Attachment 0005 - OPSEC Plan Template.pdf
PDF 139 KB Posted
- Attached to
- CANISTER, MINE, PRACTICE, M88 Federal contract opportunity
- Solicitation number
- W15QKN21R0106
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OPSEC PLAN FORMAT
INSTRUCTIONS – PLEASE REVIEW
The attached plan is formatted to provide you with a basic outline to prepare an Operations Security (OPSEC). The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during performance of the contract. The OPSEC Plan describes the methods to: (1) Identify OPSEC security responsibilities and requirements (2) Define overall OPSEC security standard practice procedures (3) Identify potential problem areas and determine solutions, and (4) Develop OPSEC security awareness inputs into the overall system security process.
Bold letters indicates places where you need to fill in your specific information. In some places you need to decide whether a paragraph applies to your organization. You may need to delete some paragraphs, or add depending on your situation. Be sure to update this OPSEC Plan as necessary.
Please do not use only this document for development of your plan. There are sections on Threat, Critical Information, Vulnerabilities, and Countermeasures where you should insert site-specific data when possible. No generic formula can adequately address the range of information required by an OPSEC plan. Should you need assistance with developing any of this part of the plan, please contact:
Interagency OPSEC Support Staff: 301-982-0323 https://www.iad.gov/ioss
TITLE OF PROGRAM
OPERATIONS SECURITY PLAN
Contract No. ______________
Date
Prepared by: (signature) Approved by: (signature) Typed Name Typed Name Title Title
Prepared for: Submitted by:
Contracting Organization Contractor Address Address
TABLE OF CONTENTS
FORWARD 3
1. General 4
1.1 Administration
1.2 Applicability
1.3 Responsibilities
1.3.1 OPSEC Manager
1.3.2 Program Manager
1.3.3 Program Personnel
1.4 Purpose
1.5 Interface with Support Agencies
1.6 Subcontractor Applicability
1.7 For Official Use Only (FOUO)
1.7.1 Handling, Storing & Transmitting FOUO
1.7.2 Markings
1.8 Distribution Requirements for Technical Documents
2. Threats 7
2.1 General Applicability
2.2 Human Intelligence (HUMINT)
2.2.1 Overt – Open Source Literature
2.2.2 Open Source Intelligence
2.2.3 Visitors
2.2.4 Covert – Illegal Entry/Coercion/Collusion
2.3 Signals Intelligence (SIGINT)
2.4 Imagery Intelligence (IMINT)
2.5 Measurement & Signatures Intelligence (MASINT)
2.6 Intelligence threats to (company)
2.6.1 Worldwide General Threat
2.6.2 Changing Nature of the Worldwide Threat
2.6.3 Intelligence Collection Threat to (company, site A)
2.6.4 Intelligence Collection Threat to (company, site B)
3. Critical Information 11
4. Vulnerabilities 12
4.1 General Vulnerabilities
4.2 Contractual Vulnerabilities
5. OPSEC Measures 14
5.1 General OPSEC Measures
5.2 Contractual OPSEC Measures
FORWARD
1. Give an overview of the program in the first paragraph. Who are the partners or participants? Are there foreign governments/businesses involved?
2. The specific objectives of this contractual effort are to (design, fabricate, test, produce… what?)
3. This Operations Security (OPSEC) Plan was prepared by (insert name or organization of contractor) for (insert the contracting organization name) in accordance with the:
o DD Form 254, Contract Number XXXXXXX o National Industrial Security Program Operating Manual (NISPOM) o DD Form 1423, Contract Data Requirements List or DD Form 1664, Data Item
Description o US Army ARDEC OPSEC Plan o Any other guidance required by the contracting organization or internal policy
4. The plan describes (contractor) actions to implement a cost-effective OPSEC program for protecting the (contract name or product name) technology.
5. The OPSEC plan is an operations plan – not a security plan. Program personnel should consider it their plan to protect the U.S. technological lead and (contractor company)’s competitive position. We anticipate the development or derivation of innovative concepts during the program. How well each team member protects sensitive information on this project may not only affect our national security, but may directly impact (contractor company)’s future business endeavors.
