Military reference books and manuals (2009-2023, Volume 4) - page 12

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 4)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     10      11      12      13     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 4) - page 12

 

 

Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Q ==========================================
Questionable Intelligence Activity. An intelligence activity, as defined in EO 12333, that may be unlawful
or contrary to E.O., Presidential directive, or applicable DoD policy governing that activity. (DoDD
5148.11, ATSD/IO, 24 Apr 2013) Also see intelligence oversight.
DoD Policy: See DoD 5240 1-R, Procedures Governing the Activities of DoD Intelligence
Components that Affect United States Persons, 7 Dec 1982.
Also see DTM 08-052, DoD Guidance for Reporting Questionable Intelligence Activities and
Significant or Highly Sensitive Matters, 17 Jun 2009 with chg 4 dated 21 Aug 2013; copy at
Quit Claim. A document in which an asset acknowledges that all commitments due have been met by the
handler’s organization. (HDI Lexicon, April 2008)
266
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
R ==========================================
Rabbit. [Tradecraft jargon] The target in a surveillance operation. (CI Centre Glossary)
Radiogram. Coded bursts of data sent by a radio transmitter that can be picked up by a radio receiver
that has been set to the proper frequency; as transmitted, radiograms generally sound like the
transmission of Morse code. (FBI Affidavit, 25 June 2010)
Radicalization. The process of acquiring and holding radical or extremist beliefs. (Congressional
Research Service Report R42553, Countering Violent Extremism in the United States, 19 Feb 2014)
Also see self-radicalization; violent extremism, violent radicalization.
-- Also, the social and behavioral process whereby people adopt and embrace extremist attitudes,
values or behaviors. It is a risk factor for involvement in terrorism, but involvement in terrorism does not
always result from radicalization. JP1-02 does not include a definition for radicalization. (Defense Science
Board Report, Predicting Violent Behavior, Aug 2012, citing Horgan’s The Psychology of Terrorism 2nd
Edition, 2012)
Radicalization Process
The FBI model describes the radicalization process - the “way stations” - as four incremental
stages of development: 1) Preradicalization, 2) Identification, 3) Indoctrination, and 4) Action.
Each one is distinct, and a radicalized individual may never reach the final stage.
See chart—The Radicalization Process—below…
Source: Carol Dyer, Ryan E. McCoy, Joel Rodriguez, and Donald N. Van Duyn, “Countering Violent Islamic
Extremism: A Community Responsibility, FBI Law Enforcement Bulletin, Vol 76, No 12, Dec 2007*
267
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the process by which an individual, group, or mass of people undergoes a transformation
from participating in the political process via legal means to the use or support of violence for political
purposes. (Army Tactical Reference Guide, Radicalization into Violent Extremism - A Guide for Military
Leaders, April 2011
The growth in social media and the terrorist use of chat rooms, Facebook, Twitter, YouTube, and
other sites has facilitated radicalization inside the United States.
-- Seth G. Jones, The RAND Corporation, “The Extremist Threat to the U.S. Homeland,” Testimony Before
the Committee on Homeland Security United States House of Representatives, 15 January2014
(This testimony available at <http://www.rand.org/pubs/testimonies/CT403.html>)
____________________
There is no easily identifiable terrorist-prone personality, no single path to radicalization and
terrorism. Many people may share the same views, and only a handful of the radicals will go further
to become terrorists. The transition from radical to terrorist is often a matter of happenstance. It
depends on whom one meets and probably on when that meeting occurs in the arc of one’s life.
-- Brian M. Jenkins*
* Brian Michael Jenkins, Would Be Warriors: Incidents of Jihadist Terrorist Radicalization in the United
States Since September 11, 2001 (Santa Monica, CA: The RAND Corporation, 2010), p. 7.
_____________________
Studies by the Department of Homeland Security’s Office of Intelligence and Analysis indicate that
the radicalization dynamic varies across ideological and ethno-religious spectrums, different
geographic regions, and socio-economic conditions. Moreover, there are many diverse “pathways”
to radicalization and individuals and groups can radicalize or “de-radicalize” because of a variety of
factors.
-- U.S. Congress, Senate Committee on Homeland Security and Governmental Affairs, Written Testimony
of Charles E. Allen, Assistant Secretary of Intelligence and Analysis and Chief Intelligence Officer,
Department of Homeland Security, “Threat of Islamic Radicalization to the Homeland,” 110th Cong.,
1st sess., March 14, 2007, p. 5.
__________________________
Also see US Army Asymmetric Warfare Group, Tactical Reference Guide, Radicalization into
Violent Extremism, A Guide for Military Leaders, August 2011—copy available at:
Raid. An operation to temporarily seize an area in order to secure information, confuse an adversary,
capture personnel or equipment, or to destroy a capability culminating with a planned withdrawal.
(JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Rapport Building. Establishing a sense of connection between the interviewer and the interviewee to
facilitate communication and information sharing. (Keats, 1993)
Raw Data. Bits of collected data that individually convey little or no useful information and must be
collated, aggregated, or interpreted to provide meaningful information. (ODNI, U.S. National Intelligence -
An Overview 2011)
Raw Intelligence. A colloquial term meaning collected intelligence information that has not yet been
converted into finished intelligence. (ODNI, U.S. National Intelligence - An Overview 2011)
Reachback. The process of obtaining products, services, and applications, or forces, or equipment, or
material from organizations that are not forward deployed. (JP 1-02 and JP 3-30, Command and Control
for Joint Air Operations, 12 Jan 2010)
Reactive Operation. An operation initiated in response to a FIS personal contact. (AFOSI Manual 71-142,
OFCO, 9 Jun 2000)
268
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Real Time. Pertaining to the timeliness of data or information which has been delayed only by the time
required for electronic communication. This implies that there are no noticeable delays. (Previously in
JP 2-0, Joint Intelligence) Also see near real time.
Reasonable Belief. A reasonable belief arises when the fact and circumstances are such that a
reasonable person would hold the belief. Reasonable belief must rest on the facts and circumstances
that can be articulated; “hunches” or intuitions are not sufficient. Reasonable belief can be based on
experience, training, and knowledge in foreign intelligence or counterintelligence work applied to facts
and circumstances at hand, so that a trained and experienced “reasonable person” might hold a
reasonable belief sufficient to satisfy this criterion when someone unfamiliar with foreign intelligence or
counterintelligence work might not. (DoD 5240.1-R, December 1982) Also see probable cause;
reasonable suspicion.
Reasonable Expectation of Privacy. In U.S. constitutional law the expectation of privacy is a legal test
which is crucial in defining the scope of the applicability of the privacy protections of the Fourth
Amendment to the United States Constitution.
The extent to which a reasonable person in the particular circumstances involved is entitled to believe
his or her actions are not subject to outside observations. Must be both objectively and subjectively
reasonable [as well as] very fact specific. (SJA Office, USAINSCOM)
____________________
As a general matter the Supreme Court has held that there may be circumstances in which a
government employee has a legitimate expectation of privacy in the contents of governmental
property that the employee uses or controls at work, such as an office or a locked desk drawer.
See: O’Connor, 480 U.S. at 716-19 (1987) (plurality) (public employee has a reasonable expectation
of privacy in personal items, papers, and effects in office, desk, and file cabinets provided by public
employer); see id. at 730-31 (Scalia, J., concurring) (government employee has a legitimate
expectation of privacy in the contents of his office).
Instead, whether, in a particular circumstance, a government employee has a legitimate expectation
of privacy in his use of governmental property at work is determined by “[t]he operational realities of
the workplace” and “by virtue of actual office practices and procedures, or by legitimate regulation.”
See: O’Connor, 480 U.S. at 717 (plurality); see United States v. Simons, 206 F.3d 392, 398 (4th Cir.
2000) (“[O]ffice practices, procedures, or regulations may reduce legitimate privacy expectations.”).
Reasonable Suspicion. Specific and articulable facts which, taken together with rational inferences from
those facts, evince more than an inchoate and unparticularized suspicion or hunch of criminal activity.
(United States v. Mason, 628 F.3d 123, 128 - 4th Cir. 2010 [quoting United States v. Branch, 537 F.3d
328, 336 - 4th Cir. 2008])
Recognition Signal. Any prearranged signal by which individuals or units may identify each other.
(JP 1-02 and JP 3-50. Personnel Recovery, 20 Dec 2011)
-- Also, prearranged visual indicator used for recognition and identification between intelligence
personnel. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
-- Also, prearranged visual signal used by intelligence personnel to identify each other. (FBI FCI
Terms)
Reconnaissance (RECON). A mission undertaken to obtain, by visual observation or other detection
methods, information about the activities and resources of an enemy or adversary, or to secure data
concerning the meteorological, hydrographic, or geographic characteristics of a particular area. (JP 1-02
and JP 2-0, Joint Intelligence, 22 Oct 2013)
269
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Records Check. The process whereby a Special Agent obtains relevant information about Sources or
Subjects from the records and information holdings of military, civilian or government agencies, as well as
certain commercial companies and vendors, during the conduct of an investigation or operation. Types
include military agency checks (MACs), local agency checks (LACs) and national agency checks (NACs).
-- Military Agency Check (MAC): a records or files check conducted at any military agency within the
jurisdiction of the CI element conducting the check.
-- Local Agency Check (LAC): a records or files check of official or publically available information
retained by any local office or government agency within the jurisdiction of the CI element
conducting the check. Records may include holdings and databases maintained by local and state
law enforcement agencies, local courts, local offices of federal agencies, etc.
-- National Agency Check (NAC): formal requests to federal agencies for searches of their records
and supporting databases and files for information of investigative or operational interest. NACs
include DoD agencies, as well as other federal agency holdings, e.g., FBI, CIA, DHS, ICE, IRS,
OPM, State Department, FINCEN, etc.
Recovery Operations. Operations conducted to search for, locate, identify, recover, and return isolated
personnel, human remains, sensitive equipment, or items critical to national security. (JP 1-02 and
JP 3-50, Personnel Recovery, 5 Jan 2007)
Recruitment. The deliberate and calculating effort to gain control of an individual and to induce him or her
to furnish information or to carry out intelligence tasks for an intelligence or CI service. (DoDI S-5240.17,
CI Collection Activities, 14 Mar 2014)
-- Also, authorized personnel establishing control over an foreign individual who, witting or unwitting
of USG involvement, accepts tasking as a result of the established relationship; authorized personnel
establishing control over a U.S. person who, fully aware of USG involvement, accepts tasking as a result
of the established relationship. (DoDI S-5200.42, Defense HUMINT and Related Activities (U), 8 Dec
2009 w/ chg 1 dated 16 Aug 2010)
-- Also, the acquisition of an individual’s services who, witting or unwitting of U.S. Government
involvement, accepts directions and control thus obligating both parties to an act in a prescribed manner.
(HDI Lexicon, April 2008)
-- Also, the establishment of a degree of control over an individual who, witting or unwitting of U.S.
Government involvement accepts tasking as a result of the relationship established. (Army TC 2-22.307,
Aug 2009)
-- Also, the process of enlisting an individual to work for an intelligence or counterintelligence service.
(FBI FCI Terms)
-- Also, term for the tradecraft process of enlisting a target individual to work for an intelligence or
security service. (The CIA Insider’s Dictionary, by Leo D. Carl, 1996)
-- Also, the tradecraft process of enlisting a target individual to work for an intelligence service—in
most cases against his own country. The process includes spotting, assessing, developing, and
recruitment. Motivation may be ideological, financial, or other, such as revenge. (A Spy’s Journey)
Recruitment… is a process of salesmanship, almost of seduction.
-- SSCI Report 99-522 (1986)
270
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Agent recruiting is the most important task of both strategic and operational intelligence. No real
problems can be solved without agent penetration in basic government, military and technological
centres of the enemy.
-- Victor Suvorov, Inside Soviet Military Intelligence (1984); see Chapter 4 - Agent Recruiting.
_____________________
Agent recruitment is a tedious process with a low rate of success and a high rate of return. Of
every ten agents recruited, eight will fall by the wayside because they lose their access or they tire
of the commitment, one will be a problem—mainly of security—and one will work as a productive
agent, perhaps for decades.
-- Joseph W. Wippl (35 year CIA career with the National Clandestine Service), “The Qualities That
Make a Great Case Officer,” International Journal of Intelligence and Counterintelligence, Vol 25
No 3 (Fall 2012), p. 602
_____________________
Recruitment… is an art form
How do you do recruitment? “How do you sell anything in life? You have to have a product, you
have to develop a relationship, and in that relationship you have to be able to identify people’s
strengths and weaknesses. And then you have to be able to ask that tough question: Will you help
me? There is a sense of timing in it. It’s an art form, very frankly.”
-- Jack Devine, 32-year CIA veteran in “Ten Questions,” Time Magazine, Vol. 183 No. 23, 16 June 2014. p. 60
Recruitment Cycle. The… process by which intelligence services recruit agents (aka the agent
acquisition process). (James M. Olson, Fair Play: The Moral Dilemmas of Spying, 2006)
“The recruitment cycle is the essence of spying”
Seven steps of the recruitment cycle: 1) Spotting; 2) Assessing; 3) Developing; 4) Pitching; 5) Formalizing;
6) Producing; and 7) Terminating.
-- James M. Olson (CIA Retired), Former Chief CIA Counterintelligence
-- Also, Agent Recruitment Cycle (ARC): the systematic method for acquiring agents HUMINT
sources) who will satisfy intelligence collection requirements and meet intelligence needs.
The Agent Recruitment Cycle consists of six steps:
+ Spotting (or identifying) individuals who can meet intelligence needs as identified by analyst or
policymakers.
+ Assessing whether the spotted individuals have the placement and access to provide the
desired information as well as beginning the process of determining their motivations,
vulnerabilities, and suitability.
+ Developing a relationship with the individual to further assess the factors above and to explore
whether they will be responsive to initial tasking for intelligence information.
+ The actual recruitment.
+ Training and handling meetings with the agent, including taskings and debriefings.
+ Either turning an agent over to another case officer or terminating the relationship.
-- Randy Burkett, “An Alternative Framework for Agent Recruitment: From MICE to RASCALS,”
Studies in Intelligence, Vol 57, No 1 (March 2013), p. 55
_____________________
Seven basic areas: 1) Spotting; 2) Evaluation; 3) Recruiting; 4) Testing; 5) Training; 6) Handling;
and 7) Termination.
+ Spotting: the process of identifying foreigners or other persons who might be willing to spy…
+ Evaluation: a thorough review of all information available…
+ Recruiting: the recruitment “pitch”.… People volunteer or agree to spy on their governments
for many reasons. It is the task of the recruiter to determine what reason—if one exists—is
most likely to motivate the potential agent.
+ Testing: [testing the asset’s] loyalty and reliability …
271
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
+ Training: [tradecraft training] instructed in one of several methods of covert
communications… learn the use of clandestine contacts. And… will be given training
on security precautions, such as the detection and avoidance of surveillance.
+ Handling: Successful handling of an agent hinges on the strength of the relationship
that the case officer is able to establish with the agent. ….a good case officer must
combine the qualities of a master spy, a psychiatrist, and a father confessor. …One of the
biggest problems in handling an agent is caused by the changeover of case officers.
+ Termination: All clandestine operations ultimately come to an end. …[need for] resettlement
-- Victor Marchetti and John D. Marks, The CIA and the Cult of Intelligence, 2nd Edition (1980), pp 215-228
_______________________
Agent recruitment [cycle]: 1) Spot; 2) Assess; 3) Develop & Recruit; 4) Test; 5) Train; 6) Handle;
and 7) Terminate.
-- Jefferson Mack, Running a Ring of Spies (1996)
Recruitment-in-Place (RIP). An official who overtly continues to work for his government and
clandestinely provides information of intelligence value to a foreign government; will in many instances
be connected with a foreign government’s intelligence service. (CI Community Lexicon) Also see
penetration; penetration operation.
-- Also, a person who agrees to become an agent and retain his position in his organization or
government while reporting on it to an intelligence or security organization of a foreign country.
(ICS Glossary)
-- Also, inducement of a person to become an informant or agent of an intelligence service while he
or she remains in the same position and status. This term applies to personnel of foreign establishments,
diplomatic or other, who continue to occupy their regular posts instead of defecting. (AFOSI Instruction
71-101, 6 Jun 2000)
-- Also, a foreign national who overtly continues to work for his government and covertly provides the
U.S. with information of intelligence value. (FBI FCI Terms)
Recruitment-in-place, one of the most difficult and sensitive activities in counterintelligence.
-- William H. Webster, Director FBI, Speech on 22 March 1986
____________________________
Recruiting anybody to be a spy is an act of seduction. Recruiting hostile intelligence officers
amounts to seducing seducers—an art in itself.
--
Angelo Codevilla, Informing Statecraft: Intelligence for a New Century (1992), p. 337
____________________________
A recruitment who stays on the job… is the ultimate prize, the crown jewel of any
counterintelligence operation. At great personal risk, a recruitment in place is in a position to
provide continuous and up-to-date information. By contrast, a defector, while usually welcome, is
of less value. Once debriefed of the information he or she knows, and with no further access to
secrets, a defector has diminished worth.
-- David Wise, Tiger Trap: America’s Secret Spy War with China (2011), p. 177
____________________________
It is axiomatic in intelligence work that ‘there is no better counterintelligence than recruiting the
other side’s intelligence officers.’
--
James M. Olson (CIA Retired), Former Chief CIA Counterintelligence
Reconstitution. The process of restoring critical assets and their necessary infrastructure
support systems (or their functionality) to pre-incident operational status. (DoDI 3020.45, DCIP
Management, 21 Apr 2008)
272
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
RED. In cryptographic systems, refers to information or messages that contain sensitive or classified
information that is not encrypted. (CNSSI No. 4009, National Information Assurance Glossary, 26 April
2010) Also see BLACK.
RED EYE. The RED EYE Task Force, hosted by AFMC [Air Force Material Command] and sponsored
by Region 1 [AFOSI] is a multi-agency operation consisting of nine federal law enforcement and
intelligence agencies working together to identify, exploit, neutralize and mitigate threats of illicit
procurement and illegal export of sensitive U.S. technology to foreign adversaries. (AFOSI 2012
Fact Book)
Red Team. An organizational element comprised of trained and educated members that provide an
independent capability to fully explore alternatives in plans and operations in the context of the
operational environment and from the perspective of adversaries and others. (JP 1-02 and JP 2-0,
Joint Intelligence, 22 Oct 2013) Also see red team analysis.
A “CI Red Team” is a simulation of a foreign intelligence collection activities of a specified
friendly/Blue target, such as a RDA project/program, installation, military operation, etc. May
include the identification of physical, electronic, acoustic, or visual patterns of the supported
activity/agency as may be seen through the eyes of ad adversary.
Red Team Analysis. Models the behavior of an individual or group by trying to replicate how an
adversary would think about an issue. (CIA, A Tradecraft Primer: Structured Analytical Techniques
for Improving Intelligence Analysis, June 2005) Also see red team.
Red Team analysis tries to consciously place the analyst in the same cultural, organizational, and
personal setting -- “putting them in their shoes” -- in which the target individual or group operates.
Red Team analysis is not easy to conduct. It requires significant time to develop a team of qualified
experts who can think like the adversary.
Contrarian methods and “Red Teams” should be a routine part of the analytical process.
-- Jeffrey R, Cooper, Curing Analytical Pathologies, Center for the Study of Intelligence (Dec 2005), p. 43
Redaction. For purposes of declassification, the removal of exempted information from copies of a
document. (DoD Manual 5200.01-Vol 1, DoD Information Security Program, 24 Feb 2012)
Refugee. A person who owing to a well-founded fear of being persecuted for reasons of race, religion,
nationality, membership of a particular social group or political opinion, is outside the country of his or her
nationality and is unable or, owing to such fear, is unwilling to avail himself or herself of the protection of
that country. See also dislocated civilian; displaced person; evacuee; expellee; stateless person. (JP 1-02
and JP 3-29, Foreign Humanitarian Assistance, 17 Mar 2009)
Regional Security Officer (RSO). A security officer responsible to the chief of mission (ambassador), for
security functions of all US embassies and consulates in a given country or group of adjacent countries.
(JP 1-02 and JP 3-10, Joint Security Operations in Theater, 3 Feb 2010)
-- Also, Diplomatic Security Special Agents of the U.S. Department of State (DoS), assigned to U.S.
diplomatic missions overseas as the personal advisor to the ambassador or chief of mission on all
security issues and coordinate all aspects of a mission's security program. They develop and implement
effective security programs to protect DoS employees from terrorist, criminal, and technical attack both at
work and at home. The RSO serves as the primary liaison with foreign police and security services
overseas in an effort to obtain support for U.S. law enforcement initiatives and investigations. (DoS)
See Department of State website at: <http://www.state.gov/m/ds/protection/c8756.htm>
273
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Reid Technique. A method of questioning subjects and assessing their credibility. The technique consists
of a non-accusatory interview combining both investigative and behavior-provoking questions. If the
investigative information indicates that the subject committed the crime in question, the Reid Nine Steps
of Interrogation are utilized to persuade the subject to tell the truth about what they did. The Reid
technique involves three different components — factual analysis, interviewing, and interrogation.
(Wikipedia; accessed 21 Aug 2013)
The term "Reid Technique" is a registered trademark of the firm John E. Reid and Associates,
which offers training courses in the method they have devised. The technique is widely used by
numerous law-enforcement agencies. For more information see: <http://www.reid.com/>
Remediation. Actions taken to correct known deficiencies and weaknesses once a vulnerability has been
identified. (DoDD 3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg
2 dated 21 Sep 2012)
-- Also, the act of mitigating a vulnerability or a threat. (CNSSI No. 4009, National Information
Assurance Glossary, 26 April 2010)
Rendition. An extra-territorial activity to apprehend and return a person to the US or another country, with
or without permission from the country in which the subject is apprehended. (National HUMINT Glossary)
The term “rendition” in the counterterrorism context means nothing more than moving someone
from one country to another, outside the formal process of extradition.
-- Daniel Benjamin, Former Director for Counterterrorism, National Security Council
_________________________
For additional information see CRS Report (RL32890) Renditions: Constraints Imposed by Laws
on Torture, 8 Sep 2009; copy available at: <http://www.fas.org/sgp/crs/natsec/RL32890.pdf>
Repatriate. A person who returns to his or her country or citizenship, having left said native country either
against his or her will, or as one of a group who left for reason of politics, religion, or other pertinent
reasons. (JP 1-02)
Repatriation.
1) The procedure whereby American citizens and their families are officially processed back
into the United States subsequent to an evacuation. (JP 3-68, Noncombatant Evacuation Operations, 23
Dec 2010); and 2) The release and return of enemy prisoners of war to their own country in accordance
with the 1949 Geneva Convention Relative to the Treatment of Prisoners of War. (JP 1-0, Personnel
Support to Joint Operations, 16 Oct 2006)
Report of Investigation (ROI). An executive summary of all results of investigative activity conducted in
an investigation. (902d MIG Investigations Handbook, updated 17 Oct 2012) .
Reportable Incident. Any suspected or alleged violation of Department of Defense policy or of other
related orders, policies, procedures or applicable law, for which there is credible information. (JP 1-02
and JP 3-63, Detainee Operations, 30 May 2008)
Request For Assistance (RFA). A request based on mission requirements and expressed in terms of
desired outcome, formally asking for assistance.
Request For Information (RFI). 1) Any specific time-sensitive ad hoc requirement for intelligence
information or products to support an ongoing crisis or operation not necessarily related to standing
requirements or scheduled intelligence production. 2) A term used by the National Security
Agency/Central Security Service to state ad hoc signals intelligence requirements. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
274
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Research, Development, and Acquisition (RDA). All activities associated with research and engineering,
acquisition, international transfers of technology, and disposal of defense-related technology.
(DoDI O-5240.24,CI Activities Supporting RDA, 8 Jun 2011 with change 1 dated 15 Oct 2013)
Residency. An office or location in a country used by foreign intelligence officers from which to plan,
coordinate, and execute intelligence activities. Also refers to the number of foreign intelligence agents
present in a given area. (AR 381-20, Army CI Program, 25 May 2010)
Resilience. The ability to prepare for and adapt to changing conditions and withstand and recover rapidly
from disruptions; includes the ability to withstand and recover from deliberate attacks, accidents, or
naturally occurring threats or incidents. (PPD-21, 2013)
Resiliency. The characteristic or capability to maintain functionality and structure (or degrade gracefully)
in the face of internal and external change. (DoDI 3020.45, DCIP Management, 21 Apr 2008)
Resistance Movement. An organized effort by some portion of the civil population of a country to resist
the legally established government or an occupying power and to disrupt civil order and stability.
(JP 1-02 and JP 3-05, Special Operations, 18 Apr 2011)
Responsible Analytical Center (RAC). The Intelligence organization that has responsibility for providing
integrated all-source analysis, or application of analysis, to produce an intelligence product to answer a
specific COCOM Intelligence Task List (ITL) task or sub-task. DoD organizations that qualify as RACs
include: DIA analytical offices [including DAC-1C] and Intelligence Centers, the COCOM Joint Intelligence
Operations Centers (JIOCs), and the Service intelligence production centers (MCIA, NASIC, NGIC, and
ONI). (CJCSM 3314.01, Intelligence Planning, 28 Feb 2007)
Restraint. In the context of joint operation planning, a requirement placed on the command by a higher
command that prohibits an action, this restricting freedom of action. (JP 1-02 and JP 5-0, Joint Operation
Planning, 11 Aug 2011)
Restricted Area. An area (land, sea or air) in which there are special restrictive measures employed to
prevent or minimize incursions and/or interference, where special security measures are employed to
prevent unauthorized entry. Restricted areas may be of different types depending on the nature and
varying degree of importance of the security interest, or other matter contained therein. Restricted areas
must be authorized by the installation/activity commander/director, properly posted, and shall employ
physical security measures. Additionally, Controlled Areas may be established adjacent to Restricted
Areas for verification and authentication of personnel. (DoD 5200.08-R, Physical Security Program,
9 Apr 2007)
-- Also, 1) An area (land, sea, or air) in which there are special restrictive measures employed to
prevent or minimize interference between friendly forces; and 2) An area under military jurisdiction in
which special security measures are employed to prevent unauthorized entry. (JP 1-02)
Restricted Target. A valid target that has specific restrictions placed on actions authorized against it due
to operational considerations. Also see restricted target list. (JP 3-60, Joint Targeting, 13 Apr 2007)
Restricted Target List (RTL). A list of restricted targets nominated by elements of the joint force and
approved by the joint force commander. This list also includes restricted targets directed by higher
authorities. Also see restricted target. (JP 3-60, Joint Targeting, 13 Apr 2007)
Returnee. A displaced person who has returned voluntarily to his or her former place of residence.
(JP 3-29, Foreign Humanitarian Assistance, 17 Mar 2009)
Revolution. The overthrow or renunciation of one government or ruler and the substitution of another by
the governed. (Army FM 3-24-2, Tactics in Counterinsurgency, April 2009)
275
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Risk. Probability and severity of loss linked to threats or hazards and vulnerabilities. (DoDD 3020.40,
DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, probability and severity of loss linked to hazards (JP 1-02 and JP 5-0, Joint Operation
Planning, 11 Aug 2011)
-- Also, a measure of consequence of peril, hazard or loss, which is incurred from a capable
aggressor or the environment (the presence of a threat and unmitigated vulnerability). (DoD 5200.08-R,
Physical Security Program, 9 Apr 2007)
-- Also, a measure of the potential degree to which protected information is subject to loss through
adversary exploitation. (DoD 5205.02-M, DoD OPSEC Program Manual, 3 Nov 2008)
-- Also, a measure of the extent to which an entity is threatened by a potential circumstance or event,
and typically a function of 1) the adverse impacts that would arise if the circumstance or event occurs;
and 2) the likelihood of occurrence. (CNSSI No. 4009, National Information Assurance Glossary, 26 April
2010)
-- Also, the potential for an unwanted outcome resulting from an incident, event, or occurrence, as
determined by its likelihood and the associated consequences. (DHS, National Infrastructure Protection
Plan - 2009)
When you hear “calculated risk,” don’t ask to see the calculations.
-- Dr. Gus Weiss, Former Assistant Secretary of Defense for Space Policy
(quoted in Intelligence Analysis: A Target-Centric Approach)
Risk, in the context of critical infrastructure and terrorism, can be defined as the potential
consequence associated with a particular kind of attack or event against a particular target,
discounted by the likelihood that such an attack or event will occur (threat) and the likelihood that
the target will sustain a certain degree of damage (vulnerability).
