Military reference books and manuals (2009-2023, Volume 4) - page 11

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 4)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     9      10      11      12     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 4) - page 11

 

 

Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, the systematic process of using interrogation approaches to question a captured or detained
person to obtain reliable information to satisfy foreign intelligence collection requirements. (DoDD
3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and Tactical Questioning, 11 Oct 2012 w/
chg 1 dated 15 Nov 2013)
DoD Policy: No person in the custody or physical control of DoD or detained in a DoD facility shall
be subject to cruel, inhuman, or degrading treatment or punishment as defined in title XIV of Public
Law 109-163, also known as, “The Detainee Treatment Act of 2005.” Acts of physical or mental
torture are prohibited.
All intelligence interrogations, debriefings, or tactical questioning to gain intelligence from captured
or detained personnel shall be conducted humanely, in accordance with applicable law and policy,
including Army FM 2-22.3 (Human Intelligence Collector Operations, 6 Sep 2006).
____________________
Intelligence interrogations and tactical questioning will be conducted only by personnel trained
and certified IAW DoDD 3115.09. All DoD interrogations will operate using US Army Field Manual
2-22.3, Human Intelligence Collector Operations.
-- JP 2-01.2, CI & HUMINT in Joint Operations (U), 16 Mar 2011 w/ chg 1 dated 26 Aug 2013, p. IV-9
____________________
For DoD policy see DoDD 3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and
Tactical Questioning, 11 Oct 2012 with change 1 dated 15 Nov 2013.
Also see Interrogation: World War II, Vietnam, and Iraq (Washington, DC: National Intelligence
College, Sep 2008); available online at <http://www.ndic.edu/press/12010.htm>
Intelligence Interviewing. The [non-coercive] gathering of useful and accurate information by
professionals questioning detainees. (Intelligence Science Board, Intelligence Interviewing: Teaching
Papers and Case Studies, April 2009) Also see educing information; elicitation; debriefing; interrogation;
interview.
See the 2009 Intelligence Science Board report, Intelligence Interviewing: Teaching Papers and
Case Studies, available online at <www.fas.org/irp/dni/isb/interview.pdf> -- the emphasis of this
report is on non-coercive intelligence interviewing.
This report may be of interest to the full range of intelligence professionals involved with
interrogation and intelligence interviewing. In particular to those who focus on strategic
interrogation and/or “high-value” detainees.
Intelligence Liaison.
[Activity which] includes official contacts between a component of the US
Intelligence Community and a foreign intelligence or security service which are directly related to
espionage or counterintelligence, or other intelligence activities. (DCID 5/1P) Also see liaison.
Intelligence Mission Management (IMM). A systematic process by a joint intelligence staff to proactively
and continuously formulate and revise command intelligence requirements, and track the resulting
information through the processing, exploitation, and dissemination process to satisfy user requirements.
(JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan 2012)
Intelligence Officer (IO). A professionally trained member of an intelligence service. He or she may be
serving in the home country or abroad as a member of a legal or illegal residency. (AFOSI Manual
71-142, 9 Jun 2000 and FBI FCI Terms)
-- Also, a professional employee of an intelligence organization engaged in intelligence activities.
(ODNI, U.S. National Intelligence - An Overview 2011)
186
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Intelligence Operations. The variety of intelligence and counterintelligence tasks that are carried out by
various intelligence organizations and activities within the intelligence process. Intelligence operations
include planning and direction, collection, processing and exploitation, analysis and production,
dissemination and integration, and evaluation and feedback. (JP 1-02 and JP 2-01, Joint and National
Intelligence Support to Military Operations, 5 Jan 2012)
-- Also, the tasks undertaken by military intelligence units and Soldiers to obtain information to satisfy
validated requirements. (ADRP 2-0, Intelligence, Aug 2012)
Note: Intelligence consists of two components: foreign intelligence (FI) and counterintelligence
(CI). Intelligence operations is a broad term with broad application, whereas “CI operations” is a
specific term with a precise application.
_____________________
Intelligence operations are conducted to provide intelligence in support of all missions.
Intelligence operations gain and maintain contact with threat forces; collect signatures and
observables to identify, locate, and provide intentions of threat forces and threat networks.
Intelligence operations are not solely accomplished from airborne platforms or standoff surveillance
sites. They are often executed in and amongst local populations and in close proximity to threat
forces and/or groups. Intelligence operations also facilitate understanding of the terrain and civil
considerations within an area of operations.
-- U.S. Army TRADOC Pam 525-2-1, US Army Concept for Intelligence 2016-2028, 13 Oct 2010, p. 9
Intelligence Oversight. The process of independently ensuring all DoD intelligence, counterintelligence,
and intelligence-related activities are conducted in accordance with applicable U.S. law, E.O.s,
Presidential directives, and DoD issuances designed to balance the requirement for acquisition of
essential information by the IC, and the protection of Constitutional and statutory rights of U.S. persons.
Intelligence Oversight also includes the identification, investigation, and reporting of questionable
intelligence activities and S/HS matters involving intelligence activities. (DoDD 5148.11, ATSD/IO, 24 Apr
2013)
Intelligence Planning (IP). The intelligence component of the Adaptive Planning and Execution system,
which coordinates and integrates all available Defense Intelligence Enterprise capabilities to meet
combatant commander intelligence requirements. (JP 2-0, Joint Intelligence, 22 Oct 2013) Also see
Counterintelligence Functional Support Plan (CI FSP).
-- Also, the intelligence portion of Adaptive Planning and Execution (APEX). Intelligence planning
provides a process that effectively integrates, synchronizes, prioritizes and focuses Defense intelligence
(both Theater and National) on achieving the supported commander’s operational objectives and desired
effects during all phases of the plan. Additionally, the process identifies knowledge gaps and capability
shortcomings within the DoD intelligence community (IC). (CJCSM 3314.01, Intelligence Planning, 28 Feb
2008)
Note: the term “Intelligence Campaign Planning” or “ICP” is no longer in use; the process is now
referred to as “Intelligence Planning.”
Intelligence Planning Process. The intelligence component of Adaptive Planning. It is a process that
integrates, synchronizes, prioritizes, and focuses DoD Intelligence (both theater and national) on
achieving the supported commander’s operational objectives and desired effects during all phases of
an OPLAN or concept plan. Additionally, the process identifies knowledge gaps and capability shortfalls
within DoD Intelligence. (DoDI 5105.21, DIA, 18 Mar 2008)
Intelligence Preparation of the Battlespace (IPB). The analytical methodologies employed by the
Services or joint force component commands to reduce uncertainties concerning the enemy,
environment, time, and terrain. Intelligence preparation of the battlespace supports the individual
operations of the joint force component commands. (JP 1-02 and JP 2-01.3, Joint Intelligence Preparation
of the Operational Environment) Also see Joint Intelligence Preparation of the Operational Environment.
187
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Intelligence Process. The process by which information is converted into intelligence and made available
to users. The process consists of six interrelated intelligence operations: planning and direction,
collection, processing and exploitation, analysis and production, dissemination and integration, and
evaluation and feedback. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military
Operations, 5 Jan 2012) Also see intelligence cycle.
-- Also, the Army refers to the intelligence cycle as the “intelligence process,” which it defines as:
intelligence operations are conducted by performing four steps that constitute the intelligence process:
Plan, Prepare, Collect, and Produce. Additionally, there are four continuing activities that occur across
the four intelligence process steps: Generate intelligence knowledge, Analyze, Assess, and Disseminate.
(See Chapter 4, “Intelligence Process in Full Spectrum Operations,” Army FM 2-0, Intelligence, Mar 2010)
-- Also, those steps by which information is collected, converted into intelligence, and disseminated.
(Senate Report 95-755, Book I - Glossary, 26 Apr 1976)
Intelligence Processing. Conversion of collected information and/or intelligence into a form more suitable
for the production of intelligence. (CI Community Glossary and ICS Glossary)
Intelligence Product. An intelligence report disseminated to customers by an intelligence agency or
element. The report contains information and/or analysis of potential intelligence value to meet the
intelligence needs of users within and outside the Intelligence Community. It may involve current or
future developments or capabilities, intentions, and activities of entities of interest. (ICD 208, 17 Dec
2008)
Intelligence Production. The integration, evaluation, analysis, and interpretation of information from single
or multiple sources into finished intelligence for known or anticipated military and related national security
consumer requirements. (JP 2-0, Joint Intelligence, 22 Oct 2013) Also see production.
-- Also, conversion of material into finished intelligence through the integration, analysis, evaluation,
and/or interpretation of all available data and the preparation of intelligence products is support of known
or anticipated customer requirements. (CI Community Glossary and ICS Glossary)
Intelligence Reach. The activity by which intelligence organizations proactively and rapidly access
information from, receive support from, and conduct direct collaboration and information sharing with
other units and agencies, both within and outside the area of operations, unconstrained by geographic
proximity, echelon, or command. (ADRP 2-0, Intelligence, Aug 2012)*
* Note: Supersedes the definition in Army FM 2-0, Intelligence, 23 Mar 2010
________________________
Three important aspects of intelligence reach
are searches and queries, data mining, and collaboration.
-- ADRP 2-0, Intelligence, Aug 2012
Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA). An act to reform the intelligence
community and the intelligence and intelligence-related activities of the United States Government, and
for other purposes. IRTPA established both the position of Director of National Intelligence (DNI) and the
National Counterterrorism Center (NCTC). (PL 108-458, 17 Dec 2004)
Intelligence-Related Activities. Those activities outside the consolidated defense intelligence program
that: respond to operational commanders' tasking for time-sensitive information on foreign entities;
respond to national intelligence community tasking of systems whose primary mission is support to
operating forces; train personnel for intelligence duties; provide an intelligence reserve; or are devoted to
research and development of intelligence or related capabilities. (Specifically excluded are programs that
188
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
are so closely integrated with a weapon system that their primary function is to provide immediate-use
targeting data.) (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations,
5 Jan 2012)
Intelligence Report (INTREP). A specific report of information, usually on a single item, made at any level
of command in tactical operations and disseminated as rapidly as possible in keeping with the timeliness
of the information. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations,
5 Jan 2012)
-- Also, a product of the production step of the intelligence cycle. (ICS Glossary)
Intelligence Reporting. The preparation and conveyance of information by any means. More commonly,
the term is restricted to reports as they are prepared by the collector and as they are transmitted by the
collector to the latter's headquarters and by this component of the intelligence structure to one or more
intelligence-producing components. Thus, even in this limited sense, reporting embraces both collection
and dissemination. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1
dated 26 Aug 2011)
Intelligence Requirement (IR). 1) Any subject, general or specific, upon which there is a need for the
collection of information, or the production of intelligence; 2) A requirement for intelligence to fill a gap in
the command’s knowledge or understanding of the operational environment or threat forces. (JP 2-0,
Joint Intelligence, 22 Oct 2013) Also see information requirements; collection requirement.
The articulation of the requirement is the most important
part of the process, and it seldom is as simple as it might seem.
- DIA, Intelligence Essentials for Everyone, June 1999
-- Also, a requirement for intelligence to fill a gap in the command’s knowledge or understanding of
the operational environment or threat forces. (DoDD S-3325.09, Oversight, Management, and Execution
of Defense Clandestine Source Operations (U), 9 Jan 2013 w/ chg 1 dated 13 Jun 2013)
-- Also, [intelligence] requirement: a general or specific validated request for intelligence information
made by a user. (National HUMINT Glossary)
-- Also, a type of information requirement developed by subordinate commanders and the staff
(including subordinate staffs) that requires dedicated ISR collection for the elements of threat, terrain
and weather, and civil considerations. (Army FM 2-0, Intelligence, 23 Mar 2010)
-- Also, the need to collect intelligence information or to produce intelligence, either general or
specific, on a particular subject. (ODNI, U.S. National Intelligence - An Overview 2011)
Intelligence Sensemaking. Encompasses the processes by which specialized knowledge about
ambiguous, complex, and uncertain issues is created. This knowledge is generated by professionals
who in this context become known as Intelligence Sensemakers. (Sensemaking: A Structure for an
Intelligence Revolution by David T. Moore) Also see sensemaking.
Copy of Sensemaking: A Structure for an Intelligence Revolution by David T. Moore available at
Intelligence Source. The means or system that can be used to observe and record information relating
to the condition, situation, or activities of a targeted location, organization, or individual. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
An “intelligence source” can be people, documents, equipment, or technical sensors.
189
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Intelligence Sources and Methods. 1) Sources: Persons, images, signals, documents, data bases, and
communications media capable of providing intelligence information through collection and analysis
programs, e.g., HUMINT, IMINT, SIGINT, and MASINT; and 2) Methods: Information collection and
analysis strategies, tactics, operations and technologies employed to produce intelligence products.
If intelligence sources and methods are disclosed without authorization their effectiveness may be
substantially negated or impaired. (IC Standard 700-1, 4 Apr 2008)
The terms “intelligence sources and methods” are used in legislation and executive orders to
denote specific protection responsibilities of the Director of National Intelligence (DNI).
Intelligence, Surveillance, and Reconnaissance (ISR). An activity that synchronizes and integrates the
planning and operation of sensors, assets, and processing, exploitation, and dissemination systems in
direct support of current and future operations; this is an integrated intelligence and operations function.
(DoDD 5143.01; JP 1-02; and JP 2-01, Joint and National Intelligence Support to Military Operations,
5 Jan 2012)
Intelligence Synchronization. The “art” of integrating information collection and intelligence analysis with
operations to effectively and efficiently support decisionmaking. (ADRP 2-0, Intelligence, Aug 2012)
Intelligence System. Any formal or informal system to manage data gathering, to obtain and process the
data, to interpret the data, and to provide reasoned judgments to decision makers as a basis for action.
(JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan 2012)
Intelligence Task List (ITL). A compilation of the specified and implied intelligence tasks required to
satisfy the information needs to support the successful achievement of the Combatant Command’s
operational objectives. The ITL is developed by the Combatant Command J2 and Defense Intelligence
Operations Coordination Center (DIOCC). Assignment of roles and responsibilities for the specific
collection, analysis and production is accomplished during the development of the [COCOM’s IPLAN]
and the NISP. The end state is a synchronized collection, analysis and production effort, from tactical to
national level that will support the successful achievement of the Combat Command’s operational
objectives. (CJCSM 3314.01, Intelligence Planning, 28 Feb 2007)
Intelligence Threat. The intention and capability of any adversary to acquire and exploit critical
information. The purpose of the acquisition is to gain a competitive edge or diminish the success of a
particular U.S program, operations, or industrial activity. (IOSS Intelligence Threat Handbook - Jun 2004)
Also see threat; threat to national security; transnational threat; foreign intelligence collection threat.
Foreign intelligence services, along with terrorist groups, transnational criminal organizations, and
other nonstate actors, are targeting and acquiring our national security information, undermining
our economic and technological advantages, and seeking to influence our national policies and
processes covertly. These foreign intelligence efforts employ traditional methods of espionage and,
with growing frequency, innovative technical means.
Among significant foreign threats, Russia and China remain the most capable and persistent
intelligence threats and are aggressive practitioners of economic espionage against the United
States.
-- DNI, Worldwide Threat Assessment of the US Intelligence Community, SSCI, 12 March 2013
Intellipedia. The Intelligence Community’s version of the famous encyclopedia. It is used by analysts,
working groups, and engineers throughout the IC. (CIA news release March 2008)
Interagency. United States Government agencies and departments, including the Department of
Defense. (JP 1-02 and JP 3-08, Interorganizational Coordination During Joint Operations, 24 Jun 2011)
Also see interagency coordination.
Interagency Coordination. Within the context of DoD involvement, the coordination that occurs between
elements of DoD, and engaged US Government agencies and departments for the purpose of
accomplishing an objective. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
190
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Inter-dependency. [In critical infrastructure usage] relationships or connections between entities of
different DoD Components and defense infrastructure sectors. (DoDD 3020.40, DoD Policy and
Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012) Also see intra-
dependency.
Interdiction.
1) An action to divert, disrupt, delay, or destroy the enemy’s military surface capability before
it can be used effectively against friendly forces, or to otherwise achieve objectives; and 2) In support of
law enforcement, activities conducted to divert, disrupt, delay, intercept, board, detain, or destroy, as
appropriate, vessels, vehicles, aircraft, people, and cargo. See also air interdiction. (JP 1-02 and JP 3-03,
Joint Interdiction, 3 May 2007)
Intergovernmental Organization (IGO). An organization created by a formal agreement (e.g., a treaty)
between two or more governments. It may be established on a global, regional, or functional basis for
wide-ranging or narrowly defined purposes. Formed to protect and promote national interests shared by
member states. Examples include the United Nations, North Atlantic Treaty Organization, and the African
Union. (JP 1-02 and JP 3-08, Interorganizational Coordination During Joint Operations, 24 Jun 2011)
-- Also, an organization comprised primarily of sovereign states (referred to as member states), or
of other IGOs. ( w/ chg 2 dated 21 Sep 2012, DoD Policy and Responsibilities for Critical Infrastructure,
14 Jan 2010)
Internal Security. The state of law and order prevailing within a nation. (JP 1-02 and JP 3-08, Inter-
organizational Coordination During Joint Operations, 24 Jun 2011)
International Terrorist Activities. Activities undertaken by or in support of terrorists or terrorist
organizations that occur totally outside the United States, or that transcend national boundaries in terms
of the means by which they are accomplished, the persons they appear intended to coerce or intimidate,
or the locale in which the perpetrators operate or seek asylum. (DoD 5240.1-R, 7 Dec 1982)
International Terrorism. Activities that involve violent acts or acts dangerous to human life that violate
federal, state, local, or tribal criminal law or would violate such law if committed within the United States or
a state. Local, or tribal jurisdiction; appear to be intended to intimidate or coerce a civilian population; to
influence the policy of a government by intimidation or coercion; or to affect the conduct of a government
by assassination or kidnapping; and occur totally outside the United States, or transcend national borders
in terms of the means by which they are accomplished, the persons they appear to be intended to coerce
or intimidate, or the locale in which their perpetrators operate or seek asylum. (50 USC 1810 Section
101(c) and FBI Domestic Investigations and Operations Guide, 15 Oct 2011)
International Traffic in Arms Regulations (ITAR). A set of United States government regulations that
control the export and import of defense-related articles and services on the United States Munitions List
(USML). (Wikipedia, accessed 10 Sep 2013)
ITAR implements the provisions of the Arms Export Control Act (AECA), and are described in Title
22 (Foreign Relations), Chapter I (Department of State), Subchapter M of the Code of Federal
Regulations. The Department of State Directorate of Defense Trade Controls (DDTC) interprets
and enforces ITAR. Its goal is to safeguard U.S. national security and further U.S. foreign policy
objectives.
The related Export Administration Regulations are enforced and interpreted by the Commerce
Department. DoD is also involved in the review and approval process. Physical enforcement of
import and export laws at border crossings is performed by Customs and Border Protection, an
agency of the Department of Homeland Security.
191
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
INTERPOL. The world’s largest international police organization, with 188 member countries. Created in
1923, it facilitates cross-border police co-operation, and supports and assists all organizations, authorities
and services whose mission is to prevent or combat international crime. (www.interpol.int/ )
INTERPOL aims to facilitate international police co-operation even where diplomatic relations do
not exist between particular countries. Action is taken within the limits of existing laws in different
countries and in the spirit of the Universal Declaration of Human Rights. INTERPOL’s constitution
prohibits “any intervention or activities of a political, military, religious or racial character.”
Interpretation. A part of the analysis and production phase in the intelligence process in which the
significance of information is judged in relation to the current body of knowledge. (Previously in JP 2-0,
Joint Intelligence, 22 Jun 2007)
Interrogation. Systematic effort to procure information by direct questioning of a person under the control
of the questioner. (JP 1-02; JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26
Aug 2011; and Senate Report 94-755, Book I - Glossary, 26 Apr 1976) Also see educing information;
elicitation; debriefing; intelligence interrogation; intelligence interviewing; interview; strategic intelligence
interrogation.
-- Also, interaction and conversation with a source who appears initially unwilling to provide
information. (Educing Information - Interrogation: Science and Art, Dec 2006)
-- Also, systematic effort to procure information to answer specific collection requirements by direct
and indirect questioning techniques of a person who is in the custody of the forces conducting the
questioning. (Army FM 2-22.3, HUMINT Collector Operations, 6 Sep 2006 and FM 2-0, Intelligence,
23 Mar 2010)
-- Also [law enforcement interrogation], the systematic effort by law enforcement investigators to
prove, disprove, or corroborate information relevant to a criminal investigation using direct questioning
in a controlled environment. (FM 19-10 / ATTP 3-39, Law and Order Operations, June 2011)
-- Also, a methodology employed during the interview of a person to obtain information that the
source would not otherwise willingly disclose. A typical purpose is not necessarily to force a confession,
but rather to develop, playing on the source's character, sufficient rapport as to prompt the source to
disclose information valuable to the interrogator. (Wikipedia; accessed 1 Aug 2007)
Within DoD: Intelligence interrogation is the systematic process of using approved techniques,
consistent with applicable law, to question a captured or detained person to obtain reliable
information responsive to intelligence requirements. Interrogation is considered an overt HUMINT
collection method but is regulated separately from other DoD HUMINT activities.
____________________
For DoD policy see DoDD 3115.09, DoD Intelligence Interrogation, Detainee Debriefings, and
Tactical Questioning, 11 Oct 2012.
Per Executive Order 13491, Ensuring Lawful Interrogations (22 Jan 2009), only those interrogation
approaches and techniques addressed in U.S. Army FM 2-22.3 are authorized.
U.S. Army FM 2-22.3, Human Intelligence Collector Operations (Sep 2006), available online at:
Interrogation Approach. [In detainee operations] an interrogation technique as identified in U.S. Army
Field Manual 2-22.3 that is used by trained and certified interrogators to establish and maintain control
over and rapport with a detainee in order to gain the detainee’s cooperation to answer the interrogator’s
questions. (DoDD 3115.09, DoD Intelligence Interrogations, Detainee Debriefings, and Tactical
Questioning, 11 Oct 2012 w/ chg 1 dated 15 Nov 2013)
192
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Interview.
[In intelligence usage,] to gather information from a person who is aware that information is
being given although there is ignorance of the true connection and purposes of the interviewer. Generally
overt unless the collector is other than purported to be. (JP 1-02) Also see educing information;
elicitation; debriefing; intelligence interrogation; intelligence interviewing; interrogation.
-- Also, a nonstructured discussion, where open-ended questions are asked to determine facts about
an incident or crime. (FM 19-10 / ATTP 3-39, Law and Order Operations, June 2011)
-- Also, a dynamic human interaction to collect facts to be used for decision-making and/or action-
taking. Interviewing is the gathering of facts/information; it is non-accusatory and less structured than
an interrogation.
-- Also, a conversation between two or more people (the interviewer and the interviewee) where
questions are asked by the interviewer to obtain information from the interviewee. Interviews can be
divided into two rough types, interviews of assessment and interviews for information. (Wikipedia)
Investigative interview is the process whereby an investigator verbally obtains information from
people associated with direct knowledge relevant to the investigation.
Intra-dependency. Relationships or connections between entities of a DoD Component and a defense
infrastructure sector. (DoDD 3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan
2010 w/ chg 2 dated 21 Sep 2012) Also see inter-dependency.
Intrusion.
[In cyber usage], unauthorized access to a DoD, DIB [defense industrial base], or critical
infrastructure network, information system, or application. (DoDI S-5240.23, CI Activities in Cyberspace
(U), 13 Dec 2010 with change 1 dated 16 Oct 2013)
-- Also, unauthorized act of bypassing the security mechanisms of a system. (CNSSI No. 4009,
National Information Assurance Glossary, 26 April 2010)
-- Also. movement of a unit or force within another nation’s specified operational area outside of
territorial seas and territorial airspace for surveillance or intelligence gathering in time of peace or tension.
(JP 1-02)
Investigation. The systematic inquiry into an allegation of unfamiliar or questionable activities, wherein
evidence is gathered to substantiate or refute the allegation or questionable activity. An investigation is
initiated when there are articulable facts that indicate a possible violation of law or policy. Some
investigations may be conducted unilaterally by an agency (depending on their authorities), jointly with an
external investigate body, or referred to an external investigate body for unilateral investigation. (ONCIX
Insider Threat Detection - Glossary) Also see counterintelligence investigation.
-- Also, the application of law enforcement and/or counterintelligence authorities and methodologies
to conduct a detailed, sustained, structured, and objective inquiry to ascertain the truth about an event,
situation, or individual. (SECNAVINST 5430.107, Mission & Functions of the NCIS, 28 Dec 2005)
-- Also, the act of investigating; the process of inquiring into or following up; research; study; inquiry,
especially patient or thorough inquiry or examination…. (Wiktionary; accessed 28 June 2012)
Conducting a successful investigation is often the result of having a wide range of knowledge and
using common sense in its application. There are certain actions that apply to all investigations.
Investigators follow these intelligent and logical steps to ensure that an investigation is conducted
systematically and impartially. There are certain actions that, over time, have proven useful for
specific investigations. It is a wise investigator who understands and applies the knowledge, skills,
and techniques learned for a particular investigation and uses them wherever they are most useful
in any investigation.
