Military reference books and manuals (2009-2023, Volume 4) - page 8

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 4)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     6      7      8      9     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 4) - page 8

 

 

Domestic Operational Law Handbook 2021
be State’s TAG; the Deputy Chief of Staff for Operations; the Plans, Operations, and Training Officer;
and the Task Force or other commanders.
4.
Training
Judge advocates should seek opportunities to assist trainers responsible for ensuring that individual
members learn and apply the correct standards for force. In this role, they can write or assist in writing
information papers, training vignettes, and legal memoranda. Also, the use of a training certification
process may be useful.
E. Conclusion
When the NG operates in a State status, either Title 32 or SAD, the rules for the use of force are based
on the State law where the mission is taking place. Developing these rules for the use of force requires
knowledge of the relevant State law, including the level of law enforcement authority given to the NG,
and the criminal laws relating to self-defense. Judge advocates providing advice on the drafting of the
RUF must also tailor their RUF to the specific mission, and determine the appropriate level of
coordination with the State Attorney General’s Office, the local district attorney, and other law
enforcement agencies. Finally, judge advocates should assist commanders in developing appropriate
training so that all NG service-members are fully aware of the State’s RUF prior to engaging in
operations.
Chapter 11
243
RUF for the National Guard
Domestic Operational Law Handbook 2021
Chapter 11
RUF for the National Guard
244
Domestic Operational Law Handbook 2021
CHAPTER 12
FUNDING DOMESTIC OPERATIONS
KEY REFERENCES:
10 U.S.C. §§ 271-284 - Military Support for Civilian Law Enforcement Agencies.
10 U.S.C. §§ 251-255 - Insurrection Act.
10 U.S.C. § 2012 - Support and Services for Eligible Organizations and Activities Outside
Department of Defense (Innovative Readiness Training Program).
10 U.S.C. § 2551 - Equipment and Barracks: National Veterans’ Organizations.
10 U.S.C. § 2552 - Equipment for Instruction and Practice: American Red Cross.
10 U.S.C. § 2554 - Equipment and Other Services: Boy Scout Jamborees.
10 U.S.C. § 2555 - Transportation Services: International Girl Scout Events.
10 U.S.C. § 2556 - Shelter for Homeless; Incidental Service.
10 U.S.C. § 2558 - National Military Associations; Assistance at National Conventions.
10 U.S.C. § 2564 - Provision of Support for Certain Sporting Events.
10 U.S.C. § 2576 - Surplus Military Equipment: Sale to State and Local Law Enforcement,
Firefighting, Homeland Security, and Emergency Management Agencies.
10 U.S.C. § 2667 - Leases: Non-Excess Property of Military Departments and Defense Agencies.
18 U.S.C. § 1385 - Posse Comitatus Act.
31 U.S.C. § 1301 - The Purpose Statute.
31 U.S.C. §§ 1341-44, 1350-51, 1511-19 - Amount and the Anti-Deficiency Act.
31 U.S.C. § 1502 - The Time Statute.
31 U.S.C. § 1535 - Economy Act.
31 U.S.C. § 3302 - Miscellaneous Receipts.
32 U.S.C. § 112 - Drug Interdiction and Counter-Drug Activities.
42 U.S.C. § 5121, et seq., as amended - Stafford Act.
50 U.S.C. § 2311 - Response to Threats of Terrorist Use of Weapons of Mass Destruction
National Defense Authorization Act for Fiscal Year 1991, Pub. L. No. 101-510, § 1004 (as
amended, Additional Support for Counter-Drug Activities).
Department of Defense Appropriations Act, 1994, Pub. L. No. 103-139, § 8131 (Emergency
Response Fund, Defense).
Omnibus Consolidated Appropriations Act, 1997, Pub. L. No. 104-208, § 5802 (Support to
International Sporting Competitions - Defense).
National Defense Authorization Act for Fiscal Year 1997, Pub. L. No. 104-201, § 1031, (as
amended, Authority to Provide Additional Support for Counter-Drug Activities of Mexico).
National Defense Authorization Act for Fiscal Year 1998, Pub. L. No. 105-85, § 1033 (Authority
to provide Additional Support for Counter-Drug Activities of Peru and Colombia).
National Defense Authorization Act for Fiscal Year 2002, Pub. L. No. 107-107, § 1021 (Extension
and Restatement of Authority to Provide Department of Defense Support for Counter-Drug
Activities of other Governmental Agencies).
National Defense Authorization Act for Fiscal Year 2002, Pub. L. No. 107-107, § 302, Working
Capital Funds.
National Defense Authorization Act for Fiscal Year 2003, Pub. L. No. 107-248, Title II Operation
and Maintenance.
Chapter 12
245
Funding Domestic Operations
Domestic Operational Law Handbook 2021
National Defense Authorization Act for Fiscal Year, 2009, Pub. L. No 110- 417, Subtitle C,
Counter Drug Activities.
Department of Defense Appropriations Act, 2010, Pub. L. No. 111-118.
National Defense Authorization Act for Fiscal Year 2011, Pub. L. No 111-383.
National Defense Authorization Act for Fiscal Year 2020, Pub. L. No 116-92.
DoDD 3025.18 - Defense Support of Civil Authorities, September 21, 2012 (C2, March 18, 2018).
DoDD 5200.31E - DoD Military Working Dog (MWD) Program, August 10, 2011 (Incorporating
Change 1, Effective September 21, 2020).
DoD Manual 3025.1, Vol. 1, Defense Support to Civil Authorities: Overview, Incorporating
Change 1, April 13, 2017.
DoD Manual 3025.01, Vol. 2. Defense Support of Civil Authorities: DoD Incident Response (11
Aug. 2016) (Ch.1 13 Apr. 2017).
DoD Manual 3025.01, Vol. 3, Defense Support of Civil Authorities: Pre-Planned DoD Support of
Law Enforcement Agencies, Special Events, Community Engagement, and other Non-DoD Entities
(11 Aug. 2016) (Ch. 1 13 Apr. 2017).
DoDI 1100.24 - Innovative Readiness Training (IRT): Support and Services for eligible
Organizations and Activities Outside DoD, May 5, 2020.
DoDI 3025.20 - Defense Support of Special Events, April 6, 2012 (C1, May 24, 2017).
DoDI 3025.21, Defense Support of Civilian Law Enforcement Agencies, February 27, 2013,
Incorporating Change 1, Effective February 8, 2019.
DoD Financial Management Regulation (FMR) 7000.14-R vol. 14 - Administrative Control of
Funds and Anti-Deficiency Act Violations.
DoD Financial Management Regulation (FMR) 7000.14-R, vol.12, ch. 6 - Defense Emergency
Response Fund.
CJCSI 3710.01B, DoD Counterdrug Support, January 26, 2007 (current as of June 12, 2014).
CNGBI 3000.04 - NG Bureau Domestic Operations, January 24, 2018.
NGR 500-2/ANGI 10-801, National Guard Counterdrug Support, August 28, 2008 (Currently
under re-write as a CNGB Manual. Check for publishing at end of FY21).
NGR 500-5/ANGI 10-208, National Guard Domestic Law Enforcement Support and Mission
Assurance Operations, August 18, 2010.
AR 75-14/OPNAVINST 8027.7/AFI 32-3002-0/MCO 8027.1E, Inter-Service Responsibilities for
Explosive Ordnance Disposal, March 17, 2020.
AR 75-15, Policy for Explosive Ordnance Disposal, December 17, 2019.
AR 190-12, Military Working Dogs, October 23, 2019.
AR 700-131, Loan and Lease of Army Material, August 23, 2004.
AR 725-1, Special Authorization and Procedures for Issues, Sales, and Loans, October 17, 2003.
SECNAVINST 5820.7C - Cooperation with Civilian Law Enforcement Officials, January 26,
2006.
OPNAVINST 3440.16D - Navy Defense Support of Civil Authorities Program.
AFI 10-801 - Defense Support of Civil Authorities (DSCA), September 19, 2012.
AFI 31-202 - Military Working Dog Program, May 16, 2009.
FEMA Disaster Operations Legal Reference (DOLR) Version 4.0, September 25, 2020.
Chapter 12
Funding Domestic Operations
246
Domestic Operational Law Handbook 2021
A. Introduction: Basic Fiscal Law Framework
The principles of Federal appropriations law permeate all Federal Government activity. Fiscal issues
arise frequently during domestic operations, and the failure to understand fiscal nuances may lead to
the improper expenditure of funds and sanctions against those responsible for funding violations.
Under the U.S. Constitution, Congress raises revenue and appropriates funds for Federal agency
operations and programs.1 Courts interpret this constitutional authority to mean that Executive branch
officials, e.g., commanders and staff members, must find affirmative authority for the obligation and
expenditure of appropriated funds.2 To that end, the Comptroller of the United States at the
Government Accountability Office (GAO) developed a three-part “necessary expense” test to ensure
the proper expenditure of Federal funds. That test is:
The expenditure must have a logical relationship to the appropriation charged;
The expenditure must not be prohibited by law; and
The expenditure must not be otherwise provided for. Likewise, in many cases, Congress has
specifically limited the ability of the Executive branch to obligate and expend funds, in annual
authorization or appropriations acts or in permanent legislation.
In domestic operations, the Department of Defense (DoD) supports requesting local and state civil
authorities in response to disasters and emergencies.3 This Federal Government support is coordinated
with and through the Federal Emergency Management Agency (FEMA).4 As such, military assistance
is provided to civil authorities on a reimbursable basis.5 In the case of some authorized activities such
as counterdrug support, Congress annually appropriates money to the Department of Defense for this
purpose.6 For other authorized activities, Congress has established special “no year” accounts (such as
the Disaster Relief Fund (DRF) and the Support for International Sporting Competitions (SISC)
account) into which the Department of Defense can transfer part of its annual appropriation of
Operation and Maintenance (O&M) funds.7 Once O&M funds are transferred to such an account, the
funds are available for the same purposes and for the same time period as the appropriation to which
1 See U.S. CONST. art. I, § 7.
2 See, e.g., U.S. v. MacCollom, 426 U.S. 317, 321 (1976) (“The established rule is that the expenditure of public funds is
proper only when authorized by Congress, not that public funds may be expended unless prohibited by Congress.”). An
obligation arises when the government incurs a legal liability to pay for its requirements, e.g., supplies, services, or
construction. For example, a contract award normally triggers a fiscal obligation. Commands also incur obligations when
they obtain goods and services from other U.S. agencies or a host nation. An expenditure is an outlay of funds to satisfy a
legal obligation. Both obligations and expenditures are critical fiscal events. See 31 U.S.C. § 1501 (2012).
3 See National Preparedness Goal, 2nd Ed. (May 2015), https://www.fema.gov/sites/default/files/2020-
06/national_preparedness_goal_2nd_edition.pdf (last visited April 13, 2021).
4 See DoDD 3025.18 - Defense Support of Civil Authorities, September 21, 2012 (C2, March 18, 2018) [hereinafter DoDD
3025.18].
5
42 U.S.C. § 5147 - Reimbursement of Federal Agencies (1988).
6 CHAIRMAN JOINT CHIEFS OF STAFF, INSTR. 3710.01B, DOD COUNTERDRUG SUPPORT (26 Jan. 2007) [hereinafter CJCSI
3710.01B].
7 See Disaster Relief Fund: Fiscal Year 2021 Funding Requirements, Federal Emergency Management Agency, February
13, 2021).
Chapter 12
247
Funding Domestic Operations
Domestic Operational Law Handbook 2021
transferred. In providing some types of support, the Department of Defense has the authority to act
directly and expend O&M funds. As a result, of these various types of situations, it is important to
understand that the purpose, time, and amount rules apply in domestic support operations.
B. Basic Fiscal Controls
Congress imposes fiscal controls through three basic mechanisms, each implemented by one or more
statutes. The controls are as follows:
Obligations and expenditures must be for a proper purpose (the purpose of the funds appears in
the language of the appropriation and normally follows the word “for”);
Obligations must occur within the time limits applicable to the appropriation (e.g., O&M funds
are available for obligation for one fiscal year) (remember, “current year funds for current year
needs”; and
Obligations must be within the amounts authorized by Congress (no spending in advance of nor
in excess of an appropriation).8
With that said, there are certain statutory exceptions to these fiscal controls. When dealing in a
domestic operations scenario, most of the expenditures are unplanned and emergent. It is the
responsibility of the judge advocate to work with the Contracting Officer, or in the case of the National
Guard (NG), the United States Property and Fiscal Officer (USPFO), to identify legal courses of action
then properly advise the commander.
1.
Purpose
Although each fiscal control is important, the “purpose” control is most likely to become an issue
during military operations. The Purpose Statute provides that “[a]ppropriations shall be applied only
to the objects for which the appropriations were made except as otherwise provided by law.”9 Thus,
expenditures must be authorized by law (permanent legislation or annual appropriations act) or be
“reasonably related” to the purpose of an appropriation. Judge advocates should ensure, therefore, that
an expenditure fits an appropriation (or permanent statutory provision), or is for a purpose that is
necessary and incident to the general purpose of an appropriation; the expenditure is not prohibited by
law; and the expenditure is not provided for otherwise, i.e., it does not fall within the scope of some
other appropriation.
A corollary to the “purpose” control is the prohibition against augmentation.10 Appropriated funds
designated for a general purpose may not be used for another purpose for which Congress has
appropriated other funds.11 If two funds are equally available for a given purpose, an agency may elect
8 See 2020 Fiscal Law Deskbook, The Judge Advocate General’s Legal Center and School.
9 See 31 U.S.C. § 1301(a) (2012).
10 See Nonreimbursable Transfer of Admin. Law Judges, B-221585, 65 Comp. Gen. 635 (1986); cf. 31 U.S.C. § 1532.
(2012) (prohibiting transfers from one appropriation to another except as authorized by law).
11 Secretary of the Navy, 20 Comp. Gen. 272 (1940).
Chapter 12
Funding Domestic Operations
248
Domestic Operational Law Handbook 2021
to use either, but once the election is made, the agency must continue to charge the same fund.12 This
concept is known legally as the “election doctrine,” and the election is binding even after the chosen
appropriation is exhausted.13
Unless otherwise authorized by law, a Federal unit’s O&M funds, cannot be used to provide support to
civil authorities. The same holds true for equipment procured with Federal funds. So, the question
becomes, “What law or policy authorizes a unit to expend funds or incur expenses when providing
support to civil authorities?” This chapter discusses the answer in depth. Likewise, if a Federal
agency accepts funds outside the normal appropriations process, then the agency is augmenting the
funds that Congress has appropriated. In addition, retaining those funds violates the Miscellaneous
Receipts Statute.14 When an agency retains these funds, this also violates the Constitutional
requirement for an appropriation.15 These legal principles prohibit unauthorized DoD expenditures to
further State missions. These principles also prohibit units from accepting resources directly from
State and local entities.
There are, however, statutory [and GAO-sanctioned] exceptions to the Miscellaneous Receipts Statute.
For example intra- and inter-governmental acquisition authorities allow agencies to retain and use
funds from sources other than those appropriated by Congress directly to that particular agency.16 The
Economy Act authorizes a Federal agency to order supplies or services from another Federal agency.
For these transactions, the requesting agency must reimburse the performing agency fully for the direct
and indirect costs of providing the goods and services.17 This stage is where misunderstandings arise
regarding the NG in terms of State Active Duty (SAD) missions. That is, when a State performs a
SAD mission using Federal equipment (e.g., vehicles and helicopters), the United States Property and
Fiscal Officer (USPFO) is required under NG Regulation NGR 500-5 to seek reimbursement from the
State.18 However, the request from the USPFO to the State is not an Economy Act transaction, and
therefore the reimbursement authority at 31 U.S.C. § 1536 is not applicable. Judge advocates may
wish to consult agency regulations for order approval requirements.19
Congress also has authorized certain expenditures for military support to civil law enforcement
agencies (CLEAs) in counter-drug operations. Support to CLEAs is reimbursable unless it occurs
during normal training and results in a benefit to the Department of Defense that is substantially
12 See Funding for Army Repair Projects, Comp. Gen. B-272191, Nov. 4, 1997, 97-2 CPD P141.
13 Honorable Clarence Cannon, B-139510, May 13, 1959, available at http://www.gao.gov/products/403911 (Rivers and
Harbors Appropriation exhausted; Shipbuilding and Conversion, Navy, unavailable for used to dredge channel to shipyard).
14 See 31 U.S.C. § 3302(b) (2012); Interest Earned on Unauthorized Loans of Fed. Grant Funds, B-246502, 71 Comp. Gen.
387 (1992).
15 See Use of Appropriated Funds by Air Force to Provide Support for Child Care Centers for Children of Civilian
Employees, B-222989, 67 Comp. Gen. 443 (1988); Bureau of Alcohol, Tobacco, and Firearms--Augmentation of
Appropriations--Replacement of Autos by Negligent Third Parties, B-226004, 67 Comp. Gen. 510 (1988).
16 See, e.g., Economy Act, 31 U.S.C. § 1535 (2012).
17 See Washington Nat’l Airport; Fed. Aviation Admin., B-136318, 57 Comp. Gen. 674 (1978) (depreciation and interest);
Obligation of Funds Under Mil. Interdental Purchase Requests, B-196404, 59 Comp. Gen. 563 (1980); see also DoD
7000.14-R, vol. 11A, ch. 1, para. 010201.J (waiving overhead for transactions within DoD).
18 U.S. DEPT OF ARMY AND AIR FORCE, NATL GUARD, REG. 500-5, NATIONAL GUARD DOMESTIC LAW ENFORCEMENT
AND MISSION ASSURANCE OPERATIONS para. 5-5.c (18 Aug. 2010) [hereinafter NGR 500-5].
19 See, e.g., GEN. SERVS. ADMIN. ET AL., FEDERAL ACQUISITION REG. Subpart 17.5 (Aug 2018) [hereinafter FAR]; Defense
Federal Acquisition Regulation Subpart 217.5; Army Federal Acquisition Regulation Supplement Subpart 17.5.
Chapter 12
249
Funding Domestic Operations
Domestic Operational Law Handbook 2021
equivalent to that which otherwise would be obtained from routine training or operations.20 Another
statutory provision authorizes operations or training to be conducted for the sole purpose of providing
CLEAs with specific categories of support.21 In 10 U.S.C. Section 124, Congress assigned the
operational mission of detecting and monitoring international drug traffic (a traditional CLEA
function) to the Department of Defense. By authorizing DoD support to CLEAs at essentially no cost,
Congress has authorized augmentation of CLEA appropriations.
2. Time
The “time” control has two major elements: (1) appropriations have a definite life span; and (2)
appropriations normally must be used for the needs that arise during their period of availability. Most
appropriations are available for a finite period. For example, O&M funds, the appropriation most
prevalent in an operational setting, are available for one year; procurement appropriations are available
for three years; and construction funds have a five-year period of availability. If funds are not
obligated during their period of availability, they expire and are unavailable for new obligations (e.g.,
new contracts or changes outside the scope of an existing contract). It is possible to use expired funds,
however, to adjust existing obligations (e.g., to pay for a price increase following an in-scope change
to an existing contract). The “bona fide needs rule” provides that funds are available only to satisfy
requirements that arise during their period of availability, and will affect which fiscal year
appropriation you will use to acquire supplies and services.22 This is commonly referred to as using
current year funds for current year needs.
The bona fide need for supplies normally exists when the Government will actually be able to use the
items. Thus, a command would use a currently available appropriation for computers needed and
purchased in the current fiscal year. Conversely, commands may not use current year funds for
computers not needed until the next fiscal year. It is proper to use year-end spending for computers if
the delivery is within a reasonable time after the new fiscal year begins. However, commands must
document the current year need. Note that there are “lead-time” and “stock-level” exceptions to the
general rule governing purchases of supplies.23 In any event, there is a prohibition of “stockpiling”
items.24
Normally, severable services are bona fide needs of the period in which they are performed. Grounds
maintenance, custodial services, and vehicle/equipment maintenance are examples of recurring
services considered severable. The general rule is to obligate current year funds for recurring services
performed in the current fiscal year. As an exception however, 10 U.S.C. § 2410a permits funding a
contract (or other agreement) for severable services using an appropriation current when the contract is
executed, even if some services will be performed in the subsequent fiscal year. Conversely, non-
severable services are bona fide needs of the year in which a contract (or other agreement) is executed.
Non-severable services are those that contemplate a single undertaking, e.g., studies, reports, overhaul
20 See 10 U.S.C. § 377 (2012).
21 See § 1004 of the 1991 National Defense Authorization Act (FY91 NDAA), as amended (10 U.S.C. § 374, note).
22 See 31 U.S.C. § 1502(a) (2013).
23 See DEPT OF DEFENSE, DEFENSE FINANCE AND ACCOUNTING SERVICE, DFAS-IN Reg. 37-1, DEFENSE FINANCE AND
ACCOUNTING SERVICE REG. INDIANAPOLIS 37-1 ch. 8 (Jan. 2010) [hereinafter DFAS-IN 37-1].
24 See Mr. H.V. Higley, B-134277, Dec. 18, 1957, available at http://redbook.gao.gov/6/fl0029466.php.
Chapter 12
Funding Domestic Operations
250
Domestic Operational Law Handbook 2021
of an engine, painting a building, etc. For non-severable services, the command should fund an entire
undertaking with fiscal year appropriations when the contract (or agreement) is executed.25
The issue in the performance of domestic operations is two-pronged. First, when it comes to major
disasters and emergencies, the request for DoD assistance is normally planned with little lead time.
Thus, it is likely that no funds with a period of availability were appropriated for the specific purpose
requested. Second, hurricanes normally hit near the end of the fiscal year. In this case, there are two
concerns that a judge advocate should remember: 1) Current year funds should be used for current
year needs; and 2) Federal Acquisition Regulation (FAR) Part 18, Emergency Acquisitions, is a good
resource to use.
3.
Amount
The Anti-Deficiency Act (ADA) prohibits any Federal Government officer or employee from: 1)
making or authorizing an expenditure or obligation in advance of or in excess of an appropriation;26 2)
making or authorizing an expenditure or incurring an obligation in excess of a formal subdivision of
funds, or in excess of amounts permitted by regulations prescribed under 31 U.S.C. § 1514(a);27 or 3)
from accepting voluntary services, unless authorized by law.28
Commanders must ensure that fund obligations and expenditures do not exceed amounts provided by
higher headquarters. Although over-obligation of an installation O&M account normally does not
trigger a reportable ADA violation, an over-obligation locally may lead to a breach of a formal O&M
subdivision at a higher echelon level.29
Commanders must investigate suspected violations to establish responsibility and discipline violators.
Regulations require “flash reporting” of possible ADA violations.30 If a command confirms a
violation, the cause of the violation, as well as the senior responsible individual, must be identified.
Investigators file reports through finance channels to the office of the Assistant Secretary of the Army,
Financial Management & Comptroller (ASA (FM&C)). Further reporting through Office of the
Secretary of Defense (OSD), the OMB, GAO, President, and Congress is required if ASA (FM&C)
concurs with a finding of a violation.
By regulation, commanders must impose administrative sanctions on responsible individuals.
Criminal action also may be taken if a violation was knowing and willful.31 In previous cases,
lawyers, commanders, contracting officers, and resource managers have been found to be responsible
for violations. Common problems that have triggered potential ADA violations include the following:
25 See DFAS-IN 37-1, supra note 23.
26 See 31 U.S.C. § 1341 (2012).
27 See 31 U.S.C. § 1517 (2012).
28 See 31 U.S.C. § 1342 (2012).
29 See 31 U.S.C. § 1514(a) (2012) (requiring agencies to subdivide and control appropriations by establishing
administrative subdivisions); 31 U.S.C. § 1517 (2013); DFAS-IN 37-1, supra note 23.
30 See DEPARTMENT OF DEFENSE, DoD 7000.14-R, FINANCIAL MANAGEMENT REGULATION vol. 14 (May 2015) [hereinafter
DoD 7000.14-R]; DFAS-IN 37-1, supra note 23.
31
31 U.S.C. §§ 1349 -1350 (2012).
Chapter 12
251
Funding Domestic Operations
Domestic Operational Law Handbook 2021
Without statutory authority, obligating (e.g., awarding a contract) current year funds for the
bona fide needs of a subsequent fiscal year. This may occur when activities stockpile supply
items in excess of those required to maintain normal inventory levels;
Exceeding a statutory limit (e.g., funding a contingency construction project in excess of $2M
with O&M; acquiring investment items in excess of an aggregate $250K with O&M funds);
Obligating funds for purposes prohibited by annual or permanent legislation; and
Obligating funds for a purpose for which Congress has not appropriated funds (e.g., personal
expenses where there is no regulatory or case law support for the purchase or where Congress
has placed a funding prohibition).
C. Military Assistance to Civil Authorities
The Federal military’s primary mission is to fight and win the nation’s wars. From time to time, the
Department of Defense will provide support to civil authorities while the civil authorities retain
primary responsibility for and control over the incident. The starting point for all DoD support to civil
authorities is DoDD 3025.18, Defense Support of Civil Authorities (DSCA). When speaking of the
NG, it is important to separate NG Civil Support (NGCS) from DSCA. NGCS is, “[s]upport provided
by the NG while in a State Active Duty status or Title 32 status to civil authorities for domestic
emergencies, designated law enforcement, and other activities.”32 In contrast, DSCA is, “[s]upport
provided by U.S. Federal military forces, DoD civilians, DoD contract personnel, DoD Component
assets, and NG forces (when the Secretary of Defense, in coordination with the Governors of the
affected States, elects and requests to use those forces in title 32, U.S.C., status) in response to requests
for assistance from civil authorities for domestic emergencies, law enforcement support, and other
domestic activities, or from qualifying entities for special events.”33 The NG may perform DSCA
when supporting a mission that has been assigned to the Department of Defense by the Federal
Emergency Management Agency (FEMA), and when performing this mission, the NG personnel are in
their 32 U.S.C. 502(f)(2) status.34 Otherwise, when providing civil support, the NG is performing
NGCS where DoDD 3025.18 does not apply.