Threat includes not only the identification of specific adversaries, but also their intentions and
capabilities (both current and future). Consequences include lives and property lost, short term
financial costs, longer term economic costs, environmental costs, etc.
Given this definition, risk is not threat, nor vulnerability to a threat, nor the estimated consequences
associated with a specific attack, but some integration of the three.
-- CRS Report, RL30153, 8 Jan 2007
Risk Avoidance. A security philosophy which postulates that adversaries are all-knowing and highly
competent, against which risks are avoided by maximizing defenses and minimizing vulnerabilities.
(DSS Glossary) Also see risk management.
Risk Analysis. A method by which individual vulnerabilities are compared to perceived or actual security
threat scenarios in order to determine the likelihood of compromise of critical information. (DSS Glossary)
-- Also, examination of information to identify the risk to an information system. See risk assessment.
(CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Risk Assessment. A systematic examination of risk using disciplined processes, methods, and tools. A
risk assessment provides an environment for decision makers to evaluate and prioritize risks continuously
and to recommend strategies to remediate or mitigate those risks. (DoDD 3020.40, DoD Policy and
Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, the identification and assessment of hazards (first two steps of risk management process).
(JP 1-02 and JP 3-07.2, Antiterrorism, 24 Nov 2010)
276
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a process of evaluating the risks to information based on susceptibility to intelligence
collection and the anticipated severity of loss. (DoD 5205.02-M, DoD OPSEC Program Manual,
3 Nov 2008)
-- Also, a defined process used to fuse the procedures of analyzing threat, risks, and vulnerabilities,
into a cohesive, actionable product. (DoD 5200.08-R, Physical Security Program, 9 Apr 2007)
-- Also, the process of evaluating security risks based on analyses of threats, vulnerabilities, and
probable adverse consequences to a facility, system, or operation. (IC Standard 700-1, 4 Apr 2008)
Risk Assessment
The process of identifying, prioritizing, and estimating risks. This includes determining the extent to
which adverse circumstances or events could impact an enterprise. Uses the results of threat and
vulnerability assessments to identify risk to organizational operations and evaluates those risks in
terms of likelihood of occurrence and impacts if they occur. The product of a risk assessment is a
list of estimated, potential impacts and unmitigated vulnerabilities. Risk assessment is part of risk
management and is conducted throughout the Risk Management Framework (RMF).
-- CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010
Risk Management (RM). The process of identifying, assessing, and controlling, risks arising from
operational factors and making decisions that balance risk cost with mission benefits. (JP 1-02 and
JP 3-0, Joint Operations, 11 Aug 2011)
The basic concept for a cost effective security system is risk management rather than the
unattainable and unaffordable goal of risk avoidance.
-- Joint Security Commission II Report, 24 August 1999, p.12
-- Also, a process by which decision makers accept, reduce, or offset risk and subsequently make
decisions that weigh overall risk against mission benefits. (DoDD 3020.40, DoD Policy and
Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, process and resultant risk of systematically identifying, assessing and controlling risks.
Commanders/Directors are required to identify critical assets and their subsequent protection
requirements, including future expenditures required for the protection requirements. (DoD 5200.08-R,
Physical Security Program, 9 Apr 2007)
-- Also, the process of selecting and implementing security countermeasures to accept or mitigate the
risk of a known or suspected threat to an acceptable level based on cost and effectiveness. (IC Standard
700-1, 4 Apr 2008)
-- Also, Antiterrorism (AT) Risk Management: the process of systematically identifying, assessing,
and controlling risks arising from operational factors and making decisions that balance possible adverse
outcomes with mission benefits. AT risk management is one of the five minimum elements of an AT
program. The end products of the AT program risk management process shall be the identification of DoD
elements and personnel that are vulnerable to the identified threat attack means. From the assessment of
risk based upon the three critical components of AT risk management (threat assessment, criticality
assessment, and vulnerability assessment), the commander or DoD civilian manager must determine
which DoD elements and personnel are at greatest risk and how best to employ given resources and FP
measures to deter, mitigate, or prepare for a terrorist incident. (DoDI 2000.12, DoD Antiterrorism
Program, 1 Mar 2012 with change 1 dated 9 Sep 2013)
Risk Mitigation. Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/
countermeasures recommended from the risk management process. (CNSSI No. 4009, National
Information Assurance Glossary, 26 April 2010)
277
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Risk Response. Actions taken to remediate or mitigate risk, or to reconstitute capability in the event of
loss or degradation. (DoDD 3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan
2010 w/ chg 2 dated 21 Sep 2012)
Romeo Spies. Men whose task is to seduce women who have access to confidential material, in the
hope that through pillow talk the women will reveal secrets. (Encyclopedia of Cold War Espionage, Spies,
and Secret Operations, 3rd revised edition 2012)
Rolling Car Pickup. A clandestine car pickup executed so smoothly that the car hardly stops at all and
seems to have kept moving forward. (CI Centre Glossary) Also see car pick-up.
Rule of the Least Intrusive Means. The collection of information by a DoD intelligence component must
be accomplished by the least intrusive means or lawful investigative technique reasonably available.
(DIA Intelligence Law Handbook, Sep 1995)
This rule prescribes a hierarchy of collection techniques which must be considered before an
intelligence component engages in collection of information about US persons. The methodologies
below become progressively more intrusive as one proceeds through this hierarchical framework:
-- First, to the extent feasible, information must be collected from publically available materials, or
with the consent of the person or persons concerned.
-- Second, if collection from these sources is not feasible, then cooperating sources may be used.
-- Third, if neither publically available information nor cooperating sources are sufficient or feasible,
and then collection may be pursued using other lawful investigative techniques that require
neither a judicial warrant nor the approval of the Attorney General of the United States.
-- Finally, when none of the first three approaches has been sufficient or feasible, then the
collecting intelligence component may seek approval for use of one of the techniques that
require a warrant or approval of the Attorney General.
DoD Policy: see DoD Regulation 5240.1-R, Procedures Governing the Activities of DoD
Intelligence Components that Affect United States Persons, 7 Dec 1982 (para C2.4.2, page 18).
Rules of Engagement (ROE). Directives issued by competent military authority that delineate the
circumstances and limitations under which United States forces will initiate and/or continue combat
engagement with other forces encountered. (JP 1-02 and JP 1-04, Legal Support to Military Operations,
17 Aug 2011)
Ruse. In military deception, a trick of war designed to deceive the adversary, usually involving the
deliberate exposure of false information to the adversary's intelligence collection system. (JP 1-02 and
JP 3-13.4, Military Deception, 13 Jul 2006)
278
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
S ==========================================
Sabotage. An act or acts with intent to injure, interfere with, or obstruct the national defense of a country
by willfully injuring or destroying, or attempting to injure or destroy, any national defense or war materiel,
premises, or utilities, to include human and natural resources. (JP 1-02 and JP 2-01.2, CI & HUMINT in
Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, the willful destruction of government property with the intent to cause injury, destruction, or
defective production of national defense or war materials by either an act of commission or omission.
(IC Standard 700-1, 4 Apr 2008)
Sabotage is a violation of Title 18 USC, §§ 2151-2156.
_______________________
[S]abotage is the destruction of material by covert means
in order to destroy the capability of a country to pursue its policies.
-- Tucker, David. Illuminating the Dark Arts of War,
New York: Continuum International Publishing Group, 2012, p. 136
Safe House. An innocent-appearing house or premises established by an organization for the purpose of
conducting clandestine or covert activity in relative security. (JP 1-02 and JP 3-07.2, Antiterrorism, 24 Nov
2010)
-- Also, a facility use to afford security for operations. (HDI Lexicon, April 2008)
-- Also, house or premises controlled by an intelligence service that affords at least temporary
security for individuals engaged in intelligence operations. (CI Community Lexicon)
-- Also, any house, apartment, office, or other building or quarters used to afford security for persons
engaged in clandestine activities or for intelligence collection purposes. Safe houses may be used as
refuge for or holding of agents or defectors; lodging and feeding of couriers, escapees, or evaders;
lodging and working space for agents; rendezvous training, briefing, or questioning; or storage of supplies
and equipment. (National HUMINT Glossary)
-- Also, a location controlled by an intelligence service that provides a secure place for individuals
engaged in intelligence operations to meet. (FBI FCI Terms)
-- Also, a secure facility, unknown to adversary intelligence and security services, used for agent
meetings, defector housing or debriefing, and similar support functions. (CIA in D&D Lexicon, 1 May
2002)
-- Also, [safehouse] a secure location used by intelligence services to meet with agents or for other
clandestine purposes. The renter or purchaser of a safehouse is usually a cutout, someone who has no
visible connection with intelligence work or with any official organization. (James M. Olson, Fair Play: The
Moral Dilemmas of Spying, 2006)
-- Also, [safehouse] a sterile location, normally a house or apartment—but could be a hotel room as
well—used to meet agents securely. (A Spy’s Journey)
Safeguarding. Measures and controls that are prescribed to protect classified information. (DoD Manual
5200.01-Vol 1, DoD Information Security Program, 24 Feb 2012)
279
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Sanction Enforcement. Operations that employ coercive measures to control the movement of certain
types of designated items into or out of a nation or specified area. (JP 1-02 and JP 3-0, Joint Operations,
11 Aug 2011)
Sanitization. The editing of intelligence to protect sources, methods, capabilities, and analytical
procedures to permit wider dissemination (IC Standard 700-1, 4 Apr 2008)
Sanitize. To revise a report or other document in such a fashion as to prevent identification of sources,
or of the actual persons and places with which it is concerned, or of the means by which it was acquired.
Usually involves deletion or substitution of names and other key details. (JP 1-02)
Sanitizing. The removal of information from the media or equipment such that data recovery using
any known technique or analysis is prevented. Sanitizing shall include the removal of data from
the media, as well as the removal of all classified labels, markings, and activity logs. Properly sanitized
media may be subsequently declassified upon observing the organization’s respective verification and
review procedures. (DSS Glossary)
Satellite Reconnaissance Advanced Notice (SATRAN) Program. Advanced warning of reconnaissance
satellite orbits so military commanders can take appropriate action. (Center for Army Lessons Learned,
In response to the intelligence threat from Soviet imagery satellites, the United States initiated the
Satellite Reconnaissance Advanced Notice (SATRAN) program… in 1966.
-- Jeffrey T. Richelson, The US Intelligence Community (2012, Sixth Edition), pp. 270-271
_________________
The mission of the SATRAN Program is to provide the US military, US Government agencies…
with warning of periods where their equipment or activities are vulnerable to reconnaissance by
foreign spacecraft. The SATRAN program provides accurate overflight information in a timely
manner so that foreign spacecraft are denied the opportunity to collect useful intelligence data.
-- Intellipedia (accessed 4 Mar 2014)
SATRAN. Acronym, see Satellite Reconnaissance Advanced Notice Program above.
Scams. [Cyber usage] Fake deals that trick people into providing money, information, or service in
social-networking-risks-1>)
Scattered Castles. The IC [Intelligence Community] security clearance repository and the Director of
National Intelligence’s authoritative source for clearance and access information for all IC, military
services, DoD civilians, and contractor personnel. DoD information is furnished by JPAS. (IC Standard
700-1, 4 Apr 2008)
Scientific and Technical Intelligence (S&TI). The product resulting from the collection, evaluation,
analysis, and interpretation of foreign scientific and technical information that covers: a. foreign
developments in basic and applied research and in applied engineering techniques; and b. scientific and
technical characteristics, capabilities, and limitations of all foreign military systems, weapons, weapon
systems, and materiel; the research and development related thereto; and the production methods
employed for their manufacture. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military
Operations, 5 Jan 2012)
Scientific Method. [One of the four basic types of reasoning applied to intelligence analysis, it] combines
deductive and inductive reasoning: induction is used to develop the hypothesis, and deduction is used to
test it. (DIA, Intelligence Essentials for Everyone, June 1999) Also see abduction; deduction; induction.
For additional information see Knowledge Management in the Intelligence Enterprise by Edward
Waltz (2003).
280
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Screening. In intelligence, [the] evaluation of an individual; or a group of individuals to determine their
potential to answer collection requirements or to identify individuals who match a predetermined source
profile coupled with the process of identifying and assessing the areas of knowledge, cooperation, and
possible approach techniques for an individual who has information of intelligence value. (JP 1-02 and
JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
For additional information see Chapter 6 “Screening,” FM 2-22.3, Human Intelligence Collection
Operations.
SCRM. See Supply Chain Risk Management.
Search. An examination, authorized by law, of a specific person, property, or area for specified property
or evidence, or for a specific person for the purpose of seizing such property, evidence, or person.
(AR 190-20) Also see physical search, search warrant, seizure.
Search Warrant. An express authorization to search and seize issued by competent civilian authority.
(AR 190-20) Also see search, seizure.
A search warrant is a court order authorizing law enforcement to search a specified location and
seize evidence. Under the Fourth Amendment, searches must be reasonable and specific.
The Fourth Amendment prohibits unreasonable searches and seizures (U.S. Constitution.
Amendment. IV). Searches and seizures are presumptively unreasonable, unless they are
conducted pursuant to a warrant issued by a neutral magistrate upon a sworn showing of probable
cause (Terry v. Ohio, 393 U.S. 1, 20, 1968).
Sector-Specific Agency. Federal departments and agencies identified in Homeland Security Presidential
Directive 7, “Critical Infrastructure Identification, Prioritization, and Protection,” 7 December 2003 as
responsible for CI/KR [critical infrastructure and/or key resource] protection activities in specified national
CI/KR sectors. (DoDD 3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/
chg 2 dated 21 Sep 2012)
-- Also, a Federal department or agency designated by PPD-21 with responsibility for providing
institutional knowledge and specialized expertise as well as leading, facilitating, or supporting the security
and resilience programs and associated activities of its designated critical infrastructure sector in the all-
hazards environment. (PPD-21, 2013)
PDD 21 identifies 16 critical infrastructure sectors and designates associated Federal SSAs.
For the critical infrastructure sector “Defense Industrial Base” the Department of Defense is the
designated SSA by PDD 21.
Secret, Security classification that shall be applied to information, the unauthorized disclosure of which
reasonably could be expected to cause serious damage to the national security that the original
classification authority is able to identify or describe. (EO 13526) Also see security classification.
SECRET Internet Protocol Router Network (SIPRNet). The worldwide SECRET-level packet switch
network that uses high-speed internet protocol routers and high-capacity Defense Information Systems
Network circuitry. (JP 1-02 and JP 6-0, Joint Communications, 10 Jun 2010)
Secret Writing (SW). Invisible writing. (FBI FCI Terms)
-- Also, any tradecraft technique employing invisible messages hidden in or on innocuous materials.
This includes invisible inks and microdots, among many other variations. (CI Centre Glossary)
281
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, tradecraft term that describes the act of using special inks or special carbons papers
(impregnated with chemicals) to write messages clandestinely. The utilization of special inks is known
as the “wet system.” The utilization of special carbon papers is known as the “dry system.” (Encyclopedia
of the CIA, 2003]
The simplest secret writing uses organic inks: milk, vinegar, lemon juice, even urine. These inks
dry invisibly and can be developed by applying heat. Espionage agencies have produced many
inks made of chemicals that could be developed only by a specific chemical.
-- Spy Book
_____________________
The chief difficulty with secret inks was their inability to handle great volume of information that
spies had to transmit in a modern war.
-- David Kahn, The Codebreakers (1967)
_____________________
The techniques of secret writing are the same the world over. First the spy writes his cover letter.
Then he writes the secret message on top, using a special sheet of carbon paper treated with a
colorless chemical. Tiny particles of the chemical; are transferred to the letter, which can then be
developed by the recipient. Most developing agents make the chemical traces grow, so that the
message becomes legible, and unless the correct agent is known, the message remains
undetectable.
-- Peter Wright, Spy Catcher (1987), p.119
_____________________
For an explanation of secret inks, see Robert Wallace and H. Keith Melton, Spycraft: The Secret
History of the CIA’s Spytechs from Communism to Al-Qaeda (2008), pp. 427-437.
Section 603 Referral. Section 603 of the "Intelligence Authorization Act for FY 1990" states: “Subject to
the authority of the Attorney General, the FBI shall supervise the conduct of all investigations of violations
of the espionage laws of the United States by persons employed by or assigned to United States
diplomatic missions abroad. All departments and agencies shall report immediately to the FBI any
information concerning such a violation. All departments and agencies shall provide appropriate
assistance to the FBI in the conduct of such investigations. Nothing in this provision shall be construed
as establishing a defense to any criminal, civil, or administrative action." (Public Law 101-193, 30 Nov
1989) Also see Section 811 Referral.
Section 811 Referral. Section 811 of the Intelligence Authorization Act of 1995 (50 USC 402a) is the
legislative act that governs the coordination of counterespionage investigations between Executive
Branch agencies and departments and the FBI. Section 811 referrals are the reports - made by the
Executive Branch agencies or departments to the FBI under Section 811(c)(1)(a) - that advise the FBI
of any information, regardless of origin, which may indicate that classified information is being, or may
have been, disclosed in an unauthorized manner to a foreign power or agent of a foreign power.
(CI Community Lexicon)
Section 811 was enacted in response to the damage to US national security caused by the Aldrich
Ames espionage case. The Ames case led to a legislative call for agencies to share data in
counterespionage investigations and for the FBI to be involved earlier in the process of evaluating
information concerning the possible compromise of classified information.
Within DoD, all 811 Referrals are considered “significant CI activities” and as such must also be
reported to DIA Office of Counterintelligence - Counterespionage Division (OCI-2)
_________________________
282
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
"811" referrals… allow our operational counterintelligence sections to concentrate solely on
detecting and countering foreign intelligence operations, focus on emerging strategic threats,
and protecting United States secrets from compromise.
-- Robert S. Muller, III, Director FBI
Before the Senate Committee on the Judiciary (6 June 2002)
Security. Proactive measures adopted to safeguard personnel, information, operations, resources,
technologies, facilities, and foreign relations against harm, loss, or hostile acts and influences. (DoDD
5200.43, Management of the Defense Security Enterprise, 1 Oct 2012 w/ chg 1 dated 24 Apr 2013)
Also see operational security (OPSEC); security disciplines; security profession, security professional.
DoD Policy
Security is a mission critical function of the DoD and its proper execution has a direct impact on all
DoD missions and capabilities and on the national defense.
Security is the personal responsibility of all DoD personnel….
-- DoD 5200.43, Management of the Defense Security Enterprise, 1 Oct 2012
-- Also, 1) Measures taken by a military unit, activity, or installation to protect itself against all acts
designed to, or which may, impair its effectiveness.
2) A condition that results from the establishment
and maintenance of protective measures that ensure a state of inviolability from hostile acts or influences.
3) With respect to classified matter, the condition that prevents unauthorized persons from having access
to official information that is safeguarded in the interests of national security. (JP 1-02; JP 2-0, Joint
Intelligence, 22 Oct 2013; and JP 3-10, Joint Security Operations in Theater, 3 Feb 2010)
-- Also, the protection of information to assure it is not accidentally or intentionally disclosed to
unauthorized personnel. (DSS Glossary)
Security is not counterintelligence - counterintelligence is not security.
“People like to confuse counterintelligence (CI) with security. In practice, the two are related
but not identical.”
-- William R. Johnson, Thwarting Enemies at Home and Abroad (2009)
________________________
“…[C]ounterintelligence measures deal directly with foreign intelligence service activities, while
security programs are indirect defensive actions that minimize vulnerabilities.”
-- SSCI Report 99-522 (1986)
________________________
“Counterintelligence investigates the enemy, or if you will in the modern world, the opposition, to
learn their capabilities, intentions, methods and focus. It is not security work. Security protects.
It does not attack. [Emphasis added] CI attacks the actor. It attacks the opposition intelligence
structures. It is not speculative. CI feeds security because it helps them focus on meaningful
measures and safeguards. Using CI to help security is just smart security.”
-- Robert P Hanssen (Soviet Spy, Former FBI Agent and current Federal inmate) as quoted in
“Diary of a Spy” by Paul M. Rodriquez, Insight on the News, 16 July 2001.
_______________________
Security vs. Counterespionage -- “[T]he security effort seeks primarily to protect its assigned
material against compromise, deliberate or accidental, while the counter-espionage effort
operates actively to identify, thwart. mislead, and destroy an opposing espionage capability.”
-- George P. Morse, America Twice Betrayed: Reversing Fifty Years of Government
Security Failure (1995), p. 50
_______________________
283
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
“Counterintelligence… is often confused with security—that is, merely with protecting secrets
and protecting against subversion. Yet whereas the objective of security is to cut and prevent
all contacts between hostiles and those who are to be protected the objective of CI is to engage
hostile intelligence, control what it knows, and if possible control what it does. In principle, neither
security people nor CI people deny the validity of the others approach, but CI people think of
security as flatfooted cops, and the latter think of the former as game-playing spooks.”
-- Angelo Codevilla, Informing Statecraft: Intelligence for a New Century (1992), p. 26
_______________________
“Security is a dimension of clandestinity in espionage, counterespionage, counterintelligence,
adultery, and poker. It is to these activities what style is to a writer, an athlete, or a musician,
but it is not itself a work, a game, or a performance. Its purpose is prophylactic: it excludes
toxic and infectious organisms and conserves vital fluids.”
-- William R. Johnson, “Clandestinity and Current Intelligence.” Studies in Intelligence, vol 20, no. 3,
(Fall 1976), pp. 15-69. Originally classified “Secret / No Foreign Dissem” [declassified].
_______________________
“CI and security shall be regarded as interdependent and mutually supportive disciplines with
shared objectives and responsibilities associated with the protection of secrets and assets.”
“Security programs establish appropriate personnel, physical, information, operations, industrial
and technical security, safeguards, and countermeasures to protect information and information
systems, personnel, operations, resources, technologies, and facilities from threats.”
-- ICD 700, Protection of National Intelligence, 7 Jun 2012
UNCLASSIFIED
the degree of protection against
danger, damage, loss, and crime.
PERSONNEL
PHYSICAL
SECURITY
SECURITY
INDUSTRIAL
OPERATIONS
SECURITY
EO 12968
DoD 5200.08-R
SECURITY
DoD 5200.2-R
DoDI 5200.08
EO 12829
DoDD 5205.02
DoD 5220.22-R
DoD 5220.2-M
NISPOM
COMMUNICATION
INFORMATION
SECURITY
SECURITY
DoDI 8523.01
EO 13526
DoDI 5200.01
DoD Manual 5200.1
Volumes 1-4
Security Programs are the indirect defensive
actions that minimize vulnerability
-- Senate Select Committee on Intelligence Report 99-522 (1986)
85
9 June 2012
“Security is a vital element of the operational effectiveness of the national security activities of the
government and of military combat readiness.”
-- President Ronald Reagan, NSDD-145, 17 Sep 1984
________________________
284
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
General functions and responsibilities performed by security professionals, including
communications security, counterintelligence awareness, security systems, international programs,
operations security, research and technology protection, sensitive compartmented information
security, special access program security, and security program policy.
-- DoDI 3305.13, DoD Security Education, Training, and Certification, 13 Feb 2014
________________________
Security--Four Basic Principles
According to the Joint Security Commission, security is a dynamic and flexible system guided by
four basic principles:
1) Security policies and services must be realistically matched to the threats we face. The
processes we use to formulate policies and deliver services must be sufficiently flexible to facilitate
their evolution as the threat changes.
2) Security policies and practices must be consistent and coherent across the Defense and
Intelligence Communities, thereby reducing inefficiencies and enabling us to allocate scare
resources efficiently.
3) Security standards and procedures must result in the fair and equitable treatment of the
members of our communities upon whom we rely to guard the nation’s security.
4) Security policies, practices, and procedures must provide the security we need at a price we can
afford.
-- Joint Security Commission, Redefining Security: A Report to the Secretary of Defense and
the Director Central Intelligence, 28 Feb 1994, p. 3
____________________
Security is a highly decentralized government function. […] Effectively addressing security
generates costs that must be balanced against risk and threats. Security, as a discipline, has
historically been dominated by “police” type management, processes, and enforcement
approaches. Although the police function is still required, today’s security vulnerabilities are
increasingly technical in nature and related to information technology systems, software, and
hardware.
-- WMD Report (31 March 2005), p. 545
Security Classification. A category to which national security information and material is assigned to
denote the degree of damage that unauthorized disclosure would cause to national defense or foreign
relations of the United States and to denote the degree of protection required. (JP 1-02)
There are three categories of security classification:
1) Top Secret--National security information or material that requires the highest degree of
protection and the unauthorized disclosure of which could reasonably be expected to cause
exceptionally grave damage to the national security. Examples of "exceptionally grave damage"
include armed hostilities against the United States or its allies; disruption of foreign relations vitally
affecting the national security; the compromise of vital national defense plans or complex
cryptologic and communications intelligence systems; the revelation of sensitive intelligence
operations; and the disclosure of scientific or technological developments vital to national security.
2) Secret--National security information or material that requires a substantial degree of protection
and the unauthorized disclosure of which could reasonably be expected to cause serious damage
to the national security. Examples of "serious damage" include disruption of foreign relations
significantly affecting the national security; significant impairment of a program or policy directly
related to the national security; revelation of significant military plans or intelligence operations;
and compromise of significant scientific or technological developments relating to national security.
3) Confidential--National security information or material that requires protection and the
unauthorized disclosure of which could reasonably be expected to cause damage to the national
security.
For additional information see website at:
285
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Security Classification Guide (SCG). A documentary form of classification guidance issued by an OCA
[original classification authority] that identifies the elements of information regarding a specific subject
that must be classified and establishes the level and duration of classification for each such element.
(DoD Manual 5200.01-Vol 1, DoD Information Security Program, 24 Feb 2012)
Security Clearance. An administrative determination by competent authority that an individual is eligible,
from a security stand-point, for access to classified information. (JP 1-02)
Within DoD, a security clearance is a determination that a person is eligible under DoD policy for
access to classified information. Clearances allow personnel to access classified information
categorized into three levels: top secret, secret, and confidential. The damage to national defense
and foreign relations that unauthorized disclosure could reasonably be expected to cause ranges
from “exceptionally grave damage” for top secret information to “damage” for confidential
information.
___________________
The security clearance process is designed to determine the trustworthiness of an individual prior to
granting him or her access to classified national security information. The process has evolved
since the early 1950s, with antecedents dating to World War II.
A security clearance is a determination that an individual—whether a direct federal employee or a
private contractor performing work for the government—is eligible for access to classified national
security information.
A security clearance alone does not grant an individual access to specific classified materials.
Rather, a security clearance means that an individual is eligible for access. In order to gain access
to specific classified materials, an individual should also have a demonstrated “need to know” the
classified information for his or her position and policy area responsibilities. In addition, prior to
accessing classified information, an individual must sign an appropriate nondisclosure agreement.
-- CRS Report R43216, Security Clearance Process: Answers to Frequently Asked Questions, 9 Sep 2013 *
Security Clearance Investigation. An inquiry into an individual's loyalty, character, trustworthiness and
reliability to ensure that he or she is eligible for access to national security information. (ONCIX,
<http://www.ncix.gov/SEA/reform/secvssuit.php >; accessed 18 Sep 2012) Also see suitability
investigation.
The Director of National Intelligence shall serve as the Security Executive Agent. As the Security
Executive Agent the Director of National Intelligence shall direct the oversight of investigations and
determinations of eligibility for access to classified information or eligibility to hold a sensitive
position made by any agency; shall be responsible for developing uniform and consistent policies
and procedures to ensure the effective, efficient, and timely completion of investigations and
adjudications relating to determinations of eligibility for access to classified information or eligibility
to hold a sensitive position."
- EO 13467, Reforming Processes Related to Suitability for Government Employment, Fitness for
Contractor Employees, and Eligibility for Access to Classified National Security Information, 2 Jul 2008
Security Compromise. The disclosure of classified information to persons not authorized access thereto.
