Attachment 3 - OPSEC Information.pdf

PDF 1 MB Posted

Attached to
Med Admin 10 Federal contract opportunity
Solicitation number
FA462021RA201
Issued by
Department of the Air Force Air Mobility Command

View the file

Other files for this federal contract opportunity

Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

What is OPSEC?

Operation Security (OPSEC) is a method to deny adversaries information about friendly intentions and capabilities, which they need to make effective and timely decisions. OPSEC prevents or lessens an adversary’s ability to use our sensitive information to disrupt friendly operations.

FACT: More than 80% of our adversaries’ intelligence needs come from unclassified sources.

In today’s world of global acquisition where so much information is available at a stroke of a key, unclassified information has taken on an entirely new importance. While the Internet provides the main avenue of information loss, our adversaries use others sources to collect on us. These include:

Social Engineering

Elicitation / Solicitation

Press Releases

Surveillance

Eavesdropping

Trash Analysis

Who’s the adversary? Our adversaries include but are not limited to:

Foreign Intelligence Services (FIS)

Hackers / Hacker Groups

Criminals

Terrorists

Anarchists

Disgruntled Insiders

What are they after? All military operations depend upon some form of secrecy, tactical or technological advantage for mission success! Avoid disclosing the following information:

Details of future Operations/Exercises

Defensive and Offensive Tactics

Unit strengths

Names/photographs/travel plans of VIPs

Present and future US capabilities

Supply Inventories

Locations of Critical Infrastructure

Training Deficiencies

OPSEC has never been more important than it is today and will be in the future. It is what helps us to protect and maintain the technological advantage we have.

What can I do?

There are many things that you could do to apply OPSEC in your everyday procedures:

Don’t post sensitive information, to include photos, to the Internet.

Shred Sensitive Unclassified paperwork, such as alert rosters, work orders or technical manuals.

Report suspicious activities on or near the installation to the Unit Security Manager.

Avoid wearing your security badge outside the installation.

Only share information with those who have a ‘need to know’ to accomplish our mission.

Don’t photograph exercises or operations without authorization.

FA462021RA201

Med Admin 10

Attachment - 3 OPSEC Info

Fairchild AFB Basic Critical Information and Indicator List

The following lists describes types of sensitive (critical) information that may be of use to adversaries of the United States Air Force or Fairchild AFB. Do not discuss or transmit details of the following categories of information in non-secure areas or via non-secure means. Do not disclose them to people who do not possess a need-to-know – those who are not directly involved in your project.

Prior to any public release (articles, social media, web sites, blogs, etc.), contractor personnel will consult Public Affairs, the unit or wing Operations Security (OPSEC) specialists to ensure compliance. For further information contact the following offices:

92 ARW OPSEC Signature Manager (509) 247-3012/5258

Air Force Office of Special Investigations (AFOSI) (509) 247-2591/2592

Fairchild Antiterrorism Office (509) 247-9498

Fairchild Public Affairs Office (509) 237-5705

FAFB Basic Critical Information List

Details of:

Current and future operations / exercises

Vulnerabilities, degradation /outages of critical infrastructures or telecommunications

Key personnel/VIP schedules and travel itineraries

Personnel, acquisition and logistics information

Emergency response or contingency plans

Freedom of Information Act (FOIA) Information

FAFB Operational Indicator List

Unit recall

Unplanned Strike Meetings

Unplanned Mobility Processing

Unusual Requests for area of responsibility (AOR) Site Information

Abnormal Changes of Duty Schedules

Increased Transport Activity

Increased Security

Unusual Working Hours

Unusual Increase in Aircraft Maintenance or Servicing

FA462021RA201

FAFB OPSEC 2

Fairchild AFB Contractor OPSEC Level 2 Measures

1. The Operations Security (OPSEC) program reduces potential vulnerabilities of Air Force missions to hostile intelligence collection by preventing exposure of sensitive information.

OPSEC applies to all activities that prepare, sustain, or employ forces during both peacetime and wartime operations.

2. As your organization is contracted to perform work in support of the Fairchild AFB mission, you are responsible to protect this information. Sensitive, or Critical Information includes specific facts about U.S. Air Force operational intentions, capabilities or activities that are vitally needed by potential enemies to plan and act against US military mission accomplishment.