-- FM 3-19.13, Law Enforcement Investigations, Jan 2005, p. 1-15
193
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Investigations, Collections & Operations Nexus (ICON). The Air Force’s central counterintelligence
and counterterrorism analysis center of excellence; an element of the Air Force Office of Special
Investigations (AFOSI).
The ICON is AFOSI’s primary stop for analytical and specialist support for all criminal and
counterintelligence investigations and operations. It is the home to AFOSI’s 24/7 Global Watch
Center and the current Intelligence Desk which produces AFOSI”S flagship publication, the “AFOSI
Blue Line.” Additionally, the ICON is responsible for acting as the key liaison and interface with
National Intelligence and Law Enforcement organizations for AFOSI’s CI, CT, criminal, economic
crime, and cyber operational issues.
-- Air Force Office of Special Investigations
Investigative Jurisdiction. Term for the jurisdiction of an investigative agency over a particular crime
or over the locus of where the crime was committed. (Leo D. Carl, The CIA Insider’s Dictionary, 1996)
Investigative Lead. A person who possesses information about or was a witness to an incident under
investigation or a record which contains information of value to the investigation. (AR 381-20, Army CI
Program, 25 May 2010) Also see lead.
Investigative Plan (IP). A detailed plan for the conduct of a CI investigation to ensure that all investigative
activity is conducted in a properly sequenced, coordinated, coherent, timely and efficient manner. The
plan should outline the actions to be accomplished to resolve an allegation, a report, or information
relating to matters under investigation. (AR 381-20, Army CI Program, 25 May 2010)
-- Also, a document used to plan proposed investigative activities, including special investigative
techniques, to support counterintelligence investigation. (Army FM 2-22.2, CI, Oct 2009)
Blueprint for a CI Investigation - a tool to describe the purpose & objectives
The IP is the equivalent of an operations order for the conduct of a CI investigation.
-- 902d MI Group Investigations Handbook, Jun 2012, p.94
CI investigations will vary is scope, objective, and resources to successfully resolve the incident
under investigation. The IP is the document that provides a detailed road map on the conduct of
CI investigations including all investigative participants, all investigative activities required, all
resources and external support required, and all interagency or legal coordination required to
successfully resolve the incident. IPs are living documents and may require revision due to
information development and case direction.
- Army FM 2-22.2, Counterintelligence, Oct 2009 (Chapter 2 - CI Investigations, pp. 2-1 thru 2-47)
Investigative Source. See FOUO definition in AR 381-20, Army CI Program (U), 25 May 2010.
Investigative Source Operation (ISO). A controlled counterintelligence operation that may be used in
counterintelligence investigations. Also see counterintelligence investigation.
Three types of CI Investigative Source Operations are: role players; collaborative sources; and
investigative access sources.
Proposals for the use of an ISO require proper legal review and formal approval. For detailed
information see classified Army Regulation 381-20, Army Counterintelligence Program (U),
25 May 2010, Chapter 10 - Counterintelligence Operations, paragraph 10 -2 (pp. 44-47).
Irregular Warfare (IW) A violent struggle among state and non-state actors for legitimacy and influence
over the relevant population(s). (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013)
194
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a violent struggle among state and non-state actors for legitimacy and influence over the
relevant population(s). Irregular warfare favors indirect and asymmetric approaches, though it may
employ the full range of military and other capacities, in order to erode an adversary's power, influence,
and will. (DoD 3000.07, Irregular Warfare, 1 Dec 2008)
-- Also, [as defined by Army] a violent struggle among state and nonstate actors for legitimacy and
influence over a population. (FM 3-0, Operations, Feb 2008)
ITAR. See International Traffic in Arms Regulations.
195
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
J ==========================================
J-2X. The staff element of the intelligence directorate of a joint staff that combines and represents the
principal authority for counterintelligence and human intelligence support. (JP 1-02 and JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011) Also see 2X.
-- Also, a J-2 staff element normally associated with a deployed joint force, consisting basically of the
HUMINT operations cell (HOC) and the task force counterintelligence coordinating authority (TFCICA),
and the Operational Support Element (OSE). The J-2X is responsible for coordination and deconfliction
of all human source-related activity. (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
Jack-in-the-Box (JIB). A dummy—sometimes inflatable—placed in a car to deceive [surveillance] about
the number of persons in the vehicle. (Spy Book)
A three-dimensional human torso sitting atop a spring-activated scissor-lift mechanism fitted with
a rotating head, which collapse[s] into a small portable briefcase or duffel bag. “ Can be used to
effectively elude surveillance by “controlling the location of the event (an empty street…), the
lighting (an unlit area), the audience (the trailing surveillance car), the timing (when the cars were
a sufficient distance apart), and the sight line (visible only from the rear).”
-- H. Keith Melton and Robert Wallace, The Official CIA Manual of Trickery and Deception (2009)
________________________
It is used in an automobile to evade surveillance, by deceiving (a) surveillant(s) that a person being
tailed is still in the automobile, when, in fact, the jib has replaced him or her. The FBI was allegedly
thus deceived while staking out Edward Lee Howard, the former CIA case officer who escaped and
subsequently defected to the former USSR.“
-- Leo D. Carl, The CIA Insider’s Dictionary (1996), p. 319
________________________
“A jib is an inflatable man-sized dummy first employed by the CIA in the early 1980s. It was
designed to replace an operative escaping from the inside of a moving vehicle. As the escapee
rolls from the passenger side of the vehicle, the jib is employed. Thus, the jib serves as a decoy for
pursuers [trailing surveillance team].”
-- W. Thomas Smith, Jr., Encyclopedia of the CIA, 2003
Jihad. Arabic word derived from a verb that means “to struggle, strive, or exert oneself.” Violent
extremists understand the concept jihad as a “religious call to arms.” Also see jihadist.
Historically, key Sunni and Shia religious texts most often referred to jihad in terms of religious
approved fighting on behalf of Islam and Muslims. Most Al Qaeda-produced ideological material
reflects Al Qaeda supporters’ shared view of jihad as an individual duty to fight on behalf of Islam
and Muslims, and, in some case, to offensively attack Muslims and non-Muslims who are deemed
insufficiently pious or who oppose enforcement of Islamic principles and religious law.
The terms jihadist, violent Islamist, and militant Islamist refer to groups and individuals whose
statements indicate that they share such an understanding of jihad and who advocate or use
violence against the United States or in support of transnational Islamist agendas.
-- Congressional Research Service (CRS) Report R41674, 8 Mar 2011
____________________________
…[J]ihad is a complex term that can be understood in a number of different ways. Traditional
Islamic jurisprudence distinguishes between two major levels of jihad. The Greater Jihad refers to
the inner struggle of the individual believer to affirm his or her commitment to the requirements of
Islam, and is also called jihad of the heart. It is the Lesser Jihad, or jihad of the sword (often
translated “holy war,” a translation the author scrupulously avoids) that is the central concern of his
study.
196
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Sometimes called the “sixth pillar of Islam,” there is no question that jihad is a required commitment
of the Muslim. Moreover, although most Qur’anic verses define it as the collective responsibility all
Muslims to defend the community against non-Muslim aggressors, there are a few verses, as well
as hadith (authentic traditions ascribed to the Prophet Muhammad), that can be interpreted to
justify wars of imperial conquest. It is also certainly true that at various times in Islamic history
conquerors have used the concept of jihad to justify imperial expansion.
-- Max L. Gross, Dean of the School of Intelligence Studies, Joint Military Intelligence College,
and Middle East scholar and intelligence analyst. (As quoted in Joint Military Intelligence College,
Discussion Paper 13, entitled Global War Terrorism: Analyzing the Strategic Threat, Nov 2004, p. viii-ix).
Jihadist. Term describes radicalized individuals using Islam as an ideological and/or religious justification
for their belief in the establishment of a global caliphate, or jurisdiction governed by a Muslim civil and
religious leader known as a caliph. (CRS Report R41416, 23 Jan 2013) Also see jihad.
Jihadists draw on Salafi Islam—the fundamentalist belief that society should be governed by
Islamic law based on the Quran and following the model of the immediate followers and
companions of the Prophet Muhammad.
The CRS Report points out there is an important distinction between the terms “radicalization” and
“violent extremism” as it relates to the threshold of U.S. law enforcement interest and action. This is
because Americans have the right under the First Amendment to adopt, express, or disseminate
ideas, even hateful and extremist ones. But when radicalized individuals mobilize their views, i.e.,
they move from a radicalized viewpoint to membership in a terrorist group, or to planning, materially
supporting, or executing terrorist activity, then the nation’s public safety and security interests are
activated. Thus, the terms may be differentiated as follows:
-- “Radicalization” describes the process of acquiring and holding radical, extremist, or jihadist
beliefs.
-- “Violent Extremism” describes violent action taken on the basis of radical or extremist
beliefs. For many, this term is synonymous with “violent jihadist” and “jihadist terrorist.”
The term “violent jihadist” characterizes jihadists who have made the jump to illegally supporting,
plotting, or directly engaging in violent terrorist activity.
See CRS Report R41416, American Jihadist Terrorism: Combating a Complex Threat. For more
on Salafi Islam, see CRS Report RS21695, The Islamic Traditions of Wahhabism and Salafiyya.
For more on Al Qaeda’s global network, see CRS Report R41070, Al Qaeda and Affiliates:
Historical Perspective, Global Presence, and Implications for U.S. Policy.
Joint. Connotes activities, operations, organizations, etc., in which elements of two or more Military
Departments participate. (JP1, Doctrine for the Armed Forces of the United States, 25 Mar 2013 and
JP 1-02)
Joint Base. For purposes of base defense operations, a joint base is a locality from which operations of
two or more of the Military Departments are projected or supported and which is manned by significant
elements of two or more Military Departments or in which significant elements of two or more Military
Departments are located. (JP 1-02 and JP 3-10, Joint Security Operations in Theater, 03 February 2010)
Joint Captured Materiel Exploitation Center (JCMEC). A physical location for deriving intelligence
information from captured enemy materiel. It is normally subordinate to the Joint Force/J-2. (JP 2-01,
Joint and National Intelligence Support to Military Operations, 5 Jan 2012)
Joint Counterintelligence Unit (JCIU). An organization composed of Service and Department of Defense
agency counterintelligence personnel, formed under the authority of the Secretary of Defense and
assigned to a combatant commander, which focuses on the combatant command strategic and
operational counterintelligence missions. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations,
16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
197
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, an organization composed of Service and Defense agency CI personnel, formed under the
authority of a Secretary of Defense-approved operation order, which focuses on combatant command
strategic and operational CI missions within an area of conflict. This unit is under the command authority
of the Combatant Commander, or his or her duly designated subordinate joint force commander, for the
duration of the operation, or as otherwise specified in the operation plan or order. (DoDI S-5240.09,
OFCO, 29 Oct 2008)
For more detailed discussion of the JCIU see Appendix B, Joint Counterintelligence Unit (U),
JP 2-01.2, CI & HUMINT in Joint Operations (U), 16 Mar 2011 w/ chg 1 dated 26 Aug 2011.
Also see the Joint Counterintelligence Unit Handbook (U), published June 2010 by the Defense
CI & HUMINT Center (D2X-ES-C Lessons Learned Branch).
For lessons learned see the following classified reports —
-- (U) Strategic CI Directorate Iraq (SCID-I) Lesson Learned Report, 5 Jun 2009
-- (U) Strategic CI Directorate Afghanistan (SCID-A) Lesson Learned Report, undated
circa Jun 2010)
Note: The transition of Strategic CI Directorates (SCIDs) to Joint CI Units (JCIUs) was not merely
a change in title—it fundamentally changed the SCID from a CI organization with no clear chain of
command to a CI unit that is directed, controlled, and focused by the Combatant Commander at
the operational level of war.
Joint Counterintelligence Training Academy (JCITA). Professional training and education institution for
advanced joint DoD CI training. (DoDI 3305.11, DoD CI Training, 19 Mar 2007) See counterintelligence
training.
-- Also, the primary professional training and education center for advanced and joint CI training
within DoD and is known as the DoD Center of Excellence for CI training. (DoDI JCITA, 13 Nov 2013)
JCITA provides advanced counterintelligence training to the Department of Defense and
other national security stakeholders agencies within the federal government.
JCITA SIPRNet website at: <https://jcita.dia.smil.mil >
JCITA …training counterintelligence today to protect our nation tomorrow.
Joint Deployable Intelligence Support System (JDISS). A transportable workstation and communications
suite that electronically extends a joint intelligence center to a joint task force or other tactical user.
(JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013)
Joint Doctrine. Fundamental principles that guide the employment of US military forces in coordinated
action toward a common objective. Joint doctrine contained in joint publications also includes terms,
tactics, techniques, and procedures. It is authoritative but requires judgment in application. (JP 1-02)
Joint Document Exploitation Center (JDEC). A physical location for deriving intelligence information from
captured adversary documents including all forms of electronic data and other forms of stored textual and
graphic information. It is normally subordinate to the joint force intelligence directorate. (JP 1-02 and
JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, a joint center established to receive, inventory, catalogue, selectively translate, and
disseminate captured or acquired documents and media. (DHE-M 3301.002, Vol II Collection Operations,
23 Nov 2010)
198
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Joint Force. A general term applied to a force composed of significant elements, assigned or attached,
of two or more Military Departments operating under a single joint force commander. (JP 1-02)
Joint Force Commander (JFC). A general term applied to a combatant commander, subunified
commander, or joint task force commander authorized to exercise combatant command (command
authority) or operational control over a joint force.
(JP1, Doctrine for the Armed Forces of the United
States, 25 Mar 2013 and JP 1-02) Also see joint force.
Joint Intelligence. Intelligence produced by elements of more than one Service of the same nation.
(JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013)
Joint Intelligence Operations Center (JIOC). An interdependent, operational intelligence organization
at the Department of Defense, combatant command, or joint task force (if established) level, that is
integrated with national intelligence centers, and capable of accessing all sources of intelligence
impacting military operations planning, execution, and assessment. (JP 1-02 and JP 2-0, Joint
Intelligence, 22 Oct 2013)
-- Also, those centers, below the Defense-level (COCOM and specified Unified Commands)
established by the Secretary of Defense on 3 April 2006, to plan, prepare, integrate, direct, synchronize,
and manage continuous, full-spectrum defense intelligence operations within their respective AORs. The
J2 of each command is designated as the respective JIOC Director. (DIA HUMINT Manual, Vol I,
DHE-M 3301.001, 30 Jan 2009 w/ chg 2 dated 1 Feb 2012)
Joint Intelligence Preparation of the Operational Environment (JIPOE). The analytical process used by
joint intelligence organizations to produce intelligence estimates and other intelligence products in support
of the joint force commander’s decision-making process. It is a continuous process that includes defining
the operational environment; describing the impact of the operational environment; evaluating the
adversary; and determining adversary courses of action. (JP 1-02 and JP 2-01.3, Joint Intelligence
Preparation of the Operational Environment)
Joint Intelligence Support Element (JISE). A subordinate joint force element whose focus is on
intelligence support for joint operations, providing the joint force commander, joint staff, and components
with the complete air, space, ground, and maritime adversary situation. (JP 1-02 and JP 2-01, Joint and
National Intelligence Support to Military Operations, 5 Jan 2012)
Joint Intelligence Task Force-Combating Terrorism (JITF-CT). See Defense Combating Terrorism Center
(DCTC).
In the fall of 2012 the JITF-CT transitioned to the Defense Combating Terrorism Center (DCTC).
Joint Intelligence Training (JIT). Fundamental training that guides the development and utilization of
intelligence professionals and organizations designed to support two or more Services employed in
coordinated action. (DoDI 3305.14, JIT, 28 Dec 2007)
Joint Inter-Agency Cyber Task Force (JIACTF). Joint inter-agency task force created by the Director of
National Intelligence (DNI) to execute DNI responsibilities in monitoring and coordinating the CNCI and
to report to the President on Comprehensive National Cybersecurity Initiative (CNCI) implementation,
together with recommendations as deemed appropriate. (Securing Cyberspace for the 44th Presidency,
Dec 2008)
199
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Joint Interrogation and Debriefing Center (JIDC). Physical location for the exploitation of intelligence
information from detainees and other sources. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations,
16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
JIDCs are established under the direction of the joint force commander within the joint operations
area and are normally collocated with detainee holding facilities. The mission of the JIDC is to
conduct screening and interrogation of detainees, questioning of walk-in sources, and translation
and exploitation of documents associated with detainees. The JIDC coordinates exploitation of
captured equipment with the joint captured material exploitation center, captured documents with
the joint document exploitation center, and high-value human sources with the joint strategic
exploitation center.
For additional information see JP 3-63, Detainee Operations, 30 May 2008
Joint Interrogation Operations (JIO). 1) Activities conducted by a joint or interagency organization to
extract information for intelligence purposes from enemy prisoners of war, dislocated civilians, enemy
combatants, or other uncategorized detainees; or 2) Activities conducted in support of law enforcement
efforts to adjudicate enemy combatants who are believed to have committed crimes against US persons
or property. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan
2012)
Joint Investigation. An investigation in which more than one investigative agency has established
investigative authority over an offense and/or subject of the investigation, and the agencies involved
agree to pursue the investigation in concert, with agreements reached detailing investigative
responsibilities, procedures, and methods. (CI Community Lexicon)
Joint Operational Planning. Planning activities associated with joint military operations by combatant
commanders and their subordinate joint force commanders in response to contingencies and crises.
(JP 5-0, Joint Operation Planning, 11 Aug 2011)
Joint Operation Planning and Execution System (JOPES). An Adaptive Planning and Execution system
technology. (JP 5-0, Joint Operation Planning, 11 Aug 2011)
Joint Operation Planning Process (JOPP). An orderly, analytical process that consists of a logical
set of steps to analyze a mission, select the best course of action, and produce a joint operation plan or
order. (JP 5-0, Joint Operation Planning, 11 Aug 2011)
Joint Operations. A general term to describe military actions conducted by joint forces and those Service
forces employed in specified command relationships with each other, which of themselves, do not
establish joint forces. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Joint Operations Area (JOA). An area of land, sea, and airspace, defined by a geographic combatant
commander or subordinate unified commander, in which a joint force commander (normally a joint task
force commander) conducts military operations to accomplish a specific mission. (JP 1-02 and JP 3-0,
Joint Operations, 11 Aug 2011)
Joint Personnel Adjudication System (JPAS). The centralized database of standardized personnel
security processes; virtually consolidates the DoD Central Adjudication Facilities by offering real time
information concerning clearances, access, and investigative statuses to authorized DoD security
personnel and other interfacing organizations. (IC Standard 700-1, 4 Apr 2008)
-- Also, the centralized Department of Defense database of standardized personnel security
processes; virtually consolidates the DoD Central Adjudication Facilities by offering real time information
concerning clearances, access, and investigative statuses to authorized DoD security personnel and
other interfacing organizations (e.g., Defense Security Service, Defense Manpower Data Center, Defense
Civilian Personnel Management, and the Air Force personnel Center). (DSS Glossary)
200
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Joint Personnel Recovery Center (JPRC). The primary joint force organization responsible for planning
and coordinating personnel recovery for military operations within the assigned operational area.
(JP 1-02 and JP 3-50, Personnel Recovery, 5 Jan 2007)
Joint Strategic Capabilities Plan (JSCP). A plan that provides guidance to the combatant commanders
and the Joint Chiefs of Staff to accomplish tasks and missions based on current military capabilities.
(JP 5-0, Joint Operation Planning, 11 Aug 2011)
Joint Strategic Exploitation Center (JSEC). Theater-level physical location for an exploitation facility that
functions under the direction of the joint force commander and is used to hold detainees with potential
long-term strategic intelligence value, deemed to be of interest to counterintelligence or criminal
investigators, or who may be a significant threat to the Unites States, its citizens or interest, or US allies.
(JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
The JSEC is a theater-level exploitation facility and is normally collocated with a rear area
collection and holding center for detainees. The JSEC’s mission is the conduct of interrogations
and debriefings to generate intelligence information responsive to theater and national
requirements, and to identify detainees with potential long-term strategic intelligence value,
deemed to be of interest to counterintelligence or criminal investigators, or who may be a
significant threat to the United States, its citizens or interests, or US allies.
Joint Task Force (JTF). A joint force that is constituted and so designated by the Secretary of Defense,
a combatant commander, a subunified commander, or an existing joint task force commander. (JP 1-02)
Joint Task Force Counterintelligence Coordinating Authority. See Task Force Counterintelligence
Coordinating Authority (TFCICA).
Joint Terrorism Task Forces (JTTFs). Small cells of highly trained, locally based, investigators, analysts,
linguists, SWAT experts, and other specialists from dozens of U.S. law enforcement and intelligence
agencies. It is a multi-agency effort led by the Justice Department and FBI designed to combine the
resources of federal, state, and local law enforcement. (DoJ website: <http://www.usdoj.gov/jttf/>) Also
see National Joint Terrorism Task Force.
-- Also, a coordinated “action arm” for federal, state, and local government response to terrorist
threats in specific U.S. geographic regions. The FBI is the lead agency that oversees the JTTFs.
(ODNI, U.S. National Intelligence - An Overview 2011)
-- Also, an FBI-led task force whose primary mission is to collect intelligence of actual, suspected, or
planned acts of terrorism directed against U.S. persons and property. (DoD FCIP Strategy FY 2013-2017)
JTTFs were established by the FBI to conduct operations to predict and disrupt terrorist plots.
JTTFs are in over 100 cities nationwide; in addition, there is at least one in each of the FBI’s 56
field offices. The National Joint Terrorism Task Force (NJTTF), in Washington, D.C., coordinates
all the JTTFs.
--
ODNI, U.S. National Intelligence - An Overview 2011, p. 30
____________________
Joint Terrorism Task Forces (JTTFs) are based in 103 cities nationwide, with at least one in each
of the FBI’s 56 field offices. They include more than 4,400 members nationwide and represent
some 600 state and local agencies and 50 federal agencies.
-- FBI, Today’s FBI: Facts & Figures 2013-2014
____________________
DoD CI personnel participating on JTTFs work in partnership with other JTTF members to detect
and neutralize terrorists, terrorist-enabling individuals, and organizations threatening DoD interest.
-- DoDI 5240.22, CI Support to Force Protection, 24 Sep 2009, p. 6
201
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Joint Worldwide Intelligence Communications System (JWICS). The sensitive compartmented information
portion of the Defense Information Systems Network, which incorporates advanced networking
technologies that permit point-to-point or multipoint information exchange involving voice, text, graphics,
data, and video teleconferencing. (JP 2-0, Joint Intelligence, 22 Oct 2013)
-- Also, the Intelligence Community’s TS-SCI global network; a communications network that delivers
secure information services to national and defense intelligence components around the world. All U.S.
Government TS-SCI networks run off of JWICS. (National Intelligence: A Consumer’s Guide - 2009)
Judgment. [As used in intelligence analysis] Judgment is what analysts use to fill gaps in their
knowledge. It entails going beyond the available information and is the principal means of coping with
uncertainty. It always involves an analytical leap, from the known into the uncertain. Judgment is an
integral part of all intelligence analysis. (Psychology of Analysis by Richards J. Heuer, Jr, 1999)
202
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
K ==========================================
Key. A numerical value used to control cryptographic operations, such as decryption, encryption,
signature generation, or signature verification. (CNSSI No. 4009, National Information Assurance
Glossary, 26 April 2010)
Key Enabler. That crucial element that supplies the means, knowledge, or opportunity that allows for the
success of an assigned task or mission. (USJFCOM Glossary)
Key Facilities List. A register of selected command installations and industrial facilities of primary
importance to the support of military operations or military production programs. It is prepared under the
policy direction of the Joint Chiefs of Staff. (JP 1-02)
Keystroke Monitoring. The process used to view or record both the keystrokes entered by a computer
user and the computer’s response during an inactive session. (NIST, Glossary of Key Information
Security Terms, May 2013)
Khobar Towers Bombing. A terrorist [truck] bombing of the residence of U.S. military personnel at the
Khobar Towers complex in Dhahran, Saudi Arabia, on 25 June 1996 killed 19 American military
personnel and wounded hundreds more. (Words of Intelligence, 2nd Edition, 2011)
Knowledge. In the context of the cognitive hierarchy, information analyzed to provide meaning and value
or evaluated as to implications for the operation. (FM 6-0, Mission Command, 11 Aug 2003).
Knowledge Management. The process of enabling knowledge flow to enhance shared understanding,
learning, and decisionmaking. (ADRP 6-0, Mission Command, May 2012)
Knowledgeability Brief (KB). A document used to notify consumers of the availability and background of
an overt source for debriefing. (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
203
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
L ==========================================
Laundering. In counterdrug operations, the process of transforming drug money into a more manageable
form while concealing its illicit origin. Foreign bank accounts and dummy corporations are used as
shelters. (JP 1-02 and JP 3-07.4, Joint Counterdrug Operations, 13 Jun 2007)
-- Also, a process of hiding sources, transmittal, and people involved in financial matters and transfers
of money for intelligence and today more commonly for criminal purposes, primarily associated with
terrorist activity and narcotics trafficking. (Words of Intelligence, 2nd Edition, 2011)
Law Enforcement. Activities to protect people, places and things from criminal activity resulting from non-
compliance with laws, includes patrols, emergency responses, undercover operations, arrests, raids, etc.