(DSS Glossary)
Security Countermeasures (SCM). Actions, devices, procedures, and/or techniques to reduce security
risks. (IC Standard 700-1, 4 Apr 2008)
-- Also, those protective activities required to prevent espionage, sabotage, theft, or unauthorized
use of classified or controlled information, systems, or material of the Department of Defense. (JP 1-02;
and in previous edition JP 2-01.2, dated 13 Jun 2006)
Security Detainee. Those detainees who are not combatants, but who may be under investigation or
pose a threat to US forces if released. (Army FM 2-22.3, HUMINT Collector Operations, Sep 2006)
286
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Security Disciplines. Core functions and responsibilities performed by security professionals with a
concentration in personnel, physical, information, and industrial security. (DoDI 3305.13, DoD Security
Education, Training, and Certification, 13 Feb 2014) Also see security; security professional.
Security Environment Threat List. A list of countries with United States Diplomatic Missions that is
compiled by the Department of State and updated semi-annually. The listed countries are evaluated
based on: transnational terrorism; political violence; human intelligence; technical threats; and criminal
threats [and rated via] four threat levels: Critical, High, Medium and Low. (DSS Glossary)
Four Threat Levels:
Critical - defined as a definite threat to United States assets based on adversary’s capability,
intent to attack, and targeting conducted on a recurring basis;
High - defined as a credible threat to United States assets based on knowledge of an adversary’s
capability, intent to attack, and related incidents at similar facilities;
Medium - defined as a potential threat to United States assets based on knowledge of an
adversary’s desire to compromise the assets and the possibility that the adversary could obtain
the capability to attack through a third party who has demonstrated such a capability; and
Low - defined as little as no threat as a result of the absence of credible evidence of capability,
intent, or history of actual or planned attack against United States assets.
Security Executive Agent (SecEA). The Director of National Intelligence shall serve as the Security
Executive Agent. (EO 13467, 30 Jun 2008)
For additional information see Security Executive Agent Directive 1 “Security Executive Agent
Authorities and Responsibilities,” 13 Mar 2012.
Security Incident. A security compromise, infraction, or violation. (DSS Glossary)
Security In-Depth. A concept of security calling for layered and complementary controls sufficient to
detect and deter infiltration and exploitation of an organization, its information systems and facilities.
(IC Standard 700-1, 4 Apr 2008)
-- Also, a combination of layered and complementary security controls sufficient to deter, detect, and
document unauthorized entry and movement within the installation and/or facility and the ability to delay
and respond with force. Examples include the use of perimeter fences, employee and visitor entry and/or
exit controls, sensors and intrusion detection systems, closed circuit video monitoring, security patrols
during working and non-working hours, or other safeguards that mitigate vulnerabilities. (DTM 09-012,
8 Dec 2009, w/ chg 2 dated 9 Sep 2012)
-- Also, an array of security measures which, considered as a whole, provide a level of security
greater that that by any one measure individually. Includes identification checks, perimeter fences, police
patrols, motion detectors, and other security measures. (DoD Manual S-5240.09, OFCO Procedures and
Security Classification Guide, 13 Jan 2011 w/ change 1 dated 16 Oct 2012)
Security Infraction. A security incident that is not in the best interest of security and does not involve the
loss, compromise, or suspected compromise of classified information. (DSS Glossary)
Security Measures: [Actions] taken by the government and intelligence departments and agencies,
among others, for protection from espionage, observation, sabotage, annoyance, or surprise. With
respect to classified materials, it is the condition which prevents unauthorized persons from having
access to official information which is safeguarded in the interests of national defense. (Senate Report
94-755, Book I - Glossary, 26 Apr 1976)
287
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Security Profession. An occupation dedicated to the protection of people, facilities, information,
operations, and activities. (DoDI 3305.13, DoD Security Education, Training, and Certification, 13 Feb
2014) Also see security; security disciplines; security professional.
Security Professional. An individual who is educated, trained, and experienced in one or more security
disciplines and provides advice and expertise to senior officials on the effective and efficient
implementation, operation, and administration of the organization’s security programs. (DoDI 3305.13,
DoD Security Education, Training, and Certification, 13 Feb 2014) Also see security; security profession.
Security Service. Entity or component of a foreign government charged with responsibility for
counterespionage or internal security functions. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint
Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011; and CI Community Lexicon)
Sedition. Willfully advocating or teaching the duty or necessity of overthrowing the US government or any
political subdivision by force or violence. (JP 1-02; also in previous edition JP 2-01.2, dated 13 Jun 2006)
Sedition and criminal subversion of military forces are violations of Title 18 USC, §§ 2384-2390 and
is a punishable offense under UCMJ Article 94. It is a term of law which refers to overt conduct that
is deemed by the legal authority as tending toward insurrection against the established order. It is
the crime of creating a revolt, disturbance, or violence against lawful civil authority with the intent to
cause its overthrow or destruction. Sedition often includes subversion of a constitution and
incitement of discontent (or resistance) to lawful authority. A seditionist is one who engages in or
promotes the interests of sedition.
The difference between sedition and treason consists primarily in the subjective ultimate object of
the violation to the public peace. Sedition does not consist of levying war against a government nor
of adhering to its enemies, giving enemies aid, and giving enemies comfort. Nor does it consist, in
most representative democracies, of peaceful protest against a government, nor of attempting to
change the government by democratic means (such as direct democracy or constitutional
convention).
Sedition is the stirring up of rebellion against the government in power. Treason is the violation of
allegiance to one's sovereign or state, giving aid to enemies, or levying war against one's state.
Sedition is encouraging one's fellow citizens to rebel against their state, whereas treason is actually
betraying one's country by aiding and abetting another state.
Seizure. The taking or dispossession of property from the possessor by an authorized person or
the restriction of the freedom of movement of an individual against his or her will by an agent of the
Government. (AR 190-20) Also see search.
Self-radicalization. Significant steps an individual takes in advocating or adopting an extremist belief
system for the purpose of facilitating ideologically-based violence to advance political, religious, or social
change. The self-radicalized individual has not been recruited by and has no direct, personal influence or
tasking from other violent extremists. The self-radicalized individual may seek out direct or indirect
(through the Internet for example) contact with other violent extremists for moral support and to enhance
his or her extremist beliefs. (DoDD 5240.06, CIAR, 17 May 2011 with change 1 dated 30 May 2013) Also
see radicalization; violent radicalization.
-- Also, the process whereby people seek out opportunities for involvement in terrorist activity absent
a formal involvement in a terrorist group and/or recruitment by others. (DSB Report, Predicting Violent
Behavior, Aug 2012, citing Horgan’s The Psychology of Terrorism 2nd Edition, 2012)
-- Also, self radicalization: a phenomenon in which individuals become terrorists without joining an
established radical group, although they may be influenced by its ideology and message. (DSB Report,
Predicting Violent Behavior, Aug 2012)
288
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Senate Select Committee on Intelligence (SSCI). Created pursuant to Senate Res. 400, 94th Congress:
to oversee and make continuing studies of the intelligence activities and programs of the United States
Government, and to submit to the Senate appropriate proposals for legislation and report to the Senate
concerning such intelligence activities and programs. Provides legislative oversight over US intelligence
activities to assure that such activities are in conformity with the Constitution and laws of the United
The 1980 Intelligence Oversight Act charged the SSCI and the House Permanent Select
Committee on Intelligence (HPSCI) with authorizing the programs of US intelligence agencies
and overseeing their activities.
It is IC policy that IC elements shall, in a timely manner, keep the Congressional intelligence
committees fully informed, in writing, of all significant anticipated intelligence activities, significant
intelligence failures, significant intelligence activities, and illegal activities.
-- ICD 112, Congressional Notification, 16 Nov 2011
See an interested article entitled “Congressional Oversight of Intelligence: One Perspective,” by
Mary Sturtevant, Senate Committee Staff, in American Intelligence Journal, Summer 1992; copy
available on line at:
Senior Defense Official / Defense Attaché (SDO/DATT). Principal DoD official in a U.S. embassy, as
designated by the Secretary of Defense. (DoDD 5105.75, DoD Operations at Defense Embassies,
21 Dec 2007) Also see Defense Attaché Office.
The SDO/DATT is the Chief of Mission’s (COM’s) principal military advisor on defense and national
security issues, the senior diplomatically accredited DoD military officer assigned to a US
diplomatic mission, and the single point of contact for all DoD matters involving the embassy or
DoD elements assigned to or working from the embassy.
All DoD elements assigned or attached to or operating from U.S. embassies are aligned under the
coordinating authority of the SDO/DATT. See DoD Directive 5105.75, DoD Operations at U.S.
Embassies.
Sensitive. Requiring special protection from disclosure that could cause embarrassment, compromise, or
threat to the security of the sponsoring power. May be applied to an agency, installation, person, position,
document, material, or activity. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military
Operations, 5 Jan 2012)
Sensitive Activities [within DoD]. Operations, actions, activities, or programs that are generally handled
through special access, compartmented, or other sensitive control mechanisms because of the nature of
the target, the area of operation, or other designated aspects. Sensitive activities also include operations,
actions, activities, or programs conducted by any DoD Component that, if compromised, could have
enduring adverse effects on U.S. foreign policy, DoD activities, or military operations; or cause significant
embarrassment to the United States, its allies, or the DoD. (DoDI O-5100.94, Oversight, Coordination,
Assessment, and Reporting of DoD Intelligence and Intelligence-Related Sensitive Activities, 27 Sep
2011 w/ change 1 dated 15 Oct 2013)
Sensitive Compartmented Information (SCI). All information and materials bearing special community
controls indicating restricted handling within present and future community intelligence collection
programs and their end products for which community systems of compartmentation have been or will be
formally established. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations,
5 Jan 2012)
-- Also, classified information concerning or derived from intelligence sources, methods, or analytical
processes requiring handling exclusively within formal access control systems established by the DNI.
(National Intelligence: A Consumer’s Guide - 2009).
289
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, classified national intelligence information concerning or derived from intelligence sources,
methods, or analytical processes that is required to be handled within formal access control systems
established by the DNI. (DoDI 5200.01, DoD Information Security Program and Protection of Sensitive
Compartmented Information, 9 Oct 2008 w/ chg 1)
Sensitive Compartmented Information Facility (SCIF). An accredited area, room, group of rooms, or
installation where sensitive compartmented information (SCI) may be stored, used, discussed, and/or
electronically processed. SCIF procedural and physical measures prevent the free access of persons
unless they have been formally indoctrinated for the particular SCI authorized for use or storage within
the SCIF. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan
2012)
-- Also, a subset of CNI [Classified National Intelligence] concerning or derived from intelligence
sources, methods or analytical processes that is required to be protected within formal access control
systems established by the DNI [Director of National Intelligence]. (ICD 703, Protection of Classified
National Intelligence, Including Sensitive Compartmented Information, 21 Jun 2013)
-- Also, an accredited area where Sensitive Compartmented Information may be stored, used,
discussed, and/or processed. Only those Intelligence Community Agencies with SCIF Accreditation
Authority may officially accredit facilities to handle, process, and store SCI materials. (National
Intelligence: A Consumer’s Guide - 2009).
For additional information on SCIFs see Physical and Technical Security Standards for Sensitive
Compartmented Information Facilities, IC Standard Number 705-1, 17 Sep 2010, and Standards
for the Accreditation and Reciprocal Use of Sensitive Compartmented Information, IC Standard
Number 705-2, 17 Sep 2010.
Sensitive Information. Information that the loss, misuse, unauthorized access, or modification could
adversely affect the national interest, the conduct of Federal programs, or the privacy to which individuals
are entitled under section 552a of Title 5, United States Code, but that has not been specifically
authorized under criteria established by an Executive order or an Act of Congress to be kept secret in
the interest of National defense or foreign policy. (DoD 5205.02-M, DoD OPSEC Program Manual, 3 Nov
2008)
Sensitive Site. A geographically limited area that contains, but is not limited to, adversary information
systems, war crimes sites, critical government facilities, and areas suspected of containing high value
targets. (JP 1-02 and JP 3-31, Command and Control for Joint Land Operations, 29 Jun 2010)
-- Also, a designated, geographically limited area with special diplomatic, informational, military, and
economic sensitivity for the United States. This includes factories with technical data on enemy weapon
systems, war crimes sites, critical hostile government facilities, areas suspected of containing persons of
high rank in a hostile government or organization, terrorist money-laundering areas, and document
storage areas for secret police forces. (Army FM 2-0, Intelligence, 23 Mar 2010)
Sensitive Site Exploitation (SSE). Within DoD, term rescinded. See site exploitation.
This term was previously defined in JP 1-02 as: a related series of activities inside a captured
sensitive site to exploit personnel documents, electronic data, and material captured at the site,
while neutralizing any threat posed by the site or its contents.
Note: Army Tactics, Techniques and Procedures (ATTP) 3-90.15 [FM 3-90.15] (8 Jul 2010) also
rescinded “sensitive site exploitation” as a doctrinal term.
Sensitive Sources and Methods. A collective term for those persons, organizations, things, conditions,
or events that provide intelligence information and those means used in the collection, processing, and
production of such information which, if compromised, would be vulnerable to counteraction that could
reasonably be expected to reduce their ability to support US intelligence activities. (ICS Glossary)
290
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Sensemaking. A set of philosophical assumptions, substantive propositions, methodological framings,
and methods. (Sensemaking: A Structure for an Intelligence Revolution by David T. Moore) Also see
sensemaking. Also see intelligence sensemaking.
Sensemaking goes beyond analysis, a disaggregative process, and also beyond synthesis, which
meaningfully integrates factors relevant to an issue. It includes an interpretation of the results of
that analysis and synthesis. It is sometimes referred to as an approach to creating situational
awareness “in situations of uncertainty.”
Copy of Sensemaking: A Structure for an Intelligence Revolution by David T. Moore available at
Serials. Individual items of evidence in a counterintelligence case are known as serials. They may not
necessarily reach a standard required for a criminal prosecution but the objective is not necessarily to
achieve a public trial and conviction, but to develop an investigation to the point where some advantage
can be achieved. While serials may include entirely circumstantial evidence, unsubstantiated allegations,
and coincidence, until verified or dismissed through inquiry and research, they remain valid and may stay
in a dossier for decades. (Historical Dictionary of Cold War Counterintelligence, 2007)
Shape. The ability to conduct activities to affect the perceptions, will, behavior, and capabilities of
partner, competitor, or adversary leaders, military forces, and relevant populations to further U.S. national
security or shared global security interests. (Joint Capability Areas Taxonomy & Lexicon, 15 Jan 2008)
Shielded Enclosure. Room or container designed to attenuate electromagnetic radiation, acoustic
signals, or emanations. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Short-Range Agent Communication (SRAC). A device that allows agent and [case] officer to
communicate clandestinely over a limited distance. (Spycraft)
Signal. A prearranged visual or audio sign that a dead drop has been filled or emptied or that an
emergency meeting is needed. (FBI FCI Terms) Also see signals.
-- Also, prearranged visual or audio indicator having a designated significance for intelligence
personnel involved. For example, to signify that a dead drop has been filled or emptied or to call an
emergency or unscheduled personal meeting. (AFOSI Manual 71-142, OFCO, 9 June 2000)
Signal Flags. The IC [Intelligence Community] database containing information used to assist security
and counterintelligence professionals conducting National Agency Checks on individuals applying for
positions with IC organizations. (IC Standard 700-1, 4 Apr 2008)
Signal Security (SIGSEC). A generic term that includes both communications security and electronics
security. (JP 1-02) Also see security.
Signal Site. A prearranged fixed location, usually in a public place, on which an agent or intelligence
officer can place a predetermined mark in order to alert the other to operational activity. Such a mark may
be made by, for example, chalk or a piece of tape. (FBI -- Affidavit: USA vs. Robert Philip Hanssen,
16 Feb 2001)
The operational activity signaled may be the fact that a dead drop has been "loaded" and is ready
to be "cleared." A call-out signal may be used to trigger a contact between an agent and an
intelligence officer.
- FBI: Affidavit USA vs. Robert Philip Hanssen, 16 Feb 2001)
-- Also, a covert means of communications using a nonalerting signal, such as a chalk mark on a
lamppost, to either initiate or terminate a clandestine act, (Spycraft) Also see signals.
291
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Signals. Any form of clandestine tradecraft using a system of marks, signs, or codes for signaling
between operatives. (CI Centre Glossary) Also see signal site.
Signals Intelligence (SIGINT). 1) A category of intelligence comprising either individually or in combination
all communications intelligence [COMINT], electronic intelligence [ELINT], and foreign instrumentation
signals intelligence [FISINT], however transmitted.
2) Intelligence derived from communications,
electronic, and foreign instrumentation signals. (JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013)
For DoD policy see DoDI O-3115.07, Signals Intelligence (SIGINT), 15 Sep 2008
-- Also, intelligence gathered from data transmissions [signals intercepts], including Communications
Intelligence (COMINT), Electronic Intelligence (ELINT), and Foreign Instrumentation Signals Intelligence
(FISINT). SIGINT includes both raw data [collection] and the analysis of that data to produce intelligence.
(ODNI, U.S. National Intelligence - An Overview 2011)
-- Also, information derived from intercepted communications and electronic and data transmissions.
(WMD Report, 31 Mar 2005)
The collection of signals intelligence is necessary for the United States to advance its national
security and foreign policy interests and to protect its citizens and the citizens of its allies and
partners from harm.
-- PDD-28 Signals Intelligence Activities, 17 Jan 2014
_______________________
The Intelligence Community refers to the collection and exploitation of signals transmitted from
communication systems, radars, and weapon systems as signals intelligence or SIGINT. SIGINT
consists of Communications Intelligence (COMINT) - technical and intelligence information derived
from intercept of foreign communications; Electronic Intelligence (ELINT) - information collected
from systems such as radars and other weapons systems; and Foreign Instrumentation Signals
Intelligence (FISINT) - signals detected from weapons under testing and development.
SIGINT is collected in a variety of ways depending on the type of signal targeted. The National
Security Agency (NSA) collects the raw SIGINT and then NSA translators, cryptologists, analysts,
and other technical experts turn the raw data into something that an all-source analyst can use.
Once the NSA has collected, processed, and analyzed SIGINT, it is passed on to CIA and
Intelligence Community analysts who use it to complement information from other sources to
produce finished intelligence.
The volume and variety of today’s signals adds challenges to the timely production of finished
intelligence for policymakers. It is a lot of work to track and analyze all the SIGINT collected.
-- www.cia.gov (accessed, 30 Nov 2010)
______________________
Signals Intelligence (SIGINT): The interception of signals, whether between people, between
machines, or a combination of both. The National Security Agency (NSA) is responsible for
collecting, processing, and reporting SIGINT. Within the NSA, the National SIGINT Committee
advises the Director, NSA, and the Director of National Intelligence (DNI) on policy issues and
manages the SIGINT requirements system.
-- www.intelligence.gov (accessed 13 Aug 2012)
______________________
Signals Intelligence (SIGINT)… comprises Communications Intelligence (COMINT) and Electronic
Intelligence (ELINT) , and activities pertaining thereto….
-- NSCID 6, Signals Intelligence, 17 Feb 1972 (redacted copy, complete original version is TOP SECRET)
Available at:
Signature. A recognizable, distinguishing pattern. See also attack signature or digital signature. (CNSSI
No. 4009, National Information Assurance Glossary, 26 April 2010)
292
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Signatures. [In CI usage,] indicators of potential FISS and ITO [international terrorist organizations]
methods of operations, including static surveillance of U.S. forces [and] installations…. (Army FM 2-22.2,
CI, Oct 2009)
Sign-of-Life Signal. A signal emitted periodically to signify that an agent is safe. (FBI FCI Terms)
Silver Triangle. The South American region consisting of Peru, Bolivia, and Colombia that is historically
known to be a major illegal drug production area. (JP 3-07.4, Joint Counterdrug Operations, 13 Jun 2007)
Single Scope Background Investigation (SSBI). Investigation for individuals requiring a top secret
clearance or working in a critical sensitive position; normally covers a 5-year period and consists of a
subject interview, NAC, credit checks, character references, and employment records checks and
references.
-- Also, a personnel security investigation consisting of all the elements prescribed in Standard B of
ICPG 704.1. The period of investigation for a SSBI varies, ranging from the immediate preceding 3 years
for neighborhood checks to immediately preceding 10 years for local agency checks. (IC Standard 700-1,
4 Apr 2008)
Singleton. Intelligence operations conducted by a single intelligence officer or agent. These operations
include intelligence collection, servicing agents, and courier services. (Spy Book)
Site Exploitation. A series of activities to recognize, collect, process, preserve, and analyze information,
personnel, and/or materiel found during the conduct of operations. (JP 1-02 and JP 3-31, Command and
Control for Joint Land Operations, 29 Jun 2010)
-- Also, systematically searching for and collecting information, material, and persons from a
designated location and analyzing them to answer information requirements, facilitate subsequent
operations, or support criminal prosecution. (Army Tactics, Techniques & Procedures 3-90.15 [FM
3-90.15], Site Exploitation Operations, 8 Jul 2010)
Situation Report (SITREP). A report giving the situation in the area of a reporting unit or formation.
(JP 1-02 and JP 3-50, Personnel Recovery)
Situational Awareness. Immediate knowledge of the conditions of the operation, constrained
geographically and in time. (Army FM 3-0, Operations, Feb 2008)
Slammer. Project Slammer was an Intelligence Community sponsored study of espionage to determine
the motivation of the convicted spies and to learn the methods by which they committed their crimes.
In 1985 U.S. intelligence agencies embarked on a 10-year benchmark study named Project
Slammer, which was focused on interviewing incarcerated spies. It examined “espionage by
interviewing and psychologically assessing actual espionage subjects Additionally, persons
knowledgeable of subjects were contacted to better understand the subjects' private lives and how
they are perceived by others while conducting espionage.” Project Slammer sought to understand
of the dynamics of espionage and to incorporate of that enhanced understanding into government
and industry security programs.
Project Slammer research endeavor consisted of voluntary interviews with incarcerated spies and
subsequent analysis of the data. The effort was essentially de-funded in the early nineties and
consequently lost impetus. Nevertheless, there are currently extant several Slammer papers and
tapes which are used throughout the security community. Those analyses deal with the essential
and multi-faceted motivational patterns underlying espionage.
Although dated, the study's findings remain significant, and the conclusions included: No offender
entered a position of trust with the intent to betray; and there were two prevalent sets of personality
traits:
1) highly manipulative, dominant, and self-serving; and 2) passive, easily influenced, and
lacking self-esteem.
293
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Sleeper. [Tradecraft jargon] an illegal; or agent in a foreign country who does not engage in intelligence
activities until told to do so. (FBI FCI Terms)
-- Also, a spy placed in a target area but does not engage in espionage until he or she is activated at
a future time. (Spy Book)
-- Also, an illegal or agent residing in a foreign country under orders to engage in no intelligence
activities. The inactive status, which can endure for a considerable time, serves to strengthen the legend
and permit access by a foreign power to an individual in position to be ready for action under certain
circumstances should a specific need arise. (Word of Intelligence, 2nd Edition, 2011)
SMADS. See Strategic Mission Assurance Data System.
Social Engineering, An attempt to trick someone into revealing information (e.g., a password) that can be
used to attack an enterprise. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
-- Also, the art of gaining access to buildings, systems or data by exploiting human psychology, rather
than by breaking in or using technical hacking techniques. (The Ultimate Guide to Social Engineering,
undated)
Copy of “The Ultimate Guide to Social Engineering” available on line at:
Social Networking. Web-based services that allow individuals to create a public profile, to create a list of
users with whom to share connection, and view and cross the connections within the system. (Wikipedia)
Most social network services are web-based and provide means for users to interact over the
Internet, such as e-mail and instant messaging. Social network sites are varied and they
incorporate new information and communication tools such as, mobile connectivity,
photo/video/sharing and blogging. Social networking sites allow users to share ideas, pictures,
posts, activities, events, and interests with people in their network.
The main types of social networking services are those that contain category places (such as
former school year or classmates), means to connect with friends (usually with self-description
pages), and a recommendation system linked to trust. Popular methods now combine many of
these, with American-based services such as Facebook, Google+, YouTube, LinkedIn, Instagram,
Pinterest, Tumblr and Twitter widely used worldwide; Nexopia in Canada; Badoo, Bebo, VKontakte
(Russia), Delphi (also called Delphi Forums), Draugiem.lv (mostly in Latvia), Hi5 (Europe), Hyves
(mostly in The Netherlands), iWiW (mostly in Hungary), Nasza-Klasa, Soup (mostly in Poland),
Glocals in Switzerland, Skyrock, The Sphere, StudiVZ (mostly in Germany), Tagged, Tuenti (mostly
in Spain), and XING in parts of Europe; Hi5 and Orkut in South America and Central America; Mxit
in Africa; and Cyworld, Mixi, Orkut, renren, weibo and Wretch in Asia and the Pacific Islands.
Social networking services are increasingly being used in legal and criminal investigations.
Information posted on sites such as MySpace and Facebook has been used by police (forensic
profiling), probation, and university officials to prosecute users of said sites. In some situations,
content posted on MySpace has been used in court
-- Wikipedia at <http://en.wikipedia.org/wiki/Social_networking> (accessed 11 Mar 2014)
_________________________
See “Social Media: Establishing Criteria for Law Enforcement Use” by Robert D. Stuart, M.S., in
FBI, Law Enforcement Bulletin, Feb 2013. Article available at: <http://www.fbi.gov/stats-
services/publications/law-enforcement-bulletin/2013/february/social-media-establishing-criteria-for-
law-enforcement-use>
294
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
“Under Investigation: Social Media Use by Law Enforcement”
Socio-Cultural Dynamics. Information about the social, cultural, and behavioral factors characterizing the
relationships and activities of the population of a specific region or operational environment. (DoDD
3600.01, Information Operations, 14 Aug 2006 with Chg 1, 23 May 2011)
Sociocultural Analysis (SCA). The analysis of adversaries and other relevant actors that integrates
concepts, knowledge, and understanding of societies, populations, and other groups of people, including
their activities, relationships, and perspectives across time and space at varying scales. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
Sociocultural Factors. The social, cultural, and behavioral factors characterizing the relationships and
activities of the population of a specific region or operational environment. (JP 1-02 and JP 2-01.3, Joint
Intelligence Preparation of the Operational Environment)
Software Assurance. The level of confidence that software functions as intended and is free of
vulnerabilities, either intentionally or unintentionally designed or inserted as part of the software
throughout the lifecycle. (DoDI 5200.44, Protection of Mission Critical Functions to Achieve Trusted
Systems and Networks, 5 Nov 2012)
Source. A person, thing, or activity from whom information or services are obtained. (DoDD S-3325.09,
Oversight, Management, and Execution of Defense Clandestine Source Operations, 9 Jan 2013, with chg
1 dated 13 Jun 2013) Also see agent; asset, controlled source; human source; HUMINT source.
-- Also, 1) A person, thing, or activity from which information is obtained; 2) In clandestine activities,
a person (agent), normally a foreign national, in the employ of an intelligence activity for intelligence
purposes; or 3) In interrogation activities, any person who furnishes information, either with or without the
knowledge that the information is being used for intelligence purposes. In this context, a controlled source
is in the employment or under the control of the intelligence activity and knows that the information is to
be used for intelligence purposes. An uncontrolled source is a voluntary contributor of information and
may or may not know that the information is to be used for intelligence purposes. (JP 1-02 and JP 2-01.2,
CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
295
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a person from whom information or services are obtained. (DoDD S-5200.37, Management &
Execution of Defense HUMINT, 9 Feb 2009 w/ chg 2)
-- Also, a person, device, system, or activity from which services or information are obtained.
(Defense HUMINT Enterprise Manual 3301.02, Vol II Collection Operations, 23 Nov 2010)
-- Also, a person from whom information or services are obtained. (DoDD 3600.01, Information
Operations, 14 Aug 2006 with Chg 1, 23 May 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, a document, interview, or other means by which information has been obtained. From an
intelligence perspective, sources are individuals (or HUMINT) who collect or possess critical information
needed for intelligence analysis. (ODNI, U.S. National Intelligence - An Overview 2011)
Source Directed Requirement (SDR). A HUMINT collection requirement based upon the placement and
access of a source to collect and report on a specific person, place, thing, or event. (DHE-M 3301.001,
DIA HUMINT Manual, Vol I, 30 Jan 2009 w/ chg 2)
Source Management. The process of registering and monitoring the use of sources involved in
counterintelligence and human intelligence operations to protect the security of the operations and avoid
conflicts among operational elements. (JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg
1 dated 26 Aug 2011)
Source Registry. A source record/catalogue of leads and sources acquired by collectors and centralized
for management, coordination and deconfliction of source operations. (JP 1-02 and JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Source Validation. Vetting to determine if a source is who he/she claims to be, is free of external control,
is capable of behaving in a secure manner, and possesses placement and access consistent with
tasking. (HDI Lexicon, April 2008) Also see vetting and counterintelligence flags.