6. (Indicate in this paragraph whether or not the contracting organization or program has provided a Critical Information List (CIL) or Essential Elements of Friendly Information (EEFI) list. If such a list has been provided, attach it to this plan.)
7. Requests for additional information or assistance should be submitted to (POC name & phone number).
1. GENERAL
1.1 ADMINISTRATIVE
This Operations Security (OPSEC) Plan will serve as the implementing document for contract activities undertaken by (company name) on the (program name) program. A copy will be available for each participant to review.
This plan will be reviewed periodically as additional intelligence threat information becomes available, or as the program plan changes, but no less than annually. Specific changes may be required periodically by the (contracting organization name), or as OPSEC considerations on this program occur.
The requirements of the National Industrial Security Program Operating Manual (NISPOM), DoD 5220.22M are not modified by the OPSEC plan. Rather, these protective measures are expanded to include sensitive unclassified information, activities, and operations that are identified as requiring protection.
1.2 APPLICABILITY
This plan is applicable to appropriate (product name) elements at all (company name) and subcontractor facilities and locations that may be tasked to work on the program. Each subcontractor is responsible for OPSEC implementation. (Add additional information as necessary).
1.3 RESPONSIBILITIES
1.3.1 OPSEC MANAGER
The (company name) OPSEC Manager is responsible for developing the OPSEC Plan and monitoring its implementation and operation to ensure compliance. He/she will be OPSEC Level II certified and serves as the principal advisor to the Program Manager on all OPSEC matters and will:
1) Coordinate all OPSEC policy responsibilities and procedures within the program.
2) Revise the OPSEC Plan as necessary.
3) Coordinate the annual review and update of the sensitive aspects of the program.
4) Accumulate and disseminate updated threat information to program personnel.
5) Assist in the review of contract requirements for OPSEC considerations.
6) Conduct OPSEC Program briefings and training as necessary.
1.3.2 PROGRAM MANAGER
The (company name) Program Manager is responsible for the overall implementation of the OPSEC procedures and requirements at (company name) facilities and to ensure that all other facilities supporting the program develop similar procedures or comply with the requirements of this plan.
1.3.3 PROGRAM PERSONNEL
Employees associated with (program name) are required to attend all Program OPSEC briefings.
Personnel must comply with all OPSEC principles and procedures. All personnel must also be familiarized with what information is deemed critical and required OPSEC measures.
1.4 PURPOSE
OPSEC is a mandated program designed to safeguard sensitive program information, operations and activities which if exploited could compromise current or future plans and activities. This is accomplished by the identification and elimination or control of vulnerabilities that might be exploited by intelligence analysis.
This OPSEC plan is designed to document the OPSEC analysis and outline procedures to be followed by program employees to prevent the disclosure of classified information and minimize revelation of sensitive information, activities and operations to any unauthorized person, thus purposefully impeding intelligence collection efforts. Applicable activities and operations of the contract will be analyzed to determine known or suspected vulnerabilities to this program.
Countermeasures designed to eliminate or reduce these vulnerabilities to an acceptable risk level have been established and implementing instructions are identified in section (XX) of this plan.
1.5 INTERFACE WITH SUPPORT AGENCIES
Interfaces with outside agencies regarding OPSEC matters including the Defense Security Service (DSS), shall be coordinated through the contractor’s OPSEC Manager.
1.6 SUBCONTRACTOR APPLICABILITY
OPSEC will apply to the activities of (subcontractor names). They must implement and operate within the approved (company name) OPSEC Plan. An OPSEC assessment of their activities must be conducted, documented and submitted to (company name) for approval. International subcontractors, as well as, any additional U.S. subcontractors will receive OPSEC guidance with an approved DD Form 254, as applicable.
Determination as to whether OPSEC should be imposed is the responsibility of each subcontractor with respect to his or her lower tier suppliers in accordance with the guidance received from its prime contractor.
For those subcontractors not conversant or experienced with the Operations Security Program, (company name) will provide additional guidance to aid in the development of their OPSEC Plan.
1.7 FOR OFFICIAL USE ONLY (FOUO)
(Company name) has been authorized to receive, generate, and protect For Official Use Only (FOUO) material as part of the contract requirements. This section outlines the requirements for safeguarding FOUO.
