111 Operation Security (OPSEC)
111.1 Define OPSEC. - answerOPSEC - Denying an adversary critical information
regarding our planning, processes or operations; and regularly assessing our ability to
prevent exploitation.
General categories of potentially critical information that should be protected: Current
and future operations, Travel itineraries, usernames and passwords,
Access/identification cards, Entry/exit security procedures, Capabilities and limitations,
Address and phone lists, Budget information, Building plans, VIP/distinguished visitor
movements
111.2 Discuss the five step planning process. - answer1. Identify Critical Information
(CI) - Critical information is defined as information about friendly (U.S., allied, and/or
coalition) activities, intentions, capabilities, or limitations an adversary seeks in order to
gain a military, political, diplomatic, economic, or technological advantage. Such
information, if revealed to an adversary prematurely may prevent or complicate
missions accomplishment, reduce mission effectiveness, damage friendly resources, or
cause loss of life if revealed to an adversary.
2. Threat Assessment - Current, relevant threat information is critical in developing
appropriate OPSEC protective measures. The threat assessment (TA) step in the
OPSEC process includes identifying potential adversaries and their associated
capabilities, limitations, and intentions to collect, analyze, and use knowledge of our CI
against us. The threat refers to more than an enemy agent hiding behind a rock. The
following examples represent threats:
o An unauthorized person attempting to acquire CI.
o A person supplying CI to an adversary.
o A person inadvertently providing CI information to an adversary.
o Someone overheard at, for example, the gym or education center talking about an
upcoming deployment.
o Intent + Capability = Threat
3. Vulnerability Analysis - An operational or mission-related vulnerability exists when the
adversary has the capability to collect indicators, correctly analyze them, and take
timely action. The vulnerability analysis identifies operation or mission vulnerabilities.
Weaknesses that reveal CI through collected and analyzed indicators create
vulnerabilities. Indicators are those friendly actions and information that adversary
intelligence efforts can potentially detect or obtain and then interpret to derive friendly
CI.
4. Risk Assessment - Risk assessments estimate an adversary's
111.3 Discuss the responsibilities of the command OPSEC Officer. - answerCommand
OPSEC Officer - ensures all participants are aware of relevant CI and coordinate timely,
resourced solutions for the Commander regarding process implementation and OPSEC
best practices.
111.1 Define OPSEC. - answerOPSEC - Denying an adversary critical information
regarding our planning, processes or operations; and regularly assessing our ability to
prevent exploitation.
General categories of potentially critical information that should be protected: Current
and future operations, Travel itineraries, usernames and passwords,
Access/identification cards, Entry/exit security procedures, Capabilities and limitations,
Address and phone lists, Budget information, Building plans, VIP/distinguished visitor
movements
111.2 Discuss the five step planning process. - answer1. Identify Critical Information
(CI) - Critical information is defined as information about friendly (U.S., allied, and/or
coalition) activities, intentions, capabilities, or limitations an adversary seeks in order to
gain a military, political, diplomatic, economic, or technological advantage. Such
information, if revealed to an adversary prematurely may prevent or complicate
missions accomplishment, reduce mission effectiveness, damage friendly resources, or
cause loss of life if revealed to an adversary.
2. Threat Assessment - Current, relevant threat information is critical in developing
appropriate OPSEC protective measures. The threat assessment (TA) step in the
OPSEC process includes identifying potential adversaries and their associated
capabilities, limitations, and intentions to collect, analyze, and use knowledge of our CI
against us. The threat refers to more than an enemy agent hiding behind a rock. The
following examples represent threats:
o An unauthorized person attempting to acquire CI.
o A person supplying CI to an adversary.
o A person inadvertently providing CI information to an adversary.
o Someone overheard at, for example, the gym or education center talking about an
upcoming deployment.
o Intent + Capability = Threat
3. Vulnerability Analysis - An operational or mission-related vulnerability exists when the
adversary has the capability to collect indicators, correctly analyze them, and take
timely action. The vulnerability analysis identifies operation or mission vulnerabilities.
Weaknesses that reveal CI through collected and analyzed indicators create
vulnerabilities. Indicators are those friendly actions and information that adversary
intelligence efforts can potentially detect or obtain and then interpret to derive friendly
CI.
4. Risk Assessment - Risk assessments estimate an adversary's
111.3 Discuss the responsibilities of the command OPSEC Officer. - answerCommand
OPSEC Officer - ensures all participants are aware of relevant CI and coordinate timely,
resourced solutions for the Commander regarding process implementation and OPSEC
best practices.