Operations Security (OPSEC) is a process that identifies critical information to determine if friendly actions can be observed by adversary intelligence systems, determines if information obtained by adversaries could be interpreted to be useful to them, and then executes selected measures that eliminate or reduce adversary exploitation of friendly critical information. [1]
OPSEC is a methodology that denies critical information to an adversary. It measures identify, control, and protect generally unclassified evidence that is associated with sensitive operations and activities. [1]
OPSEC Process
Examines a complete activity to determine what, if any, exploitable evidence of classified or sensitive activity may be acquired by adversaries. It is an analytical, risk-based process that incorporates five distinct elements. [1]
- Critical information identification: Identify information needed by an adversary instead of attempting to protect all classified or sensitive unclassified information.
- Threat analysis: Research and analysis of intelligence, counterintelligence, and open source information to identify likely adversaries to a planned operation.
- Vulnerability analysis: Examine each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then comparing those indicators with the adversary’s intelligence collection capabilities identified in the previous action.
- Risk assessment: First, planners analyze the vulnerabilities identified in the previous action and identify possible OPSEC measures for each vulnerability. Second, specific OPSEC measures are selected for execution based upon a risk assessment done by the commander and staff.
- OPSEC countermeasures: The command implements the OPSEC measures selected in the assessment of risk action or, in the case of planned future operations and activities, includes the measures in specific OPSEC plans.
OPSEC Planning
The following factors must be considered:
- The commander plays the critical role.
- OPSEC is an operations function, not a security function.
- JFCs should establish a fully functional IO cell.
- Planning must focus on identifying and protecting critical information.
- The ultimate goal of OPSEC is increased mission effectiveness.
- OPSEC is one of the factors considered during the development and selection of friendly courses of action.
- OPSEC planning is a continuous process.
- The public affairs officer participates in OPSEC planning to provide assessments on the possible negative effects of media coverage and all other public release of information
AcqLinks and References:
- [1] Joint Publication 3-13.3 “Operations Security” – 29 Jun 2006
- [2] DoD Manual 5205.02M “DoD Operations Security (OPSEC) Program Manual” – 3 Nov 2008
- [3] DoD Directive 5205.02E “DoD Operations Security (OPSEC) Program” – 20 Jun 2012
- Website: OPSEC Dictionary
- Website: National OPSEC Program – Press Cancel when certification page come up
Updated: 6/21/2018