FOUO includes topics of unclassified information identified in the Classification Guide that are eligible for exemption from mandatory public disclosure under the Freedom of Information Act.
(Company name) is also authorized to protect as FOUO information that is:
1) Contained in commercial or financial information generated by or for the Government with
The understanding it is on a privileged or confidential basis (e.g., bids, contracts, proposals, trade secrets, inventions, discoveries, proprietary data, or data on contract performance, income, profits, losses and expenditures, etc.).
2) Included in communications to Government agencies and Commands that offer advice, suggestions, or reports prepared on behalf of the Army; and received or generated by a Command preliminary to a decision or action where premature disclosure would interfere With the purpose for which the records are created.
1.7.1 HANDLING, STORING, AND TRANSMITTING FOUO
All materials as defined above will be handled, stored, and transmitted in accordance with the guidance provided by (contracting organization name).
Program personnel shall be briefed on FOUO procedures. Access to FOUO material will be limited to those personnel who need the material to do their job. FOUO material shall be handled in a way to preclude its disclosure to the general public. FOUO information will always be placed in a locked desk drawer when left unattended.
1.7.2 MARKINGS
All materials defined as FOUO will be marked in accordance with guidance provided by (contracting organization name).
The marking “For Official Use Only” will be stamped in bold letters at least 5/16 inches high near the bottom of each unclassified page containing FOUO. The abbreviation “FOUO” will not be used.
All emails containing FOUO information will be marked appropriately and encrypted when transmitted.
1.8 DISTRIBUTION REQUIREMENTS FOR TECHNICAL DOCUMENTS
All technical documents, including such informal documents as working papers, memoranda, and preliminary reports if those documents are not already in the public domain, and if they are likely to be disseminated outside of the Department of Defense shall be marked with the appropriate Distribution statement by the US Government. Technical information is defined by DoD Directive
5230.24 as: information, including scientific information that relates to research, development, engineering, test, evaluation, production, operation, use, and maintenance of munitions and other military supplies and equipment. Distribution marking requirements apply to technical information generated in any form. A distribution statement is a statement used in marking a technical document to denote the extent of its availability for distribution, release, and disclosure without additional approvals or authorizations. A distribution statement marking is distinct from and in addition to a security classification marking assigned in accordance with DoD 5200.1-R.
2. THREATS
2.1 GENERAL APPLICABILITY
Based upon information provided by (contracting organization name) and other Government Agencies, the threats applicable to the (program name) efforts stem primarily from five sources:
Human Intelligence (HUMINT), Signals Intelligence (SIGINT), Imagery Intelligence (IMINT), Measurement and Signatures Intelligence (MASINT) and Foreign Intelligence Services and Non-traditional Threats (FISNT). The worldwide intelligence collection threat is multi-disciplined, highly sophisticated, and extremely dedicated. Intelligence collection efforts may use only one discipline (or a combination of disciplines) to obtain information.
As new threat data is received, distribution shall be made to program personnel and other participants in program activities as appropriate.
2.2 HUMAN INTELLIGENCE (HUMINT) THREAT
Human intelligence describes activities to obtain both classified and unclassified information through the use of human agents. Endeavors of human agents (both overt and covert) pose a substantial threat if countermeasures to neutralize or minimize their activities are not employed.
2.2.1 OVERT – OPEN SOURCE INFORMATION
Significant quantities of unclassified, highly technical documents (both formal as well as in-house distribution and coordination items) offer a lucrative target to an adversary. Requests for documents relating to the program should be anticipated since many Intelligence Services work through clearinghouses and employ cover organizations in their increasing attempts to collect technology.
2.2.2 Open Source Intelligence (OSINT)
Open Source Intelligence (OSINT) is a category of intelligence information derived from written/printed/graphic and computer database sources as well as open discussions. It is information obtained from an analysis of information available to the general public and most often accomplished by overt HUMINT sources.
With the development of computers, OSINT has assumed a greater role in worldwide information gathering. Vast amounts of information of significant interest to other governments are available in computerized databases. Computer aided OSINT is a key part of intelligence efforts that are accomplished with minimal risk and cost.
