SFPC Operations Security (OPSEC) Concepts 2 — Questions and Answers
Question 1: What is the first step in the OPSEC process?
- Applying countermeasures
- Identifying critical information (Correct answer)
- Analyzing threats
- Assessing risk
Correct answer: Identifying critical information
The first step in the OPSEC process is identifying critical information — determining what information, if obtained by adversaries, would be most harmful to the mission or operation.
The OPSEC process consists of five steps. The first and foundational step is identifying critical information — determining which specific information about the organization's capabilities, activities, limitations, and intentions would be most valuable to adversaries and most harmful if known. This becomes the focus of all subsequent OPSEC measures.
Question 2: What is a 'critical information list' (CIL) in OPSEC?
- A list of all classified documents
- A prioritized compilation of information that must be protected from adversary collection (Correct answer)
- A list of personnel with security clearances
- A list of critical infrastructure components
Correct answer: A prioritized compilation of information that must be protected from adversary collection
A CIL is a prioritized listing of the critical information that an organization must protect because its compromise would provide adversaries with a significant advantage.
A Critical Information List (CIL) is a key OPSEC product that identifies and prioritizes the specific elements of information that must be protected. Items on the CIL are determined based on the adversary's capability to collect and exploit the information and the impact of that exploitation. The CIL is used to focus OPSEC measures on the most important vulnerabilities.
Question 3: What is an 'OPSEC indicator' as used in the five-step OPSEC process?
- A security clearance level
- Observable actions or information that could allow an adversary to detect, identify, or derive critical information (Correct answer)
- A type of classified marking
- A security training certification
Correct answer: Observable actions or information that could allow an adversary to detect, identify, or derive critical information
OPSEC indicators are observable data or activities that can be detected and analyzed by an adversary to deduce critical information about friendly operations.
An OPSEC indicator is any observable action, activity, or piece of information that an adversary can detect and analyze to derive critical information. Indicators may be observable in activities such as unusual work patterns, increased personnel or equipment movement, procurement patterns, or communications activity. OPSEC analysis identifies these indicators so countermeasures can be applied.
Question 4: What is the purpose of OPSEC 'countermeasures'?
- To attack adversary intelligence collection systems
- To eliminate or reduce OPSEC vulnerabilities by protecting critical information from adversary collection (Correct answer)
- To classify additional information
- To conduct counterintelligence investigations
Correct answer: To eliminate or reduce OPSEC vulnerabilities by protecting critical information from adversary collection
OPSEC countermeasures are actions taken to eliminate or reduce OPSEC vulnerabilities by preventing adversaries from detecting indicators of critical information or exploiting those indicators.
OPSEC countermeasures are the measures selected to protect critical information and reduce vulnerabilities identified during the OPSEC analysis. Countermeasures may include security measures (controlling access to information), cover (disguising activities), concealment (hiding activities), and deception (misleading the adversary). They are selected based on the assessed threat and the cost-benefit of their implementation.
Question 5: What is 'threat analysis' in the OPSEC process?
- Analyzing cyber threats only
- Identifying potential adversaries, their capabilities, and their likely intelligence collection methods (Correct answer)
- Assessing employee security risks
- Analyzing physical security vulnerabilities
Correct answer: Identifying potential adversaries, their capabilities, and their likely intelligence collection methods
Threat analysis identifies who the adversaries are, what they are capable of collecting, and what their likely targets and collection methods are.
Threat analysis in the OPSEC process involves identifying all potential adversaries (foreign intelligence services, competitors, terrorists, etc.), assessing their intelligence collection capabilities and methods, and determining what critical information they are likely targeting. Understanding the threat enables the selection of effective countermeasures focused on protecting information from realistic collection threats.
Question 6: What does 'vulnerability analysis' determine in the OPSEC process?
- Only technological vulnerabilities
- Whether adversaries can obtain critical information by exploiting observable indicators (Correct answer)
- Employee vulnerabilities only
- Financial system vulnerabilities
Correct answer: Whether adversaries can obtain critical information by exploiting observable indicators
Vulnerability analysis determines whether adversaries could exploit observable indicators or other weaknesses to collect and correctly interpret the organization's critical information.
OPSEC vulnerability analysis compares the existing and potential indicators identified in the indicator analysis against the threat's collection capabilities to determine whether adversaries could use those indicators to obtain critical information. A vulnerability exists when a threat can collect an indicator and correctly interpret it as critical information. Identified vulnerabilities become the focus of OPSEC countermeasures.
What is the first step in the OPSEC process?