Attachment 0002-PEO CSCSS OPSEC Program.pdf

PDF 1 MB Posted

Attached to
Water Storage Distribution System (Solicitation) Federal contract opportunity
Solicitation number
W56HZV21R0011
Issued by
Department of the Army Materiel Command TACOM Life Cycle Management Command

About this file

This is a summary of a federal solicitation for water storage and distribution systems. The U.S. Army Contracting Command-Detroit Arsenal intends to procure up to 123 water storage distribution systems with capacities of 100,000 gallons or split capacities of 2 units at 50,000 gallons each. The systems will include collapsible fabric storage tanks, pumps, meters, hoses, fittings and nozzles, as well as hypochlorination units. The Government will award up to five IDIQ contracts initially for testing pump assemblies. Test results will be used to downselect to a single IDIQ holder for full system production and logistics products, as well as potential spare pumps. The resulting contracts will have a five-year firm fixed price term with two additional option years. This procurement is exclusively set aside for small businesses. Interested vendors should contact the buyer, Jon Kaercher, at (586) 282-0328. The soliciting agency is the U.S. Army's TACOM Life Cycle Management Command.

View the file

Other files for this federal contract opportunity

Other files attached to Water Storage Distribution System (Solicitation), newest first.
File Type Posted
WSDS QA 91-95.pdf PDF
Attachment 0010 SESAME.xlsx XLSX spreadsheet
W56HZV21R0011-0002.pdf PDF
WSDS VENDOR QA (10 June) (questions 36-90) Final.pdf PDF
Attachment 0009 WSDS FDSC Certified 16 Apr 21.pdf PDF
Attach 0009 WSDS FDSC Certified 16 Apr 21.pdf PDF
Attachment_0042_Pricing_Workbookv2 (4 Jun 21).xlsx XLSX spreadsheet
Attachment_0040_Pricing_Workbookv2 (4 Jun 21).xlsx XLSX spreadsheet
Attachment_0042_Pricing_Workbookv2.xlsx XLSX spreadsheet
Notice to Offerors.pdf PDF
Attachment_0040_Pricing_Workbookv2.xlsx XLSX spreadsheet
Attachment_0042_Pricing_Workbookv2.xlsx XLSX spreadsheet
WSDS VENDOR QA (as of 25 May 2021).pdf PDF
Attachment 0038_Technical Review Criteria.docx DOCX document
Attachment 0034- Additional Guidelines for Controlled Unclassified Information.docx DOCX document
Attachment 0033- Department of Defense Guide to Item Unique Identification Quality Assurance.doc DOC document
Attachment 0029- Provisioning Requirements Worksheet.docx DOCX document
Attachment 0011- LPD Attribute Selection Sheet.pdf PDF
Copy of Attachment 0005- HMMR Format.XLSX XLSX spreadsheet
Attachment 0004- Request for Use of Prohibited Materials.doc DOC document
Instructions.docx DOCX document
Copy of Attachment 0042 - Updated Pricing Workbook.xlsx XLSX spreadsheet
Attachment 0039 - Copyright Release Letter Template.docx DOCX document
Attachment 0037 PKG1_LPD Coded Data Products Packaging.docx DOCX document
Attachment 0026-IADS Dataset_TOC File Template.docx DOCX document
Attachment 0017- AMPS Procedures for Users and Administrators.pdf PDF
Copy of Attachment 0010-SESAME.xlsx XLSX spreadsheet
Attachment 0007 - WSDS Technical Data Package (TDP).zip ZIP file
Attachment 0006- CARC Paint Drawing 12585018.pdf PDF
Attachment 0024-TPG 2016-01 Rev 1 Source Data.pdf PDF
Attachment 0028-SSI.DOCX DOCX document
Attachment 0027-ATPD 2232 Packaging.pdf PDF
Attachment 0025-TM Crosswalk Form.xls XLS spreadsheet
Copy of Attachment 0015-LORA.xlsx XLSX spreadsheet
Attachment 0013-GMTK CL.pdf PDF
Attachment 0003 - ATPD-2425 WSDS.pdf PDF
Solicitation WSDS.pdf PDF
Attachment 0009- Failure Definition and Scoring Criteria (FDSC).docx DOCX document
Attachment 0018-DE Style Guide 1-26-18.pdf PDF
Copy of Attachment 0041 - Use of Existing Government-Furnished Property.xlsx XLSX spreadsheet
Copy of Attachment 0040 - Pricing Workbook revised 4 20 2021.xlsx XLSX spreadsheet
Attachment 0036- Incoming Transaction Format Packaging.docx DOCX document
Attachment 0035- MOS Operator and Maintenance Tasks 92W-91J.docx DOCX document
Attachment 0032- IUID Data Plate Examples.docx DOCX document
Attachment 0031-Microscan UID Compliance Results.pdf PDF
Attachment 0030 - Pump Reliability and Mobility PQT Plan WSDS-v16.docx DOCX document
Attachment 0023-General Publications Requirements for Page-Based Manuals.doc DOC document
Attachment 0022-TABLE A-VII-NMWR Requirements Matrix.docx DOCX document
Attachment 0020-TABLE A-IV - TM Requirements Matrix -23.docx DOCX document
Attachment 0021-TABLE A-VI - TM Requirements Matrix -23P RPSTL.DOCX DOCX document
Show all 50

Water Storage Distribution System (Solicitation) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ii

UNCLASSIFIED//FOR OFFICIAL USE ONLY

TABLE OF CONTENTS

PAGE

1. (U) PURPOSE 1

2. (U) POLICY 1

3. (U) DEFINITION 1

4. (U) GENERAL 1

5. (U) RESPONSIBILITIES 2

a. (U) OPSEC Officer (OPSECO) 2

b. (U) Public Affairs Officer (PAO) 3

c. (U) PEO Webmaster 3

d. (U) Program and Product Managers (PM) 3

e. (U) PM OPSECO 4

f. (U) All PEO Personnel 5

(U) DISTRIBRUTION

(U) APPENDIX A: OPSEC CONCEPT AND CONSIDERATIONS A-1

(U) APPENDIX B: INFORMATION OPERATIONS (IO) B-1

(U) APPENDIX C: REVIEWS, SURVEYS AND LIMITS OF SECRECY C-1

(U) APPENDIX D: CRITICAL INFORMAION D-1

a. (U) Personnel D-1

b. (U) Information Systems (IS) D-1

c. (U) Equipment and Vehicles D-2

d. (U) Initial Operational Capability (IOC)/Systems Acquisition D-3

(U) APPENDIX E: ESSENTIAL ELEMENTS OF FRIENDLY INFORMATION

(EEFI)