2.2.3 VISITORS
Visitors to the facilities include, but are not limited to government personnel, subcontractors, vendors, suppliers, contract labor organizations and service groups (repairmen, telephone, janitorial, etc.) who may obtain information of interest to an adversary or competitor. The greater danger to the program is the possible visual and aural disclosure of information that could inadvertently occur during these visits. Always use proper access control measures in all contractor facilities. Always question and request identification from individuals who are not familiar in the area.
2.2.4 COVERT – ILLEGAL ENTRY/COERCION/COLLUSION (ESPIONAGE)
While this aspect of HUMINT is normally considered to be the exception rather than the rule, the possibility still exists for these methods to be employed against the program. With joint ventures and international partners the probability is almost assured. Examples include placing serendipitous listening devices in meeting rooms and foreign aircraft carriers, recruiting agents from the general population and key people who have access to sensitive information, etc. This type of intelligence gathering includes all clandestine and illegal activities and operations of Intelligence Services. Covert operations inflict severe damage and compromise to our country.
These items are included as an awareness factor to ensure program participants are fully cognizant of the possible threats from various Intelligence Services.
2.3 SIGNALS INTELLIGENCE (SIGINT) THREAT
SIGINT describes the capability to obtain classified and certain unclassified information by monitoring communication systems, or by analyzing electromagnetic radiation/emanations from various types of equipment.
Most activities and organizations are highly susceptible to the SIGINT threat. SIGINT is derived from signal interception and includes all Communications Intelligence (COMINT), Electronics Intelligence (ELINT) and Foreign Instrumentation Signals Intelligence (FISINT).
Telephone conversations are especially vulnerable because most are relayed, at some point in transmission, via microwave signals that are easily monitored. The use of double-talk and self-generated codes is not effective as a means to protect sensitive information during telephone conversations. Professional intelligence analysts easily defeat these procedures.
Current technology has produced a situation in which telephones in the hung-up (on-hook) position may frequently transmit room conversations occurring in the vicinity of the telephone. The telephone handset acts as a microphone that can pick-up and transmit room electronic signals and voice. This may be the result of accidental or intended modification, or because of a design characteristic of the telephone instrument or its associated equipment.
2.4 IMAGERY INTELLIGENCE (IMINT) THREAT
IMINT describes the capability to derive information from imagery developed over the full range of the electromagnetic spectrum. Intelligence Service representatives see a distinct danger in the employment of clandestine photography.
Applications of IMINT include:
1) Hand-held photography
2) Satellites, scheduled commercial aircraft and private aircraft overflights that employ advanced photographic techniques.
3) Unauthorized use of copying/duplicating equipment.
IMINT frequently provides very valuable intelligence. Imagery of experiments or tests can be obtained from land, sea, air and space platforms. The most serious threat from IMINT resources at the national level stems from photoreconnaissance satellites.
2.5 MEASUREMENT AND SIGNATURES INTELLIGENCE (MASINT) THREAT
MASINT is technically derived intelligence that detects, locates, tracks, identifies, and describes the unique characteristics of fixed and dynamic target sources. MASINT contributes both unique and complementary information on a wide range of intelligence requirements, and is often the basis for cross-cueing other collection disciplines. It is considered highly reliable since it collects performance data and characteristics on actual targets that do not intend to create an indication of presence or activity. MASINT target signatures are converted into threat recognition and identification profiles and the surveillance, tracking, discrimination, and engagement algorithms that guide smart weapons. Civil applications can include timely warning of forest fires and volcanic eruptions, tracking volcanic ash clouds, detecting pollution sources, and providing data on natural phenomena to support environmental studies.
2.6 INTELLIGENCE COLLECTION THREATS TO (COMPANY)
The following analysis of threat is from unclassified sources. There is a consensus within the U.S.
Intelligence Community that such collection efforts face almost all contractors developing new technologies. Any business enterprise operating in the global competitive market should recognize that it is continually targeted by intelligence collection efforts.