-- Also, the generic name for the activities of the agencies responsible for maintaining public order
and enforcing the law, particularly the activities of prevention, detection, and investigation of crime and
the apprehension of criminals. (www.ojp.usdoj.gov; accessed 29 Apr 2013)
Counterintelligence is part art, part science, a discipline
aimed at identifying and exploiting or stopping foreign spies.
Law enforcement is easier: You identify the bad guys and arrest them.
-- Bill Gertz, “Enemies,” The Washington Times, 18 Sep 2006
Traditional law enforcement activities aim at apprehending and prosecuting perpetrators of criminal
activity after the commission of their crimes. In most circumstances, the primary responsibility of
law enforcement is to determine whether a crime has been committed, conduct an investigation to
identify and apprehend the perpetrator, and gather evidence to assist prosecutors in a criminal trial.
Law Enforcement is police work waging a war against crime—it’s evidence-prosecution centric.
Whereas counterintelligence is national security work waging a war against foreign intelligence
threats—it’s information-exploitation centric.
Each operates in fundamentally dissimilar manners… different legal authorities, oversight
structures, governing paradigms, cultures, etc. These two disciplines merge or intersect when
hidden intelligence activity is also criminal, i.e., national security crimes (espionage, treason,
spying, etc.).
“Effective enforcement of U.S. espionage statues and Articles 104 and 106 of
the Uniform Code of Military Justice is essential to national security…. Services
have different approaches to counterintelligence due to their unique missions.…
NCIS and AFOSI counterintelligence doctrine holds that counterintelligence
primarily is a law enforcement issue. …under Army counterintelligence doctrine,
counterintelligence is, first and foremost, an intelligence mission….
Considerable intersection exists between law enforcement, counterintelligence,
and intelligence in the areas of espionage, terrorism, and low-intensity conflict….
The law enforcement, counterintelligence, and intelligence collection disciplines
must complement one another.”
-- “Report of the Advisory Board on the Investigative Capability in the Department of Defense - Vol. I,”
Department of Defense, January 1995, pp. 67-75.
Copy available online at: <http://handle.dtic.mil/100.2/ADA299523>
___________________
The goals of law enforcement and intelligence collection conflict…
“Law enforcement agencies collect information solely to put criminals in prison—a onetime,
short-term goal; pay the informant, make a bust, go to trial with the informer as witness.
Espionage is conducted for long-term production of intelligence: recruit the agent, collect the
information, hopefully for years or decades.”
-- Duane R. Clarridge, A Spy For All Seasons: My Life in the CIA (1997), p. 409
204
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Law Enforcement Agency (LEA). Any of a number of agencies (outside the Department of Defense)
chartered and empowered to enforce US laws in the United States, a state or territory (or political
subdivision) of the United States, a federally recognized Native American tribe or Alaskan Native Village,
or within the borders of a host nation. (JP 1-02 and JP 3-28, Defense Support of Civil Authorities, 31 Jul
2013)
Law Enforcement Officer. An employee, the duties of whose position are primarily the prevention,
investigation, apprehension, or detention of individuals suspected or convicted of offenses against the
criminal laws, including an employee engaged in this activity who is transferred to a supervisory or
administrative position; or serving as a probation or pretrial services officer. (Cited as 18 USC at
Law of War. That part of international law that regulates the conduct of armed hostilities. Also called the
law of armed conflict. (JP 1-02 and JP 1-04, Legal Support to Military Operations,17 August 2011)
Lawful Search. An examination, authorized by law, of a specific person, property, or area for specified
property evidence, or a specific person, for the purpose of seizing such property, evidence or person.
(AR 190-30, Military Police Investigation, 1 Nov 2005)
Lead. In intelligence usage, a person with potential for exploitation, warranting additional assessment,
contact, and/or development. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/
chg 1 dated 26 Aug 2011) Also see Counterintelligence Operational Lead (CIOL).
-- Also, an identified potential source. (HDI Lexicon, April 2008 and Defense HUMINT Enterprise
Manual 3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, [for investigative purposes,] single investigative element of a case requiring action. (IC
Standard 2008-700-01, 4 Apr 2008)
-- Also, any source of information that, if exploited, may reveal information of value in the conduct of
a counterintelligence investigation. (AR 381-20, Army CI Program, 25 May 2010)
-- Also, for CI collection purposes, any person who has the potential to provide information of value
to the supported command. (DoD, CI Functional Services IWG Handbook, 19 Feb 2009)
Lead Agency. The US Government agency designed to coordinate the interagency oversight of the day-
to-day conduct of an ongoing operation. (JP 1-02 and JP 3-08 Interorganizational Coordination During
Joint Operations, 24 June 2011)
-- Also, in CI usage concerning an investigation, the agency in a joint investigation that has primary
authority concerning the offense committed or is designated as such by agreement of the investigative
agencies involved. The lead agency is ultimately responsible for determination of investigative
responsibilities, procedures, and methods. Also see joint investigation.
Lead Federal Agency (LFA). The federal agency that leads and coordinates the overall federal response
to an emergency. Designation and responsibilities of a lead federal agency vary according to the type of
emergency and the agency’s statutory authority. (JP 1-02 and JP 3-41, CBRNE Consequence
Management, 2 Oct 2006)
Leaks. See unauthorized disclosure.
National Security Leaks
“I am deeply disturbed by the continuing leaks of classified information to the media…, disclosures
of this type endanger American lives and undermine America’s national security.”
-- Senator Dianne Feinstein, Chairman of the Senate Intelligence Committee, 5 June 2012
205
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Least Intrusive Means. See Rule of Least Intrusive Means. The collection of information about US
persons shall be accomplished by the least intrusive means.
Legal Attaché (LEGAT). The FBI has offices around the globe. These offices—called legal attachés
or legats—are located in U.S. embassies. (fbi.gov)
-- Also, the title of FBI special agents deployed abroad to liaison posts in overseas diplomatic
missions… (Historical Dictionary of Cold War Counterintelligence, 2007)
Legal Residency. An intelligence apparatus in a foreign country composed of intelligence officers
assigned as overt representatives of their government, but not necessarily identified as intelligence
officers. (ICS Glossary)
Legal Traveler. Any individual traveling with legitimate documentation to perform a specific collection
or support mission. (National HUMINT Glossary)
-- Also, any individual traveling with legal documentation to perform specified intelligence collection
or support missions, or any individual who may be selected for debriefing on legal travel to or through
geographical areas of interest. (AR 381-20, Army CI Program, 25 May 2010)
Legend. The complete cover story developed for an operative. (CI Centre Glossary)
-- Also, a coherent and plausible account of an individual’s background, living arrangements,
employment, daily activities, and family given by a foreign intelligence service by an illegal or agent.
Often the legend will be supported by fraudulent documents. (FBI FCI Terms)
-- Also, false identify that an agent builds up through forged documents and other means such as
living under the name of the person whose identify he assumes. (Spy Book)
-- Also, a carefully constructed cover for an intelligence officer. (Spycraft)
-- Also, a spy’s fictional identity and a complete cover story developed for operatives. (Encyclopedia
of Cold War Espionage, Spies, and Secret Operations, 3rd edition, 2012)
Liaison. That contact or intercommunication maintained between elements of military forces or other
agencies to ensure mutual understanding and unity of purpose and action. (JP 1-02 and JP 3-08,
Interorganizational Coordination During Joint Operations, 24 Jun 2011) Also see intelligence liaison.
-- Also, [activity] conducted to obtain information and assistance, to coordinate or procure material,
and to develop views necessary to understand counterparts. Liaison contacts are normally members of
the government, military, law enforcement, or other member of the local or coalition infrastructure. The
basic tenet of liaison is quid pro quo. An exchange of information, services, material, or other assistance
is usually a part of the transaction. (Army FM 2-22.3, HUMINT Collector Operations, 6 Sep 2006)
A basic tenet of liaison is quid pro quo (something for something exchange.
-- FM 2-22.2, Counterintelligence , October 2009, p. 4-8
_______________________
“A crucial but often overlooked part of U.S. intelligence efforts is liaison with foreign intelligence
services…. A productive liaison relationship does not necessarily preclude spying on each other—
but it does mean both sides try to be especially careful not to get caught at it.”
-- James M. Olson, Fair Play: The Moral Dilemmas of Spying (2006)
_______________________
206
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Liaison is not explicitly spelled out in the theoretical approaches [regarding] intelligence. If one
looks to the intelligence cycle paradigm, one will even discover that liaison has no fixed location in
the cycle… it is actually a mode of activity in every point in the intelligence cycle [and] shares this quality
with counter-intelligence.”
-- Dutch Analysts Bob De Graaf and Cees Wiebes in Jeffreys-Jones, External Vigilance (1997)
_______________________
“Answering questions about the costs and benefits of foreign intelligence liaison requires a thorough
understanding of the subject in theory and in U.S. practice. Although sometimes equated with
intelligence sharing, intelligence liaison is actually better understood as a form of subcontracted
intelligence collection based on barter.”
-- Dr. Jennifer E. Sims, “Foreign Intelligence Liaison: Devils, Deals, and Details,” International Journal
of Intelligence and Counterintelligence, Vol 19 No 2 (Summer 2006), p. 196
_______________________
“Liaison has a number of associated risks, one being the problem of false corroboration. It is not
uncommon for several intelligence services to unwittingly use the same agent.”
-- Robert M. Clark, Intelligence Analysis: A Target-Centric Approach (2004), p. 72
Liaison Operations. Operations to coordinate activities and exchange information with foreign military,
governmental, and non-governmental civilian agencies. (DHE-M 3301.002, Vol II Collection Operations,
23 Nov 2011)
According to Army FM 2-22.3 (HUMINT Collector Operations), “liaison operations” are programs
to coordinate activities and exchange information with host country and allied military and civilian
agencies and NGOs. CI liaison activities are designed to ensure a cooperative operating
environment for CI elements and/or to obtain information, gain assistance, develop CI leads for
further exploitation, procure material, etc.
Lie. Any statement made with the intent to deceive. (Textbook of Political-Military Counterdeception:
Basic Principles & Methods, August 2007)
Light Cover [aka shallow cover]. A type of cover that will not withstand close scrutiny or due diligence.
(National HUMINT Glossary)
Line of Operations. 1) A logical line that connects actions on nodes and/or decisive points related in time
and purpose with an objective(s). 2) A physical line that defines the interior or exterior orientation of the
force in relation to the enemy or that connects actions on nodes and/or decisive points related in time and
space to an objective(s). (JP 1-02)
-- Also, a line that defines the directional orientation of a force in time and space in relation to the
enemy and links the force with its base of operations and objectives. (Army FM 3-0, Operations, Feb
2008)
Link. A behavioral, physical, or functional relationship between nodes. (JP 1-02)
Link Analysis. Subset of network analysis, exploring associations between objects.
Listening Post. A secure site at which signals from an audio operation are monitored and/or received.
(Spycraft)
Load. Tradecraft jargon… to put something in a dead drop; to service a dead drop. (Leo D. Carl, The CIA
Insider’s Dictionary, 1996)
207
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Load Signal. A visual signal to indicate the presence of an individual or object at a given location. (HDI
Lexicon, April 2008)
-- Also, …a visual signal displayed in a covert manner to indicate the presence of an individual or
object at a given location. (JP 1-02 and JP 3-50, Personnel Recovery, 5 Jan 2007)
Local Agency Check (LAC). A review of the appropriate criminal history and court records in jurisdictions
over areas where the Subject has resided, attended school, or been employed during a specific period of
time. (IC Standard 700-1, 4 Apr 2008) Also see Military Agency Check; National Agency Check.
-- Also, a records or files check of official or publicly available information retained by any local office
or government agency within the AO [area of operation] of the field element conducting the check. (FM 2-
22.2, Counterintelligence, October 2009)
-- Also, a records or files check of official or publicly available information conducted at any local
office or government agencies within the operational area of the [CI] field element conducting the check.
These records may include holdings and databases maintained by local and state law agencies, local
courts, and local offices of federal agencies. (902d MI Group Investigations Handbook, Jun 2012)
-- Also, an investigative check of local police departments, courts, etc., to determine whether the
subject has been involved in criminal conduct. The LAC is a part of all Personnel Security Investigations
(PSIs) except the Entrance National Agency Check (ENTNAC). (DSS Glossary)
Logic Bomb. A piece of code intentionally inserted into a software system that will set off a malicious
function when specified conditions are met. (NIST, Glossary of Key Information Security Terms, May
2013)
-- Also, computer jargon for programmed instructions clandestinely inserted into software, where they
remain inactive and undetected until the computer reached a certain point in its operations, at which time
the instructions take over. (Leo D. Carl, The CIA Insider’s Dictionary, 1996)
-- Also, [in cyber usage] also known as a “time bomb,” a program that allows a Trojan to lie dormant
and then attack when the conditions are just right. Triggers for logic bombs include a change in a file, a
particular series of keystrokes, or a specific time or date. (McAfee Labs - Threat Glossary)
Lone Wolf. A lone wolf or lone-wolf fighter is someone who commits violent acts in support of some
group, movement, or ideology, but does so alone, outside of any command structure. (Wikipedia;
accessed 28 Jun 2011)
The lone wolf - one of the biggest challenges
Individuals who sympathize with or actively support al-Qa’ida may be inspired to violence and
can pose an ongoing threat, even if they have little or no formal contact with al-Qa’ida.
-- National Strategy for Counterterrorism, June 2011, p. 4
___________________________
Lone wolf terrorism involves terrorist attacks carried out by persons who (a) operate individually,
(b) do not belong to an organized terrorist group on network, and (c) whose modi operandi are
collected are conceived and directed by the individual without any direct outside hierarchy.
-- Flükiger, “The Radical,” pp. 111-119.
___________________________
208
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
“Inspire” magazine -- al Qaeda of the Arabian Peninsula’s English-language magazine -- has a
regular feature called “Open Source Jihad” …that is intended to train… lone wolves and small cells
in the West to conduct attacks and to provide them with the tools necessary to do attacks. [This
magazine seeks to encourage] …jihadists to conduct lone wolf attacks. Lone wolf assailants are
really the most difficult type for government intelligence and security agencies to gather intelligence
about. Really to find a lone wolf assailant, you need to monitor his activities closely and understand
what’s going on inside his head if he doesn’t communicate to other people. Because of this, the
lone wolf really presents a challenge to Western security and intelligence agencies.
-- Stratfor.com (4 April 2010)
___________________________
A Lone Wolf is characterized by the following operational strengths and weaknesses. First, it is
difficult to anticipate who a Lone Wolf is because there is no longer any need for physical contact
with extremists for radicalization to occur. As Raffaello Pantucci puts it in his article on Lone
Wolves: “The increasing prevalence of the Internet and the easy availability of extremist material
online have fostered the growth of the autodidactic extremist.” Second, the Lone Wolf actor is
the most difficult terrorist to detect, deter, or capture, because his planning takes place
almost entirely within his own mind [emphasis added].
-- Thomas F. Ranieri with Spencer Barrs, “Internet and Ideology: The Military Counterintelligence
Challenges of the Net Wolf,” American Intelligence Journal, Vol 29, No 2, 2011, p. 82
Lookout. Stationary position from which a fixed surveillance is conducted and is ostensibly hidden from
view or knowledge of the target of the surveillance. (Words of Intelligence, 2nd Edition, 2011)
Low Visibility Operations. Sensitive operations wherein the political-military restrictions inherent in covert
and clandestine operations are either not necessary or not feasible; actions are taken as required to limit
exposure of those involved and/or their activities. Execution of these operations is undertaken with the
knowledge that the action and/or sponsorship of the operation may preclude plausible denial by the
initiating power. (JP 1-02 and JP 3-05.1, Joint Special Operations Task Force Operations, 26 Apr 2007)
209
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
M =========================================
M3. Acronym for “Multimedia Message Manager” within the DoD Intelligence Information System
(DoDIIS). M3 provides automated text message handling to the military and civilian intelligence
community in a classified environment.
M3 is the standard message handler for the DoDIIS community which provides: real-time
dissemination of incoming message traffic based on user interest profiles; retrospective search of
archive message database; and message composition, co-ordination, release and validation. M3
software automatically filters and delivers personalized information to individuals and groups,
based on their content and delivery preferences. The search software also enables users to search
through more than 20 years' worth of stored messages.
Mail Cover. The process by which a record is made of any data appearing on the outside cover of
any class of mail matter as permitted by law, other than that necessary for the delivery of mail or
administration of the Postal Service. (DoD 5240.1-R, Dec 1982)
-- A record of information on the outside (cover) of any mail piece. It is kept to locate a fugitive,
protect national security, or obtain evidence of a crime punishable by a prison term exceeding 1 year.
This record is one of the few ways information on mail may be disclosed outside the USPS, and its use
is lawful only if authorized by postal regulations. (USPS Pub 32, Glossary of Postal Terms, May 1997)
-- Also, an investigative tool used to record information on the outside container, envelope, or
wrapper of mail, including the name and address of the sender and the place and date of postmarking.
(USPS Publication 146, A Law Enforcement Guide to the U.S. Postal Service, Sep 2008)
Postal Service Regulation 39 CFR § 233.3 is the sole authority and procedure for opening a mail
cover and for processing, using and disclosing information obtained from a mail cover.
See USPS Pub 146, A Law Enforcement Guide to the U.S. Postal Service (Sep 2008)* and USPS
Pub 55, USPS Procedures: Mail Cover Requests, available from the US Postal Service by request
to authorized users.
* USPS Pub 146 also available at: <www.hsdl.org/?view&doc=112575&coll=limited>
Make (aka made). Tradecraft jargon… surveillance term for the surveillant being detected by the subject
of a surveillance. (Leo D. Carl, The CIA Insider’s Dictionary, 1996)
Malicious Code. Software or firmware intended to perform an unauthorized process that will have
adverse impact on the confidentiality, integrity, or availability of an information system. A virus, worm,
Trojan horse, or other code-based entity that infects a host. (NIST, Glossary of Key Information Security
Terms, May 2013) Also see malware, Trojan Horse.
Malicious Cyber Activity. Activities, other than those authorized by or in accordance with U.S. law, that
seek to compromise or impair the confidentiality, integrity, or availability of computers, information or
communications systems, networks, physical or virtual infrastructure controlled by computers or
information systems, or information resident thereon. (PPD-20, US Cyber Operation (U), 16 Oct 2012)
Malware. A program that is inserted into a system, usually covertly, with the intent of compromising the
confidentiality, integrity, or availability of the victim’s data, applications, or operating system or of
otherwise annoying or disrupting the victim. (NIST, Glossary of Key Information Security Terms, May
2013)
210
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a generic term used to describe malicious software such as viruses, Trojan horses, spyware,
and malicious active content. (McAfee.com; accessed 15 Nov 2010)
-- Also, malicious or malevolent software, including viruses, worms, and Trojans, that is
preprogrammed to attack, disrupt, and/or compromise other computers and networks. A packaged
exploitation of vulnerability, there is often a
“payload” of instructions detailing what the system should do
after it has been compromised. (Cybersecurity and Cyberwar)
-- Also, malicious software that secretly accesses a computer system without the owner's informed
consent. A general term to mean a variety of forms of hostile, intrusive, or annoying software or program
code, including computer viruses, worms, trojan horses, spyware, most rootkits, and other malicious
software or program. (Wikipedia)
Malware -- an acronym that stands for MALicious softWARE -- comes in many forms. Generally
speaking, malware is software code or snippets of code designed with malice in mind and usually
performs “undesirable actions” on a host system.
_____________________
According to Kevin Coleman, Defense Systems, “…in 2009, there were 25 million new strains of
malware. That equals a new strain of malware every 0.79 seconds.” Recently he blogged that
“…in the past month [Sep 2012] there were more than 2,166,000 new strains of malware
introduced into our operational environment.”
-- Source:
(accessed 15 Dec 2012)
_____________________
According to an article in the Journal of Homeland and National Security Perspectives, In 2008,
“a service member in the Middle East inserted a flash drive with malware known as
agent.btz into a classified government computer. The worm infected the classified
intranets titled Secret Internet Protocol Router Network (SIPRNET) and Joint Worldwide
Intelligence communication System (JWICS). The worm had been designed to execute
a predetermined search once on the targeted computer system, upon finding the
desired data it would transfer it covertly to the thumb drive, and once reinserted into
a machine connected to the internet the data immediately transferred from the thumb
drive back to the creators of the malware. The foreign intelligence agency that designed
this worm, suspected of being Russian Intelligence, created a highly sophisticated worm
in agent.btz that could think for itself, morphing when threatened and capable of
identifying and using multiple exfiltration paths. Agent.btz is probably not the only
malware that has successfully accessed classified American systems. Foreig
intelligence agencies are constantly working to develop more advanced intrusion
sets, at the same time the U.S. attempts to detect intrusions. It would be irresponsible
to assume that U.S. networks are fully secure, and the U.S., and every other nation,
will have to deal with that reality for the foreseeable future.”
--
Ashley Tanner, “Examining the Need for a Cyber Intelligence Discipline,” Journal of Homeland
and National Security Perspectives 1:1, 2014
Manipulation. The mixing of factual and fictitious or exaggerated evidence (one of the four deception
means for conveying deception information to a target). (CIA, D&D Lexicon, 1 May 2002)
Maritime Domain. All areas and things of, on, under, relating to, adjacent to, or bordering on a sea,
ocean or other navigable waterway, including all maritime-related activities, infrastructure, people, cargo,
and vessels and other conveyances. (NSPD-41/HSPD-13, Maritime Security Policy, 21 Dec 2004)
-- Also, the oceans, seas, bays, estuaries, islands, coastal areas, and the airspace above these,
including the littorals. (JP 3-32, Command and Control for Joint Maritime Operations, 8 Aug 2006)
211
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Marine Corps Intelligence Activity (MCIA). MCIA provides tailored intelligence and services to the Marine
Corps, other services, and the IC based on expeditionary mission profiles in littoral areas. (DoD FCIP
Strategy FY 2013-2017)
For Marine Corps doctrine, tactics, techniques, and procedures on counterintelligence see Marine
Corps Warfighting Publication (MCWP) 2-14, Counterintelligence, 5 Sep 2000.
Maskirovka. Soviet term -- a set of measures to deceive, or mislead, the enemy with
respect to Soviet national security capabilities, actions, and intentions. These measures include
concealment, simulation, diversionary actions and disinformation. The Soviet Union doctrine of
maskirovka calls for the use of camouflage, concealment and deception (CC&D) in defense-related
programs and in the conduct of military operations. (NSSD 108, 12 Oct 1983) Also see deception.
Maskirovka is actually a very broad concept that encompasses many English terms. These
include: camouflage, concealment, deception, imitation, disinformation, secrecy, security, feints,
diversions, and simulation. While terms overlap to a great extent, a complication is that the Russian
term is greater than the sum of these English terms. Thus, those in the West should attempt to
grasp the entire concept rather than its components.
Maskirovka is not a new concept in the USSR. Its roots can be traced to the Russian Imperial
Army. Several Soviet authors trace it back to Dmitry Donskoy's placing a portion of his mounted
forces in an adjacent forest at the Battle of Kulikovo Field in 1380. Seeing a smaller force than
anticipated, the Tatars attacked, only to be suddenly overpowered by the concealed force.
-- Charles Smith,“Soviet Maskirovko,” Airpower Journal, Spring 1988
MCC. See Military Counterintelligence Collection.
McCarthyism. The practice of making accusations of disloyalty, subversion, or treason without proper
regard for evidence. (<http://en.wikipedia.org/wiki/McCarthyism>; accessed 29 Aug 2012)
The term has its origins in the period in the United States known as the Second Red Scare, lasting
roughly from 1950 to 1954 and characterized by heightened fears of communist influence on
American institutions and espionage by Soviet agents. Originally coined to criticize the anti-
communist pursuits of Republican U.S. Senator Joseph McCarthy of Wisconsin, "McCarthyism"
soon took on a broader meaning, describing the excesses of similar efforts. The term is also now
used more generally to describe reckless, unsubstantiated accusations, as well as demagogic
attacks on the character or patriotism of political adversaries.
-- Source: Wikipedia at <http://en.wikipedia.org/wiki/McCarthyism> (accessed 29 Aug 2012)
Meaconing. A system of receiving radio beacon signals and rebroadcasting them on the same frequency
to confuse navigation. The meaconing stations cause inaccurate bearings to be obtained by aircraft or
ground stations. (JP 1-02 and JP 3-13.1, Electronic Warfare, 25 Jan 2007)
Measurement and Signature Intelligence (MASINT). Information produced by quantitative and qualitative
analysis of physical attributes of targets and events in order to characterize, and identify them.
(ICD 1, Intelligence Community Leadership, 1 May 2006)
-- Also, technically derived intelligence data other than imagery and SIGINT. The data results in
intelligence that locates, identifies, or describes distinctive characteristics of targets. It employs a broad
group of disciplines including nuclear, optical, radio frequency, acoustics, seismic, and materials
sciences. (ODNI, U.S. National Intelligence - An Overview 2011)
212
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, information produced by quantitative and qualitative analysis of physical attributes of targets
and events in order to characterize, locate, and identify them. MASINT exploits a variety of
phenomenolgies to support signature development and analysis, to perform technical analysis, and to
detect, characterize, locate, and identify targets and events. MASINT is derived from specialized,
technically-derived measurements of physical phenomenon intrinsic to an object or event and it includes
the use of quantitative signatures to interpret the data. (DoDI 5105.58, MASINT, 22 Apr 2009)
-- Also, information produced by quantitative and qualitative analysis of physical attributes of targets
and events to characterize, locate, and identify targets and events, and derived from specialized,
technically derived measurements of physical phenomenon intrinsic to an object or event. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
-- Also, describes a category of technically derived information that provides distinctive characteristics
of a specific event such as a nuclear explosion, or locates, identifies, and describes distinctive
characteristics of targets through such means as optical, acoustic, or seismic sensors. (WMD Report)
MASINT will become increasingly important in providing unique scientific or highly technical
information contributions to the IC. It can provide specific weapon identifications, chemical
compositions and material content, and a potential adversary’s capability to employ weapons.