E-1

(U) APPENDIX F: INTELLIGENCE COLLECTION THREAT

F-1

a. (U) Foreign intelligence Service Threat F-1

b. (U) Terrorist Threat F-1

c. (U) Insider Threat F-1

d. (U) Criminal Threat (Outsider) F-2

e. (U) Environmental Threat F-2

f. (U) Military Threat F-2

g. (U) Human Intelligence (HUMINT) F-2

h. (U) Signal Intelligence (SIGINT) F-2

i. (U) Measurement and Signatures Intelligence (MASINT) F-3

j. (U) Imagery Intelligence (IMINT) F-3

k. (U) Open Source Intelligence (OSINT) F-3

l. (U) Computer Intrusion for Collection Operations F-3

m. (U) Technology Transfer F-3

n. (U) Professional Conferences/Symposiums F-3 iii

o. (U) Personnel Disaffection F-3

(U) APPENDIX G: VULNERABILITY ASSESSMENT G-1

a. (U) Information Security (INFOSEC) Vulnerabilities G-1

b. (U) Operations Security (OPSEC) Vulnerabilities G-1

c. (U) Physical Security Vulnerabilities G-2

d. (U) Automated Information Security (AIS) Vulnerabilities G-2

e. (U) Antiterrorism (AT) and Force Protection (FP) Vulnerabilities G-3

(U) APPENDIX H: PEO ASSESSMENT OF RISK H-1

(U) APPENDIX I: OPSEC MEASURES I-1

(U) APPENDIX J: PEO OPSEC PROGRAM MATRIX J-1

(U) APPENDIX K: OPSEC WORKING GROUP K-1

(U) APPENDIX L: OPSEC IN CONTRACTING L-1

(U) APPENDIX M: OPSEC REVIEW PROCESS M-1

(U) APPENDIX N: OPSEC COMMAND INSPECTION CHECKLIST N-1

(U) APPENDIX O: WEB/MEDIA SITE QUARTERLY OPSEC REVIEW

CHECKLIST

O-1

(U) APPENDIX P: ACRONYMS AND TERMS P-1

(U) APPENDIX Q: REFERENCES Q-1

(U) ANNEX A: PEO STAFF OPSEC Policy

(U) ANNEX B: PROGRAM MANAGER – EXPEDITIONARY ENERGY &

SUSTAINMENT SYSTEMS OPSEC Policy

(U) ANNEX C: PROGRAM MANAGER – FORCE PROJECTION OPSEC

Policy

(U) ANNEX D: PROGRAM MANAGER – JOINT PROGRAM, JOINT LIGHT

TACTICAL VEHICLE OPSEC Policy

(U) ANNEX E: PROGRAM MANAGER – MINE RESISTANT AMBUSH

PROTECTED VEHICLES OPSEC Policy

(U) ANNEX F: PROGRAM MANAGER –TRANSPORTATION SYSTEMS

OPSEC Policy

UNCLASSIFIED//FOR OFFICIAL USE ONLY

1. (U) PURPOSE: This Program establishes roles and responsibilities within the PEO as it relates to Operations Security.

2. (U) POLICY: Operations Security is vital in the protection of Critical Information (CI) which an adversary can utilize to harm our personnel and equipment and disrupt our mission. All PEO CS&CSS personnel (military, civilian, support contractors, business and industrial partners and potential contractors) will comply with this program.

3. (U) DEFINITION: OPSEC is a process of identifying CI and subsequently analyzing friendly actions attendant to military operations and other activities in order to:

a. (U) Identify those actions that can be observed by adversary intelligence systems.

b. (U) Determine indicators adversary intelligence systems might obtain that could be interpreted or pieced together to derive CI to be useful to them.

c. (U) Select and execute measures that eliminate, or reduce to an acceptable level, the vulnerabilities of friendly actions to adversary exploitation.

4. (U) GENERAL:

a. (U//FOUO) This program specifically addresses the following areas: assignment of Operations Security (OPSEC) responsibilities, a systematic approach to developing necessary OPSEC measures, implementation of OPSEC training, requirements for the review of command OPSEC measures and reporting, and cross-command/interagency support to the program. It is designed to provide a basic understanding of OPSEC functions and how they apply to the PEO.

Each program or product may require a unique approach to OPSEC depending upon their function within the organization. The basic concepts set forth herein are essentially the same for every program or product office. OPSEC is applicable to all activities within the PEO, from the daily routine to planning, testing, exercise, and evaluation phases.

b. (U//FOUO) This guidance prescribes PEO policies and procedures to assist in OPSEC.

The overall purpose of OPSEC is to strengthen our traditional security procedures by identifying existing vulnerabilities or weaknesses and applying measures to preserve essential secrecy in every phase of operations, exercises, test, or activities. The goal is to deny our adversaries access to any CI. CI is technologies and information desired by an adversary that is sensitive, and its disclosure could seriously impact our programs. It does not have to be classified information. An adversary can learn about our programs by piecing together obtainable unclassified information. In our attempt to shield our activities, it is not only important to follow normal security practices but also to implement OPSEC measures as needed. This OPSEC guidance will identify and discuss the five-step process: Identifying CI, Analysis of Threats, Analysis of Vulnerabilities, Assessment of Risks, and the Application of OPSEC measures. In essence, OPSEC is designed to examine –using the OPSEC review process- information that’s proposed for public release.

c. (U//FOUO) OPSEC applies across all command lines and to all aspects of PEO CS&CSS.

All information which is command or organizational CI must be reviewed for OPSEC before public release.

UNCLASSIFIED//FOR OFFICIAL USE ONLY

5. (U) RESPONSIBILITIES:

(U//FOUO) All PEO associates, contractors and business and industrial partners, are responsible for the security of the information owned by the PEO to which he/she has access to.

Each piece of information that an adversary can obtain fills-in one more piece of the puzzle as it relates to our overall plan of action.

a. (U) OPSECO:

(1) (U//FOUO) Serve as the principal staff officer for overall management of the OPSEC Program.

(2) (U//FOUO) Ensure the integration and synchronization of the OPSEC program with higher headquarters’ OPSEC program.

(3) (U//FOUO) With input from the Program Management (PM) OPSECOs, prepare and recommend the OPSEC Program; once approved, make changes when directed and review each year.

(4) (U//FOUO) Coordinate the PEO OPSEC Working Group (OSWG) IAW Appendix K and participate in USAASC OSWG.

(5) (U//FOUO) Develop and recommend OPSEC measures to be implemented within the

PEO.

(6) (U//FOUO) Conduct OPSEC reviews of PEO Staff operational plans and reports to ensure adherence to OPSEC policies and procedures.

(7) (U//FOUO) Ensure training exercises include realistic OPSEC considerations and that any evaluation of a training exercise includes an evaluation of OPSEC procedures.

