WASHINGTON: A Trump cyber memo authorised vetted US companies to attack foreign cybercrime groups under direct federal control. President Donald Trump signed the directive on August 12.
The National Coordination Centre will run the programme, according to the White House memorandum. The Department of Justice and Department of Homeland Security will jointly oversee operations.
Participating companies may conduct cyber surveillance and cyber effects operations against designated foreign criminal organisations.
The memo defines cyber effects as the manipulation, disruption, denial, degradation or destruction of targeted digital systems or infrastructure.
The programme cannot target organisations that form part of a foreign government or operate wholly under its direction. Every operation requires written approval from both programme directors before a company may act.
The directors must establish operating procedures within 60 days. Those rules will cover technical standards, personnel vetting, facility security, target identification, legal reviews and interagency coordination.
Agencies may require each participating company to maintain at least $1 million in bonds or escrow. A company could forfeit that money for breaching its federal contract.
Read: Sessions forms US cyber task force after election warnings
Companies must stop and report operations that exceed approved limits. They must also report imminent infrastructure attacks or actions risking death, serious injury or armed conflict.
Read: Global cyber attack slows; search on for hackers
The White House fact sheet said the programme targets ransomware, financial fraud and other cyber-enabled crimes. Officials must submit the first status report within 180 days and report annually afterwards.