20.2 Operations Security (AFH-1 Section 18B)

Key Takeaways

  • The purpose of operations security is to reduce the vulnerability of USAF missions by eliminating or reducing successful adversary collection and exploitation of critical information.
  • The OPSEC cycle consists of five actions: identify critical information, analyze threats, analyze vulnerabilities, assess risk, and apply appropriate operations security countermeasures.
  • The five basic characteristics of OPSEC indicators are signatures, associations, profiles, contrasts, and exposure.
  • A profile is the sum of an activity's signatures and associations; a contrast is any difference between an activity's standard profile and its current actions.
  • Exposure refers to when and for how long an indicator is observed — the longer it is observed, the better an adversary can form associations and update the profile.
Last updated: August 2026

Purpose of the USAF Operations Security Program

AFH 1 states the purpose in one sentence: the purpose of operations security is to reduce the vulnerability of USAF missions by eliminating or reducing successful adversary collection and exploitation of critical information. The verbs are eliminating or reducing. The object is adversary collection and exploitation, not the information itself. OPSEC does not replace classification. It denies an adversary the ability to assemble observations — many unclassified — into something useful in time to act.

Operations security uses a cycle to identify, analyze, and control critical information that applies to all activities used to prepare, sustain, or employ forces during all phases of operations. USAF personnel can be under observation at their peacetime bases and locations, in training or exercises, while moving, or when deployed and conducting combat operations. For an SSgt or TSgt, a predictable home-station routine is as much an OPSEC problem as a deployed convoy brief.

Profiling and Signature Management

USAF units use a profiling process to identify vulnerabilities and indicators of their day-to-day activities. Operations security program managers and signature managers then use the signature management methodology to apply measures or countermeasures to hide, control, or simulate indicators. Signature managers also recommend modifying day-to-day activities to create variations in the status quo. Simulate is a legitimate countermeasure, not merely concealment. Predictable patterns are themselves a vulnerability.

AFH 1 says operations security involves attentiveness to three tasks: identify those actions that can be observed by adversary intelligence systems; determine what specific indications could be collected, analyzed, and interpreted to derive critical information in time to be useful to adversaries; and select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation. The qualifier in time to be useful to adversaries matters. Information that arrives too late to affect the mission is not the same risk as information that arrives while the adversary can still act.

Operational Effectiveness

Operations security involves a series of analyses to examine the planning, preparation, execution, and post-execution phases of any operation or activity across the entire spectrum of military action and in any operational environment. Post-execution is in the list. After-action photos and recovery patterns can still reveal how a unit deploys and reconstitutes.

OPSEC analysis lets decision-makers weigh the risk to their operations and decide how much risk to accept, as operational risk management does in mission planning. Operational effectiveness is enhanced when commanders and other decision-makers apply operations security from the earliest stages of planning. Operations security principles must be integrated into operational, support, exercise, acquisition planning, and day-to-day activities so the transition to contingency operations is seamless.

The Operations Security Cycle

AFH 1 lists five distinct actions. Learn them in this order. Do not confuse them with the five-step risk management process; the OPSEC cycle splits threat analysis and vulnerability analysis.

StepDistinct action in the OPSEC cycle
1Identify critical information
2Analyze threats
3Analyze vulnerabilities
4Assess risk
5Apply appropriate operations security countermeasures

Critical information is what the adversary needs to plan against friendly forces. Analyze threats asks who is watching. Analyze vulnerabilities asks which friendly actions give that collector a path. Assess risk comes before anyone selects a countermeasure. Apply appropriate operations security countermeasures is the hide, control, or simulate step — last, not first. Example: a deployment window (critical information), family social media (threat/open source), a shared calendar photo (vulnerability), and changing posts or simulating a different pattern (countermeasure).

Operations Security Indicators

Operations security indicators are friendly, detectable actions and open-source information that can be interpreted or pieced together by an adversary to derive critical information. They are friendly (our actions), detectable, and include open-source information. The danger is that they can be pieced together, not that any one of them is classified.

AFH 1 names five basic characteristics of operations security indicators that make them potentially valuable to an adversary.

CharacteristicAFH 1 definition
SignaturesObservable activities and operational trends that reveal critical information to adversary intelligence collection. Signature management identifies, prioritizes, and manages physical, technical, and administrative indicators of friendly operational profiles that, if ignored, will be exploited. Defense of those profiles is accomplished by denying adversary collection of critical information
AssociationsThe relationship of an indicator to other information or activities. Characteristics of the relationship make it identifiable or cause it to stand out
ProfilesEach functional activity generates more-or-less unique signatures and associations. The sum of these signatures and associations is the activity's profile. Profiling maps the local operating environment and captures process points with critical information value
ContrastsAny difference observed between an activity's standard profile and most recent or current actions
ExposureWhen and for how long an indicator is observed. The longer an indicator is observed, the better chance an adversary can form associations and update the profile of operational activities

The five build on one another: a signature is one observable activity; an association relates it to other information; a profile is the sum of signatures and associations; a contrast breaks that picture; exposure is duration. SSgts and TSgts own the section's status quo — name the critical information, shorten exposure, and vary routines.

Test Your Knowledge

What are the five actions in the operations security cycle, in the order AFH 1 lists them?

A
B
C
D
Test Your Knowledge

Which characteristic of an OPSEC indicator does AFH 1 define as the sum of an activity's signatures and associations?

A
B
C
D
Test Your Knowledge

According to AFH 1, why does the duration of an indicator's observation matter?

A
B
C
D