(8) (U//FOUO) Coordinate with the PAO to ensure an OPSEC review is conducted before the release of information concerning the command and command programs/projects In Accordance With (IAW) the references and Appendix M.

(9) (U//FOUO) Ensure OPSEC training is conducted IAW reference a. and Appendix J of this program document.

(10) (U//FOUO) Conduct an annual OPSEC assessment.

(11) (U//FOUO) IAW reference e, 4-1.b.8, conduct a quarterly OPSEC review of PEO social media sites utilizing the checklist at Appendix O.

(12) (U//FOUO) Conduct OPSEC reviews of material for public release to ensure adherence to OPSEC policies and procedures utilizing the OPSEC review process Appendix M.

(13) (U//FOUO) Conduct OPSEC reviews of PEO contracts IAW reference j and Appendix L.

(14) (U//FOUO) On an annual basis, consolidate the PM CIL recommendations and present it for PEO approval; once approved, disseminate to need to know entities.

b. (U) PAO:

(1) (U//FOUO) Comply with Federal, Department of Defense (DoD), and Department of the Army (DA) Website administration policies and implementing content-approval procedures that include OPSEC and PAO reviews before updating or posting information on all Websites IAW reference b, 4-20.g. (11).

(2) (U//FOUO) IAW reference c., 5-4., safeguarded information will not be discussed, shown, or made available to unauthorized individuals. Information, materials, or records must be reviewed for OPSEC considerations prior to public release. The staff office or agency providing the information, materials, or records to the PAO for release initiate the review IAW Appendix M.

(3) (U//FOUO) Consider OPSEC in all Public Affairs (PA) operations.

(4) (U//FOUO) Provide unclassified information about the Army and its activities to the public with maximum disclosure and minimum delay. Do not release information that would adversely affect national security, threaten the personal safety, or invade the privacy of members of the Armed Forces, IAW reference b., 3-3.j and Section II Terms, Sensitive Information.

(5) (U//FOUO) Coordinate directly with the PEO OPSECO on all questionable releases and for additional guidance on any release.

c. (U) PEO Webmaster:

(1) (U//FOUO) Comply with Federal, DoD, and DA website administration policies and implemented content-approval procedures that include OPSEC and PAO reviews;

the public release statement: "DISTRIBUTION STATEMENT A - APPROVED FOR PUBLIC RELEASE; DISTRIBUTION IS UNLIMITED should be properly affixed to the information before updating or posting on Websites.

(2) (U//FOUO) IAW reference e, 4-1.b.8, and in conjunction with the OPSECO, conduct a quarterly OPSEC review of PEO Web and social media sites utilizing the checklist at Appendix O of this program.

(3) (U//FOUO) Coordinate directly with the OPSECO for additional guidance as needed on any questionable Website posting.

d. (U) Program and Product Managers (PM):

(1) (U//FOUO) Protect Critical Program Information (CPI) and ensure appropriate OPSEC measures are taken within your PM in order to provide maximum protection of all functions and activities.

(2) (U//FOUO) Assign an OPSEC Officer and ensure he/she is trained IAW reference a., 4-2.b.1 (Level II resident training). It is recommended that an alternate OPSECO be trained as well. Because contractors do not have authority over U.S. military and government personnel

UNCLASSIFIED//FOR OFFICIAL USE ONLY

and cannot represent the position of the U.S. Government, contract employees will not be assigned as the command’s OPSEC PM or OPSEC officer (reference a. 2-8.3). However, they may perform OPSEC duties in a supporting capacity as the OPSEC coordinator.

(3) (U//FOUO) Assist the PEO OPSECO with integrating OPSEC into all organizational activities.

(4) (U//FOUO) Develop Security Classification Guides (SCG) for programs and projects that require them, prepare a DD Form 2024 for the PEO’s signature and storage within the Defense Technical Information Center (DTIC) and route the documents to the PEO Staff via the PEO OPSECO. Each SCG you develop must be reviewed every five years.

(5) (U//FOUO) Program Managers will develop an OPSEC Policy -in accordance with this Program- addressing specific operation of the PM; this Policy will be an annex to the PEO’s program (refer to the Table of Contents for your PM’s Annex designator). Product Managers will develop an OPSEC Policy -in accordance with this Program and the PM’s Policy-addressing specific operation of the Product as an annex to the Program Manager’s policy.

(6) (U//FOUO) On an annual basis, review your programs for additions or subtractions to the PEOs CIL and present the CIL to the PEO OPSECO.

e. (U) PM OPSECO:

(1) (U//FOUO) Develop the PM’s OPSEC policy IAW this program as an Annex to this program.

(2) (U//FOUO) Participate in the PEO OSWG.

(3) (U//FOUO) On an annual basis, assist the PEO OPSECO in the development of the organization’s CIL.

(4) (U//FOUO) Develop and recommend OPSEC measures to be implemented within the

PEO/PM.

(5) (U//FOUO) Conduct OPSEC reviews of PM contracts, operational plans, public release documents and reports to ensure adherence to OPSEC policies and procedures.

(6) (U//FOUO) Ensure training exercises include realistic OPSEC considerations and that any evaluation of a training exercise includes an evaluation of OPSEC procedures. Further, ensure pre-exercise OPSEC briefings are conducted incorporating the threat, CI/Essential Elements of Friendly Information (EEFI), and OPSEC measures.

(7) (U//FOUO) Ensure an OPSEC review is conducted before the public release of information concerning the command and command programs/projects IAW Appendix M.

(8) (U//FOUO) Ensure OPSEC training is conducted IAW reference a. and Appendix J.

(9) (U//FOUO) Assist the PEO OPSECO with the annual OPSEC assessment.

(10) (U//FOUO) Conduct OPSEC reviews of qualifying PM contracts IAW Appendix L.

f. (U) All PEO Personnel/Associates (Military, Government Employee, Contractor, Matrix

Employees, Business and Industry partners, Visitors):

(1) (U//FOUO) Implement OPSEC measures.

(2) (U//FOUO) Complete initial orientation and annual awareness OPSEC training IAW reference a., 4-1 and 4-2 to:

(a) (U//FOUO) Understand how OPSEC complements traditional security programs to maintain essential secrecy of U.S. military capabilities, intentions, and plans;

(b) (U//FOUO) Learn how to apply OPSEC to daily tasks;

(c) (U//FOUO) Understand how adversaries aggressively seek information on U.S.

military capabilities, intentions, and plans;

(d) (U//FOUO) Become knowledgeable of the local multidisciplinary adversary intelligence threat;

(e) (U//FOUO) Become knowledgeable of PEO CI and EEFI, and how to protect it by applying OPSEC measures to prevent inadvertent disclosure;

(3) (U//FOUO) Maintain need-to-know and telephone security;

(4) (U//FOUO) Limit distribution of sensitive unclassified information to include technical data, Controlled Unclassified Information (CUI), FOUO, Personally Identifiable Information (PII) and CPI.

