AF099 · Lesson 44 of 71
Operation Security (OPSEC) Orientation
Table of ContentsShow
- Overview
- Operations Security (OPSEC)
- Individual OPSEC Responsibilities
- Personnel Security Program
- Personnel Security Reporting Requirements
- Key reminders
- Counter Insider Threat — Awareness and Categories
- Insider Threat Potential Vulnerabilities and Behavioral Indicators
- Behavioral indicators
- Techniques adversaries use to get information from you
- The Impact of Technological Advancements on Insider Threat
- How to Report Suspected Insider Threat Activity
- Information Security
- Controlled Unclassified Information (CUI)
- Types of unauthorized disclosure
- Results of unauthorized disclosure
- Summary
Note: This section is titled "OPSEC Orientation" but the printed source heading reads "Security." It covers four security disciplines: OPSEC, Personnel Security, Counter Insider Threat, Information Security, plus Controlled Unclassified Information (CUI).
Security and countermeasures are used to protect critical information — and they're a continuous process. Failure to implement these can result in injury or death, damage to resources, or loss of technology.
There are threats out there that will try to influence you to let your guard down. Good decision-making matters here.
This section covers OPSEC, the Personnel Security Program, Counter Insider Threat awareness, Information Security, and CUI.
Overview
Objective: Identify basic facts and general principles about intermediate Airmanship fundamentals.
Learning Outcomes
- Identify the four main security disciplines: OPSEC, Personnel Security, Counter Insider Threat, Information Security.
- Recall the personal roles and responsibilities within the four main security programs.
- Identify what is needed to report and who to report to for questions regarding security.
Foundational Competencies
- Decision Making — Makes well-informed, effective, and timely decisions; uses sound judgment to integrate and weigh situational constraints, risks, and rewards.
- Influence — An intent to persuade, convince, or impress others to elicit support, make impacts, or achieve effects on others.
Summary
- Operations Security (OPSEC)
- Personnel Security
- Counter Insider Threat
- Information Security
- Controlled Unclassified Information (CUI)
Operations Security (OPSEC)
According to DAFI 10-701, Operations Security (OPSEC) is an information-related capability that preserves friendly essential secrecy by using a process to identify, control, and protect critical information and indicators that could allow adversaries — or potential adversaries — to identify and exploit friendly vulnerabilities. OPSEC's desired effect is to influence the adversary's behavior and actions by protecting friendly operations and activities.
OPSEC is a 6-step process:
- Identifying critical information — information the organization has determined is valuable to an adversary.
- Analyzing threats to that information.
- Analyzing vulnerabilities.
- Assessing the risk — evaluate the degree of probable harm or adverse impact a vulnerability (or combination of vulnerabilities) may cause if exploited by an adversary.
- Applying appropriate countermeasures to address those vulnerabilities and reduce risk.
- Periodic Assessment.
Individual OPSEC Responsibilities
Be familiar with your organization's critical information and indicators, then protect it from unauthorized disclosure.
- For any questions about OPSEC responsibilities or how to protect critical information, ask your supervisor or Unit Security Manager.
- Use the encryption key on all emails with critical information (information valuable to an adversary).
- Don't publicly disseminate or publish photos displaying critical information — including on social media.
- Avoid discussing information on non-secure lines (cellular, internet, etc.).
- Properly destroy all products (paper, disks, hard drives, etc.).
- Actively encourage others — including family members and family readiness groups — to protect critical information and indicators.
- OPSEC is everyone's responsibility!
Personnel Security Program
The purpose: ensure only loyal, trustworthy, and reliable members have access to classified information.
Three aspects of the Personnel Security Program:
- Background Investigation
- Adjudications — determining if you'll be granted security clearance eligibility.
- Continuous Vetting
All Airmen are submitted for a security clearance and are subject to an initial background investigation. Once the clearance is granted, all are enrolled in Continuous Vetting.
If in a position requiring a Top Secret (TS) clearance — a higher level of clearance — Airmen are subject to an initial TS clearance.
There are 13 categories of "derogatory" information that must be reported under the Personnel Security Program when an individual has a security clearance. Examples: Allegiance to the U.S., Foreign Influence, and Criminal conduct.