All DoD human sources are vetted in accordance with National HUMINT Manager Directive 001.08
(HUMINT Source Validation).
For DoD policy see DoDI S-3325.07, Guidance for the Conduct of DoD Human Source
Validation (U), 22 Jun 2009.
Special Access Program (SAP). A program established for a specific class of classified information that
imposes safeguarding and access requirements that exceed those normally required for information at
the same classification level. (DoDD 5205.07, SAP Policy, 1 Jul 2010)
-- Also, a program activity which has enhanced security measures and imposes safeguarding and
access requirements that exceed those normally required for information at the same level. Information to
be protected within the SAP is identified by an SCG [security classification guide]. (DoDI 5205.11,
Management, Administration, and Oversight of DoD Special Access Programs, 6 Feb 2013)
-- Also, a sensitive program, approved in writing by a head of agency with original top secret
classification authority, that imposes need-to-know and access controls beyond those normally provided
for access to confidential, secret, or top secret information. The level of controls is based on the criticality
of the program and the assessed hostile intelligence threat. The program may be an acquisition program,
an intelligence program, or an operations and support program. (JP 1-02 and JP 3-05.1, Joint Special
Operations Task Force Operations, 26 Apr 2007)
DoD SAPs are established and maintained only when absolutely necessary to protect the Nation’s
most sensitive capabilities; information; technologies; operations; and research, development, test
and evaluation; or when required by statute pursuant to DoDD 5205.07, SAP Policy, 1 Jul 2010.
_______________________
296
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Acknowledged - Unacknowledged - Waived
Acknowledged SAP: A SAP whose existence is acknowledged, affirmed, or made known to
others, but its specific details (technologies, materials, techniques, etc.,) are classified as specified
in the applicable SCG.
Unacknowledged SAP: A SAP having enhanced security measures ensuring the existence of
the program is not acknowledged, affirmed, or made known to any person not authorized for such
information.
Waived SAP: A SAP for which the Secretary of Defense has waived applicable reporting in
accordance with DoD Manual 5200.01 following a determination of adverse effect to national
security. An unacknowledged SAP that has more restrictive reporting and access controls than
other unacknowledged SAPs.
______________________
Interestingly, the Joint Security Commission noted in its 1994 report (Redefining Security) that --
“Special Access Programs are used to compensate for the fact that the classification
system is not trusted to protect information effectively and does not adequately enforce
the ‘need to know’ principle.”
Special Access Program Central Office (SAPCO). The office within a DoD Component or OSD PSA that,
when directed, executes, manages, administers, oversees, and maintains records on the SAPs for which
it has been assigned CA. Responsibilities may also include developing and implementing policies and
procedures for oversight, management, execution, administration, SAP security, IA for SAP IS, and
records management of SAPs under their cognizance, as directed. (DoDD 5205.07, Special Access
Program Policy, 1 Jul 2010)
The DoD SAPCO is the office charged by the Deputy Secretary of Defense with responsibility as
the designated proponent for developing and implementing policies and procedures for DoD SAP
execution, management, and administration.
_______________________
For special access programs pertaining to intelligence sources, methods, and activities (but not
including military operational, strategic, and tactical programs), these functions shall be exercised
by the Director of National Intelligence.
-- EO 13526, Classified National Security Information, 29 Dec 2009
Special Actions. Those functions that due to particular sensitivities, compartmentation, or caveats cannot
be conducted in normal staff channels and therefore require extraordinary processes and procedures and
may involve the use of sensitive capabilities. (JP 1-02 and JP 3-05.1, Joint Special Operations Task
Force Operations, 26 Apr 2007)
Special Activities. Activities conducted in support of national foreign policy objectives abroad which are
planned and executed so that the role of the U .S. Government is not apparent or acknowledged publicly,
and functions in support of such activities, but which are not intended to influence U .S. political
processes, public opinion, policies, or media and do not include diplomatic activities, the collection and
production of intelligence, or related support functions. (IC Standard 700-1, 4 Apr 2008) Also see covert
action.
-- Also, within DoD: None -- term rescinded by JP 3-05, Special Operations, 18 Apr 2011.
As previously defined, it was a term synonymous with “covert action“ -- see covert action.
Special Agent. Within DoD: None -- term rescinded by JP 2-01.2, CI & HUMINT in Joint Operations, 16
Mar 2011. See Counterintelligence Special Agent.
Previously defined in JP 1-02 as: a person, either United States military or civilian, who is a
specialist in military [law enforcement,] security or the collection of intelligence or
counterintelligence information.
297
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a United States military or civilian who is a specialist in military security or in the collection of
intelligence or counterintelligence information. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
Special Area Clearance. The required concurrence granted to DoD personnel by the Department of State
and the Office of the USD(P) for travel to certain overseas areas designated by the Department of State
as special areas. (DoDD 4500.54E, DoD Foreign Clearance Program, 28 Dec 2009)
Special Collection Service (SCS). [According to open source,*] a joint CIA-NSA signals intelligence
collection organization.
-- Also, elite, highly secret U.S. electronic intelligence group that conducts eavesdropping operations
in [foreign] countries. The service is controlled by the NSA… [also] CIA experts are often assigned. (Spy
Book)
* See Jeffrey T. Richelson, The US Intelligence Community, Sixth Edition, 2012, pp. 224-226
_______________________
“According to a former high-ranking intelligence official, SCS was formed in the late 1970s after
competition between the NSA's embassy-based eavesdroppers and the CIA's globe-trotting
bugging specialists from its Division D had become counterproductive. While sources differ on how
SCS works, some claim its agents never leave their secret embassy warrens where they perform
close-quarters electronic eavesdropping, while others say agents operate embassy-based
equipment in addition to performing riskier ‘black-bag’ jobs, or break-ins, for purposes of
bugging….”
-- Jason Vest & W. Madsen , “A Most Unusual Collection Agency,” The Village Voice, 24 Feb - 2 Mar 1999
Special Collection Techniques. Those lawful investigative techniques which are employed by a DoD
intelligence component under the rule of the least intrusive means, after a determination has been made
that the required information is not publicly available, available with the consent of the person or persons
concerned, or available from cooperative sources. (DIA Intelligence Law Handbook, Sep 1995) Also see
rule of the least intrusive means.
Special collection techniques -- also commonly referred to as “special investigative techniques”
within CI channels -- are addressed in DoD 5240.1-R, Procedures Governing the Activities of DoD
Intelligence Components that Affect United States Persons, 7 Dec 1982,
Procedures 5-10:
* Procedure 5 - Electronic Surveillance
* Procedure 6 - Concealed Monitoring
* Procedure 7 - Physical Searches
* Procedure 8 - Searches and Examination of Mail
* Procedure 9 - Physical Surveillance
* Procedure 10 - Undisclosed Participation in Organizations
Special Communication. See definition provided in DTM 08-019, Establishment of the DoD Special
Communication Enterprise Office (SCEO), 11 Jun 2008, marked FOUO.
Special Event. An international or domestic event, contest, activity, or meeting, which by its very nature,
or by specific statutory or regulatory authority, may warrant security, safety, and/or other logistical support
or assistance from the Department of Defense. (DODD 3025.18, Defense Support of Civil Authorities,
29 Dec 2010)
Special Event Management. Planning and conduct of public events or activities whose character may
them attractive targets for terrorist attack. (FBI Domestic Investigations and Operations Guide, 15 Oct
2011)
298
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Special Information Operations (SIO). Information operations that by their sensitive nature and due to
their potential effect or impact, security requirements, or risk to the national security of the United States,
require a special review and approval process. (JP 3-13, Information Operations, 13 Feb 2006) Also see
information operations.
Special Investigative Inquiry (SII). A supplemental personnel security investigation of limited scope
conducted to prove or disprove relevant allegations that have arisen concerning a person upon whom a
personnel security determination has been previously made and who, at the time of the allegation, holds
a security clearance or otherwise occupies a position that requires a personnel security determination.
(IC Standard 700-1, 4 Apr 2008)
Special Investigative Techniques. See Special Collection Techniques.
Special Limiting Criteria (SLC).
[Term used in document/media exploitation activities]. A narrowly-
defined set of criteria intended to restrict access to data that, if compromised, could imperil planned
operations, contain evidence of espionage or counterintelligence operations, identify sources and
methods, and[/or] contain illegal or inappropriate material. (National Media Exploitation Center)
Special Mission Unit (SMU). A generic term to represent a group of operations and support personnel
from designated organizations that is task-organized to perform highly classified activities. (JP 1-02 and
JP 3-05.1, Joint Special Operations Task Force Operations, 26 Apr 2007)
Special Operations (SO). Operations requiring unique modes of employment, tactical techniques,
equipment and training often conducted in hostile, denied, or politically sensitive environments and
characterized by one or more of the following: time sensitive, clandestine, low visibility, conducted with
and/or through indigenous forces, requiring regional expertise, and/or a high degree of risk. (JP 3-05,
Special Operations, 18 Apr 2011)
Special Operations Activities. Activities that include each of the following insofar as it relates to special
operations: direct action, strategic reconnaissance, unconventional warfare, foreign internal defense, civil
affairs, psychological operations, counterterrorism, humanitarian assistance, theater search and rescue,
and such other activities as may be specified by the president or the Secretary of Defense.
(DoDD S-3325.09, Oversight, Management, and Execution of Defense Clandestine Source Operations, 9
Jan 2013, with chg 1 dated 13 Jun 2013)
Special Reconnaissance (SR). Reconnaissance and surveillance actions conducted as a special
operation in hostile, denied, or politically sensitive environments to collect or verify information of strategic
or operational significance, employing military capabilities not normally found in conventional forces.
(JP 3-05, Special Operations, 18 Apr 2011)
Special Security Center. The Director of National Intelligence element responsible for developing,
coordinating, and overseeing Director of National Intelligence security policies and databases to support
Intelligence Community security elements. The Special Security Center interacts with other Intelligence
Community security organizations to ensure that Director of National Intelligence equities are considered
in the development of national level security policies and procedures. (DSS Security Glossary)
Specified Task. In the context of joint operation planning, a task that is specifically assigned an
organization by its higher headquarters. (JP 1-02 and JP 5-0, Joint Operation Planning, 11 Aug 2011)
Spoofing. [Tradecraft jargon] A ploy designed to deceive the observer into believing that an operation
has gone bad when, in fact, it has been put into another compartment. (Spy Dust)
-- Also, [cyber usage] deceiving computers or computer users by hiding or faking one’s identity. Email
spoofing utilizes a sham email address or simulates a genuine email address. IP spoofing hides or masks
social-networking-risks-1>)
299
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Spot. [In intelligence usage,] to locate and recruit people demonstrated access to intelligence targets.
(TOP SECRET: The Dictionary of Espionage and Intelligence, 2005)
-- Also, to identify for consideration potential sources as candidates for recruitment. (AFOSI Manual
71-142, OFCO, 9 Jun 2000)
Spot Report. A non-standard DoD HUMINT report (not an IR) used to report on actionable/perishable
HUMINT of a non-CRITIC nature. (DHE-M 3301.001, Vol I: Collection Requirement, Reporting, and
Evaluation Procedures, 30 Jan 2009, w/ chg 2 dated 1 Feb 2012)
-- Also, a concise narrative report of essential information covering events or conditions that may
have an immediate and significant effect on current planning and operations that is afforded the most
expeditious means of transmission consistent with requisite security. Also called SPOTREP. (Note: In
reconnaissance and surveillance usage, spot report is not to be used.) (JP 1-02 and JP 3-09.3, Close Air
Support)
For CRITIC reporting see Chapter Three - Specialized Intelligence Reporting, DHE-M 3301.001,
Vol I: Collection Requirement, Reporting, and Evaluation Procedures (U), 30 Jan 2009, w/ chg 2,
dated 1 Feb 2012.
Spotter. In intelligence, an agent or illegal assigned to locate and assess individuals in positions of value
to an intelligence service. (JP 1-02; JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1
dated 26 Aug 2011; and CI Community Lexicon) Also see spotter / assessor.
-- Also, an agent or illegal assigned to locate and assess individuals who might be of value to an
intelligence service. (FBI FCI Terms)
Spotter / Assessor. An asset assigned to locate and/or assess individuals of intelligence or operational
interest. (HDI Lexicon, April 2008) Also see spotter; spotter assessor operation.
Spotter / Assessor Operation. Those actions taken to identify persons who may be in contact with or
placed in contact with opposition intelligence and counterintelligence services, and to determine the
potential value of these persons as intelligence or counterintelligence sources.
(AR 381-47, OFCO,
17 Mar 2006)
Spy. A generic term that refers… to either a professional intelligence officer work works for an
intelligence service, or to a foreign source or asset who steals secrets on behalf of that intelligence
service. (James M. Olson, Fair Play: The Moral Dilemmas of Spying, 2006)
-- Also, a person employed by or in the service of a foreign government, either with or without pay, to
secure information considered vital to the waging of a shooting or economic war against another country.
(Committee on Un-American Activities, U. S. House of Representatives, April 1949)
[T]he spy is the greatest of soldiers. If he is the most detested
by the enemy, it is only because he is the most feared.
- King George V (1865-1936)
_____________________
A U.S, intelligence officer that handles clandestine human sources is normally referred to as a
“case officer (C/O)” or “operations officer (OO).” The people that case officers or OOs recruit as
penetrations of foreign governments and organizations are their “agents.” Agents have access to
important information and pass that information secretly to their case officers/OOs.
_____________________
An army without secret agents is exactly like a man without eyes or ears.
-- Chia Lin, Chinese Strategist of the late eighth century
_____________________
300
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
One spy in the right place is worth 20,000 men in the field.
-- Napoleon
_________________________
In the circumstances of espionage and betrayal,
one county’s heroic spy is another’s traitor.
-- Frederick P. Hitz, Former Inspector General of the CIA (1990 - 1998)
_________________________
“What do you think spies are: priests, saints, and martyrs?
They’re a squalid procession of vain fools, traitors too, yes;
pansies, sadists and drunkards, people who play
cowboys and Indians to brighten their rotten lives…”
-- Alec Leamas, the protagonist in LeCarre’s The Spy Who Came in From the Cold.
Spy Dust (also called METKA). Chemical marking compound developed by the KGB to keep tabs on the
activities of a target officer. The compound is made of nitrophenyl pentadien (NPPD) and luminol. (Spy
Dust)
Spying. Under Article 106, UCMJ, in time of war, the act of clandestinely or under false pretences,
collecting or attempting to collect, information with the intent to convey it to a hostile party.
(AR 381-20,
Army CI Program, 25 May 2010)
Like war, spying is dirty business. Shed of its alleged glory, a soldier’s job is to kill.
Peel away the claptrap of espionage and the spy’s job is to betray trust.
-- William Hood, Mole (1993)
________________________
Spying is a major weapon in the state’s exercise of power, according to Machiavelli.* In his “Art of
War.’ He provides amazingly modern and sophisticated instructions on how to prevent spying by
the enemy (counterintelligence), how to deceive the enemy (covert action), and how to learn its
intentions (espionage).
-- James M. Olson, Fair Play: The Moral Dilemmas of Spying (2006), p. 23
* Niccolo Machiavelli (1469-1527), Florentine statesman and patriot.
Spyware. Software that is secretly or surreptitiously installed into an information system to gather
information on individuals or organizations without their knowledge; a type of malicious code. (CNSSI
No. 4009, National Information Assurance Glossary, 26 April 2010)
-- Also, a wide range of unwanted programs that exploit infected computers for commercial gain.
They can deliver unsolicited pop-up advertisements, steal personal information (including financial
information such as credit card numbers), monitor web-browsing activity for marketing purposes, or
route HTTP requests to advertising sites. (McAfee.com; accessed 15 Nov 2010)
Stability Operations. An overarching term encompassing various military missions, tasks, and activities
conducted outside the United States in coordination with other instruments of national power to maintain
or reestablish a safe and secure environment, provide essential governmental services, emergency
infrastructure reconstruction, and humanitarian relief. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug
2011)
Staff Judge Advocate (SJA). A judge advocate so designated in the Army, Air Force, or Marine Corps,
and the principal legal advisor of a Navy, Coast Guard, or joint force command who is a judge advocate.
(JP 1-04, Legal Support to Military Operations, 17 Aug 2011)
Stake Out. Stationary surveillance of a person, site, or facility. (AFOSI Manual 71-142, OFCO, 9 Jun
2000)
301
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, stakeout: a surveillance point or location that has been employed (or laid out) with the benefit
of prior planning. Usually meant to be occupied for an extended period of time. (Words of Intelligence, 2nd
Edition, 2011)
Standard Operating Procedure (SOP). A set of instructions covering those features of operations which
lend themselves to a definite or standardized procedure without loss of effectiveness. The procedure is
applicable unless ordered otherwise. (JP 1-02 and JP 3-31,Command and Control for Joint Land
Operations, 29 June 2010)
Star-Burst Maneuver. A countersurveillance ploy in which more than one target car or target officer is
being followed and they suddenly go in different directions, forcing the surveillance team to make instant
choices about whom to follow. (CI Centre Glossary)
Statement Analysis (also called Scientific Content Analysis or SCAN and Investigative Discourse
Analysis). A technique for analyzing the words people use. Proponents claim this technique can be used
to detect concealed information, missing information, and whether the information that person has
provided is true or false. (Wikipedia, accessed 5 Mar 2014)
Station. A CIA operational center overseas… usually, but not always, located under cover in a U.S.
official installation. The senior officer in charge of a station is known as the chief of station, or COS.
(James M. Olson, Fair Play: The Moral Dilemmas of Spying, 2006)
Status of Forces Agreement (SOFA). An agreement that defines the legal position of a visiting military
force deployed in the territory of a friendly state. Agreements delineating the status of visiting military
forces may be bilateral or multilateral. Provisions pertaining to the status of visiting forces may be set forth
in a separate agreement, or they may form a part of a more comprehensive agreement. These provisions
describe how the authorities of a visiting force may control members of that force and the amenability of
the force or its members to the local law or to the authority of local officials. (JP 1-02 and JP 3-16,
Multinational Operations, 7 Mar 2007)
-- Also, an accord, either bilateral or multilateral, that defines the legal position of a visiting military
force deployed in the territory of a friendly state, usually delineating matters affecting the relationship
between the military force and the civilian authorities and population. (AR 381-20, Army CI Program,
25 May 2010)
Stay Behind [ aka sleeper]. Agent or agent organization established in a given country to be activated
in the event of hostile overrun or other circumstances under which normal access would be denied.
(JP 1-02)
Steganography. The art, science, and practice of communicating in a way that hides the existence of the
communication. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
-- Also, the process of hiding information by embedding messages within other, seemingly harmless
messages. The process works by replacing bits of useless or unused data in regular computer files (such
as graphics, sound, text) with bits of different, invisible information. This hidden information can be plain
text, cipher text, or even images. (US Army TRADOC DCSINT Handbook 1.02, 15 Aug 2007)
-- Also, the art and science of writing hidden messages in such a way that no one, apart from the
sender and intended recipient, suspects the existence of the message, a form of security through
obscurity. (Wikipedia; accessed 4 April 2011)
Steganography (from the Greek root “staganos,” meaning covered or secret), or stego, is the
technique of hiding data in a host file. […] Simply put, stego is hiding a covert message within
another file so that only the sender and receiver can access it.
-- Eric Cole, “Steganography: More than Meets the Eye, “ in Information Security, November 2006 (pp. 32-37)
___________________________
302
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Steganography is the process of secreting data in an image. Moscow Center uses steganographic
software that is not commercially available. The software package permits the SVR clandestinely
to insert encrypted data in images that are located on publicly-available websites without the data
being visible. The encrypted data can be removed from the image, and then decrypted, using
SVR-provided software. Similarly, SVR-provided software can also be used to encrypt data, and
then clandestinely to embed the data in images on publicly-available websites.
-- FBI Affidavit, 25 June 2010
__________________________
The advantage of steganography, over cryptography alone, is that messages do not attract
attention to themselves. Plainly visible encrypted messages—no matter how unbreakable—will
arouse suspicion, and may in themselves be incriminating in countries where encryption is illegal.
Therefore, whereas cryptography protects the contents of a message, steganography can be said
to protect both messages and communicating parties.
With the advent of digital media, steganography has come to include the hiding of digital
information within digital files. Media files are ideal for steganographic transmission because of
their large size. As a simple example, a sender might start with an innocuous image file and adjust
the color of every 100th pixel to correspond to a letter in the alphabet, a change so subtle that
someone not specifically looking for it is unlikely to notice it.
-- Wikipedia (accessed 4 April 2011)
__________________________
For additional information also see -- <http://www.steganographypro.com/> and
Sterilize. To remove from material to be used in covert and clandestine actions any marks or devices
which can identify it as originating with the sponsoring organization or nation. (Senate Report 94-755,
Book I - Glossary, 26 Apr 1976)
Strategic Communication. Focused United States Government efforts to understand and engage key
audiences to create, strengthen, or preserve conditions favorable for the advancement of United States
Government interests, policies, and objectives through the use of coordinated programs, plans, themes,
messages, and products synchronized with the actions of all instruments of national power. (JP 1-02)
Strategic Debriefing. Debriefing activity conducted to collect information or to verify previously collected
information in response to national or theater level collection priorities. (JP 2-01.2, CI & HUMINT in Joint
Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011; and Army FM 2-22.3, HUMINT Collector
Operations, 6 Sep 2006)
Sources for strategic debriefing operations include but are not limited to émigrés, refugees,
displaced persons, defectors, and selected U.S. personnel.
Strategic Intelligence. Intelligence required for the formation of policy and military plans at national and
international levels. Strategic intelligence and tactical intelligence differ primarily in level of application, but
may also vary in terms of scope and detail. (JP 1-02) Also see intelligence; operational intelligence;
tactical intelligence.
Sherman Kent defined strategic intelligence as “high-level foreign positive intelligence.”
Strategic Intelligence Interrogation. An intelligence interrogation of any person who is in the custody or
under the effective control of the DoD or under detention in a DoD facility, conducted at a theater-level
detention facility. (DoDD 3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and Tactical
Questioning, 11 Oct 2012 w/ chg 1 dated 15 Nov 2013) Also see intelligence interrogation.
303
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Strategic Level of War. The level of war at which a nation, often as a member of a group of nations,
determines national or multinational (alliance or coalition) strategic security objectives and guidance, and
then develops and uses national resources to achieve these objectives. (JP 1-02 and JP 3-0, Joint
Operations, 11 Aug 2011) Also see also operational level of war; tactical level of war.
Strategic Mission Assurance Data System (SMADS). A classified geospatially enabled Critical
Infrastructure database with the capability to analyze potential national, strategic, and operational impacts
resulting from the loss or disruption of Critical Infrastructure and Key Resources (CIKR).
Strongly recommended that all DoD CI personnel providing CI support to DCIP obtain an SMADS
account.
SMADS is a restricted database accessible on SIPRNet at: <https://smads.stratcom.smil.mil>
Access is only granted to end-users who have a valid user account (requires valid need-to-know).
Permissions are granted based upon a user’s mission and associated responsibilities.
SMADS is managed and maintained by the U.S Strategic Command (USTRATCOM) Mission
Assurance Division (MAD). It is the current Joint Staff program of record for Critical Infrastructure
and Key Resources (CIKR).
Refer to the SMADS User Manual which serves as a general reference for end-users; it provides a
step-by-step guide to performing web-enabled database tasks, while incorporating some DCIP
program information to help facilitate the completion of these tasks.
For other DCIP tools see web site at: <http://dcip.dtic.mil/DCIPtools.html>
Strategy. A prudent idea or set of ideas for employing the instruments of national power in a
synchronized and integrated fashion to achieve theater, national, and/or multinational objectives.
(JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
-- Military Strategy. The art and science of employing the armed forces of a nation to secure the
objectives of national policy by the application of force or the threat of force. (JP 1-02)
-- National Military Strategy. The art and science of distributing and applying military power to attain
national objectives in peace and war; also called NMS. (JP 1-02)
-- National Strategy. The art and science of developing and using the diplomatic, economic, and
informational powers of a nation, together with its armed forces, during peace and war to secure national
objectives; also called national security strategy or grand strategy. (JP 1-02)
Structured Analysis. A distinct form of intelligence analysis methodology that provides a step-by-step
process for analyzing the kinds of incomplete, ambiguous, and sometimes deceptive information that
analysts must deal with.
Structured analysis is a mechanism by which internal thought processes are externalized in a
systematic and transparent manner so that they can be shared, built on, and easily critiqued by
others. Structured analysis helps analysts ensure that their analytical framework—the foundation
upon which they form their analytical judgments—is as solid as possible.
For in-depth information on structured analysis see Richards J. Heuer, Jr. and Randolph H.
Pherson, Structured Analytical Techniques for Intelligence Analysis (Washington, DC; CQ Press,
2011).
Subject. Person, place, or thing observed or under investigation. (AFOSI Manual 71-142, OFCO, 9 Jun
2000) Also see suspect.
-- Also, a person about whom probable cause exists to believe that the person committed a particular
criminal offense. (AR 195-2, Criminal Investigation Activities, 15 May 2009)
304
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Subject Interview. Interview with the subject of an investigation; it may be non-custodial or custodial.
Interviews of subjects of CI investigations are conducted to afford subjects the opportunity to refute,
explain, clarify or mitigate allegations of espionage, terrorism, and other acts that may constitute
threats to national security.
-- AR 381-20, Army CI Program, 25 May 2010
Subversion. Actions designed to undermine the military, economic, psychological, or political strength or
morale of a governing authority. (JP 1-02 and JP 3-24, Counterinsurgency, 22 Nov 2013) Also see
subversive activity.
-- Also, actions designed to undermine the military, economic, political, psychological, or moral
strength of a nation or entity. It can also apply to an undermining of a person’s loyalty to a government or
entity. (Senate Report 95-755, Book I - Glossary, 26 Apr 1976)
-- Also, actively encouraging military or civilian personnel to violate laws, disobey lawful orders or
regulations, or disrupt military activities with the willful intent thereby to interfere with, or impair the loyalty,
morale, or discipline of the US military forces. Lending aid, comfort, and moral support to individuals,
groups, or organizations that advocate the overthrow of the U.S. Government. (AR 381-20, Army CI
Program, 25 May 2010)
-- Also, the crime of creating a revolt, disturbance, or violence against lawful civil authority with the
intent to cause its overthrow or destruction. (Dictionary.com)
Subversion refers to an attempt to overthrow structures of authority, including the state. It is an
overturning or uprooting. Subversive activity is the lending of aid, comfort, and moral support to
individuals, groups, or organizations that advocate the overthrow of incumbent governments by
force and violence. All willful acts that are intended to be detrimental to the best interests of the
government and that do not fall into the categories of treason, sedition, sabotage, or espionage
are placed in the category of subversive activity.
_____________________
In the context of DoD investigative policy, subversion refers only to such conduct as is forbidden
by the laws of the United States. Specifically, this is limited to information concerning the activities
of individuals or groups that involve or will involve the violation of Federal law, for the purpose of:
1) Overthrowing the Government of the United States or the government of a State; and
2) Substantially impairing for the purpose of influencing U.S. Government policies or decisions.
-- DoD 5200.2-R, Personnel Security Program, Jan 1987 (w. chg 3), p.22
Subversion of Department of Defense Personnel. Actions designed to undermine the loyalty, morale, or
discipline of DoD military and civilian personnel. (JP 1-02)
-- Also, [previously defined in DoDI 5240.06, 7 Aug 2004] an act or acts inciting military or civilian
personnel of the DoD to violate laws, disobey lawful orders or regulations, or disrupt military activities with
the willful intent thereby to interfere with, or impair the loyalty, morale, [or] discipline, of the Military Forces
of the United States.
Criminal subversion of military forces is a violation of Title 18 USC, §§ 2384-2390.
Subversive Activity. Anyone lending aid, comfort, and moral support to individuals, groups or
organizations that advocate the overthrow of incumbent governments by force and violence is subversive
and is engaged in subversive activity. All willful acts that are intended to be detrimental to the best
interests of the government and that do not fall into the categories of treason, sedition, sabotage, or
espionage will be placed in the category of subversive activity. (JP 1-02)
305
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Suitability Investigation. An inquiry into a person's identifiable character traits and conduct sufficient to
decide whether an individual's employment or continued employment would or would not protect the
integrity or promote the efficiency of the service. (ONCIX, http://www.ncix.gov/SEA/reform/secvssuit.php;
accessed 18 Sep 2012) Also see security clearance investigation.