(5) (U//FOUO) Learn not to talk about work in public locations.

(6) (U//FOUO) Be familiar with this OPSEC Program, the PM OPSEC Policy and where to obtain additional OPSEC guidance as needed;

(7) (U//FOUO) Handle any attempt by unauthorized personnel to solicit sensitive or CI as a Threat Awareness Reporting Program (TARP) incident per Reference (g). Report all facts immediately to the nearest supporting counterintelligence office and inform the chain of command.

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U) DISTRIBUTION:

(U//FOUO) DEPUTY PROGRAM EXECUTIVE OFFICERS

(U//FOUO) EXECUTIVE OFFICER

(U//FOUO) ASSISTANT PROGRAM EXECUTIVE OFFICE – CHIEF INFORMATION OFFICE/

SYSTEMS ENGINEERING & INFORMATION TECHNOLOGY

(U//FOUO) ASSISTANT PROGRAM EXECUTIVE OFFICE – LOGISTICS

(U//FOUO) ASSISTANT PROGRAM EXECUTIVE OFFICE – BUSINESS MANAGEMENT

(U//FOUO) DIRECTOR OF CURRENT OPERATIONS

(U//FOUO) PROGRAM MANAGER – EXPEDITIONARY ENERGY & SUSTAINMENT

SYSTEMS

(U//FOUO) PROGRAM MANAGER – FORCE PROJECTION

(U//FOUO) PROGRAM MANAGER – JOINT PROGRAM, JOINT LIGHT TACTICAL VEHICLE

(U//FOUO) PROGRAM MANAGER – MINE RESISTANT AMBUSH PROTECTED VEHICLES

(U//FOUO) PROGRAM MANAGER –TRANSPORTATION SYSTEMS

A-1

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U) APPENDIX A: OPSEC CONCEPT AND CONSIDERATIONS:

1. (U) OPSEC CONCEPT:

a. (U) Many activities, incident to normal daily functioning, will convey information and indicators to adversaries in spite of security measures. Information available from detectable friendly activities, when combined with other information held by an adversary, may shape the adversary's perceptions of friendly intentions, military capabilities, actions and possible weaknesses. These indicators may provide answers to intelligence questions. When classified or sensitive unclassified activities, such as operations and exercises, field tests of systems, etc.

are planned and executed, out-of-the-ordinary actions can often result in adversaries learning our intent by piecing together the indicators.

b. (U) Intelligence systems function worldwide. Often the command directly responsible, as well as commands providing support, execute activities that convey pertinent information or indicators of intentions, capabilities, and vulnerabilities. Therefore, both primary and supporting operations and other activities must be systematically examined to determine potential disclosures that would cause cancellation or failure of the primary undertaking. Subsequently, one must plan and execute protective measures that permit operations and activities to proceed effectively while preserving requisite essential secrecy. OPSEC is the process designed to do this.

c. (U) An OPSEC vulnerability exist when OPSEC indicators are collected by an adversary, the information is processed, and the adversary has time to react in a harmful way. CI collected by an adversary today could be used to develop a technological advantage for the adversary’s use many years in the future. Collection capabilities used to obtain information depend on some form of target cooperation. For example, throwing sensitive but unclassified information in the trash or releasing sensitive information into the public domain makes it vulnerable to collection by the adversary. If proper OPSEC measures are applied, it is often possible to eliminate or control many detectable indicators of CI about our intentions, capabilities, and activities.

d. (U) The objective of OPSEC is to ensure mission effectiveness. Overuse of OPSEC protective measures, unfortunately, can reduce mission effectiveness. For example, communications are often needed in exercises and communications, if intercepted can be an indicator; if an OPSEC protective measure dictated that we cease communications to eliminate the indicator, the exercise would greatly suffer or fail. In this instance, it may be possible to deny information by acting against adversary’s collectors and analysts rather than stopping the actions. Actions that may be implemented include the use of jamming, obscurant, weather, camouflage, environmental conditions, or Military Deception (MD) to influence adversary perceptions and conclusions. An example would be: a cover operation or diversion/feint to draw collection and analytical interest elsewhere.

e. (U) Planning for secrecy must extend beyond exposure of raw information and consider possible assumptions and estimates made by an adversary. Logical conclusions based on generally available information, trend analysis based on historical data or technical possibilities, and broad experience of adversary planners and decision makers must all be factored in. MD may be required to mislead adversary analysts in order to maintain essential secrecy.

A-2

UNCLASSIFIED//FOR OFFICIAL USE ONLY

f. (U) The following are examples of unclassified information that may be indicators alerting an adversary to the existence of a project, application of advanced technology, a new tactic, or technique previously unknown to the adversary:

(1) (U) Unclassified agreements between government agencies; their association in a project or operation that outlines methods, procedures, and current U.S. Government intentions, and future objectives.

(2) (U) Special or unique requests providing special instructions which could reveal capabilities or the technology of a new weapon or vehicle system.

(3) (U) Public relations release describing aspects of technological or operational cooperation between the US and other nations.

(4) (U) Announcements of formation of specialized groups, special elements or organizations, which could signal special intentions, activities, or capabilities.

(5) (U) Consolidated budget execution for specific projects, testing of items or tactics, and monies spent that are intended for future acquisition.

2. (U) OPSEC CONSIDERATIONS:

a. (U) OPSEC must be considered when preparing policies, procedures, and doctrine, when designing systems, and when prescribing logistic and administrative practices.

b. (U) Policies, procedures, and doctrines govern the freedom of action and can introduce a degree of rigidity in the way functions are performed. Over time, the constraints imposed and procedural habits will become apparent, allowing adversaries to better predict what PEO associates will or will not do and how various functions will be carried out.

c. (U) Systems and tactics are of little value if, during their development, an adversary realizes the capability to locate, track, identify, target, and destroy that system or counter the tactic when it is deployed or implemented. Administrative and logistic practices are generally overt and can reveal information of considerable value to an adversary.

d. (U) Standards and procedures make it simple to detect changes in routines that may indicate a capability is being readied for use.

B-1

(U) APPENDIX B: INFORMATION OPERATIONS (IO):

1. (U) INFORMATION OPERATIONS (IO):

a. (U) Destruction (hard kill and weapons effect), Electronic Warfare (EW), MD, Psychological Operations (PSYOP), Civil Affairs (CA), PA, and OPSEC are the elements of IO.