DAF policy requires individuals to report these issues to their Security Manager and/or Supervisor. Not doing anything could impact your security clearance.
Personnel Security Reporting Requirements
Security Executive Agent Directive 3 requires reports to the Security Manager:
- Unofficial Travel — must obtain approval by the Security Manager prior to travel.
- Contact with non-U.S. citizens.
Report to the Security Manager if you become aware of any of the following on other individuals with access to classified information:
- Unwillingness to comply with rules, regulations, or security requirements.
- Unexplained affluence or excessive indebtedness.
- Alcohol abuse or illegal use or misuse of drugs or drug activity.
- Mental health issues that may affect the ability to protect classified information.
- Criminal conduct.
- Activity that raises doubts about whether the individual's continued national security eligibility is consistent with national security interest.
- Misuse of U.S. Government property or information systems.
Other items to report to the Security Manager:
- If you apply for or obtain foreign citizenship.
- Application for, possession, or use of a foreign passport or identity card for travel.
- Attempted elicitation, exploitation, blackmail, coercion, or enticement to obtain classified or other protected information.
- Media contacts where the media seeks access to classified or otherwise protected information — whether or not it results in unauthorized disclosure.
- Arrests.
- Bankruptcy or over 120 days delinquency on any debt.
- Alcohol- or drug-related treatment.
The following must be reported if you have access to Top Secret information:
- Direct involvement in foreign business, foreign bank accounts, ownership of foreign property, foreign citizenship, application for and receipt of foreign citizenship, application for / possession / use of a foreign passport or identity card for travel, voting in a foreign election, or adoption of non-citizen children.
Key reminders
- Self-reporting does not equal loss of security clearance. The majority of reporting is mitigated and favorably adjudicated.
- It's better to self-report than to be caught and not have reported.
- Everyone is responsible to report on themselves and other covered individuals.
Counter Insider Threat — Awareness and Categories
DoD Directive 5205.16, The DoD Insider Threat Program, defines an "Insider Threat" as the threat that an insider will use their authorized access — wittingly or unwittingly — to do harm to the security of the United States. This threat can include damage through:
- Espionage
- Terrorism
- Unauthorized disclosure of national security information
- Loss or degradation of department resources or capabilities
There are 5 categories of Insider Threat:
- Leaks — Intentional, unauthorized disclosure of classified or proprietary information to a person or organization that doesn't have a "need-to-know."
- Spills — Unintentional transfer of classified or proprietary information to unaccredited or unauthorized systems, individuals, applications, or media.
- Espionage — Unauthorized transmittal of classified or proprietary information to a competitor, foreign nation, or entity with the intent to harm.
- Sabotage — To deliberately destroy, damage, or obstruct — especially for political or military advantage.
- Targeted Violence — Any form of violence directed at an individual or group for a specific reason. Not a random act.
Insider Threat Potential Vulnerabilities and Behavioral Indicators
The following are triggers that usually become the tipping point of an insider becoming a threat. Stressors such as financial issues, loneliness, and being disgruntled with the job can make someone vulnerable.
Seeking help from friends or other avenues can reduce the stressors before they affect the person and the mission. Vulnerabilities such as exploitable promiscuity and addictive behaviors (gambling, alcohol) are typically avoided by society and have a greater negative perception.
A vulnerability exists when an adversary can collect critical information and/or indicators, correctly analyze them, and act to hurt the mission. A vulnerability can be a procedure, failure of security, poor judgment, lack of threat awareness, processing critical information on unsecured systems without encryption, or the system design itself.
Conducting exercises and analyzing operations can help identify vulnerabilities. Understanding what you can/should post on social media is critical. If in doubt about what you can and cannot post, ask the Security Manager and/or don't post it.
Behavioral indicators
Behavioral indicators are another way to identify when an insider can be a threat:
- Attempting to gain access to classified information without a need to know.
- Disabling anti-virus software.
- Attempting to burn discs without authorization.
- Using deception to access secure information and/or communications equipment.
- Displaying signs of unexplained affluence.
- Falsifying information.
- Associating with extremist or terrorist groups.
- Accessing facilities during unusual or off-duty hours.