2.6.1 WORLDWIDE GENERAL THREAT
Pervasive worldwide multi-discipline information collection activities are being conducted against U.S. contractors on a daily basis. Increasingly significant resources are devoted to monitor activities of U.S. Defense contractors. Clearly, our adversaries can produce reliable information on business capabilities, vulnerabilities, and intentions. The intelligence threat to the U.S. economic and scientific base has actually increased dramatically since the end of the cold war.
2.6.2 CHANGING NATURE OF THE WORLDWIDE THREAT
EXAMPLE ONLY (SHOULD BE UPDATED TO REFLECT CURRENT WORLDWIDE
SITUATIONS) The collapse of the Soviet Union (now the Commonwealth of Independent States – {CIS}) in December 1991 intensified the intelligence collection threat posed by foreign countries.
That collapse allowed the redirection of collection efforts from the military to technological and economic interests. Our traditional adversaries continue to conduct intelligence activities. Over 50 Third World governments, using intelligence training received from former Soviet Union bloc countries, continue to act unilaterally in intelligence collection. Nontraditional adversaries, 94 out of 171 countries studied, target the U.S.
Over 20 nations (both friends and foes) have been identified as conducting economic espionage activities against U.S. Corporations. They target any information that will give their indigenous companies an edge in the world marketplace. This economic espionage is expected to continuously increase in the near future with the main target being the theft of “core” technologies.
To a lesser degree countries in Asia, Europe, the Middle East and Latin America are also collecting. The most active countries are the CIS, Israel, France, and Japan. The most proficient are China, Japan, France, Israel, Sweden, Switzerland and Britain.
Foreign Countries use this type of intelligence to directly support business - - their spying easily pays for itself. They target not only western technology to help their country’s industry compete in the world marketplace, but also seek to obtain financial and commercial information to gain an immediate bottom-line advantage in the world marketplace.
2.6.3 INTELLIGENCE COLLECTION THREAT TO (COMPANY NAME, SITE A)
The threat to operations of the U.S. or individual companies arises from the capabilities of hostile countries, friendly countries, or competitors, to piece together bits of information. Information is analyzed over time to determine patterns and to assign meanings to detectable activities.
Generally, competitive analyses and estimates are very valuable if they are 70% correct. At 100% correct theses predictions are invaluable to our competitors or adversaries.
(Company name, Site A) tends to be most vulnerable to (XXXINT) collection efforts. Intelligence sources indicate that the (program name) will be targeted by (adversary). Fill in specific threat at various phases of program.
2.6.4 INTELLIGENCE COLLECTION THREAT TO (COMPANY NAME, SITE B)
During this phase (company name) at (Site B) is extremely vulnerable to all of the collection efforts: SIGINT, HUMINT, IMINT, and MASINT, since there will be outdoor testing. The threat is further enhanced by the limited physical and administrative security controls in place at (Site B) for (program name).
(Site B) is susceptible to the same SIGNIT, HUMINT, and IMINT collection efforts as (Site A). As well as additional IMINT and MASINT efforts due to the limited patrols of the (program name) program areas and lack of security cameras. Electronic equipment may be used in daily operations to process both classified and unclassified information. Collection of information of intelligence value using MASINT techniques could go undetected.
3. CRITICAL INFORMATION
The definition of critical information refers to all information, operations, and activities to be undertaken in performance of the contract that might reveal information necessary to the success of the program. Key questions about friendly intentions and military capabilities likely to be asked by opposition planners and decision makers are defined as Essential Elements of Friendly Information (EEFI).
The following critical information and EEFI are those items of the (program name) program that has vulnerabilities identified. Amendments to this OPSEC Plan and EEFI list will be made as additional EEFI are identified.
(The following items should be considered. Delete as appropriate, or add others.)
1) Travel to and from (Country); FAR limitations re: authorized flights. Is there an identifiable travel pattern?
2) (Program name) International Connections/Partners. What are the support activities for
(program name)?
3) What political constraints have been placed on (Program name) planning, activities, or
Government?
4) What is the most critical aspect of the program?
5) What critical information may our adversaries already know?
6) Who might want to exploit our technology?
7) What testing will occur? Where will it occur? Will it be in or outdoors? Who will conduct the testing?
8) Technology Transfer: What type of technology is being transferred? What is authorized for transfer? What is the process to transfer technology to foreign partners? How are foreign partners, visitors, and unsolicited unclassified requests for information handled?