The Posse Comitatus Act (18 U.S.C. § 1385) provides limitations on the types of support that the
Federal military may provide to civil authorities. The following are areas of common allowable
military support and their governing policies and authorities:35
32 CHIEF, NATL GUARD BUREAU, INST. 3000.04, NATIONAL GUARD BUREAU DOMESTIC OPERATIONS GL-2 (24 Jan. 2018)
[hereinafter CNGBI 3000.04].
33 U.S. DEP’T. OF DEF., DIR. 3025.18, DEFENSE SUPPORT OF CIVIL AUTHORITIES 19 (29 Dec. 2010) (C2, 19 Mar. 2018)
[hereinafter DoDD 3025.18].
34 U.S. DEP’T. OF DEF., INSTR. 3025.22, THE USE OF THE NATIONAL GUARD FOR DEFENSE SUPPORT OF CIVIL
AUTHORITIES paras. 3.d, and 3.e (26 Jul. 2013) (C2, 15 May 2018) [hereinafter DoDI 3025.22]; see also 32 U.S.C.
502(f)(2).
35 See generally U.S. DEP’T. OF DEF., INSTR. 3025.21, DEFENSE SUPPORT OF CIVILIAN LAW ENFORCEMENT AGENCIES
(27 Feb. 2013) (C1, 8 Feb. 19) [hereinafter DoDI 3025.21].
Chapter 12
Funding Domestic Operations
252
Domestic Operational Law Handbook 2021
Civil disaster and emergencies (Stafford Act (42 42 U.S.C. §§ 5121, et seq.), DoDD 3025.18).
Civil disturbances; Insurrection Act (10 U.S.C. §§ 251-255, DoDI 3025.21).
Support to civilian law enforcement (DoDI 3025.21).
o Sharing information (10 U.S.C. § 271, DoDI 3025.21).
o Loan of equipment and use of facilities (10 U.S.C. § 272, DoDI 3025.21).
o Training and provision of expert advice. (10 U.S.C. § 273, DoDI 3025.21).
o Maintenance and operation of equipment. (10 U.S.C. § 274, DoDI 3025.21).
Counterdrug support:
o Detection and monitoring (10 U.S.C. § 124).
o Training and other support. (10 U.S.C. § 1004, Fiscal Year (FY) 91 NDAA, as amended
by § 1021, FY 02, NDAA; CJCSI 3710.01B).
Innovative Readiness Training (10 U.S.C. § 2012, DoDI 1100.24).
Department of Defense Support to Special Events to include support to International Supporting
Events. 10 U.S.C. § 2564(a)-(c), DoDI 3025.20
Support to Private Organizations. (10 U.S.C. § 2554 (Boy Scouts of America), 10 U.S.C. §
2555 (Girl Scouts of America), 10 U.S.C. § 2551 (National Veterans’ Organizations), 10
U.S.C. § 2552 (American Red Cross), 10 U.S.C. § 2558 (National Military Associations), and
10 U.S.C. § 2556 (Homeless).
Loan or Lease of Non-Excess Property of a Military Department (10 U.S.C. § 266 Leases,
Army Regulation (AR) 700-131, Loan and Lease of Army Material, and 31 U.S.C. § 1535
Agency Agreements).
Explosive Ordinance Disposal (EOD): AR 75-14, AR 75-15.
Military Working Dogs. DoDD 5200.31E, AR 190-21.
Miscellaneous support:
o Sensitive support. DoDD S-5210-36.
o Law enforcement detachments. 10 U.S.C. § 379.
o Emergencies involving chemical or biological weapons. 10 U.S.C. § 382.
Chapter 12
253
Funding Domestic Operations
Domestic Operational Law Handbook 2021
D. DoDD 3025.18, Defense Support of Civil Authorities (DSCA)
This Directive governs DoD military assistance provided to civil authorities within the 50 States,
District of Columbia, Puerto Rico, and U.S. possessions and territories. This policy provides the six
criteria, known as the CARRLL factors, against which commanders should evaluate all requests for
support shall be evaluated:
Cost - who pays and the impact on DoD budget;
Appropriateness - whether conducting the requested mission is in the DoD’s interest;
Readiness - impact on the DoD’s ability to perform its primary mission;
Risk - safety of DoD forces;
Legality - compliance with the law; and
Lethality - potential use of lethal force by or against DoD forces.
Per DoDD 3025.18, the Secretary of Defense (SecDef) is the approval authority for DoD assistance in
civil disturbances, responses to chemical, biological, radiological, and nuclear events, defense
assistance to civilian law enforcement agencies (except as authorized by DoDI 3025.21 as discussed
below), and support that has the potential for lethality.
When Combatant Commands use their assigned, they must coordinate with the Chairman of the Joint
Chiefs of Staff (CJCS). SecDef approval is not required when immediate response authority of the
local commander under DoDD 3025.18 is used, but a reassessment of the appropriateness of the use of
this authority is required within the first 72 hours of a response.36
As noted above, DoDD 3025.18 is the DSCA policy for the DoD. Distinction must be made when
considering the usage of the NG to support a DSCA mission assigned to the DoD by FEMA. At this
juncture, DoDI 3025.22 must be reviewed because this policy and DoDD 3025.18 become applicable
to members of the NG when serving in their 32 US.C. § 502(f) status.37
36
“The DoD official directing a response under immediate response authority shall reassess whether there remains a
necessity for the Department of Defense to respond under this authority as soon as practicable but, if immediate response
activities have not yet ended, not later than 72 hours after the request for assistance was received.” DoDD 3025.18, supra
note 33, para 4.g.(2).
37 DoDI 3025.22, supra note 34.
Chapter 12
Funding Domestic Operations
254
Domestic Operational Law Handbook 2021
E.
Disaster and Emergency Relief38
The Stafford Act provides four means by which the Federal Government may become involved in a
disaster and relief effort: the President may declare the area a major disaster39; the President may
declare the area an emergency40; the President may send in DoD assets on an emergency basis to
“preserve life and property”;41 and the President may send in Federal assets where an emergency
occurs in an area over which the Federal Government exercises primary responsibility by virtue of the
Constitution or Federal statute.42
The Department of Homeland Security (DHS), through FEMA, directs and coordinates the Federal
response on behalf of the President. DHS has prepared the National Response Framework (NRF),
which defines fifteen Emergency Support Functions (ESFs) for which certain Federal agencies have
either a primary or supporting role. The Corps of Engineers is the primary agency for ESF #3, Public
Works and Engineering. DoD is a supporting agency for all others.
FEMA appoints a Federal Coordinating Officer (FCO), typically the senior FEMA official on-scene.
Because of the likelihood of DoD involvement, a Defense Coordinating Officer (DCO) is assigned to
the FCO. The DCO, an O-6 or above, is identified from a Training Support Brigade (TSB). Training
Support Brigades are located throughout the continental United States (CONUS). Training Support
Brigade commanders are dual-hatted as DCOs. The DCO will be the FCO’s single point of contact for
DoD support. The FCO issues Mission Assignments (MA), defining the task and maximum
reimbursement amount, to the Federal agencies responding.
The DoD is reimbursed by FEMA for the incremental costs of providing support pursuant to the
DCO’s tasking in response to the FEMA mission assignment. Incremental expenses are reimbursed, or
those expenses incurred by the agency providing the military assistance that—but for the request for
assistance—would not otherwise have incurred these expenses. The Department of Defense Financial
Management Regulation (FMR) 7000.14-R, vol. 12, ch. 6, para. 060204, lists the following costs as
eligible for reimbursement:
Overtime, travel, and per diem of permanent DoD civilian personnel;
Wages, travel, and per diem of temporary DoD civilian personnel assigned solely to
performance of services directed by the Executive Agent;
38 See generally Disaster Relief Act Amendments of 1974 (Stafford Act), Pub. L. No. 93-288, 88 Stat. 143 (1974); DoDD
3025.18, supra note 33; DOD MANUAL 3025.01, VOL. 1, DEFENSE SUPPORT OF CIVIL AUTHORITIES: OVERVIEW (11 Aug.
2016) (Ch.1 13 Apr. 2017) [hereinafter DODM 3025.01]; CNGBI 3000.04, supra note 32; CHIEF OF NAVAL OPERATIONS,
INSTR. 3440.16D; NAVY DEFENSE SUPPORT OF CIVIL AUTHORITIES PROGRAM (29 Jun 2009); U.S. DEPT OF AIR FORCE,
INSTR. 10-801, DEFENSE SUPPORT OF CIVIL AUTHORITIES (DSCA) (19 Sept. 2012) [hereinafter AFI 10-801].
39 See 42 U.S.C. § 5170 (2012).
40 See 42 U.S.C. § 5191 (2012) (same criteria as for a major disaster, except it also requires that the governor define the
type and amount of federal aid required, and total federal assistance may not exceed $5 million).
41 See 42 U.S.C. § 5170b(c) (2012).
42 See 42 U.S.C. § 5191(b) (2012).
Chapter 12
255
Funding Domestic Operations
Domestic Operational Law Handbook 2021
Travel and per diem of active duty military, and costs of reserve component personnel called to
active duty by a federal official who is assigned solely to the performance of services directed
by the Executive Agent;
Cost of work, services, and material procured under contract for the purposes of providing
assistance directed by the Executive Agent;
Cost of materials, equipment and supplies (including transportation, repair and maintenance)
from regular stocks used in providing directed assistance;
All costs incurred which are paid from trust, revolving, or other funds, and whose
reimbursement the law requires; and
Other costs submitted with written justification or otherwise agreed to in writing by the Joint
Director of Military Support or appropriate Service representative.
Requests for reimbursement are made using an SF-1080, Voucher for Transfers between
Appropriations or Funds. It is important to note that Federal agencies, which exceed the
reimbursement amount, or execute tasks not within the MA, may not be reimbursed.
For the DoD response, the Assistant Secretary of Defense for Homeland Defense and Americas’
Security Affairs (ASD(HD&ASA)) is the DoD lead for disaster relief operations. As such, they are the
approval authority for all such support, unless it involves Combatant Command-assigned forces. The
Joint Director of Military Support (JDOMS) is the ASD(HD&ASA) agent. The JDOMS coordinates
and monitors the DoD effort. The JDOMS normally produces the Execute Order and obtains the
SecDef’s signature for a given mission. USNORTHCOM (CONUS, Alaska, Puerto Rico, and the
Virgin Islands) and USINDOPACOM (Hawaii, and Pacific possessions and territories) are responsible
for developing disaster response plans and for the execution of those plans needed for a response.
They may form a Joint Task Force for this purpose.
1.
Immediate Response Authority (IRA)
IRA permits local military commanders to act immediately to save lives, prevent human suffering, and
mitigate great property damage in imminently serious conditions when time does not permit approval
from higher headquarters.43 Types of support authorized include rescue, evacuation, and emergency
treatment of casualties; emergency restoration of essential public services; emergency removal of
debris and explosive ordnance; and recovery and disposal of the dead.44 This type of support is
provided on a reimbursable basis, but assistance should not be denied because the requester is unable
or unwilling to commit to reimbursement.45 Reimbursement is routed to the Department of the
Treasury.
43 DoDD 3025.18, supra note 33, para 4.i.
44 DOD MANUAL 3025.01, VOL. 2. DEFENSE SUPPORT OF CIVIL AUTHORITIES: DOD INCIDENT RESPONSE (11 Aug. 2016)
(Ch.1 13 Apr. 2017), sec. 5.3 [hereinafter DODM 3025.01, VOL 2.].
45 DoDD 3025.18, supra note 33, at para. 4.i.6.
Chapter 12
Funding Domestic Operations
256
Domestic Operational Law Handbook 2021
IRA is very limited and should be invoked only for bona fide emergencies. Contemporaneous
coordination with JDOMS and ASD(HD&ASA) should always occur in these scenarios, and in any
other case potentially involving this type of assistance to civil authorities. The commander must
reassess the need for immediate response not less than 72 hours after the civil authority submitted the
request for assistance.46 To obtain reimbursement for costs incurred as a result of an immediate
response, the Department of Defense should request reimbursement from the State or local government
to whom assistance was provided. In some cases, the State and local governments may not have the
available funding to reimburse. With that said, all is not lost. “Ongoing [S]tate and local response
activity may be reimbursed if a declaration is issued, including for evacuations, sheltering and other
emergency protective measures.”47 Should the State have funding available to reimburse the
Department of Defense, funding is not sent directly to a unit account. Instead, “States must reimburse
the United States Treasury in accordance with section 9701 [Fees and Charges for Government
Services and Things of Value] of [Title 31 of the United States Code].”48
If authorized by law, for instance under the Stafford Act, and approved by the appropriate DoD official
(i.e. Secretary of Defense or the President), the support may be provided on a non-reimbursable
basis.49 Even if the civil authority was unaware of this rule, and paid the money directly to the unit,
Federal military personnel must still comply with the rules governing “money for the Government”
more commonly referred to as the Miscellaneous Receipts Statute, 31 U.S.C. 3302(b). The same
applies to mutual aid agreements. (see DoDM 3025.01 Vol 2; DoDI 6055.06 Encl 2; and 42 USC
Section 1855(d)).
2.
Emergency Response Fund (ERF)
Since November 2003, the ERF has been closed out.50 Congress created the ERF in the FY90 National
Defense Appropriation Act, Pub. L. 101-165, in response to Hurricane Hugo. Under this provision,
“the Fund is available for providing reimbursement to currently applicable appropriations of the [DoD]
for supplies and services provided in anticipation of requests from other Federal Departments and
agencies and State and local governments for assistance on a reimbursable basis to respond to natural
and manmade disasters.”51
In FY94, § 8131 of the National Defense Appropriation Act, Pub. L. No. 103-139, amended the FY90
provision giving DoD the ability to request reimbursement from the ERF for its own disaster response
efforts. Specifically, the language provides, “the Fund may be used, in addition to other funds
available to DoD for such purposes, for expenses of DoD which are incurred in supplying supplies and
services furnished in response to natural or manmade disasters.”52
46 Id. at para. 4.i.5.
47 FEDERAL EMERGENCY MANAGEMENT AGENCY, DISASTER OPERATIONS LEGAL REFERENCE VER. 3.0 1-3 (20 Jan. 2017)
[hereinafter Disaster Ops Legal Reference 3.0].
48 DoDD 3025.18, supra note 33, at para. 4.d.
49 Id.
50 Closed out in § 1105 of the FY04 Emergency Supplemental Appropriations Act.
51 FY90 National Defense Appropriation Act, Pub. L. 101-165 National Defense Authorization Act for Fiscal Years 1990
Pub. L. No. 101-165, 103 Stat. 1563 [hereinafter NDAA for FY90].
52 National Defense Authorization Act for Fiscal Years 1994, Pub. L. No. 103-139 [hereinafter NDAA for FY94].
Chapter 12
257
Funding Domestic Operations
Domestic Operational Law Handbook 2021
Prior to November 2003, if the State and local government were unable or unwilling to reimburse the
Department of Defense, the command would forward a request for reimbursement to the ERF.53 This
fund was available for providing reimbursement to currently applicable DoD appropriations for
supplies and services provided in anticipation of requests from other Federal departments and agencies
and from State and local governments for assistance on a reimbursable basis to respond to natural or
manmade disasters.
The Act that closed out the ERF provided that, effective November 1, 2003, adjustments to obligations
that before such date would have been properly chargeable to the ERF shall be charged to current
appropriations available for the same purpose.54 Now, it may be possible to seek reimbursement
through FEMA. In some instances, FEMA has provided reimbursement to the DoD for IRA assistance
by “ratifying” the DoD action after the fact. Such ratification, however, is done on a case-by-case
basis. What a commander may find is the support previously provided under the commander’s
immediate response authority rolled under a mission assignment from FEMA for which reimbursement
is available via the disaster relief fund in accordance with the Stafford Act. Another option is the
usage of DoD resources to perform emergency work “during the immediate aftermath of an incident
which may ultimately qualify for assistance under [the Stafford Act].”55 The Governor may request
the President to direct the Secretary of Defense to use DoD assets to perform emergency work for up to
10 days before the formal declaration of a major disaster or emergency.56 Thus, even though the ERF
no longer exists, there are multiple ways to reimburse Federal military units for expenditures while
providing legal support to civil authorities before a declaration or mission assignment.
F. Civil Disturbance Operations (CDOs)57
The maintenance of law and order is primarily vested in State and local officials. Involvement of
military forces will only be appropriate in extraordinary circumstances. Use of the military under these
authorities to conduct law enforcement activities is a specific exception to the Posse Comitatus Act
(PCA). The probable order of employment of forces in response to a certain situation will be (1) local
and State police; (2) NG in their SAD status; (3) Federal civil law enforcement officials; and (4)
Federal military troops, to include, if necessary, NG personnel called to active Federal service.
The insurrection statutes permit the President to use the Federal Armed Forces domestically under
certain circumstances.58 The Attorney General coordinates all Federal Government activities relating
to civil disturbances. If the President decides to respond to the situation, he must first issue a
proclamation to the insurgents, prepared by the Attorney General, directing them to disperse within a
53 See DoD 7000.14-R, supra note 30, ch. 6.
54 Id.
55
42 U.S.C. § 5170b c.1 (2012) [hereinafter Emergency Work].
56 Id.
57 U.S. CONST. art. IV, § 4: “The United States shall guarantee to every State in this Union a Republican Form of
Government, and shall protect each of them against Invasion; and on Application of the Legislature, or of the Executive
(when the Legislature cannot be convened), against domestic Violence”; Insurrections, 10 U.S.C. §§ 251-255 (2012);
DODI 3025.21, supra note 35.
58 The Insurrection Act of 1807, 10 U.S.C. §§ 251-55 [hereinafter The Insurrection Act].
Chapter 12
Funding Domestic Operations
258
Domestic Operational Law Handbook 2021
limited time.59 At the end of that time-period, the President may issue an executive order directing the
use of Federal Armed Forces. The Attorney General appoints a Senior Civilian Representative of the
Attorney General (SCRAG) as his action agent.
For the DoD response, the Secretary of Defense has reserved the authority to approve support in
response to civil disturbances.60 Although the civilian authorities have the primary responsibility for
civil disturbances, Federal Armed Forces shall remain under Federal military command and control at
all times. Federal Armed Forces shall not be used for civil disturbances unless specifically directed by
the President (pursuant to 10 U.S.C. §§ 251-255), except for emergency employment of Federal
military forces in the following limited circumstances:61
To prevent the loss of life or wanton destruction of property or to restore governmental
functioning, in cases of civil disturbances, if the duly constituted authority local authorities are
unable to control the situation and circumstances preclude obtaining prior Presidential
authorization; and
When duly constituted State or local authorities are unable or decline to provide adequate
protection for Federal property or functions.
Although employment under these authorities permits direct enforcement of the law by military forces,
the military’s role in law enforcement should be minimized as much as possible. The DoD’s role is to
support the civilian authorities, not replace them. Once the President directs the employment of
Federal military forces, the Department of Defense may use O&M funds to cover the cost.
G. Support to Civilian Law Enforcement62
Although certain activities may be law enforcement-type activities, they will not violate the PCA when
Federal military personnel to provide indirect assistance. With proper approval, DoD activities may
make equipment (including associated supplies and spare parts) or facilities available to Federal, State,
or local law enforcement officials for law enforcement purposes.
Under 10 U.S.C. § 274(a), the Secretary of Defense may make DoD personnel available for the
maintenance of equipment provided, to include equipment provided pursuant to 10 U.S.C. § 272.
Under 10 U.S.C. § 274(b)(1), the Secretary may also, upon a request from the head of a Federal law
enforcement agency, make DoD personnel available to operate equipment with respect to criminal
violations of the Controlled Substances Act, the Immigration and Naturalization Act, the Tariff Act of
1930, the Maritime Drug Law Enforcement Act, and any law, foreign or domestic, prohibiting terrorist
59 See 10 U.S.C. § 334 (2013).
60 See DoDD 3025.18, supra note 27, para. 4.j.
61 The Insurrection Act, supra note 58.
62 See generally 10 U.S.C. §§ 272-274, 277; DODI 3025.21, supra note 35; CNGBI 3000.04, supra note 32; U.S. DEPT OF
NAVY, SECY NAVY INSTR. 5820.7C, COOPERATION WITH CIVILIAN LAW ENFORCEMENT OFFICIALS, para. 8 (26 Jan. 2006)
[hereinafter SECNAVINST 5820.7C]; U.S. DEPT OF ARMY, REG. 700-131, LOAN, LEASE, AND DONATION OF ARMY
MATERIEL (24 Aug. 2004) [hereinafter AR 700-131]; AFI 10-801, supra note 38.
Chapter 12
259
Funding Domestic Operations
Domestic Operational Law Handbook 2021
activities; a foreign or domestic counter-terrorism operation; or a rendition of a suspected terrorist from
a foreign country to the United States to stand trial.
Under 10 U.S.C. § 274(b)(2), DoD personnel made available to a civilian law enforcement agency
may operate equipment for the following purposes:
Detection, monitoring, and communication of the movement of air and sea traffic;
Detection, monitoring, and communication of the movement of surface traffic outside of the
geographic boundary of the United States and within the United States not to exceed 25 miles
of the boundary if the initial detection occurred outside the boundary;
Aerial reconnaissance;
Interception of vessels or aircraft detected outside the land area of the U.S. for the purposes of
communicating with and directing said vehicle to a specific location;
Operating equipment to facilitate communications;
Subject to joint approval by the Secretary of Defense and Attorney General:
o Transportation of civilian law enforcement personnel along with any other civilian or
military personnel who are supporting, or conducting, a joint operation with civilian law
enforcement personnel;
o Operation of a base of operations;
o Transportation of suspected terrorists from foreign countries to the U.S. for trial (so
long as the requesting Federal law enforcement agency provides all security for such
transportation and maintains custody over the suspect through the duration of the
transportation).
1.
Economy Act
Pursuant to 10 U.S.C. § 277, the support provided between Federal agencies under these authorities is
reimbursable under the Economy Act, unless the support is provided in the normal course of training
or operations, or the support results in a substantially equivalent training value. Under 31 U.S.C. §
1535, an Economy Act order may be placed by the head of an agency (delegable down to a warranted
contracting officer) with another agency. The order may be a Military Interdepartmental Purchase
Request (MIPR), a Memorandum of Understanding (MOU) for support, or an interagency agreement.
Form is not the key—content is the critical matter. The definition of “agency” includes military
departments.63 The content defines the type of support to be rendered and the reimbursement to be
provided.
63 FAR, supra note 19, at pt. 2.101.
Chapter 12
Funding Domestic Operations
260
Domestic Operational Law Handbook 2021
2.
Miscellaneous Receipts
The Miscellaneous Receipts Statute, 31 U.S.C. § 3302(b), requires that any dollars received by an
agency must go into the general treasury, without any deduction for any charges or claims, unless there
is a positive legal authority, like the Economy Act, that allows an agency to retain the money. The
Economy Act does not apply to NG in the performance of SAD missions. Further, although the
language in 10 U.S.C. § 272 et seq. authorizes support to State and local civilian law enforcement
agencies, the reimbursement provision in 10 U.S.C. § 277 provides no mechanism for reimbursement
except for support between Federal agencies. If commanders loan equipment to State or local CLEAs
under this authority, any reimbursement obtained would go to the U.S. Treasury as a Miscellaneous
Receipt. It is important to note that reimbursement is required, unless the law allows a waiver. The
only way to avoid this problem is for the commander to lease the equipment under 10 U.S.C. § 2667.
The Leasing Statute provides a mechanism for reimbursement. If a loan is authorized, there must be
no adverse impact on national security or military preparedness. (Specific details regarding the
Leasing Statute are in Section L of this Chapter)
The Secretary of the Army has statutory authority to approve loans, leases, and donations of Army
material. The Chief, Integrated Logistics Support Division (DALO-SMP) is responsible for acting on
loan and lease request and loan and lease extensions forwarded for Headquarters, Department of the
Army (HQDA) review by major Army Commands (MACOMs). AR 700-131 contains detailed
procedures on the loan or transfer of Army property. For the Navy and Marine Corps, the Assistant
Secretary of the Navy (SECNAV) (Manpower and Reserve Affairs) may approve requests for non-
lethal equipment for more than sixty days.64 All other requests may be approved as specified in
SECNAVINST 5820.7C. For the Air Force, AFI 10-801 states that in circumstances not immediately
threatening to human life, causing human suffering, or threatening great property damage, requests for
equipment or facilities for Federal, State, or local civilian officials (including law enforcement) should
be addressed in accordance with AFI 23-119 and AFI 32-9003. For the NG, the loan of weapons,
combat/tactical vehicles, vessels and aircraft require approval of the service secretary or their designee.
Requests for loan/lease of NG equipment, which require HQDA or HQAF approval, will be reviewed
by National Guard Bureau (NGB));65 however, it must be remembered that the Secretary of Defense is
the approval authority for all DoD support to counterterrorism operations, emergency support to civil
disturbances, and law enforcement agencies that will result in a planned event with the potential for
confrontation with named individuals/groups or use of lethal force.
3.
Excess Property
In addition to loan/lease authority, The National Defense Authorization Act of 1997 added a new
section to Title 10. Section 2576a, “Excess Personal Property; Sale or Donation for law enforcement
activities,” permits DoD to provide excess personal property suitable for use in counter-drug and
counter-terrorism activities to Federal and State agencies. The program is commonly referred to as the
“1033 Program” because it fell under Section 1033 of the 1997 NDAA (PL 104-181). 10 U.S.C. §
2576 authorizes the surplus sale of military equipment to state and local law enforcement and
firefighting agencies.
10 U.S.C. § 2576(a) authorizes the surplus sale of military equipment to Federal
64 SECNAVINST 5820.7C, supra note 62.
65 NATIONAL GUARD REG. 500-5, NATIONAL GUARD DOMESTIC LAW ENFORCEMENT SUPPORT AND MISSION ASSURANCE
OPERATIONS para 4-8 (Aug. 2010) [hereinafter NGR 500-5].
Chapter 12
261
Funding Domestic Operations
Domestic Operational Law Handbook 2021
and State agencies suitable for carrying out law enforcement, firefighting, homeland security, and
emergency management services. The State or local agency must initiate a request for the equipment.