Their integrated use degrades an adversary's IO capabilities and systems. IO activities are in two categories: Defensive IO and Offensive IO. Our IO insures effective friendly Command and Control (C2). OPSEC is that element of IO that deprives adversaries the CI they require to make effective decisions.

b. (U) While EW and destruction directly target an adversary's ability to command its forces, OPSEC seeks to degrade the quality of the adversary's decisions. It hinders the adversary's intelligence system's ability to gather CI. Concealing one's capabilities and intentions from the adversary creates or enhances the opportunity for surprise.

c. (U) OPSEC directly supports deception by suppressing indicators of real activities, while deception creates false indicators. Conversely, deception used as an OPSEC measure can distract the adversary's attention away from real indicators or to provide plausible explanations of real activities.

d. (U) EW supports OPSEC by degrading or destroying the adversary's intelligence collection capability. OPSEC protects friendly C2 and EW from attack.

e. (U) OPSEC supports PSYOP, CA and PA by ensuring the adversary does not have foreknowledge of how we plan on influencing their forces and acquiring their population’s support. This type of OPSEC support includes protection of Rules of Engagement (ROE), PSYOP themes, projected CA activities, and ensuring that PA personnel are aware of the CI.

C-1

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U) APPENDIX C: REVIEWS, SURVEYS AND LIMITS ON SECRECY:

1. (U) OPSEC REVIEWS, ASSESSMENTS AND SURVEYS:

a. (U) OPSEC review is an evaluation of a document to ensure protection of sensitive or CI.

The term document –in this instance- means: memorandum, letter, message, briefing, contract, news releases, technical document, proposal, plan, order, response to Freedom of Information Act (FOIA), or Privacy Act requests or other visual or electronic media to include video and audio. The OPSECO will be responsible for conducting the organization’s OPSEC reviews as needed; Reference a, chapter 5, section I.

b. (U) An OPSEC assessment is an analysis tool to for the overall OPSEC process; the assessment can be performed on an operation, exercise, test or activity to evaluate the degree of compliance with the published OPSEC Program. The OPSEC assessment evaluates and improves the effectiveness of protecting CI and acts as a diagnostic tool that focuses on compliance with existing OPSEC guidance. Utilizing the checklist in Appendix N, the PEO OPSECO will, at a minimum, perform an OPSEC assessment for each of the PM’s and Staff as part of the PEO’s Command Inspection Program (CIP). This annual requirement does not preclude OPSEC assessments being conducted other than as part of the annual CIP;

assessments may be conducted as needs dictate. OPSEC assessments are: Reference a, chapter 5, section II.

c. (U) The OPSEC survey is a method to determine if there is adequate protection of CI during planning, preparation, execution, and post-execution phases of any operation or activity.

The survey analyzes all associated functions to identify sources of information, what they disclose, and what can be derived from the information. The survey is resource intensive;

therefore, an OPSEC assessment will be conducted first. If the assessment indicates that a need exists, conduct the survey. Reference a, chapter 5, section III.

2. (U) LIMITS ON SECRECY:

Care should be taken in determining the required degree of secrecy. Too much secrecy may have a harmful effect; too little has resulted in mission or system failure. Broad factors to consider include:

a. (U) Adversaries must have some knowledge of friendly capabilities and intentions so they will perceive threats; this is a deterrence.

b. (U) The public must have knowledge in regards to military capabilities to foster recruitment of required personnel, gain internal political support, ensure understanding of defense budgeting requests, and support defense alliances.

D-1

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U) APPENDIX D: CRITICAL INFORMATION (CI):

1. (U) CI consists of specific facts about friendly intentions, capabilities, and activities needed by adversaries to plan and act effectively to cause failure or unacceptable consequences for friendly mission accomplishment.

2. (U//FOUO) The OPSECOs, in conjunction with other staff officer’s and PM review, will develop the organization’s overall Critical Information List (CIL) and EEFI for PEO’s approval. It is the PEO’s intent that all organization personnel be aware of the organization’s CIL and EEFI so that they can better apply OPSEC to their daily tasks.

3. (U//FOUO) CI will be identified and OPSEC measures applied for each PEO operation, mission, training or other activities.

(U//FOUO) The PEO CIL is as follows:

a. (U//FOUO) Personnel:

1. (U//FOUO) Acquisition Workforce Statistical Data; especially that containing PII

2. (U//FOUO) Acquisition Funding Priorities

3. (U//FOUO) Sudden cancellation of leave or emergency recall of Personnel

4. (U//FOUO) Dates of deployment/redeployment

5. (U//FOUO) Detailed information regarding meetings, celebrations or other gatherings of PEO personnel whether on or off post (ie… Christmas party, bowling events, offsite, picnic, etc....). Detailed information such as: number or names of participants, exact location, etc…

b. (U//FOUO) Information Systems (IS):

1. (U//FOUO) Experimental system that drives requirements for a fielded system

2. (U//FOUO) The association of an operating system’s services with an individual Army Tactical IS

3. (U//FOUO) The association of an individual Army Tactical IS with information Assurance Vulnerability Alert (IAVA)

4. (U//FOUO) IAVA patches mitigated through other means, i.e. blocked at firewall, Access Control List (ACL) restrictions, service not running, etc….

D-2

5. (U//FOUO) Real-time network controls in effect on the Tactical Internet

6. (U//FOUO) Active Security Devices (ACL, firewalls, IDS) in effect on the Tactical Internet

7. (U//FOUO) Baseline configuration of security devices

8. (U//FOUO) System/terminal passwords

9. (U//FOUO) Unauthorized events and incidents involving Tactical IS

10. (U//FOUO) Tactical Internet tests (Until executed)

c. (U//FOUO) Equipment, vehicles and vessels:

1. (U//FOUO) Equipment Fielding Schedules

2. (U//FOUO) System Training Schedules

3. (U//FOUO) Unit level system evaluations (until executed)

4. (U//FOUO) General Vulnerability evaluation schedule

5. (U//FOUO) Specific budget information

6. (U//FOUO) Architecture

7. (U//FOUO) General performance requirements

8. (U//FOUO) Components-detailed information

9. (U//FOUO) Measured throughput-type of data being measured (test/operational)

10. (U//FOUO) Network diagrams

11. (U//FOUO) Specific Internet protocol (IP) addresses

12. (U//FOUO) Individual IP addresses associated with a classified host

13. (U//FOUO) Compilations, databases, documents, or graphics that contain compilations of the following information: IP addresses, system, system role, Unit Reference Number (URN), or user name

14. (U//FOUO) Experimental events not fielded or hand receipted to units

D-3

15. (U//FOUO) Detailed configuration data

16. (U//FOUO) Measured capabilities

17. (U//FOUO) System Requirements for Security

18. (U//FOUO) Security plans (procedures, password management)