-- IC21: HPSCI Staff Study, 6 Apr 1996 (p. 40)
__________________________
MASINT is scientific and technical intelligence information used to locate, identify, or describe
distinctive characteristics of specific targets. It employs a broad group of disciplines including
nuclear, optical, radio frequency, acoustics, seismic, and materials sciences. For example, MASINT
can identify distinctive radar signatures created by specific aircraft systems or the chemical
composition of air and water samples.
The Central MASINT Organization, a component of the Defense Intelligence Agency, is the focus
for all national and Department of Defense MASINT matters.
-- www.intelligence.gov (accessed 13 Aug 2012)
__________________________
An excellent open source book on MASINT see: Robert M. Clark, The Technical Collection of
Intelligence. Washington, DC: CQ Press, 2011.
Measures of Effectiveness (MOE). A criterion used to assess changes in system behavior, capability,
or operational environment that is tied to measuring the attainment of an end state, achievement of an
objective, or creation of an effect. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Media Exploitation. The receipt, cataloging, duplication, screening/prioritizing, gisting, initial evaluation,
translating key pieces of media, uploading data into appropriate data bases, identifying the need for
further detailed exploitation of pieces of media, tracking the requested detailed exploitation efforts, and
disseminating selected media for further use/analysis by the Intelligence Community. (National Media
Exploitation Center CONOPS, Jan 2004)
MI5. British Security Service is responsible for "protecting the UK against threats to national security from
espionage, terrorism and sabotage, from the activities of agents of foreign powers, and from actions
intended to overthrow or undermine parliamentary democracy by political, industrial or violent means."
MI6. British Secret Intelligence Service (SIS) is responsible for foreign intelligence. MI6 collects secret
intelligence and mounts covert operations overseas in support of British Government objectives IAW the
UK’s Intelligence Services Act of 1994. (www.sis.gov.uk/)
213
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
MICE. The commonly used acronym to explain the motivation of traitors. MICE stands for “money,
ideology, coercion, and ego,” a combination of which may prompt an individual to betray his/her country.
(Historical Dictionary of Cold War Counterintelligence, 2007) Also see motivation.
M
oney
I
deology
C
oercion - Blackmail
go
E
L Reagan - 22 Sep 97
Motivations for espionage vary
If you add “revenge” to the list above, then the acronym is “CRIME”
“MALICE” is another acronym for Money, Anger, Lust, Ideology, Compromise, and Ego.
___________________________
Spies, being human, often invent a better-sounding motive if their sole reason for
betraying their country is money.”
-- General Frantisek Moravec, Former head of Czech Military Intelligence
Microdot. Photographic reduction of documents to three by six millimeters. (FBI FCI Terms) See Mikrat.
-- Also, the photographic reduction of writing or other material to facilitate transfer from one location
to another without detection. (Spy Book)
-- Also, an optical reduction of a photographic negative to a size that is illegible without magnification,
usually 1mm or smaller in area. (Spycraft)
Microdots are another method of surreptitious communication between an agent in the field and his
controller. Photographs are reduced down to microscopic size, so that they are practically invisible
to the naked eye. Microdots are generally concealed under stamps, on top of punctuation marks in
typewritten letters, or under the lips of envelopes.
- Peter Wright, Spycatcher (1987), p. 119
Mikrat. Smaller than a microdot. (FBI FCI Terms) See microdot.
-- Also, the product of microphotography, as used in microdots. (Spy Book)
214
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Military Agency Check (MAC). A records or files check conducted at any military agency with the AO
[area of operations] of the field element conducting the check. (FM2.22-2, Counterintelligence, Oct 2009).
Also see local agency check; national agency check.
Military Assistance Advisory Group (MAAG). A joint Service group, normally under the military command
of a commander of a unified command and representing the Secretary of Defense, which primarily
administers the US military assistance planning and programming in the host country. (JP 1-02 and
JP 3-22, Foreign Internal Defense, 12 Jul 2010)
Militarily Critical Technology. See critical technology; militarily critical technologies list; technology.
Militarily Critical Technologies List (MCTL). A technical reference for the development and
implementation of DoD technology security policies on international transfers of defense related goods,
services, and technologies as administered by the Director, Defense Technology Security Administration
(DTSA). (DoDI 3020.46, MCTL, 24 Oct 2008)
-- MCTL website at <http://www.dtic.mil/mctl/>
Military Counterintelligence Collection (MCC). An CI collection activity using recruited or non-recruited
sources to collect information responsive to operational, tactical, and strategic CI requirements, to include
those of the Military Departments. (DoDI S-5240.17, CI Collection Activities, 14 Mar 2014) Also see
collection; counterintelligence collection; counterintelligence collection activities.
Military Deception (MILDEC). Deception that is conducted to deliberately mislead adversary and potential
adversary decision makers and commanders in order to cause the adversary to take specific actions or
inactions that will contribute to the accomplishment of the friendly mission. [This definition is proposed for
inclusion in the next edition of JP 1-02]. (DoDI S-3604.01, Department of Defense Military Deception,
11 Mar 2013) Also see deception, deception in support of OPSEC.
-- Also, actions executed to deliberately mislead adversary military decision makers as to friendly
military capabilities, intentions, and operations, thereby causing the adversary to take specific actions (or
inactions) that will contribute to the accomplishment of the friendly mission. (JP 1-02 and JP 3-13.4,
Military Deception, 13 Jul 2006)
-- Also, those actions executed to deliberately mislead adversary decisionmakers as to friendly
military capabilities, intentions, and operations, thereby causing the adversary to take specific actions
(or inactions) that will contribute to the accomplishment of the friendly mission. (Army FM 3-0, Operations,
with Chg 1, 2011)
In war-time, truth is so precious that she should always be attended by a bodyguard of lies
-- Winston Churchill (November 1943)
as cited in Anthony Cave Brown, Bodyguard of Lies: The Extraordinary True Story Behind D-Day (1975)
MILDEC is conducted to deliberately mislead adversary and potential adversary decision makers
and commanders in order to cause the adversary to take specific actions or inactions that will
contribute to accomplishment of the friendly mission.
MILDEC can mask, protect, reinforce, exaggerate, minimize, distort, or otherwise misrepresent
U.S. technical and operational capabilities, intentions, operations, and associated activities.
___________________
215
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
According to JP 3-13.4, Counterintelligence provides the following for MILDEC planners:
1) Identification and analysis of adversary intelligence systems to determine the best deception
conduits;
2) Establishment and control of deception conduits within the adversary intelligence system,
also known as offensive CI operations;
3) Participation in counterdeception operations;
4) Identification and analysis of the adversary’s intelligence system and its susceptibility to
deception and surprise; and
5) Feedback regarding adversary intelligence system responses to deception operations.
For additional information see Joint Pub 3-13.4, Military Deception, 13 Jul 2006
_____________________
It was Desert Storm that I became convinced of the power of deception in warfare,
it truly is a force multiplier.
-- Tommy Franks (General, USA Ret), American Solider (2004)
Military Department (MILDEP). One of the departments within the Department of Defense created by
the National Security Act of 1947, which are the Department of the Army, the Department of the Navy,
and the Department of the Air Force. (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar
2013)
Military Department Counterintelligence Organization (MDCO). Elements of the Military Departments
authorized to conduct CI investigations, i.e., Army CI, Naval Criminal Investigative Service [NCIS], and
the Air Force Office of Special Investigations [AFOSI]. (DoDD 5240.06, CIAR, 17 May 2011 w/ chg 1 and
DoDI 5240.10, CI in the Combatant Commands and Other DoD Components, 5 Oct 2011 w/ chg 1)
MDCO, formerly known as “CI Lead Agencies,” approved for inclusion in next edition of JP 1-02.
Military Information Support Operations (MISO). Planned operations to convey selected information and
indicators to foreign audiences to influence their emotions, motives, objective reasoning, and ultimately
the behavior of foreign governments, organizations, groups, and individuals. The purpose of
psychological operations is to induce or reinforce foreign attitudes and behavior favorable to the
originator’s objectives. (JP 1-02 and JP 3-13.2, Psychological Operations, 7 Jan 2010)
Previously known as Psychological Operations or PSYOP; this change directed by SECDEF
Memo, subject: Changing the Term Psychological Operations (PSYOP) to Military Information
Support Operations (MISO), dated 3 Dec 2010. Also FY2012 National Defense Authorization Act
(P.L.112-81) Section 1086, re-designates “psychological operations” as “military information
support operations” in Title 10, United States Code, to conform to DoD usage.
Military Intelligence (MI). The collection, analysis, production, and dissemination of information relating to
any foreign military or military-related situation or activity that is significant to military policy-making or the
planning and conduct of military operations and activities. (DoDD 5143.01, USD/I, 23 Nov 2005)
Military intelligence appears in three basic forms: strategic, operational, and tactical.
-- Strategic Intelligence: intelligence that is required for the formulation of strategy, policy, and
military plans and operations at the national and theater levels.
-- Operational Intelligence: intelligence that is required for planning and conducting campaigns
and major operations to accomplish strategic objectives within theaters or operational areas. It
focuses on narrower, but significant theater-oriented military responsibilities.
-- Tactical Intelligence: intelligence that is required for planning and conducting tactical military
operations at the local level. It concerns information about the enemy that is designed to help
locate the enemy and decide which tactics, units, and weapons will most likely contribute to
victory in an assigned area, and when properly applied, it can be a significant force multiplier.
216
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Military Intelligence Board (MIB). A decision-making forum which formulates Department of Defense
intelligence policy and programming priorities. (JP 1-02 and JP 2-0, Joint Intelligence, 22 Oct 2013)
Military Intelligence Program (MIP). The MIP consists of programs, projects, or activities that support
the Secretary of Defense’s intelligence, counterintelligence, and related intelligence responsibilities.
This includes those intelligence and counterintelligence programs, projects, or activities that provide
capabilities to meet warfighters’ operational and tactical requirements more effectively. The term excludes
capabilities associated with a weapons system whose primary mission is not intelligence. The term “MIP”
replaces the terms “Joint Military Intelligence Program (JMIP)” and “Tactical Intelligence and Related
Activities (TIARA).” (DoDD 5205.12, MIP, 14 Nov 2008)
The Joint Military Intelligence Program (JMIP) and the Tactical Intelligence and Related Activities
(TIARA) were combined in 2005 to form the MIP.
“The MIP was established to improve management of Defense Intelligence capabilities and
resources. USD/I is the Program Executive for the MIP.”
-- USD/I Memo, subj: Establishment of the MIP, 1 Sep 2005
Military Service. A branch of the Armed Forces of the United States, established by act of Congress,
in which persons are appointed, enlisted, or inducted for military service, and which operates and is
administered within a military or executive department. The Military Services are: the United States Army,
the United States Navy, the United States Air Force, the United States Marine Corps, and the United
States Coast Guard. (JP 1-02)
Military Source Operations. The collection, from, by and/or via humans, of foreign, military and military-
related intelligence. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1
dated 26 Aug 2011)
-- Also, DoD HUMINT collection and operations focused on foreign military and military-related
intelligence conducted under the authorities of the Secretary of Defense. Military source operations are
conducted by appropriately trained and certified personnel under the control of a Defense HUMINT
Executor. (DoDD S-3325.09, Oversight, Management, and Execution of Defense Clandestine Source
Operations, 9 Jan 2013, with chg 1 dated 13 Jun 2013)
-- Also, the collection from, by, and/or via humans, of foreign military and military-related intelligence
conducted under SecDef authorities to satisfy DoD needs. (HDI Lexicon, April 2008)
-- Also, DoD HUMINT activity or operation which is conducted to specifically respond to, and satisfy,
DoD intelligence collection requirements. These operations directly support the execution of the
Secretary’s responsibilities, commanders in the field, military operational planners, and the specialized
requirements of the military departments (e.g., research and development process, the acquisition of
military equipment, and training and doctrine) and span the entire HUMINT operational continuum,
utilizing varying degrees of tradecraft to ensure the safety and security of the operation. (Defense
HUMINT Enterprise Manual 3301.002, Vol II Collection Operations, 23 Nov 2010)
Military Source Operations are conducted by trained personnel under the control of Defense
HUMINT Executors. See DoDD S-5200.37, Management and Execution of Defense HUMINT (U),
9 Feb 2009 for specifics.
Misdirection. A classic conjurer’s trick, misdirection is the term applied in the counterintelligence
community for the tactic of supplying an ostensibly plausible explanation for an event actually caused by
something quite different, probably by an individual or an operation, deemed sufficiently valuable to
require protection. Invariably a human asset may produce some information which requires action that
could compromise him or her, so misdirection is intended to divert attention elsewhere. (Historical
Dictionary of Cold War Counterintelligence, 2007)
217
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Misperception. The formation of an incomplete or inaccurate image or perception of some aspect of
reality. The faulty image may be formed due to a lack of information or intentionally erroneous information
provided to the perceiver. (CIA, D&D Lexicon, 1 May 2002)
Mission. 1) The task, together with the purpose, that clearly indicates the action to be taken and the
reason therefore; 2) in common usage, especially when applied to lower military units, a duty assigned to
an individual or unit; a task. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Mission Assurance. A process to protect or ensure the continued function and resilience of capabilities
and assets—including personnel, equipment, facilities, networks, information and information systems,
infrastructure, and supply chains—critical to the execution of DoD mission-essential functions in any
operating environment or condition. (DoDD 3020.40, DoD Policy and Responsibilities for Critical
Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, the process or state of ensuring the survival of an organization’s essential missions and
operating capability when confronted by natural or man-made emergencies and disasters. (DoD Strategy
for Operating in Cyberspace, May 2011)
Mission Critical Functions. Any function, the compromise of which would degrade the system
effectiveness in achieving the core mission for which it was designed. (DoDI 5200.44, Protection of
Mission Critical Functions to Achieve Trusted Systems and Networks, 5 Nov 2012)
Mission Manager. A position with the [Intelligence] Community for an individual, operating with the
Director’s [DNI] authorities, who coordinates all intelligence activities against a specific country or topic
[e.g., counterterrorism counterproliferation, counterintelligence]. (HPSCI Report 27 Jul 2006)
-- Also, Mission Managers are the principal Intelligence Community officials overseeing all aspects
of national intelligence related to their respective mission areas. Mission Managers are designated for
counterintelligence, counterterrorism, Counterproliferation, Iran, North Korea, and Cuba & Venezuela.
(ICD 900, Mission Management, 21 Dec 2006)
The NCIX serves as the Mission Manger for Counterintelligence.
The Director NCTC serves as the Mission Manager for Counterterrorism.
Mission Need. A requirement for access to specific information to perform or assist in a lawful and
authorized governmental function. Mission needs are determined by the mission and functions of an IC
element or the roles and responsibilities of particular IC personnel in the course of their official duties.
(ICD 501, 21 Jan 2009)
Mission Statement. A short sentence or paragraph that describes the organization’s essential task(s),
purpose, and action containing the elements of who, what, when, where, and why. (JP 1-02 and JP 5-0,
Joint Operation Planning, 11 Aug 2011) Also see mission.
Mission Tasking Authority (MTA). See Counterintelligence Mission Tasking Authority.
Mitigation. Actions taken in response to a warning or after an incident occurs that are intended to lessen
the potentially adverse effects on a given military operation or infrastructure. (DoDD 3020.40, DoD Policy
and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
-- Also, ongoing and sustained action to reduce the probability of or lessen the impact of an adverse
incident. Includes solutions that contain or resolve risks through analysis of threat activity and vulnerability
data, which provide timely and accurate responses to prevent attacks, reduce vulnerabilities, and fix
systems. (DSS Glossary)
-- Also, capabilities necessary to reduce loss of life and property by lessening the impact of disasters.
( PPD-8, 2011)
218
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Modus Operandi (MO). A distinct pattern or method of procedure thought to be characteristic of or
habitually followed by an individual or an organization involved in criminal or intelligence activity.
(AR 381-20, Army CI Program, 25 May 2010)
Modus Operandi--a Latin phrase--approximately translated as "method of operating." The term is
used to describe someone's habits or manner of working, their method of operating or functioning.
In English, it is frequently shortened to M.O.
Mole. A member of an organization who is spying and reporting on his/her own organization on behalf
of a foreign country; also called a penetration. (National HUMINT Glossary) Also see mole hunt;
penetration.
-- Also, a human penetration into an intelligence service or other highly sensitive organization. Quite
often a mole is a defector who agrees to work in place. (CI Centre Glossary)
-- Also, literary and media term for penetration agent infiltrated into an opposition government agency.
(Leo D. Carl, The CIA Insider’s Dictionary, 1996)
-- Also, the opposing faction’s insert, or penetration, into an intelligence apparatus. (TOP SECRET:
The Dictionary of Espionage and Intelligence, 2005)
In 1622, Sir Francis Bacon used the term "mole" in the History of the Reign of King Henry VII:
He was careful and liberal to obtain good Intelligence from all parts abroad…. As
for his secret spials, which he did employ both at home and abroad, by them to
discover what practices and conspiracies were against him, surely his care required
it; he had such moles [emphasis added] perpetually working and casting to undermine
him. (p. 216)
In modern times, the term was popularized by John le Carré (penname for David Cornwell, a
British author of espionage novels) who used the term “mole” to mean a “penetration” of a
adversary intelligence service. In le Carré’s 1974 novel, Tinker, Tailor, Soldier, Spy, Smiley is
recalled to hunt down a Soviet “mole” in the Circus (British Secret Intelligence Service, aka MI6).
Also a title of a book by William Hood, Mole: The True Story of the First Russian Spy to Become
an American Counterspy about Pyotr Semyonovich Popov, a Major in Soviet Military Intelligence
Hood’s book, Mole, is one of the best publicly available descriptions of a penetration of an
intelligence service and provides a detailed and highly personal account of how intelligence
tradecraft is practiced, the mental and psychological toll this takes, and the risks involved (for
both agent and case officer).
Mole Hunt. The term popularized by John le Carré for a counterintelligence investigation conducted into
hostile penetration. (Historical Dictionary of Cold War Counterintelligence, 2007) Also see mole.
-- Also, the search for moles in one’s own service. (Encyclopedia of Cold War Espionage, Spies, and
Secret Operations, 3rd edition, 2012)
Also the title of a book by David Wise, Molehunt: The Secret Search for Traitors That Shattered
the CIA (1992).
Money Laundering. Generally refers to financial transactions in which criminals, including terrorist
organizations, attempt to disguise the proceeds, sources or nature of their illicit activities. (US Department
of Treasury)
219
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Moscow Rules. The ultimate tradecraft methods for use in the most hostile of the operational
environments. During the Cold War, Moscow was considered the most difficult of operating
environments. (Spy Dust)
Once, an accident. Twice, a coincidence. Three times, an enemy action.
-- Ian Fleming, Goldfinger (1959)
Auric Goldfinger mentions this rule to James Bond in Goldfinger's warehouse in Geneva.
“Moscow rules” …the precepts we all understand for conducting our operations in the most difficult
of operating environments: the Soviet capital. …They were dead simple, and all full of common
sense:
-- Never make surveillance mad or embarrassed—they will shut you down.
-- Never look over your shoulder or steal free looks in store windows when on the street.
-- Make them think it was their fault that they had lost you, not vice versa, because KGB
officers knew better than to report their own mistakes.
… a mantra that could guide them in determining whether they were the subject of hostile
surveillance: Once, an accident. Twice, a coincidence. Three times, an enemy action.
-- Antonio and Jonna Mendez, Spy Dust: Two Masters of Disguise Reveal the Tools and
Operations that Helped Win the Cold War (2002), p. 36
Motivation. The complex of reasoning and emotional or other drives that induces a person to accept
employment or cooperate with an agency for a particular assignment. (AFOSI Instruction 71-101,
6 Jun 2000) Also see “MICE.”
-- Also, broadly defined, is a feeling or state of mind that influences one’s choices and actions.
(PERSEREC Technical Report 05-10, May 2005)
-- Also, tradecraft jargon for bases for agent recruitment that are usually (1) ideological; (2) financial;
(3) coercion or blackmail; (4) sexual; (5) ego satisfaction; (6) familial; (7) love of adventure or excitement;
(8) a combination of two or more of the preceding. (Leo D. Carl, The CIA Insider’s Dictionary, 1996)
Motivation for espionage results from a complex interaction
between personality characteristics and situational factors
-- PERSEREC Technical Report 05-10, May 2005 (p.1)
____________________________
Psychological portraits of the major spies show complex motivations, which often include
dissatisfaction with the job. …The profile of a traitor may not be significantly different from that of
many sociopaths or felons. …Spies also usually have two other characteristics: They relish the
secret world of intrigue and they enjoy the chance to show others as fools. …The typical spy enjoys
deception and may have a personality bordering on, or well into, the psychotic.
-- Thomas B. Allen and Norman Polmar, Merchants of Treason: America’s Secrets for Sale (1988), pp.51-52
Espionage Motivations
Motives by which spies are driven are highly individualized—simple motives often conceal deeper
and more complicated motivations. Motivation for espionage is often elusive and frequently
involves multiple reasons. According to a 2008 PERSEREC study, assigning the motivation for
committing espionage is often most accurate when motivation is inferred from evidence available
while the crime was being committed, rather than from the self justifications after the fact. Like most
criminals, once caught, spies see their own past intentions and the pressures that may have
affected their behavior in a changed light. Motives for espionage can also change over the course
of espionage activities.
MONEY: Historically a leading motivation -- the primacy of money as a motive is a common
observation in studies of espionage. Money (financial gain) also appears frequently in combination
with other motives. Americans most consistently have cited money as the dominant motive for
espionage, especially in the 1980s—the decade of the spy. This motivation reflects a person’s
need for money (e.g., indebtedness, financial pressures), or simple greed, or some combination
thereof. Often seen in people who see themselves as underpaid (whether real or perceived). Many
220
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
cases involved indebtedness. Being in debt or having a history of insolvency, bankruptcy, or late
payments is a major component of the financial considerations scrutinized in a personnel security
investigation for a security clearance. Among the typical financial motives of debt or greed, debt
continues to motivate espionage more than just greed. Although no recent cases, several past
spies were frequent gamblers. Money remains one of multiple motives in many recent cases.
“Spies, being human, often invent a better-sounding motive if their sole reason
for betraying their country is money.”
-- General Frantisel Moravec, Former Head of Czech Military Intelligence
IDEOLOGY/DIVIDED LOYALTIES: This motivation encompasses both ideological driven motives
(commitment to a competing political or economic system, e.g. Communism or Jihadism) and/or
those with competing allegiances (i.e., intellectual or emotional commitments to another country
through birth, family ties or cultural affinity). Ideology was the dominant motive in the 1940s,
whereas divided loyalties has increased over time of all motives for espionage. Divided loyalties—
holding and acting on an allegiance to a foreign country or cause in addition to or in preference to
allegiance to the United States—has dramatically increased since 1990. PERSEREC studies
indicate that spying prompted by divided loyalties has become the most common motive for
American espionage, replacing spying for money as the primary motive. Additionally this trend has
been accelerating since 2000.
COMPROMISE/COERCION: Being forced to commit espionage through blackmail or threat to
relatives in a foreign country. Used to recruit spies most often in the early period before 1980, when
foreign intelligence services engaged in occasional blackmail using relatives overseas, or
entrapped Americans in sexual blackmail scams. Has not been seen in recent cases.
EGO/THRILLS: Some spies commit espionage for thrills or to make themselves feel important—
ego-boosting. Some have a fascination with spying and find espionage a thrilling enterprise that
allows them to enact fantasies of secret lives and heroic deeds they have read about in popular spy
novels. Includes the related ego-boost of getting away with it, as well as the thrill of successfully
maintaining a secret life parallel to the spy’s professional career, and thereby cleverly
demonstrating that his competence surpasses his colleagues. Although rarely the primary motive,
there have been several cases involving individuals who spied for the thrill of getting away with
espionage, or from their need to stroke their egos.
DISGRUNTLEMENT/REVENGE: In recent cases, disgruntlement was the second most common
cause. This motive takes many different forms: disenhancement, extreme unhappiness with
people and employment, disaffection, bitterness, frustration, anger, disillusionment, and alienation.
Usually directly related to employment/work-related issues caused by the person’s relationships or
treatment in the workplace, and associated desire to take revenge. Disappointment, anger,
frustration, or alienation can arise from interactions among coworkers or between employees and
supervisors. Feelings of disgruntlement often lead to efforts to get revenge and espionage is one
way to get bak at the offending individual, organization, or at the whole government they represent.
A common motivation among those who volunteer.
INGRATIATION: The desire to help or please someone else motive some to commit espionage.
Most often through an emotional, personal relationship or attachment. This motivation can also
manifest when trying to impress a potential future employer. Most spies who committed espionage
to please others tended to be successful.