The program is managed by the Defense Logistics Agency Law Enforcement Support Office at Fort
Belvoir, Virginia. 10 U.S.C. § 2576a and § 2576b provide additional mechanisms for the transfer of
excess property (without sale) to law enforcement and firefighting agencies.
4.
Expert Advice and Training66
DoD components are authorized to give expert advice and/or training to Federal, State, and local law
enforcement in certain cases. Overarching policy regarding the provision of this assistance is found at
32 C.F.R. § 182, and more specific policy is found in DoDI 3025.21.
DoD components may provide, subject to approval limitations in DoDI 3025.21, expert advice to
Federal, State, or local law enforcement officials in accordance with 10 U.S.C. § 373.67 A specific
example of this type of support is military working dog team support to civilian law enforcement. The
dogs are analogous with equipment, and their handlers to providers of expert advice.68 Direct
assistance by DoD personnel in activities that are fundamentally civilian law enforcement operations is
not permitted, except as specifically authorized by DoDI 3025.21.69
DoD components may also provide, subject to approval limitations in DoDI 3025.21, training to
Federal, State, and local civilian law enforcement officials. This does not permit large-scale or
elaborate DoD training, and does not permit regular or direct involvement of DoD personnel in
activities that are fundamentally civilian law enforcement operations, except as otherwise authorized
by DoDI 3025.21.
DoD personnel may only provide training when the use of non-DoD personnel would be unfeasible or
impractical from a cost or time perspective, and when it would not otherwise compromise military
preparedness of the United States.70 It may not involve DoD personnel participating in a law
enforcement operation, unless specifically authorized under DoDI 3025.21. DoD personnel must
conduct the training assistance at a location where there is not a reasonable likelihood of a
confrontation between law enforcement personnel and civilians, unless otherwise authorized by law.71
DoDI 3025.21 does not permit the provision of “advanced military training.” Advanced military
training includes advanced marksmanship training, sniper training, military operations in urban terrain
(MOUT), advanced MOUT, close quarters battle/close quarters combat, and similar training.72 The
66 See generally 10 U.S.C. §§ 273, 275, 277 (2012); 50 U.S.C. § 2316; DODI 3025.21, supra note 35, Encl. 5;
SECNAVINST 5820.7C, supra note 62, paras. 9.a.(4)-(5); AFI 10-801, supra note 38.
67 DoDI 3025.21, supra note 35, Encl. 3.
68 See generally U.S. DEPT OF DEFENSE, DIR. 5200.31E, DOD MILITARY WORKING DOG (MWD) PROGRAM, (10 Aug.
2011) (C1, 21 Sept. 2020) [hereinafter DODD 5200.31E]; U.S. DEPT OF AIR FORCE, AFI 31-121, MILITARY WORKING DOG
PROGRAM (17 Oct. 2012), 32 C.F.R. §182 (2013).
69 Specific examples where direct assistance is permitted include the case of the execution of a quarantine under 42 U.S.C.
§ 97, when such actions are necessary to prevent significant loss of life and wanton destruction of property and are
necessary to restoring governmental function, and when action is needed to protect national parks and other certain federal
lands, among many other instances. DODI 3025.21, supra note 35, Encl. 3.
70 DoDI 3025.21, supra note 35, Encl. 3.
71 Id.
72 Id.
Chapter 12
Funding Domestic Operations
262
Domestic Operational Law Handbook 2021
SecDef policy on advanced military training in this context is discussed further in Deputy Secretary of
Defense Memorandum “DoD Training Support to U.S. Civilian Law Enforcement Agencies,” June 29,
1996, and Deputy Secretary of Defense Memorandum “Request for Exception to Policy,” November
12, 1996 (both available from the Office of the Assistant Secretary of Defense for Homeland Defense
and Americas’ Security Affairs (ASD (HD & ASA), room 3D247, 2600 Defense Pentagon,
Washington D.C. 20301).
The Secretary of Defense is the approval authority for requests for direct assistance in support of
civilian law enforcement agencies, including those responding with assets with the potential for
lethality, except for the use of emergency authority as provided for under DoDD 3025.18 or under one
of the exceptions provided in DoDI 3025.21. Requests that involve Defense Intelligence and
Counterintelligence entities are subject to SecDef approval and the guidance in DoDD 5240.01, DoD
Intelligence Activities and DoD 5240.1-R, Procedures Governing the Activities of DoD Intelligence
Components that Affect U.S. Persons (see Chapter 9 infra for further guidance).
Otherwise, the Secretaries of the Military Departments and the Directors of the Defense Agencies may,
in coordination with the ASD(HD&ASA), approve the use of DoD personnel: (1) to provide training or
expert advice in accordance with DoDI 3025.21; For equipment maintenance in accordance with the
specific provisions of DoDI 3025.21, enclosure 3; to monitor and communicate the movement of air
and sea traffic in accordance with the specific provisions of DoDI 3025.21, enclosure 3. All other
requests, including those in which subordinate authorities recommend disapproval, shall be submitted
promptly to the ASD(HD&ASA) for consideration by the Secretary of Defense, as appropriate.73
Support provided under these authorities to a Federal agency is reimbursable under the Economy Act,
unless the support is provided in the normal course of training or operations, or the support results in a
substantially equivalent training value.74 It is important to note that pursuant to 31 U.S.C. § 6505,
under the “Intergovernmental Cooperation Act,” Federal agencies are authorized to provide to State
and local governments “statistical and other studies and compilations, development projects, technical
tests and evaluations, technical information, training activities, surveys, reports, and documents and
other similar services that an executive agent is especially competent and authorized by law to
perform.”
Two common requests the Department of Defense may receive under this statute are for the provision
of “technical information and training activities.” OMB Circular A-97 defines these two as follows: 1)
training of the type which the Federal agency is authorized by law to conduct for Federal personnel
and others or which is similar to such training; and 2) technical information, data processing,
communications, and personnel management systems services which the Federal agency normally
provides for itself or others under existing authorities.
A reimbursement mechanism is provided under 31 U.S.C. § 6505 between the Federal and State/local
level. Reimbursements received by the Federal agency for the costs of services provided will be
deposited to the credit of the principal appropriation or other account from which the costs of
providing the services have been paid or are to be charged. It is important to remember that these
reimbursed dollars do not go into the Miscellaneous Receipts account.
73 Id.
74 Id., Encl. 9.
Chapter 12
263
Funding Domestic Operations
Domestic Operational Law Handbook 2021
5.
Sharing Information75
Any information collected in the normal course of military operations may be provided to appropriate
civilian law enforcement agencies. Collection must be compatible with military training and planning.
To the maximum extent practicable, DoD personnel should take into account the needs of civilian law
enforcement officials when planning and executing of military training and operations.76
H. Counterdrug Support77
Counterdrug support operations have become an important activity within the Department of Defense.
All DoD support is coordinated through the Office of the Defense Coordinator for Drug Enforcement
Policy and Support (DEP&S), which is located within the Office of the Assistant Secretary of Defense
for Special Operations and Low Intensity Conflict (ASD (SO/LIC)). DoD support to counterdrug
operations is funded through annual DoD appropriations unlike other support provided by DoD, which
must be reimbursed by the agency receiving support. The Office of the Defense Coordinator for Drug
Enforcement Policy and Support channels this appropriated money to the providers of counterdrug
support.
1.
Detection and Monitoring
The Department of Defense is the lead Federal agency for detection and monitoring (D&M) of aerial
and maritime transit of illegal drugs into the United States.78 D&M is therefore a DoD mission.
Although a military mission, D&M is to be carried out in support of Federal, State, and local law
enforcement authorities. Note that the statute does not extend to D&M missions covering land transit
(i.e., the Mexican border). Interception of vessels or aircraft is permissible outside the land area of the
U.S. to identify and direct the vessel or aircraft to a location designated by the supported civilian
authorities.79 Detection and monitoring missions involve airborne (Airborne Warning and Control
Systems (AWACS), aerostats), seaborne (primarily U.S. Navy (USN) vessels), and land-based radar
(to include Remote Over the Horizon Radar (ROTHR)) sites. Federal funding for NG counterdrug
activities, to include pay, allowances, travel expenses, and operations and maintenance expenses is
provided pursuant to 32 U.S.C. § 112. The State must prepare a drug interdiction and counter-drug
75
10 U.S.C. § 371 (2013); DoDI 3025.21, supra note 35, Encl. 7; SECNAVINST 5820.7C, supra note 62, para. 7; AFI 10-
801, supra note 38, Attachment 1, ch. 3.
76
10 U.S.C. § 371(b) (2013).
77
10 U.S.C. § 124 (2013); 32 U.S.C. § 112 (2013); Sec. 1004, FY91 NDAA as amended by sec. 1021, FY02 NDAA; sec.
1031, FY97 NDAA; sec. 1033, FY98 NDAA; OFFICE OF THE DEFENSE COORDINATOR FOR DRUG ENFORCEMENT POLICY
AND SUPPORT, POLICY OF 26 JAN. 1995, PRIORITIES, POLICIES, AND PROCEDURES FOR DEPARTMENT OF DEFENSE
COUNTERDRUG SUPPORT TO DOMESTIC DRUG LAW ENFORCEMENT AGENCIES (26 Jan. 1995); CJCSI 3710.01B, supra note
6; NATIONAL GUARD BUREAU, REG. 500-2/ANGI 10-801, NATIONAL GUARD COUNTERDRUG SUPPORT (29 August 2008)
[hereinafter NGR 500-2]. At the time this handbook was published, this regulation was being re-drafted as a CNGB
Manual.
78
10 U.S.C. § 124 (2013).
79 DoDI 3025.21, supra note 35, Encl. 3.
Chapter 12
Funding Domestic Operations
264
Domestic Operational Law Handbook 2021
activities plan.80 The Office of the Defense Coordinator for Drug Enforcement Policy and Support
reviews each State’s implementation plan and disburses funds.
2.
Additional Support
Congress has given DoD additional authorities to support Federal, State, local, and foreign
governments that have counterdrug responsibilities. These are in addition to the authorities contained
in 10 U.S.C. §§ 371-377 (discussed above). These have not been codified, however, so it is necessary
to refer to the public laws instead. Many of these are reproduced in the notes following 10 U.S.C. §
374 in the annotated codes. Section 1004 of the 1991 NDAA, as amended, is the primary authority
used for counterdrug operations. The statute permits broad support to Federal, State, and local as well
as foreign authorities (when requested by a federal counterdrug agency, typically the Drug
Enforcement Agency (DEA) or a member of the State Department country team that has counterdrug
responsibilities). These authorities are not exceptions to the PCA, and any support provided must
comply with the PCA restrictions. Additionally, any domestic training provided must comply with the
Deputy Secretary of Defense policy on advanced training.
Types of permitted support include maintenance and repair of equipment; transportation of personnel
(United States and foreign), equipment, and supplies CONUS/OCONUS; establishment of bases of
operations CONUS/OCONUS; training of law enforcement personnel, to include associated support
and training expenses; detection and monitoring of air, sea, surface traffic outside the United States,
and within 25 miles of the border if the detection occurred outside the United States; construction of
roads, fences, and lighting along U.S. border; linguist and intelligence analyst services; aerial and
ground reconnaissance; and establishment of command, control, communication, and computer
networks for improved integration of law enforcement, active military, and NG activities.81
Approval authorities are contained in CJCSI 3710.01B. Non-operational support—that which does not
involve the active participation of DoD personnel—including the provision of equipment only, use of
facilities, and formal schoolhouse training, is requested and approved in accordance with DoDI
3025.21 and implementing Service regulations, discussed above. For operational support, the
Secretary of Defense is the approval authority. Approval will typically be reflected in a CJCS-issued
deployment order.
The Secretary of Defense has delegated approval authority for certain missions to Combatant
Commanders, with the ability for further delegation, but no delegation lower than a flag officer.82 The
delegation depends on the type of support provided, the number of personnel provided, and the length
of the mission.83 For example, delegation runs from the Secretary to NORTHCOM to Joint Task
Force North (JTF North) for certain missions along the southwest border of the U.S.84 Requests for
DoD support must meet the following criteria:85
80
32 U.S.C. § 112 (2013).
81 CJCSI 3710.01B, supra note 6.
82 Id.
83 Id.
84 Id.
85 Id.
Chapter 12
265
Funding Domestic Operations
Domestic Operational Law Handbook 2021
Support request must have a clear counterdrug connection;
Support request must originate with Federal, state or local agency having counterdrug
responsibilities;
Request must be for a type of support that the Department of Defense is authorized to provide;
Support must clearly assist with counterdrug activities of agency;
Support is consistent with DoD support of the National Drug Control Strategy;
DEP&S Priorities for the provision of support;
Multi-jurisdictional, multi-agency task forces that are in a high intensity drug trafficking area
(HIDTA);
Individual agencies in a HIDTA;
Multi-jurisdictional, multi-agency task forces not in a HIDTA;
Individual agencies not in a HIDTA; and
All approved CD operational support must have military training value.
Under § 1206, of the FY 1990 NDAA, Congress directed the Armed Forces, to the maximum extent
practicable, to conduct training exercises in declared drug interdiction areas. In § 1031 of the FY 1997
NDAA, Congress authorized and provided additional funding specifically for enhanced support to
Mexico. The support involves the transfer of certain non-lethal specialized equipment such as
communication, radar, navigation, and photo equipment. Under § 1033, FY 1998 NDAA, Congress
authorized, and provided additional funding specifically for, enhanced support to Colombia and Peru.
Section 1021 of the FY 2004 NDAA, expands the list of eligible countries to include Afghanistan,
Bolivia, Ecuador, Pakistan, Tajikistan, Turkmenistan, and Uzbekistan. This authority is subject to
extension by the annual National Defense Authorization Act; and was extended by § 1021 of the FY
2009 NDAA.
I.
Innovative Readiness Training (IRT)86
IRT is primarily a guard and reserve program and is similar in appearance to 10 U.S.C. § 401,
Humanitarian and Civic Assistance (HCA) for overseas operations. It is military training conducted
off-base in the civilian community that utilizes the units and individuals of the Armed Forces under the
jurisdiction of the Secretary of a military department or a combatant commander, to assist civilian
86
10 U.S.C. § 2012 (2012); U.S. DEPT OF DEFENSE, INSTR. 1100.24, INNOVATIVE READINESS TRAINING (IRT):
SUPPORT AND SERVICES FOR ELIGIBLE ORGANIZATIONS AND ACTIVITIES OUTSIDE DOD (5 MAY 2020) [hereinafter
DODI1100.24].
Chapter 12
Funding Domestic Operations
266
Domestic Operational Law Handbook 2021
efforts in addressing civic and community needs of the United States, its territories and possessions,
and the Commonwealth of Puerto Rico as provided for within 10 U.S.C. § 2012. Examples of IRT
activities include constructing rural roads and aircraft runways, small building and warehouse
construction in remote areas; transporting medical supplies, equipment and material to medically
underserved areas of the country; and providing medical and dental care to Native Americans, Alaska
Natives, and other medically underserved communities.87
Any Federal, regional, State, or local governmental entity is eligible to receive the assistance, as are
youth and charitable organizations specified in § 508 of Title 32, and any other entity as may be
approved by the Secretary of Defense on a case-by-case basis. There must be a relationship to military
training. Assistance may be provided only if: (1) the assistance provided accomplishes valid unit
training requirements; or (2) the assistance provided by an individual involves tasks that directly relate
to the specific Military Occupational Specialty (MOS) of the military member.88
O&M funding expenditures are authorized for expendable readiness training items only. These may
include, but are not limited to, the following: fuel; equipment lease; travel; training supplies; and
incidental costs to support the training not normally provided for a deployment. IRT O&M funds are
not authorized for the payment of civilian manpower contracts, e.g., contracting a civilian labor force
to perform duties related to IRT activities.89 DoD policy memorandum dated August 24, 2000,
provides guidance that annual NDAAs will authorize the transfer of a certain amount of defense-wide
O&M funds ($20 million in FY03) to be transferred to fund pay and allowances for personnel working
on IRT program projects. In April 2002, the Department of Defense issued additional guidelines to
include the requirement for a Certification of Non-Competition with other public or private sector
organizations. This comports with the statutory language that “the assistance is not reasonably
available from a commercial entity.”90 IRT assistance is not authorized in response to natural or man-
made disasters or in support of civilian law enforcement.91
J. DoD Support to Special Events92
Upon the request of a Federal, State, or local government agency responsible for providing law
enforcement services, security services, or safety services, the Secretary of Defense may authorize a
Combatant Commander, a commander of a military installation, or a commander of another DoD
facility, to provide assistance for special events. This includes international sporting events such as
World Cup Soccer Games, the Goodwill Games, the Olympics, and any other civilian sporting event.
The Attorney General must certify that such assistance is necessary to meet essential security or safety
needs.
87 DOD MANUAL 3025.01, VOL. 3. DEFENSE SUPPORT OF CIVIL AUTHORITIES: PRE-PLANNED DOD SUPPORT OF LAW
ENFORCEMENT AGENCIES, SPECIAL EVENTS, COMMUNITY ENGAGEMENT, AND OTHER NON-DOD ENTITIES (11 Aug. 2016)
(Ch.1 13 Apr. 2017), sec. 10.3 [hereinafter DODM 3025.01, VOL 3.]
88 Id., 3.1.
89
19 July 1999, DoD Policy Memorandum Regarding Innovative Readiness Training O&M Funds (on file with CLAMO).
90
10 U.S.C. § 2012 (2012).
91 DoDI 1100.24, supra note 86.
92
10 U.S.C. § 2564 (2012); U.S. DEPT OF DEFENSE, INST. 3025.20, DEFENSE SUPPORT OF SPECIAL EVENTS (6 Apr. 2012)
(C. 1, 24 May 2017) [hereinafter DoDI 3025.20].
Chapter 12
267
Funding Domestic Operations
Domestic Operational Law Handbook 2021
Additional conditions are that such assistance cannot reasonably be met by another source or agency,
that there is no adverse impact on military readiness, and that the requesting agency agrees to
reimburse the Department of Defense.93 It is important to note that the applicable statutory provision
for these events does not apply to Special Olympics and The Paralympics because the assistance is
authorized and funded under a different authority, the Support for International Sporting Competitions
(SISC) account that funds support of International Sporting Competitions. Support provided under this
statute, 10 U.S.C. § 2564, is reimbursable under the Economy Act, unless the support is provided in
the normal course of training or operations, or the support results in a substantially equivalent training
value.
The SISC account is a “no year” account that consolidated appropriations of previous events. As noted
earlier, the Department of Defense transfers O&M into this account. Because the account is set up as a
“no year use until expended account,” that rule applies to any money transferred into the account. The
account authorized the funding of logistical and security support (other than pay and non-travel-related
allowances of members of the Armed Forces of the United States, except for members of the reserve
components thereof called or ordered to active duty in connection with providing such support).
In the NDAA for fiscal year 2002, Pub. L. No. 107-107, § 302, Congress amended the law to include
state active duty and full-time NG to be included in the definition of “active duty.” Under this change,
the SISC account could fund the pay and non-travel-related allowances of these two groups of
individuals when they provided essential security and safety support during the 2002 Winter Olympic
Games and the 2002 Paralympic Games. In the same provision, Congress waived the requirement that
the Attorney General had to certify that support was necessary for the 2002 Winter Olympic Games. It
is important to note that this waiver was event-specific, and ordinarily certification by the Attorney
General is required.
K. Support to Private Organizations and Individuals
1.
Boy Scouts of America
10 U.S.C. § 2554 allows the Department of Defense to provide equipment and transportation to the
Boy Scouts for National and World Jamborees. Support is provided on a no-cost basis to the U.S.
Government and requires bonding to ensure reimbursement.
2.
Girl Scouts of America
10 U.S.C. § 2555 allows the Department of Defense to provide transportation only to Girl Scouts to
support international Girl Scout events. Support is provided on a no-cost basis to the U.S. Government
and requires bonding to ensure reimbursement.
3.
National Veterans’ Organizations
Pursuant to 10 U.S.C. § 2551, the Department of Defense may provide equipment and barracks to
national veterans’ organizations to support state and national conventions or national youth athletic
93 Id., Encl. 3.
Chapter 12
Funding Domestic Operations
268
Domestic Operational Law Handbook 2021
tournaments. Support is provided on a no-cost basis to the U.S. Government and requires bonding to
ensure reimbursement.
4.
American Red Cross
10 U.S.C. § 2552 allows the Department of Defense o provide equipment for instruction and practice
to the American Red Cross. Support is provided on a no-cost basis to the U.S. Government and
requires bonding (twice value of equipment loaned) to ensure reimbursement.
5.
National Military Associations
Pursuant to 10 U.S.C. § 2558, the Department of Defense may provide specified support to designated
“National Military Associations” for their national conventions. Specified support includes limited air
and ground transportation, communications, medical assistance, administrative support, and security
support. Support is provided under the following conditions: (1) the Service Secretary concerned has
approved the support in advance; (2) the support is provided in conjunction with training in appropriate
military skills; and (3) support can be provided within existing funds otherwise available to the Service
Secretary concerned, i.e., O&M funds.
6.
Homeless Individuals
10 U.S.C. § 2556 allows for DoD provision of incidental services to shelter homeless individuals.
These incidental services include utilities, bedding, security, transportation, renovation of facilities,
minor repairs to make facility available, and property liability insurance. Support is on a non-
reimbursable basis and may not have an adverse impact on military readiness or interfere with military
operations.
L. Loan or Lease of Non-Excess Property of a Military Department94
1.
Authorized Loan or Lease of Non-Excess Property
Generally, the Economy Act, 10 U.S.C. § 1535, governs the loan of DoD supplies and other equipment
to other Federal agencies on a reimbursable basis. The leasing statute, 10 U.S.C. § 2667, governs the
lease of DoD property to organizations outside the government when a determination has been made
that: (1) for the period of the lease, the materiel is not needed for public use; (2) it is not excess
property; and (3) the lease will promote the national defense or be in the public interest.
The Army is the only Service that has a regulation specifically governing the loan or lease of its
materiel: AR 700-131. Army Policy is that Army materiel is intended for the Army mission, and may
only be loaned or leased under compelling circumstances and when the material sought is not
otherwise needed for mission requirements. Agencies loaning or leasing materiel from an Army
activity are responsible for all costs associated with the loan or lease to include shipping, return, and
repair of the materiel. The primary determining factors for loans and leases are (1) the basis of their
94
10 U.S.C. § 2667 (2012); U.S. DEPT OF ARMY, REG. 700-131, LOAN, LEASE, AND DONATION OF ARMY MATERIEL (23
Aug. 2004) [hereinafter AR 700-131]; U.S. DEPT OF ARMY, REG. 725-1, SPECIAL AUTHORIZATION AND PROCEDURES FOR
ISSUES, SALES, AND LOANS (17 Oct. 2003) [hereinafter AR 725-1].
Chapter 12
269
Funding Domestic Operations
Domestic Operational Law Handbook 2021
purpose and (2) the duration. Consider the following factors in determining whether to approve a loan
or lease:
Military requirements and priorities;
Stocks and programmed Army requirements;
Type classification with pending changes;
Minimum diversion of Army stocks;
The adequacy of the borrower’s resources;
The availability of alternative resources such as commercial leases; and
The eligibility of the recipient.
The approval authority for a loan or lease of Army materiel varies based on the category of the
requested equipment. Table 2-1, AR 700-131 provides a comprehensive list of the categories of
equipment that may be loaned or leased, and the proper approval authority. A command must report
any Army material loaned or leased in response to a natural or manmade disaster to JDOMS as soon as
possible. The property officer who is accountable for the equipment loaned or leased will keep all
records of loans of DoD material. Loans are made at no additional cost to the government. Borrowers
are responsible for all incremental costs (costs above the normal Army operating expenses) and these
will be identified and added into the loan agreement.
Agencies loaning or leasing materiel from an Army activity are responsible for all costs associated
with the loan or lease to include shipping, return, and repair of the materiel. Reimbursable incremental
costs include the following:
Any overtime pay and pay of additional civilian personnel required to accompany, operate,
maintain, or safeguard borrowed equipment;
Travel and per diem expenses of Army personnel (military and civilian);
Packing, crating, handling, and shipping from supply source to destination and return, to
include port loading and off-loading;
All transportation, including return for repair and renovation;
Hourly rate for the use of Army aircraft;
Petroleum, oils, and lubricants (including aviation fuel);
The cost of material lost, destroyed, or damaged beyond economical repair;
Utilities (gas, water, heat, and electricity);
Chapter 12
Funding Domestic Operations
270
Domestic Operational Law Handbook 2021
Any modification or rehabilitation or real property that affects its future use by the Army;
Overhaul of returned material;
Repair parts used in maintenance and renovation;
Price decline of borrowed stock fund material at which returned property can be sold;
Issue and turn-in inspection labor costs;
Charges for the use of vehicles, except petroleum, oils, and lubricants and per diem costs;
Use of real property;
Restoration costs for historical property; and
Lease fees.
It is important to note that in addition to the above reimbursable costs, leases require the borrower to
pay a lease fee equal to the fair market value of the lease interest in the property.
2.
Emergency Exceptions
Emergency loans or leases are those made to prevent “loss of life, grave bodily harm, or major
destruction of property, and when the lack of communications facilities prevents the use of normal
procedures.” Emergency loans and leases will not be withheld because a formal reimbursement
agreement has not been negotiated and concluded. Additionally, loans or leases that would otherwise
be permitted by service regulations may be approved under emergency conditions at the local level,
vice the approval level designated in Table 2-1 of AR 700-131. Emergency requests for the loan or
lease of Army materiel may be verbal or electronic in nature. The borrower must send a formal written
request to the lending agency as soon as possible, and must complete a loan or lease agreement within
five days of the original transaction.
3.
Additional Requirements
Leases carry additional requirements under AR 700-131. Army materiel will not be leased if a
reasonable counterpart can be purchased or leased in the commercial market. Leases are limited to a
maximum five-year term unless the Secretary of the Army (SECARMY), or one of his designees,
approves an extended lease term. The SECARMY also has the authority to revoke a loan or a lease at
any time. Lessees must post a surety bond to cover damage or loss of the leased property and, if
necessary, show proof of either vehicular or hull insurance. In an emergency a lease may be made
without a bond, but the bond must be posted within five days of the lease. FAR Part 28 governs the
bonding requirements. The SECARMY must approve any bond forfeiture. Bonds are normally
forfeited when the materiel is not returned at the end of the lease period or the lessee refuses to pay for
damage or other lease expenses.