19. (U//FOUO) Detailed information of incident involving vehicle accident and/or personnel injury or vehicle damage or malfunction

20. (U//FOUO) Individual vulnerability test (test instrument and raw data)

21. (U//FOUO) Open source vulnerability information on COTS products

22. (U//FOUO) Specific Modernization

23. (U//FOUO) Financials; prior to budget submission or bid acceptance

24. (U//FOUO) A breakout of unclassified yearly funding costs, which could prejudice negotiations with a contractor or prospective contractor within the meaning of DOD Directive 5400.7

d. (U//FOUO) Initial Operational Capability (IOC)/System Acquisition:

1. (U//FOUO) Future test dates and test locations

2. (U//FOUO) Drawings of armor: Drawings, blueprints, or photographs, hardcopy or electronic, showing dimensions (width, length, thickness, weight, etc) of armor sections, when the classified armor material's unique placement and unique configuration is not identified

3. (U//FOUO) Drawings, blueprints, or photographs, hardcopy or electronic showing framework or skeleton of hull structure with no reference to armor material or armor recipe

4. (U//FOUO) Engineering Change Proposal (ECP) documents with individual drawings pertaining to armor components for improvement of armor protection that do not reveal current or future threshold or objective levels of installed armor

5. (U//FOUO) Internal view of hull not showing any classified armor design information, classified armor configuration or vulnerabilities

D-4

UNCLASSIFIED//FOR OFFICIAL USE ONLY

6. (U//FOUO) Any test documentation, photographs, videos, or damaged vehicles that do not reveal information about any vehicle testing procedure or vehicle vulnerability (Example: test plans for brake hydraulic, electrical, crew comfort)

7. (U//FOUO) Combat damaged vehicles and photographs of combat damaged vehicles without amplifying information that does not include classified armor material or classified armor configurations or specific threat munitions range or velocity or angle of attack or explosive characteristics

8. (U//FOUO) A photo or video of a piece of metal or armor that has failed a Government/contractor test that may show penetration but displays no other threat information or amplifying information

9. (U//FOUO) Photographs of the interior of the armored vehicles and vessels with installed Government Furnished Equipment (GFE)

10. (U//FOUO) Ad hoc testing performed by contractors or other organizations without using any classified test plans, or classified criteria and when no vulnerabilities are revealed

11. (U//FOUO) Pre-shot and post shot vehicle checklists used to document the operational and functional status of each vehicle that have not been annotated with the crew survivability performance of the vehicle from ballistic and mine testing from live fire test events

12. (U//FOUO) A standard sample or plate of armor material used but not yet tested that reveals proprietary information

13. (U//FOUO) A standard sample or plate of armor material with a ballistic hole or dent in it that reveals proprietary information

14. (U//FOUO) A sample that is a new proposal for an armor solution that reveals proprietary information

15. (U//FOUO) Installation manuals, repair guides, and maintenance literature

16. (U//FOUO) Specific instructions (how or locations where armor kits are installed)

17. (U//FOUO) Weapon accuracy

18. (U//FOUO) All non-unit status reports (USR) Automotive Reliability, Availability, Maintainability - Durability (RAM-D) criteria

19. (U//FOUO) Demonstrated communications-electronics effectiveness

D-5

20. (U//FOUO) Demonstrated Intra- and Inter-operability communications effectiveness

21. (U//FOUO) Evaluation of human factors engineering and ergonomic design goals

22. (U//FOUO) Evaluation of logistics supportability and maintainability criteria

23. (U//FOUO) Assets or programmed quantities by Theater, Reserve or Pre-positioned sets (CONUS or OCONUS (not specific to units.))

24. (U//FOUO) Transportation of armored vehicles and vessels enroute to Space and Naval Warfare Systems Center (SPAWAR)

25. (U//FOUO) Armored vehicles and vessels that are being transported to SPAWAR with no Government Furnished Equipment included

26. (U//FOUO) Technical Manuals

27. (U//FOUO) Operating Manuals

28. (U//FOUO) Depot Work Maintenance Requirement/Manuals

29. (U//FOUO) Information relating to operational systems with the exception of armor classified subsystems identified elsewhere in this guide, the evaluation of operational effectiveness and operational suitability from information collected during test events; such as Limited User Evaluations, Operational Assessments, and Operational Test & Evaluations

30. (U//FOUO) Other deficiencies that reveal degradation or inability of the system/program to achieve required and desired automotive performance characteristics and criteria

31. (U//FOUO) Evaluations or assessments by users of design deficiencies that reveal degradation of system/program design

32. (U//FOUO) All safety deficiencies until corrected

33. (U//FOUO) Vehicle fleet total numbers and their operational status using non USR criteria

34. (U//FOUO) Information Disclosing Shipping, Receiving and Vehicle Recovery Operations, methods of shipping armor, armor kits, or vehicles with armor (Examples: rail, air, ship overland truck cargo, etc.)

D-6

35. (U//FOUO) When specific information is provided on armor shipments or vehicles with armor upgrades which includes mode of shipment, quantities, and delivery dates, but does not include the unit receiving the shipment or the unit delivery location(s)

36. (U//FOUO) Information Disclosing Battlefield and Battle Damage Assessments: Battle damaged assessments or failure analysis reports that do not contain sufficient detail to disclose a vulnerability

37. (U//FOUO) Unclassified modeling and simulation software and source codes

38. (U//FOUO) A battle damaged vehicle that contains sensitive, GFE but no classified equipment or information

39. (U//FOUO) Demilitarization Processing for MRAP FOV: Photos, drawings, or sketches showing battle damage without reference to type of weapon, or range, or velocity, or angle of attack

40. (U//FOUO) Excerpts (narrative or visual displays) from demilitarization manual showing diagrams or sketches depicting cut lines

41. (U//FOUO) Demilitarization Procedures Manual (Demilitarization Disposal Trade Security Controls Management Plan) issued by Joint Program Office

42. (U//FOUO) Vehicle preparation procedures for prepping armored vehicles and vessels prior to the DEMIL process

43. (U//FOUO) Armor cutting methods that does not disclose ballistic protection requirements

44. (U//FOUO) The Generic threats against which the system provides protection without the specific projectile, range, or azimuths. No vulnerability revealed (e.g. small arms, artillery, mines, etc.…)

45. (U//FOUO) Improvised Explosive Devices (IED) and mine data no threat is revealed

46. (U//FOUO) Ad hoc testing performed by contractors or other organization without using the classified testing procedures or classified criteria when no vulnerabilities are revealed

47. (U//FOUO) A listing of expected threat munitions likely used in an attack against the armor

D-7

UNCLASSIFIED//FOR OFFICIAL USE ONLY

48. (U//FOUO) Drawings or final products revealing the internal armor configuration/receipt without performance characteristics

49. (U//FOUO) A piece of metal/armor that has successfully undergone a test but does not show any threat information (No Penetration)

50. (U//FOUO) A photo or video of a piece of metal/armor that has failed a DoD test. Displays no other information (Shows Penetration)

51. (U//FOUO) Untested ballistic properties not associated with a specific mode.