RECOGITION: Usually a secondary motive of spies seeking recognition, approval and/or attention
from those to whom they provided information. Individuals often feel overworked and
underappreciated and espionage allows them to connect or bond with an agent handler and seek
the approval and attention of the handler.
___________________________
For more information, see following Defense Personnel Security Research Center (PERSEREC) Reports:
-- Americans Who Spied Against Their Country Since World War II, Rpt PERS-TR-92-005, May 1992
-- Espionage Against the United States by American Citizens 1947-2001, Rpt 02-5, Jul 2002
-- Changes in Espionage by Americans: 1947-2007, Tech Rpt 08-05, Mar 2008
-- Espionage and Other Compromises of National Security: Case Summaries from 1975 to 2008, 2 Nov 2009
221
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
MTAC. See Multiple Threat Alert Center.
Multiple Threat Alert Center (MTAC). Department of Navy’s fusion, analysis and dissemination center
for terrorist, criminal, counterintelligence and security information; operated by the Naval Criminal
Investigative Service (NCIS).
The terrorist attack on the World Trade Center in New York and the Pentagon in Washington, DC
on September 11, 2001 led NCIS to transform the Antiterrorist Alert Center (ATAC) into the MTAC
in 2002.
Multilateral Collection. A collection activity conducted with two or more cooperating foreign intelligence
services against a mutually targeted foreign intelligence, security service, or international terrorist entity.
(Previously in DoDI S-5240.17, CI Collection, 12 Jan 2009) Also see bilateral.
Multilateral: activities conducted with more than one nation.
Multilateral OFCO. An OFCO [Offensive Counterintelligence Operation] conducted by a U.S. CI agency
with two or more cooperating foreign intelligence services against a mutually targeted FISS, foreign entity,
or terrorist element. (DoDI S-5240.09, 29 Oct 2008)
Multilevel Security (MLS). Concept of processing information with different classifications and categories
that simultaneously permits access by users with different security clearances and denies access to users
who lack authorization. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Multinational. Between two or more forces or agencies of two or more nations or coalition partners.
Also see also alliance; coalition. (JP 1-02)
Multinational Force (MNF). A force composed of military elements of nations who have formed an
alliance or coalition for some specific purpose. (JP 1-02) Also see multinational operations.
Multinational Operations. A collective term to describe military actions conducted by forces of two or
more nations, usually undertaken within the structure of a coalition or alliance. (JP 1-02 and JP 3-16,
Multinational Operations, 7 Mar 2007) Also see alliance; coalition; coalition action.
Multispectral Imagery (MSI). The image of an object obtained simultaneously in a number of discrete
spectral bands.(JP 1-02 and JP 3-14, Space Operations, 6 Jan 2009)
222
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
N ==========================================
Narcoterrorism. Terrorism that is linked to illicit drug trafficking. (JP 1-02 and JP 3-07.4, Joint
Counterdrug Operations, 13 Jun 2007)
Name Trace. A search of available recorded data to find information about a person, normally conducted
to determine the presence or absence of derogatory information about the person, as a first step in
judging his suitability or intelligence value. (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, a search of data for information about an individual, organization, or subject. (National
HUMINT Glossary)
National Agency Check (NAC). An in-depth name trace consisting of Federal Bureau of Investigation
Name and Criminal History Fingerprint Checks, Defense Clearance Investigation Index (DCII) search,
and can include checks on military personnel records, citizenship, selective service, Central Intelligence
Agency records, State Department records, and other US Government agencies. Also see local agency
check; military agency check.
-- Also, [part of a] personnel security investigation consisting of a review of: investigative and criminal
history files of the Federal Bureau of Investigation, including a technical fingerprint check; Office of
Personnel Management Security/Suitability Investigations Index; DoD Central Index of Investigations
(DCII) and Joint Personnel Adjudication System (JPAS); and such other national agencies (e.g., CIA,
DNI) as appropriate to the individual’s background. (IC Standard 700-1, 4 Apr 2008)
-- Also, formal request to federal agencies for searches of their records and supporting databases
and files for information of investigative [/CI] interest. (FM 2-22.2, Counterintelligence, Oct 2009 and 902d
MI Group Investigations Handbook, Jun 2012)
-- Also, an integral part of all background investigations, the NAC consists of searches of OPM‘s
Security/Suitability Investigations Index (SII); the Defense Clearance and Investigations Index (DCII); the
FBI Identification Division's name and fingerprint files, and other files or indices when necessary. (Army -
see below)
National Agency Check and Inquiries (NACI) - This is the basic and minimum investigation required
on all new Federal employees. It consists of a NAC with written inquiries and searches of records
covering specific areas of a person's background during the past five years. Those inquiries are
sent to current and past employers, schools attended, references, and local law enforcement
authorities.
Access NACI (ANACI) - This is a new investigation designed as the required initial investigation for
Federal employees who will need access to classified national security information at the
Confidential or Secret level. The ANACI includes NACI and Credit coverage with additional local
law enforcement agency checks.
NAC with Local Agency Check and Credit (NACLC) - This is a new investigation which is the same
as the ANACI without the written inquiries to past employers, schools attended, etc. It is designed
as the initial investigation for contractors at the Confidential and Secret national security access
levels. The NACLC also is to be used to meet the reinvestigation requirement for all individuals
(including contractors) who have Confidential or Secret clearances.
-- US Army at: <http://www.dami.army.pentagon.mil/site/PerSec/InvTypes.aspx> (accesses 24 Sep 2013)
National Capital Region (NCR). A geographic area encompassing the District of Columbia and eleven
local jurisdictions in the State of Maryland and the Commonwealth of Virginia. (JP 1-02 and JP 3-28,
Defense Support of Civil Authorities, 31 Jul 2013)
223
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Center for Credibility Assessment (NCCA). A federally funded institution providing graduate
and continuing education courses in psychophysiological detection of deception (PDD).
-- Also, an interagency training institute that provides polygraph education and training, conducts
credibility assessment research and development, and manages the Polygraph Quality Assurance
Program. (DoD FCIP Strategy FY 2013-2017)
For DoD policy see DoDD 5210.48, Polygraph and Credibility Assessment Program. NCCA is under
the operational control of the Defense Counterintelligence and Human Intelligence Center (DCHC),
DIA. It was previous known as the Defense Academy for Credibility Assessment (DACA) and before
that as the DoD Polygraph Institute (DoDPI).
National Clandestine Service (NCS). The NCS operates as the clandestine arm of the CIA, and serves
as the national authority for the coordination, deconfliction, and evaluation of clandestine human
intelligence operations across the Intelligence Community. The NCS supports our country's security and
foreign policy interests by conducting clandestine activities to collect information that is not obtainable
through other means. The NCS also conducts counterintelligence and special activities as authorized by
-- Also, the NCS serves as the national authority for the integration, coordination, deconfliction, and
evaluation of human intelligence operations across the entire Intelligence Community, under authorities
delegated to the Director of the CIA who serves as the National HUMINT Manager. The Director of the
NCS reports directly to the Director of the CIA and will work with the Office of the Director of National
Intelligence to implement all of the DNI's statutory authorities. (ODNI News release 3-05, 13 Oct 2005)
Also see Defense Clandestine Service.
Formerly known as CIA Directorate of Operations or DO (in 2005, the DO transitioned to the NCS).
The NCS was established in response to recommendations made in March 2005 by the
President's Commission on the Intelligence Capabilities of the United States Regarding Weapons
of Mass Destruction.
_______________________
Collecting foreign intelligence — finding someone who has protected information and convincing
that person to share it — is the “bread and butter” of what the clandestine service does, although
“if we succeed, we’d rather not talk about it.”
-- Thomas Twetten, Former Chief of CIA Clandestine Operations, 27 Jan 2011
________________________
Clandestine Service…
A clandestine service does much more than simply collect "HUMINT" clandestinely, that is secretly
exploit agents for the purpose of collecting intelligence. A clandestine service also works in liaison
with other spy services to run all types of operations; it taps telephones and installs listening
devices; it breaks into or otherwise gains access to the contents of secured facilities, safes, and
computers; it steals, compromises, and influences foreign cryptographic capabilities so as to make
them exploitable by US SIGINT; it protects its operations and defends the government from other
intelligence services by engaging in a variety of counterespionage activities, including the
aggressive use of double agents and penetrations of foreign services; and it clandestinely
emplaces and services secret SIGINT and MASINT sensors. It also has the capability of using its
techniques and access to run programs at the President's direction to influence foreign
governments and developments, that is, "covert action." The unifying aspect of these activities is
not some connection to HUMINT; rather, they are highly diverse but interdependent activities that
are best conducted by a clandestine service.
-- IC 21: Intelligence Community in the 21st Century, Chap. IX - Clandestine Service; available on line at:
224
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Counterintelligence Executive (NCIX). Performs duties provided in the CI Enhancement Act of
2002 and such other duties as may be prescribed by the Director of National Intelligence or specified by
law. NCIX serves as Mission Manager of Counterintelligence and the Chairperson of the National CI
Policy Board. Resides within the Office of the Director of National Intelligence (ODNI). (CI Enhancement
Act of 2002) Also see Office of the National Counterintelligence Executive.
-- Also, the NCIX serves as the head of national counterintelligence for the U.S. Government, per the
CI Enhancement Act of 2002. (National Intelligence: A Consumer’s Guide - 2009)
Additional information on NCIX at <http://www.ncix.gov/about/index.html>
National Counterintelligence Policy Board (NACIPB). Special board established by statue within the
executive branch of Government; reports to the President through the National Security Council. The
Board serves as the principal mechanism for developing policies and procedures for the approval of the
President to govern the conduct of counterintelligence activities; and upon the direction of the President,
resolving conflicts that arise between elements of the Government conducting such activities. The Board
also acts as an interagency working group to ensure the discussion and review of matters relating to the
implementation of the Counterintelligence Enhancement Act of 2002 and provides advice to the National
Counterintelligence Executive on priorities in the implementation of the National Counterintelligence
Strategy. (Extracted from 50 U.S.C. §402a)
NACIPB is chaired by the National Counterintelligence Executive and consists of senior USG
personnel appointed by the head of the department or element concerned, as follows: Department
of Justice, including the Federal Bureau of Investigation (FBI); Department of Defense, including
the Joint Chiefs of Staff; Central Intelligence Agency (CIA); Department of State; Department of
Energy; and any other department, agency, or element of the US Government specified by the
President.
National Counterproliferation Center (NCPC). Coordinates strategic planning within the Intelligence
Community (IC) to enhance intelligence support to United States efforts to stem the proliferation of
weapons of mass destruction and related delivery systems. It works with the IC to identify critical
intelligence gaps or shortfalls in collection, analysis or exploitation, and develop solutions to ameliorate or
close these gaps. It also works with the IC to identify long-term proliferation threats and requirements and
develop strategies to ensure the IC is positioned to address these threats and issues. NCPC will reach
out to elements both inside the IC and outside the IC and the U.S. Government to identify new methods
or technologies that can enhance the capabilities of the IC to detect and defeat future proliferation threats.
(ODNI News release 9-05, 21 Dec 2005)
-- Also, the NCPC, which resides in the ODNI, is the bridge from the IC to the policy community for
activities within the U.S. Government associated with countering the proliferation of weapons of mass
destruction (WMD). (National Intelligence: A Consumer’s Guide - 2009)
National Counterterrorism Center (NCTC). The primary center for US government analysis of terrorism.
It falls under the Office of the Director of National Intelligence (ODNI). One of its primary missions is "to
serve as the central and shared knowledge bank on known and suspected terrorists and international
terrorist groups, as well as their goals, strategies, capabilities, and networks of contacts and support."
(EO 13354, National Counterterrorism Center, 27 Aug 2004)
In August 2004, the President established the NCTC to serve as the primary USG organization for
integrating and analyzing all intelligence pertaining to terrorism and counterterrorism and to
conduct strategic operational planning by integrating all instruments of national power. In
December 2004, Congress codified the NCTC in the Intelligence Reform and Terrorism Prevention
Act (IRTPA) and placed the NCTC in the Office of the Director of National Intelligence (ODNI).
NCTC is a multi-agency organization dedicated to eliminating the terrorist threat to US interests at
home and abroad.
____________________
225
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
NCTC was established in 2004 to ensure that information from any source about potential terrorist
acts against the U.S. could be made available to analysts and that appropriate responses could be
planned. Investigations of the 9/11 attacks had demonstrated that information possessed by
different agencies had not been shared and thus that disparate indications of the looming threat
had not been connected and warning had not been provided.
NCTC prepares studies ranging from strategic assessments of potential terrorist threats to daily
briefings and situation reports. It is also responsible, directly to the President, for planning (but not
directing) counterterrorism efforts. The NCTC received a statutory charter in the Intelligence
Reform and Terrorism Prevention Act of 2004 (P.L. 108-458); it currently operates with a staff of
more than 500 personnel from its headquarters in northern Virginia.
-- Congressional Research Service (CRS) Report R41022, 19 Dec 2011
National Crime Information Center (NCIC). A computerized system of crime records and data,
maintained by the Federal Bureau of Investigation, that can be tapped into by virtually every criminal
justice agency nationwide. (Cyber Threats to National Security, Symposium Five, 2011)
National Critical Infrastructure and Key Assets (NCI & KA). Within DoD: None - term removed from
JP 1-02.
Previously defined in JP 3-28, Civil Support (14 Sep 2007) as: The infrastructure and assets vital
to a nation’s security, governance, public health and safety, economy, and public confidence. They
include telecommunications, electrical power systems, gas and oil distribution and storage, water
supply systems, banking and finance, transportation, emergency services, industrial assets,
information systems, and continuity of government operations.
National Critical Systems and Technology Joint Task Force (NCST-JTF). A collaborative forum to lead
USIC and federal agency counterintelligence efforts for the protection of critical technologies.
(NCST-JTF tri-fold, undated, circa 2012)
NCST-JTF Mission
Leverage the collective CI resources of the Task Force member agencies to prevent, preempt,
deter, and investigate attempts to acquire, proliferate and transfer critical US technologies to
foreign powers.
Apprehend and prosecute individuals who may commit or plan such acts negatively affecting U.S.
National Security interest.
National Cyber Investigate Joint Task Force (NCIJTF). The focal point for all government agencies to
coordinate, integrate, and share information related to all domestic cyber threat investigations. The FBI
is responsible for developing and supporting the joint task force, which includes 19 intelligence agencies
and law enforcement, working side by side to identify key players and schemes. Its goal is to predict and
prevent what’s on the horizon and to pursue the enterprises behind cyber attacks. (www.fbi.gov;
accessed 18 Jun 2013)
On 8 January 2008, the President signed Presidential Directive NSPD-54/HSPD-23 which
mandated the National Cyber Investigative Joint Task Force to be the focal point for all government
agencies and to coordinate, integrate, and share information related to all domestic cyber threat
investigations.
NCIJTF Mission: Ensure the U.S. Government is coordinating all its efforts to address national
security cyber intrusions, including intelligence operations and investigations. The NCITF’s
functions are structured in three groups: the Information Operations Group, the Analysis Group,
and the Law Enforcement Group.
For more information on the NCIJTF see <http://www.fbi.gov/about-us/investigate/cyber/ncijtf>
_______________________
226
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Cyber Investigative Joint Task Force - Analytical Group (NCIJTF-AG)
The Defense Cyber Crime Center (DC3) resources and manages the Analytic Group of the
NCIJTF, which operates under overall FBI stewardship, joined by other national LE/CI
organizations. Focused on nation-state threat actors, AG leads a collaborative analytical and
technical exchange with subject matter experts from LE/CI, CND, IC, and IA agencies to build a
threat picture to enable proactive LE/CI cyber operations.
National Defense Strategy (NDS). A document approved by the Secretary of Defense for applying the
Armed Forces of the United States in coordination with Department of Defense agencies and other
instruments of national power to achieve national security strategy objectives. (JP 1, Doctrine for the
Armed Forces of the United States, 25 Mar 2013)
National Detainee Reporting Center (NDRC). National-level center that obtains and stores information
concerning enemy prisoners of war, civilian internees, and retained personnel and their confiscated
personal property. May be established upon the outbreak of an armed conflict or when persons are
captured or detained by U.S. military forces in the course of the full range of military operations. Accounts
for all persons who pass through the care, custody, and control of the U.S. Department of Defense.
(JP 1-02 and JP 3-63, Detainee Operations, 30 May 2008)
National Disclosure Policy (NDP-1). A document that promulgates national policy and procedures in the
form of specific disclosure criteria and limitations, definition of terms, release arrangements, and other
guidance required by U.S. departments and agencies having occasion to disclose classified information
to foreign governments and international organizations. NDP-1 establishes and provides for management
of interagency mechanisms and procedures required for effective implementation of the national policy.
National Disclosure Policy Committee. Central authority for formulation, promulgation, administration,
and monitoring of the NDP-1.
National Emergency. A condition declared by the President or the Congress by virtue of powers
previously vested in them that authorize certain emergency actions to be undertaken in the national
interest. (JP 1-02 and JP 3-28, Defense Support of Civil Authorities, 31 Jul 2013)
National Essential Functions. That subset of Government functions that are necessary to lead and
sustain the Nation during a catastrophic emergency. (PDD-21, 12 Feb 2013)
National Foreign Intelligence Program. All programs, projects, and activities of the intelligence
community, as well as any other programs of the intelligence community designated jointly by the Director
of Central Intelligence and the head of a United States department or agency or by the President. Such
term does not include programs, projects, or activities of the military departments to acquire intelligence
solely for the planning and conduct of tactical military operations by US Armed Forces. (50 USC §401a)
National Geospatial-Intelligence Agency (NGA). A member of the US Intelligence Community, as well as
a Combat Support Agency of the Department of Defense, that provides timely, relevant and accurate
geospatial intelligence in support of national security objectives.
The term “geospatial intelligence” or “GEOINT” means the exploitation and analysis of imagery and
geospatial information to describe, assess and visually depict physical features and geographically
referenced activities on the Earth. Geospatial intelligence consists of imagery, imagery intelligence
and geospatial (e.g., mapping, charting and geodesy) information.
-- See NGA website at <https://www1.nga.mil/>
________________________
The National Imagery and Mapping Agency (NIMA) transitioned to the National Geospatial-
Intelligence Agency (NGA) in 2003. NIMA established its internal CI element on 1 April 2002.
See the official history of the NGA and predecessors, Advent of the National Geospatial-
Intelligence Agency, September 2011, by the Office of the NGA Historian, available at
227
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National HUMINT Collection Directive (NHCD). A set of national-level strategic collection requirements for
a particular country, geographic area, or transnational issue, prepared by the NHRTC in coordination with
IC and other organizations. (DHE-M 3301.001, Vol I: Collection Requirement, Reporting, and Evaluation
Procedures, 30 Jan 2009, w/ chg 2 dated 1 Feb 2012)
-- Also, an integrated inter-agency mechanism for tasking human intelligence requirements to
members of the Intelligence Community that have the best capability and probability of acquiring that
information at the least cost and least risk. A standing / enduring intelligence requirement. (National
HUMINT Glossary)
National HUMINT Requirements Tasking Center (NHRTC). Congressionally mandated to integrate all
HUMINT collection and reporting capabilities within the US Government. [Staffed by] senior officers from
the Department of State, Department of Defense, and CIA; the center produces National HUMINT
Collection Directives (NHCDs) and Collection Support Briefs (CSBs). (National HUMINT Glossary)
The NHRTC reports to the National HUMINT Manager. See DCID 3/7, National HUMINT
Requirements Center (U), 1 Jun 1992 (classified CONFIDENTIAL).
National Industrial Security Program (NISP). National program established by EO 12829 for the
protection of information classified under EO 12958 as amended, or its successor or predecessor orders,
and the Atomic Energy Act of 1954, as amended. The National Security Council is responsible for
providing overall policy direction for the NISP. The Secretary of Defense is the Executive Agent for the
NISP. The Information Security Oversight Office (ISOO) is responsible for implementing and monitoring
the NISP and for issuing implementing directives that shall be binding on agencies. (DoD 5220.22-M,
NISPOM, 28 Feb 2006) Also see the Defense Security Service (DSS); industrial security.
The Defense Security Service (DSS) is designated as the DoD Cognizant Security Office (CSO)
for cleared contractors within the NISP.
For additional information see Information Security Oversight Office (ISSO) website at:
National Infrastructure Coordinating Center. The national physical critical infrastructure center, as
designated by the Secretary of Homeland Security, which coordinates a national network dedicated to the
security and resilience of critical infrastructure of the United States by providing 24/7 situational
awareness through information sharing, and fostering a unity of effort. (www.dhs.gov)
National Infrastructure Protection Center (NIPC). The FBI's NIPC is charged with detecting, preventing
and responding to cyber and physical attacks on US critical infrastructure and overseeing computer crime
investigation conducted by FBI field offices.
National Infrastructure Protection Plan (NIPP). A plan developed by the Department of Homeland
Security [DHS] to provide the unifying structure for the integration of a wide range of efforts for the
enhanced protection and resiliency of the nation’s critical infrastructure and key resources into a single
national program. (Cyber Threats to National Security, Symposium Five, 2011)
Copy of the NIPP 2013 also available at: <https://www.hsdl.org/?view&did=747827>
National Infrastructure Sector. One of the 18 national CI/KR [critical infrastructure and/or key resource]
sectors identified in Homeland Security Presidential Directive 7, “Critical Infrastructure Identification,
Prioritization, and Protection,” 17 December 2003. (DoDD 3020.40, DoD Policy and Responsibilities for
Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
228
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Insider Threat Task Force (NITTF). National Task Force focused on Insider Threat issues under
joint leadership of the Attorney General and the Director of National Intelligence; established IAW EO
13587, October 2011 The NCIX and FBI co-direct the daily activities of the NITTF.
The NITTF assists federal agencies develop insider threat programs to help prevent, deter, and
detect compromises of classified information by malicious insiders. Its goals is to prevent classified
information from getting into the hands of people who can harm the national security of our country.
-- NITTF Fact Sheet, subj: NITTF External Communications Guidance, undated
National Insider Threat Working Group (NISTWG). Interagency, cross-discipline working group
established by the National Counterintelligence Policy Board to focus exclusively on insider threat issues.
National Intelligence. All intelligence, regardless of the source from which derived and including
information gathered within or outside of the United States, which pertains, as determined consistent with
any guidelines issued by the President, to the interests of more than one department or agency of the
Government; and that involves (a) threats to the United States, its people, property, or interests; (b) the
development, proliferation, or use of weapons of mass destruction; or (c) any other matter bearing on
United States national or homeland security. (Intelligence Reform and Terrorism Prevention Act of 2004,
§1012; also JP 1-02 and JP 2-01, Joint & National Intelligence Support to Military Operations, 5 Jan
2012)
-- Also, intelligence which pertains to the interest of more than one department or agency of the US
Government. (50 USC §401a)
The US Government uses intelligence to improve and understand the consequences of its national
security decisions.
National Intelligence Board. Serves as the senior Intelligence Community advisory body to the Director of
National Intelligence (DNI) on the analytic judgments and issues related to analysis of national
intelligence; functions include: production, review, and coordination of national intelligence; interagency
exchanges of national intelligence information; sharing of IC intelligence products with foreign
governments; protection of intelligence sources and methods; activities of common concern and other
matters as may be referred to it by the DNI. (ICD 202, National Intelligence Board, 16 Jul 2007)
National Intelligence Council (NIC). The Intelligence Community's center for mid-term and long-term
strategic thinking. Its primary functions are to: 1) Support the DNI in his role as head of the Intelligence
Community; 2) Provide a focal point for policymakers to task the Intelligence Community to answer their
questions; 3) Reach out to nongovernmental experts in academia and the private sector to broaden the
Intelligence Community's perspective; 4) Contribute to the Intelligence Community's effort to allocate its
resources in response to policymakers' changing needs; and 5) Lead the Intelligence Community's effort
to produce National Intelligence Estimates (NIEs) and other NIC products. (ODNI website)
The NIC is responsible for the US Intelligence Community’s most authoritative assessments of
major issues affecting the national security. By law [50 USC §403-3b(b)(1)], the NIC is to consist of
“senior analysts within the intelligence community and substantive experts from the public and
private sector, who shall be appointed by, report to, and serve at the pleasure” of the DNI. The
senior analysts are known as National Intelligence Officers (NIOs).
NIC responsibilities are set forth in ICD 207, National Intelligence Council, 9 June 2008.
National Intelligence Coordination Center (NIC-C). Provides a mechanism to strategically manage and
direct collection across defense, foreign and domestic realms. [Interfaces with the Defense Intelligence
Coordination Center (DIOCC]. (National Intelligence: A Consumer’s Guide - 2009)
229
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Intelligence Estimate (NIE). The DNI's most authoritative written judgment concerning national
security issues. NIEs contain the coordinated judgments of the Intelligence Community regarding the
likely course of future events. (ODNI website)
-- Also, a strategic estimate of the capabilities, vulnerabilities, and probable courses of action of
foreign nations produced at the national level as a composite of the views of the intelligence community.