"The Director of the Office of Personnel Management shall serve as the Suitability Executive Agent.
As the Suitability Executive Agent, the Director of the Office of Personnel Management will be
responsible for developing and implementing uniform and consistent policies and procedures to
ensure the effective, efficient, and timely completion of investigations and adjudications relating to
determinations of suitability and eligibility for logical and physical access."
-- EO 13467 (30 June 2008)
Superencryption. Process of encrypting encrypted information. Occurs when a message, encrypted off-
line, is transmitted over a secured, on-line circuit, or when information encrypted by the originator is
multiplexed onto a communications trunk, which is then bulk encrypted. (CNSSI No. 4009, National
Information Assurance Glossary, 26 April 2010)
Supply Chain. The linked activities associated with providing materiel from a raw materiel stage to an
end user as a finished product. (JP 1-02 and JP 4-09, Distribution Operations, 5 Feb 2010) Also see
adversarial supply chain operations, supply chain attack, supply chain risk, supply chain risk
management.
-- Also, the linked activities associated with providing materiel from a raw materiel stage to an end
user as a finished product or system. Including design, manufacturing, production, packaging, handling,
storage, transport, mission operation, maintenance, and disposal. (DoDI 4140.67, DoD Counterfeit
Prevention Policy, 26 Apr 2013)
-- Also, organizations, people, technology, information and associated resources involved in moving a
product or service from supplier to customer. (National Counterintelligence Strategy of the United States
of America, 2012)
-- Also, a system of organizations, people, activities, information, and resources, possibly international
in scope, that provides products or services to consumers. (CNSSI No. 4009, National Information
Assurance Glossary, 26 April 2010)
Supply Chain: 1) Starting with unprocessed raw materials and ending with the final customer using
the finished goods, the supply chain links many companies together; 2) the material and
informational interchanges in the logistical process stretching from acquisition of raw materials to
delivery of finished products to the end user. All vendors, service providers, and customers are
links in the supply chain.
-- CSCMP Glossary, Feb 2010, p. 179
See Supply Chain Management Terms and Glossary, Feb 2010. Available online at:
Supply Chain Attack. Attacks that allow the adversary to utilize implants or other vulnerabilities inserted
prior to installation in order to infiltrate data, or manipulate information technology hardware, software,
operating systems, peripherals (information technology products) or services at any point during the life
cycle. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Supply Chain Risk. The risk that an adversary may sabotage, maliciously introduce unwanted function,
or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, or
maintenance of an item of supply or a system so as to surveil, deny, disrupt, otherwise degrade the
function, use or operation of the item or system. (DoDI O-5240.24, CI Activities Supporting RDA, 8 Jun
2011 w/ chg 1 and DoDI 5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems
and Networks, 5 Nov 2012) Also see supply chain risk management; supply chain risk mitigation; supply
chain vulnerabilities.
306
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the risk that adversaries will insert malicious code into or otherwise subvert the design,
manufacturing, production, distribution, installation, or maintenance of ICT components that may be used
in DoD systems to gain unauthorized access to data, to alter data, to disrupt operations, or to interrupt
communications. (DTM 09-016, SCRM to Improve the Integrity of Components Used in DoD Systems, 25
Mar 2010 w/ chg 3 dated 23 Mar 2012)
The risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise
subvert the design, integrity, manufacturing, production, distribution, installation, operation, or
maintenance of an item of supply or a system so as to surveil, deny, disrupt, or otherwise degrade
the function, use, or operation of a system.”
-- The Ike Skelton National Defense Authorization Act for Fiscal Year 2011, (Section 806)
The increased dependence of the United States on global inputs in the manufacturing and service
sectors, especially relating to information technology, opens the door to greater supply-chain
vulnerabilities. As international companies and foreign individuals play a greater role in the
information-technology supply chain, the specter of persistent, stealthy subversion is raised—
particularly by foreign intelligence and military services, as well as international terrorists and
criminal groups.
________________________
Within DoD, see DoDI 52400.44 (Protection of Mission Critical Functions to Achieve Trusted
Systems and Networks, 5 Nov 2012) which establishes policy to minimize the risk that DoD’s
warfighting mission capability will be impaired due to vulnerabilities in system design or sabotage or
subversion of a system’s mission critical functions or critical components by foreign intelligence,
terrorists, or other hostile elements.
DoD computing systems, are a constant target of foreign exploitation. A 2007 Defense Science
Board report noted that the software industry has become increasingly and irrevocably global.
Much of the code is now written outside the United States, some in countries that may have
interests inimical to those of the United States. The combination of DoD’s profound and growing
dependence upon software and the expanding opportunity for adversaries to introduce malicious
code into this software has led to a growing risk to the Nation’s defense.
See report of the Defense Science Board Task Force on Mission Impact of Foreign Influence on
DoD Software, Sep 2007.
____________________________
“A computer chip with a hidden, malicious flaw could sabotage a weapons system. And the
compromised hardware is almost impossible to detect…. A chip might even be embedded with a
‘kill switch,’ allowing the weapon to be disabled by remote control.
…only about 2 percent of the
integrated circuits purchased every year by the military are manufactured in the United States.”
-- David Wise, Tiger Trap: America’s Secret Spy War with China (2011), p. 233
____________________________
"The Defense supply chain is at risk: More than two-thirds of electronics in U.S. advanced fighter
aircraft are fabricated in off-shore foundries."
-- Dr. Kaigham J. Gabriel, Acting Director DARPA, DoD
March 2012 - Testimony before the Senate Armed Services Committee hearing on Emerging Threats
and Capabilities
____________________________
“Interdependence of information technologies and integration of foreign technology in US
information technology, telecommunications, and energy sectors will increase the potential scope
and impact of foreign intelligence and security services’ supply chain operations. The likely
continued consolidation of infrastructure suppliers—which means that critical infrastructures and
networks will be built from a more limited set of provider and equipment options—will also increase
the scope and impact of potential supply chain subversions.”
-- James R. Clapper, DNI, Statement for the Record, Worldwide Threat Assessment of the US Intelligence
Community, Senate Committee on Armed Services, 18 April 2013
____________________________
307
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Counterfeit Electronic Parts in the DoD Supply Chain…
“In March 2001, the Senate Armed Services Committee initiated an investigation into counterfeit
electronic parts in the Department of Defense (DOD) supply chain. The investigation uncovered
overwhelming evidence of large numbers of counterfeit parts making their way into critical defense
systems. … The investigation… found overwhelming evidence that companies in China are the
primary source of counterfeit electronic parts in the defense supply chain.”
-- Armed Services U.S. Senate Report 112-167, 21 May 2012; copy of full report at:
Supply Chain Risk Management (SCRM). The management of supply chain risk whether presented by
the supplier, the supplied product and its sub-components, or the supply chain (e.g., packaging, handling,
storage, and transport). (DoDI O-5240.24, CI Activities Supporting RDA, 8 Jun 2011 with change 1 dated
15 Oct 2013) Also see adversarial supply chain operations, supply chain attack, supply chain risk;
supply chain risk mitigation; supply chain vulnerabilities.
-- Also, the systematic identification, assessment, and quantification of potential supply chain
disruptions with the objective to control exposure to risk or reduce its negative impact on supply chain
performance.(DoDI 4140.01, DoD Supply Chain Materiel Management Policy, 14 Dec 2011)
-- Also, a systematic process for managing supply chain risk by identifying susceptibilities,
vulnerabilities and threats throughout DoD’s “supply chain” and developing mitigation strategies to
combat those threats whether presented by the supplier, the supplied product and its subcomponents, or
the supply chain (e.g., initial production, packaging, handling, storage, transport, mission operation, and
disposal). (DoDI 5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems and
Networks, 5 Nov 2012)
-- Also, management of risk that an adversary may sabotage, malicious[ly] introduce unwanted
functions, or otherwise subvert the design, manufacturing, production, distribution, installation, or
maintenance of an item of supply or a system so as to surveil, deny, disrupt, otherwise degrade the
function, use or operation of the item or system. (DoD FCIP Strategy FY 2013-2017)
-- Also, [within the Intelligence Community] the management of risk to the integrity, trustworthiness,
and authenticity of products and services within the supply chain. It addresses the activities of foreign
intelligence entities and other adversarial attempts aimed at compromising the IC supply chain, which
may include the introduction of counterfeit or malicious items into the IC supply chain. (ICD 731, Supply
Chain Risk Management, 7 Dec 2013)
Supply chain risk management encompasses many disciplines and requires participation from
subject matter experts in acquisition, counterintelligence, information assurance, logistics, program
offices, analysis, security, and other relevant functions as necessary.
-- ICD 731, Supply Chain Risk Management, 7 Dec 2013
___________________
The President’s Comprehensive National Cybersecurity Initiative (CNCI) 11 directs the
implementation of SCRM in information and communications technology (ICT) acquisition.
___________________
Various SCRM References:
National Strategy for Global Supply Chain Security, White House, Jan 2012; copy available at
Committee on National Security Systems Directive (CNSSD) No. 505, Supply Chain Risk
Management (U), 7 Mar 2012; available at www.cnss.gov
For SCRM policy within the IC see Intelligence Community Directive (ICD) 701, Supply Chain Risk
Management, 7 Dec 2013.
“Supply Chain Risk Management Awareness” by J. Filsinger, B. Fast, D. Wolf, et al; copy available
308
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Supply Chain Risk Mitigation. A process to ensure software and hardware commodity items are not
compromised by malicious actions that disrupt or endanger military operations or provided an entry point
for gaining access or control of DoD systems. (DoD Strategy for Operating in Cyberspace, May 2011)
Also see supply chain risk; supply chain risk management; supply chain risk vulnerabilities.
Manage Supply Risk - Identify, assess, and prioritize efforts to manage risk by utilizing layered
defenses, and adapting our security posture according to the changing security and operational
environment.
-- White House, National Startegy for Global Supply Chain Security, Jan 2012, p.1
Supply Chain Vulnerabilities. An assessment of the supply chain related to CPI [critical program
information] to determine if an adversary has the capability and intent to affect it in a manner that
compromises the military effectiveness of the given platform, weapon system, or network. (DoDI 5200.39,
CPI within the DoD,16 Jul 2008 with change 1 dated 28 Dec 2010) Also see supply chain risk; supply
chain risk mitigation; supply chain risk management.
Supplier Assurance. Evidence demonstrating the level of confidence that a supplier is free from
vulnerabilities. (DoDI 5200.39, CPI within the DoD,16 Jul 2008 with change 1 dated 28 Dec 2010)
Support Agent. An agent recruited to do support work, such as finding and living in safehouses, serving
as a courier, or any of the other activities required to support a spy in place. In many cases, this support
agent is a local citizen of the country in which the CIA operates. (A Spy’s Journey)
Support Asset. An asset who acquires, maintains, and/or provides services. (HDI Lexicon, April 2008)
Supported Commander. 1) The commander having primary responsibility for all aspects of a task
assigned by the Joint Strategic Capabilities Plan or other joint operation planning authority.
2) In the
context of joint operation planning, the commander who prepares operation plans or operation orders in
response to requirements of the Chairman of the Joint Chiefs of Staff. 3) In the context of a support
command relationship, the commander who receives assistance from another commander's force or
capabilities, and who is responsible for ensuring that the supporting commander understands the
assistance required. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011) Also see support; supporting
commander.
Supporting Commander. 1) A commander who provides augmentation forces or other support to a
supported commander or who develops a supporting plan. Includes the designated combatant commands
and Defense agencies as appropriate. 2) In the context of a support command relationship, the
commander who aids, protects, complements, or sustains another commander's force, and who is
responsible for providing the assistance required by the supported commander. (JP 1-02 and JP 3-0,
Joint Operations, 11 Aug 2011) Also see support; supported commander.
Suspect Counterfeit. Materiel, items, or products in which there is an indication by visual inspection,
testing, or other information that it may meet the definition of counterfeit materiel provided herein.
(DoDI 4140.67, DoD Counterfeit Prevention Policy, 26 Apr 2013) Also see counterfeit material.
Surreptitious Entry. Entry by stealth. (Spycraft)
-- Also, unauthorized entry in a manner which leaves no readily discernible evidence. (DSS Glossary
and AR 381-14, Technical Counterintelligence, 30 Sep 2002)
-- Also, any entry into a guarded or locked area or container and a departure therefrom without
leaving a trace that such entry was made. (FM 30-17, Counterintelligence Operations, Jan 1972)
Surreptitious Entry Unit. Unit in OTS [CIA’s Office of Technical Service] whose specialty was opening
locks and gaining access to enemy installations for the purpose of supporting bugging operations. (Spy
Dust)
309
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Surveillance. The systematic observation of aerospace, surface, or subsurface areas, places, persons,
or things, by visual, aural, electronic, photographic, or other means. JP 1-02 and JP 3-0, Joint Operations,
11 Aug 2011) Also see counter surveillance, electronic surveillance, physical surveillance, surveillance
detection.
“Surveillance is a valuable investigative tool [emphasis added]….”
“Investigators always should assume that subjects engaged in operational, terrorist, or criminal
activity will attempt to detect surveillance by employing a variety of methods and techniques….
During surveillances, participants must remain vigilant and alert to the possibility of
countersurveillance techniques being employed against them.”
-- John T. Nason, “Conducting Surveillance Operations” in FBI Law Enforcement Bulletin, May 2004
-- Also, systematic observation of a target. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
-- Also, the continuous watching or listening (overtly or covertly) of people, vehicles, places, or objects
to obtain information concerning the activities and identities of individuals.
(Peter Jenkins, Surveillance
Tradecraft: The Professional’s Guide to Covert Surveillance Training, 2010)
-- Also, the tradecraft of undetected observation. Surveillance can be physical, electronic, or acoustic.
It may include audio or photographic observation and includes mail opening. (A Spy’s Journey)
-- Also, actively but unobtrusively observing a subject to gather information about their
activities and whereabouts. (Webster’s New World Law Dictionary, 2010)
-- Also [as used within DoD concerning force protection], monitoring the activity of DoD personnel,
facilities, processes, or systems including showing unusual interest in a facility, infrastructure, or
personnel (e.g., observations through binoculars, taking notes, drawing maps or diagrams of the facility,
and taking pictures or video of a facility, infrastructure, personnel, or the surrounding environment) under
circumstances that would cause a reasonable person to perceive a threat to DoD personnel, facilities, or
forces in transit. (DTM 08-007, DoD Force Protection Threat Information, 22 Jul 2008)
CI Surveillance
Operations
PHYSICAL
Static
Foot
Mobile
AERIAL
TECHNICAL
Surveillance Assets
Supporting CI Investigations & Operations
UNCLASSIFIED
118
310
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Surveillance, by definition, is intrusion into the affairs of other people.
-- William R. Johnson, Thwarting Enemies at Home and Abroad (2009)
The word surveillance comes from the French surveiller, to watch over. The term is often used
for all forms of observation or monitoring, not just visual observation.
In order to be effective, surveillance must go unnoticed and be undetected.
__________________
Surveillance can be used from a static point, on foot, from vehicle or by using technical devices.
In most cases a combination of all four are used, with targets even often taking public transport
and even attempting to detect or avoid surveillance.
-- Peter Jenkins in an introduction to Surveillance Tradecraft (2010)
__________________
Surveillance, physical: term for the universal tradecraft of undetected observation conducted by
humans versus technical means.
Surveillance, technical: generic term for surveillance using various forms of visual, auditory and
electronic aids in covering a designated target.
Surveillance, close: tradecraft jargon term for surveillance maintained where the prevention of
loss of the subject is paramount.
Surveillance, discreet: tradecraft jargon term for surveillance maintained on a “loose” basis, the
prevention of detection being paramount, even to the loss of the subject being tailed. Generally,
the guiding rule is to discontinue surveillance rather than risk actions which make the subject
aware of the surveillance.
Surveillance, fixed: tradecraft jargon term for a stationary or static surveillance. Also stakeout,
tradecraft jargon for the static surveillance of a given target.
Surveillance, foot: tradecraft jargon term for, as the words imply, a surveillance conducted on foot.
Surveillance, mobile: tradecraft jargon term for surveillance conducted with the use of various
mobile platforms, e.g., vehicles, aircraft, boats, etc.
-- Adapted from The CIA’s Insider’s Dictionary by Leo D. Carl (1996)
______________________
Surveillance… must be executed with maximum care lest its target become aware of it.
-- Allen W. Dulles, The Craft of Intelligence (2006), p. 124
Surveillance Detection. Measures taken to detect and/or verify whether an individual, vehicle, or location
is under surveillance. (DoDI S-5240.15, FPRG, 20 Oct 2010 with change 1 dated 16 Oct 2013) Also see
counter surveillance, surveillance.
-- Measures taken to determine if an individual is under surveillance. (HDI Lexicon, April 2008)
-- Also, self-initiated actions taken by a target/subject to identify surveillance. Conducted by taking
advantage of screen and flow, couple with detailed route selection, and noting possible surveillance
against time and distance relationships. (CI Community Lexicon)
Surveillance Detection Route (SDR). A carefully crafted route, of varying lengths and complexity
depending on the operational environment, used by a case officer and/or agent to get to a meeting site,
and after leaving the meeting site, [to] determine that the case officer and agent are not under
surveillance before going to and after the ops meeting. (National HUMINT Glossary)
-- Also, a preplanned route used to determine if an individual is under surveillance. (HDI Lexicon,
April 2008)
311
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a planned route taken by an agent or handler prior to conducting a clandestine act…
designed to identify or elude surveillance. (Spycraft)
-- Also, surveillance detection run; a route designed to erode or flush out surveillance without alerting
them to an operative's purpose. (CI Centre Glossary)
Professional case officers of all services, conduct lengthy SDRs before engaging in operational
acts. A good SDR gives a case officer the opportunity to flush out surveillance if it is there and to
make a determination of his or her surveillance status. The CIA jargon for completing an SDR
and verifying without any doubt that surveillance is not there is “getting black.”
-- James M. Olson, Fair Play: The Moral Dilemmas of Spying (2006)
________________________________
Case officers posted to Moscow station underwent rigorous training in “denied area tradecraft”…
The primary discipline was the surveillance detection route (SDR). Case officers moved about on
long and circuitous routes planned in advance while searching for KGB “tails.” If they detected
surveillance, they aborted their missions. If no surveillance was detected, they would “go black”
for brief periods and perform operational acts.
-- Benjamin B. Fischer, “Spy Dust and Ghost Surveillance: How the KGB Spooked the CIA and Hid
Aldrich Ames in Plain Sight,” International Journal of Intelligence and Counterintelligence, Vol 24
No 2 (Summer 2011), p. 275
________________________________
See a brief discussion of “Surveillance Detection Runs” in an excellent article by Barry G. Royden,
CIA, entitled “Tolkachev, A Worthy Successor to Penkovsky: An Exceptional Espionage Operation”
originally classified SECRET and published in CIA’s Studies In Intelligence, Vol. 41, No. 4. 1997.
Later declassified and published in Studies In Intelligence, Vol 47, No. 3, 2003, Unclassified
Edition; available at:
publications/csi-studies/studies/vol47no3/article02.html>
Surveillance Device. A piece of equipment or mechanism used to gain unauthorized access to and
removal of information. (DoDI 5240.05, TSCM, 3 Apr 2014)
Suspect. A person about whom some credible information exists to believe that the person committed a
particular criminal offense. (AR 195-2, Criminal Investigation Activities, 15 May 2009) Also see subject.
Susceptibility. The inherent capacity of an asset to be affected by one or more threats or Hazards.
(DoDI 3020.45, DCIP Management, 21 Apr 2008)
Suspension of Access. The temporary withdrawal of a person's eligibility for access to classified
information. Access is suspended when information becomes known that casts doubt on whether
continued access is consistent with national security interests. (AR 380-67, Personnel Security Program,
24 Jan 2014)
Suspicious Activity. Observed behavior reasonably indicative of pre-operational planning related to
terrorism or other criminal activity. (ISE-FS-200 v1.5 cited in DoDI 2000.26, SAR, 1 Nov 2011) See
suspicious activity report (SAR).
Suspicious Activity Report (SAR). Official documentation of behavior that may be indicative of
preoperational planning related to terrorism or criminal intentions. (DoDI 2000.12, DoD AT Program, 1
Mar 2013, w/ change 1 dated 9 Sep 2013)
-- Also, official documentation of observed behavior reasonably indicative of pre-operational planning
related to terrorism or other criminal activity. (ISE-FS-200 v1.5 cited in DoDI 2000.26, SAR, 1 Nov 2011)
See suspicious activity.
eGuardian -- the FBI’s law enforcement-centric threat reporting system -- rapidly disseminates
SARs dealing with information regarding a potential threat or suspicious activity throughout the
national law enforcement community to include DoD.
312
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
For DoD policy see DoDI 2000.26, Suspicious Activity Reporting, 1 Nov 2011.
Access to the eGuardian system is via Law Enforcement Online (LEO). Only DoD law
enforcement personnel or analysts within DoD law enforcement organizations will enter SARs
into the eGuardian system.
Categories of Suspicious Activity (see encl 4, DoDI 2000.26): Acquisition of Expertise; Breach or
Attempted Intrusion; Eliciting Information; Expressed or Implied Threat; Flyover or Landing,
Materials Acquisition or Storage; Misrepresentation; Recruiting; Sabotage, Tampering, or
Vandalism; Surveillance; Testing of Security; Theft, Loss, or Diversion; Weapons Discovery; and
Unexplained Absences of International Military Students.
Information Sharing Environment (ISE) Functional Standard (FS) Suspicious Activity Reporting
Version 1.5 (ISE-FS-200 v1.5) available on line at: <http://www.ise.gov/sites/default/files/ISE-FS-
200_ISE-SAR_Functional_Standard_V1_5_Issued_2009.pdf>
Suspicious Contact. Efforts by any individual, regardless of nationality, to obtain illegal or unauthorized
access to classified information or to compromise a cleared employee, all contacts by cleared employees
with known or suspected intelligence officers from any country, or any contact which suggests the
employee concerned may be the target of an attempted exploitation by the intelligence services of
another country. (DSS Glossary)
Swallow. A female operative who uses sex as a tool. (Spy Dust)
The swallow’s mission is to engage in sexual activity with the targeted person and gather the
intelligence either through pillow talk or blackmail. In order to be able to blackmail the targeted
person into disclosing secrets, the sexual activity usually takes place in a prearranged room or
residence equipped with hidden cameras and recording devices.
-- Encyclopedia of the Central Intelligence Agency (2003)
_____________________
A male operative who uses sex as a tool is referred to as a “Raven.”
For additional open source information see David Lewis, Sexpionage: The Exploitation of Sex
by Soviet Intelligence (1976).
Sweep. [Jargon] To electronically and/or physically examine a room or area in order to detect any
clandestine devices; a search for “bugs,” i.e., concealed electronic listening devices at a specific location.
(Words of Intelligence, 2nd Edition, 2011)
Synchronization. 1) The arrangement of military actions in time, space, and purpose to produce maximum
relative combat power at a decisive place and time. 2) In the intelligence context, application of
intelligence sources and methods in concert with the operation plan to ensure intelligence requirements
are answered in time to influence the decisions they support. (JP 1-02 and JP 2-0, Joint Intelligence,
22 Oct 2013)
Synthesis. In intelligence usage, the examining and combining of processed information with other
information and intelligence for final interpretation. (JP 2-0, Joint Intelligence, 22 Oct 2013)
Systems Administrator (SA). Individual responsible for the installation and maintenance of an information
system, providing effective information system utilization, adequate security parameters, and sound
implementation of established Information Assurance policy and procedures. (CNSSI No. 4009, National
Information Assurance Glossary, 26 April 2010)
System Assurance. The justified measures of confidence that the system functions as intended and is
free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the
system at any time during the life cycle. (DoDI 5200.39, CPI Protection within DoD, 16 Jul 2008 with
change 1 dated 28 Dec 2010)
313
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
T ==========================================
Tactical Control (TACON). Command authority over assigned or attached forces or commands, or military
capability or forces made available for tasking, that is limited to the detailed direction and control of
movements or maneuvers within the operational area necessary to accomplish missions or tasks
assigned. TACON is inherent in operational control. TACON may be delegated to, and exercised at any
level at or below the level of combatant command. When forces are transferred between combatant
commands, the command relationship the gaining commander will exercise (and the losing commander
will relinquish) over these forces must be specified by the Secretary of Defense. TACON provides
sufficient authority for controlling and directing the application of force or tactical use of combat support
assets within the assigned mission or task. (JP 1, 25 Mar 2013 and JP 1-02) Also see combatant
command; combatant command (command authority); operational control.
Tactical Intelligence. Intelligence required for planning and conducting tactical operations. (JP 1-02 and
JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Tactical Intelligence and Related Activities (TIARA). Those activities outside the National Foreign
Intelligence Program that accomplish the following: 1) respond to operational commanders' tasking for
time-sensitive information on foreign entities; 2) respond to national intelligence community tasking of
systems whose primary mission is support to operating forces; 3) train personnel for intelligence duties;
4) provide an intelligence reserve; or 5) are devoted to research and development of intelligence or
related capabilities. Specifically excluded are programs that are so closely integrated with a weapon
system that their primary function is to provide immediate-use targeting data. (Previously in JP 1-02)
Tactical Level of War. The level of war at which battles and engagements are planned and executed to
achieve military objectives assigned to tactical units or task forces.
(JP 1-02 and JP 3-0, Joint
Operations, 11 Aug 2011) Also see operational level of war; strategic level of war.
Tactical Questioning (TQ). The field-expedient initial questioning for information of immediate tactical
value of a captured or detained person at or near the point of capture and before the individual is placed
in a detention facility. Tactical questioning is generally performed by members of patrols, but can be done
by any appropriately trained DoD personnel. Tactical questioning is limited to direct questioning. (DoDD
3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and Tactical Questioning, 11 Oct 2012 w/
chg 1 dated 15 Nov 2013)
For DoD policy see DoDD 3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and
Tactical Questioning, 11 Oct 2012
-- Also, direct questioning by any Department of Defense personnel of a captured or detained person
to obtain time-sensitive tactical intelligence, at or near the point of capture or detention and consistent
with applicable law. (JP 1-02 and JP 3-63, Detainee Operations, 30 May 2008)
-- Also, expedient initial questioning for information of immediate tactical value. (Army FM 2-22.3,
Human Intelligence Collector Operations, Sep 2006)
Tag. Something that is attached to the item to be located and/or tracked, which increases its ability to be
detected or its probability of identification by a surveillance system suitably tuned to the tag. (Defense
Science Board 2004 Summer Study, Transition to and from Hostilities, Dec 2004)
Tags can be either active (such as radio-emitting tags) or passive (such as radio frequency
identification [RFID] tags). Passive tags can also be chemical (such as infrared fluorescent) or
biological in nature.
314
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Task. A clearly defined action or activity specifically assigned to an individual or organization that must
be done as it is imposed by an appropriate authority. (JP 1, 25 Mar 2013)
Task Critical Asset. An asset that is of such extraordinary importance that its incapacitation or destruction
would have a serious, debilitating effect on the ability of one or more DoD Components or DISLA
organizations to execute the task or mission-essential task it supports. Task critical assets are used to
identify defense critical assets. (DoDD 3020.40, DoD Policy and Responsibilities for Critical Infrastructure,
14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
Target. 1) An entity or object considered for possible engagement or other action; 2) in intelligence
usage, a country, area, installation, agency, or person against which intelligence operations are
directed… [emphasis added] (JP 1-02 and JP 3-60)
-- Also, an individual, organization, or intelligence service against which intelligence operations are
conducted. Also refers to documents or instruments which an intelligence service is trying to obtain, or the
subject of a surveillance. (FBI FCI Terms)
Target Audience (TA). An individual or group selected for influence. (JP 1-02 and JP 3-13, Information
Operations, 13 Feb 2006)
Target Folder. A folder, hardcopy or electronic, containing target intelligence and related materials
prepared for planning and executing action against a specific target. (JP 1-02 and JP 3-60, Joint
Targeting, 13 Apr 2007)
Target Intelligence. Intelligence that portrays and locates the components of a target or target complex
and indicates its vulnerability and relative importance. (JP 3-60, Joint Targeting, 13 Apr 2007)
Targeted Violence: Pre-conceived violence focused on individuals, groups, or locations where
perpetrators are engaged in behaviors that precede and are related to their attacks. These perpetrators
consider, plan and prepare before engaging in acts of violence and are often detectable, providing an
opportunity for disruption of the intended violence. (DSB Report, Predicting Violent Behavior, Aug 2012)
“There is no panacea for stopping all targeted violence.”
-- DSB Report, Predicting Violent Behavior, August 2012
Copy of Defense Science Board Report (DSB), Predicting Violent Behavior, Aug 2012 available at:
Targeting. The process of selecting and prioritizing targets and matching the appropriate response to
them, considering operational requirements and capabilities. (JP 3-0, Joint Operations, 11 Aug 2011)
-- Also, the act of focusing on a country, organization, non-state actor, installation, system, or person
to identify an operational or intelligence goal. (National HUMINT Glossary)
-- Also, the process of selecting targets and matching the appropriate response to them, including
operational requirements and capabilities. The purpose of targeting is to disrupt, delay, or limit threat
interference with friendly COAs [courses of actions]. (FM 2-22.2, Counterintelligence, Oct 2009)
CI support to the targeting process include the development of CI targets list to identify those FISS
and ITO persons, organizations, facilities, or installations that must be exploited through raid and
capture to gain additional intelligence or neutralization to disable or destroy, negate, mitigate, or
degrade the adversary’s ability to collect on U.S. forces.
-- FM 2.22-2, Counterintelligence, October 2009, p. 5-7
______________________
315
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
See JP 3-60, Joint Targeting, for additional information.
Note: The doctrinal targeting process that has been adopted by the Army is denoted by the
acronym “D3A,” which stands for “Decide, Deliver, Detect, and Assess” and is covered in-depth
in FM 6-20-10, Tactics, Techniques, and Procedures for the Targeting Process, 8 May 1996.
TARP. Acronym for Threat Awareness and Reporting Program; see Army Regulation 381-12, TARP,
4 Oct 2012.
Task Asset. [In critical infrastructure usage] an asset that is directly used to support execution of one or
more operations, tasks, activities, or mission essential tasks (METs). (DoDI 3020.45, DCIP Management,
21 Apr 2008) Also see asset, defense critical asset, defense critical infrastructure program (DCIP), task
critical asset.
Task Critical Asset (TCA). An asset that is of such extraordinary importance that its incapacitation or
destruction would have a serious, debilitating effect on the ability of one or more DoD Components or
DISLA organizations to execute the task or mission-essential task it supports. Task critical assets are
used to identify defense critical assets. (DoDD 3020.40, Policy and Responsibilities for Critical
Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012) Also see asset, defense critical asset, defense
critical infrastructure program (DCIP), task asset.
Tier 1 - 3 Task Critical Assets
Tier 1 TCA. An asset the loss, incapacitation, or disruption of which could result in mission (or
function) failure at the DoD, Military Department, Combatant Command, sub-unified command,
Defense Agency, or defense infrastructure sector level.
Tier 2 TCA. An asset the loss, incapacitation, or disruption of which could result in severe mission
(or function) degradation at the DoD, Military Department, Combatant Command, subunified
command, Defense Agency, or defense infrastructure sector level.
Tier 3 TCA. An asset the loss, incapacitation, or disruption of which could result in mission (or
function) failure below the Military Department, Combatant Command, sub-unified command,
Defense Agency, or defense infrastructure sector level.
-- DoDM 3020.45-Vol 1, Defense Critical Infrastructure Program (DCIP): DoD Mission-Based Critical
Asset Identification Process (CAIP), 24 Oct 2008
Task Force Counterintelligence Coordinating Authority (TFCICA). An individual that affects the overall
coordination of counterintelligence activities (in a joint force intelligence directorate counterintelligence
and human intelligence staff element, joint task force configuration), with other supporting CI
organizations, and supporting agencies to ensure full CI coverage of the task force operational area.
(JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Tasking. Directing or requesting a source to perform in a specific manner to achieve an objective or
conduct an activity. (DoDI S-5200.42, Defense HUMINT and Related Activities (U), 8 Dec 2009)
-- Also, the process associated with acceptance of a validated collection requirement and assigning it
to organic collection assets for action. (DHE-M 3301.001, Vol I: Collection Requirement, Reporting, and
Evaluation Procedures, 30 Jan 2009, w/ chg 2 dated 1 Feb 2012)
Tear Line. A physical line on an intelligence message or document separating categories of information
that have been approved for foreign disclosure and release. (JP 2-0, Joint Intelligence, 22 Oct 2013) Also
see tearline reporting.
The sanitized information below the tear line should contain the substance of the information above
the tear line, but without identifying the sensitive sources and methods. This will permit wider
dissemination, in accordance with “need-to-know”, need-to-release, and write-to-release principles
and foreign disclosure guidelines of the information below the tear line.
316
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a physical line on an intelligence message or document separating categories of information
that have been approved for foreign disclosure and release. Normally, the intelligence below the tear line
is that which has been previously cleared for disclosure or release. (DoDI S-5240.17, CI Collection
Activities, 14 Mar 2014)
Tearline Reporting. An automated or manual technique for separating an intelligence report into multiple
portions separated by machine-or human-readable tearlines. A tearline section is the area in an
intelligence report or finished intelligence product where the sanitized version of a more highly classified
and/or controlled report is located. The sanitized information within the tearlines contains the substance
of the more detailed information without identifying the sensitive sources and methods, allowing wider
dissemination of substantive intelligence information to authorized users. (ICD 206, 17 Oct 2007) Also
see tear line.
Also see ICD 209, Tearline Production and Dissemination, 6 Sep 2012
Technical Counterintelligence (TCI). A component of counterintelligence technical services. TCI includes
Technical Surveillance Countermeasures (TSCM) and the investigation, study, and control of
compromising emanations from information systems, known as TEMPEST. Also see technical
penetration, Technical Surveillance Countermeasures, TEMPEST.
The essence of technical counterintelligence collection is learning through technical means what
foreign intelligence services see, hear, and sense, what they know about one’s own technical
means, and how they are using this information.
-- Roy Godson, Dirty Tricks or Trump Cards: US Covert Action and Counterintelligence (1995), p. 224
Technical Counterintelligence (TCI) Countermeasures. Any action, device, procedure, technique, or
other measure that reduces the vulnerability of any equipment or facility that electronically processes
information to technical exploitation of classified and/or sensitive information. (AR 381-14, Technical
Counterintelligence [U], 30 Sep 2002)
Technical Intelligence (TECHINT). Intelligence derived from the collection, processing, analysis, and
exploitation of data and information pertaining to foreign equipment and materiel for the purposes of
preventing technological surprise, assessing foreign scientific and technical capabilities, and developing
countermeasures designed to neutralize an adversary’s technological advantages. (JP 1-02 and JP 2-0,
Joint Intelligence, 22 Oct 2013)
-- Also, the identification, assessment, collection, exploitation, and evacuation of captured enemy
materiel (CEM) in support of national and immediate technical intelligence requirements. TECHINT
provides rapid performance and vulnerability assessments of enemy equipment, giving a critical edge to
US forces in current and future operations. (Army FM 2-22.401, TECHINT, 9 Jun 2006)
Technical Hazard. An insecure condition that could permit the technical exploitation of an area with
classified national security information, restricted data, and/or unclassified information requiring
protection. (AR 381-14, Technical Counterintelligence, 30 Sep 2002)
Technical Penetration. The use of technological means to conduct an intentional, unauthorized
interception of information-bearing energy. (DoDI 5240.05, TSCM Program, 22 Feb 2006)
-- Also, a deliberate, unauthorized, clandestine emplacement of a device or modification of existing
government equipment, or the clandestine employment of a technique, which allows the technical
monitoring within an area for the purpose of gaining information.
(Defense HUMINT Enterprise Manual
3301.002, Vol II Collection Operations, 23 Nov 2010)
317
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, technical penetrations include the employment of optical, electro-optical, electromagnetic,
fluidic, and acoustic means as the sensor and transmission medium, or the use of various types of
stimulation or modification to equipment or building components for the direct or indirect transmission of
information meant to be protected. (Previously in JP 2-01.2, CI & HUMINT Support to Joint Operations,
13 Jun 2006)
“…[I]t had been my experience that the most up-to-snuff secret audio and other clandestine
monitoring techniques always seemed to be a step ahead of the counter-surveillance teams.”
-- Richard Helms with William Hood, A Look Over My Shoulder (2003), p. 449
Technical Security. A security discipline dedicated to detecting, neutralizing, and/or exploiting a wide
variety of hostile and foreign penetration technologies. This discipline mandates training in various
countermeasure techniques. (IC Standard 700-1, 4 Apr 2008)
Technical Services. The investigative use of video surveillance and interception of oral, electronic and
wire communications. (AFPD 71-1, Criminal Investigations and Counterintelligence, 1 Jul 1999)
Technical Surveillance. The use of optical, audio, or electronic monitoring devices or systems to
surreptitiously collect information. (DoDI 5240.05, TSCM, 3 Apr 2014)
-- Also, surveillance accomplished through the use of electronic listening devices, vehicle trackers,
and signaling devices. (CI Community Lexicon)
Technical Surveillance Countermeasures (TSCM). Techniques to detect, neutralize, and exploit technical
surveillance technologies and hazards that permit the unauthorized access to or removal of information.
(DoDI 5240.05, TSCM Program, 3 Apr 2014)
-- Also, techniques and measures to detect and neutralize a wide variety of hostile penetration
technologies that are used to obtain unauthorized access to classified and sensitive information.
Technical penetrations include the employment of optical, electro-optical, electromagnetic, fluidic, and
acoustic means as the sensor and transmission medium, or the use of various types of stimulation or
modification to equipment or building components for the direct or indirect transmission of information
meant to be protected. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1
dated 26 Aug 2011)
-- Also, physical, electronic, and visual techniques used to detect and counter technical security
devices, technical security hazards, and related physical security deficiencies. (IC Standard 700-1,
4 Apr 2008)
Long history of adversary technical surveillance
collection and exploitation of sensitive U.S. facilities and activities…
In 1944, the very first TSCM sweep uncovered 120 microphones in the Moscow Embassy [U.S.
Embassy in Moscow].”
-- Frederick L. Wettering, “Counterintelligence: The Broken Triad.” International Journal of
Intelligence and Counterintelligence 13 (Fall 2000), pp. 265-299.
TSCM identifies technically exploitable conditions and provides strategies to mitigate or remove
them.
_____________________
318
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
TSCM represents the convergence of two distinct disciplines -- counterintelligence and security
countermeasures. These techniques and countermeasures are designed to detect and nullify a
wide variety of technologies used to gain unauthorized access to classified national security
information, restricted data, or otherwise sensitive information.
-- ICD 702, TSCM, 18 Feb 2008
_____________________
TSCM involves the search for technical surveillance devices or “bugs.” …[T]he overwhelming
number of technical attacks against US interests occur overseas. … Scare resources should be
directed both to specific threat-driven inspections and to the maintenance of an R&D and training
effort,
-- Joint Security Commission, Redefining Security: A Report to the Secretary of Defense and the Director
Central Intelligence, 28 Feb 1994, p. 61
_____________________
The TSCM Program includes four separate functions: detection, nullification, isolation, and
education.
-- FM 2-22.2, Counterintelligence, October 2009, p. 6-5;
also AR 381-14, Technical Counterintelligence (TCI) (U), 30 Sep 2002, p. 7
_____________________
TSCM: the systematic physical and electronic examination of a designated area by properly
trained, qualified and equipped persons in an attempt to discover electronic eavesdropping
devices, security hazards or security weaknesses.
___________________
PROJECT GUNMAN
A most spectacular case of electronic espionage occurred in the 1980s, at the height of the Cold
War, when it was discovered that Soviet intelligence had successfully implanted very sophisticated
bugs in a large number of electronic typewriters at the U.S. embassy in Moscow. On 25 March
1985, the story of the Soviet bug of U.S. typewriters in the Moscow Embassy broke on the CBS
nightly news.
For detailed information see Sharon A. Maneki, Learning From the Enemy: The GUNMAN Project,
NSA, 2012, 35 pages. Available on line at: http://www.nsa.gov/about/_files/cryptologic_heritage/
Technical Surveillance Device (TSD). A device covertly installed to monitor (visually, audibly, or
electronically) sensitive activities and/or information processing within a target area. (ICS Glossary)
Technical Threat Analysis. A continual process of compiling and examining information on technical
surveillance activities against personnel, information, operations, and resources. (DoDI 5240.05, TSCM
Program, 3 Apr 2014)
Technology. The application of scientific and technical information and know-how to design, produce,
manufacture, use, adapt, reconstruct, or reverse-engineer goods. This includes technical information and
data in all forms, including electronic form. The term does not include the goods themselves, nor does it
include scientific information in the public domain. (DoDI 2040.02, International Transfers of Technology,
Articles, and Services, 10 Jul 2008) Also see critical technology.
Technology Readiness Level (TRL). A standard utilized in the scientific community to track the maturity of
a technology. The readiness level is depicted on a numerical scale form one to nine, where one
represents the initial idea stage and nine represents the final fielding and utilization of the technology.
(DoD FCIP Strategy FY 2013-017)
319
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Technology Targeting Risk Assessment (TTRA). A country-by-country assessment conducted by the
Defense Intelligence Community that quantifies risks to CPI [critical program information] and related
enabling technologies for weapons systems, advanced technologies or programs, and facilities such as
laboratories, factories, research and development sites (test ranges, etc.), and military installations. The
TTRA evaluates five independent risk factors, each of which contributes to an overall risk factor. The five
areas evaluated are: Technology Competence, National Level of Interest, Risk of Technology Diversion,
Ability to Assimilate, and Technology Protection Risk. (DoDI 5200.39, CPI within DoD, 16 Jul 2008 with
change 1 dated 28 Dec 2010)
The TTRA and CI Assessment provide laboratory/technical directors and Program Managers with
information required to establish a comprehensive security program for the protection of identified
critical program information (CPI).
Technology Transfer. The intentional communication (sharing) of knowledge, expertise, facilities,
equipment, and other resources for application to military and nonmilitary systems. (DoDI 5535.8, DoD
Technology Transfer Program, 14 May 1999)
-- Also, transferring, exporting, or disclosing defense articles, defense services, or defense technical
data covered by the United States Munitions List (USML) to any foreign person or entity in the United
States (U.S.) or abroad. (DSS Glossary)
Telecommunications and Information Systems Security. Protection afforded to telecommunications and
information systems, in order to prevent exploitation through interception, unauthorized electronic access,
or related technical intelligence threats, and to ensure authenticity. Such protection results from the
application of security measures (including cryptosecurity, transmission security, emission security, and
computer security) to systems which generate, store, process, transfer, or communicate information of
use to an adversary, and also includes the physical protection of technical security material and technical
security information. (National Security Directive 42, National Policy for the Security of National Security
Telecommunications and Information Systems, 5 Jul 1990)
Copy of NSD 42 available at: <http://www.fas.org/irp/offdocs/nsd/nsd42.pdf>
TEMPEST. An unclassified term referring to technical investigations for compromising emanations from
electrically operated information processing equipment; these investigations are conducted in support of
emanations and emissions security. (JP 1-02) Also see compromising emanations; TEMPEST Test.
-- Also, an unclassified term that refers to the investigation and study of compromising emanations.
(IC Standard 700-1, 4 Apr 2008)
-- Also, a name referring to the investigation, study, and control of compromising emanations from
telecommunications and automated information systems equipment. (CNSSI No. 4009, National
Information Assurance Glossary, 26 April 2010)
-- Also, Transient Electro Magnetic Pulse Emanation Standard (TEMPEST) the investigation, study,
and control of compromising emanations from telecommunication and automated information systems
equipment. (Defense HUMINT Enterprise Manual 3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, the evaluation and control of compromising emanations from telecommunications and
automated information systems. TEMPEST countermeasures are designed to prevent FISS and ITO
[international terrorist organization] exploitation of compromising emanations by containing them within
the space of the equipment or facility processing classified information. (Army FM 2-22.2, CI, Oct 2009)
320
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- An unclassified term referring to technical investigations for compromising emanations from
electrically operated, information processing equipment; they are conducted in support of emanations and
emission security. (ICS Glossary, Jun 1989)
TEMPEST - the problem of compromising radiation. Any time a machine is used to process
classified information electrically… that machine may emit radio frequency or acoustic energy.
These emissions, like tiny radio beacons, may radiate through free space for considerable
distances…. Or they may be induced on nearby conductors like signal lines, power lines,
telephones lines, or waste pipes and be conducted along those paths for some distance…. When
these emissions can be intercepted and recorded, it is frequently possible to analyze them and
recover the intelligence that was processed by the source equipment. The phenomenon affects
not only cipher machines buy any information-processing equipment—teletypewriters, duplicating
equipment, intercoms, facsimile, computers.…
-- Source: NSA, TEMPEST: A Signal Problem, undated [declassified/redacted version]
______________________
TEMPEST (an acronym for Transient Electromagnetic Pulse Emanation Standard) is both a
specification for equipment and a term used to describe the process for preventing compromising
emanations. The fact that electronic equipment such as computers, printers, and electronic
typewriters give off electromagnetic emanations has long been a concern of the US Government.
An attacker using off-the-shelf equipment can monitor and retrieve classified or sensitive
information as it is being processed without the user being aware that a loss is occurring. …
Given the absence of a domestic threat, any use of TEMPEST countermeasures within the US
should require strong justification.
[TEMPEST] attacks require a high level of expertise, proximity to the target, and
considerable collection time. [emphasis added]
The commission recognizes the need for an active overseas TEMPEST program but believes the
domestic threat is minimal.
-- Joint Security Commission, Redefining Security: A Report to the Secretary of Defense and the Director
Central Intelligence, 28 Feb 1994, pp. 60-61
______________________
According to a declassified NSA publication: “There is no special meaning in the word
‘TEMPEST.’ It was simply picked from a covername list by a NSA engineer in the early 1950s.
However, TEMPEST has now become a generic word used throughout the US Government and
industry to describe the unintentional emanation of classified information from an equipment.”
-- NSA, Crypotolog, Nov 1983 [declassified], p. 1
______________________
For a history of TEMPEST see declassified NSA publication, A History of U.S. Communications
Security (U), [Vol I], revised July 1973, pp. 89-101; covers the timeframe through 1972.
This NSA report identified the main TEMPEST countermeasures as: “low-level keying,
shielding, filtering, grounding, isolation, and physical protective measures.” It also high-
lighted that shielded enclosures “provided not only the best means, but the only means we
had come across to provide really complete TEMPEST protection in those environments
where a large-scale intercept effort could be mounted at close range.”
TEMPEST Test. A laboratory or on site (field) test to determine the nature and amplitude of conducted or
radiated signals containing compromising information. (NSTISSI 7002, TEMPEST Glossary, 17 Mar
1995) Also see compromising emanations; TEMPEST.
Temporary Refuge. Protection afforded for humanitarian reasons to a foreign national in a DoD shore
installation, facility, or military vessel within the territorial jurisdiction of a foreign nation or in international
waters, under conditions of urgency in order to secure the life or safety of that person against imminent
danger, such as pursuit by a mob. (DoDI 2000.11, Procedures for Handling Requests for Asylum and
Temporary Refuge, 13 May 2010)
321
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Terrorism. The unlawful use of violence or threat of unlawful violence to instill fear and coerce
governments or societies. Terrorism is often motivated by religious, political, or other ideological beliefs
and committed in the pursuit of goals that are usually political. (JP 1-02 and JP 3-07.2, Antiterrorism,
24 Nov 2010) Also see homegrown terrorist, radicalization, violent extremism, violent radicalization.
There is no universally accepted definition of terrorism.
It remains the subject of continuing debate in international bodies.
-- Lord Carlile of Berriew Q.C. (March 2007)
-- Also, premeditated, politically motivated violence perpetrated against non-combatant targets by
sub-national groups or clandestine agents (22 USC §2656f(d) and the National Strategy for Combating
Terrorism, Feb 2003) [Definition used by Department of State, NCTC and CIA].
-- Also, the unlawful use of force and violence against persons or property to intimidate or coerce a
government, the civilian population, or any segment thereof, in furtherance of political or social objectives.
(28 CFR §0.85) [Definition used by FBI, which reflects its mission, identifying a terrorist incident as a
violation of the criminal laws of the United States and a suspected terrorist would, therefore, be subject to
arrest and prosecution.]
-- Also, [the federal crime of terrorism] an offense that is calculated to influence or affect the conduct
of government by intimidation or coercion, or to retaliate against government conduct. This includes
terrorist acts committed within and outside U.S. national boundaries. (18 USC §2332b(g)(5)(A)).
-- Also, violent or illegal action taken on the basis of radical or extremist beliefs. (CRS Report
R42553, Countering Violent Extremism in The United States, 19 Feb 2014)
The Federal Bureau of Investigation (FBI) is the lead agency for investigating the federal crime of
terrorism. If another federal agency identifies an individual who is engaged in terrorist activities or
in acts in preparation of terrorist activities, the other agency is required to promptly notify the FBI.
The extraterritorial jurisdiction for terrorism crimes is specified in 18 U.S.C. 2332b(e) and (f).
Pursuant to 28 C.F.R. 0.85(1), the Attorney General has assigned responsibility to the Director of
the FBI to “Exercise Lead Agency responsibility in investigating all crimes for which it has primary
or concurrent jurisdiction and which involve terrorist activities or acts in preparation of terrorist
activities within the statutory jurisdiction of the United States. Within the United States, this would
include the collection, coordination, analysis, management and dissemination of intelligence and
criminal information as appropriate.”
-- Congressional Research Service (CRS) Report R41780, 27 Apr 2011
__________________________
For additional information on terrorism, see US Army TRADOC G2 Handbook No.1, A Military
Guide to Terrorism in the Twenty-First Century, 15 Aug 2007.
Terrorism Threat Assessment. The process used to conduct a threat analysis and develop an evaluation
of a potential terrorist threat; [or] the product of a threat analysis for a particular unit, installation, or
activity. (DoDI 2000.16, DoD Antiterrorism Standards, 2 Oct 2006)
Terrorist. One that engages in acts or an act of terrorism. (answer.com; accessed 27 October 2011)
Terrorists undertake criminal acts that involve the use or threat of violence against innocent
persons. These acts are premeditated, intended to achieve a political objective through coercion or
intimidation of an audience beyond the immediate victims.
- National Security Decision Directive 207, The National Program for Combating Terrorism (U),
originally TOP SECRET, declassified
Note: Within DoD; None -- the term “terrorist” removed from JP 1-02. Previously defined in
JP 3-26, Counterterrorism (13 Nov 2009) as “those who commit acts of terrorism.”
322
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Terrorist Extremist. An extremist that uses terrorism -- the purposeful targeting of ordinary people -- to
produce fear to coerce or intimidate governments or societies in the pursuit of political, religious, or
ideological goals. Extremists use terrorism to impede and undermine political progress, economic
prosperity, the security and stability of the international state system, and the future of civil society.
(National Military Support Plan - War on Terrorism, 1 Feb 2006)
Terrorist Group. Any number of terrorists who assemble together, have a unifying relationship, or are
organized for the purpose of committing an act or acts of terrorism.
Current list of Foreign Terrorist Organizations (FTOs) at US Department of State web site:
Terrorist Identities Datamart Environment (TIDE). The U.S. Government’s (USG) central repository of
information on international terrorist identities. TIDE supports the USG’s various terrorist screening
systems or “watchlists” and the US Intelligence Community’s overall counterterrorism mission. (NCTC)
The TIDE database includes, to the extent permitted by law, all information the USG possesses
related to the identities of individuals known or appropriately suspected to be or to have been
involved in activities constituting, in preparation for, in aid of, or related to terrorism (with the
exception of purely domestic terrorism information). This information is available to
counterterrorism professionals throughout the Intelligence Community, including the Department of
Defense, via the web-based, read-only “TIDE Online.”
Terrorism Screening Center (TSC). A multi-agency center administered by the FBI with support from the
Department of Homeland Security, the Department of State, the Department of Justice, the Department of
Defense, the Department of the Treasury, and the Office of the Director of National Intelligence. The TSC
maintains the U.S. government’s consolidated Terrorist Watchlist—a single database of identifying
information about those known or reasonably suspected of being involved in terrorist activity. (fbi.gov)
The TSC was created by HSPD-6 (16 Sep 2003) to consolidate the USG’s approach to terrorist
screening by creating a single comprehensive database of known or appropriately suspected
terrorists (KSTs), and to make the information from this consolidated list available to foreign,
federal, state, local, territorial, tribal, regulatory and private sector entities through the TSC’s 24/7
Terrorist Screening Operations Center (TSOC).
For additional information see FBI web site at: <http://www.fbi.gov/about-us/nsb/tsc>
Terrorist Screening Database (TSDB). Under Homeland Security Presidential Directive-6, the TSDB is
the master terrorist watchlist, for both international and domestic terrorists, maintained by the Terrorist
Screening Center (TSC) for the U.S. Government.
Terrorist Threat. An expression of intention, by an individual or group, to commit an act or acts of
violence to inflict injury or damage in pursuit of political, religious, or ideological objectives. (DoDI
2000.12, DoD Antiterrorism Program, 1 Mar 2012, w/ change 1 dated 9 Sep 2013)
Terrorist threats emanate from a diverse array of terrorist actors, ranging from formal groups to
homegrown violent extremists (HVEs) and ad hoc, foreign-based actors.
US-based extremists will likely continue to pose the most frequent threat to the US Homeland.
-- DNI, Worldwide Threat Assessment of the US Intelligence Community, SSCI, 29 January 2014, p. 4
Terrorists with Global Reach - Transnational Terrorists. Terrorist organizations with an operational and
support network in multiple countries that possess the capability to recruit, plan, resource, and execute
terrorist acts worldwide. (National Military Support Plan - War on Terrorism, 1 Feb 2006)
TFCICA. See Task Force Counterintelligence Coordinating Authority.
323
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Theater. The geographical area for which a commander of a geographic combatant command has been
assigned responsibility. (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013 and
JP 1-02)
Theater Clearance. Clearance for official travel within a geographic combatant command area of
responsibility granted by the responsible geographic combatant commander or other delegated authority.
(DoDD 4500.54E, DoD Foreign Clearance Program, 28 Dec 2009)
Theater of War. Defined by the Secretary of Defense or the geographic combatant commander, the area
of air, land, and water that is, or may become, directly involved in the conduct of the war. A theater of war
does not normally encompass the geographic combatant commander's entire area of responsibility and
may contain more than one theater of operations. (JP 1-02)
Theater Strategy. An overarching construct outlining a combatant commander’s vision for integrating and
synchronizing military activities and operations with the other instruments of national power in order to
achieve national strategic objectives. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Thermal Imagery. Imagery produced by sensing and recording the thermal energy emitted or reflected
from the objects which are imaged. (JP 1-02)
Third Agency Rule. An agreement among the US Government agencies participating in the exchange of
intelligence data forbidding one agency to disseminate to another agency information which originated
with a third agency. (National HUMINT Glossary)
-- Also, the tenet that information, usually classified or sensitive, originating in one U.S. agency not be
disseminated by another agency to which the information has not been made available without the
consent of the originating agency. (AR 381-20, Army CI Program, 25 May 2010)
Threat. The intention and capability of an adversary to undertake actions that would be detrimental to the
interest of the U.S. (IC Standard 700-1, 4 Apr 2008)
-- Also, the sum of the potential strengths, capabilities, and strategic objectives of any adversary that
can limit or negate U.S. mission accomplishment or reduce force, system, or equipment effectiveness.
(DoDD 5200.1-M, Acquisition Systems Protection Program, March 1994)
-- Also, an adversary having the intent, capability, and opportunity to cause loss or damage. (DoDD
3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep
2012)
-- Also, the perceived imminence of intended aggression by a capable entity to harm a nation, a
government or its instrumentalities, such as intelligence, programs, operations, people, installations, or
facilities. (DoD 5200.08-R, Physical Security Program, 9 Apr 2007)
-- Also, (1) A source of unacceptable risk; or (2) The capability of an adversary coupled with the
adversary’s intention to undertake actions that would be detrimental to the success of certain activities or
operations. (ODNI, U.S. National Intelligence - An Overview 2011)
-- Also, the capability of an adversary coupled with his intentions to undertake any actions detrimental
to the success of program activities or operations. (IOSS OPSEC Glossary of Terms, 27 Aug 2003)
-- Also, any combination of actors, entities, or forces that have the capability and intent to harm
United States forces, United States national interests, or the homeland. (ADRP 3-0, Unified Land
Operations, May 2012)
-- Also see threat to national security; transnational threat; foreign intelligence collection threat;
insider threat.
324
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Threat Advisory. An advisory is a one-time product or produced on a recurring schedule - daily, weekly,
or monthly. The advisory informs authorized recipients of an immediate or the potential for a foreign
intelligence or terrorist threat. The advisory typically contains information of a perishable nature.
(DoDI 5240.18, CI Analysis & Production, 17 Nov 2009 with change 1 dated 15 Oct 2013)
A threat advisory is distinguishable from an assessment and an analysis report in that it is prepared
when there is an imminent or near-term intelligence or terrorist threat. A threat advisory often
contains perishable information with only limited study or research conducted prior to publication.
Threat Analysis. a process that examines an adversary’s technical and operational capabilities,
motivation, and intentions, designed to detect and exploit vulnerabilities. (DoDM 5205.02-M, DoD OPSEC
Program Manual, 3 Nov 2008)
-- Also, terrorism threat analysis, a continual process of compiling and examining all available
information concerning potential terrorist activities by terrorist groups that could target the DoD
Components or DoD elements and personnel. A threat analysis shall review the factors of a terrorist
group’s operational capability, intentions, activity, and the security environment within which friendly
forces operate. Threat analysis is an essential step in identifying probability of terrorist attack and results
in a threat assessment. (DoDI 2000.12, DoD Antiterrorism Program, 1 Mar 2012 with change 1 dated 9
Sep 2013; also JP 1-02 and JP 3-07.2, Antiterrorism, 24 Nov 2010)
Threat Assessment. A resultant product of the defined process used to conduct a threat analysis and
develop an evaluation of a potential threat. Also, it is the product of a threat analysis for a particular unit,
installation, or activity. (DoD 5200.08-R, Physical Security Program, 9 Apr 2007)
-- Also, DCIP Threat Assessment: [in Defense Critical Infrastructure Protection usage] a compilation
of strategic intelligence information incorporating multi-faceted threats facing DCAs [Defense Critical
Assets] and Tier 1 TCAs [Task Critical Assets]. DCIP threat assessments address threats posed to DCAs
[and Tier 1 TCAs] from domestic and transnational terrorist elements, foreign intelligence and security
services, and weapons of mass destruction. (DoDI 5240.19, CI Support to the Defense Critical
Infrastructure Program, 31 Jan 2014)
-- Also, an evaluation of the current or projected capability of a foreign intelligence service or
international terrorist group to limit, neutralize, or negate the effectiveness of a friendly mission,
organization, or material item through multidisciplined intelligence collection, espionage, or sabotage.
(AR 381-20, Army CI Program, 25 May 2010)
-- Also, in antiterrorism, examining the capabilities, intentions, and activities, past and present, of
terrorist organizations as well as the security environment within which friendly forces operate to
determine the level of threat. (JP 1-02 and JP 3-07.2, Antiterrorism, 24 Nov 2010)
-- Also, [in antiterrorism usage] the process used to conduct a threat analysis and develop an
evaluation of a potential terrorist threat; the product of a threat analysis for a particular unit, installation,
or activity. (DoDI 2000.12, DoD Antiterrorism Program, 1 Mar 2012 with change 1 dated 9 Sep 2013)
Threat Finance. The covert movement of the profits of illicit acts or of funds that will support illicit acts.
(A Guide to Counter Threat Finance Intelligence by Marilyn B. Peterson, 2009) Also see counter threat
finance (CTF).
The covert movement of money is the underlying facilitator of all threat activity.
Within DoD, see DoDD 5205.14, DoD Counter Threat Finance Policy, 19 Aug 2010 (w/ chg1 dated
16 Nov 2012)
325
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Threat Indicator. Any observable action that displays violent behavior, abnormal disgruntlement,
radicalization, or an extreme world view on religion or another type of ideology. (US Army, Asymmetric
Warfare Group, Insider Threats in Partnering Environments: A Guide for Military Leaders, Jun 2011)
4CD5-B693-0D59B108E7EC-1326399638300>
72811.pdf>
Threat Warning. The urgent communication and acknowledgement of time-critical information essential
for the preservation of life and/or vital resources. (JP 1-02 and JP 2-01, Joint and National Intelligence
Support to Military Operations, 5 Jan 2012)
Threats to the National Security. International terrorism; espionage and other intelligence activities,
sabotage, and assassination, conducted by, for, or on behalf of foreign powers, organizations, or persons;
foreign computer intrusion; and other matters determined by the Attorney General, consistent with
Executive Order 12333 or a successor order. (FBI, Domestic Investigations and Operations Guide,
15 Oct 2011)
Time Bomb. Resident computer program that triggers an unauthorized act at a predefined time.
(CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Time-Sensitive Collection Requirement (TSCR). A HUMINT collection requirement (HCR) needing
immediate or time-specific action. Those organizations tasked with the time sensitive collection
requirement should provide initial intelligence reports or a report stating an inability to collect on the
requirement with 48 hours of issuance. (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
Tosses (hand, vehicular) [e.g., hand toss, car toss]. Tradecraft techniques for placing drops by tossing
them while on the move. (CI Centre Glossary)
Traces. The product resulting from a name check. (AFOSI Instruction 71-101, 6 Jun 2000)
Tracking. Precise and continuous position-finding of targets by radar, optical, or other means. (JP 1-02
and JP 3-07.4, Joint Counterdrug Operations, 13 Jun 2007)
Tradecraft. Specialized methods and equipment used in the organization and activity of intelligence
organizations, especially techniques and methods for handling communications with agents. Operational
practices and skills used in the performance of intelligence related duties. (JP 1-02; JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011; DoDI S-5240.17, CI Collection
Activities, 14 Mar 2014; and CI Community Lexicon)
Tradecraft
The methods of the clandestine operator…
Principles and techniques of clandestine operations
Successful espionage is impossible without good tradecraft
In general, tradecraft is the sum total of the skills the Case Officer or agent must master in order
to securely operate in the field and preserve security of operational activity.
_____________________
“Tradecraft is an art—a combination of common sense and imagination…. [T]he art of tradecraft,
the methods employed to mange an intelligence operation. It is an art because of the nuances
involved and it is not easy to learn. Some, lacking the personality traits, can never master it.”
-- Richard L. Holm, The Craft We Chose (2011), pp 25 and 275
_____________________
326
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
The techniques adopted by spies to conceal their activities are lumped together under the
catch-all term “tradecraft.” It refers to a vast range of protective measures devised to preserve
the operational security of spying.
-- Frederick P. Hitz (Former CIA IG 1990-1998), The Great Game (2005)
___________________
Pillars of Tradecraft: assessment; cover and disguise; concealments; clandestine surveillance;
and covert communications.
-- Spycraft (p. 363)
___________________
[T]he greatest danger… lay not in betrayal by a Soviet mole, as Angleton would have it, but by
simple mistakes in tradecraft and a failure to maintain proper compartmentation of information.
-- Benjamin Weiser, A Secret Life (2004)
___________________
“The spy who does not take tradecraft seriously is unlikely to remain a spy for very long.”
-- H.H.A. Cooper and Lawrence J. Redlinger, Making Spies: A Talent Spotter’s Handbook
-- Also, the art, discipline and methodology of conducting secure clandestine operations and
intelligence collection. (National HUMINT Glossary)
-- Also, the tactics, techniques, and procedures used in executing HUMINT, counterintelligence,
or related activities to obscure, protect, or otherwise frustrate detection. (HDI Lexicon, April 2008)
-- Also, specialized techniques used in intelligence operations. (FBI FCI Terms)
-- Also, the techniques, technology, and methodologies used in covert intelligence operations.
Tradecraft applies to both the procedures, such as surveillance detection routes, as well as the use of
devices in covert audio and agent communications. (Spycraft)
-- Also, the art, methodology, and know-how of conducting clandestine operations and intelligence
collection techniques. Includes such things as dead drops, covert communications, how to recruit agents,
secret writing and photography, surveillance, and surveillance detection. (A Spy’s Journey)
-- Also, the essential skills required to conduct successful clandestine operations. (Encyclopedia of
Cold War Espionage, Spies, and Secret Operations, 3rd edition, 2012)
-- Also, the techniques of the espionage trade, or the methods by which an agency involved in
espionage conducts its business. Elements of tradecraft, in general terms, include the ways in which an
intelligence officer arranges to make contact with an agent, the means by which the agent passes on
information to the officer, the method for paying the agent, and the many precautions and tactics of
deception applied along the way. (<http://www.espionageinfo.com/Te-Uk/Tradecraft.html>)
Tradecraft - Analytical. The term “tradecraft” usually applied to espionage techniques, but there is also
analytical tradecraft: techniques, methods, and standards of the practice of analysis, e.g., framing
questions, marshaling evidence, making concise arguments, identifying intelligence gaps, etc. Analytical
tradecraft affords some criteria by which to judge analytical products and analysts.
Transmission Security. The component of communications security that results from all measures
designed to protect transmissions from interception and exploitation by means other than cryptanalysis.
(JP 1-02 and JP 6-0, Joint Communications, 10 Jun 2010) Also see communications security.
Transnational Threat. Any transnational activity (including international terrorism, narcotics trafficking, the
proliferation of weapons of mass destruction and the delivery for such weapons, and organized crime)
that threatens the national security of the United States. (50 USC §401a)
327
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, any activity, individual, or group not tied to a particular country or region that operates across
international boundaries and threatens United States national security or interests. (JP 1-02 and JP 3-26,
Counterterrorism, 13 Nov 2009)
DoD further defines a transnational threat as any activity, individual, or group not tied to a particular
country or region that operates across international boundaries and threatens US national security
or interests. These threats also include extremists who enter into convenient relationships that
exploit each others’ capabilities and cloud the distinction between crime and terrorism (e.g., violent
extremist organizations and opportunists, drug trafficking organizations, transnational criminal
organizations [TCOs], and those trafficking in persons).
Lawless and subversive organizations can take advantage of failed states, contested spaces, and
ungoverned areas by forging alliances with corrupt government officials and some foreign
intelligence services, further destabilizing political, financial, and security institutions in fragile
states, undermining competition in world strategic markets, using cyberspace technologies and
other methods to perpetrate sophisticated frauds, creating the potential for the transfer of WMD to
terrorists, and expanding narco-trafficking and human and weapons smuggling networks.
-- JP 3-27, Homeland Defense, 29 Jul 2013 (p. I-4)
Transnational Organized Crime (TOC). Self-perpetuating associations who operate transnationally for the
purpose of obtaining power, influence, monetary and/or commercial gains, wholly or in part by illegal
means, while protecting their activities through a pattern of corruption and/ or violence, or while protecting
their illegal activities through a transnational organizational structure and the exploitation of transnational
commerce or communication mechanisms. (White House, Strategy to Combat Transnational Organized
Crime, Jul 2011)
Transnational Criminal Organizations pose a National Security Threat
TOC represent a globally-networked national security threat and pose a real and present risk to the
safety and security of Americans and our partners across the globe.
Countering TOC is defined as the means to detect, counter, contain, disrupt, deter, or dismantle
the transnational activities of state and non-state adversaries threatening U.S. and partner nation
national security.
Copy of the Strategy to Combat Transnational Organized Crime (July 2011) at:
Also see The “New” Face of Transnational Crime Organizations (TCOs): A Geopolitical
Perspective and Implications to U.S. National Security, March 2013 (a compendium of white papers
on TCOs).
__________________________
“Transnational organized crime (TOC) networks erode good governance, cripple the rule of law
through corruption, hinder economic competitiveness, steal vast amounts of money, and traffic
millions of people around the globe. (Cybercrime, an expanding for-profit TOC enterprise….) TOC
threatens US national interests in a number of ways: …drug activity, facilitating terrorist activity,
money laundering, corruption, human trafficking, and environmental crime.”
-- James R. Clapper, DNI, Statement for the Record, Worldwide Threat Assessment of the US Intelligence
Community, Senate Committee on Armed Services, 18 April 2013
Trap. A hidden indicator to detect or confirm surreptitious tampering or search of items (e.g., documents,
letters, packages, luggage, drawers, safes, rooms, film, equipment) by security or other personnel.
(AFOSI Manual 71-119, CI Investigations, 27 Oct 2009)
Trap and Trace. A device which capture the incoming electronic or other impulses which identify the
origination number of an instrument or device from which a wire or electronic communication was
transmitted; see 18 USC §3127(4). (AR 381-10, US Army Intelligence Activities, 3 May 2007) Also see
pen register; trap and trace device.
A trap and trace device identifies all incoming phone numbers to a particular telephone.
A pen register captures all outgoing phone numbers a particular telephone has called.
328
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Trap and Trace Device. Captures the incoming electronic or other impulses that identify the originating
number or other dialing, routing, addressing or signaling information reasonably likely to identify the
source of a wire or electronic communication, provided that such information does not include the
contents of any communication. (FBI Domestic Investigations and Operations Guide, 15 Oct 2011)
Also see pen register; trap and trace.
Trash Cover. The intentional search of a specific person’s trash (that is located at the place of collection),
whether from a home or business, designed to find information relevant to an ongoing investigation when
no reasonable expectation of privacy exists. A trash cover is a targeted effort to gather information
regarding a particular person or entity by reviewing that person or entity’s refuse. (FBI Domestic
Investigations and Operations Guide, 15 Oct 2011)
Treason. -- Violation of the allegiance owed to one's sovereign or state; betrayal of one's country.
(JP 1-02)
-- Also, [previously defined in DoDI 5240.06, CI Awareness, Briefing, and Reporting Programs, 7 Aug
2004) Whoever, owing allegiance to the United States, levies war against them or adheres to their
enemies, giving them aid and comfort within the United States or elsewhere, is guilty of treason [in war
time, treason is a violation of Title 18 USC, § 2381].
“Treason is the ultimate mid-life crisis.”
-- Dr. Marcus, CIA Psychiatrist in Sira by David Ignatius
Treason is the only crime specifically defined in the U.S. Constitution. Article III Section 3
delineates treason as follows:
“Treason against the United States, shall consist only in levying
War against them, or in adhering to their Enemies, giving them Aid and Comfort. No Person shall
be convicted of Treason unless on the Testimony of two Witnesses to the same overt Act, or on
Confession in open Court.”
The crime is prohibited by legislation passed by Congress; 18 U.S.C. § 2381 states "whoever,
owing allegiance to the United States, levies war against them or adheres to their enemies, giving
them aid and comfort within the United States or elsewhere, is guilty of treason and shall suffer
death, or shall be imprisoned not less than five years and fined under this title but not less than
$10,000; and shall be incapable of holding any office under the United States." In the history of
the United States there have been fewer than 40 federal prosecutions for treason and even fewer
convictions.
__________________________
Treason is the ultimate word of betrayal. Treason means stabbing your country on the back. But in
legal terms, treason, the only crime that is defined in the U.S. Constitution has a narrow meaning…
The founding fathers, well aware of the political use of treason charges by the kings of England,
wanted to restrict the crime to one that could not be used as an excuse for the elimination of
political rivals.”
-- Thomas B. Allen and Norman Polmar, Merchants of Treason: America’s Secrets for Sale (1988), p. 176
_________________________
Treason is loved of many, but the traitor is hated of all.”
-- Robert Greene
Triple Agent. An agent who serves three [intelligence] services in an agent capacity but who, like a
double agent, wittingly or unwittingly withholds significant information from two services at the instigation
of the third service. (FBI FCI Terms)
Trojan. A type of malware disguised or attached to legitimate or innocuous-seeming software, but that
instead carries a malicious payload, most often opening a backdoor to unauthorized users. (Cybersecurity
and cyberwar) Also see Trojan Horse.
329
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Trojan Horse. A computer program that appears to have a useful function, but also has a hidden and
potentially malicious function that evades security mechanisms, sometimes by exploiting legitimate
authorizations of a system entity that invokes the program. (CNSSI No. 4009, National Information
Assurance Glossary, 26 April 2010) Also see Trojan.
-- Also, a computer program with an apparently or actually useful function that contains additional
(hidden) functions that surreptitiously exploit the legitimate authorizations of the invoking process to the
detriment of security (for example, making a “blind copy” of a sensitive file for the creator of the Trojan
horse). (DoD 5220.22.22-M-Sup 1, NISPOM Supplement, Feb 1995)
-- Also, a malicious program that pretends to be a benign application; it purposefully does something
the user does not expect. Trojans are not viruses since they do not replicate, but they can be just as
destructive. (McAfee.com; accessed 15 Nov 2010)
True Name. A genuine and accurate representation of an individual or organization name, that may
involve alterations of other identity information (e.g., address, telephone number, credit score, employer)
when used under an approved cover in order to conceal true identity, purpose, or organizational
affiliation. (DoDI S-5105.63, Implementation of DoD Cover and Cover Support Activities, 20 Jun 2013)
Trusted Foundry Program. DoD program that provides a cost-effective means to assure the integrity and
confidentiality of integrated circuits during design and manufacturing while providing the US Government
with access to leading edge microelectronics technologies for both Trusted and non-sensitive
applications. (DMEA web site)
Defense Microelectronics Activity (DMEA) is the program manager for the DoD Trusted Foundry
program; see website at: <http://www.dmea.osd.mil/trustedic.html>
Also see NSA’s Trusted Access Program Office (TAPO) web site at:
TSCM. See Technical Surveillance Countermeasures.
TSCM Practitioner. An individual trained and certified to conduct all TSCM activities within DoD. (DoDI
5240.05, TSCM, 3 Apr 2014) Also see TSCM Technician.
TSCM Technician. An individual trained to perform limited TSCM activities under the oversight of a
TSCM practitioner. (DoDI 5240.05, TSCM, 3 Apr 2014) Also see TSCM Practitioner.
TSCM Equipment. Equipment or mechanisms used to identify the presence of surveillance devices.
TSCM includes general purpose, specialized, or fabricated equipment to determine the existence and
capability of surveillance devices. (DoDI 5240.05, TSCM, 3 Apr 2014)
Turnover. The official changing of an agent from one case officer to the other—i.e., turning him over to
another. (A Spy’s Journey)
Two-Person Control (TPC). the continuous surveillance and control of material at all times by a minimum
of two authorized individuals, each capable of detecting incorrect or unauthorized procedures with respect
to the task being performed and each familiar with established security requirements. (DoDI 5200.33,
Defense Courier Operations, 30 Jun 2011) Also see two-person integrity; two-person rule.
-- Also, continuous surveillance and control of positive control material at all times by a minimum of
two authorized individuals, each capable of detecting incorrect and unauthorized procedures with respect
to the task being performed and each familiar with established security and safety requirements. (CNSSI
No. 4009, National Information Assurance Glossary, 26 April 2010)
330
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Two-Person Integrity. A provision that prohibits one person from working alone. (DoD 5220.22.22-M-
Sup 1, NISPOM Supplement, Feb 1995)
Two-Person Rule. A system designed to prohibit access by an individual to nuclear weapons and certain
designated components by requiring the presence at all times of at least two authorized persons, each
capable of detecting incorrect or unauthorized procedures with respect to the task to be performed.
(JP 1-02)
331
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
U
==========================================
Umbrella Special Access Program (SAP). An approved Department of Defense (DoD) Special Access
Program (SAP) that contains compartments for specific projects within the overall program. While there is
no formal requirement to obtain separate approval for each individual project under the umbrella SAP,
each project must be consistent with the Special Access Program Oversight Committee (SAPOC)-
approved scope of the umbrella SAP. The nickname, program description, and accomplishments of
each significant project will be reported in the annual Special Access Program report. Note: An individual
participant’s access can be afforded across-the-board at the umbrella level or specific individual project
access can be granted on a limited or non-umbrella level. (DSS Glossary)
Unacceptable Risk. Threat to the life, safety, or health of employees, contractors, vendors, or visitors; to
the Government’s physical assets or information systems; to personal property; to records, privileged,
proprietary, financial, or medical records; or to the privacy of data subjects, which will not be tolerated by
the Government. (DoDI 5200.02, DoD Personnel Security Program, 21 Mar 2014)
Unacknowledged SAP. A SAP [Special Access Program] having protective controls ensuring the
existence of the program is not acknowledged, affirmed, or made known to any person not authorized
for such information. (DoDD 5205.07, SAP Policy, 1 Jul 2010) Also see acknowledged SAP.
Unauthorized Access. Any access that violates the stated security policy. (CNSSI No. 4009, National
Information Assurance Glossary, 26 April 2010)
Unauthorized Disclosure. A communication or physical transfer of classified information to an
unauthorized recipient. (EO 13526, Classified National Security Information, 29 Dec 2009 and DoDD
5210.50, Unauthorized Disclosure of Classified Information to the Public, 22 Jul 2005)
Unauthorized disclosures of classified information, including media leaks, may compromise
sources and methods and pose a threat to national security.
-- ICD 701 Security Policy for Unauthorized Disclosures of Classified Information, 14 Mar 2007
-- Also, a communication or physical transfer, usually of sensitive but unclassified information or
classified information, to an unauthorized recipient. (ODNI, U.S. National Intelligence - An Overview
2011)
-- Also, an event involving the exposure of information to entities not authorized access to the
information. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
-- Also, intentionally conveying classified documents, information, or material to any unauthorized
person (one without the required clearance, access, and need to know). (AR 381-12, Threat Awareness
and Reporting Program, 4 Oct 2010)
Unauthorized disclosures of classified information put at risk the success of the most sensitive
classified operations, plans, partnerships, and technologies of DoD and our mission partners.
Personnel who disclose classified information without authorization, in addition to having potentially
committed a crime, breach the trust that we, as leaders, have placed in them.
-- SECDEF memorandum, subj: Deterring and Preventing Unauthorized Disclosures of Classified
Information, 18 Oct 2012*
332
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Unauthorized disclosure of classified information is an increasingly common occurrence.
The harm caused by… frequent unauthorized disclosures is manifold. Particular items of
information appearing in the press provide valuable intelligence for our adversaries concerning the
capabilities and plans of the United States for national defense and foreign relations…. Disclosures
about US intelligence programs are particularly damaging, because they may cause sources to dry
up. Lives of human agents are endangered and expensive technical systems become subject to
countermeasures.
--
The Willard Report, 31 March 1982
Leaking sensitive information is like giving the enemy our play book.
____________________
Each year, countless unauthorized leaks cause severe damage to our intelligence activities and
expose our capabilities. The fact of the matter is, some of the worst damage done to our
intelligence community has come not from penetration by spies, but from unauthorized leaks by
those with access to classified information…. The threat leaks pose to our national security is
alarming, and it is imperative we do more to protect our national secrets.
-- Congressman Rep. Pete Hoekstra at the Heritage Foundation, 25 July 2005.
____________________
Intelligence requires secrets. And secrecy is under assault…. When secrecy is breached, foreign
targets of US intelligence—such as adversary countries and terrorists—learn about, and then often
develop countermeasures to, US intelligence techniques and operations. As a result, the
effectiveness of intelligence declines, to the detriment of the national security policymakers and
warfighters, and the citizenry that it is meant to serve.
--
James B. Bruce, Former CIA Officer
See Bruce’s excellent article, entitled “The Consequences of Permissive Neglect: Laws and Leaks
of Classified Intelligence” in Studies of Intelligence (Vol 47 No 1), available online at:
studies/studies/vol47no1/article04.html>
____________________
Leaks are a problem that has plagued intelligence agencies throughout modern history - they can
undermine intelligence operations, jeopardize intelligence sources and methods, and have a
terrible impact on the lives of covert agents who are publicly exposed.
-- Senator Ron Wyden, cited in Senate Report 112-12, 4 April 2011, p. 12
____________________
The unauthorized release of classified documents in 2010 by major newspapers and the Wikileaks
website underscore the risks of widespread dissemination of sensitive information.
-- CRS Report RL33539, Intelligence Issues for Congress, 20 Jun 2011
____________________
In the secret operations canon it is axiomatic that the probability of leaks escalates exponentially
each time a classified document is exposed to another person—be it an Agency employee, a
member of Congress, a senior official, a typist, or a file clerk. Effective compartmentation is
fundamental to all secret activity…. The potential leaks—deliberate or accidental—is vast.
-- Richard Helms with William Hood, A Look Over My Shoulder (2003), pp.184-185
____________________
Every once in a while, there are people in the United States government who decide that they want
to break federal criminal law and release classified information, and they ought to be imprisoned.
And if we find out who they are, they will be imprisoned. Why people do it, I do not know.
-- Defense Secretary Donald Rumsfeld
____________________
333
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
When information about our intelligence, our people, or our operations appears in the media, it
does incredible damage to our nation's security and our ability to do our job of protecting the nation.
More importantly, it could jeopardize lives. For this reason, such leaks cannot be tolerated.”
-- CIA Director Leon Panetta, Nov 2010
____________________
Leaks of classified information regarding intelligence sources and methods can disrupt intelligence
operations, threaten the lives of intelligence officers and assets, and make foreign partners less
likely to work with us. The culture of leaks has to change.
-- Senator Dianne Feinstein, Chairman of the Senate Intelligence Committee, 25 July 2012
Uncertain Environment. Operational environment in which host government forces, whether opposed to
or receptive to operations that a unit intends to conduct, do not have totally effective control of the territory
and population in the intended operational area. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Uncertainty. Doubt resulting from awareness of imperfect knowledge. This may arise from information
absence, perceived error, deception, unpersuasive nature of evidence, complexity, etc. (A Handbook of
the Psychology of Intelligence Analysis, Richard L. Rees, Ph.D., Editor; n.d. - circa 2007)
In analysis, uncertainty can derive from seeing plausible alternatives to the truth (the latter of which
may be unknown or unknowable). Moreover, emotional and motivational factors attend cognitive
uncertainty. Analysts can feel anxiety or discomfort if they lack confidence or self-esteem generally,
feel an aversion to ambiguity, or have a need to please, or have a hypersensitivity to criticism. This
affective element can exist even in the presence of sufficient evidence to make a reasonable
judgment. Some analyst may well estimate the truth, but—in contrast to the inscription on the wall
of the CIA lobby (John 8:32)—the truth.
-- A Handbook of the Psychology of Intelligence Analysis, Richard L. Rees, Ph.D., Editor; n.d., p. 375
Unconventional Warfare (UW). A broad spectrum of military and paramilitary operations, normally of long
duration, predominantly conducted through, with, or by indigenous or surrogate forces who are organized,
trained, equipped, supported, and directed in varying degrees by an external source. It includes, but is not
limited to, guerrilla warfare, subversion, sabotage, intelligence activities, and unconventional assisted
recovery. (DoDD 3000.07, Irregular Warfare, 1 Dec 2008)
-- Also, activities conducted to enable a resistance movement or insurgency to coerce, disrupt, or
overthrow a government or occupying power by operating through or with an underground, auxiliary, and
guerrilla force in a denied area. (JP 3-05, Special Operations, 18 Apr 2011)
Undeclared. An officer, asset, agent, or action whose agency affiliation is not formally identified to a
foreign intelligence or security service, government or organization, or other US Government entity.
(National HUMINT Glossary)
-- Also, an individual or action whose intelligence affiliation is not disclosed. (HDI Lexicon, April 2008)
Undercover Activity. Any investigative activity involving the use of an assumed identity by an undercover
employee for an official purpose, investigative activity, or function. (FBI, Domestic Investigations and
Operations Guide, 15 Oct 2011)
Undercover Employee. An employee of the FBI, another federal, state, or local law enforcement agency,
another entity of the United States Intelligence Community (USIC), or another foreign intelligence agency
working under the direction and control of the FBI whose relationship with the FBI is concealed from third
parties by the maintenance of a cover or alias identity for an official purpose, investigative activity, or
function. (FBI, Domestic Investigations and Operations Guide, 15 Oct 2011)
334
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Undercover Operation. A phrase usually associated with the law enforcement community and which
describes an operation that is so planned and executed as to conceal the identity of, or permit plausible
denial by, the sponsor. (DSS Glossary)
Understand. The ability to individually and collectively comprehend the implications of the character,
nature, or subtleties of information about the environment and situation to aid decision-making. (Joint
Capability Areas Taxonomy & Lexicon, 15 Jan 2008)
Unified Action. The synchronization, coordination, and/or integration of the activities of governmental
and nongovernmental entities with military operations to achieve unity of effort. (JP 1, Doctrine for the
Armed Forces of the United States, 25 Mar 2013)
Unified Command Plan (UCP). The document, approved by the President, that sets forth basic guidance
to all unified combatant commanders; establishes their missions, responsibilities, and force structure;
delineates the general geographical area of responsibility for geographic combatant commanders; and
specifies functional responsibilities for functional combatant commanders. (JP 1, Doctrine for the Armed
Forces of the United States, 25 Mar 2013 and JP 1-02) Also see Combatant Command.