52. (U//FOUO) Generic technical recommendations from a contractor when not associated with a specific vehicle

53. (U//FOUO) Administrative data e.g. timelines, progress status and production quantities

54. (U//FOUO) Content of software applications

55. (U//FOUO) Technical data packages

56. (U//FOUO) Technical armor manuals

57. (U//FOUO) Combat damaged vehicles and photos of combat damaged vehicles without amplifying information of cause of damage

58. (U//FOUO) Drawings of final products revealing dimensions of length, width and/or thickness and weight of installed armor (does not disclose armor internal receipt)

59. (U//FOUO) Drawings or final products revealing the internal armor configuration/recipe without performance characteristics

60. (U//FOUO) Future improvements in armor made during production that clearly show a marked increase in vehicles survivability

61. (U//FOUO) Manufacturing specifications

62. (U//FOUO) Thickness and area density of installed armor

63. (U//FOUO) Interim and final designs or equivalent documentation, which would include any list of materials used in the design of installed armor kits

64. (U//FOUO) A standard sample of metal alloy or plate with a ballistic hole or dent in it

D-8

65. (U//FOUO) A standard sample of metal alloy or plate with a ballistic hole or dent from specific munitions

66. (U//FOUO) A piece of metal or sample that is a new proposal for armor solution

67. (U//FOUO) Installation manuals, repair guides, and maintenance literature that does not reveal tested performance information

68. (U//FOUO) Specific locations of where armor or armor kits are installed

69. (U//FOUO) Any compilation of end items used in final product to include composition and configurations of armor or armor kits installed

70. (U//FOUO) Final individual plate components to include, length, width, thickness and weight

71. (U//FOUO) Methods of shipping armor, armor kits, or vehicles with armor (examples: rail, air, ship, overland truck cargo, etc…)

72. (U//FOUO) When specific information is provided on armor shipments or vehicles with armor upgrades which includes mode of shipment, quantities, and delivery dates, but does not include the unit receiving the shipment or the unit delivery location(s)

73. (U//FOUO) Specific details regarding the performance of the modified COTS UGVs, subsystems, or components

74. (U//FOUO) Electromagnetic Environmental Effects on UGV Systems

75. (U//FOUO) Operator Control Unit (OCU)/ System (OCS) Memory Cards and

Passwords

76. (U//FOUO) Technology integration and Design details of UGVs

77. (U//FOUO) Frequency management, transmission characteristics, control/video/data link encryption characteristics correlated to specific UGVs

E-1

(U) APPENDIX E: ESSENTIAL ELEMENTS OF FRIENDLY INFORMATION (EEFI)

1. (U) PURPOSE. To provide the PEO workforce the Essential Elements of Friendly Information (EEFI).

2. (U//FOUO) DISCUSSION. EEFI are questions that the adversary is likely to ask about friendly capabilities, activities, limitations, and intentions. The answers to EEFI are CI. If you are asked these or similar questions outside a work environment, it is probably inappropriate and reporting the incident (TARP) would be prudent.

(U//FOUO) What is the schedule, and security arrangements for senior leaders and visiting VIPs?

(U//FOUO) Where are the assets/leaders deployed and what is the deployment purpose, itinerary, and destination?

(U//FOUO) What are the security measures planned or implemented for high visibility, high personnel concentration events?

(U//FOUO) What are your readiness levels and vulnerabilities?

(U//FOUO) What are equipment capabilities, design, limitations, reliability and vulnerabilities?

(U//FOUO) What measures will the U.S. Army and subordinate units take if their computer systems or applications are attacked?

(U//FOUO) What is the security disposition and where are your information networks?

(U//FOUO) What is your supply chain?

(U//FOUO) What system breaks down the most?

(U//FOUO) What are specific testing, production and delivery dates and locations?

(U//FOUO) What capabilities does PEO CS & CSS need in its vehicles now and in the future?

(U//FOUO) What were the test results of (specific test)?

(U//FOUO) What systems, whether in use or prepositioned, are located (specific location)?

(U//FOUO) What are PEO AT/FP procedures and countermeasures?

(U//FOUO) What intelligence measures have exploited PEO platforms and systems?

(U//FOUO) Who are the key PEO CS&CSS security personnel?

(U//FOUO) Who develops the hardware and software for (specific system)?

(U//FOUO) Where are your maintenance and operator manuals stored?

(U//FOUO) What PEO CS&CSS managed systems will be part of the Army enduring fleet?

(U//FOUO) What communications are available for (specific system)?

(U//FOUO) What can the armor protect?

(U//FOUO) What type of armor is on (specific system)?

(U//FOUO) What is the Controlled Unclassified Information (CUI) on PEO programs?

(U//FOUO) Where is the CUI and how is it handled or secured?

E-2

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U//FOUO) How well do the COTS work in austere conditions?

(U//FOUO) What modifications had to be made for the COTS to work?

(U//FOUO) What price did (Specific Company) bid on the (specific system)?

(U//FOUO) Who is on the source selection board?

(U//FOUO) How is your (specific system) testing progressing?

(U//FOUO) What are the system testing benchmarks?

(U//FOUO) What are your testing schedules and where are the testing grounds?

F-1

(U) APPENDIX F: INTELLIGENCE COLLECTION THREAT:

(U//FOUO) It should be well known that there are threats to our programs and information. It is imperative that we know some information regarding those threats as it will help us protect our interests. Listed below are some examples of specific types of threats -within each of the major categories of threats- and information collection capabilities. Examples cited may pertain to more than one category, e.g., terrorists might use HUMINT, SIGINT, etc… to collect information about their target.

a. (U) Foreign Intelligence Service Threat (see Information Collection Capabilities below)

(1) (U) HUMINT (e.g., recruitment, blackmail, surreptitious entry, phone taps, bugs, unauthorized computer access, social engineering, etc.)

(2) (U) SIGINT (e.g., intercept/exploit communications, computer data, TEMPEST (see definition), etc.)

(3) (U) IMINT (e.g., overhead imaging, hand held photography, etc.)

(4) (U) MASINT (e.g., radar intelligence, infrared intelligence and nuclear intelligence.)