(JP 1-02 and JP 2-01, Joint and National Intelligence Support to Military Operations, 5 Jan 2012)
National Intelligence Priorities Framework (NIPF). The Director of National Intelligence’s guidance to the
IC on the national intelligence priorities approved by the President. (ODNI, U.S. National Intelligence -
An Overview 2011)
-- Also, the DNI’s sole mechanism for establishing national intelligence priorities. The NIPF consists
of: intelligence topics approved by the President; a process for assigning priorities to countries and non-
state actors relevant to the approved intelligence topics; and a matrix showing those priorities. It is
updated semi-annually. The NIPF is used by the ODNI and IC elements in allocating collection and
analytical resources. (ICD 204, 13 Sep 2007)
A key instrument for keeping the IC attentive to both policymaker concerns and potential shocks…
The NIPF process gathers the needs of senior decision makers across the US government on a
semi-annual basis to support prudent allocation of both collection and analytical resources for the
following 6-to-12 months.
- DNI 2006 Annual Report of the US Intelligence Community (Feb 2007)
National Intelligence Program (NIP). All programs, projects, and activities of the IC, as well as any other
programs of the IC designated jointly by the DNI and the head of a US department or agency or by the
President. It does not include programs, projects, or activities of the military departments to acquire
intelligence solely for the planning and conduct of tactical military operations by US Armed Forces.
(National Security Act §3(6) and ICD 1, 1 May 2006)
Formerly known as the National Foreign Intelligence Program (NFIP), the NIP provides the
resources needed to develop and maintain intelligence capabilities that support national priorities.
The DoD Foreign Counterintelligence Program or FCIP is part of the NIP.
________________________
The Federal Budget (FY 2012) disclosed for the first time the aggregate funding for NIP - $55
billion in 2012. However, detailed funding requests for intelligence activities remain classified. See
National Intelligence Strategy. A strategy document prepared by the ODNI in consultation with the
relevant departments that establishes the strategic objectives for the Intelligence Community (IC); it sets
forth the framework for a more unified, coordinated and effective IC [and] guides IC policy, planning,
collection, analysis, operations, programming, acquisition, budgeting, and execution. (ODNI News
release 4-05)
The National Intelligence Strategy (NIS) sets forth the framework for a more unified, coordinated,
and effective US Intelligence Community (IC) and guides IC policy, planning, collection, analysis,
operations, programming, acquisition, budgeting, and execution. The strategy outlines strategic
objectives that are referred to as either mission or enterprise objectives. The unclassified National
Intelligence Strategy (Aug 2009) is available at <http://www.dni.gov/reports/2009_NIS.pdf>
CI is one of six mission objectives of the NIS (Mission Objective 4 is Integrate Counterintelligence).
This is the first time that CI was identified as a mission objective within the NIS; see NIS pp 8-9.
230
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Intelligence Support Plan (NISP). The NISP, in conjunction with the Combatant Command’s
Annex B: [Intelligence Plan or IPLAN] supports COCOM operational plans directed by the President and
the Secretary of Defense. The NISP defines the national Intelligence Community (IC) agencies’ and
related organizations’ intelligence collection, and analysis & production support roles and responsibilities
within the COCOM area of responsibility and the national IC to ensure integrated intelligence operations,
synchronized with the COCOM operational plan. The NISP supports the COCOM’s operational objectives
during all phases of the operation and contributes to the achievement of the COCOM’s desired
operational effects. (CJCSM 3314.01, Intelligence Planning, 28 Feb 2007) Also see Counterintelligence
Functional Support Plan (CI FSP).
National Joint Terrorism Task Force (NJTTF). The NJTTF was established in July 2002 to serve as a
coordinating mechanism with the FBI's partners on terrorism issues. Over 40 agencies are represented
in the NJTTF, which has become a focal point for information sharing and the management of large-scale
projects that involve multiple partners. Also see Joint Terrorism Task Force (JTTF). (DoJ website:
-- Also, the NJTTF was created to act as a liaison and conduit for information on threats and leads
from FBI Headquarters to the local JTTFs and to 40 participating agencies including representatives from
members of the Intelligence Community; components of the departments of Homeland Security, Defense,
Justice, Treasury, Transportation, Commerce, Energy, State, and Interior; NYPD; Nuclear Regulatory
Commission; Railroad Police; U.S. Capitol Police; and others. (FBI)
National Media Exploitation Center (NMEC). A Director of National Intelligence (DNI) Center composed
of DIA, CIA, FBI, NSA, and Defense Cyber Crime Center (DCCC) as partner organizations; DIA is the
Executive Agent. NMEC acts as a DOMEX [document and media exploitation] service of common
concern and ensures prompt and responsive DOMEX support to meet the needs of intelligence, defense,
homeland security, law enforcement, and other US Government Consumer’s, to include provision of
timely and accurate collection, processing, exploitation, and dissemination consistent with the protection
of intelligence sources and methods. (ICD 302, Document and Media Exploitation, 6 Jul 2007)
Director DIA is the IC Executive Agent for the NMEC (para 2d, DoDD 3300.03).
National Military Strategy (NMS). A document approved by the Chairman of the Joint Chiefs of Staff for
distributing and applying military power to attain national security strategy and national defense strategy
objectives. (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013) Also see national
security strategy.
The NMS defines the national military objectives, establishes the strategy to accomplish these
objectives, and addresses the military capabilities required to execute the strategy. The Chairman
develops the NMS by deriving overall security policy guidance from the President’s NSS, and
through consulting with the other JCS members and combatant commanders. The NMS describes
the strategic landscape and includes a discussion of the potential threats and risks.
-- CJCSI 3100.01A, Joint Strategic Planning System, 1 Sep 1999
National Policy. A broad course of action or statements of guidance adopted by the government at the
national level in pursuit of national objectives. (JP 1, Doctrine for the Armed Forces of the United States,
25 Mar 2013)
National Reconnaissance Office (NRO). Responsible for integrating unique and innovative space-based
reconnaissance technologies, and the engineering development, acquisition, and operation of space
reconnaissance systems and related intelligence activities. (JP 2-0, Joint Intelligence, 22 Oct 2013)
The NRO is responsible for research and development (R&D), acquisition, launch, deployment,
and operation of overhead reconnaissance systems, and related data-processing facilities to collect
231
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
intelligence and information to support national and DoD missions and other United States
Government (USG) needs (DoD Directive 5105.23, NRO, 28 June 2011).
The NRO designs, builds and operates the nation's reconnaissance satellites. According to the
NRO, their satellites provide constant global access to critical information otherwise unavailable
to the President, his cabinet, other national leaders and numerous customers in the Defense and
Intelligence communities. These satellites provide services in three broad categories: GEOINT,
SIGINT, and Communications.
In recent years, the NRO has implemented a series of actions declassifying some of its operations.
The existence of the organization was declassified in September 1992.
On 6 Sep 1961, the NRO was established as a joint CIA-Air Force operation. Throughout the
1960s, U.S. operation of reconnaissance satellites was officially classified. It was not until Jan
1971 that the NRO's existence was first disclosed by the media, when it was briefly mentioned in a
New York Times article. A more extensive discussion of the NRO appeared in the Washington
Post (9 Dec 1973) as a result of the inadvertent disclosure in a Congressional report.
In September 1992 DoD acknowledged the existence of the NRO, an agency established in 1961
to manage the development and operation of the nation's reconnaissance satellite systems.
See NRO website at <www.nro.gov/ > For additional information see Jeffrey T. Richelson,
"Undercover in Outer Space: The Creation and Evolution of the NRO," International Journal of
Intelligence and Counterintelligence, 13, 3 (Fall 2000): pp. 301-344.
National Security. A collective term encompassing both national defense and foreign relations of the
United States with the purpose of gaining: a) a military or defense advantage over any foreign nation or
group of nations; b) a favorable foreign relations position; or c) a defense posture capable of successfully
resisting hostile or destructive action from within or without, overt or covert. (JP 1, Doctrine for the Armed
Forces of the United States, 25 Mar 2013)
-- Also, the national defense or foreign relations of the United States. (EO 13526, Classified National
Security Information, 29 Dec 2009)
National Security Act. The National Security Act of 1947 realigned and reorganized the United States'
armed forces, foreign policy, and Intelligence Community apparatus in the aftermath of World War II.
The Act merged the Department of War and the Department of the Navy into the National Military
Establishment (NME) headed by the Secretary of Defense. It was also responsible for the creation of a
separate Department of the Air Force from the existing United States Army Air Forces. Initially, each of
the three service secretaries maintained quasi-cabinet status, but the act was amended in 1949 to assure
their subordination to the Secretary of Defense. At the same time, the NME was renamed as the
Department of Defense. Aside from the military reorganization, the act established the National Security
Council, a central place of coordination for national security policy in the Executive Branch, and the
Central Intelligence Agency, the United States' first peacetime intelligence agency. (Public Law No. 235,
80 Cong., 61 Stat. 496)
The cornerstone of the current national security system is the National Security Act of 1947 as
amended, designed to meet the challenges of the post-WWII, Cold War world. That legislation laid
the foundations of a new national security regime, including the creation of the National Security
Council, the Central Intelligence Agency, the Department of Defense, a separate Department of the
Air Force, and a permanent Joint Chiefs of Staff. See National Security Act of 1947, P.L. 80-235.
The National Security Act has been amended numerous times since its enactment. Reference to
the “National Security Act of 1947, as amended” indicates the legal authority cited is legislation
passed after 1947 that replaced one or more provisions of the original act.
National Security Agency (NSA). The U.S.’s cryptologic organization, with responsibility for protecting
U.S. National Security information systems and collecting and disseminating foreign signals intelligence.
Areas of expertise include cryptanalysis, mathematics, computer science, and foreign language analysis.
(National Intelligence: A Consumer’s Guide - 2009)
232
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a member of the US Intelligence Community, as well as a Combat Support Agency of the
Department of Defense. NSA/Central Security Service leads the community in delivering responsive,
reliable, effective, and expert Signals Intelligence (SIGINT) and Information Assurance (IA) products
and services, and enables Network Warfare operations to gain a decisive information advantage for the
Nation and our allies under all circumstances. (www.nsa.gov)
NSA is the U.S. Government lead for cryptology, and its mission encompasses both Signals
Intelligence (SIGINT) and Information Assurance (IA) activities. The Central Security Service (CSS)
conducts SIGINT collection, processing, analysis, production, and dissemination, and other
cryptologic operations as assigned by the Director, NSA/Chief, CSS. NSA/CSS provides SIGINT
and IA guidance and assistance to the DoD Components, as well as national customers.
-- DoDD 5100.20, NSA/CSS, 26 Jan 2010
__________________
The Central Security Service (CSS) oversees the function of the military cryptologic system,
develops policy and guidance on contributions of military cryptology to the Signals Intelligence /
Information Security (SIGINT/INFOSEC) enterprise, and manages the partnership of NSA and the
Service Cryptologic Components. NSA as a whole is known as “NSA/CSS.”
-- National Intelligence: A Consumer’s Guide - 2009. p. 43
__________________
The U.S. SIGINT effort… employs space and airborne collection ground stations, covert listening
posts, surface ships, and submarines.
-- Jeffrey T. Richelson, The US Intelligence Community (2012, Sixth Edition)
__________________
I think it's fair to say that the demands on the Agency approach infinity.
Everybody wants to know everything about everything.
-- Louis Tordella, a longtime deputy director of NSA (1995)
__________________
See 60 Years of Defending Our Nation, National Security Agency, 2012; available at :
Also see -
Matthew M. Aid, The Secret Sentry: The Untold History of the National Security Agency. New
York: Bloomsbury, 2009.
James Bamford, The Shadow Factory: The Ultra-Secret NSA from 9/11 to the Eavesdropping on
America. New York: Anchor Book, 2008.
National Security Branch (NSB). Major element of the FBI that executes the FBI’s national security mission
to lead and coordinate intelligence efforts that drive actions to protect the United States. The NSB is composed
of the Counterterrorism Division (CTD), Counterintelligence Division (CD), Directorate of Intelligence (DI),
Weapons of Mass Destruction Directorate (WMDD), Terrorist Screening Center (TSC), and High-Value
Detainee Interrogation Group (HIG). (www.fbi.gov; accessed 31 Jul 2013)
The FBI’s national security and intelligence missions are unified under the authority of the
Executive Assistant Director (EAD) who reports to the Deputy Director FBI. The EAD-NSB has
full operational and management authority over all FBI Headquarters and field national security
programs, including the authority to initiate, terminate, or reallocate any of the investigations or
other activities within the NSB.
The EAD-NSB is also responsible for the continued development of a specialized national security
workforce and is the lead FBI official responsible for coordination and liaison with the Director of
National Intelligence (DNI) and the Intelligence Community (IC).
233
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Security Council (NSC). A governmental body specifically designed to assist the President in
integrating all spheres of national security policy. (JP 1, Doctrine for the Armed Forces of the United
States. 25 Mar 2013)
The NSC was established by the National Security Act of 1947 as the principal forum to consider
national security issues that require presidential decision. Congress envisioned that the NSC would
allow military and civilian government departments and agencies to work more effectively together
on national security matters.
__________________________________
The National Security Council (NSC) is the President’s principal forum for considering national
security and foreign policy matters with the senior national security advisors and cabinet officials.
For DOD, the President’s decisions drive strategic guidance promulgated by the Office of the
Secretary of Defense (OSD) and refined by the Joint Strategic Planning System (JSPS). To carry
out Title 10, United States Code (USC), statutory responsibilities, the Chairman of the Joint Chiefs
of Staff (CJCS) utilizes the JSPS to provide a formal structure in aligning ends, ways, and means,
and to identify and mitigate risk for the military in shaping the best assessments, advice, and
direction of the Armed Forces for the President and SecDef.
-- JP 5-0, Joint Operation Planning (11 Aug 2011)
National Security Council Intelligence Directive (NSCID). A formal statement of policy by the National
Security Council, binding upon those US Government agencies within the purview of NSC authority.
(National HUMINT Glossary)
Regarding counterintelligence, see NSCID 5, US Espionage and Counterintelligence Activities
Abroad, 17 Feb 1972.
National Security Crimes. Crimes likely to impact upon the national security, defense, or foreign relations
of the United States, including but not limited to espionage, spying, sabotage, treason, and sedition.
National Security Division (NSD). Element of the Department of Justice (DoJ) created by the
reauthorization of the USA PATRIOT Act in March 2006, the Division merges the primary national security
elements of DoJ, fulfilling a key recommendation of the March 2005 report of the Commission on the
Intelligence Capabilities of the United States Regarding Weapons of Mass Destruction (WMD
Commission). The Division consists of the Counterterrorism and Counterespionage Sections; the Office of
Intelligence Policy and Review; and a Law & Policy Office. (DoJ website at <http://www.usdoj.gov/nsd/>)
The Counterespionage Section (CES), NSD, DoJ, supervises the investigation and prosecution of
cases affecting national security, foreign relations, and the export of military and strategic
commodities and technology.
CES has executive responsibility for authorizing the prosecution of cases under criminal statutes
relating to espionage, sabotage, neutrality, and atomic energy. It provides legal advice to U.S.
Attorney's Offices and investigative agencies on all matters within its area of responsibility, which
includes 88 federal statutes affecting national security. It also coordinates criminal cases involving
the application of the Classified Information Procedures Act (CIPA). In addition, the Section
administers and enforces the Foreign Agents Registration Act of 1938 (FARA) and related
disclosure statutes.
The Office of Intelligence Policy and Review (OIPR), NSD, DoJ, prepares and files all applications
for electronic surveillance and physical search under the Foreign Intelligence Surveillance Act of
1978 (FISA). The Office also advises the National Security Division and various client agencies,
including the CIA, FBI, and the Defense and State Departments, on questions of law, regulation,
and guidelines, as well as on the legality of domestic and overseas intelligence operations.
National Security Emergency. Any occurrence, including natural disaster, military attack, technological,
or other emergency, that seriously degrades or threatens the national security of the United States.
(DoDD 5111.13, ASD(HD&ASA), 16 Jan 2009)
234
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Security Information (NSI). Any information that has been determined, pursuant to Executive
Order 12958, as amended, or any predecessor order, to require protection against unauthorized
disclosure and that is so designated. (IC Standard 700-1, 4 Apr 2008)
Note: EO 12958 superseded by EO 13526, Classified National Security Information, 29 Dec 2009.
For additional information see Information Security Oversight Office (ISSO) website at:
National Security Interests. The foundation for the development of valid national objectives that define
United States goals or purposes. (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013)
National Security Letter (NSL). An administrative demand for documents or records that are relevant to
an authorized investigation to protect against international terrorism or clandestine intelligence activities.
(FBI Domestic Investigations and Operations Guide, 15 Oct 2011)
-- Also, a NSL seeks customer and consumer transaction information in national security
investigations from communications providers, financial institutions, and credit agencies. Five statutory
provisions vest government agencies responsible for foreign intelligence investigations with authority to
issue written commands comparable to administrative subpoenas. (CRS Report RS22406, 27 Sep 2010)
National security letters, which are analogous to administrative subpoenas and are authorized by
five federal statutes. They are only available for authorized national security investigations
(international terrorism or foreign intelligence/CI investigations), not general criminal investigations
or domestic terrorism investigations. NSLs are issued directly by federal agency officials.
NSLs can only be used to seek certain transactional information permitted under the five NSL
provisions, and cannot be used to acquire the content of any communications. The scope of
documents which may be obtained pursuant to a national security letter is more limited than that
which might be authorized in a FISA order. Statutory provisions at 18 USC §2709, 12 USC §3414,
15 USC §1681u, 15 USC §1681v and 50 USC §436; as amended by PL 109-177 and PL 109-178.
_____________________
“FBI currently issues an average of nearly 60 NSLs per day.”
-- CRS Report RL 33320 (3 Jan 2014), p. 22, footnote 139
_____________________
Also see CRS Report RS22406 at <http://www.fas.org/sgp/crs/intel/RS22406.pdf> and
National Security Strategy (NSS). A document approved by the President of the United States for
developing, applying, and coordinating the instruments of national power to achieve objectives that
contribute to national security. (JP 1, Doctrine for the Armed Forces of the United States, 25 Mar 2013)
National Special Security Event (NSSE). A designated event that, by virtue of its political, economic,
social, or religious significance, may be the target of terrorism or other criminal activity.
(JP 1-02 and
JP 3-28, Defense Support of Civil Authorities, 31 Jul 2013)
-- Also, major event considered to be nationally significant as designated by the President or his
designated representative, the Secretary of the Department of Homeland Security. Some events
categorized as NSSE include presidential inaugurations, major international summits held in the United
States, major sporting events, and presidential nominating. NSSE designation factors include: anticipated
attendance by U.S. officials and foreign dignitaries; size of the event; and significance of the event.
(CRS Report RS22752, updated 19 Mar 2008)
The US Secret Service is the lead federal agency responsible for coordinating, planning,
exercising, and implementing security for NSSEs. Designated the lead agency in PL 106-544.
235
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National Threat Identification and Prioritization Assessment (NTIPA). A strategic threat assessment
produced by the Office of the National Counterintelligence Executive (ONCIX) that defines and prioritizes
threats to the US posed by traditional and emerging foreign intelligence activities. It is designed to assist
senior policymakers and officials with CI responsibilities focus on the current and emerging foreign
intelligence threats that could cause unacceptable damage to US national security. The NTIPA fulfills the
reporting requirement outlined in the Counterintelligence Enhancement Act of 2002. (ONCIX)
“The NTIPA informs the President if the United States of the gravest threats to our nation.”
-- National Counterintelligence Strategy of the United States of America - 2012
__________________________
The NTIPA is a compendium of foreign intelligence threat data, mandated by statute to be
produced annually by the Office of the National Counterintelligence Executive and submitted to the
President for approval
Community work on the NTIPA (the first of which submitted in 2004 and
approved in 2005) revealed broad challenges in collection and analysis on these difficult targets.
Prioritizing foreign intelligence threats is an even more demanding analytical task, depending as it
does on the consumer’s interests (for example, foreign threats to [CIA] DO operations in country X
or to deployed forces in country Y may be far different from the rank ordering of country threats to
U.S. national security information at home) and the national security context in which they arise
(that is, threat priorities do not directly correlate to foreign intelligence capability alone but must be
measured against the potential for harm or disruption to U.S. national security concerns and
objectives, as prioritized by policy leadership).”
-- Michelle K. Van Cleave (former NCIX), Counterintelligence and National Strategy, School for National
Security Executive Education, National Defense University, April 2007, footnote 36, pp. 33-34
___________________
The NTIPA does not go into effect until approved by the President. The NCIX submits each
approved NTIPA or modification thereof to the congressional intelligence committees.
NTIPA versus NIPF - CI action is driven by the approved NTIPA and foreign intelligence (FI)
collection is driven by the NIPF (National Intelligence Priorities Framework). Each has different
focus and priorities, as well as a totally different operational dynamic.
Need for CI action is much different from the need for FI collection.
National Virtual Translation Center (NVTC). Provides timely and accurate translations of foreign
intelligence for all elements of the IC. Its mission includes acting as a clearinghouse for facilitating
interagency use of translators; partnering with elements of the U.S. Government, academia, and private
industry to identify translator resources and engage their services; building a nationwide team of highly
qualified, motivated linguists and translators, connected virtually to the program office in Washington,
D.C.; and applying state-of-the-art technology to maximize translator efficiency. (National Intelligence:
A Consumer’s Guide - 2009)
The NVTC is a DNI Center and the FBI is the IC Executive Agent.
Naval Criminal Investigative Service (NCIS). The federal law enforcement agency charged with
conducting investigations of felony-level offenses affecting the Navy and Marine Corps - that is, crimes
punishable by confinement for more than one year. NCIS also performs investigations and operations
aimed at identifying and neutralizing foreign intelligence, international terrorist, and cyber threats to the
Department of the Navy. In addition, it provides warning of threats and specialized defensive force
protection support to U.S. naval forces around the world. Criminal investigation is at the foundation of
virtually all the organization does, but the NCIS mission is broad. Transnational terrorism has been and
remains a key focus area for the agency. Today, NCIS’ mantra is: Prevent Terrorism, Protect Secrets,
and Reduce Crime. (www.ncis.navy.mil; accessed 28 Jun 2012)
Mission: NCIS is a federal law enforcement agency that protects and defends the DON
[Department of Navy] against terrorism and foreign intelligence threats, investigates major criminal
offenses, enforces the criminal laws of the United States and the UCMJ, assists commands in
maintaining good order and discipline, and provides law enforcement and security services to the
Navy and Marine Corps on a worldwide basis.
236
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Director NCIS reports directly to the Secretary of the Navy and is the senior official for criminal
investigations, counterintelligence, and security with the DON. Additionally, the Director NCIS is
the senior official within DON for terrorism investigations and related operations designed to
identify, detect, neutralize, or prevent terrorist planning and activities, and provides antiterrorism
expertise and services to DON components.
-- SECNAV Instruction 5430.107, Mission and Functions of the NCIS, 28 Dec 2005
Also see SECNAV Instruction 3850.2C, Department of the Navy Counterintelligence, 20 Jul 2005
“Criminal investigation is at the foundation of virtually all the organization does…”
NCIS. Acronym, see Naval Criminal Investigative Service.
Near Real Time. Pertaining to the timeliness of data or information which has been delayed by the time
required for electronic communication and automatic data processing. This implies that there are no
significant delays. (JP 1-02 and TRADOC Pam 525-2-1, US Army Functional Concept for Intelligence,
13 Oct 2010) Also see real time.
Need-to-know. A criterion used in security procedures that requires the custodians of classified
information to establish, prior to disclosure, that the intended recipient must have access to the
information to perform his or her official duties. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations,
16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, a determination that a prospective recipient requires access to specific classified information
in order to perform or assist in a lawful and authorized governmental function. (DoD Manual 5200.01-
Vol 1, DoD Information Security Program, 24 Feb 2012)
-- Also, a determination within the executive branch in accordance with directives issued pursuant
to this order [EO 13526] that a prospective recipient requires access to specific classified information
in order to perform or assist in a lawful and authorized governmental function. (EO13526, Classified
National Security Information, 29 Dec 2009)
The need-to-know principle is fundamental to the intelligence business.”
-- Duane R. Clarridge, A Spy For All Seasons: My Life in the CIA (1997), p. 310
The “need-to-know” principle, simply put, is that a person in authorized possession of classified
information must determine that another person requires access to that information in order to
perform a specific and authorized function and that such person has appropriate clearances and
access approvals.
…A major tightening up of the “need-to-know” practice is in order. It is particularly disturbing to
see the proliferation of detailed knowledge about intelligence sources and methods.
-- HPSCI Report (#100-5), “United States Counterintelligence and Security Concerns - 1986,”
100th Congress 1st session, 4 Feb 1987, p. 9
Net-Centric. The ability to provide a framework for full human and technical connectivity and
interoperability that allows all DoD users and mission partners to share the information they need, when
they need it, in a form they can understand and act on with confidence, and protects information from
those who should not have it. (Joint Capability Areas Taxonomy & Lexicon, 15 Jan 2008)
Network. [In critical infrastructure protection usage] a group or system of interconnected or cooperating
entities, normally characterized as being nodes (assets), and the connections that link them. (DoDD
3020.40, DoD Policy and Responsibilities for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep
2012)
Network Operations (NetOps). Activities conducted to operate and defend the Global Information Grid.
(JP 1-02 and JP 6-0, Joint Communications, 10 Jun 2010)
237
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Neutralize. 1) As pertains to military operations, to render ineffective or unusable.
2) To render enemy
personnel or material incapable of interfering with a particular operation.
3) To render safe mines,
bombs, missiles, and booby traps. 4) To make harmless anything contaminated with a chemical agent.
(JP 1-02)
Neutrality. In international law, the attitude of impartiality during periods of war adopted by third states
toward a belligerent and subsequently recognized by the belligerent, which creates rights and duties
between the impartial states and the belligerent. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
Neutral State. In international law, a state that pursues a policy of neutrality during war. (JP 1-02)
Nickname. A combination of two separate unclassified words that is assigned an unclassified meaning
and is employed only for unclassified administrative, morale, or public information purposes. (JP 1-02)
Also see codeword.
Non Attributable Internet Access. Use of a commercial internet service provider to access publicly
available information on the internet while protecting the unit’s U.S. government affiliation, disclosing
essential elements of friendly information, or exposing U.S. government information systems to intrusion
or manipulation. (AR 381-20, Army CI Program, 25 May 2010)
Noncustodial Interview. Interview conducted when subjects are interviewed without depriving them of
their freedom in any significant manner (e.g., arrest or detention). Subjects voluntarily consent to the
interview and are advised that they may depart at any time. (Army FM 2-22.2, CI, Oct 2009)
Non-Disclosure Agreement (NDA). An official authorized contract between an individual and the United
States (U.S.) Government signed by an individual as a condition of access to classified national
intelligence. The NDA specifies the security requirements for access and details the penalties for non-
compliance. (DSS Glossary)
Nongovernmental Organization (NGO). A private, self-governing, not-for-profit organization dedicated to
alleviating human suffering; and/or promoting education, health care, economic development,
environmental protection, human rights, and conflict resolution; and/or encouraging the establishment of
democratic institutions and civil society. (JP 1-02 and JP 3-08, Interorganizational Coordination During
Joint Operations, 24 Jun 2011)
-- Also, a legally-constituted organization created by persons having the legal authority to do so with
no participation or representation of any government. (DoDD 3020.40, DoD Policy and Responsibilities
for Critical Infrastructure, 14 Jan 2010 w/ chg 2 dated 21 Sep 2012)
Non-Official Cover (NOC). Term used by case officers who operate overseas outside the usual
diplomatic cover. (Spy Book)
-- Also, NOC, pronounced as “knock,” an acronym for “nonofficial cover.” Primarily a CIA term used
where one is operating without cover of diplomatic protection or US government employment. (TOP
SECRET: The Dictionary of Espionage and Intelligence, 2005)
Case officers that have no visible affiliation with the U.S. government. NOCs, as they are called,
might typically operate as business executives, students, writers, or in some other
nongovernmental capacity. They perform those jobs in addition to doing their espionage. If they are
caught in the act of spying, they do not have diplomatic immunity and are subject to the full force of
the local law, including prosecution for espionage and imprisonment. NOCs usually receive less
scrutiny and surveillance from the local authorities than their official colleagues.
-- James M. Olson, Fair Play: The Moral Dilemmas of Spying (2006)
________________________
238
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
According a Congressional Research Service report, placing U.S. intelligence officials in foreign
countries under “nonofficial cover” (NOC) in businesses or other private capacities is possible, but
it presents significant challenges to U.S. agencies. Administrative mechanisms are vastly more
complicated [than those] for officials formally attached to the embassy; special arrangements have
to be made… The responsibilities of operatives under nonofficial cover to the parent intelligence
agency have to be reconciled with those to private employers, and there is an unavoidable potential
for conflicts of interest…
-- CRS Report RL33539, Intelligence Issues for Congress, 14 Sep 2011, p. 6
Non-Permissive Environment. An operational environment in which host government forces, whether
opposed to or receptive to operations that a unit intends to conduct, do not have effective control of the
territory and population in the intended operational area (Uncertain Environment); or an operational
environment in which hostile forces have control as well as the intent and capability to oppose or react
effectively to the operations a unit intends to conduct (Hostile Environment). (National Military Strategy
to Combat Weapons of Mass Destruction, Feb 2006)
Non-Title 50 (NT50). Refers to those federal departments and organizations whose authorities derive
from portions of United States Code other than Title 50, which addresses U.S. intelligence activities.
NT50s are involved in many activities that affect national security, such as conducting foreign affairs;
combating pandemic diseases; halting illicit trafficking; conducting scientific and medical research;
regulating finance, commerce, and transportation; and protecting food, water and nuclear infrastructures.
Notice of Intelligence Potential (NIP). A document alerting consumers of a potential collection opportunity
involving sources, It is often associated with travel by the source or attendance at some event. (DHE-M
3301.002, Vol II Collection Operations, 23 Nov 2010)
Notional. Fictitious; most commonly used to refer to a nonexistent agent but also used to refer to fictitious
organizations, individuals, or sources of information. (FBI FCI Terms)
-- Also, fictitious, imaginary, existing only in the perception of the target. Antonym of real, true,
genuine, or legitimate. (CIA, D&D Lexicon, 1 May 2008)
-- Also, Notionals: fictious [sic], private commercial entities which exist on paper only. They serve as the
ostensible employer of intelligence personnel, or as the ostensible sponsor of certain activities in support of
clandestine operations. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
Notorious Individual. Someone who is widely known and has an unfavorable public reputation.
(DoDD S-5200.37, Management and Execution of Defense HUMINT (U), 9 Feb 2009 w/. chg 2)
239
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
O ==========================================
OFCO. Acronym, see Offensive Counterintelligence Operation.
Offensive Counterintelligence Operation (OFCO). A clandestine CI activity conducted for military,
strategic, DoD, or national CI and security purposes against a target having suspected or known affiliation
with FISS [Foreign Intelligence & Security Service], international terrorism, or other foreign persons or
organizations, to counter terrorism, espionage, or other clandestine intelligence activities that threaten the
security of the Department or the United States. The two types of OFCO are double agent operations and
Counterintelligence Controlled Source Operations (CSO). (DoDI S-5240.09, OFCO, 29 Oct 2008)
If defensive counterintelligence is checkers, then offensive counterintelligence is chess.
-- Steven Aftergood, “DIA Takes on Offensive Counterintelligence,” Secrecy News (12 Aug 2008)
_______________________
An ideal counterintelligence system anticipates the enemy’s move, notionally
satisfies his needs, and indeed operates a notional intelligence service for him.
-- Eric W. Timm, “Countersabotage--A CI Function” Studies in Intelligence, V7:2 (Spring 1963), p. 67
_______________________
Offensive CI operations - CI folks call OFCO - are clandestine CI activities run in support of DoD
military national security objectives and programs against individuals known or suspected to be
foreign intelligence officers with connections to foreign intelligence or international terrorist
activities. And they’re run to counter the foreign intelligence operations, espionage, against DoD
national activities and, of course, terrorist operations against DOD or national. These are very
tightly controlled departmental activities run by a small group of specially selected people within
DoD. There are only four organizations in the department that can run these operations - Army
Counterintelligence, Naval Criminal Investigative Service, Air Force Office of Special
Investigations, and now DIA with the center [Defense CI & HUMINT Center].
-- Toby Sullivan, Director of Counterintelligence for USD/I, 5 Aug 2008;
see Federal News Service transcript at <http://www.fas.org/irp/news/2008/08/dia-dchc.pdf>
_______________________
Offensive counterintelligence could exploit knowledge of secret adversary infrastructures to
keep adversaries off-balance and to force them to divert critical resources to defend against
the offensive thrusts of well-informed enemies. Offensive counterintelligence can also deceive
and manipulate the leaders of hostile coalitions, as Western governments did repeatedly in
WWII, and in the Gulf War.
--
Roy Godson, Dirty Tricks or Trump Cards: US Covert Action and Counterintelligence, with new
introduction by the author (paperback 2001), p. xxx
_______________________
For detailed information concerning DoD OFCO see DoDI S-5240.09, OFCO (U), 29 Oct 2008
Many… offensive operations have changed history,
but remain a misunderstood, and even unappreciated, CI penetration methodology.
-- CI Centre (www.cicentre.com)
240
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also (previously defined in DoDD O-5240.02, dated 20 Dec 2007), an approved CI operation
involving a formally recruited human source conducted for DoD or national purposes against a target
having suspected or known foreign intelligence and security services affiliation, international terrorist
affiliation, or other foreign persons or organizations, to counter terrorism, espionage, or other clandestine
intelligence activities that threaten the security of the Department and/or the United States.
Note: this definition was deleted from DoDD O-5240.02 with change 1 dated 30 Dec 2010.
Offensive Cyber Operations (OCO). Cyberspace operations intended to project power by the application
of force in or through cyberspace. (JP 1-02 and JP 3-12, Cyberspace Operations, 5 Feb 2013)
-- Also, includes all US Government programs and activities that, through the use of cyberspace, 1)
actively gather information from computers, information systems or networks or 20 manipulate, disrupt,
deny, degrade, or destroy targeted adversary computers, information systems, or networks. (NSPD-38)
-- Also, offensive operations to destroy, disrupt, or neutralize adversary cyberspace capabilities both
before and after their use against friendly forces, but as close to their source as possible. The goal of
Offensive Cyberspace Operations (OCO) is to prevent the employment of adversary cyberspace
capabilities prior to employment. This could mean preemptive action against an adversary. (DSS
Glossary)
Official Information. Information that is owned by, produced for or by, or is subject to the control of the
United States Government. (JP 1-02 and JP 3-61, Public Affairs, 25 Aug 2010)
Office of Foreign Missions (OFM). An office in the Department of State, Bureau of Diplomatic Security
that has three missions: 1) Protecting the interests of the US and its citizens from foreign diplomats'
abuses of privileges and immunities; 2) Improving the treatment of US· personnel assigned abroad by
imposing reciprocal treatment on foreign diplomats assigned to the US; and 3) Services to the foreign
diplomatic community in a variety of areas. Programs include the review of all notifications by foreign
missions of any intent to acquire property in the US and monitoring of foreign diplomatic travel.
Office of the National Counterintelligence Executive (ONCIX). [The U.S. Government agency] charged
with integrating the activities of all CI programs to make them coherent and efficient, coordinating CI
policy and budgets to the same end, and evaluating the performance of the CI community against the
[National CI] strategy. (National Intelligence: A Consumer’s Guide - 2009) Also see National
Counterintelligence Executive.
-- Also, ONCIX provides effective leadership and support to the counterintelligence and security
activities of the US Intelligence Community, the US Government, and US private sector entities who are
at risk of intelligence collection or attack by foreign adversaries. (www.ncix.gov; accessed 9 Jun 2014)
The ONCIX is part of the Office of the Director of National Intelligence and is staffed by senior
counterintelligence (CI) and other specialists from across the national intelligence and security
communities. The ONCIX develops, coordinates, and produces:
▪ Annual foreign intelligence threat assessments and other analytic CI products
▪ An annual national CI strategy for the US Government
▪ Priorities for CI collection, investigations, and operations
▪ CI program budgets and evaluations that reflect strategic priorities
▪ In-depth espionage damage assessments
▪ CI awareness, outreach, and training standards policies.
-- www.ncix.gov (accessed 9 Jun 2014)
Office of Special Investigations (OSI). See Air Force Office of Special Investigations (AFOSI).
241
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
One-Time Pad (OTP). Sheets of paper or silk printed with random five-number group ciphers to be used
to encode and decode enciphered messages. (CI Centre Glossary)
-- Also, groups of random numbers or letters arranged in columns, used for encoding and decoding
messages. Since the codes are only used once, a properly employed OTP is theoretically unbreakable.
(Spycraft)
-- Also, sheets of randomly generated numbers, usually formatted into four- or five-digit groups. Each
party to the secret communication… uses the same one-time pad. By a simple process of alphabetic
substitution, along with “false subtraction” and “false addition,” the two sides can securely communicate
with each other. (James M. Olson, Fair Play: The Moral Dilemmas of Spying, 2006)
-- Also, manual one-time cryptosystem produced in pad form. (CNSSI No. 4009, National Information
Assurance Glossary, 26 April 2010)
An unbreakable cipher when used properly
One-time pad (OTP), also called Vernam-cipher or the perfect cipher, is a crypto algorithm where
plaintext is combined with a random key. It is the only known method to perform mathematically
One-Time Source. A source who, may not reasonably be expected to provide information on a regular
or continuing basis by reason of limited knowledgeability or circumstances of contact. (HDI Lexicon, April
2008)
-- Also, a source of information of value that was, and will be, encountered only once. (US Army
FM 2-22.3, HUMINT Collector Operations, 6 Sep 2006)
A one-time source cannot be tasked to collect information, but can be sensitized to information in
which the collector is interested.
One-Way Radio Link (OWRL). The method of transmitting over radio (by voice, key, or impulses)
messages to intelligence personnel who, by prearrangement, are in possession of a time schedule,
signal, code, or cipher that enables them to receive and decipher messages. (AFOSI Manual 71-142,
OFCO, 9 Jun 2000)
One-Way Voice Link (OWVL). One-way radio link that transmits a coded voice message to intelligence
personnel who, by prearrangement, are in possession of a time schedule, signal, code, or cipher that
enables them to receive and decipher messages. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
-- Also, shortwave radio link used to transmit prerecorded enciphered messages to an operative, who
is usually working in place in a hostile area. (CI Centre Glossary)
Open. Not classified or concealed. (CIA, D&D Lexicon, 1 May 2002)
Open Source. Any person or group that provides information without the expectation of privacy—the
information, the relationship, or both is not protected against public disclosure. (Army Techniques
Publication
2-22.9, Open-Source Intelligence, 10 Jul 2012)
Open Source Acquisition. The act of gaining possession of, or access to open source information
synonymous with “open source collection.” The preferred term is acquisition because by definition, open
sources are collected and disseminated by others[,] open source exploiters acquire previously collected
and publicly available information second-hand. (ICD 301, National Open Source Enterprise, 11 Jul 2006)
Also see open source information and open source intelligence.
242
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Open Source Center (OSC). Advances the Intelligence Community’s exploitation of openly available
information to include the Internet, databases, press, radio, television, video, geospatial data, photos and
commercial imagery; functions include collection, analysis and research, training and information
technology management to facilitate government-wide access and use. The Director CIA will administer
the Center on behalf of the DNI. (ODNI News Release 6-05, 8 Nov 2005)
-- Also, the OSC acts as a service of common concern to advance the IC’s exploitation of open
source material and nurtures acquisition, procurement, analysis, dissemination, and sharing of open
source information, products, and services throughout the USG; established at CIA and builds on the
former Foreign Broadcast Information Service and will include personnel from across the IC and other
USG organizations; Dir CIA serves as the DNI’s Executive Agent for the Center. (ICD 310, National Open
Source Enterprise, 11 Jul 2006)
Open Source Collection. See Open Source Acquisition.
Open Source Information. Publicly available information which anyone can lawfully obtain by request or
observation. (ICD 301, National Open Source Enterprise, 11 Jul 2006)
-- Also, information that any member of the public could lawfully obtain by request or observation as
well as other unclassified information that has limited public distribution or access. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
We have no need for spies. We have the Times.
-- Tsar Nicholas I cited in Haswell, Spies and Spymasters (1977)
Open Source Intelligence (OSINT). Intelligence produced from publicly available information that is
collected, exploited, and disseminated in a timely manner to an appropriate audience for the purpose of
addressing a specific intelligence requirement. (PL109-163 § 931 and ICD 1, 1 May 2006)
“Ninety percent of intelligence comes from open sources. The other ten percent, the clandestine
work, is just the more dramatic. The real intelligence hero is Sherlock Holmes, not James Bond.”
-- Lieutenant General Samuel V. Wilson, USA (Ret.), Former Director, Defense Intelligence Agency
-- Also, relevant information derived from the systematic collection, processing, and analysis of
publicly available information in response to known or anticipated intelligence requirements. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
-- Also, publicly available information appearing in print or electronic form, including information from
radio, television, newspapers, journals, the Internet, commercial databases, and videos, graphics, and
drawings used to enhance intelligence analysis and reporting. (ODNI, U.S. National Intelligence - An
Overview 2011)
-- Also, relevant information derived from the systematic collection, processing, and analysis of
publicly available information in response to intelligence requirements. (Army FM 2-22.9, Open Source
Intelligence, Dec 2006)
-- Also, the discipline that pertains to intelligence produced from publicly available information that is
collected, exploited, and disseminated in a timely manner to an appropriate audience for the purpose of
addressing a specific intelligence requirement. (Army FM 2-0, Intelligence, 23 Mar 2010)
OSINT generally falls into four categories: 1) widely available data and information; 2) targeted
commercial data; 3) individual experts; and 4) “gray” literature, which consists of written information
produced by the private sector, government, and academe that has limited availability, either
because few copies are produced, existence of the material is largely unknown, or access to
information is constrained.
243
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
OSINT can include: media such as newspaper, magazines, radio, television, and computer-based
information; public data such as government reports, and official data such as budgets and
demographics, hearings, legislative debates, press conferences, and speeches; information
derived from professional and academic sources such as conferences, symposia, professional
associations, academic papers, dissertations and theses, and experts; commercial data such as
commercial imagery; gray literature such as trip reports, working papers, discussion papers,
unofficial government documents, proceedings, preprints, research reports, studies, and market
surveys; and information, which although unclassified, could be considered company proprietary,
financially sensitive, legally protected, or personally damaging, as well as information derived from
Internet blogs.
-- CRS Report RL34270, 5 Dec 2007
_______________________________
Clandestine technical and humint sources can be used to confirm this kind of special take from
open sources—and open sources can be used to confirm the information from clandestine sources.
-- Roy Godson, Dirty Tricks or Trump Cards: US Covert Action and Counterintelligence (1995), p. 204
Operation Order (OPORD). A directive issued by a commander to subordinate commanders for the
purpose of effecting the coordinated execution of an operation. (JP 5-0, Joint Operation Planning, 11 Aug
2011)
Operation Plan (OPLAN). 1) Any plan for the conduct of military operations prepared in response to
actual and potential contingences; 2) A complete and detailed joint plan containing a full description of the
concept of operations, all annexes applicable to the plan, and a time-phased force and deployment data.
(JP 5-0, Joint Operation Planning, 11 Aug 2011)
Operational Control (OPCON). The authority to perform those functions of command over subordinate
forces involving organizing and employing commands and forces, assigning tasks, designating objectives,
and giving authoritative direction necessary to accomplish the mission. (JP 1, Doctrine for the Armed
Forces of the United States, 25 Mar 2013)
Operational Cycle (Ops Cycle). See recruitment cycle.
Operational Environment. A composite of the conditions, circumstances, and influences that affect the
employment of capabilities and bear on the decisions of the commander. (JP 1-02 and JP 3-0, Joint
Operations, 11 Aug 2011)
Operational Intelligence. Intelligence that is required for planning and conducting campaigns and major
operations to accomplish strategic objectives within theaters or operational areas. (JP 1-02 and JP 2-0,
Joint Intelligence, 22 Oct 2013) Also see strategic intelligence; tactical intelligence.
Operational Interest (OI).
[Within HUMINT usage] exclusive contact with a source, as established by a
HUMINT organization. Within DoD, established for all sources upon IDSRS Deconfliction and assignment
of a NFN. Between DoD and other national agencies, granted for clandestine leads and sources by the
Interagency Source Registry (ISR). (DHE-M 3301.002, Vol II Collection Operations, 23 Nov 2010)
-- Also, see classified definition in AR 381-20, Army CI Program (U), 25 May 2010.
Operational Level of War. The level of war at which campaigns and major operations are planned,
conducted, and sustained to achieve strategic objectives within theaters or other operational areas.
(JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011) Also see tactical level of war; strategic level of war.
Operational Proposal. A formal document prepared by DoD collection elements to outline a proposed
activity or operation. (HDI Lexicon, April 2008)
Operational Testing. A continuing process of evaluation that may be applied to either operational
personnel or situations to determine their validity or reliability. (JP 1-02)
244
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, any means or process employed to establish authenticity, reliability, or control. (HDI Lexicon,
April 2008)
Operational Warning. A warning to theater level or equivalent decision makers of developing situations or
ongoing event which may initiate operational planning or trigger the execution or change in status of
standing operations or contingency plans. (DoDD 3115.16, The Defense Warning Network,5 Dec 2013)
Operations Officer - CIA. A career track within the Core Collector profession of the National Clandestine
Service (NCS), Central Intelligence Agency (CIA). Operations Officers (OO’s) are focused full time on
clandestinely spotting, assessing, developing, recruiting, and handling individuals with access to vital
foreign intelligence on the full range of national security issues. OO’s use their sound judgment, high
integrity, strong interpersonal skills, and ability to assess the character and motivations of others to
establish strong human relationships and trust that provides the foundation needed to acquire high-value
intelligence from foreign sources. An OO’s career can include assignments in the NCS’s three key areas
of activity—human intelligence collection, counterintelligence, and covert action—on issues of highest
interest to US national security, such as international terrorism, weapons proliferation, international crime
and narcotics trafficking, and capabilities and intentions of rogue nations. Operations Officers serve the
bulk of their time in overseas assignments that range typically from 2-3 years. (CIA; see
Operations Security (OPSEC). A process of identifying critical information and analyzing friendly actions
attendant to military operations and other activities to: identify those actions that can be observed by
adversary intelligence systems; determine indicators and vulnerabilities that adversary intelligence
systems might obtain that could be interpreted or pieced together to derive critical information in time to
be useful to adversaries, and determine which of these represent an unacceptable risk; then select and
execute countermeasures that eliminate the risk to friendly actions and operations or reduce it to an
acceptable level. (DoDD 5205.02E, DoD OPSEC Program, 20 Jun 2012)
-- Also, a process of identifying critical information and subsequently analyzing friendly actions
attendant to military operations and other activities to: a) identify those actions that can be observed by
adversary intelligence systems; b) determine indicators that adversary intelligence systems might obtain
that could be interpreted or pieced together to derive critical information in time to be useful to
adversaries; and c) select and execute measures that eliminate or reduce to an acceptable level the
vulnerabilities of friendly actions to adversary exploitation. (JP 1-02 and JP 3-13.3, Operations Security,
4 Jan 2012)
OPSEC’s most important characteristic is that it is a process and not a collection of
specific rules and instructions that can be applied to every operation or activity
Although good operational security (Opsec) does not guarantee the success of any intelligence
operation, faulty Opsec almost surely guarantees worse than failure.
-- Angelo Codevilla, Informing Statecraft: Intelligence for a New Century (1992), p. 33
___________________________
OPSEC… is a systematic and proved process… [to] deny potential adversaries information about
capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence
of the planning and execution of sensitive Government activities.
-- NSDD 298, National Operations Security Program, 22 Jan 1988, p.1
___________________________
[T]here is a clear and compelling need for operational security in a military environment and in the
conduct of sensitive operations.
-- Joint Security Commission, Redefining Security, 28 Feb 1994, p. 66
___________________________
Director, DIA provides intelligence and counterintelligence threat analysis to support OPSEC
planning to all DoD Components. .
- DoDD 5205.02E, DoD OPSEC Program, 20 Jun 2012, p. 5
245
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
National OPSEC Program
In 1988, President Ronald Reagan signed National Security Decision Directive 298 (NSDD 298).
This directive established the “National Operations Security Program” as a means to identify,
control, and protect unclassified information and evidence associated with U.S. national security
programs and activities.
NSDD 298 named the Director, National Security Agency, as the Executive Agent for interagency
OPSEC training and included in his responsibilities the establishment and maintenance of the
Interagency OPSEC Support Staff (IOSS).
The primary responsibility of the IOSS is to act as a consultant to other U.S. government
departments or agencies by providing technical guidance and assistance that will result in self-
sufficient OPSEC Programs for the protection of U.S operations. Members of the IOSS staff
assess OPSEC programs, assist in OPSEC program development, conduct surveys, assessments
and provide OPSEC training.
See IOSS web site at: <https://www.iad.gov/ioss/>
Operations Security Assessment (OPSEC Assessment). An evaluative process, usually exercise, or
support function to determine the likelihood that critical information can be protected from the adversary’s
intelligence.
(JP 1-02 and JP 3-13.3, Operations Security, 4 Jan 2012)
Operations Security Countermeasures (OPSEC Security Countermeasures). Methods and means to gain
and maintain essential secrecy about critical information. (JP 1-02 and 3-13.3, Operations Security, 4 Jan
2012)
Operations Security Indicators (OPSEC Indicators). Friendly detectable actions and open-source
information that can be interpreted or pieced together by an adversary to derive critical information. (JP 1-
02 and JP 3-13.3, Operations Security, 4 Jan 2012)
Operations Security Process (OPSEC Process). A process that examines a complete activity to
determine what, if any, exploitable evidence of classified or sensitive activity may be acquired by
adversaries. It is an analytical, risk-based process that incorporates five distinct elements: 1) critical
information identification; threat analysis; 3) vulnerability analysis; 4) risk assessment; and 5) OPSEC
countermeasures. (DoD 5205.02-M, DoD OPSEC Program Manual, 3 Nov 2008)
The operations security process involves five steps:
identification of critical information, analysis of threats,
analysis of vulnerabilities, assessment of risk, and
application of appropriate countermeasures.