Once a loan or lease is approved, a loan or lease agreement will be entered into before the materiel is
delivered. The agreement will reflect the statutory basis for the loan or lease, and will describe in
Chapter 12
271
Funding Domestic Operations
Domestic Operational Law Handbook 2021
detail all terms of the loan or lease and the responsibilities of both parties. The official accountable for
the property of the borrowing activity must sign the loan or lease agreement. The loan or lease
agreement will be held by the activity that issues the material until final settlement. When the
Department of Defense has made a lease of personal property, the costs associated with the lease are
placed into a special account established for the respective defense agency whose property is subject to
the lease. Amounts in the account are available solely for maintenance, repair, restoration or
replacement of leased personal property.
M. Explosive Ordnance Disposal (EOD)95
EOD is the detection, identification, field evaluation, rendering safe, recovery, and final disposition of
unexploded explosive ordnance (UXO).96 Explosive Ordnance Disposal operations outside of DoD
installations are primarily the responsibility of civil authorities. DoD assistance may be provided in
the form of EOD actions and/or advice, upon request from Federal agencies or civil authorities at any
level, when the Service concerned determines that such assistance is required or desirable in the
interest of public safety.97 Each Service is responsible for all self-caused Explosive Ordnance
contamination on its own installations and operation bases.98
N. Military Working Dogs99
Military working dogs include patrol dogs, and patrol dogs with specialized training in either
narcotic/contraband detection or explosive detection.100 Explosive Detector Dog team assistance may
be provided to Federal agencies or civil authorities. Upon a request from a Federal agency or State or
local civilian authority at any level, the installation commander concerned determines that the
“provision of the requested assistance is lawful, required in the interest of public safety and meets the
requirements of DoDD 3025.18 or DoDI 3025.21.”101
95 U.S. DEPT OF ARMY, U.S. DEPT OF NAVY, AND U.S. DEPT OF AIR FORCE, REG. 75-14/INSTR. 8027.7/AFI 32-3002-
O/MCO 8027.1E, INTER-SERVICE RESPONSIBILITIES FOR EXPLOSIVE ORDNANCE DISPOSAL (17 Mar. 2020) [hereinafter AR
75-14]; U.S. DEPT OF ARMY, REG. 75-15, POLICY FOR EXPLOSIVE ORDNANCE DISPOSAL (17 Dec. 2019) [hereinafter AR
75-15]; DODI 3025.21, supra note 35, Encl. 5.
96 AR 75-14, supra note 95.
97 Id. para. 4-3.
98 Id. para. 2-3.
99 DODD 5200.31E, supra note 68; U.S. DEPT OF ARMY, REG. 190-12, MILITARY WORKING DOG PROGRAM (23 Oct. 2019)
[hereinafter AR 190-12].
100 AR 190-12, supra note 99.
101 AR 75-15, supra note 95, para. 3-15.
Chapter 12
Funding Domestic Operations
272
Domestic Operational Law Handbook 2021
O. Miscellaneous Support102
To respond to an emergency involving biological or chemical weapons of mass destruction that is
beyond the capabilities of the civil authorities to handle, the Secretary of the Department of Homeland
Security may request DoD assistance directly. Available assistance would include monitoring,
containing, disabling, and disposing of the weapon. For weapons of mass destruction, Federal funding
is provided to the Department of Defense to develop and maintain domestic terrorism rapid response
teams (Civil Support Teams) to aid Federal, State, and local officials and responders. Civil Support
Teams are composed of full time Army and Air NG members. These teams are Federally resourced,
trained, evaluated, and they operate under Federal doctrine. They perform their missions, however,
primarily under the command and control of state governors.103
P. Funding Issues Related to the Use of NG in Domestic Operations
The NG is both an “organized militia” of a State, as well as a reserve component of both the Army and
the Air Force. When referring to the NG’s Federal reserve component status, the appropriate term is
“NG of the United States.” In terms of domestic operations, it is important to recognize that NG
members are in one of three statuses: (1) Title 10, (2) Title 32 and (3) State Active Duty (SAD). When
NG members are mobilized and placed on Title 10 orders, they are Federally-funded and under a
Federal chain of command like any other active component Airman or Soldier. Typically, this is seen
when a NG unit is mobilized for OCONUS military operations. When they are serving in a Title 32
capacity, they are Federally funded, but operating under a “State” chain of command up to the State’s
Governor. The most typical use of NG members in a Title 32 status is when they are performing their
required weekend training or their two-weeks of Annual Training. When they are serving in a SAD
status, they are funded by the State, and are under a State chain of command. That is, often times
when a NG unit is performing a State emergency response (e.g., flood, wildfires, etc.) they are often in
a purely State status, and being paid out of that State’s funding (as opposed to Federal funding).
In terms of Domestic Operations, there is a specific DoD Instruction that covers the employment of
NG personnel in a Title 32 status—DoDI 3025.22, “The Use of the NG for Defense Support to Civil
Authorities.” It explains that the Secretary of Defense, with the concurrence of the affected Governors,
is the “sole authority” to authorize DoD funding of the NG for DoD operations or missions, including
DSCA. If authorized by SecDef to perform Federally-funded (Title 32) domestic operations, the NG
personnel are typically performing such operations pursuant to 32 U.S.C § 502(f). Accordingly, the
NG Service members performing such operations are paid out of the Army NG and Air NG personnel
accounts. If this type of Title 32 duty is pursuant to a Mission Assignment from FEMA, FEMA may
reimburse those military personnel accounts under the Stafford Act. That is, if the Secretary of
Defense determines that the NG is the appropriate sourcing solution for a FEMA mission assignment
and authorizes the use of NG personnel to perform the mission in a Title 32 status, FEMA may
reimburse the accounts from Disaster Relief Funds. This use of Federal funding for a SecDef-
102
10 U.S.C. §§ 379, 382 (2012); National Defense Authorization Act for Fiscal Year 1997, Pub. L. 104-201, Title XIV
(Defense Against Weapons of Mass Destruction), 110 Stat. 2422 (1996); U.S. DEPT OF DEFENSE, DIR. S-5210.36,
PROVISION OF DOD SENSITIVE SUPPORT TO DOD COMPONENTS AND OTHER DEPARTMENTS AND AGENCIES OF THE U.S.
GOVERNMENT (U) (6 NOV. 2008) [hereinafter DoDD 5210.36].
103 See supra Chapters 3 and 6 for more information on these teams.
Chapter 12
273
Funding Domestic Operations
Domestic Operational Law Handbook 2021
authorized use of the NG is not to be confused with the use of a State’s NG in a SAD status. Again,
when NG members are performing operations in a SAD status, the costs of that type of mission are
borne by the State, and not by the Department of Defense.
Finally, in order to understand the Federal funding for the NG, it is important for judge advocates to
understand the role of the NG Bureau (NGB), and NGB’s United States Property and Fiscal Officers,
(USPFOs). NGB is a “Joint Activity of the Department of Defense,” with statutory authority
stemming from 10 U.S.C. § 10501-10508. The primary DoD-level implementation of that authority is
set out in the NGB Charter—DoDD 5105.77. The NGB is led by the Chief of NGB (CNGB), who is a
four-star general and a member of the Joint Chiefs of Staff. CNGB is responsible for planning and
administering the budgets of the Army NG and the Air NG of the United States. CNGB is also
responsible for supervising the acquisition/supply/accountability for Federal property issue to the NG
through the USPFO.104
As applied to domestic operations, the USPFOs (as the agents of Service Secretaries through CNGB)
play a central role at the State NG level in terms of providing oversight for Federal funds and Federal
equipment that is in the possession of their State’s NG. During a SAD mission, the State’s Adjutant
General (Commander of that State’s NG) has the authority to use Federal equipment for State
emergency response as determined by the Governor. The USPFOs are responsible for tracking the
Federal equipment (particularly vehicles and helicopters) for reimbursement purposes. Following a
SAD mission, the USPFO presents a bill to the State for reimbursement.
104 See 10 U.S.C. § 10503.
Chapter 12
Funding Domestic Operations
274
Domestic Operational Law Handbook 2021
Chapter 12
275
Funding Domestic Operations
Domestic Operational Law Handbook 2018
CHAPTER 13
CYBERSPACE OPERATIONS IN THE NATIONAL GUARD
KEY REFERENCES:
National Security Presidential Memorandum 13 (NSPM-13), 2018.
Support and Services for Eligible Organizations and Activities Outside Department of Defense, 10
U.S.C. § 2012 et seq.
The Computer Fraud and Abuse Act, 18 U.S.C. § 1030 et seq.
Electronic Communications Privacy Act of 1986 (ECPA), 18 U.S.C. §§ 2510-2523.
The Wiretap Act, 18 U.S.C. § 2511 et seq.
The Stored Communications Act, 18 U.S.C. § 2701 et seq.
The Pen Trap and Trace Act, 18 U.S.C. § 3121 et seq.
National Guard, 32 U.S.C. § 502 et seq.
Executive Order (E.O.) 12333 - U.S. Intelligence Activities, December 4, 1981, as amended by
E.O. 13284 (2003), E.O. 13355 (2004) and E.O. 13470 (2008).
E.O. 13636, Improving Critical Infrastructure Cybersecurity.
Presidential Policy Directive 41, United States Cyber Incident Coordination, 26 July 2016.
Department of Defense, Cyber Strategy, (Washington, D.C. 2018).
Department of Defense Directive (DoDD) 1100.20, Support and Services for Eligible
Organizations and Activities Outside the Department of Defense, 12 April 2004.
DoDD 3025.18, Defense Support of Civil Authorities (DSCA), 29 December 2010, Incorporating
Change 2, 19 March 2018.
DoDD 5148.13, Intelligence Oversight, 26 April 2017.
DoDD 5240.01, DoD Intelligence Activities, 27 August 2007, Incorporating Change 3, 9
November 2020.
Department of Defense Instruction (DoDI) 1215.06, Uniform Reserve, Training and Retirement
Categories, 11 March 2014, Incorporating Change 1, Effective 19 May 2015.
DoDI 1100.24, Innovative Readiness Training (IRT): Support and Services for Eligible
Organizations and Activities Outside DoD, 5 May 2020.
DoDI 3025.21, Defense Support of Civilian Law Enforcement Agencies, 27 February 2013
Incorporating Change 1, Effective 8 February 2019.
DoDI 3025.22, The Use of National Guard for Defense Support of Civil Authorities, 26 July 2013,
Incorporating Change 1, Effective 15 May 2017.
DoDI 4000.19, Support Agreements, 16 December 2020.
DoD Manual 5240.01, Procedures Governing the Conduct of Intelligence Activities, 8 August
2016.
DoD 5240.1-R, Procedures Governing the Activities of DoD Intelligence Components that Affect
United States Persons, December 1982, Incorporating Change 2, Effective 26 April 2017.
Joint Publication 3-12, Cyberspace Operations, 8 June 2018.
SecDef Memorandum, Leveraging Military Training for Incidental Support of Domestic Civilian
Law Enforcement Agencies Information Needs, 14 Jul 2017.
SecDef Memorandum, Reimbursable Activities in Support of Other Entities, 19 Jun 2020.
Directive Type Memorandum (DTM) 17-007, Interim Policy and Guidance for Defense Support to
Cyber Incident Response, 21 June 2017, Incorporating Change 2, 6 June 2019.
Chapter 13
Cyberspace Operations in the National Guard
276
Domestic Operational Law Handbook 2021
Deputy Secretary of Defense (DepSecDef) Policy Memorandum (PM) 16-002, Cyber Support and
Service Provided Incidental to Military Training and National Guard Use of DoD Information
Networks, Software, and Hardware for State Cyberspace Activities, 24 May 2016.
Extension of Policy Memorandum 16-002, Cyber Support and Services Provided Incidental to
Military Training and National Guard Use of DoD Information Networks, Software, and Hardware
of State Cyberspace Activities, 1 March 2018.
Extension to Policy Memorandum 16-002, Cyber Support and Services Provided Incidental to
Military Training and National Guard Use of DoD Information Networks, Software, and Hardware
for State Cyberspace Activities, 18 October 2018.
Transition of Policy Memorandum 16-002, Cyber Support and Services Provided Incidental to
Military Training and National Guard Use of DoD Information Networks, Software, and Hardware
for State Cyberspace Activities, 21 March 2019.
Extension to Policy Memorandum 16-002, Cyber Support and Services Provided Incidental to
Military Training and National Guard Use of DoD Information Networks, Software, and Hardware
for State Cyberspace Activities, 2 March 2020.
SecDef Memorandum, Definition of Department of Defense Cyberspace Operations Forces (DoD
COF), 2 December 2019.
DA CIO and DAF CIO Memorandum, Transition of Policy Memorandum 16-002 Policy on
National Guard Use of Federal Property for State Cyberspace Activities, 11 Feb 2021.
National Guard Cyber Strategy, 5 Jan 2018.
National Guard Regulation (NGR) 5-2, National Guard Support Agreements, 14 Oct 2010.
NGR 350-1, Army National Guard Training, 4 August 2009.
Air National Guard Instruction 36-2001, Management of Training and Operational Support within
the Air National Guard, 30 April 2019.
OpJAGAF 2005/36, 28 July 2005, AIR NATIONAL GUARD JAO.
Department of Homeland Security, National Response Framework, (October 2019).
Department of Homeland Security, National Cyber Incident Response Plan, (December 2016).
A. Introduction
Cyberspace, while part of the information environment, is dependent on the air, land, maritime, and
space physical domains. Much as operations in the physical domains rely on physical infrastructure
created to take advantage of naturally occurring features, operations in cyberspace rely on networked,
stand-alone, and platform-embedded Information Technology (IT) infrastructure, in addition to the
data that resides on, and is transmitted through, these components, to enable military operations in a
man-made domain.
Cyberspace presents unique challenges by threats from nation-states to individual actors to accidents
and natural hazards; anonymity and difficulties with attribution; geography challenges; technology
challenges; and private industry and public infrastructure ownership.1 Cyberspace reaches across
geographic and geopolitical boundaries. It is integrated in the operation of critical infrastructures, as
well as the conduct of commerce, governance, and national defense activities.2 While many elements
1 Joint Publication 3-12, Cyberspace Operations, 8 June 2018 [hereinafter JP 3-12].
2 Id.
Chapter 13
277
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
of cyberspace can be mapped geographically, a full understanding of an adversary’s disposition and
capabilities in cyberspace involves understanding the target, not only at the underlying physical
network layer but also at the logical network layer and cyber-persona layer, including profiles of
system users and administrators and their relationship to adversary critical factors.3
For example, cyberspace activities are generally not linear in nature. One computer does not normally
interact directly with another computer. Rather, data is transferred through multiple routers and
servers, all of which are not always in the same town, state or even country. As a result, actions
intended to have a domestic effect in cyberspace could have international consequences. Another
consideration is that most military equipment is not governed by restrictive licensing agreements,
whereas software licensing agreements may restrict who may use a cyber-tool kit and how it can be
used. Finally, attribution is not as clear as in the kinetic realm. What may appear to be an action taken
by a local resident could be an action orchestrated by a foreign actor.
This complex and evolving battle space requires legal practitioners to have both a basic understanding
of how the cyberspace works as well as the laws and policies governing those actions.
B. DoD Cyberspace Missions
The 2018 DoD Cyber Strategy directs the Department of Defense to defend forward, shape the day-to-
day competition, and prepare for war by building a more lethal force, expanding alliances and
partnerships, reforming the Department, and cultivating talent, while actively competing against and
deterring our competitors in cyberspace.4
Cyberspace operations (CO) is the employment of cyberspace capabilities where the primary purpose
is to achieve objectives in or through cyberspace. The Department of Defense has three cyberspace
missions: offensive cyberspace operations (OCO), defensive cyberspace operations (DCO), and DoD
Information Network (DoDIN) operations. These three mission types comprehensively cover the
activities of the cyberspace forces.5
DoDIN Operations. The DODIN operations mission includes operational actions taken to
secure, configure, operate, extend, maintain, and sustain DoD cyberspace and to create and
preserve the confidentiality, availability, and integrity of the DoDIN.
DCO. DCO missions are executed to defend the DoDIN, or other DoD cyberspace forces have
been ordered to defend, from active threats in cyberspace.
OCO. OCO are CO missions intended to project power in and through foreign cyberspace
through actions taken in support of CCDR or national objectives.6
3 Id.
4 Department of Defense, Cyber Strategy, (Washington D.C. 2018).
5 JP 3-12, supra note 1, II-2.
6 Id. at II-2-3.
Chapter 13
Cyberspace Operations in the National Guard
278
Domestic Operational Law Handbook 2021
Cyberspace missions are categorized as OCO, DCO, or DoDIN operations based only on the intent or
objective of the issuing authority, not based on the cyberspace actions executed, the type of military
authority used, the forces assigned to the mission, or the cyberspace capabilities used.7
Authority for CO actions undertaken by the U.S. Armed Forces is derived from the U.S. Constitution
and Federal law. Authorities for specific types of military COs are established within SecDef policies,
including DoD instructions, directives, and memoranda, as well as in Executive Orders and operational
orders issued by the Secretary of Defense and subordinate commanders approved to execute the
subject missions.8
Judge advocates practicing in this area should review National Security Presidential Memorandum 13
(NSPM-13), a classified document providing the overall guidance for cyber activities conducted by the
United States, in its entirety. It is important to note that capability does not mean authority.
Understanding the effects of cyber capabilities is key to determining the necessary authority to
perform a DoD cyber mission. The Department of Defense conducts COs consistent with U.S.
domestic law, applicable international law, and relevant Federal Government and DoD policies. The
laws that regulate military actions in U.S. territories also apply to cyberspace. Therefore, DoD
cyberspace forces that operate outside the DoDIN, when properly authorized, are generally limited to
operating in gray and red9 cyberspace only, unless they are issued different rules of engagement or
conducting defense support of civil authorities (DSCA) under appropriate authority. Since each CO
mission has unique legal considerations, the applicable legal framework depends on the nature of the
activities to be conducted, such as OCO or DCO, DSCA, internet service provider (ISP) actions, law
enforcement and counterintelligence activities, intelligence activities, and defense of the homeland.10
These DoD cyber missions can be categorized as defensive or offensive operations (as depicted in
Figure 1. Cyberspace Operations) depending on the capability and the effects of that capability.11
7 Id. at III-2.
8 Id.
9 The term “blue cyberspace” denotes areas in cyberspace protected by the United States, its mission partners, and other
areas DoD personnel may be ordered to protect. Although the Department of Defense has standing orders to protect only
the DoD information network (DoDIN), cyberspace forces prepare on order, and when requested by other authorities, to
defend or secure other United States Government (USG) or other cyberspace, as well as cyberspace related to critical
infrastructure and key resources (CI/KR) of the United States and partner nations. The term “red cyberspace” refers to those
portions of cyberspace owned or controlled by an adversary or enemy. All cyberspace that does not meet the description of
either “blue” or “red” is referred to as “gray” cyberspace. Id. at I-4-5.
10 Id. at III-11.
11 Brett T. Williams, The Joint Force Commander’s Guide to Cyberspace Operations, 73 J. FORCE Q., 12, 14 (2d Q. 2014).
Chapter 13
279
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
1.
Protecting the DoDIN
The DoDIN operations mission includes operational actions taken to secure, configure, operate,
extend, maintain, and sustain DoD cyberspace and to create and preserve the confidentiality,
availability, and integrity of the DoDIN. These include proactive cyberspace security actions which
address vulnerabilities of the DoDIN or specific segments of the DoDIN. It also includes the set-up of
tactical networks by deployed forces to extend existing networks, maintenance actions and other non-
security actions necessary for the sustainment of the DoDIN, and the operation of red teams and other
forms of security evaluation and testing.
DoDIN operations are network-focused and threat-agnostic: the cyberspace forces and workforce
undertaking this mission endeavor to prevent all threats from negatively impacting a particular network
or system they are assigned to protect. They are threat-informed and use all available intelligence about
specific threats to improve the security posture of the network. DoDIN operations does not include
actions taken under statutory authority of a chief information officer (CIO) to provision cyberspace for
Chapter 13
Cyberspace Operations in the National Guard
280
Domestic Operational Law Handbook 2021
operations, including IT architecture development; establishing standards; or designing, building, or
otherwise operationalizing DoDIN IT for use by a commander.12
Cyberspace security actions are a primary component action of the DoDIN operations mission.
Examples of cyberspace security actions include increasing password strength, installing a software
patch to remove vulnerabilities, encrypting stored data, training users on cyberspace security best
practices, restricting access to suspicious Web sites, or blocking traffic on unused router ports.13
Service-retained cyberspace forces, CCMD cyberspace forces, RC forces, and DoD agency and
activity staffs execute much of the DoDIN operations required to secure and operate the various
backbones, sub-nets, segments, enclaves, and private networks of the DoDIN under the planning,
direction, integration, and synchronization of the JFHQ-DoDIN
2. Defensive Cyberspace Operations (DCO)
DCO missions are executed to defend the DoDIN, or other cyberspace DoD cyberspace forces have
been ordered to defend, from active threats in cyberspace. Specifically, they are missions intended to
preserve the ability to utilize blue cyberspace capabilities and protect data, networks, cyberspace-
enabled devices, and other designated systems by defeating on-going or imminent malicious
cyberspace activity. DCO missions, which defeat specific threats that have bypassed, breached, or are
threatening to breach security measures, are distinguishable from DoDIN operations, which endeavor
to secure DoD cyberspace from all threats in advance of any specific threat activity.
DCOs are threat-specific and frequently support mission assurance objectives. DCO missions are
conducted in response to specific threats of attack, exploitation, or other effects of malicious
cyberspace activity and leverage information from maneuver, intelligence collection,
counterintelligence (CI), law enforcement (LE), and other sources as required. DCOs include
outmaneuvering or interdicting adversaries taking or about to take actions against defended cyberspace
elements, or otherwise responding to imminent internal and external cyberspace threats. The goal of
DCO is to defeat the threat of a specific adversary and/or to return a compromised network to a secure
and functional state. The components of DCO are DCO-Internal Defensive Measures (DCO-IDM),
Defensive Cyberspace Operations-Response Actions (DCO-RA), and Defense of Non-DOD
Cyberspace.
DCO-IDM. DCO-IDM are those actions taken internally to friendly cyberspace.14 DCO-IDM are the
form of DCO mission where authorized defense actions occur within the defended network or portion
of cyberspace. It includes pro-active and aggressive internal threat hunting for advanced and/or
persistent threats, as well as the active internal countermeasures and responses used to eliminate these
threats and mitigate their effects. For example, CPT operations conducted on key terrain in
cyberspace, for mission-critical assets in response to indications of malicious cyberspace activity, are
DCO-IDM missions, even before indicators of compromise exist.15 In other words, DCO-IDM include
12 Id.at II-2.
13 Id.at II-6.
14 WILLIAMS, supra note 11, at 16.
15 JP 3-12, supra note 1, at II-4.
Chapter 13
281
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
hunting on friendly cyber terrain for threats attempting to evade security protocols and directing
appropriate internal responses.16
Cyberspace defense actions are the component actions of a DCO-IDM mission. Cyberspace defense
actions are taken within protected cyberspace to defeat specific threats that have breached or are
threatening to breach the cyberspace security measures and include actions to detect, characterize,
counter, and mitigate threats, including malware or the unauthorized activities of users, and to restore
the system to a secure configuration.17 Internal countermeasures are cyberspace defense actions taken
as part of a DCO-IDM mission; for example, closing router ports being used by an adversary for
unauthorized access or blocking malware that is beaconing out of the DoDIN.18
DCO-RA. DCO-RA are the form of a DCO mission where actions are taken external to the defended
network or portion of cyberspace without the permission of the owner of the affected system.
DCO-RA actions “are normally in foreign cyberspace.”19 DCO-RA are taken outside the DoDIN to
stop or block an attack. Cyberspace exploitation actions and cyberspace attack actions are taken as part
of a DCO-RA mission.20 An example of DCO-RA is shutting down an external router from which
malicious activity is emanating. Some DCO-RA missions may include actions that rise to the level of
use of force, with physical damage or destruction of enemy systems. DCO-RA missions “require a
properly coordinated military order and careful consideration of scope, rules of engagement, and
measurable objectives.”21 In other words, DCO-RA include activities “outside friendly network space
to stop an attack before it reaches our key cyber terrain.”22 To use a metaphor, we “catch arrows”
with DCO-IDM and we “kill the archer” with DCO-RA.
Defense of Non-DoD Cyberspace. DCOs generally focus on the DoDIN, which includes all of DoD
cyberspace. However, military cyberspace forces prepare to defend any U.S. or other blue cyberspace
when ordered. DoD operations rely on many non-DoD segments of cyberspace, including private
sector and mission partner networks, security of which is the responsibility of the resource owners,
including other Federal departments and agencies, private sector entities, and other partners. Since
DoD associated cyberspace are known targets for malicious cyberspace activity, protection of these
non-DoD networks and systems can be a vital component of mission assurance. However, the
Department of Defense cannot guarantee the robustness of the security standards applied to such
networks. The commander’s mission risk analysis should account for this uncertainty in the security of
non-DoD cyberspace.
When required under a specific authorizing order, and in full coordination with DHS and other
Federal departments and agencies, DoD cyberspace forces undertake DCO-RA and DCO-IDM
missions to defend these and other non-DoD cyberspace segments, like national CI/KR or partner
networks. Prioritization schemes for defense of CI/KR should be established in advance. If DCO-IDM
missions are ordered as part of a defense support of a civil authorities (DSCA) operation, active
16 WILLIAMS, supra note 11, at 16.
17 JP 3-12, supra note 11, at II-4.
18 Id.
19 Id. at II-4.
20 Id.
21 Id.
22 WILLIAMS, supra note 11, at 16.
Chapter 13
Cyberspace Operations in the National Guard
282
Domestic Operational Law Handbook 2021
component forces may be supported by National Guard (NG) forces activated under Title 32 if
authorized by the Secretary of Defense or Title 10.23
3.