(5) (U) OSINT (e.g., Websites, public releases, newspapers, etc.)

b. (U) Terrorist Threat

(1) (U) Assassination

(2) (U) Bombing

(3) (U) Kidnapping

(4) (U) Radiological, biological, and/or chemical attacks

(5) (U) Nuclear attacks

(6) (U) Stand-off weapons attacks/raids

c. (U) Insider Threat

(1) (U) Malicious acts by disgruntled personnel (violence, sabotage)

(2) (U) Espionage/theft, unauthorized disclosure or inadvertent loss of classified or sensitive material

F-2

UNCLASSIFIED//FOR OFFICIAL USE ONLY

(3) (U) Theft of property

d. (U) Criminal Threat (Outsider)

(1) (U) Violent acts against people

(2) (U) Theft/destruction of property

(3) (U) Mob violence

(4) (U) Hacking/cracking of computer systems

e. (U) Environmental Threat

(1) (U) Fire

(2) (U) Storm

(3) (U) Pollution

(4) (U) Earthquake

(5) (U) Flood

f. (U) Military Threat

(1) (U) Nuclear

(2) (U) Radiological, biological, and/or chemical

(3) (U) Conventional

(4) (U) Information Warfare

(U) Information Collection Capabilities:

g. (U//FOUO) HUMINT is derived from human sources. To the public, HUMINT remains synonymous with espionage and clandestine activities, yet in reality, most HUMINT collection is performed by overt collectors such as diplomats and military attaches. HUMINT is the oldest, and arguably the best, method of collecting information.

h. (U//FOUO) SIGINT is derived from signal intercepts comprising, either individually or in combination, all communications intelligence (COMINT), electronic intelligence (ELINT), and foreign instrumentation signals intelligence (FISINT), however transmitted.

F-3

UNCLASSIFIED//FOR OFFICIAL USE ONLY

i. (U//FOUO) MASINT is scientific and technical intelligence information obtained by quantitative and qualitative analysis of data derived from specific technical sensors for the purpose of identifying any distinctive features associated with the source emitter or sender.

j. (U//FOUO) IMINT is a product of imagery analysis. Imagery includes representations of objects reproduced electronically or by optical means on film, electronic display devices, or other media. Imagery can be derived from visual photography, radar sensors, infrared sensors, lasers, and Electro-optics.

k. (U//FOUO) OSINT involves the use of materials available to the public; OSINT examples include: newspapers, magazines, radio, television, Web-based communities and user-generated content, social-networking sites, video sharing sites, wikis, blogs, etc…. With the proliferation of electronic databases, it has become easier to collate large quantities of data and structure information to meet the needs of the adversary collector. Open source information can provide extremely valuable information concerning PEO activities and capabilities. For the average PEO employee, it is most important to ensure FOUO information is not improperly discarded and that we do not “talk out-of-school”; do not discuss PEO business outside the PEO. Remember the old adage: “Loose Lips Sink Ships”.

l. (U//FOUO) Computer Intrusion for Collection Operations. It is unclear to what extent foreign intelligence services are using computer hackers to obtain proprietary data or sensitive government information, or whether they have developed the capability to use computer intrusion techniques to disrupt communications activities.

m. (U//FOUO) Technology Transfer. There continues to be increasing concern within DoD, as well as the civilian market place, over the growing challenges to the United States' lead in military and other types of technology. When we fail to provide dissemination restrictions on documents, comply and enforce Export Control restrictions, or conduct OPSEC reviews of various papers proposed for public media release and presentations, we are indirectly subsidizing foreign weapons development (we provide them with new technology for their own systems, as well as assist them in developing countermeasures for use against U.S. systems and items now in development).

n. (U//FOUO) Professional Conferences/Symposia. During attendance at conferences/symposia, personnel associated with the PEO are susceptible to elicitation and exploitation by participating individuals (including persons from allied countries) who are unwittingly or covertly representing the intelligence collection agencies of foreign governments. Collection efforts may range from innocuous questions to actual blackmail. Without constant awareness of the threat, PEO personnel may inadvertently release sensitive information.

o. (U//FOUO) Personnel Disaffection. Disaffected staff (the “Insider Threat”) can present a significant risk as they are still deemed trusted employees; their potential to http://en.wikipedia.org/wiki/Web_2.0 http://en.wikipedia.org/wiki/User-generated_content http://en.wikipedia.org/wiki/Video_hosting_service

F-4

UNCLASSIFIED//FOR OFFICIAL USE ONLY

inflict damage is high. Staff will usually become aware of what Information Assets are of value and, although they may not have direct access themselves, may be able to obtain access through personal relationships. Theft of information or material, altering data, sabotage, espionage, and contamination or destruction of critical materials or equipment could cause serious damage to programs or loss of public confidence in operations.

G-1

(U) APPENDIX G: VULNERABILITY ASSESSMENT

1. (U) Vulnerabilities are friendly actions that may become indicators. Indicators may be evaluated by an adversary to provide a basis for effective decision making.

Vulnerabilities consist of actions that habitually occur (patterns), and unique detectable characteristics (out of the ordinary) that identify the type of activity or intention. An example: our adversary observes that the staff meets every morning at 0800. In the past week, the staff has not met until 1000 and then again at 1400 and the staff now meets with a uniformed military person. This change indicates a different pattern alerting the adversary that something out-of-the-ordinary is happening; perhaps planning an event or operation that could be exploited. However, vulnerability in OPSEC exists only when these three conditions are met:

a. (U) An adversary has the capability to collect the indicator.

b. (U) The adversary has the time to collect, report, analyze, and make a decision.

c. (U) The adversary can react or take an action that will be harmful to our activities.

(U) Note: The adversary’s abilities will be discussed in a later segment.

2. (U//FOUO) OPSEC Officer(s), in coordination with Force Protection Officer(s), compare adversary collection capabilities against PEO activities to determine our vulnerabilities. OPSEC measures must be established to protect potential vulnerabilities from: (this is not an all-encompassing list; it’s more of an example):

a. (U//FOUO) Information Security (INFOSEC) Vulnerabilities:

(1) (U//FOUO) Employment of un-cleared personnel to duties that may provide the opportunity for access to sensitive unclassified information.

(2) (U//FOUO) Failure to properly protect sensitive unclassified equipment and material.

b. (U//FOUO) OPSEC Vulnerabilities

(1) (U//FOUO) Leadership not stressing the importance of OPSEC. Lacking leadership focus, personnel may be or become lackadaisical toward OPSEC.

(2) (U//FOUO) Open sources whereby documents are published and distributed without OPSEC reviews or limited distribution statements as applicable.

(3) (U//FOUO) Documents generated that are not reviewed for proper marking and handling instructions.

(4) (U//FOUO) Improper disposal of sensitive,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .