16.2 Operations Security (OPSEC)
Key Takeaways
- The purpose of OPSEC is to reduce the vulnerability of Air Force missions by eliminating or reducing successful adversary collection and exploitation of critical information.
- The OPSEC cycle consists of five actions: identify critical information, analyze threats, analyze vulnerabilities, assess risk, and apply appropriate countermeasures.
- The five basic characteristics of OPSEC indicators are signatures, associations, profiles, contrasts, and exposure.
- A profile is the sum of an activity's signatures and associations; a contrast is any difference between an activity's standard profile and its current actions.
- Exposure refers to when and for how long an indicator is observed — the longer it is observed, the better an adversary can form associations and update the profile.
What OPSEC Is For
AFH 1 states the purpose in one sentence: "The purpose of operations security is to reduce the vulnerability of USAF missions by eliminating or reducing successful adversary collection and exploitation of critical information."
Notice the two verbs — eliminating or reducing — and the object: adversary collection and exploitation, not the information itself. OPSEC does not classify information; it denies an adversary the ability to assemble unclassified observations into something useful.
OPSEC uses a cycle to identify, analyze, and control critical information that applies to all activities used to prepare, sustain, or employ forces during all phases of operations.
The scope is deliberately broad: "USAF personnel can be under observation at their peacetime bases and locations, in training or exercises, while moving, or when deployed and conducting combat operations." OPSEC is not a deployment-only concern.
Profiling and Signature Management
AFH 1 describes the working method:
- USAF units utilize a profiling process to identify vulnerabilities and indicators of their day-to-day activities
- Operations security program managers and signature managers use the signature management methodology to apply measures or countermeasures to hide, control, or simulate indicators
- Signature managers also recommend modifying day-to-day activities at an installation or organization to create variations in the status quo
Three verbs to hold: countermeasures hide, control, or simulate indicators. Simulate is the one candidates forget — deception is a legitimate OPSEC countermeasure, not merely concealment.
"Creating variations in the status quo" is the same logic as the Random Antiterrorism Measures Program in Section 18E: predictability is itself a vulnerability.
The Three Things OPSEC Requires Attention To
AFH 1 lists what OPSEC "involves attentiveness to":
- Identify those actions that can be observed by adversary intelligence systems
- Determine what specific indications could be collected, analyzed, and interpreted to derive critical information in time to be useful to adversaries
- Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation
The qualifier in the second item is important: "in time to be useful to adversaries." Information that reaches an adversary too late to act on is not the same risk as information that arrives in time.
Operational Effectiveness
OPSEC "involves a series of analyses to examine the planning, preparation, execution, and post-execution phases of any operation or activity across the entire spectrum of military action and in any operational environment." Four phases — and post-execution is included, which candidates often miss.
AFH 1 draws an explicit parallel to Chapter 17: "Operations security analysis provides decision-makers with a means of weighing the risk to their operations. Decision-makers must determine the amount of risk they are willing to accept in particular operational circumstances in the same way as operational risk management allows commanders to assess risk in mission planning."
And the timing rule: "Operational effectiveness is enhanced when commanders and other decision-makers apply operations security from the earliest stages of planning" — the same "integrate early" principle as risk management.
The OPSEC Cycle — Five Distinct Actions
OPSEC principles "must be integrated into operational, support, exercise, acquisition planning, and day-to-day activities to ensure a seamless transition to contingency operations."
| Step | Action |
|---|---|
| 1 | Identify critical information |
| 2 | Analyze threats |
| 3 | Analyze vulnerabilities |
| 4 | Assess risk |
| 5 | Apply appropriate operations security countermeasures |
The order is testable. Note that threats are analyzed before vulnerabilities, and that risk assessment sits between analysis and countermeasures — you cannot select a countermeasure until you have weighed the risk.
Compare it to the five-step risk management process in Section 17F (identify hazards → assess hazards → develop controls and make decisions → implement controls → supervise and evaluate). Both are five steps, both start with identification, and both end with action — but the OPSEC cycle splits threat and vulnerability analysis into separate steps, which the RM process combines into a single assessment. The exam sometimes offers RM steps as distractors on an OPSEC question, so keep the two lists distinct.
OPSEC Indicators
"Operations security indicators are friendly, detectable actions and open-source information that can be interpreted or pieced together by an adversary to derive critical information."
Every word in that definition does work. Indicators are friendly (our own actions), detectable, and include open-source information — and the threat is that they can be pieced together, not that any one of them is secret.
The Five Basic Characteristics
| Characteristic | AFH 1's definition |
|---|---|
| Signatures | "Observable activities and operational trends that reveal critical information to adversary intelligence collection." Signature management is "a systematic approach to identify, prioritize, and manage physical, technical, and administrative indicators of friendly forces' operational profiles that, if ignored, will be exploited by an adversary." Defense of operational profiles is accomplished by implementing measures to deny adversary collection of critical information |
| Associations | "The relationship of an indicator to other information or activities." The characteristics of the relationship make it identifiable or cause it to stand out |
| Profiles | "Each functional activity generates its own set of more-or-less unique signatures and associations. The sum of these signatures and associations is the activity's profile." A profiling process maps the local operating environment and captures process points that present key signatures and profiles with critical information value |
| Contrasts | "Any difference observed between an activity's standard profile and most recent or current actions" |
| Exposure | "When and for how long an indicator is observed. The longer an indicator is observed, the better chance an adversary can form associations and update the profile of operational activities" |
How the Five Fit Together
They are not five parallel items — they build on one another, and understanding the structure makes the definitions unmistakable:
- A signature is a single observable activity or trend
- An association is the relationship between that indicator and other information
- A profile is the sum of signatures and associations for an activity
- A contrast is a change from that profile
- Exposure is the time dimension — how long the adversary gets to watch
Worked example. A squadron's normal pattern is aircraft launching between 0800 and 1600 with the dining facility busiest at 1130 (signatures). Increased late-night maintenance activity correlating with additional fuel truck movements is an association. Together, the squadron's routine constitutes its profile. When the squadron suddenly begins launching at 0300 and the base exchange sells out of certain supplies, that departure from the norm is a contrast. And the fact that an observer parked outside the gate can watch all of this for weeks is exposure.
The most commonly missed pair is profile versus contrast. A profile is the baseline; a contrast is the deviation from it. An item describing "the sum of an activity's signatures and associations" is keyed to profile; one describing "a difference between the standard pattern and current actions" is keyed to contrast.
And remember the OPSEC guidance from Chapter 15: because social media magnifies reach, it brings increased risk of magnifying operational security lapses, and even unclassified information, when brought together with other information, can create problems when in the wrong hands. That aggregation problem is exactly what indicators describe.
What are the five actions in the operations security cycle, in order?
Which characteristic of an OPSEC indicator is defined as the sum of an activity's signatures and associations?
According to AFH 1, why does the duration of an indicator's observation matter?