arXiv · 2505.12613
Towards Centralized Orchestration of Cyber Protection Condition (CPCON)
Abstract
The United States Cyber Command (USCYBERCOM) Cyber Protection Condition (CPCON) framework mandates graduated security postures across Department of Defense (DoD) networks, but current implementation remains largely manual, inconsistent, and error-prone. This paper presents a prototype system for centralized orchestration of CPCON directives, enabling automated policy enforcement and real-time threat response across heterogeneous network environments. Building on prior work in host-based intrusion response, our system leverages a policy-driven orchestrator to standardize security actions, isolate compromised subnets, and verify enforcement status. We validate the system through emulated attack scenarios, demonstrating improved speed, accuracy, and verifiability in CPCON transitions with human-in-the-loop oversight.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Mark Timmons, Daniel Lukaszewski, Geoffrey Xie, Thomas Mayo, Donald McCanless. 2025-05-19. Towards Centralized Orchestration of Cyber Protection Condition (CPCON). https://arxiv.org/abs/2505.12613
Cite the original work for its findings. Save a collection to share your selection of sources.