Offensive Cyberspace Operations (OCO)
OCO are CO missions intended to project power in and through foreign cyberspace through actions
taken in support of CCDR or national objectives. All CO missions conducted outside of blue
cyberspace with a commander’s intent other than to defend blue cyberspace from an ongoing or
imminent cyberspace threat are OCO missions. Some OCO missions may include actions that rise to
the level of use of force, with physical damage or destruction of enemy systems. OCO missions
require a properly coordinated military order and careful consideration of scope, ROE, and measurable
objectives.24 Cyberspace exploitation actions and cyberspace attack actions are taken as part of an
OCO mission.25 An example of OCO is hacking an adversary’s computer without the owner’s
knowledge or consent. Authorities governing OCO activities are classified and a detailed description
is outside the scope of this handbook. However, briefly stated, OCO represents a synergy between
Title 50 (national intelligence) authorities to collect signals intelligence, and Title 10 (military)
authorities to apply force in that realm. For full situational awareness and to advise on mission
capability and authority, judge advocates must obtain the appropriate security clearance to fully
understand the DoD cyber missions, including classified portions of the missions.
The following table illustrates where each cyber activity falls into the DoD cyber mission.
DoD Cyber
Cyber Activity
Mission
DCO-IDM
Cyberspace security
Cyberspace defense
Internal countermeasures
OCO
Cyberspace exploitation, including military intelligence
activities, maneuver, information collection, and other
DCO-RA
enabling actions requires to prepare for future military
operations
External countermeasures
OCO
Cyberspace attack:
Deny (degrade, disrupt, destroy)
DCO-RA
Manipulate
External countermeasures
23 JP 3-12, supra note 1, at II-5.
24 Id. at II-5.
25 Id.
Chapter 13
283
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
C. DoD Cyber Operations Forces (DoD COF)
The DoD COF consists of units organized, trained, and equipped to conduct offensive cyberspace
operations, defensive cyberspace operations, and DoDIN operations. 26 There are five operational
groups (Group 1-5) specifically categorized as DoD COF, including cyber mission forces, U.S. Cyber
Command Subordinate Command elements, DoD Component Network Operations Centers and Cyber
Security Service Providers, special capability providers, and specially designated units. There are five
groups (Groups 6-10) that are specifically NOT categorized as DoD COF. NG cyber units align to the
various COF elements within USCYBERCOM and the Service components through the Global Force
Management process. Members in Title 32 train for the Federal mission.
Group 1: Cyber Mission Force (CMF). The Secretary of Defense and the Chairman, Joint Chiefs of
Staff, established the CMF to organize and resource the force structure required to conduct key
cyberspace missions. CDRUSCYBERCOM exercises COCOM of the CMF, which is a subset of the
DoD’s total force for CO. Various Service tactical cyberspace units, assigned to
CDRUSCYBERCOM, comprise the three elements of the CMF: Cyber Protection Force (CPF), Cyber
National Mission Force (CNMF), and Cyber Combat Mission Force (CCMF).27
Cyber Protection Force (CPF)
The CPF conducts COs for internal protection of the DoDIN or other blue cyberspace when ordered.
The CPF consists of cyberspace protection teams (CPTs)28 that are organized, trained, and equipped to
defend assigned cyberspace in coordination with and in support of segment owners, cybersecurity
service providers (CSSPs), and users.29
While mobilized in Title 10, members of CPTs provide surge support to active duty cyber components
(such as USCYBERCOM, AFCYBER, or ARCYBER) and support defensive cyberspace operations
by removing adversary capabilities, defending the supported commander's key cyberspace terrain and
critical assets, and preparing local cyberspace defenders to sustain advanced cyberspace defense
tactics, techniques and procedures (TTPs). CPTs are the forces tasked with the DCO-IDM mission
under USCYBERCOM.30
Cyber National Mission Force (CNMF)
The CNMF conducts COs to defeat significant cyberspace threats to the DoDIN and, when ordered, to
the nation. The CNMF is comprised of various numbered national mission teams (NMTs), associated
national support teams (NSTs), and national-level CPTs for protection of non-DoDIN blue
cyberspace.31 NMTs are the forces tasked with the DCO-RA mission under USCYBERCOM.32
26 See SecDef Memorandum, Definition of Department of Defense Cyberspace Operations Forces (DoD COF), 12
December 2019 for description of each Group.
27 JP 3-12, supra note 1, at I-9.
28 CPT is the term used when that unit is mobilized.
29 JP 3-12, supra note 1, at I-9.
30 WILLIAMS, supra note 11, at 16.
31 JP 3-12, supra note 1, at I-9.
Chapter 13
Cyberspace Operations in the National Guard
284
Domestic Operational Law Handbook 2021
DCO-RA missions are normally assigned to NMTs, which are tactical units of the CNMF that defend
the DoDIN, or other blue cyberspace when ordered. NSTs provide specialized technical and analytic
support for the units of the CMF, including intelligence analysis, cyberspace capability development,
linguist support, and planning.33
Cyber Combat Mission Force (CCMF)
The CCMF conducts CO to support the missions, plans, and priorities of the geographic and functional
CCDRs. The CCMF comprises various numbered combat mission teams (CMTs) and associated
combat support teams (CSTs). OCO missions are normally assigned to CMTs, tactical units of the
CCMF that support CCDR plans and priorities to project power in support of national objectives.
CSTs provide specialized technical and analytic support for the units of the CMF, including
intelligence analysis, cyberspace capability development, linguist support, and planning.34
Group 2: USCYBERCOM Subordinate Command Elements
Group 3: DoD Component Network Operations Centers and Cyber Security Service Providers
(CSSP). Units designated by the Secretaries of Military Departments, in coordination with other DoD
Component Heads, to conduct cyberspace operations in support of DOD IN Operations, including
DCO and internal defensive measures.
Group 4: Special Capability Providers. Any force purposely organized to execute OCO or DCO
response actions.
Group 5: Specially Designated Units. Any force designated by the President or the Secretary of
Defense as part of the DoD COF for the purpose of conducting activities in support of specific
cyberspace operations.
Group 6: DoD Business Function Elements
Group 7: Service-Retained Forces
Group 8: Joint Cyber Centers
Group 9: Intelligence units and personnel. Any intelligence-related units or personnel not in direct
support of USCYBERCOM.
Group 10: CDRUSSOCOM-assigned forces.
32 Id. at II-8.
33 Id.
34 Id.
Chapter 13
285
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
D. DCO-E
The Army National Guard has Defensive Cyberspace Operations-Elements (DCO-E), which by design
do not have an active component CMF mission. As such, DCO-Es do not perform a Title 10 mission
or function. DCO-Es may provide surge capacity at the same capability level of Title 10 assets, but
they are prohibited from being mobilized, as a unit, for Title 10 missions. The DCO-E area of
responsibility is that State’s network enclave within GuardNet; in other words, the DCO-E defend that
State’s National Guard portion of DoDIN. With proper authorization, DCO-Es may support a
validated request for assistance (RFA) to provide support outside of the DoDIN; however, personnel
from the DCO-Es providing support and services outside of the validated RFA process must be in SAD
and activated pursuant to State law.
E. Title 32 Cyberspace Activities
The National Guard must have both proper fiscal authority and the mission authority to conduct
cyberspace activities in a Title 32. The National Guard is funded by Congress to train for the Federal
mission. IDTs and annual training are conducted under 32 U.S.C. § 502(a) within an existing
published training plan.35 Additional funds for training or other missions, if appropriate, may be
authorized under 32 U.S.C. § 502(f). The President and the Secretary of Defense have authority to
authorize operational missions under 32 U.S.C. § 502(f)(2).36
National Guard personnel are prohibited from conducting DCO-RA and OCO when in a Title 32 or
SAD status.37 These activities must be conducted while in a Title 10 status. Therefore, the National
Guard can train for the Federal mission in a Title 32 but is limited to DoDIN operations and DCO-IDM
activities. Title 32 training authorities can be leveraged to provide support to (1) active component, (2)
civil authorities; and (3) other statutorily eligible entities.
1. Support to Active Component
The National Guard can provide incidental operational support (OS) while conducting training. The
key is that the primary purpose of the activity must be military training.38 DoDI 1215.06, para 6.2,
encourages maximum Reserve Component utilization by stating, “all training duty planned and
performed by Reserve Components members shall capitalize on Reserve Components capabilities to
35 Training plans must be in accordance with NGR 350-1 and ANGI 36-2001.
36 Civil support teams, counterdrug, and homeland defense are operational missions authorized by statute that fall under 32
U.S.C. § 502(f)(2). There are currently no operational cyber missions.
37 See generally U.S. DEPT OF DEF., POLY MEM. 16-002, CYBER SUPPORT AND SERVICE PROVIDED INCIDENTAL TO
MILITARY TRAINING AND NATIONAL GUARD USE OF DOD INFORMATION NETWORKS, SOFTWARE, AND HARDWARE FOR
STATE CYBERSPACE ACTIVITIES (24 May 2016) [hereinafter PM 16-002]. This memorandum is also commonly referred to
as the “CTAA” memo. CTAA stands for coordinate, train, advise, and assist cyber support and services provided by
members of the National Guard incidental to military training when using DoD information networks (DoDIN), software,
and hardware for State cyberspace activities.
38 See DoDI 1215.06, Uniform Reserve, Training and Retirement Categories (19 May 2015) para 6.2.
Chapter 13
Cyberspace Operations in the National Guard
286
Domestic Operational Law Handbook 2021
accomplish operational requirements while maintaining their mission readiness for domestic and
overseas operations. RC members may be employed to support active component mission
requirements as part of conducting training duty.”39 Additionally, “support to mission requirements,
i.e., operational support (OS), may occur as a consequence of performing training.”40
Established and approved training plans cannot be altered to meet operational requirements. Units or
individuals that participate in IDT or AT may provide incidental OS to DoD mission requirements;
however, this should not be used as a façade to conduct actual operations nor as a substitute for
mission assignments from the Department of Homeland Security (for example, through Federal
Emergency Management Agency (FEMA) or the Cybersecurity and Infrastructure Security Agency
(CISA) etc.) during or in preparation for disaster response. OS assignments can be given to
prescheduled, pre-determined mission requirements as long as documented and in accordance with the
established approved training plan.
The OS should be considered only after determining the training value and ensuring the DoD mission
is consistent with the already existing and approved training plan. Showing the predictability of
training and validated training requirements will likely warrant less scrutiny on the proper use of
federal training funds. Activity where training value is not the primary purpose as determined by the
NG commander is a violation of fiscal law and DoD policy.
There is a much narrower application of OS in OCO and DCO-RA activities. Commanders should use
the following factors when considering whether training which provides an incidental operational
benefit is permitted or in other words, whether the mission is appropriate for the National Guard or
active component:
Whether performance of the federal operational mission is consistent with the unit's
formalized training program;
Whether the Federal Government can perform the mission without the National Guard
unit. In other words, is the active component capable of performing the mission without
support from the National Guard? If not, then the National Guard has moved beyond a
support role into an operational role and is exceeding the scope of its authority; and
Whether the use of full-time Guard personnel is disproportionate to its Reserve Component
mission.
To properly consider these factors, the necessary facts must be present to identify the proposed task
and duration of the task, whether the task fits into required individual or unit training, and if not,
whether the training will nevertheless benefit the Department of Defense. This analysis should
consider policy issues with risk assessment and the appropriateness when using NG forces.
OS likely collapses into actual operational missions for activities that fall under OCO and DCO-RA,
i.e. cyberspace attack and cyberspace exploitation. Commanders must independently assess each
activity, giving greater scrutiny to live Title 10 and Title 50 missions. Generally, if an activity requires
affirmative positive authority to be conducted (such as under Title 10 or NSPM-13), then there likely is
39 Id.
40 Id.
Chapter 13
287
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
no Title 32 OS when the Title 32 unit is training for that METs; the OS ceases to exist and the training
activity merges into the operational activity of OCO and DCO-RA which are conducted in Title 10.
Currently, there is no hip-pocket authority to auto-convert from Title 32 to Title 10 for cyber missions.
2. Support to Civil Authorities
a. Support to Civil Authorities - Generally41
The National Guard can provide DSCA, when a qualifying entity requests assistance.42 DoD
publications on DSCA focus on a response in Title 10 or 32 U.S.C. §502(f)(2) status. Currently, DTM
17-007 is the only publication on DSCA for cyber operations, or Defense Support to Cyber Incident
Response (DSCIR).43 DSCIR may be provided in Title 10 or in §502(f) for a cyber incident in
response to a request for assistance from a lead Federal department or agency for asset response or
threat response outside DoDIN as described in PPD-41. This includes DSCIR for immediate response
authority to save lives, prevent human suffering, or mitigate great property damage. Based on the
nature of support, liability waivers, memorandums of understanding or agreements (including
permission from asset owner to access appropriate information and information systems), non-
disclosure agreements, or other appropriate legal documents requested by Department of Defense must
be signed before providing DSCIR.
b. Support to Civil Authorities - Intelligence Support to Law Enforcement
Cyber teams likely have intelligence personnel assigned to them. Executive Order 12333, and DoD
associated IO rules and procedures, will apply if those intelligence personnel provide support to law
enforcement. While any intelligence activities (including collection) must be done in a Title 10 status
with proper mission and authority, SecDef approval is required for the use of intelligence assets for
anything other than foreign intelligence, counterintelligence, or intelligence training. This includes
training with an incidental benefit (i.e., OS). Intelligence support to law enforcement requires SecDef
approval in accordance with Procedure 12 under DoD 5240.1-R.
c. Support to Civil Authorities - Economy Act
The Economy Act allows Federal agencies to provide support to other Federal agencies on a
reimbursable basis, unless the support is provided in the normal course of training or operations, or the
support results in a substantially equivalent training value. The Secretary of Defense determines
whether reimbursement will be sought or waived pursuant to 10 U.S.C. § 277(c). Alternative funding
sources (through Stafford Act or as appropriated by Congress) are not directly contemplated here but
exist.
41
32 U.S.C. Chapter 9 and the implementing DoD publication recognizes homeland defense as an operational mission. A
SecDef-approved Chapter 9 request would give Title 32 National Guardsmen authority for homeland defense activities in
the cyber domain to protect and defend critical infrastructure outside of the Defense Industrial Base.
42 The DoD 3025 series of publications govern providing DSCA to a qualifying entity and primarily apply to response
under Title 10 and 32 U.S.C. §502(f)(2). State law governs state responses conducted in SAD.
43 DTM 17-007 is set to expire on 21 June 2021 and will be converted to a new issuance.
Chapter 13
Cyberspace Operations in the National Guard
288
Domestic Operational Law Handbook 2021
3. Other Entities. DepSecDef PM 16-002, commonly referred to as the CTAA memo, provided
guidance on the National Guard providing cyber support and services incidental to military training
through Innovative Readiness Training (IRT) projects.44 IRT projects have traditionally been used for
engineering and construction projects (such as building a bike trail for a local government or fixing
shelters for the Boy Scouts), or for providing medical care to underserved communities. The CTAA
memo clarified that IRT includes cybersecurity projects. Specifically, the CTAA memo provides
guidance that coordinating, training, advising, and assisting certain qualifying mission partners must be
done in accordance with IRT eligibility and program requirements under 10 U.S.C. § 2012. Most
recently, the IRT portion of the CTAA memo was written into permanent DoD guidance with the new
IRT DoDI 110.24.
It is important to note that CTAA memo does not preclude consultation or other methods of training
under other authorities, such as the Economy Act and the Stafford Act.45
F. Intelligence Oversight (IO)
As stated above, cyber teams likely have intelligence personnel assigned to them triggering Executive
Order 12333 and associated IO rules and procedures. In determining whether IO rules apply, look to
the people, pipes, process, platforms, purpose, and purchase (or funding source) for the activity. The
facts drive the analysis and determination of whether IO applies to that cyber activity:
People. Are intelligence personnel being used at any point to provide any capability or
assistance from the tasking through delivery of the product to the client?
Pipes. Are any intelligence systems being used at any point to disseminate or collect the
information?
Process. Are intelligence capabilities/units/personnel being used at any point to exploit or
process the data collected and/or generate a product?
Platform. Is either the platform or sensor owned or operated by an intelligence person?
Purpose. What is the intended purpose for which the platform/capability is being used and
who is the ultimate client/recipient of data or products generated?
Purchase. Was the platform/operation purchased with NIP or MIP funds?
44 The CTAA memo expires on 1 March 2021 or when the overarching policy issues contained in the memo are contained
in permanent DoD publication.
45 Outside of CTAA activities, the CTAA memo provides guidance that consulting with government entities and with
public and private utilities, critical infrastructure owners, the Defense Industrial Base, and other non-governmental entities,
as needed, in order to protect DoDIN, software, and hardware, enhance DoD cyber situational awareness, provide for DoD
mission assurance requirements, and provide cybersecurity unity of effort are outside the context of CTAA training
activities.
Chapter 13
289
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
If any of the responses to the above questions indicate intelligence involvement, those cyber teams
need to be cautious in proceeding with their training or mission to comply with IO rules, including
requiring SecDef approval for use of intelligence equipment for a non-intel purpose.
The key to the analysis of whether data collection is an intelligence activity is the definition of
intelligence. JP 2-0 defines intelligence as “the product resulting from the collection, processing,
integration, evaluation, analysis, and interpretation of available information concerning foreign
nations, hostile or potentially hostile forces or elements, or areas of actual or potential operations.”46
JP 2-0 further distinguishes intelligence from information, in that intelligence “allows anticipation or
prediction of future situations and circumstances, and it informs decisions by illuminating the
differences in available courses of action.”47 JP 3-12 recognizes that intelligence may be derived from
information gained during military operations in cyberspace or from other sources. Cyberspace
operations are the employment of cyberspace capabilities where the primary purpose is to achieve
objectives in or through cyberspace.
In short, the Department of Defense defines intelligence as information regarding an adversary and the
process used to produce that information. Getting information on what happened, when an incident
occurred, and how an incident occurred from local system logs is likely data and at most information.
Where an incident occurred can be both information and intelligence depending on where the
compromised network is located. Who caused an incident, and why an incident occurred, falls into the
intelligence.
For example, an operator tracing an Internet Protocol (IP) address to a specific foreign or domestic
actor or collecting data during an incident is likely not an intelligence activity. This would only be a
data collection. However, if the data is tied to a known signature and there is additional data with
corresponding analysis to indicate that the activity is part of a broader scheme, then you may be
crossing the line into an intelligence activity. The following graph will help illustrate when data turns
into intelligence.
46 Joint
47 Id. a
Chapter 13
Cyberspace Operations in the National Guard
290
Domestic Operational Law Handbook 2021
G. National Cyber Incident Response Plan (NCIRP)
The National Preparedness System (NPS) outlines an organized process for the whole of community to
move forward with their preparedness activities and achieve the National Preparedness Goal. The NPS
integrates efforts across five areas - Prevention, Protection, Mitigation, Response, and Recovery.
Presidential Policy Directive (PPD)-41, “U.S. Cyber Incident Coordination,” sets forth principles
governing the Federal Government’s response to any cyber incident, provides an architecture for
coordinating the response to significant cyber incidents, and requires DHS to develop the NCIRP to
address cybersecurity risks to critical infrastructure.48 The NCIRP is part of the broader NPS and
establishes the strategic framework and doctrine for a whole-of-Nation approach to mitigating,
responding to, and recovering from a cyber-incident.
The Department of Justice is the lead Federal agency (LFA) for threat response during a significant
cyber incident, acting through the Federal Bureau of Investigations (FBI) and National Cyber
Investigative Joint Task Force.49 The Department of Homeland Security is the LFA for asset response
during a significant cyber incident, acting through the National Cybersecurity and Communications
Integration Center (NCCIC).50 PPD-41 further discusses and defines threat response activities, asset
response activities, and significant cyber incidents.
The NCIRP states that the Department of Defense is responsible for threat response to cyber incidents
affecting DoD assets and DoDIN.51 The Department of Defense can also support civil authorities for
cyber incidents outside the DoDIN when requested by the LFA, and approved by the appropriate DoD
official, or directed by the President. Such support is provided based upon the needs of the incident,
the capabilities required, and the readiness of available forces.
The Department of Homeland Security, in coordination with the heads of other appropriate Federal
departments and agencies and in accordance with the NCIRP is required to regularly update, maintain,
and exercise the Cyber Incident Annex to the National Response Framework (NRF).52 The NRF is
part of the NPS and is a guide on how the Nation responds to all types of disaster and emergencies.
The NRF contains 15 Emergency Support Functions (ESF) and annexes that describe the Federal
coordinating structures to group resources and capabilities into functional area that are most frequently
needed in a national response.53 Cyber capabilities most likely will fall under ESF #2,
48 PRESIDENTIAL POLY DIR. 41, UNITED STATES CYBER INCIDENT COORDINATION (26 July 2016) [hereinafter PPD-41].
49 PPD-41, supra note 32, sec V, para B.c.1.
50 Id. at sec. V, para B.c.2.
51 DEPT OF HOMELAND SECURITY, NATIONAL CYBER INCIDENT RESPONSE PLAN 11 (Dec. 2016) [hereinafter NCIRP
2016].
52 Id. at 9.
53 DEPT OF HOMELAND SECURITY, NATIONAL RESPONSE FRAMEWORK (June 2016) [hereinafter NRF 2016].
Chapter 13
291
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
communications under the responsibility of DHS’s Cybersecurity and Infrastructure Security Agency
(CISA).54
H. State Active Duty (SAD)
1. Background
Personnel in SAD are under the command and control of the Governor. State laws govern issues in
discipline, ethics, information protection, privacy, and liability, but certain Federal laws may apply in
areas, such as Health Insurance Portability and Accountability Act (HIPAA) and Computer Fraud and
Abuse Act. States cannot engage in international warfare, i.e., a State cannot attack a foreign country
by cyber or kinetic means. Any DCO-RA or OCO activities must be carefully reviewed and should
receive a written opinion from the State Attorney General in order to set parameters of activities.
DoD rules generally do not apply to SAD personnel, but apply to use of equipment procured through a
Federal trace, including reimbursement requirements for the use of Federal equipment, as recently
clarified by both DA and DAF CIO. Some of the cyberspace equipment or programs may be limited to
Federal use for Federal systems and, therefore, would not be authorized for State use in a SAD or
outside of the DoDIN. E.O.s 12968 and 13549, as amended, and DoD implementing guidance govern
access and use of DoD information networks, software, hardware, systems, tools, tactics, techniques,
and procedures beyond the classification level of SECRET,”55 and is prohibited in SAD.
2. SAD Access to Federal Security Clearances
Executive Orders 12968 and 13549 govern security clearances, including eligibility for, access to, and
need to know determinations, to ensure proper safeguarding of information shared with State, local,
tribal, and private sector entities (SLTPS). Blanket access to a DoD security clearance for State use is
not authorized. State use of DoD security clearances must conform to the laws and DoD policies
governing access to and protection of Federal Government classified information and systems, and
controlled unclassified information and systems. Access to DoD security clearances can be granted by
a Federal sponsor on a case-by-case, mission-specific basis if the following requirements have been
met:
NG member in SAD has an adjudicated Federal security clearance;
NG member in SAD is carrying out a Federal sponsor mission;
54 DEPT OF HOMELAND SECURITY, EMERGENCY SUPPORT FUNCTION 2, COMMUNICATIONS ANNEX (June 2016),
[hereinafter ESF 2]. CISA is responsible for protecting the Nation’s critical infrastructure from physical and cyber threats.
CISA's National Cybersecurity and Communications Integration Center (NCCIC) provides 24x7 cyber situational
awareness, analysis, incident response and cyber defense capabilities to the Federal government; state, local, tribal and
territorial governments; the private sector and international partners. CISA provides cybersecurity tools, incident response
services and assessment capabilities to safeguard the networks that support the essential operations of Federal civilian
departments and agencies.
55 PM 16-002, supra note 38, at 3.
Chapter 13
Cyberspace Operations in the National Guard
292
Domestic Operational Law Handbook 2021
Federal sponsor determines that that member has a “need for access” and “need to know” to
carry out the assigned mission; and
Federal sponsor has security cognizance over the assigned mission.56
I. Federal Laws Governing Cyber Activities
National Guard personnel may be subject to Federal criminal laws if they exceed the scope of their
mission.57 This is particularly important for National Guard personnel as they may only perform
DCO-IDM activities. National Guard personnel may only perform actions on a network when they
have permission from the network owner to do so, otherwise, they may be subject to Federal and/or
state criminal laws.
1. Electronic Communications Privacy Act (18 U.S.C. §§ 2510-2523)
The Electronic Communications Privacy Act and the Stored Wire Electronic Communications Act
together are commonly to as the Electronic Communications Privacy Act (ECPA) of 1986. The ECPA
updated the Federal Wiretap Act of 1968, which addressed interception of conversations using "hard"
telephone lines, but did not apply to interception of computer and other digital and electronic
communications. Several subsequent pieces of legislation, including The USA PATRIOT Act, clarify
and update the ECPA to keep pace with the evolution of new communications technologies and
methods, including easing restrictions on law enforcement access to stored communications in some
cases. Overall, the ECPA, as amended, protects wire, oral, and electronic communications while those
communications are being made, are in transit, and when they are stored on computers. The Act
applies to email, telephone conversations, and data stored electronically.
2.
Wiretap Act (18 U.S.C. § 2511)
The Wiretap Act prohibits the “intentional interception of any wire, oral, or electronic
communication.”58 It also prohibits “intentional disclosure or use of the contents of any wire, oral, or
electronic communication while knowing or having reason to know that the information was obtained
illegally.”59 The Wiretap Act focuses on real-time content.
3.
Stored Communications Act (18 U.S.C. § 2701)
The Stored Communications Act governs unlawful access to stored communications by prohibiting
“(a) intentionally accessing, without authorization, of a facility through which an electronic
56 Currently, DoD’s delegation of authority to USCYBERCOM to sponsor access to DoD security clearances for SAD is
effective until the CTAA memo expires.
