducted primarily to collect information or intelligence from information systems, networks, or infrastructure, including information that may be used for future cyber effects operations, with the intent to remain undetected; and (2) “Cyber Effects Operation,” which is defined as an activity resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, infrastructure, or data.

Critical Outcomes and Safeguards

Operations resulting in “Critical Outcomes” are excluded from the approval authority delegated to the Program Executive Directors. The memorandum defines “Critical Outcomes” as actions likely to result in loss of life or serious injury, or to rise to the level of use of force or armed attack under international law.

The memorandum also requires procedures addressing operations directed at U.S. persons or affecting domestic systems. It provides that Participating Companies must cease operations, conduct minimization, and notify the NCC if they discover activity exceeding approved parameters, including unintentional targeting of a U.S. person, an information system in the United States, or an information system under the control of a U.S. person.

Reporting and Legal Framework

The memorandum requires the Program Executive Directors to submit a status report to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director within 180 days and annually thereafter. It further states that Program activities must be conducted in accordance with the Constitution, applicable law, and U.S. international obligations, including 18 U.S.C. § 1030. The memorandum also provides that it does not create any enforceable right or benefit against the U.S. or any other person.