- Unauthorized contact with an officer or an agent of a foreign intelligence entity.
- Working odd hours.
If anyone is exhibiting any of the above concerning behaviors, immediately report this information to the Security Manager.
Techniques adversaries use to get information from you
It's important to be aware of your surroundings and pay attention to how adversaries get information from us — on and off duty. Knowing the techniques may help you stay alert and prevent adversaries from having any advantage:
- Direct Approach — someone approaches during travel, persistent requests to socialize, or — if presenting at a conference — a request for presentation materials months in advance.
- Exploitation — excessive photography or videotaping, concealed listening devices, malicious emails, and unsecured Wi-Fi.
- Elicitation — discreetly gather information. A conversation with a specific purpose to collect information that's not readily available without raising suspicion.
The Impact of Technological Advancements on Insider Threat
The world is more interconnected than ever before. Spies and leakers have exploited computer technology to obtain and transfer vast amounts of classified data. Technology is doubling every 18 to 36 months — the more technology advances, the more challenging information protection becomes (in part because storage capacity has also increased).
We advertise what we do by using social media and social networks. As a result, adversaries collect 80% of their initial intelligence off readily available sources.
Report to your immediate supervisor and/or local security office any suspicious activities. What to look for:
- Improper use of privilege access.
- Working odd hours without authorization.
- Knowingly bypassing technology-associated security rules and protocols.
- Inappropriate copying of classified or proprietary information.
- Request for technical or program access beyond scope of work.
- Introduction of unauthorized technical devices into the workplace.
- Keeping unauthorized backups.
- Unauthorized request for, use of, or removal of technical equipment.
- Hoarding files, data, code, and programs.
How to Report Suspected Insider Threat Activity
Suspicious activity should be brought to the attention of your supervisor and/or Security Office/Manager.
The Department of the Air Force Counter-Insider Threat Hub (DAF C-InT Hub) is responsible for detecting, analyzing, and referring Insider Threat activity. The Air Force Office of Special Investigations (AFOSI) handles criminal cases referred by the DAF Insider Threat Hub, other organizations, and individuals — including information obtained through a tip line.
For a situation involving immediate danger — call 911.
Information Security
Information Security is the classification, protection, dissemination, declassification, and destruction of information. Classified material contains information that requires protection from unauthorized disclosures to protect national security.
The types of Classified Information:
- Top Secret
- Secret
- Confidential
To have access to classified information, you must have 3 things:
- Security clearance eligibility — all military members will be submitted for at least a Secret-level clearance.
- A "Need to Know." Just having a clearance is not an operational need for access to that information.
- A signed Non-Disclosure Agreement (SF-312). Outlines your responsibilities to protect information from unauthorized disclosure and defines possible consequences if you fail.
Controlled Unclassified Information (CUI)
In addition to classified information, certain types of unclassified information also require application of access and distribution controls and protective measures for various reasons.
CUI is unclassified information that allows for, or requires, safeguarding and dissemination controls in accordance with laws, regulations, or Government-wide policies.
Unauthorized Disclosure of CUI is a communication of physical transfer of CUI to an unauthorized recipient. Under the CUI program, any loss of CUI must be reported to the immediate supervisor or the Security Manager.
Types of unauthorized disclosure
- Public Domain — Release of classified information or CUI in the public domain.
- Data Spills — Willful, negligent, and inadvertent disclosures of classified information or CUI transferred onto an information system not authorized at the appropriate level.
- Espionage — Activities designed to obtain, deliver, or communicate and/or transfer classified information or CUI intended to aid a foreign power.
- Prevention and Consequences — If you suspect unauthorized disclosure has occurred — by you or someone else — immediately report it to the Security Manager. Unauthorized disclosures may result in criminal, civil, and/or administrative sanctions.
Results of unauthorized disclosure
- Top Secret — Could cause exceptionally grave damage to national security.
- Secret — Could cause serious damage to national security.
- Confidential — Could cause damage to national security.
Summary
Security is one of the most important programs in the Air Force. This section covered OPSEC, the Personnel Security Program, Insider Threat, Information Security, and CUI. It is vital to mission success to safeguard critical information and ensure others do the same.