57 The Computer Fraud and Abuse Act, Wiretap Act, Pen Trap and Trace Act, and Stored Communications Act are the
most common Federal laws governing cyber activities. Other Federal laws that are relevant include the Privacy Act,
HIPAA, and the Freedom of Information Act (FOIA). For further reading, see Congressional Research Service (CRS)
Report R42507, Federal Laws Relating to Cybersecurity: Overview of Major Issues, Current Laws, and Proposed
Legislation, by Eric. A Fischer.
58
18 U.S.C. §§ 2511(1)(a), (b).
59
18 U.S.C. § 2511(1)(c).
Chapter 13
293
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
communication service is provided; or (b) intentionally exceeding an authorization to access that
facility and thereby obtaining, altering, or preventing authorized access to a wire or electronic
communication while it is in electronic storage in such system.”60 It protects the privacy of the
contents of files stored by service providers and of records held about the subscriber by service
providers, such as subscriber name, billing records, or IP addresses. The Stored Communications Act
focuses on past content and records.
4.
Pen Register and Trap and Trace Act (18 U.S.C. § 3121)
The Pen Register and Trap and Trace Act prohibits the real-time interception of the non-contents of
communications by a “pen register or a trap and trace device without first obtaining a court order.”61
However, the prohibition does not apply to a service provider for the operations, maintenance, and
testing of the service.62 It also does not apply to a service provider in the “protection of the rights or
property of such service provider, or to the protection of users of that service from abuse of service or
unlawful use of service.”63 The Pen Register and Trap and Trace Act focuses on real-time non-
content.
5. Computer Fraud and Abuse Act (18 U.S.C. § 1030)
In 1984, the Computer Fraud and Abuse Act, as related to fraud and related activity in connection with
computers, was added to Title 18, Chapter 47 - Fraud and False Statements. It prohibits, among other
things, the theft of information through unauthorized access or exceeded authorization on a “protected”
computer.64 A protected computer is a computer that is (a) exclusively used by a financial institution
or U.S. Government; or used by financial institute or U.S. Government and conduct that affects that
use; or (b) used in or affecting interstate or foreign commerce or communication, including computers
outside the United States, and conduct that affects that use.65
The Computer Fraud and Abuse Act also prohibits damage by “(a) knowingly causing the transmission
of a program, information, code, or command, and as a result of such conduct, intentionally causes
damage without authorization, to a protected computer; (b) intentionally accessing a protected
computer without authorization, and as a result of such conduct, recklessly causes damage; or (c)
intentionally accessing a protected computer without authorization, and as a result of such conduct,
causes damage and loss.”66
Overall, CFAA is concerned with trespass, theft, and damage. The crux of whether a Title 32 NG
person would violate the CFAA is whether that person’s activities is beyond the scope of authorized
access. Each situation would be fact-specific and can be scoped through the rules for the use of cyber
and a memorandum of agreement or understanding.
60
18 U.S.C. § 2701(a).
61
18 U.S.C. § 3121(a).
62
18 U.S.C. § 3121(b)
63
18 U.S.C. § 3121(b).
64
18 U.S.C. §§ 1030(a)(1), (2) (2012).
65
18 U.S.C. § 1030(e) (2012).
66
18 U.S.C. §1030(a)(5).
Chapter 13
Cyberspace Operations in the National Guard
294
Domestic Operational Law Handbook 2021
J. Judge Advocate Responsibilities
The National Guard, just like Department of Defense, can partner with Federal agencies, such as
Department of Homeland Security, through the Economy Act or provide Defense Support to Civil
Authorities supporting the National Response Framework, just like any other incident response
preparation through the National Preparedness System. In the cyberspace domain, there are unique
rules for the use of cyber that need to be reviewed and agreed upon by the National Guard and the asset
owner through Memoranda of Understanding/Agreement and Nondisclosure Agreements. It is
imperative to develop relationships with the State Attorney General’s office to be aware of any state
specific rules that may apply as well as the constraints that apply to Federal equipment. Some of the
issues to consider are:
Written permission from asset/network owner to access their system;
Scope of assistance to be provided (assessment and report finding; mitigation and remediation;
responses outside scope of assistance);
Status of military personnel (SAD, Title 32), command and control, and legal basis for
disciplinary actions;
Destruction/storage of data obtained, to include privacy and security restrictions;
Confidentiality of proprietary data or information (i.e., certain federal cyber equipment may
report all data to USCYBERCOM);
Whether the system will only scan or actively respond to the adversary action (i.e., hack or
hackback, which is prohibited outside of Title 10);
Privacy balanced with required disclosure of criminal/fraudulent activity;
Privacy of network users (union, contractor, etc.);
Privacy of business to not publicize discovered activity requiring criminal investigation;
Industry regulatory requirements to disclose incident;
Liability for unintended impact to operations;
Intelligence Oversight requirements (i.e., collection of USPI);
Payment for services (look to the FAR and DFARS for specific requirements);
Disputes resolution mechanism;
Conflicts of interest (use of a proprietary tool in which a National Guardsman may have
personal pecuniary interest);
Chapter 13
295
Cyberspace Operations in the National Guard
Domestic Operational Law Handbook 2018
Licensing limitations for use of a cyberspace capability and data rights for TTPs or software
developed in conjunction with private entities as part of a cyber response or exercise; and
Other relevant laws (Privacy Act, HIPAA, FOIA, FTCA, State laws, etc.).
The laws governing cyber activities are constantly changing in response to new technology and uses of
cyber capabilities in warfare. It is critical to ensure attorneys review the most recent laws, regulations
and policies when advising in this continually evolving area of the law. If you are addressing an issue
involving the cyber law, you should seek out additional expertise to assist you in this complicated area.
Chapter 13
Cyberspace Operations in the National Guard
296
DOMESTIC OPERATIONAL LAW
HANDBOOK
C E N T E R F O R L A
W AN D M I L I T A R Y O P E R A T I O N S ( C L A M O )
THE JUDGE ADVOCATE GENERAL'S LEGAL CENTER AND SCHOOL
UNITED STATES ARMY
600 MASSIE RD
CHARLOTTESVILLE, VIRGINIA
22903-1781
2021
GLOSSARY (UNCLASSIFIED)
9 June 2014
TERMS & DEFINITIONS OF INTEREST
FOR COUNTERINTELLIGENCE PROFESSIONALS
Wisdom begins with the definition of terms
-- Socrates
2X. The manager of the counterintelligence and human intelligence missions at various levels of DoD
structure, including joint, command, service, and task force. The 2X structure includes the
Counterintelligence Coordinating Authority (CICA) and the Human Intelligence Operations Center (HOC).
(AR 381-20, Army CI Program, 25 May 2010) Also see J2X.
-- Also, the counterintelligence and human intelligence advisor to the C/J/G/S-2. Denotes the 2X
positions at all echelons. The 2X staff conducts technical control and oversight for all counterintelligence
and human intelligence entities with[in] their operational purview. It coordinates, de-conflicts, and
synchronizes all counterintelligence and human intelligence activities at each level of command. (Army
FM 2-22.2, Counterintelligence, Oct 2009)
Term also refers to the staff section that the 2X leads.
Interesting historical note: During World War II the counterintelligence element of the Office of
Strategic Services (OSS) was known as “X-2” (Counter Espionage Branch). The OSS--predecessor
to today’s Central Intelligence Agency--was established on 13 June 1942 by order of President
Roosevelt. Also “XX” was the Double-Cross System, a World War II counterespionage and
deception operation controlled British military intelligence; see The Double-Cross System, Yale
University Press (1972) by Sir John Cecil Masterman,
603 Referral. See Section 603 Referral.
811 Referral. See Section 811 Referral.
This Glossary is designed to be a reference for counterintelligence (CI) professionals within the
Department of Defense (DoD); however other CI professionals may find it of use. It provides a
comprehensive compilation of unclassified terms that may be encountered when dealing with the
dynamic discipline of counterintelligence and related activities. Where some words may several
meanings within the counterintelligence or intelligence context, a variety of definitions are included.
Definitions within this Glossary cite an original source document. The quotes selected, as well as
the views and comments expressed in the shadow boxes are those of the editor and do not
necessarily reflect the official policy or position of the Department of Defense, the Office of the
National Counterintelligence Executive, the Intelligence Community, the Office of National
Intelligence, or the United States Government.
This Glossary is periodically updated. Users are encouraged to submit proposed changes,
corrections, and/or additions. Please provide a source citation for any recommended definitions.
Editor: COL Mark L. Reagan (USA Ret), mmreagan@msn.com
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
A ==========================================
A-Space (abbreviation for Analytical Space). A-Space transitioned to i-Space -- see “i-Space.” A-Space
was a virtual work environment that provided “analysts" from across the Intelligence Community a
common platform for research, analysis and collaboration.
Abort. To terminate a mission for any reason other than enemy action. It may occur at any point after the
beginning of the mission and prior to its completion. (previously in Joint Publication 1-02, DoD Dictionary
of Military and Associated Terms, hereafter referred to as JP 1-02)*
Abduction. [One of the four basic types of reasoning applied to intelligence analysis,] it is the process of
generating a novel hypothesis to explain given evidence that does not readily suggest a familiar
explanation. (DIA, Intelligence Essentials for Everyone, June 1999) Also see deduction; induction;
scientific method.
For additional information see Knowledge Management in the Intelligence Enterprise by Edward
Waltz (2003) and Critical Thinking and Intelligence Analysis by David T. Moore, JMIC Press (2006).
Access. In counterintelligence and intelligence use: 1) A way or means of approach to identify a target; 2)
Exploitable proximity to or ability to approach an individual, facility, or information that enables target to
carry out the intended mission. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011
w/ chg 1 dated 26 Aug 2011)
-- Also, the ability and opportunity to obtain knowledge of classified sensitive information or to be in a
place where one could expect to gain such knowledge. (Counterintelligence Community Lexicon, June
2000, hereinafter referred to as CI Community Lexicon)
-- Also, the ability or opportunity to obtain knowledge of classified or sensitive information. (IC
Standard 700-1, 4 Apr 2008 and DoD Manual 5200.01-Vol 1, Information Security Program, 24 Feb 2012)
-- Also, the ability and opportunity to obtain knowledge of classified information. (DoD Manual
S-5240.09-M, OFCO Procedures & Security Classification Guide, 13 Jan 2011 and DSS Glossary)
Access generally refers to the ability of a human source/asset (either CI or HUMINT) to perform a
specific operational task within the limits of acceptable risk. Types of access include direct,
indirect, first-hand, second-hand, etc.
Access Agent. An individual used to acquire information on an otherwise inaccessible target. (Human
Derived Information Lexicon Terms and Definitions for HUMINT, Counterintelligence, and Related
Activities, April 2008, hereinafter referred to as HDI Lexicon) Also see agent.
-- Also, an agent whose relationship or potential relationship with a foreign intelligence personality
allows him or her to serve as a channel for the introduction of another controlled agent for the purpose of
recruitment of the target. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
_______________
* Joint Publication 1-02, DoD Dictionary of Military and Associated Terms (JP 1-02), as amended; available online at:
<http://www.dtic.mil/doctrine/dod_dictionary/> Note: also available online at:
<https: //jdeis.js.mil>
2
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a person who facilitates contact with a target individual or entry into a facility. (Spycraft: The
Secret History of the CIA’s Spytechs from Communism to Al-Qaeda, 2008; hereinafter referred to as
Spycraft)
Access Agents
Another method of identifying and keeping track of suspected intelligence personnel is to recruit
people close to suspects, known in the jargon as “access agents.” Counterintelligence operators
can seek out secretaries, janitors, chauffeurs, interpreters, neighbors, or friends and request that
they pass on information about the target’s predilections and behavior.
-- Roy Godson, Dirty Tricks or Trump Cards: US Covert and Counterintelligence (1995), pp. 218-219
Access to Classified Information. The ability and opportunity to obtain knowledge of classified
information. Persons have access to classified information if they are permitted to gain knowledge of the
information or if they are in a place where they would be expected to gain such knowledge. Persons do
not have access to classified information by being in a place where classified information is kept if
security measures prevent them from gaining knowledge of the information. (JP 1-02)
Accommodation Address. An address for a person or organization that does not occupy the premises.
(HDI Lexicon, April 2008)
-- Also, an address where regular posted mail, or sometimes another type of communication, is
received and then held for pickup or forwarded, transmitted, or relayed to a member of a intelligence
service who does not occupy the premises. Sometimes called a mail drop, live letterbox, or cutout.
(AFOSI Manual 71-142, OFCO, 9 Jun 2000 and Spy Book)
-- Also, a "safe" address, not overtly associated with intelligence activity, used by an agent to
communicate with the intelligence service for whom he working. (FBI -- Affidavit: USA vs. Robert Philip
Hanssen, 16 Feb 2001)
-- Also, an address with no obvious connection to an intelligence agency, used for receiving mail
containing sensitive material or information (Spycraft)
-- Also, a prearranged temporary address or location where an intelligence operative may receive
mail clandestinely from a third party. (Encyclopedia of the CIA, 2003)
ACIC. See Army Counterintelligence Center.
Acknowledged SAP. A SAP [Special Access Program] whose existence is acknowledged but its specific
details (technologies, materials, techniques, etc.) are classified as specified in the applicable security
classification guide. (DoDD 5205.07, SAP Policy, 1 July 2010) Also see unacknowledged SAP.
-- Also, a Special Access Program that is acknowledged to exist and whose purpose is identified
(e.g., the B-2 or the F-117 aircraft program) while the details, technologies, materials, techniques, etc., of
the program are classified as dictated by their vulnerability to exploitation and the risk of compromise.
Program funding is generally unclassified. Note: Members of the four Congressional Defense Committees
are authorized access to the program. (DSS Glossary)
Acoustic Intelligence (ACINT). Intelligence derived from the collection and processing of acoustic
phenomena. (JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013)
3
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Acoustical Security. Those security measures designed and used to deny aural access to classified
information. (DSS Glossary and AR 381-14, Technical Counterintelligence, 30 Sep 2002)
Acoustical Surveillance. Employment of electronic devices, including sound-recording, -receiving,
or -transmitting equipment, for the collection of information. (JP 1-02)
Acquisition Special Access Program. A special access program established primarily to protect sensitive
research, development, testing, and evaluation or procurement activities in support of sensitive military
and intelligence requirements. (DSS Glossary)
Acquisition Security Database (ASDB). A classified DoD database designed to support Program
Managers, Research Technology Protection (RTP), Anti-Tamper, Counterintelligence, OPSEC, and
Security personnel supporting DoD Acquisition Programs with automated tools and functionality to enable
efficient and cost-effective identification and protection of Critical Technologies (CT) and Critical Program
Information (CPI).
-- Also, [proposed definition] the DoD horizontal protection database providing online storage,
retrieval, and tracking of CPI and supporting Program Protection documents in order to facilitate
comparative analysis of defense systems’ technology and align CPI protection activities across the DoD.
(Draft DoDI 5200.39, CPI Identification and Protection within RDA Programs)
All DoD CI personnel providing CI support to RDA should obtain an ASDB account.
ASDB is a key database for CI support to Research Development & Acquisition (RDA) which
provides on-line storage and retrieval of Program Protection Plans (PPPs), Anti-Tamper Plans,
Technology Assessment/Control Plans, Multi-Disciplined Counterintelligence Threat Assessments,
Program Protection Implementation Plans, OPSEC Plans and Security Classification Guides
(SCGs).
Acquisition Systems Protection (ASP). The safeguarding of defense systems anywhere in the acquisition
process as defined in DoD Directive 5000.1, the defense technologies being developed that could lead to
weapon or defense systems, and defense research data. ASP integrates all security disciplines, counter-
intelligence, and other defensive methods to deny foreign collection efforts and prevent unauthorized
disclosure to deliver to our force uncompromised combat effectiveness over the life expectancy of the
system. (DoD 5200.1-M, Acquisition Systems Protection Program, Mar 1994)
Actionable Intelligence. Intelligence information that is directly useful to customers for immediate
exploitation without having to go through the full intelligence production process. (ICS Glossary and
JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Active Cyber Defense. The Department of Defense’s real-time capability to discover, detect, analyze,
and mitigate threats and vulnerabilities to defend networks and systems. (DoD Strategy for Operating in
Cyberspace, May 2011)
Active Measures. In Russian, aktivnyye mery or aktivnyye meropriyatiya. …Soviet KGB tradecraft jargon
for operation involving disinformation, manipulation of communist-front organizations, agent-of-influence
operations, forgeries and counterfeiting. (The CIA Insider’s Dictionary by Leo D. Carl, 1996)
-- Also, influence operations organized by the Soviet government. These include white, gray, and
black propaganda, as well as disinformation. (Encyclopedia of Espionage, Intelligence, and Security by
The Gale Group, Inc)
4
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the Soviet term for strategies that in the West would be described as black propaganda. The
purpose was to denigrate ‘‘the main adversary’’ by using whatever disinformation channels were available
to spread false stories, plant bogus reports into the media, spread untrue rumors, and support Soviet
foreign policy objectives by undermining confidence in its opponents. (Historical Dictionary of Cold War
Counterintelligence by Nigel West)
-- Also, a form of political warfare conducted by Soviet intelligence and security services to influence
the course of world events. Active measures ranged “from media manipulations to special actions
involving various degrees of violence" and included disinformation, propaganda, counterfeiting official
documents, assassinations, and political repression, such as penetration in churches, and persecution
of political dissidents. (Extract from Christopher Andrew and Vasili Mitrokhin, The Mitrokhin Archive: The
KGB in Europe and the West, 2000)
The scale of the Soviet’s active measures campaign, and the KGB’s involvement in the
development and execution of specific items of disinformation was disclosed by a KGB officer,
Anatoli Golitsyn, following his defection in Helsinki in December 1961.
____________________
Active measures proved highly relevant to the Western counterintelligence community because it
was in the KGB’s interests to subvert the CIA, by suggesting it was driven by corruption and
influenced by dishonest politicians. The key to successful campaigns proved to be the deliberate
distortion of known facts, mixed with an element of fabrication. […] In addition, there is some
evidence to suggest that the KGB attempted to protect some of its most vital sources by interfering
in Western mole hunts through the introduction of false or misleading clues to throw the
investigations onto unproductive lines of inquiry.
-- Nigel West, Historical Dictionary of Cold War Counterintelligence
_____________________
For more information see: Soviet Active Measures in the "Post-Cold War" Era 1988-1991, A
Report Prepared at the Request of the United States House of Representatives Committee on
Appropriations by the United States Information Agency, June 1992. Copy available on line at:
Also see Deception, Disinformation, and Strategic Communications: How One Interagency Group
Made a Major Difference by Fletcher Schoen and Christopher J. Lamb, Institute for National
Strategic Studies, National Defense University, June 2012; copy available on line at:
Activity Based Intelligence (ABI). A discipline of intelligence where the analysis and subsequent
collection is focused on the activity and transactions associated with an entity, a population or an area of
interest. (NGA)
ABI is a multi-intelligence approach based on persistent collection of intelligence over a broad area
from multiple sources. Geospatial Intelligence (GEOINT), coupled with human domain analytics, is
the foundation of ABI.
The National Geospatial-Intelligence Agency (NGA) is at the forefront of the ABI push within the
Intelligence Community. The ubiquitous nature of geo-spatial intelligence (GEOINT), coupled with
Human Domain Analytics (HDA), forms the true foundation of ABI.
See A Brief Overview of Activity Based Intelligence and Human Domain Analytics,” (Sep 2012) by
Mark Phillips available on line at:
______________________
ABI is an inherently multi-INT approach to activity and transactional data analysis to resolve
unknowns, develop object and network knowledge, and drive collection.
-- Cited by Letitia A. Long, Director NGA, in her article “Activity Based Intelligence: Understanding the
Unknown,” in The Intelligencer: Journal of U.S. Intelligence Studies, Vol 20 No. 2, Fall/Winter 2013, p. 7
_____________________
5
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
ABI is really a new tradecraft that builds on top of something that’s been around for awhile called
‘patterns of life.’
-- Jordan Becker, Vice President & General Manger for GEOINT-ISR, BAE Systems,
Quoted in “GEOINT Tradecraft: Human Geography” by Greg Slabodkin, DefenseSystems,
Vol 7, No. 6, Oct/Nov 2013, p. 7
Activity Security Manager. The individual specifically designated in writing and responsible for the
activity’s information security program, which ensures that classified information (except SCI which is the
responsibility of the SSO appointed by the senior intelligence official) and CUI are properly handled
during their entire life cycle. This includes ensuring information is appropriately identified, marked, stored,
disseminated, disposed of, and accounted for, as well as providing guidance on the handling of security
incidents to minimize adverse effects and ensure that appropriate corrective action is taken. The security
manager may be assigned responsibilities in other security disciplines such as personnel and physical
security, etc. (DoD Manual 5200.01-Vol 1, Information Security Program, 24 Feb 2012)
Ad-Hoc Requirement (AHR). A HUMINT collection requirement with a limited emphasis, based on time or
other requirements. (Defense HUMINT Enterprise Manual 3301.02, Vol II Collection Operations, 23 Nov
2010)
-- Also, an intelligence need that was not addressed in [a] standing tasking. (National HUMINT
Glossary)
Adaptive Planning. The joint capability to create and revise plans rapidly and systematically, as
circumstances require. Also see Adaptive Planning and Execution (APEX); intelligence planning.
Adaptive Planning and Execution (APEX). A Department of Defense system of joint policies, processes,
procedures, and reporting structures, supported by communications and information technology, that is
used by the joint planning and execution community to monitor, plan, and execute mobilization,
deployment, employment, sustainment, redeployment, and demobilization activities associated with joint
operations. (JP 1-02 and JP 5-0, Joint Operation Planning, 11 Aug 2011)
Adequate Security. Security commensurate with the risk and the magnitude of harm resulting from the
loss, misuse, or unauthorized access to or modification of information. (NIST, Glossary of Key Information
Security Terms, May 2013)
Adherents. [In counterterrorism usage] individual who have formed collaborative relationships with, act
on behalf of, or are otherwise inspired to take action in furtherance of the goals of al-Qa’ida—the
organization and ideology—including b engaging in violence regardless of whether such violence is
targeted at the United States, its citizens, or its interests. (National Strategy for Counterterrorism,
June 2011)
Ad-hoc HUMINT Requirement (AHR). A HUMINT collection requirement with a limited emphasis, based
upon time or other requirements. (DHE-M 3301.001, DIA HUMINT Manual, Vol I, 30 Jan 2009 w/ chg 2)
Adjudication. Evaluation of personnel security investigations and other relevant information to determine
if it is clearly consistent with the interests of national security for persons to be granted or retain eligibility
for access to classified information, and continue to hold positions requiring a trustworthiness decision.
(DSS Glossary)
Administrative Control (ADCON). Direction or exercise of authority over subordinate or other
organizations in respect to administration and support. (JP 1, Doctrine for the Armed Forces of the United
States, 25 Mar 2013)
Admission. A polygraph examinee’s acknowledgement of a fact or a capable statement associated with a
relevant issue. (AR 381-20, Army CI Program, 25 May 2010)
6
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Advanced Persistent Threat (APT). An extremely proficient, patient, determined, and capable adversary,
including two or more of such adversaries working together. (DoDI 5205.13, Defense Industrial Base
Cyber Security/Information Assurance Activities, 29 Jan 2010)
-- Also, an adversary that possesses sophisticated levels of expertise and significant resources which
allow it to create opportunities to achieve its objectives by using multiple attack vectors (e.g., cyber,
physical, and deception). These objectives typically include establishing and extending footholds within
the information technology infrastructure of the targeted organizations for purposes of exfiltrating
information, undermining or impeding critical aspects of a mission, program, or organization; or
positioning itself to carry out these objectives in the future. The advanced persistent threat: (i) pursues its
objectives repeatedly over an extended period of time; (ii) adapts to defenders’ efforts to resist it; and (iii)
is determined to maintain the level of interaction needed to execute its objectives. (NIST, Glossary of Key
Information Security Terms, May 2013)
-- Also, a cyberattack campaign with specific, targeted objectives, conducted by a coordinated team
of specialized experts, combining organization, intelligence complexity, and patience. (Cybersecurity and
Cyberwar)
-- Also, cyber attacks mounted by organizational teams that have deep resources, advanced
penetration skills, specific target profiles and are remarkably persistent in their efforts. They tend to use
sophisticated custom malware that can circumvent most defenses, stealthy tactics and demonstrate good
situational awareness by evaluating defenders responses and escalating their attack techniques
5 Jan 2010)
The technological (cyber) APT has been used by actors in many nations as a means to gather
intelligence on individuals, and groups of individuals of interest. See additional information at:
_________________________
Also see Mandiant Report, APT1: Exposing One of China’s Cyber Espionage Units, undated (circa
Adverse Information. Any information that adversely reflects on the integrity or character of a cleared
employee, that suggests that his or her ability to safeguard classified information may be impaired, or that
his or her access to classified information clearly may not be in the interest of national security.
(DoD
Manual 5220.22-M, National Industrial Security Program Operating Manual, 28 Feb 2006)
Adversarial Supply Chain Operation (ASCO). ASCOs are the actions taken across the entire supply
chain life-cycle to attck and exploit the supply chain. ASCOs can include threatening or exploiting the
supply chains. These operations are carried out through compromise, subversion, and exposure of
material and components to or through the supply chain. The implications of ASCOs are possible
adverse effects to mission assurance affecting material, system operations and key capabilities. (DIA)
Also see supply chain, supply chain risk, supply chain risk management.
Adversary. An individual, group, organization, or government that must be denied essential information.
(DoD Manual 5200.1-M, Acquisition Systems Protection Program, Mar 1994)
-- Also, a party acknowledged as potentially hostile to a friendly party and against which the use of
force may be envisaged. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
-- Also, any individual, group, organization, or government that conducts or has the intent and
capability to conduct activities detrimental to the US Government or its assets. Adversaries may include
intelligence services, political or terrorist groups, criminals, and private interests. (CI Community Lexicon)
7
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, any foreign individual, group, organizations, or government that conducts or has the intent
and capability to conduct activities detrimental to the national security or defense of the United States or
its assets, including foreign intelligence services, political or international terrorist groups, and insurgents.
(AR 381-20, Army CI Program, 25 May 2010)
-- Also, individual, group, organization, or government that conducts or has the intent to conduct
detrimental activities. (NIST, Glossary of Key Information Security Terms, May 2013)
Adversary Collection Methodology. Any resource and method available to and used by an adversary for
the collection and exploitation of sensitive/critical information or indicators thereof. (DSS Glossary)
Adversary Intelligence Systems. Resources and methods available to and used by an adversary for the
collection and exploitation of critical information or indicators thereof. (DoDD 5205.02E, DoD OPSEC
Program, 20 Jun 2013)
Advisory Tasking. A term used in collection management to refer to collection notices that are
discretionary rather than directive in nature, with the receiving agency determining whether the
requirement is relevant to the mission of the agency and whether the agency has the resources to collect
against it. (AR 381-20, Army CI Program, 25 May 2010)
AFOSI. Acronym, see Air Force Office of Special Investigations.
Agency. In intelligence usage, an organization or individual engaged in collecting and/or processing
information.
(JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan
2012)
Agent. In intelligence usage, one who is authorized and trained to obtain or to assist in obtaining
information for intelligence or counterintelligence purposes. (JP 1-02 and JP 2-01.2, CI & HUMINT in
Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011) Also see agent of influence; agent of a
foreign entity; asset; foreign intelligence agent.
-- Also, a person who engages in clandestine intelligence activities under the direction of an
intelligence organization, but is not an officer, employee, or co-opted worker of that organization.
(National HUMINT Glossary)
-- Also, an individual other than an officer, employee, or co-opted worker of an intelligence service to
whim specific intelligence assignments are given by an intelligence service. An agent in a target country
can be operated by a legal or illegal residency or directly by the center. An agent can be of any
nationality. (FBI FCI Terms)
-- Also, 1) A person who engages in clandestine intelligence activity under the direction of an
intelligence organization but who is not an officer, employee, or co-opted worker of that organization; 2)
An individual who acts under the direction of an intelligence agency or security service to obtain, or assist
in obtaining, information for intelligence or counterintelligence proposes; [and] 3) One who is authorized
or instructed to obtain or assist in obtaining information for intelligence or counterintelligence purposes.
(ICS Glossary)
Typically, the aim of an espionage operation is to recruit an agent [emphasis added], usually a
foreign person, to carry out the actual spying. The person who targets, recruits, trains, and runs the
agent is, in American parlance, the ‘case officer.’
-- Arthur S. Hulnick, “Espionage: Does It Have a Future in the 21st Century?”
The Brown Journal of World Affairs; v XI: n 1 (2004).
_____________________
8
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
…[T]ypes of agents—singletons, sleepers, illegal spies actively running one or more sources,
illegal residents running a group of other illegals, and so forth.
--
Peter Wright, Spycatcher (1987), p. 139
_____________________
Espionage is one of the toughest games played. An agent in the right place is hard to find, but
when he is found he should be regarded as a pearl beyond price.
-- David Nelligan, The Spy in the Castle (1968)
Agent-in-Place. A person who remains in a position while acting under the direction of a hostile
intelligence service, so as to obtain current intelligence information. It is also called a recruitment-in-place.
(FBI -- Affidavit: USA vs. Robert Philip Hanssen, 16 Feb 2001) Also see recruitment-in-place (RIP).
Agent of Influence. An agent of some stature who uses his or her position to influence public opinion or
decision making to produce results beneficial to the country whose intelligence service operates the
agent. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
[Originally a Soviet term]
-- Also, a person who is directed by an intelligence organization to use his position to influence public
opinion or decision-making in a manner that will advance the objective of the country for which that
organization operates. (ICS Glossary)
-- Also, an individual who acts in the interest of an adversary without open declaration of allegiance
and attempts to exercise influence covertly, but is not necessarily gathering intelligence or compromising
classified material, is known as an agent of influence. (Historical Dictionary of Cold War
Counterintelligence, 2007)
-- Also, an agent operating under intelligence instructions who uses his official or public position, and
other means, to exert influence on policy, public opinion, the course of particular events, the activity of
political organizations and state agencies in target countries. (KGB Lexicon: The Soviet Intelligence
Officer’s Handbook, edited by KGB archivist Vasiliy Mitrokhin, 2002).
An agent of influence is a person who uses his or her position, influence, power, and credibility to
promote the objectives of an alien power…, in ways unattributable to that power, Such agents may
operate openly or surreptitiously, and their effectiveness depends on their position and the extent to
which they are prepared to misuse it, but any degree of deliberate support for an adversary power,
especially if applied in an underhanded way, savours of treachery.
-- Chapman Pincher, Traitors: The Anatomy of Treason, First U.S. Edition (1999), p. 34
Agent of a Foreign Entity. A person who engages in intelligence activities under the covert direction of
a foreign intelligence or security entity, but is not an officer, employee, or co-opted worker of that entity.
(ONCIX Analytic Chiefs Working Group, Jan 2011) Also see agent; agent of a foreign power; asset.
Agent of a Foreign Power. Means: (1) any person other than a United States person, who -
(A) acts in the United States as an officer or employee of a foreign power, or as a member of a foreign
power as defined in subsection (a)(4) of this section; (B) acts for or on behalf of a foreign power which
engages in clandestine intelligence activities in the United States contrary to the interests of the United
States, when the circumstances of such person's presence in the United States indicate that such person
may engage in such activities in the United States, or when such person knowingly aids or abets any
person in the conduct of such activities or knowingly conspires with any person to engage in such
activities; or (C) engages in international terrorism or activities in preparation therefore; or (2) any person
who - (A) knowingly engages in clandestine intelligence gathering activities for or on behalf of a foreign
power, which activities involve or may involve a violation of the criminal statutes of the United States; (B)
pursuant to the direction of an intelligence service or network of a foreign power, knowingly engages in
any other clandestine intelligence activities for or on behalf of such foreign power, which activities involve
or are about to involve a violation of the criminal statutes of the United States; (C) knowingly engages in
sabotage or international terrorism, or activities that are in preparation therefore, for or on behalf of a
foreign power; (D) knowingly enters the United States under a false or fraudulent identity for or on behalf
9
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
of a foreign power or, while in the United States, knowingly assumes a false or fraudulent identity for or
on behalf of a foreign power; or (E) knowingly aids or abets any person in the conduct of activities
described in subparagraph (A), (B), or (C) or knowingly conspires with any person to engage in activities
described in subparagraph (A), (B), or (C). (Source: 50 USC § 1801b) Also see foreign power.
Agent Handler. An [intelligence] officer or principal agent who directly manages an agent or agent
network. (National HUMINT Glossary) Also see case officer.
Agent Net. An intelligence gathering unit of agents supervised by a principal agent who is operating
under the direction of an intelligence officer. An agent net can operate in either the legal or illegal field.
(ICS Glossary and FBI FCI Terms)
Agent Recruitment Cycle (ARC). See recruitment cycle.
Air Force Office of Special Investigations (AFOSI). U.S. Air Force’s major investigative service; a federal
law enforcement and investigative agency operating throughout the full spectrum of conflict, seamlessly
within any domain; conducting criminal investigations and providing counterintelligence services.
(<www.osi.andrews.af.mil>; accessed 27 June 2012)
AFOSI Mission: Identify, exploit and neutralize criminal, terrorist
and intelligence threats to the Air Force, Department of Defense
and U.S. Government.
AFOSI Capabilities:
-- Protect critical technologies and information
-- Detect and mitigate threats
-- Provide global specialized services
-- Conduct major criminal investigation
-- Engage foreign adversaries and threats offensively
Source: AFOSI web site (accessed 27 June 2012)
All-Source Analysis. An intelligence activity involving the integration, evaluation, and interpretation of
information from all available data sources and types, to include human intelligence, signals intelligence,
geospatial intelligence, measurement & signature intelligence, and open source intelligence. (DoDD
5240.01, DoD Intelligence Activities, 27 Aug 2007) Also see analysis; analysis and production;
counterintelligence analysis.
-- Also, an intelligence activity involving the integration, evaluation, and interpretation of information
from all available data sources and types, to include HUMINT, SIGINT, MASINT, GEOINT, OSINT, and
CI. (DoDI 5105.21, DIA, 18 Mar 2008) {note this definition includes counterintelligence}.
All-source analysis can transform raw intelligence, data, and information into knowledge and
understanding.
________________________
Integrated all-source analysis should also inform and shape strategies to collect more
intelligence…. The importance of integrated, all-source analysis cannot be overstated. Without it,
it is not possible to “connect the dots.”
-- Final Report of the National Commission on Terrorist Attacks Upon the United States (2004)
All-Source Intelligence. 1) Intelligence products and/or organizations and activities that incorporate all
sources of information in the production of finished intelligence.
2) In intelligence collection, a phrase that
indicates that in the satisfaction of intelligence requirements, all collection, processing, exploitation, and
reporting systems and resources are identified for possible use and those most capable are tasked.
(JP 2-0, Joint Intelligence, 22 Oct 2013)
10
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, intelligence information derived from several or all the intelligence disciplines, including
SIGINT, HUMINT, MASINT, OSINT, and GEOINT. (ODNI, U.S. Intelligence - An Overview 2011)
-- Also, the integration of intelligence and information from all relevant sources in order to analyze
situations or conditions that impact operations. (ADRP 2-0, Intelligence, Aug 2012)*
* Note: supersedes the definition in Army FM 2-0, Intelligence, 23 Mar 2010.
ADRP = Army Doctrinal Reference Publication.
ADRPs are available online at <hhtps://armypubs.us.army.mil/doctrine/index.html>
Alliance. The relationship that results from a formal agreement between two or more nations for broad,
long-term objectives that further the common interests of the members. (JP 1-02 and JP 3-0, Joint
Operations, 11 Aug 2011)
Alias. A false identity used while carrying out authorized activities and lawful operations. (DoDI S-
5105.63, Implementation of DoD Cover and Cover Support Activities, 20 Jun 2013)
-- Also, an alternative name, used for cover purposes. (Defense HUMINT Enterprise Manual
3301.002, Vol II, Collection Operations, 23 Nov 2010)
-- Also, a false name. (National HUMINT Glossary)
-- Also, a false name assumed by an individual for a specific and often temporary purpose, i.e., to
conceal a true identity from persons or organizations with whom he or she is in contact. Also called a
pseudonym or cover name. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
-- Also, an assumed name, usually consisting of a first and last name, used by an individual for a
specific and often temporary purpose. (FBI FCI Terms)
Alternate Meet. A prearranged meeting that takes place in the event a regularly scheduled meet is
missed for any reason. (FBI FCI Terms)
Alternative Analysis.
[Analysis that] involves a fairly intensive, though time limited, effort to challenge
assumptions or to identify alternative outcomes, depending on the technique employed, with the results
captured, implicitly or explicitly, in a written product delivered to relevant policy-makers.(CIA - Sherman
Kent Center for Intelligence Analysis)
Alternative analysis includes techniques to challenge analytic assumptions (e.g., “devil’s
advocacy”), and those to expand the range.
See article “Rethinking “Alternative Analysis” to Address Transnational Threats” at:
Alternative Compensatory Control Measures (ACCM). Measures designed to safeguard sensitive
intelligence and operations when normal security measures are either not sufficient to achieve strict
controls over access to information, but where strict SAP [Special Access Program] access controls
are either not required or are too stringent. (AR 381-20, Army CI Program, 25 May 2010)
-- Also, used to safeguard sensitive intelligence or operations and support information (acquisition
programs do not qualify) when normal measures are insufficient to achieve strict need-to-know controls,
and where Special Access Program controls are not required. (DSS Glossary)
ACCMs are not Special Access Programs (SAPs). Guidance for ACCMs is contained in DoD
Manual 5200.01, Vol 3, DoD Information Security Program: Protection of Classified Information,
24 Feb 2012,
11
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Ambassador. Diplomatic official of the highest rank who is accredited to a foreign sovereign or
government, or to an international organization, as the resident representative of the sending government
or appointed for a specific diplomatic assignment. (Department of State) Also see Chief of Mission.
A U.S. ambassador serving abroad symbolizes the sovereignty of the United States and serves as
the personal representative of the President of the United States. Ambassadorial duties include
negotiating agreements, reporting on political, economic and social conditions, advising on policy
options, protecting American interests, and coordinating the activities of all U.S. Government
agencies and personnel in the country.
Analysis. [In intelligence usage] the process by which information is transformed into intelligence; a
systemic examination of information to identify significant facts, make judgments, and draw conclusions.
(ODNI, U.S. Intelligence - An Overview 2011) Also see analysis and production; all-source analysis;
counterintelligence analysis; intelligence analysis.
-- Also, the process by which collected information is evaluated and integrated with existing
information to produce intelligence that describes the current—and attempts to predict the future—impact
of the threat, terrain and weather, and civil considerations on operations. (Army FM 2-0, Intelligence,
23 Mar 2010)
-- Also, a stage in the intelligence processing cycle whereby collected information is reviewed to
identify significant facts; the information is compared with and collated with other data, and conclusions,
which also incorporate the memory and judgment of the intelligence analyst, are derived from it. (Senate
Report 94-755, Book I - Glossary, 26 Apr 1976)
INTELLIGENCE ANALYSIS…
“Joe, you’re guessing!”
Navy Capitan Matthew Garth
(Charlton Heston)
“Sir, we like to call it analysis.”
Naval Intelligence Officer Joseph Rochefort
(Harold Rowe “Hal” Holbrook, Jr.)
-- The movie Midway (1976)
Analysis is the process by which people transform information into intelligence. It includes
integrating, evaluating, and analyzing all available data -- which is often fragmented and even
contradictory -- and preparing intelligence products.
Former DCI Richard Helms noted that despite all the attention focused on the operational
(collection) side of intelligence, analysis is the core of the process to inform decision makers.
_______________________
It is of the highest importance in the art of detection to be able to recognize,
out of a number of facts, which are incidental and which are vital.
-- Sherlock Holmes
From A. Conan Doyle’s “The Reigate Squire” June 1893
(M. Hardwick, The Complete Guide to Sherlock Holmes, 1986, pp. 86-87)
_______________________
Analysis is the thinking part of the intelligence process
-- James B. Bruce and Roger Z. George
_______________________
It is not enough, of course, simply to collect information.
Thoughtful analysis is vital to sound decisionmaking.
-- President Ronald Reagan (4 Dec 1981)
_____________________
12
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
…[A]nalysis must always be timely, responsive and relevant to… customer's needs.
-- LTG Michael T. Flynn, USA, Director Defense Intelligence Agency (Jul 2012)
_____________________
Intelligence analysts select and filter information; they interpret the resultant evidence, put it into
context, and tailor it to meet… customers’ needs. In short, analysts and analysts only, create
intelligence.
-- David T. Moore, “Species of Competencies for Intelligence,” American Intelligence Journal (2005)
_____________________
Analysis must do more than just describe what is happening and why; it must identify a range of
opportunities… Analysis is the key to making sense of the data and finding opportunities to take
action.
-- DNI 2006 Annual Report of the US Intelligence Community (Feb 2007)
_____________________
The primary purpose of analytic effort is “sensemaking” and understanding, not producing reports;
the objective of analysis is to provide information in a meaningful context, not individual factoids.
-- Jeffrey R, Cooper, Curing Analytical Pathologies, Center for the Study of Intelligence (Dec 2005), p. 42
_____________________
Today, U.S. intelligence analysts spend roughly 80 percent of their time gathering intelligence but
only 20 percent analyzing it.
-- LTG Bob Noonan (USA Ret) and Greg Wenzel, “Fixing the ‘I’ in ISR,” DefenseNews, 24 Sep 2012, p. 45
_____________________
Analysts are the voice of the Intelligence Community
-- WMD Report (31 Mar 2005), p. 388
____________________
Analysts must absorb information with the thoroughness of historians,
organize it with the skill of librarians, and disseminate it with the zeal of journalists.
--TRADOC Pam 525-2-1, US Army Functional Concept for Intelligence 2016-2028, 13 Oct 2010; p. 66
________________________
Intelligence analysis is inherently an intellectual activity
that requires knowledge, judgment, and a degree of intuition.
Selected references for intelligence analysis:
Richards J. Heuer, Jr., Psychology of Intelligence Analysis (Washington, DC: Center for the Study
of Intelligence, Central Intelligence Agency), 1999.
monographs/psychology-of-intelligence-analysis/index.html>
Richards J. Heuer, Jr. and Randolph H. Pherson, Structured Analytical Techniques for Intelligence
Analysis (Washington, DC; CQ Press), 2010.
Richards J. Heuer, Jr, Improving Intelligence Analysis with ACH, 2005.
This learning aid extracts, revises, and partially updates those portions of the author’s book,
Psychology of Intelligence Analysis [cited above], that deal with Analysis of Competing Hypotheses
(ACH) and with how and why the ACH software helps intelligence analysts reduce the risk of
surprise. ACH software is available at: <http://www2.parc.com/istl/projects/ach/ach.html>
Roger Z. George and James B. Bruce, eds., Analyzing Intelligence: Origins, Obstacles, and
Innovation (Washington, DC: Georgetown University Press), 2008.
Robert M. Clark, Intelligence Analysis: A Target-Centric Approach, rev. ed. (Washington, DC: CQ
Press), 2007; also paperback 2012
David A. Schum, Evidence and Inference for the Intelligence Analyst (Lanham, MD: University
Press of America) 1987.
Morgan Jones, The Thinker’s Toolkit: 14 Powerful Techniques for Problem Solving, rev. ed. (New
York: Three Rivers Press), 1998.
13
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Robert S. Sinclair, Thinking and Writing: Cognitive Science and Intelligence Analysis, revised
edition (Washington, DC: Center for the Study of Intelligence, Central Intelligence Agency), 2010.
publications/books-and-monographs/thinking-and-writing.html>
David T. Moore, Sensemaking: A Structure for an Intelligence Revolution (Washington, DC:
National Defense Intelligence College, 2011).
A Tradecraft Primer: Structured Analytical Techniques for Improving Intelligence Analysis
(Washington, DC: U.S. Government), 2009.
Copy available at: <https://www.cia.gov/library/ publications/publications-rss-updates/tradecraft-
primer-may-4-2009.html>
A Compendium of Analytic Tradecraft Notes, Volume I, Notes 1-10, reprinted (Washington, DC:
Central Intelligence Agency), 1997.
The Sherman Kent Center for Intelligence Analysis Occasional Papers, (CIA).
Available online at:
Frank Watanabe, “Fifteen Axioms for Intelligence Analysts.” Studies in Intelligence, CIA,
Semiannual Edition, No. 1, 1997, pp. 45-47.
csi/vol40no5/pdf/v40i5a06p.pdf>
Also see Mark Lowenthal, PhD, Intelligence: From Secrets to Policy, 5th Edition (CQ Press), 2011.
Analysis and Production. In intelligence usage, the conversion of processed information into intelligence
through the integration, evaluation, analysis, and interpretation of all source data and the preparation of
intelligence products in support of known or anticipated user requirements. (JP 1-02 and JP 2-01, Joint
and National Intelligence Support to Military Operations, 5 Jan 2012) Also see analysis; all-source
analysis; counterintelligence analysis.
-- Also, the ability to integrate, evaluate, and interpret information from available sources and develop
intelligence products that enable situational awareness. (Joint Capability Areas Taxonomy & Lexicon,
15 Jan 2008)
Analysis of Competing Hypothesis (ACH). Identification of alternate explanations (hypothesis) and
evaluation of all evidence that will disconfirm rather that confirm hypotheses. (CIA, A Tradecraft Primer:
Structured Analytical Techniques for Improving Intelligence Analysis, June 2005)
ACH a highly effective technique when there is a large amount of data to absorb and evaluate. It
is particular appropriate for controversial issues when analysts want to develop a clear record that
shows what theories they have considered and how they arrived at their judgments.
See Richards J. Heuer, Jr, Improving Intelligence Analysis with ACH, Nov 2005 (Learning Aid,
ACH Version 2.0). This learning aid extracts, revises, and partially updates those portions of the
author’s book, Psychology of Intelligence Analysis [cited above], that deal with Analysis of
Competing Hypotheses (ACH) and with how and why the ACH software helps intelligence analysts
reduce the risk of surprise.
ACH software available for download at: <http://www2.parc.com/istl/projects/ach/ach.html>
Analysis Report. A type of DoD CI analytical product prepared IAW DoDI 5240.18; it may require in-
depth study and research, but generally is not as involved as an assessment. (DoDI 5240.18, CI Analysis
& Production, 17 Nov 2009 with change 1 dated 15 Oct 2013). Also see Counterintelligence Analytical
Product.
Analytic Outreach. The open, overt, and deliberate act of an IC [Intelligence Community] analyst
engaging with an individual outside the IC to explore ideas and alternate perspectives, gain new insights,
generate new knowledge, or obtain new information. (ICD 205, Analytic Outreach, 16 Jul 2008)
14
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Analytic Tradecraft. The practiced skill of applying learned techniques and methodologies appropriate to
an issue to mitigate, gain insight, and provide persuasive understanding of the issue to members of the
U.S. Government and its allies. (DIA, A Tradecraft Primer: Basic Structured Analytic Techniques, March
2008).
Note: The source document (First Edition) cited above is no longer available online. The current
version: Tradecraft Primer: Structured Analytic Techniques, 3rd Edition (3 March 2010) is now
Defense Intelligence Reference Document, Analytic Methodologies, DIA-01-1003-001A, and is
controlled as UNCLASSIFIED//FOR OFFICIAL USE ONLY.
Anomalies. Foreign power activity or knowledge, inconsistent with the expected norms that suggest prior
foreign knowledge of US national security information, processes or capabilities. (DoDD O-5240.02,
Counterintelligence, 20 Dec 2007 with change 1 dated 30 Dec 2010) See anomalous activity; anomaly.
-- Also, irregular or unusual activities that may cue the analyst on the existence of FISS and ITO
[international terrorist organizations] activity. (Army FM 2-22.2, Counterintelligence, Oct 2009)
CI anomalies differ from CI indicators (see potential espionage indicators). CI anomalies surface
as a result of FIE activities, whereas CI indictors are manifested in an insider’s actions, activities,
and/or behaviors.
______________________
Recognizing the importance of CI anomalies in the early detection and neutralization of espionage,
a White House Memorandum of August 23, 1996 called for a more systematic approach to the
handling of CI anomalies. The memorandum emphasized the need for, and value of, timely
participation of CI elements in detecting and reporting CI anomalies indicating threats to U.S.
national security.
-- DIA tri-fold, Counterintelligence Anomalies: What are They and Why Should We Look for Them?, Jan 2012
______________________
Look for the anomalies…
Look for the odd bits that seem to be out of focus, or out of sequence.
Look for the inexplicable.
-- Sean Flannery, Crossed Swords, 1989
Anomalous Activity. Irregular or unusual deviations from what is usual, normal, or expected; activity
inconsistent with the expected norm. See anomalies; anomaly.
-- Also, [in DoD cyber usage] network activities that are inconsistent with the expected norms that
may suggest FIE [Foreign Intelligence Entity] exploitation of cyber vulnerabilities or prior knowledge of
U.S. national security information, processes, or capabilities. (DoDI S-5240.23, CI Activities in
Cyberspace, 13 Dec 2010 with change 1 dated 16 Oct 2013)
Anomalous Behavior Analysis
[The CI] analyst seeks out strange or puzzling behavior pointing to a counterintelligence problem
even before it is known to exist. There are various kinds of anomalous behaviors that might tip off
an analyst about a foreign intelligence service’s successful operations. One is strategic behavior.
When a foreign government starts using the same secret technology as another government, the
analyst who finds this out may hypothesize that it because such secrets have been stolen.
-- Roy Godson, Dirty Tricks or Trump Cards: US Covert Action and Counterintelligence (1995), p. 196
Anomaly. Activity or knowledge, outside the norm, that suggests a foreign entity has foreknowledge of
U.S. information, processes, or capabilities. (DoDD 5240.06, CIAR, 17 May 2011 with change 1 dated 30
May 3013) See anomalies, anomalous activity, anomaly-based detection.
15
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Anomaly-based Detection. The process of comparing CI, security, IA [Information Assurance], LE [law
enforcement], and AT/FP [antiterrorism and force protection] behaviors and activities that are deemed
normal against other observed events to identify significant deviations and or anomalous behavior.
(DoDI 5240.26, Countering Espionage, International Terrorism, and Counterintelligence Insider Threat,
4 May 2012 with change 1 dated 15 Oct 2013)
-- Also, the process of comparing definitions of what activity is considered normal against observed
events to identify significant deviations. (NIST, Glossary of Key Information Security Terms, May 2013)
Anomaly Detection
The systems and processes used to assess deviant or unscheduled activities or presences which
may indicate anomalous activities or unauthorized access. This interpretation assumes a baseline
norm from which deviations are assumed to indicate some type of intrusion.
-- Julie K. Petersen, Understanding Surveillance Technologies: Spy Devices, Their Origins &
Applications (2001)
Anti-Tamper. Systems engineering activities intended to deter and/or delay exploitation of critical
technologies in a U.S. defense system in order to impede countermeasure development, unintended
technology transfer, or alteration of a system. (DoDI 5200.39, CPI Protection within DoD, 16 Jul 2008)
Note: DoDI 5200.39 under revision, proposed revised definition for AT: Systems engineering
activities intended to prevent, or delay exploitation of CPI in U.S. defense systems to impede
countermeasure development, unintended technology transfer, or alteration of a system due.
(Draft circa Feb 2014)
DoD Anti-Tamper Executive Agent: chartered by the Under Secretary of Defense (Acquisition,
Technology, and Logistics), and assigned to the Directorate for Special Programs, Office of the
Assistant Secretary of the Air Force for Acquisition.
Antiterrorism (AT). Defensive measures used to reduce the vulnerability of individuals and property
to terrorist acts, to include limited response and containment by local military and civilian forces.
(JP 1-02; and JP 3-07.2, Antiterrorism, 24 Nov 2010)
Also see DoDI 2000.12, DoD Antiterrorism Program, 1 Mar 2012 (w/ chg 1) and DoD O-2000.12-H,
DoD Antiterrorism Handbook, 1 February 2004
Apportionment. In the general sense, distribution for planning of limited resources among competing
requirements. (JP 1-02)
Apprehension. The taking of a person into custody or the military equivalent of “arrest.” Under Rule 304,
Manual for Courts Martial (MCM), the restraint of a person by oral or written order directing him to remain
within specified limits. (AR 381-20, Army CI Program, 25 May 2010)
Area of Responsibility (AOR). The geographical area associated with a combatant command within
which a geographic combatant commander has authority to plan and conduct operations. (JP 1-02)
Army Counterintelligence Center (ACIC). The Army’s counterintelligence analysis and production center.
ACIC’s mission is to provide timely, accurate, effective multidiscipline counterintelligence analysis
in support of the US Army combating terrorism program, ground systems technologies, and
counterintelligence investigations, operation, and activities. The ACIC is a subordinate unit of the
902d Military Intelligence Group, US Army Intelligence and Security Command, located at Fort
Meade, Maryland.
Army G-2X. The element which manages and provides technical control of the CI and HUMINT missions
in the Army. (AR 380-20, Army CI Program, 25 May 2010)
16
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Arrest. The act of detaining in legal custody. An "arrest" is the deprivation of a person's liberty by legal
authority in response to a criminal charge. (www.ojp.usdoj.gov; accessed 29 Apr 2013)
ASDB. Acronym, see Acquisition Security Database.
Assassination. The murder or attempted murder of DoD personnel for political or retaliatory reasons by
international terrorists or agents of a foreign power. (AR 381-20, Army CI Program, 25 May 2010)
-- Also, to murder (usually a prominent person) by a sudden and/or secret attack, often for political
reasons. (Wikipedia; accessed 15 Feb 2010)
“[The KGB] did everything from plotting ways to poison the capital’s
water systems to drawing up assassination plans for US leaders.”
-- Oleg Kalugin, Former Major General in the KGB
as cited in Andrew & Mitrokhin, The Mitrokhin Archive (1999)
__________________________
Assassination constitutes an act of murder that is prohibited by international law and Executive
Order 12333. In general, assassination involves murder of a targeted individual for political
purposes. Example, the 1978 “poisoned-tip umbrella” killing of Bulgarian defector Georgi Markov by
Bulgarian State Security agents on the streets of London falls into the category of an act of murder
carried out for political purposes, and constitutes an assassination.
“Wet Work” - a term originated within the Soviet intelligence - describes the art of assassination.
In 1965, Peter Deriabin, a KGB defector, testified to a Senate committee -
“The [KGB] thirteenth department is responsible for assignation and terror. This
Department is called the department of wet affairs, or in Russian ‘Mokrie Dela’….
‘Mokrei’ means ‘wet’ and in this case ‘mokrie’ means ‘blood wet’.”
Unquestionably the most neglected aspect of U.S. counterintelligence. EO 12333 specifically
provides that “Counterintelligence means information gathered and activities conducted to identify,
deceive, exploit, disrupt, or protect against… assassinations [emphasis added] conducted for or
on behalf of foreign powers, organizations, or persons, or their agents, or international terrorist
organizations or activities.”
The word assassin is derived from the word Hashshashin (Arabic: نيشاشح, ħashshāshīyīn, also
Hashishin, Hashashiyyin, or Assassins). It referred to the Nizari branch of the Ismā'īlī Shia founded
by the Persian Hassan as-Sabbah during the Middle Ages. They were active in Iran from the 8th to
the 14th centuries, and also controlled the castle of Masyaf in Syria. The group killed members of
the Muslim Abbasid, Seljuq, and Christian Crusader élite for political and religious reasons.
___________________
The important thing to know about any assassination or an attempted
assassination is not who fired the shot, but who paid for the bullet.
-- Eric Ambler, A Coffin for Dimitrios (1939)
Assessment. 1) a continuous process that measures the overall effectiveness of employing joint force
capabilities during military operations; 2) determination of the progress toward accomplishing a task,
creating a condition, or achieving an objective; 3) analysis of the security, effectiveness, and potential of
an existing or planned intelligence activity; and 4) [in human source operations] judgment of the
motives, qualifications, and characteristics of present or prospective employees or “agents.”
[emphasis added] (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
-- Also, [In CI analysis usage] a type of DoD CI analytical product prepared IAW DoDI 5240.18; it
requires in-depth study and research. (DoDI 5240.18, CI Analysis & Production, 17 Nov 2009 with change
1 dated 15 Oct 2013). Also see Counterintelligence Analytical Product.
17
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, [in intelligence usage], appraisal of the worth of an intelligence activity, source, information, or
product in terms of its contribution to a specific goal, or the credibility, reliability, pertinence, accuracy, or
usefulness of information in terms of an intelligence need. (National HUMINT Glossary)
Assessment--within the human source environment…
“A process of getting to know and understand people and describing them.”
-- Robert R. Holt, Assessing Personality (1971)
Effective assessment of human beings is an art
From an Agent Handler perspective…
“…[F]inding a likely candidate, getting to know him personally, ascertaining his interests,
uncovering his vices and possible Achilles’ heel.”
-- Victor Cherkashin, KGB Counterintelligence Officer and author of Spy Handler (2005)
Asset. Any human or technical resource available to an intelligence or security service for operational
purposes. (FBI FCI Terms) Also see agent; foreign intelligence agent; Intelligence asset; source.
-- Also, [in human source operations] a recruited source. (Defense HUMINT Enterprise Manual
3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, any resource—human, technical, or otherwise—available to an intelligence or security service
for operational use. In U.S. usage, usually a person. (Spy Book)
-- Also, [in defense critical infrastructure usage] a distinguishable entity that provides a service or
capability. Assets are people, physical entities, or information located either within or outside the United
States and employed, owned or operated by domestic, foreign, public, or private sector organizations.
(DoDD 3020.40, Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012) Also see defense
critical infrastructure program.
-- Also, [in critical infrastructure protection] person, structure, facility, information, material, or process
that has value. (DHS Lexicon, 2010) Also see crucial infrastructure.
Asset Owner. [In DCIP usage,] the DoD Components with responsibility for a DoD asset, or organizations
that own or operate a non-DoD asset. (DoDI 3020.45, DCIP Management, 21 Apr 2008) Also see task
asset, task critical asset.
Asset Validation. In intelligence use, the process used to determine the asset authenticity, reliability,
utility, suitability, and degree of control the case officer or others have. (JP 1-02 and JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011) Also see Source Validation.
The cardinal rule in tradecraft is: Never, ever fall in love with your agent.
-- Robert D. Chapman, Retired CIA Operations Officer
“Patriot or Traitor?” Book review of A Secret Life in International
Journal of Intelligence and Counterintelligence, Vol 18 No 2 (Summer 2005), p. 367
_____________________
Some human intelligence agencies do a poor job of validating human sources.
The story of ‘Curveball’—the human source who lied to the Intelligence Community about Iraq’s
biological weapons programs—is an all-too familiar one. Every agency that collects human
intelligence has been burned in the past by false reporting; indeed, the Intelligence Community has
been completely fooled several times by large-scale double-agent operations run by, among
others, the Cubans, East Germans, and Soviets. It is therefore critical that our human intelligence
agencies have excellent practices of validating and vetting their sources.
-- WMD Report, Chapter 7 - Collection, p. 367*
18
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the process used to determine the asset authenticity, reliability, utility, suitability, and degree
of control the case officer or others have. This process continues through the life of the relationship. It
may be more or less formal depending on the sensitivity of the relationship and the nature of the source.
For clandestine sources, particularly foreign nationals, the process is usually formal and revalidation is
required on a periodic basis. Whether or not it is conducted formally, it must be a well-planned and
thought out activity. (DoD CI Collection IWG Handbook, TTP for CI Collection, Collection Management,
and Collection Operations, 8 Aug 2006)
In the spy trade asset validation is simply
a system of measures to establish the reliability and veracity of sources.
-- Michael J. Sulick, American Spies: Espionage Against
the United States from the Cold War to the Present, 2013, p. 255
_________________________
For any organization that collects human intelligence, having an independent
system for asset validation is critical to producing reliable, well-vetted intelligence.
-- WMD Report (31 Mar 2005), p. 455
_________________________
Every intelligence service has the problem of distinguishing…
between a bona fide volunteer and a penetration agent who has been sent
by the other side. This is no easy matter.
-- Allen W. Dulles, The Craft of Intelligence (2006), p. 121
_________________________
See DoDI S-3325.07, Guidance for the Conduct of DoD Human Source Validation (U) and
National HUMINT Manager Directive 001.008, HUMINT Source Validation.
Assign. 1) To place units or personnel in an organization when such placement is relatively permanent,
and/or where such organization controls and administers the units or personnel for the primary function,
or greater portion of the functions, of the unit or personnel; or 2) To detail individuals to specific duties or
functions where such duties or functions are primary and/or relatively permanent. (JP 1-02 and JP 5-0,
Joint Operations Planning, 11 Aug 2011) Also see attach.
Assumption. A supposition on the current situation or a presupposition on the future course of events,
either or both assumed to be true in the absence of positive proof, necessary to enable the commander in
the process of planning to complete an estimate of the situation and make a decision on the course of
action. (JP 1-02 and JP 5-0, Joint Operations Planning, 11 Aug 2011)
Asylum. Protection granted by the U.S. Government within the United States to a foreign national who,
due to persecution or a well-founded fear of persecution on account of his or her race, religion,
nationality, membership in a particular social group, or political opinion, is unable or unwilling to avail
himself or herself of the protection of his or her country of nationality (or, if stateless, of last habitual
residence). (DoDI 2000.11, Procedures for Handling Requests for Asylum and Temporary Refuge, 13
May 2010)
Asymmetric Threat. An adversary strength that can be used against a friendly vulnerability. An adversary
may pursue an asymmetric advantage on the tactical or strategic level by identifying key vulnerabilities
and devising asymmetric concepts and capabilities to strike or exploit them. To complicate matters, our
adversaries may pursue a combination of asymmetries. (USD/I Taking Stock of Defense Intelligence
Report, 22 Jan 2004)
-- Also, a broad and unpredictable spectrum of military, paramilitary, and information operations,
conducted by nations, organizations, or individuals or by indigenous or surrogate forces under their
control, specifically targeting weaknesses and vulnerabilities within an enemy government or armed force.
(Source: Michael L. Kolodzie, US Army, circa 2001)
19
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a broad and unpredictable spectrum of risks, actions, and operations conducted by state and
non-state actors that can potentially undermine national and global security. (Cyber Threats to National
Security, Symposium Five, 2011)
Asymmetric Warfare. Combat between two or more state or non-state actors whose relative military
power, strategies, tactics, resources, and goals differ significantly. (Cyber Threats to National Security,
Symposium Five, 2011)
Atmospherics. Information regarding the surrounding or pervading mood, environment, or influence on a
given population. (DoDD 3600.01, Information Operations, 14 Aug 2006 with Chg 1, 23 May 2011)
Attach.
1) The placement of units or personnel in an organization where such placement is relatively
temporary; or 2) The detailing of individuals to specific duties or functions where such functions are
secondary or relatively temporary. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011) Also see assign.
Attaché. A diplomatic official or military officer attached to an embassy or legation, especially in a
technical capacity. Also see Senior Defense Official / Defense Attaché (SDO/DATT).
Authenticate. A challenge given by voice or electrical means to attest to the authenticity of a message or
transmission. (JP 1-02)
Authentication. 1) A security measure designed to protect a communications system against acceptance
of a fraudulent transmission or simulation by establishing the validity of a transmission, message, or
originator;
2) A means of identifying individuals and verifying their eligibility to receive specific categories
of information; 3) Evidence by proper signature or seal that a document is genuine and official; and 4) In
personnel recovery missions, the process whereby the identity of an isolated person is confirmed.
(JP 1-02 and JP 3-50, Personnel Recovery, 5 Jan 2007)
Authenticator. A symbol or group of symbols, or a series of bits, selected or derived in a prearranged
manner and usually inserted at a predetermined point within a message or transmission for the purpose
of attesting to the validity of the message or transmission. (JP 1-02)
20
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
B ==========================================
Background Investigation (BI). An official inquiry into the activities of a person designed to develop
information from a review of records, interviews of the subject, and interviews of people having
knowledge of the subject. (IC Standard 700-1, 4 Apr 2008) See personnel security investigation.
The Office of Personnel Management, Federal Investigative Services (OPM-FIS) provides
investigative products and services for over 100 Federal agencies to use as the basis for suitability
and security clearance determinations as required by Executive Orders, et al. OPM provides over
90% of the Government's background investigations, conducting over two million investigations a
year.
Backdoor. Typically unauthorized hidden software or hardware mechanism used to circumvent security
controls. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Backstop. Arrangements made to support a cover so that inquiries about the cover will elicit responses
that make the cover appear to be true. (DoDI S-5105.63, Implementation of DoD Cover and Cover
Support Activities, 20 Jun 2013)
-- Also, the arrangement made by documentary or oral means to support a cover story so that
inquiries about it will elicit responses indicating the story is true. (ICS Glossary & AFOSI Manual 71-142,
OFCO, 9 Jun 2000)
-- Also, to make arrangements made through documentary, oral, technical, fiscal, legal, or other
means to support covers (both individual and organizational). A backstopped cover provides sufficient
documentation to protect an identity in the immediate area or circumstance and in primary U.S.
Government and commercial information systems. A backstopped cover is constructed to withstand
routine scrutiny. (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, an arrangement made to support a cover story. (FBI FCI Terms)
Backstopping. Arrangements made to support covers and activities. (HDI Lexicon, April 2008)
-- Also, arrangements made through documentary, oral, technical, fiscal, physical, or other means
to support covers (both individual and organizational). A backstopped cover provides sufficient
documentation to project an identity in the immediate area or circumstance and in primary USG and
commercial information systems. Backstopping cover may be constructed to withstand scrutiny ranging
from casual or unwitting general population to a targeted hostile adversary. (DTM 08-050, Defense Cover
Program Guidance (U), 31 Mar 2009 w/ chg 2 dated 14 Apr 2011)
-- Also, verification and support of cover arrangements for an agent [case officer or intelligence
operative] in anticipation of inquiries or other actions that might test credibility of his or her cover.
(Spy Book)
-- Also, a CIA term for providing appropriate verification and support of cover arrangements for an agent
or asset in anticipation of inquiries or other actions which might test the credibility of his or its cover. (Senate
Report 94-755, Book I - Glossary, 26 Apr 1976)
Badge. A distinctive official device usually made of cast metal, which is provided by the DoD Component
and worn or carried by the bearer as a sign of authority. (DoDI 5240.25, Counterintelligence Badges and
Credentials, 30 Sep 2011 with change 1 dated 15 Oct 2013) Also see credentials.
21
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Basic Intelligence. Fundamental intelligence concerning the general situation, resources, capabilities,
and vulnerabilities of foreign countries or areas which may be used as reference material in the planning
of operations at any level and in evaluating subsequent information relating to the same subject.
(JP 1-02)
Beacon. A device typically fastened to an object or individual that transmits a radio signal in order to
track its location. The technological discipline is called beaconry. (Spycraft)
Behavioral Science Consultant. A professional with extensive training in behavioral science, mental
health, psychiatry, or psychology. (Previously in JP 2-01.2, CI & HUMINT Support to Joint Operations,
13 Jun 2006)
Behavioral Science Consultants are psychologists and forensic psychiatrists, not assigned to
clinical practice functions, but to provide consultative services to support authorized law
enforcement, counterintelligence or intelligence activities, including detention and related
counterintelligence, intelligence, interrogation, and detainee debriefing operations.
Bilateral Collection. A collection activity run jointly with a foreign intelligence service. (Previously in DoDI
S-5240.17, CI Collection, 12 Jan 2009) Also see multilateral.
Bilateral: Activities conducted with only a single foreign nation.
Bilateral/BILAT Operation. An operation run jointly with a foreign intelligence service or between two US
intelligence/CI services. (CI Community Lexicon) Also see unilateral operation.
Bigot Case. An investigation that due to the sensitivity of the subject or the nature of the investigation,
requires that it be handled on a strict need to know basis. Access to these investigations is controlled by
maintaining a list of personnel who have been approved for access, called a “bigot list.”
(AR 381-20,
Army CI Program, 25 May 2010) Also see bigot list, compartmentation.
Bigot List. Tradecraft jargon for any list of names of cleared personnel having restricted access
(need-to-know) to a sensitive operation, investigation or to special access/compartmented intelligence.
Also see bigot case, compartmentation.
-- Also, a restrictive list of persons who have access to a particular, and highly sensitive class of
information. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
In some instances, a case, due to its sensitivity or the sensitivity of the information involved, will
require that it be handled on a strict need-to-know basis. These cases are often referred to as
BIGOT cases because access to them is controlled by a BIGOT list.
-- Army FM 2-22.2, Counterintelligence, October 2009
________________________
According to a variety of sources, the term dates back to World War II when Allied orders for
officers were stamped “TO GIB” for those being sent to Gibraltar for preparations for the invasion of
North Africa; later their orders were stamped “BIG OT” (TO GIB backwards) when they were sent
back to begin planning Operation OVERLORD, the invasion of Normandy. In WWII, it was
convenient, in trying to find out if someone had access to highly restricted NEPTUNE and
OVERLORD planning information, to ask "are you bigoted?" An indignant answer of "no" ended
that part of classified discussion.
Biographical Intelligence. That component of intelligence that deals with individual foreign personalities of
actual or potential importance. (JP 1-02)
Biometrics. The process of recognizing an individual based on measurable anatomical, physiological,
and behavioral characteristics. (JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013) Also see biometrics
enabled-intelligence.
22
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a general term used alternatively to describe a characteristic or a process. As a characteristic:
A measurable biological (anatomical & physiological) and behavioral characteristic that can be used for
automated recognition. As a process: Automated methods of recognizing an individual based on
measurable biological (anatomical & physiological) and behavioral characteristics. (DoDD 8521.01E,
DoD Biometrics, 21 Feb 2008)
-- Also, the measurable biological (anatomical and physiological) and behavioral characteristics
that can be used for automated recognition; examples include fingerprint, face, and iris recognition.
(NSPD 59 / HSPD 24, Biometrics for Identification and Screening to Enhance National Security,
5 Jun 2008)
-- Also, measurable biological (anatomical and physiological) and behavioral characteristic that
may be used for automated recognition of the identity of a person or to verify his claimed identity.
Includes fingerprints, iris/retina, voice, facial, DNA, fingernail, and thermal signature. (AR 381-20,
Army CI Program, 25 May 2010)
“Biometrics has become a non-lethal weapons systems in complex, irregular warfare environments.
When you enroll a person in biometric systems now in use on the battlefield, you take away from
our enemies the ability to remain anonymous. It’s a high impact tool in the ongoing War on Terror
and gives tactical commanders a decisive edge in today and tomorrow’s battlespace.”
-- LTG John F. Kimmons, U.S. Army G-2
________________________
The Secretary of the Army is the DoD Executive Agent for DoD Biometrics.
The term “biometrics” also describes both a process and a characteristic. As a process, biometrics
consists of the automated methods of recognizing an individual based on measurable biological
(anatomical and physiological) and behavioral characteristics.
Two basic types of biometrics: 1) physical characteristics, e.g., face, hand & finger geometry, iris,
and vein structure; and 2) behavioral characteristics, e.g., voice, handwriting, typing, rhythm, and
gait. For general information see <http://www.howstuffworks.com/biometrics.htm>
See Army TC 2-22.82, Biometrics-Enabled Intelligence, March 2011
Also see John Woodward, “Biometrics in the War on Terror,” RAND Corporation (Dec 2005);
Biometrics-Enabled Intelligence (BEI). Intelligence information associated with and or derived from
biometrics data that matches a specific person or unknown identity to a place, activity, device,
component, or weapon that supports terrorist / insurgent network and related pattern analysis, facilitates
high value individual targeting, reveals movement patterns, and confirms claimed identity. (DoDD
8521.01E, DoD Biometrics, 21 Feb 2008) Also see biometric-enabled watch list (BEWL).
-- Also, the intelligence derived from the processing of biologic identity data and other all-source for
information concerning persons of interest. (JP 2-0, Joint Intelligence, 22 Oct 2013)
-- Also, the information associated with and/or derived from biometric signatures and the associated
contextual information that positively identifies a specific person and/or matches an unknown identity to a
place, activity, device, component, or weapon. (ADRP 2-0, Intelligence, Aug 2012)
BEI is a specialized analytical discipline that relies on all-source collections and a distinct
processing, exploitation, reporting, and dissemination enterprise to integrate the information from
U.S. and non-U.S. biometric collection and processing capabilities into all-source intelligence
analysis for the purpose of monitoring or neutralizing the influence and operational capacity of
individuals, cells, and networks of interest.
-- TC 2-22.82, Biometrics-Enabled Intelligence, March 2011, p. 1-9
23
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Biometrics-Enabled Watch List (BEWL). Any list of interest with individuals identified by biometric sample
instead of by name, and the desired/recommended disposition instructions for each individual.
(TC2-22.82, Biometrics-Enabled Intelligence, March 2011)
Within DoD, BEWL is a decision aid to help commanders determine what action to take when
encountering a person of interest.
Black. 1) tradecraft jargon for inconspicuousness in the sense of being free of hostile surveillance [going
black: become free of surveillance before conducting an operational act]; and 2) CIA tradecraft jargon for
clandestine or covert. (Leo D. Carl, The CIA’s Insider Dictionary, 1996)
-- Also, being free of hostile surveillance while on a clandestine mission; also refers to being in place
undetected or unknown, such as flying in black. (A Spy’s Journey)
-- Also, BLACK: designation applied to encrypted information and the information systems, the
associated areas, circuits, components, and equipment processing that information. Also see RED.
(CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Black Bag Job. [Tradecraft jargon] a surreptitious entry operation usually conducted by the FBI against
a domestically located foreign intelligence target. (Spy Dust) Also see surreptitious entry.
Aka Covert Entry…
Tactical Operations, a supersecret unit of FBI break-in artists who conduct court-authorized
burglaries [covert entries] in homes, offices, and embassies to plant hidden microphones and
video cameras and snoop into computers. …In any given year, TacOps conducts as many as four
hundred of what the FBI calls covert entries. Eighty percent are conducted in national security
cases relating to terrorism or counterintelligence.
Over the years, the FBI has conducted successful covert entries at the Russian and Chinese
embassies or their official diplomatic establishments, as well as at the homes of their diplomats
and intelligence officers.
Going up against foreign intelligence agencies is the biggest challenge because they set traps to
detect entries.
-- Ronald Kessler, The Secrets of the FBI (2011), pp 2, 7, 11, & 173
__________________________
Black Bag” -- The term applied to clandestine entries of premises containing information that is
likely to be of exceptional importance. The material may range from cryptographic data to the
membership rolls of target organizations.
-- Nigel West, Historical Dictionary of International Intelligence.
Black List.
[A list that] contains the identities and locations of individuals whose capture and detention
are of prime importance, or individuals who have been determined to be intelligence fabricators. (CI
Community Lexicon) Also see Gray List; White List.
-- Also, an official counterintelligence listing of actual or potential hostile collaborators, sympathizers,
intelligence suspects, or other persons viewed as threatening to the security of friendly military forces.
(Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
Previous DoD definition in JP 1-02: an official counterintelligence listing of actual or potential
enemy collaborators, sympathizers, intelligence suspects, and other persons whose presence
menaces the security of friendly forces. Note: this definition rescinded by JP 2-01.02, 11 Mar 2011.
_________________________
24
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Examples of individuals who may be included on a Black List:
1) Known or suspected enemy or hostile espionage, sabotage, terrorist, political, and
subversive individuals.
2) Known or suspected leaders and members of hostile paramilitary, partisan, or guerrilla groups.
3) Political leaders known or suspected to be hostile to the military and political objectives of the
United States and/or an allied nation.
4) Known or suspected officials of enemy governments whose presence in the theater of
operations poses a security threat to the U.S. Forces.
5) Known or suspected enemy collaborators and sympathizers whose presence in the theater
of operations poses a security threat to the U.S. Forces.
6) Known enemy military or civilian personnel who have engaged in intelligence, CI, security,
police, or political indoctrination activities among troops or civilians.
7) Other enemy personalities such as local political personalities, police chiefs, and heads of
significant municipal and/or national departments or agencies.
-- USMC, MCWP 2-6 (previously 2-14), Counterintelligence, 5 Sep 2000
Black Swan Event. An event that is rare, predictable only in retrospect, with extreme impacts.
Blow [Tradecraft jargon] to expose—often unintentionally—personnel, installations or other elements of a
clandestine activity or organization. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976) Also see
blown.
Blown [Tradecraft jargon] to have one’s cover exposed; to have an operation become public. (A Spy’s
Journey)
Bona Fides. The lack of fraud or deceit: a determination that a person is who he/she says he/she is.
(National HUMINT Glossary)
Tradecraft jargon for credentials which establishes the credibility of a human source.
_______________________
The determination of a defector or agent’s bona fides, the verification of their truthfulness, is critical
to the assessment of the information they provide.
-- Michael J. Sulick, American Spies: Espionage Against the United States from the Cold War to
the Present, 2013, p. 77
-- Also, good faith. In personnel recovery, the use of verbal or visual communication by individuals
who are unknown to one another, to establish their authenticity, sincerity, honesty, and truthfulness.
(JP 1-02 and JP 3-50, Personnel Recovery, 5 Jan 2007)
-- Also. the lack of fraud or deceit: a determination that a person is who he/she says he/she is.
(JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, physical and/or oral exchanges employed by an unknown individual to prove identity and
foster trust. (HDI Lexicon, April 2008)
-- Also, documents, information, action, codes, etc., offered by an unknown or otherwise suspected
individual to establish his or her good faith, identification, dependability, truthfulness, or motivation.
(ICS Glossary & AFOSI Manual 71-142, OFCO, 9 Jun 2000)
Border Crosser. An individual, living close to a frontier, who normally has to cross the frontier frequently
for legitimate purposes. (JP 1-02)
25

 

 

 

 

 

 

 

Content      ..     6      7      8      9     ..