Playing the Bad Guy: How Do Organizations Develop, Apply, and Measure Red Teams?
Total Page:16
File Type:pdf, Size:1020Kb
Playing the Bad Guy: How Do Organizations Develop, Apply, and Measure Red Teams? James Michael Fleming Dissertation submitted to the faculty of the Virginia Polytechnic Institute and State University in partial fulfillment of the requirements for the degree of Doctor of Philosophy In Public Administration/Public Affairs Anne M. Khademian Randall S. Murch James F. Wolf Thomas A. Hickok Colleen A. Woodard Matthew M. Dull 26 April 2010 Alexandria, VA Keywords: alternative, analysis, adversary, defense, intelligence, war gaming, red team, red teaming, war fighting, terrorism Playing the Bad Guy: How Do Organizations Develop, Apply, and Measure Red Teams? James Michael Fleming Abstract The study is a descriptive analysis using a case-study methodology that identifies the critical elements (methods, tools, processes, personnel, and practices) of adversary analysis identified as a red team and red-teaming. The study incorporates interview data with organization leadership, subject matter experts, and red-team developers from Department of Defense (DoD), Intelligence Community (IC), and Federally Funded Research and Development Centers (FFRDC) organizations. The study incorporates red-team governance artifacts and interviews to first identify the concepts, analyzes the critical design elements of the concept(s), and finally develops a taxonomy of red-team approaches. The study compares and contrasts four red team approaches for common themes, differences, and best practices. The data collection builds on grounded theory—i.e., identification of the methods, tools, processes, and personnel as the organizations understand and develop their red teams as part of their red-teaming analyses to address gaps in understanding possible adversaries. The four organizations studied are the U.S. Army, Training and Doctrine Command; a Department of Defense unified combatant command; the U.S. Naval War College (NWC) and its red-team detachment; and a Sandia National Laboratories (SNL) Homeland Security and Defense, National Infrastructure Simulation and Analysis Center (NISAC). Two basic types of red teams are identified from the data with a hybrid between the two types. Some of the other findings from the four red teams include a need to develop common terms and standards; a need to explain the benefits of alternative analysis to decision makers; a need to develop trend analyses on types of red teams requested by sponsors; a need to design methods to capture non-state actors; a need to include more coalition and foreign partners; and a need to immerse red teams more fully into the culture to be understood. This dissertation is dedicated to my wife Alexandra, my daughter Natalie my son Garrett, my committee chair Anne Khademian, and my committee mojo Randall Murch iii Table of Contents Chapter Title Page Terms of Reference ............................................................................................................... vii 1 Introduction 1 1.1 Overview ........................................................................................................................... 1 Study Questions ...................................................................................................................... 3 1.2 Scope of the Study ............................................................................................................ 3 1.3 Study Synopsis ................................................................................................................ 5 1.4 Contribution to the Literature ............................................................................................ 7 2 Current Red-Team Models ................................................................................................. 9 2.1 DoD/Military Rational Decisionmaking Approach ........................................................... 10 2.2 Commercial Information Technology Industry Model ...................................................... 18 2.3 Sandia National Laboratories IORTA/IDART Methodologies ......................................... 23 2.4 Summary of Red Team Operational Environments ........................................................ 27 3 Red-Team Literature Review ............................................................................................. 30 3.1 Introduction ..................................................................................................................... 30 3.2 DoD/Military Red Team Literature .................................................................................. 30 3.3 Commercial and Private Sector Red-Team Literature .................................................... 41 4 Method of Study/ Research Methodology .......................................................................... 45 4.1 Fundamental Approach ................................................................................................... 45 4.2 Theoretical Grounding/Theoretical Frameworks ............................................................. 45 4.3 Study Design ................................................................................................................... 48 4.4 Data Collection ................................................................................................................ 49 4.5 Data Sources .................................................................................................................. 50 4.6 Data Analysis .................................................................................................................. 58 5 Study Summary ................................................................................................................. 59 5.1 Overview of Red-Team Findings .................................................................................... 59 5.2 Red-Team Similarities ..................................................................................................... 61 5.3 Red-Team Differences .................................................................................................... 64 5.4 Comparison of Other Key Drivers (Including Blue Teams) ............................................. 68 6 Detailed Study Findings ..................................................................................................... 72 6.1 Findings Overview .......................................................................................................... 72 6.2 Initial Difficulties with Red-Team Organizations .............................................................. 73 6.3 United States Army Training and Doctrine Command .................................................... 75 6.4 Naval War College/Office of Naval Intelligence (ONI) Detachment (DET) ...................... 87 6.5 Combatant Command X Red Team .............................................................................. 100 6.6 Sandia National Labs .................................................................................................... 123 7 Conclusion ....................................................................................................................... 145 7.1 Study Summary ............................................................................................................ 145 7.2 Interview with the Joint Chiefs of Staff (Chief’s) Action Group (CAG)........................... 150 7.3 Red-Team Issues .......................................................................................................... 152 7.4 Red-Team Schools of Thought ..................................................................................... 153 Red-Teaming Studies and Analyses Literature .................................................................. 160 Cultural Comparisons and Contrasts Between East and Occidental Literature .................. 162 Organizational Decisionmaking Literature .......................................................................... 164 Terrorism and Political Violence Literature ......................................................................... 167 Footnotes ............................................................................................................................ 169 iv List of Tables and Figures (All tables and figures are created by the author unless otherwise cited) Tables Page Table 2-1: Red-Team Preparations Checklist ....................................................................... 15 Table 5-1: Red-Team Case Studies Comparison ................................................................. 61 Table 5-2: Attributes Repeatedly Mentioned by Respondents .............................................. 63 Table 5-3: Cross Section of UFMCS Tools, Techniques, and Procedures (across the other three case studies) ................................................................................................................ 64 Table 5-4: (Case Study) Blue-Team Emphases Areas ......................................................... 70 Table 6-1: Preliminary Organization Approach ..................................................................... 74 Table 6-2: Key UFMCS Red-Team Course Objectives and Sources ................................... 77 Table 6-3: Key UFMCS Red-Team Curriculum Objectives ................................................... 78 Table 6-4: Key UFMCS Red-Team Course Drivers .............................................................. 79-81 Table 6-5: Key UFMCS Red-Team Design Objectives ........................................................