3. Contractor employees who visit Fairchild AFB or remote FAFB installations, or remotely monitor or maintain Fairchild AFB infrastructure will:

a. Within 30 days of reporting for duty become familiar with the following types of

Fairchild AFB Critical Information and Operational Indicators that must be protected from disclosure. These include details of the following information categories:

- Critical Information

Current and future operations and/or exercises

Vulnerabilities, degradation, outages of critical infrastructures / telecommunications

Key personnel/VIP schedules and travel itineraries

Personnel, acquisition and logistics information

Emergency response or base defense plans

Freedom of Information Act (FOIA) Information

Perceived changes to, or details of, normal operating procedures

- Operational Indicators

Unit recall

Unplanned Strike Meetings

Unplanned Mobility Processing

Unusual Requests for area of responsibility (AOR) Site Information

Abnormal Changes of Duty Schedules

Increased Transport Activity

Increased Security

Unusual Working Hours

Unusual Increase in Aircraft Maintenance or Servicing

b. Protect this information from disclosure to people who are unauthorized to possess it.

These include other employees that are not part of the contracted work project, associates, family members and members of the news media.

c. Prevent disclosure of critical and sensitive information in any public domain to include, but not limited to, the Internet and other public forums.

d. Avoid publishing photographs, blogs, tweets that describe or display sensitive operations.

Examples include but are not limited to military formations and exercises, drills, emergency response procedures, and the protective measures of military facilities.

FA462021RA201

Fairchild AFB Contractor OPSEC Level 2 Measures – 2

e. Destroy (burn, shred, etc.) critical and sensitive information that is no longer needed to prevent the inadvertent disclosure or reconstruction of this material.

f. Actively encourage others (including family members) to protect critical and sensitive information.

g. Consult with the Fairchild AFB Public Affairs office or installation OPSEC Signature

Manager for an OPSEC review prior to publishing or posting Fairchild AFB- or USAF-related information in a public forum. This includes, but is not limited to letters, resumes, articles for publication, electronic mail (e-mail), Web site postings, web log (blog) postings, discussion in

Internet information forums, discussion in Internet message boards or other forms of dissemination or documentation.

h. Process, store, or transmit critical sensitive information in a manner to protect that information.

(1) DOD computer systems may be monitored for all lawful purposes, to ensure that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Network monitoring is done in accordance with DoDI 8560.01, Communications Security (COMSEC)

Monitoring and Information Assurance (IA) Readiness Testing.

(2) Unauthorized use of a DOD computer system may subject the user to criminal prosecution. Evidence of unauthorized use collected during monitoring may be used for administrative, criminal or other adverse action. Use of a DOD computer system constitutes consent for all lawful purposes.

(3) When an encryption feature is available on unclassified networks, encrypt email messages containing sensitive information. Encryption serves as an OPSEC measure to protect sensitive information transmitted over unclassified networks.

NOTE. Contract employees who fail to protect critical information from unauthorized disclosure may be subject to adverse administrative, disciplinary or contractual action.

4. Contract employees will consider any attempt by unauthorized personnel to solicit critical information or sensitive information as a human intelligence (HUMINT) incident against the

U.S. Air Force. If you have been involved in, or have knowledge of, a possible HUMINT incident, please report all facts immediately to the local Air Force Office of Special

Investigations (AFOSI). If AFOSI is not readily available, report HUMINT incidents to the supported organization’s security manager, commander, or one of the other offices listed below:

Commercial DSN

Air Force Office of Special Investigation (509) 247-2591/2592 657-2591/2592

92 ARW OPSEC Signature Manager (509) 247-3012/5258 657-3012/5258

Fairchild Antiterrorism Office (509) 247-9498 657-9498

Fairchild Information Protection Office (509) 247-2144/2076 657-2144/2076

Fairchild Public Affairs Office (509) 247-5705 657-5705

FA462021RA201

Operations Security (OPSEC) Provisions within Fairchild AFB

OPSEC Level 2 and 3 Contracts

OPERATIONS SECURITY (OPSEC) REQUIREMENTS. Contract personnel will assist organizational efforts to protect its sensitive operations and related information against hostile collection attempts or inadvertent disclosure through the use of Operations Security

(OPSEC).

OPSEC Awareness Training. DoD Contractors must ensure employees complete OPSEC awareness training within 30 days of commencing employment, and annually thereafter.

Contractor OPSEC training must be documented. Initial and annual OPSEC training credit may be satisfied through organizational training. Access to mission critical information will not be allowed until this training has been completed and documented. Contract personnel will:

Study the provided OPSEC awareness training materials provided.

Become familiar with the types of critical information and indicators which must be protected from disclosure.

OPSEC Measures. DoD Contractors must ensure their employees’ professional and personal conduct do not compromise the organization’s sensitive missions and related information.

Contract personnel will comply with provisions listed in Fairchild AFB Contractor OPSEC

Measures.

FA462021RA201

File details come from the government source that posted it. Updated .