9) Is there any Controlled Unclassified Information (CUI) on this program? Where is it? How is it handled? What unclassified parameters, if combine, could provide classified data?
The above EEFI are applicable to (Site B) as well as the following additional ones:
10) Some (program name) data at (Site B) is stored at the System Site outside of the security perimeter; is it afforded appropriate security protection? What is that protection? What about the security measures for the network at (Site B)? Are there alarms, locks, cameras, and officers in place?
11) What system is in place for controlling CUI and how will classified material be handled at
(Site B)? What about classified discussions at (Site B) for (program name) participants locally and globally (i.e., telephones, PCs, etc.)?
12) What processes are in place to ensure foreign partners access authorized information only?
How will U.S.-only data be separated?
4 VULNERABILITIES
Vulnerabilities of the program may reveal sensitive or classified information, operations, plans and/or activities, and are derived by comparing the threat to the sensitive aspects of the contract and assessing the OPSEC Indicators.
4.1 GENERAL VULNERABILITIES
The following vulnerabilities are most commonly identified in an OPSEC assessment.
1) Lack of OPSEC Awareness - - Personnel do not fully realize their OPSEC responsibilities.
Employees are not aware of the extent to which an adversary depends on obtaining unclassified information on a defense project and their capability to decipher important intelligence data from this seemingly non-critical information.
2) Testing - - subsystem testing may be vulnerable to exploitation.
3) Open Source Information - - Even unclassified information released to the news media, or at meetings, seminars, and through contractor advertisements, may provide analytical centers with valuable information regarding individual systems capabilities, limitations and technical operations.
4) Professional Conferences/Symposia - - Program personnel are susceptible to elicitation and exploitation when attending these events by fellow participants who covertly represent the intelligence collection agencies of foreign governments. Collection efforts may range from innocuous questions from foreign scientists to actual blackmail by intelligence agents.
Without constant awareness of the threat, project personnel may inadvertently release information of analytic value.
5) Communications - - All unsecured telephone conversations (including cellular phones) are vulnerable to monitoring, and all long distance microwave transmissions are subject to intercept. Such vulnerabilities provide a source of information for intelligence agents.
Communications supporting computer systems and faxes are equally vulnerable.
6) Subcontracting - - The prime contractor may fail to recognize the need for the imposition of
OPSEC on its subcontractors.
7) Automated Information Systems (AIS) Operations - - The contract authorizes the use of
AIS. Without adequate security measures, AIS are susceptible to intrusion or tampering through both hardware and software manipulation. Further, the emanations from AIS equipment and power lines may be subject to intercept. Electronic equipment such as word processors and electronic typewriters that are not TEMPEST approved, installed, and operated properly may produce emanations that are susceptible to intercept and exploitation.
8) Visitor Control - - Visitors within the facility may observe or hear sensitive information, operations, or activities.
9) Conference Room Security - - Classified and sensitive information could be compromised by covert listening devices installed in meeting rooms frequently used for sensitive discussions.
10) Disgruntled Employees and Employees with Personal Problems (Adverse Information) - -
Personnel possessing security clearances who, through personal adversities or circumstances such as marital difficulties, criminal behavior, excessive indebtedness, and/or indiscriminate use of alcohol, present attractive targets to Intelligence Services.
Supervisors and/or fellow employees may become aware of these difficulties but may fail to notify management or security to investigate, electing to ignore the problem or rationalizing that some other party will take action.
Non-action on the part of personnel who become aware of these situations can be as significant as that presented by an adversary who may attempt to exploit personnel experiencing these problems.
4.2 CONTRACTUAL VULNERABILITIES
These vulnerabilities are specific to (program name).
(INSERT VULNERABILITIES IDENTIFIED FOR THIS PROGRAM. CONSIDER THESE
POSSIBLE SOURCES OF VULNERABILITY:)
1) Use of a commercial travel office, travel patterns, and travel practices.
2) Geographic separation of the program participants.
3) Limitations of export license(s).
4) Effectiveness of the product.
5) Sympathies of program personnel for adversary countries.