Six Combatant Commands (COCOMs) have geographic area responsibilities:
-- U.S. Northern Command (NORTHCOM)
-- U.S. Central Command (CENTCOM)
-- U.S. European Command (EUCOM)
-- U.S. Pacific Command (PACOM)
-- U.S. Southern Command (SOUTHCOM)
-- U.S. Africa Command (AFRICOM)
Three COCOMs that have worldwide functional responsibilities not bounded by geography:
-- U.S. Special Operations Command (SOCOM)
-- U.S. Strategic Command (STRATCOM)
-- U.S. Transportation Command (TRANSCOM)
Note: U.S. Joint Forces Command (JFCOM) was disestablished in August 2011.
For additional information, see CRS Report, The Unified Command Plan and Combatant
Commands: Background and Issues for Congress, 3 Jan 2013, copy available at:
Uniform Code of Military Justice (UCMJ). The criminal code governing the Armed Services of the United
States. (CI Community Lexicon)
UCMJ (10 USC Chapter 47), is the foundation of military law in the United States. See UCMJ
appendix in Manual for Courts-Martial (MCM): <http://www.au.af.mil/au/awc/awcgate/law/mcm.pdf >
Unilateral Operation. A clandestine activity conducted without the knowledge or assistance of a foreign
intelligence or security service, host country, foreign organization, or non-state actor. (National HUMINT
Glossary)
United States (US). Includes the land area, internal waters, territorial sea, and airspace of the United
States, including the following: a) US territories, possessions, and commonwealths; and b) Other areas
over which the US Government has complete jurisdiction and control or has exclusive authority or
defense responsibility. (JP 1-02)
-- Also, when used in a geographic sense, means all areas under the territorial sovereignty of the
United States. (FBI Domestic Investigations and Operations Guide, 15 Oct 2011)
335
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Unity of Effort. Coordination and cooperation toward common objectives, even if the participants are not
necessarily part of the same command or organization - the product of successful unified action.
(JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013 and JP 1-02)
Unknown Subject (UNSUB). The subject of an investigation, whose identity has not been determined,
commonly referred to as an “UNSUB.” Also see DoD Unknown Subject.
Unknown Subject Lead. [Within DoD,] information indicating an unidentified current or former DoD-
affiliated individual may have passed information or provided support to an FIE. (DoD Manual 5240.26, CI
Insider Threat Program, draft 20 Nov 2013)
Unload Signal. A visual signal to indicate the departure of an individual or removal of an object from a
given locale. (HDI Lexicon, April 2008)
Unsolicited Correspondence. Request for information from a person which may range from direct
inquiries by phone, e-mail, fax, or letter in which the recipient is asked to provide seemingly innocuous
data. (AR 381-12, Threat Awareness and Reporting Program, 4 Oct 2010)
Typical requests include solicitation of research papers, requests for additional information after
a public presentation, suggestions for mutual research, requests for survey participation, and so
forth; correspondence where the actual purpose may be to identify by name and position any
individual who might be targeted later by a foreign intelligence service, and to elicit targeted
information not readily obtainable by other means.
Unwitting. A person who is not aware of USG sponsorship of or affiliation with the cover. (DoDI
S-5105.63, Implementation of DoD Cover and Cover Support Activities, 20 Jun 2013) Also see witting.
-- Also, not aware of US Government sponsorship or affiliation. (National HUMINT Glossary)
-- Also, unaware of the true nature of the activities being conducted or of the intelligence connections
of persons involved. (HDI Lexicon, April 2008)
U.S. Coast Guard (USCG). A military, multi-function, maritime service that is the principal Federal agency
responsible for safety, security, and stewardship with the maritime domain. It has diverse missions:
national defense, homeland security, maritime safety, and environmental & natural resources
stewardship. In March 2003, pursuant to the Homeland Security Act, the USCG was transferred from the
Department of Transportation to the Department of Homeland Security (DHS).
The CI component of the USCG is the Coast Guard Counterintelligence Service (CGCIS).
U.S. Homeland. The physical territory of the United States: the 50 states, District of Columbia, US
territories and territorial waters; significant infrastructure linked to the United States; and major
commercial air, land and sea corridors into the country. Also see homeland.
U.S. National. US citizen and US permanent and temporary legal resident aliens. (JP 1-02)
U.S. Person (USPERS; also USP). For intelligence purposes, a US person is defined as one of the
following: 1) a US citizen; 2) an alien known by the intelligence agency concerned to be a permanent
resident alien; 3) an unincorporated association substantially composed of US citizens or permanent
resident aliens; or 4)
a corporation incorporated in the United States, except for those directed and
controlled by a foreign government or governments. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint
Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Note: A person or organization outside the United States shall be presumed not to be a USP
unless specific information to the contrary is obtained.
336
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
U.S. Secret Service (USSS). A federal law enforcement agency mandated by Congress to carry out dual
missions: protection of national and visiting foreign leaders, and criminal investigations.
The Secret Service was established in 1865, solely to suppress the counterfeiting of U.S. currency.
Headquarters in Washington, D.C. and more than 150 offices throughout the United States and
abroad. Congress transferred USSS to the Department of Homeland Security (DHS) in 2002.
Criminal investigation activities encompass financial crimes, identity theft, counterfeiting, computer
fraud, and computer-based attacks on the nation’s financial, banking, and telecommunications
infrastructure.
Protection mission is the most prominent of the two, covering the President, Vice President, their
families, former Presidents, and major candidates for those offices, along with the White House and
the Vice President’s residence (through the Service’s Uniformed Division). Protective duties of the
Service also extend to foreign missions in the District of Columbia and to designated individuals,
such as the Homeland Security Secretary and visiting foreign dignitaries.
Separate from these specific mandated assignments, USSS is responsible for certain security
activities such as National Special Security Events (NSSEs), which include the major party
quadrennial national conventions as well as international conferences and events held in the United
States.
-- See CRS Report RL34603, The U.S. Secret Service: An Examination and Analysis of Its
Evolving Missions, 31 July 2008
U.S.A. Patriot Act. USA Patriot Act of 2011 (Public Law 107-56); see Patriot Act.
337
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
V ==========================================
Validation.
[In intelligence usage], a process associated with the collection and production of intelligence
that confirms that an intelligence collection or production requirement is sufficiently important to justify the
dedication of intelligence resources, does not duplicate an existing requirement, and has not been
previously satisfied.
(JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1
dated 26 Aug 2011)
Vault. A room(s) used for the storing, handling, discussing, and/or processing of Special Access Program
(SAP) information and constructed to afford maximum protection against unauthorized entry. (DSS
Glossary)
Vehicle-Borne Improvised Explosive Device (VBIED). A device placed or fabricated in an improvised
manner on a vehicle incorporating destructive, lethal, noxious, pyrotechnic, or incendiary chemicals and
designed to destroy, incapacitate, harass, or distract. Otherwise known as a car bomb. (JP 1-02 and
JP 3-10, Joint Security Operations in Theater, 3 Feb 2010)
VENONA. Highly classified U.S. SIGINT (cryptanalysis) effort during World War II to decipher encoded
Soviet intelligence messages transmitted to Moscow on espionage activity in the United States. VENOA
traffic indicated that the Soviets had over 300 assets of various kinds inside numerous U.S. Government
agencies.
-- Also, code name for the U.S. codebreaking project that deciphered portions of the texts of Soviet
intelligence messages between Moscow and other cities in the 1940s. Most messages concerned spy
activities in the United States. (Spy Book)
I stood in the vestibule of the enemy’s house, having entered by stealth.
I held in my hand a set of keys… and we were determined to use them.
-- FBI Agent Robert J. Lamphere
________________________
VENONA decryptions of Soviet intelligence messages in the 1940s, majority during WWII, identified
numerous agents with access to the White House, Congress, and political parties, as well as agents
in the media and in high-tech defense industries, however 178 Russian code names have yet to be
linked to the true names of the American spies.
Research in Soviet Archives has added to the corroboration of some VENONA material, including
the identities of many codenamed individuals
For additional information:
Also see “In the Enemy’s House: Venona and the Maturation of American Counterintelligence” at:
Also see The FBI-KGB War: A Special Agent's Story by Robert J. Lamphere and Tom Shachtman.
Vetting. A generic term to describe the full spectrum of asset evaluation for authenticity, reliability and
hostile control. It includes ops testing, caser officer and psychological assessment, polygraph, security,
counterintelligence interview, production review and personal record questionnaires. (National HUMINT
Glossary) Also see asset validation, source validation and counterintelligence flags.
-- Also, as related to source validation, an ongoing process the purpose of which is to continually
determine, by means of specific operational acts and analytical assessments, the motivation, veracity,
and control of a reporting source. (DoDI S-3325.07, Guidance for the Conduct of DoD Human Source
Validation (U), 22 Jun 2009)
338
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the complete process of investigating and testing a potential source or information to
determine its ability and suitability for clandestine activities. (AFOSI Instruction 71-101, 6 Jun 2000)
-- Also, a process of examination and evaluation, generally referring to performing a background
check on someone before offering him or her employment, conferring an award, etc. In addition, in
intelligence gathering, assets are vetted to determine their usefulness. (en.wikipedia.org/wiki/Vetting)
“Vetting” literally means getting a sick animal examined by a veterinarian;
it has evolved into a term meaning to test or scrutinize.
-- Spy Book
__________________
Vetting is used in agent/source authentication. The vetting process is one of testing and examining
the agent to determine the degree of the agent’s/source’s reliability and truthfulness in reporting
information. It is designed to weed out fabricators and double agents.
Violent Behavior. The intentional use of physical force or power, threatened or actual, against a person or
group that either results in or has a high likelihood of injury, death, or psychological harm to self or others.
(DoDI 1438.06, DoD Workplace Violence Prevention and Response Policy 16 Jan 2014)
Violent Extremism. Individuals who openly express their religious, political, or ideological views through
violence or a call for violence. (US Army Tactical Reference Guide, Radicalization into Violent
Extremism: A Guide for Military Leaders, Aug 2011) Also see radicalization, terrorism, violent
radicalization.
--Also, any ideology that encourages, endorses, condones, justifies, or supports the commission of a
violent act or crime… to achieve political, social, or economic changes…. (FBI Counterterrorism Analytical
Lexicon)
-- Also, the process of adopting or promoting an extremist belief system for the purpose of facilitating
ideologically based violence to advance political, religious, or social change. (House Bill 1955, 110th
Congress, 24 Oct 2007)
Copy of Army reference cited above available at:
1326399638300> Reference also at:
_____________________
The Complexity of Violent Extremism
The threat posed by violent extremism is neither constrained by international borders nor limited to
any single ideology. Groups and individuals inspired by a range of religious, political, or other
ideological beliefs have promoted and used violence against the homeland.
Increasingly sophisticated use of the Internet, mainstream and social media, and information
technology by violent extremists adds an additional layer of complexity.
-- Department of Homeland Security
_____________________
“Violent extremism presents one of the greatest threats to
the citizenry of the United States and its allies.”
-- Edges of Radicalization, Combating Terrorism Center, Feb 2012, p. 6
339
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Violent Jihadist. The term characterizes jihadists who have made the jump to illegally supporting,
plotting, or directly engaging in violent terrorist activity. (CRS Report R41416, 23 Jan 2013)
American Jihadist Terrorism: Combating a Complex Threat, CRS Report R41416, 23 Jan 2013
Violent Radicalization. The process of adopting or promoting an extremist belief system for the purpose
of facilitating ideologically based violence to advance political, religious, or social change. (House Bill
1955, 24 Oct 2007) Also see radicalization, terrorism, violent extremism.
Virus. Malicious software; a form of Trojan horse that reproduces itself in other executable code. (DoD
5220.22.22-M-Sup 1, NISPOM Supplement, Feb 1995) Also see computer virus.
-- Also, a computer program that can copy itself and infect a computer without permission or
knowledge of the user. A virus might corrupt or delete data on a computer, use e-mail programs to spread
itself to other computers, or even erase everything on a hard disk. (CNSSI No. 4009, National Information
Assurance Glossary, 26 April 2010)
-- Also, a software program, script, or macro that has been designed to infect, destroy, modify, or
cause other problems with a computer or software program. (US Army TRADOC DCSINT Handbook
1.02, 15 Aug 2007)
A virus is a computer program file capable of attaching to disks or other files and replicating itself
repeatedly, typically without user knowledge or permission. Some viruses attach to files so when
the infected file executes, the virus also executes. Other viruses sit in a computer's memory and
infect files as the computer opens, modifies, or creates the files. Some viruses display symptoms,
and others damage files and computer systems, but neither is essential in the definition of a virus;
a non-damaging virus is still a virus.
- McAfee.com; accessed 15 Nov 2010
Volunteer. A person who initiates contact with a government, and who volunteers operational or
intelligence information and/or request political asylum; includes call-ins, walk-ins, virtual walk-ins,
and write-ins. (National HUMINT Glossary)
Vulnerability.
1) The susceptibility of a nation or military force to any action by any means through
which its war potential or combat effectiveness may be reduced or its will to fight diminished; 2). The
characteristics of a system that cause it to suffer a definite degradation (incapability to perform the
designated mission) as a result of having been subjected to a certain level of effects in an unnatural
(man-made) hostile environment; and 3) In information operations, a weakness in information system
security design, procedures, implementation, or internal controls that could be exploited to gain
unauthorized access to information or an information system. (JP 1-02 and JP 3-60, Joint Targeting,
13 Apr 2007)
-- Also, a situation or circumstance, which left unchanged, may result in the degradation, loss of life,
or damage to mission-essential resources. (DoD 5200.08-R, Physical Security Program, 9 Apr 2007)
-- Also, a weakness or susceptibility of an installation, system, asset, application, or its dependencies
that could cause it to suffer a degradation or loss (incapacity to perform its designated function) as a
result of having been subjected to a certain level of threat or hazard. (DoDD 3020.40, DoD Policy and
Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, a physical feature or operational attribute that renders an entity open to exploitation or
susceptible to a given hazard. (DHS, National Infrastructure Protection Plan - 2009)
Vulnerability Analysis. A process that examines a friendly operation or activity from the point of view of
an adversary, seeking ways in which the adversary might determine critical information in time to disrupt
or defeat the operation or activity. (DoD 5205.02-M, DoD OPSEC Program Manual, 3 Nov 2008)
340
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Vulnerability Assessment (VA). A Department of Defense, command, or unit-level evaluation
(assessment) to determine the vulnerability of a terrorist attack against an installation, unit, exercise, port,
ship, residence, facility, or other site. Identifies areas of improvement to withstand, mitigate, or deter acts
of violence or terrorism. (JP 1-02 and JP 3-07.2, Antiterrorism, 24 Nov 2010)
-- Also, [regarding infrastructure] a systematic examination of the characteristics of an installation,
system, asset, application, or its dependencies to identify vulnerabilities. (DoDD 3020.40, DoD Policy and
Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, the comprehensive evaluation of an installation, facility, or activity to determine preparedness
to deter, withstand, and /or recover from the full range of adversarial capabilities based on the threat
assessment, compliance with protection standards, and risk management. (DoD 5200.08-R, Physical
Security Program, 9 Apr 2007)
-- Also, the process of identifying weaknesses in the protection of friendly operations and activities
which, if successfully exploited by foreign intelligence, could compromise current or future plans,
capabilities, or activities, including RDA [research, development and acquisition]. (AR 381-20, Army CI
Program, 25 May 2010)
Vulnerability Study. An analysis of the capabilities and limitations of a force in a specific situation to
determine vulnerabilities capable of exploitation by an opposing force. (JP 1-02)
341
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
W =========================================
Waived Special Access Program. A SAP [Special Access Program] for which the Secretary of Defense
has waived applicable reporting in accordance with [Section 119 of Title 10 US Code] following a
determination of adverse effect to national security. An unacknowledged SAP that has more restrictive
reporting and access controls. (DoDD 5205.07, SAP Policy, 1 Jul 2010)
-- Also, an unacknowledged Special Access Program (SAP) to which access is extremely limited in
accordance with the statutory authority of Section 119e of 10 United States Code (U.S.C), Reference b.
The unacknowledged SAP protections also apply to Waived SAPs. Only the Chairman, Senior Minority
member, and, by agreement, their Staff Directors of the four Congressional Defense Committees normally
have access to program material.
Waiver. An exemption from a specific requirement. (DSS Glossary)
Walk-in. An unsolicited contact who provides information. (JP 1-02; JP 2-01.2, CI & HUMINT in Joint
Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011; DoDI S-5240.17, CI Collection Activities, 14 Mar
2014; and DHE-M 3301.002, Vol II Collections Operations, 23 Nov 2010) Also see volunteer.
-- Also, an individual who voluntarily offers his services or information to a foreign government.
(FBI FCI Terms)
-- Also, an individual who offer his/her services to an intelligence service without being solicited.
(CIA, D&D Lexicon, 1 May 2002)
-- Also, someone who has something to offer or sell to the intelligence service he is approaching:
a volunteer spy. (A Spy’s Journey)
Individuals who walk-in and provide information or offer to assist are motivated by a wide range of
factors, including a sincere desire to help, pure greed, desire for revenge against some real or
perceived grievance, etc. Each walk-in interview is unique.
__________________
In the real world of secret operations volunteers have produced some of the greatest coups.
“It’s the walk-in trade that keeps the shop open” is one of the first bits of operational
wisdom impressed on newcomers to the business.
-- William Hood, Mole: The True Story of the First Russian Intelligence Officer Recruited by the CIA (1982)
__________________
As always with a “walk-in,” as we irreverently referred to volunteer agents, the first
consideration is the possibility of provocation.
-- Richard Helms with William Hood, A Look Over My Shoulder: A Life in the Central Intelligence Agency
(2003), p. 219
__________________
[Walk-in] applies universally to agents who volunteer their services to a hostile intelligence agency
by making an approach to an adversary at its premises. The KGB recognized that some of its best
sources including John Walker, Aldrich Ames, and Robert Hanssen, acted in this way, but did not
use the same term, preferring “self-recruited agents.
-- Historical Dictionary of Cold War Counterintelligence (2007)
For the story of a walk-in, see Barry G. Royden, "Tolkachev, A Worthy Successor to Penkovsky,"
Studies in Intelligence, v 47, n 3: pp. 5-33. Full article available at:
center-for-the-study-of-intelligence/csi-publications/csi-studies/studies/vol47no3/article02.html>
__________________
342
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
…it should be emphasized once more that work with “walk-ins” is an important part of
agent operations for strategic intelligence and when properly planned and conducted can
be very fruitful.
-- Ivan A. Serov, GRU General (1962)
See Ivan A. Serov, “Work with Walk-Ins,”* Studies in Intelligence, Vol 8, No, 1. This article,
originally published in 1962, is adapted from one of several on Soviet intelligence doctrine written
by high-ranking officers of the GRU (Soviet Military Intelligence). The article shows that
Soviet/Russian problems in assessing and handling the walk-in are not unlike our own. The full
csi/vol8no1/html/v08i1a02p_0001.htm >
* Note: Russian term dobrozhelatel ("well-wisher") is virtually the same as our "walk-in."
Warning. 1) A communication and acknowledgment of dangers implicit in a wide spectrum of activities by
potential opponents ranging from routine defense measures to substantial increases in readiness and
force preparedness and to acts of terrorism or political, economic, or military provocation; and 2)
operating procedures, practices, or conditions that may result in injury or death if not carefully observed or
followed. (JP 1-02) Also see warning intelligence.
-- Also, a communication and acknowledgment of dangers implicit in a wide spectrum of activities by
potential opponents ranging from routine defense measures to substantive increases in readiness and
force preparedness and to acts of terrorism or political, economic, or military provocation. (DoDD
3115.16, The Defense Warning Network,5 Dec 2013)
-- Also, to issue an advance notification of possible harm or victimization following the receipt of
information or intelligence concerning the possibility of a crime or terrorist attack. (ODNI, U.S. National
Intelligence - An Overview 2011)
Warning Intelligence. Those intelligence activities intended to detect and report time sensitive intelligence
information on foreign developments that forewarn of hostile actions or intention against United States
entities, partners, or interests. (JP 2-0, Joint Intelligence, 22 Oct 2013)
Watch List. A list of words -- such as names, entities, or phrases -- which can be employed by a
computer to select out required information from a mass of data. (Senate Report 94-755, Book I -
Glossary, 26 Apr 1976)
Weapon System. A combination of one or more weapons with all related equipment, materials, services,
personnel, and means of delivery and deployment (if applicable) required for self-sufficiency. (DoDI
5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems and Networks, 5 Nov 2012)
Weapons of Mass Destruction (WMD). Chemical, biological, radiological, or nuclear weapons capable of
a high order of destruction or causing mass casualties and exclude the means of transporting or
propelling the weapon where such means is a separable and divisible part from the weapon. (JP 1-02 and
JP 3-40, Combating WMD, 10 Jun 2009)
Specifically defined in US Code as: (1) any explosive, incendiary, or poison gas, bomb, grenade,
rocket having a propellant charge of more than 4 ounces, or missile having an explosive or
incendiary charge of more than one-quarter ounce, or mine or similar device; (2) any weapon that
is designed or intended to cause death or serious bodily injury through the release, dissemination,
or impact of toxic or poisonous chemicals or their precursors; (3) any weapon involving a disease
organism; or (4) any weapon that is designed to release radiation or radioactivity at a level
dangerous to human life. (18 USC 18 §2332a)
343
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
White List. The identities and locations of individuals who have been identified as being of intelligence or
counterintelligence interest and are expected to be able to provide information or assistance in existing or
new intelligence areas of interest. (CI Community Lexicon) Also see Black List; Gray List.
White lists contain the identities and locations of individuals in enemy controlled areas. These
individuals are of intelligence or CI interest. They are expected to be able to provide information or
assistance in the accumulation of intelligence data or in the exploitation of existing or new
intelligence areas of interest. They are usually in accord with or favorably inclined toward U.S.
policies. Their contributions are based on a voluntary and cooperative attitude. Decisions to place
individuals on the white list may be affected by the combat situation, critical need for specialists in
scientific fields, and such intelligence needs as indicated from time to time.
Examples of individuals included in this category are:
1) Deposed political leaders of a hostile state.
2) Intelligence agents employed by U.S. or allied intelligence agencies.
3) Key civilians in areas of scientific research, including faculty members of universities and
staffs of industrial or national research facilities whose credibility have been established.
-- USMC, MCWP 2-6 (previously 2-14), Counterintelligence, 5 Sep 2000
Wilderness of Mirrors. The organizational culture of the secret services. In it deceptions are false, lies are
truth, the reflections are illuminating and confusing. The phrase centers on the problem of the reliability of
the secret information about espionage and the identity of spies. The mirrors comprise information from
defectors, disinformation from the opposing sides in the Cold War, deviously covered false trails, and
facts thought to be valid but incomplete (and later established as totally untrue). (Encyclopedia of Cold
War Espionage, Spies, and Secret Operations, 3rd edition, 2012)
-- Also, expression to sgnify the confusion of the world of intelligence and espionage. James Jesus
Angleton, long-time head of counterespionage for the CIA, is generally credited with coining the term,
having written that the Wilderness of Mirrors “is that… myriad of strategms, deceptions, artifices and all
other devices of disinformation which the Soviet bloc and its coordinated intelligence services use to
confuse and split the West,” thus producing “an ever-fluid landscape where fact and illusion merge….”
(Spy Book)
Wilderness of Mirrors” a description of counterintelligence attributed to James J. Angleton. It
comes from T.S. Eliot’s poem “Gerontion” (1920); also the title of a 1980 book authored by David
C. Martin about CIA counterintelligence (New York: HarperCollins, First Edition, 1980).
Angleton was CIA’s Chief of the Counterintelligence from 1954 until his retirement in 1974. In
December 1974, Angleton was basically forced into retirement by the Director of CIA (William
Colby), who became convinced that Angleton’s “labyrinthine” approach to counterintelligence
severely hampered the Agency’s primary mission -- clandestine HUMINT collection.
Window Dressing. [Tradecraft jargon] Ancillary materials that are included in a cover story or deception
operation to help convince the opposition or casual observers that what they are observing is genuine.
(CI Centre Glossary)
Witting. A term of intelligence art that indicates that one is not only aware of a fact or piece of information
but also aware of its connection to intelligence activities. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint
Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011) Also see unwitting.
-- Also, a person is aware of USG sponsorship or affiliation. (National HUMINT Glossary)
-- Also, aware of the true nature of the activities being conducted or of the intelligence connections
of persons involved. (HDI Lexicon, April 2008)
-- Also, knowledgeable as to certain aspects of a clandestine organization and its activities.
(AFOSI Manual 71-142, OFCO, 9 Jun 2000)
344
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Workplace Violence. Any act of violent behavior, threats of physical violence, harassment, intimidation,
bullying, verbal or non-verbal threat, or other threatening, disruptive behavior that occurs at or outside the
work site. (DoDI 1438.06, DoD Workplace Violence Prevention and Response Policy 16 Jan 2014)
Worm. A self-replicating, self-propagating, self-contained program that uses networking mechanisms
to spread itself. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010) See worms.
-- Also, a type of malware that spreads automatically over a network, installing and replicating itself.
The network traffic from rapid replication and spread can cripple networks even when the malware does
not have a malicious payload. (Cybersecurity and Cyberwar)
A worm is an unwanted software program secretly planted on a computer that enables (among
other things) someone other than the owner to control it.
In 2009, cyber security analysts worldwide reported that a “worm” called Stuxnet had penetrated
and, in all likelihood, damaged an Iranian nuclear facility. The attack was apparently prosecuted
through the facility’s industrial control system.
-- RAND Report, A Cyberworm that Knows No Boundaries, 2011* (see Appendix B - Worms)
Worms. Parasitic computer programs that replicate, but unlike viruses, do not infect other computer
program files. Worms can create copies on the same computer, or can send the copies to other
computers via a network. Worms often spread via Internet Relay Chat (IRC). (McAfee.com; accessed
15 Nov 2010) See worm.
Write for Maximum Utility (WMU). An approach that guides the way that intelligence organizations
conceive, format, produce, and disseminate intelligence products in order to increase their usability
for the intended customers. (ICD 208, 17 Dec 2008) Also see write-to-release.
Utility is maximized when customers receive or are able to expeditiously discover and pull or
request intelligence, information, and analysis in a form they are able to easily use and able to
share with their colleagues, subordinates, and superiors. WMU ensures intelligence, information,
and analysis are produced in a manner to facilitate reuse—either in its entirety or in coherent
portions—thereby enabling wider dissemination and enhancing its usability.
WMU shares certain goals as well as techniques with previous and ongoing IC WTR [write-to-
release] efforts. WMU goes further than WTR in linking knowledge of the customer’s operating
environment to the intelligence production effort. The resulting effort is not “one size fits all” or
production of all intelligence products at the lowest classification, but products tailored to best meet
a customer’s requirements. This may mean producing the definitive assessment on a given topic
area based on all available intelligence, regardless of classification.
-- ICD 208, Write for Maximum Utility, 17 Dec 2008
Write-to-Release (WTR). A general approach whereby intelligence reports are written in such a way that
sources and methods are protected so that the report can be distributed to customers or intelligence
partners at lower security levels. In essence, write-to-release is proactive sanitization that makes
intelligence more readily usable by a more diverse set of customers. The term encompasses a number
of specific implementation approaches, including sanitized leads and tearline reporting. (ICD 208, 17 Dec
2008) Also see tearline reporting and write for maximum utility.
Written Statement. Permanently record of pretrial testimony of accused persons, suspects, victims,
complaints, and witnesses. (FM 19-20, Law Enforcement Investigations, Nov 1985)
Written statements may be used in courts as evidence attesting to what was told investigators.
They also are used to refresh the memory of the persons making the statements.
-- FM19-20, Law Enforcement Investigations, Nov 1985, p. 53
345

 

 

 

 

 

 

 

Content      ..     10      11      12      13     ..