6) Outdoor testing which results in exposure of the program to overhead (imagery) threats, HUMINT observation, etc.
7) Communications between test sites and program offices following testing.
8) Lack of procedures or failure to comply with those developed for controlling visits and documents/information release international partners and subcontractors.
9) Unauthorized access to specific unclassified performance parameters related or identified with the program.
5. OPSEC MEASURES
Analysis of vulnerabilities identifies tentative OPSEC measures required to maintain essential secrecy. The most desirable OPSEC measure combines the highest protection with the least impact on (program name) effectiveness. There are three categories of OPSEC measures.
1) Action Control – alternative ways of conducting actions and activities which avoid indicators that create vulnerabilities; actions taken within (program name) to eliminate/prevent or control indicators; denies access to the sensitive information, operation, or activity by applying one or more of the traditional security measure (classification, physical security).
2) Countermeasures – Disruption of adversary information collection or gathering. Eliminate or modify the pattern or vulnerability.
3) Counter-analysis – Actions to cause misinterpretation of indicators by analysts. Apply deceptive measures.
5.1 GENERAL OPSEC MEASURES
1) Education - - (Company name) will use education and training to eliminate vulnerabilities discovered through ongoing OPSEC analysis. Participants (including new hires, consultants, transferees, contract labor personnel and subcontractors) shall be briefed and kept informed (through bulletins and/or revised OPSEC guidance) of all sensitive aspects of the Program and the measures designed for the protection of this information and the need for continued awareness and enforcement of OPSEC principles.
Program participant will be briefed concerning the OPSEC significance of their day-to-day tasks, as the activities and operations undertaken in performance of the contract may communicate sensitive information to unauthorized persons just as well as documents produced.
Counterintelligence awareness briefings required by the NISPOM shall be modified, where applicable, to include elements of OPSEC.
2) Open Source Information - - Procedures are established within (company name) to ensure no public release concerning program information occurs without the prior written approval of the (contracting organization name). OPSEC consideration shall be included in the review cycle. Reviews shall also be conducted on announcements concerning visits, tests, and activities posted within facilities about Program matters. Subcontractors are required to forward all material for public release through (company name) for approval prior to releasing the material.
3) Communications - - Emphasis will be placed on instilling awareness among program participants concerning the use of communication devices. Discussions of a classified nature via insecure telephone are absolutely prohibited by Government regulations.
Aspects of Communications Security (e.g., teletype, data fax & cellular phones) will be included in the awareness briefings.
4) Subcontractor Flowdown of OPSEC - - All subcontractors’ Statement of Work will be reviewed by the OPSEC Manager prior to award of contractual work to determine OPSEC applicability.
5) Visitor Control - - All visitors are required to process through established checkpoints for verification of identity, citizenship, personnel security clearances, appropriate certification of purpose of visit, issuance of badges, inspection of articles being brought into and out of the facilities and other such measures to assure proper visitor control.
Escort for visitors shall be advised of proper escort procedures, limitation on disclosure, and other applicable controls involved in the visit.
Program personnel shall be reminded through OPSEC briefings of the potential for the inadvertent release of information by visual and aural means when visitors are present.
Activities of visitors and non-assigned personnel in the program areas shall be observed to determine that their presence is required by business needs and that no suspicious activities are detected which may pose a threat to the security of information.
6) Conference Rooms - - Conference rooms used by personnel to conduct classified meetings are inspected periodically by Security as part of the facility’s on-going participation in the Defense National Industrial Security Program. Program participants will be reminded of conference room procedures to be employed when discussing classified and sensitive/unclassified program matters. This will include attendance control, procedural security while the conference is in session, instruction on note taking, disclosure of the classification/sensitivity of information being discussed, and procedures to ensure that all material is protected during the session, during breaks, and from removal when the session ends. When warranted for especially sensitive classified discussions Top Secret conference rooms or control criteria may be used to preclude unauthorized aural access and to prevent the introduction of clandestine listening devices.
5.2 CONTRACTUAL OPSEC MEASURES
(LIST ANY ADDITIONAL COUNTERMEASURES REQUIRED FOR YOUR PROGRAM)
File details come from the government source that posted it. Updated .