-- NSDD 298, National Operations Security Program, 22 Jan 1988
Operations Security Survey (OPSEC Survey). An application of the OPSEC process by a team of subject
matter experts to conduct a detailed analysis of activities associated with a specific organization,
operation, activity, exercise, or support function by employing the known collection capabilities of potential
adversaries. (DoDD 5205.02E, DoD OPSEC Program, 20 Jun 2012)
-- Also, a collection effort by a team of subject matter experts to reproduce the intelligence image
projected by a specific operation or function simulating hostile intelligence processes. (JP 1-02 and
JP 3-13.3, Operations Security, 4 Jan 2012)
246
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Operations Security Vulnerability (OPSEC Vulberability). A condition in which friendly actions provide
operations security indicators that may be obtained and accurately evaluated by an adversary in time to
provide a basis for effective adversary decisionmaking. (JP 1-02 and JP 3-13.3, Operations Security,
4 Jan 2012)
Operations Support Element (OSE). An element that is responsible for all administrative, operations
support and services support functions within the counterintelligence and human intelligence staff
element of a joint force intelligence directorate. (JP 1-02 and JP 2-01.2, CI & HUMINT in Joint Operations,
16 Mar 2011 w/ chg 1 dated 26 Aug 2011) [Normally in the J2X]
OPSEC, See Operations Security,
Organized Cyber Intruders/Attackers. Those individuals, groups or organizations who violate
international law or conventions relating to computer networks or who otherwise use the cyberspace
domain to interfere with, disrupt, or deny computer network services. (OSD, Guidance for Employment
of the Force)
Original Classification Authority (OCA). An individual authorized in writing, either by the
President, the Vice President, or by agency heads or other officials designated by the President,
to initially classify information. (DoD IG Evaluation Guide, 22 Jan 2013)
-- Also, an individual authorized in writing, either by the United States (U.S.) President, or by agency
heads or other officials designated by the President, to classify information in the first instance. OCAs
must receive training to perform this duty. (DSS Glossary)
OCAs and other individuals delegated declassification authority in writing by the head of the IC
element may declassify information within their purview pursuant to EO 13526 and 32 CFR Part
2001 guidelines. Only the DNI may declassify space-based national imagery, pursuant to EO
12951.
-- ICD 710, Classification Management and Control Markings System, 21 Jun 2013
Other Government Agency (OGA). Within the context of interagency coordination, a non Department
of Defense agency of the United States Government. (JP 1-02)
Overhead Reconnaissance. Activities carried out by space-based capabilities whose principal purpose
is conducting and/or enabling intelligence collection. These activities are comprised of associated R&D,
acquisition, test and evaluation, and system operations performed on or by satellites, communications,
and facilities for data processing as well as command and control of spacecraft and payloads. (DoDD
5105.23, NRO, 28 Jun 2011)
Overt. Activities that are openly acknowledged by or readily attributable to the US Government, and
include activities designed to acquire information through legal and open means without concealment.
Overt information may be collected by observation, elicitation, or from knowledgeable human sources.
(ICD 304, HUMINT, 6 Mar 2008; DoDD S-5200.37, 9 Feb 2009; JP 1-02; and JP 2-01.2, CI & HUMINT
in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
-- Also, refers to being in the open, without any attempt to deceive or mislead, with full knowledge
of coordinating units or agencies; activity done without attempt to conceal it. (CI Community Lexicon)
-- Also, methods of conducting DoD activities that may be acknowledged by or attributable to the U.S.
Government. (HDI Lexicon, April 2008)
247
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Overt Collection. Intelligence activities with the ultimate goal of intelligence information collection which
are not designed or executed to conceal sponsorship, collection activity, identity of operators, or
methodologies employed. (Previously in DoDI S-5240.17, CI Collection, 12 Jan 2009) Also see open
source intelligence.
-- Also, the acquisition of intelligence information in the public domain. (CI Community Lexicon)
While the importance of clandestine collection should not be underestimated, many of the
pieces of the jigsaw puzzle which is ‘finished foreign intelligence’ can be overtly collected
by a well-organized information gathering system.”
-- Rockefeller Commission Report (June 1975), p. 209
Overt Intelligence. Information collected openly from public or open sources. (Senate Report 94-755,
Book I - Glossary, 26 Apr 1976)
Overt Operation. An operation conducted openly, without concealment. (JP 1-02 and JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
Overt [HUMINT] Operations. Openly acknowledged by, or are readily attributable to, the US Government.
Overt HUMINT methods include: debriefing, interrogation, elicitation, and observation. (JP 2-01.2, CI &
HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011)
248
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
P ==========================================
Packet Sniffer. Software that observes and records network traffic. (NIST, Glossary of Key Information
Security Terms, May 2013)
Parallel Investigative Jurisdiction. One or more agencies with differing objectives having simultaneous
authority to investigate a matter or incident. An example would be a criminal matter that has a national
security implication, which might require investigation by both a CI organization and a criminal
investigative organization. (AR 381-20, Army CI Program, 25 May 2010)
Paramilitary Forces. Forces or groups distinct from the regular armed forces of any country, but
resembling them in organization, equipment, training, or mission. (JP 1-02 and JP 3-24,
Counterinsurgency, 22 Nov 2013)
Parole. A prearranged verbal exchange used for recognition and identification between intelligence
personnel. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
-- Also, a prearranged verbal exchange used by intelligence personnel to identify themselves to each
other. (FBI FCI Terms)
Passive Source. An individual recruited by a military CI agency to act as a listening post for CI purposes
in a location associated with the individual’s job or social status. This source undertakes no actions
unless associated with such status. A passive source is recruited or placed in an area that foreign
intelligence would consider a priority target and there is evidence of foreign intelligence spotting,
assessing, or recruiting activities. (AFOSI Manual 71-119, CI Investigations, 27 Oct 2009)
Pattern Recognition. An inductive process of recognizing a commonality or trend in an aggregate of
indications from which as plausible explanation or model can be developed. (Word of Intelligence, 2nd
Edition, 2011)
Patterns. [In CI usage,] …repeated incidents that may be similar in nature or dissimilar events that occur
in a specific location or time span that may indicate potential FISS and ITO [international terrorist
organization] targeting or information exploitation. (Army FM 2-22.2, CI. Oct 2009)
Patriot Act (aka USA Patriot Act). The official title is "Uniting and Strengthening America by Providing
Appropriate Tools Required to Intercept and Obstruct Terrorism (USA PATRIOT) Act of 2001." An act to
deter and punish terrorist acts in the United States and around the world, to enhance law enforcement
investigatory tools, and for other purposes. (PL 107-56, 26 Oct 2001; codified as amended at 50 USC §
1861)
The Patriot Act substantially expanded the authority of U.S. law enforcement agencies for the
stated purpose of fighting terrorism in the United States and abroad. Among its provisions, the Act:
-- increased the ability of law enforcement agencies to search telephone and e-mail
communications and medical, financial and other records;
-- eased restrictions on foreign intelligence gathering within the United States;
-- expanded the Secretary of the Treasury’s authority to regulate financial transactions,
particularly those involving foreign individuals and entities; and
-- enhanced the discretion of law enforcement and immigration authorities in detaining
and deporting immigrants suspected of terrorism-related acts.
The act also expanded the definition of terrorism to include "domestic terrorism," thus enlarging the
number of activities to which the Patriot Act’s expanded law enforcement powers can be applied.
249
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
The Patriot Act made a number of changes to U.S. law. Key acts changed were the Foreign
Intelligence Surveillance Act of 1978 (FISA), the Electronic Communications Privacy Act of 1968
(ECPA), the Money Laundering Control Act of 1986, and Bank Secrecy Act (BSA), as well as the
Immigration and Nationality Act.
Additional information on the Patriot Act available on NCIX website at:
PCASS. Acronym for “Preliminary Credibility Assessment Screening System.” (DoDI 5210.91, Polygraph
and Credibility Assessment Procedures, 12 Aug 2010 with change 1 dated 15 Oct 2013) Also see
PCASS Instrument; polygraph examination.
PCASS Instrument. A diagnostic instrument used during an interview capable of monitoring, recording,
and/or measuring electrodermal and vasomotor activity. The PCASS instrument uses an algorithm to
evaluate the physiological responses recorded by the two components. (DoDI 5210.91, Polygraph and
Credibility Assessment Procedures, 12 Aug 2010 with chg 1 dated 15 Oct 2013) See PCASS.
The PCASS shall only be used as a field-expedient tool to screen persons of interest for
intelligence and security purposes. Only certified personnel may conduct PCASS examinations.
Per DoD policy, the PCASS will not be used to test U.S. persons (however does not apply to
PCASS examinations conducted for training); see Enclosure 5, DoD Instruction 5210.91.
Peace Operations (PO). A broad term that encompasses multiagency and multinational crisis response
and limited contingency operations involving all instruments of national power with military missions to
contain conflict, redress the peace, and shape the environment to support reconciliation and rebuilding
and facilitate the transition to legitimate governance. Peace operations include peacekeeping, peace
enforcement, peacemaking, peace building, and conflict prevention efforts. (JP 3-07.3 Peace Operations,
17 Oct 2007)
Peace Building. Stability actions, predominately diplomatic and economic, that strengthen and rebuild
governmental infrastructure and institutions in order to avoid a relapse into conflict. (JP 3-07.3, Peace
Operations, 17 Oct 2007)
Peace Enforcement. Application of military force, or the threat of its use, normally pursuant to
international authorization, to compel compliance with resolutions or sanctions designed to maintain or
restore peace and order. (JP 3-07.3, Peace Operations, 17 Oct 2007)
250
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Peacekeeping. Military operations undertaken with the consent of all major parties to a dispute, designed
to monitor and facilitate implementation of an agreement (cease fire, truce, or other such agreement) and
support diplomatic efforts to reach a long-term political settlement. (JP 3-07.3, Peace Operations, 17 Oct
2007)
Peacemaking. The process of diplomacy, mediation, negotiation, or other forms of peaceful settlements
that arranges an end to a dispute and resolves issues that led to it. (JP 3-07.3, Peace Operations, 17 Oct
2007)
Pen Register. A device which records or decodes electronic or other impulses which identify the numbers
dialed or otherwise transmitted on the telephone line to which such device is attached, but such term
does not include any device used by a provider, or customer of a wire or electronic communication
service for billing, or recording as an incident to billing, for communications services provided by such
provider or any devise used by a provider, or customer of a wire communication service for cost
accounting or other like purposes in the ordinary course of its business; see 18 USC §3127(3).
(AR 381-10, US Army Intelligence Activities, 3 May 2007) Also see trap and trace.
-- Also, [a device that] records or decodes dialing, routing addressing or signaling information
transmitted by an instrument or facility from which a wire or electronic communication is transmitted,
provided that such information must not include the contents of any communication. (FBI Domestic
Investigations and Operations Guide, 15 Oct 2011)
A pen register captures all outgoing phone numbers a particular telephone has called. A trap and
trace device identifies all incoming phone numbers to a particular telephone.
Pen register and trap and trace (PR/TT) devices enable the prospective collection on non-content
traffic information associated with wire and electronic communications, such as: the phone
numbers dialed from or to a particular telephone, including electronic communications; messages
sent from or to a particular telephone; or the internet protocol (IP) address of communications on
the Internet and other computer networks.
-- FBI Domestic Investigations and Operations Guide, 15 Oct 2011, p. 18-123
Penetration.
[In intelligence usage,] the recruitment of agents within or the infiltration of agents or
technical monitoring devices in an organization or group for the purpose of acquiring information or of
influencing its activities. (ICS Glossary)
Note: This term was previously in JP 1-02, however rescinded by JP 2-01.2, 16 Mar 2011.
-- Also, the recruitment of agents within, or the planting of agents or technical monitoring devices
within, a target organization to gain access to its secrets or to influence its activities. (Senate Report
94-755, Book I - Glossary, 26 Apr 1976)
-- Also, a principal counterintelligence objective is penetration of an adversary, and this can be
achieved by the recruitment of a key source within an opponent’s organization. Ideally, the penetration
will be the recruitment of a senior figure with sufficient access to compromise all the service’s operations,
but lower-level penetrations, such as the management of a double agent, may be sufficient to reveal the
identities of case officers and their operational premises. (Historical Dictionary of Cold War
Counterintelligence, 2007)
The best way to catch a spy is to recruit a spy
-- Counterespionage Maxim
(cited in Stuart A. Herrington, Traitors Among US: Inside the Spy Catcher’s World, 1999, p. 255)
251
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Penetration - a time-honored espionage practice
…oh what a tangled web we weave
The key to CI success is penetration. For every American spy, there are several members of the
opposition service who know who he or she is. No matter what it takes, we have to have
penetrations.
-- James M. Olson, “The Ten Commandments of Counterintelligence,” Studies in Intelligence, Vol. 54 No. 5;
_______________________
Almost every spy that we have found, both in the CIA and FBI, has been found with the aid of
recruited sources of our own on other hostile intelligence services.
-- William Webster, Former FBI Director and DCI, in Senate testimony (9 Apr 2002)
______________________
If the purpose of counterespionage is to manipulate enemy intelligence, as it is, then to have
controlled agents in the staff of an enemy service is the most important objective of
counterintelligence.
-- William R. Johnson, Thwarting Enemies at Home and Abroad (2009)
______________________
…[C]ounterespionage has one purpose which transcends all others in importance: penetration.
The only way to be sure that an enemy has been contained is to know his plans in advance and
in detail. Moreover, only a high-level penetration of the opposition can tell you whether your own
service is penetrated.
…Conducting CE without the aid of penetrations is like fighting in the dark. Conducting CE with
penetrations can be like shooting fish in a barrel. The famous case of Col. Oleg Penkovskiy…
illustrates the great value of penetrations. There can never be enough of them.
-- Austin B. Matschulat, “Coordination and Cooperation in Counterintelligence,” Studies in Intelligence,
V13: 2 (Spring 1969), pp. 29-30.
______________________
Penetrating an adversary’s intelligence service, especially the counterintelligence units, is one of
the most valuable counterintelligence techniques. Often it is also notoriously difficult.
-- Roy Godson, Dirty Tricks or Trump Cards: US Covert Action and Counterintelligence (1995), p. 207
______________________
All countries… strive hard to secure penetration agents; and they constitute the counter-
intelligence officer’s worst nightmare.
-- Chapman Pincher. Traitors: The Anatomy of Treason, First U.S. Edition (1987), p. 29
______________________
Penetrations - selected examples:
-- Colonel L Oleg V. Penkovsky was a British-US penetration of Soviet military intelligence (GRU).
-- Harold A.R. “Kim” Philby was a Soviet penetration of British intelligence.
-- Aldrich “Rick” Ames was a Soviet/Russian penetration of the CIA.
-- Robert (Bob) Hanssen was a Soviet/Russian penetration of the FBI.
Penetration Operation. The recruitment of agents within, the infiltration of agents, or the introduction of
technical monitoring devices into an organization or physical facility to acquire information or influence the
organization’s activities. (AR 381-47, OFCO, 17 Mar 2006) Also see recruitment-in-place.
Penetration Testing. [In computer usage] a test methodology in which assessors, typically working under
specific constraints, attempt to circumvent or defeat the security features of an information system.
(CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
Pentagon Force Protection Agency (PFPA). [DoD agency that] provides force protection, security, and
law enforcement to safeguard personnel, facilities, infrastructure, and other resources for the Pentagon
Reservation and designated DoD facilities within the National Capital Region (NCR). (DoDD 5105.68,
PFPA, 5 Dec 2013)
252
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Perception Management. Within DoD: None -- term removed from JP 1-02.
Periodic Reinvestigation (PR). An investigation conducted every 5 years for the purpose of updating a
previously completed background or special background investigation. The scope consists of a personal
interview, National Agency Check (NAC), Local Agency Check (LAC), credit bureau checks, employment
records, employment references, and developed character references, and normally will not exceed the
most recent 5-year period. (DSS Glossary)
Permissive Environment. Operational environment in which host country military and law enforcement
agencies have control as well as the intent and capability to assist operations that a unit intends to
conduct. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
PERSEREC. See Defense Personnel Security Research Center.
Persistent Conflict. The protracted confrontation among state, nonstate, and individual actors that are
increasingly willing to use violence to achieve their political and ideological ends. (Army FM 3-0,
Operations, Feb 2008)
Persistent Surveillance. Within DoD: None -- term removed from JP 1-02.
Previously defined in JP 1-02 and JP 2-0, Joint Intelligence (22 Jun 2007) as: a collection strategy
that emphasizes the ability of some collection systems to linger on demand in an area to detect,
locate, characterize, identify, track, target, and possibly provide battle damage assessment and re-
targeting in near or real-time. Persistent surveillance facilitates the prediction of an adversary’s
behavior and the formulation and execution of preemptive activities to deter or forestall anticipated
adversary courses of action
Persona. The social façade or image a person projects in public. A persona may be true or false. (DoDI
S-5105.63, Implementation of DoD Cover and Cover Support Activities, 20 Jun 2013)
Persona Non Grata (PNG). An international diplomatic term meaning “person who is not acceptable or
not welcome.” It is a legal status applied to diplomats who have been caught by the host country in
espionage or other unlawful activities and are expelled and thereafter denied access to the host country.
(CI Community Lexicon)
Latin for “unwelcome person.” The provision for declaring a person persona non grata is codified
in international law; see Article 9 of the Vienna Convention on Diplomatic Relations of 1961.
-- Also, a diplomatic expulsion by flag accrediting country. (AFOSI Manual 71-142, OFCO, 9 Jun
2000)
-- Also, the official act of declaring a foreign national unwelcome in this country. (FBI FCI Terms)
-- Also, in diplomatic usage and under international law, the official act of declaring a foreign national,
usually an official of a foreign government, as no longer welcome and forcing his/her expulsion. In
tradecraft terminology, the undesirable individual is PNG’d. The most common use of PNG is for foreign
diplomatic or official personnel caught in the act of engaging in illegal espionage activities. (The CIA
Insider’s Dictionary, 1996)
Personal Meeting (PM). Face-to-face contact between a handler and a lead or asset. (HDI Lexicon, April
2008)
253
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a clandestine meeting between two operatives, always the most desirable but a more risky
form of communication. (CI Centre Glossary)
Personal meetings may be held to give an agent his next assignment and instructions for carrying
it out, to train him in tradecraft or the use of technical or communications equipment, to transmit
documents, reports, technical equipment, money, or other items, or to fulfill several of these
purposes. In actual practice several purposes are usually served by a meeting. In addition to its
particular objectives more general needs can be filled. A meeting held for training purposes may
be a means for clarifying biographic data on the agent or his views on various subjects. At every
meeting with an agent one should study him and obtain new data on his potential and talents,
thereby providing a better basis for judging his sincerity and deciding how much trust to place in
him.
-- L.K. Berrenev, ‘Operational Contacts,” Studies in Intelligence, Vol 9, Winter 1965, p.64
[declassified 18 Sep 1995; originally classified SECRET].
Personal Protective Security Detail. Security personnel assigned to protect individuals who, by their
grade, assignment, symbolic value, or relative isolation, are likely attractive or accessible terrorist targets.
These trained and armed personnel are capable of providing continuous protection for designated
individuals. (DoDD 5105.68, PFPA, 5 Dec 2013)
Personally Identifiable Information (PII). Information which can be used to distinguish or trace an
individual’s identity, such as his or her name; social security number; date and place of birth; mother’s
maiden name; and biometric records, including any other personal information which is linked or linkable
to a specified individual. Includes information about an individual that identifies, links, relates, or is unique
to, or describes him or her (e.g., a social security number; age; military rank; civilian grade; marital status;
race; salary; home or office phone numbers; other demographic, biometric, personnel, medical, and
financial information, etc). (DoDD 5400.11, DoD Privacy Program, 8 May 2007)
-- Also, information that can be used to uniquely identify, contact, or locate a single person or can be
used with other sources to uniquely identify a single individual. (DSS Glossary)
Personnel Security. The security discipline that assesses the loyalty, reliability, and trustworthiness of
individuals for initial and continued eligibility for access to classified information or assignment in sensitive
positions. (DoDD 5200.43, Management of the Defense Security Enterprise, 1 Oct 2012, w/ chg 1)
-- A security discipline that assesses the loyalty, reliability, and trustworthiness of individuals for initial
and continued eligibility for access to classified information. (IC Standard 700-1, 4 Apr 2008)
-- Also, [with US Army] the application of standards and criteria to determine whether or not an
individual is eligible for access to classified information, qualified for assignment to or retention in
sensitive duties, and suitable for acceptance and retention in the total Army consistent with national
security interests. (AR 380-67, Personnel Security Program, 24 Jan 2014)
The essence of personnel security is to determine that those who have access to secrets as a
result of their jobs are people of sufficient probity and responsibility who will safeguard that data.
-- Frederick L. Wettering, “Counterintelligence: The Broken Triad.” International Journal of Intelligence
and Counterintelligence 13 (Fall 2000), pp. 265-299.
______________________
Personnel Security—The First and Best Defense
The personnel security system is a the very heart of the government’s security mission. …{The
main purpose of personnel security programs is to protect the national security interests of the
United States by insuring the reliability and trustworthiness of those whom information vital to those
interests is entrusted.
-- Joint Security Commission, Redefining Security: A Report to the Secretary of Defense and the Director
Central Intelligence, 28 Feb 1994, p. 39
______________________
254
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
For additional information see -- Personnel Security References
EO 12968, Access to Classified Information
EO 13467, Reforming Processes Related to Suitability for Government Employment, Fitness for
Contractor Employees, and Eligibility for Access to Classified National Security Information
DoD 5200.2-R, Personnel Security Program
For Army policy see: AR 380-67, Personnel Security Program
Personnel Security Investigation (PSI). An inquiry into the activities of an individual, designed to develop
pertinent information pertaining to trustworthiness and suitability for a position of trust as related to loyalty,
character, emotional stability, and reliability. (JP 1-02 and JP 2-01, Joint and National Intelligence Support
to Military Operations, 5 Jan 2012)
DoD generates 90% of the security investigation requirements in the Executive Branch….
-- Security and Suitability Process Reform: Strategic Framework, Feb 2010
______________________
A PSI is an inquiry into an individual’s loyalty, character, trustworthiness, and reliability to ensure
that he/she is eligible to access classified information, or for an appointment to a sensitive position
or position of trust. DoD uses PSIs to determine an individual’s eligibility for a security clearance.
In 2005, DoD transferred most of its PSI workload to U.S. Office of Personnel Management (OPM).
All PSIs are conducted by the designated investigative service provider. In the case of DoD, OPM
is the designated investigative service provider.
The types of PSIs vary based on the level of security clearance necessary for a given sensitive
position. The personnel security clearance process is governed primarily by EO 12968 (Access to
Classified Information), EO 13467 (Reforming Processes Related to Suitability for Government
Employment) and the Federal Investigative Standards. DoD Regulation 5200.2-R, “Personnel
Security Program,” outlines criteria for sensitive positions and the corresponding clearance levels.
-- Also, any investigation required for the purpose of determining the eligibility of DoD military and
civilian personnel, contractor employees, consultants, and other persons affiliated with the DoD, for
access to classified information, acceptance or retention in the Armed Forces, assignment or retention in
sensitive duties, or other designated duties requiring such investigation. PSIs include investigations of
affiliations with subversive organizations, suitability information, or hostage situations…conducted for the
purpose of making personnel security determinations. They also include investigations of allegations that
arise subsequent to adjudicative action and require resolution to determine an individual's current
eligibility for access to classified information or assignment or retention in a sensitive position.
(AR 380-67, Personnel Security Program, 24 Jan 2014)
Pharming. Redirecting users from legitimate websites to fraudulent ones for the purpose of extracting
confidential data, e.g., mimicking bank websites.
Phishing. Deceiving individuals into disclosing sensitive personal information through deceptive
computer-based means. (CNSSI No. 4009, National Information Assurance Glossary, 26 April 2010)
-- Also, usually an email that looks like it is from a legitimate organization or person, but is not and
contains a link or file with malware. Phishing attacks typically try to snag any random victim. Spear
phishing attacks target a specific person or organization as their intended victim. (FBI; see
255
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, a form of criminal activity using social engineering techniques through email or instant
messaging. Phishers attempt to fraudulently acquire other people’s personal information, such as
passwords and credit card details, by masquerading as a trustworthy person or business in an apparently
official electronic communication. (McAfee.com; accessed 15 Nov 2010)
-- Also, Tricking individuals into disclosing sensitive personal information through deceptive computer-
based means. (Words of Intelligence, 2nd Edition, 2011)
Phreaking. Gaining unauthorized access to telecommunication systems. (FBI; see
Physical Search. Any intrusion upon a person or a person's property or possessions to obtain items of
property or information. The term does not include examination of areas that are in plain view and visible
to the unaided eye if no physical trespass is undertaken, and does not include examinations of
abandoned property left in a public place. (DoD 5240.1-R, Dec 1982) Also see search.
Types include consented physical search, plain view search, search incident to a lawful
apprehension, and nonconsensual physical search. See USC §1821(5).
For DoD CI see Chapter 7, Procedure 7-Physical Searches, DoD 5240.1-R, Procedures Governing
the Activities of DoD Intelligence Components that Affect United States Persons, 7 Dec 1982
Physical Security. The security discipline concerned with physical measures designed to safeguard
personnel; to prevent unauthorized access to equipment, installations, material, and documents; and to
safeguard them against espionage, sabotage, damage, and theft. (DoDD 5200.43, Management of the
Defense Security Enterprise, 1 Oct 2012 w/ chg 1 dated 24 Apr 2013)
The physical protection of information, assets and personnel is fundamental to nay security system.
-- Joint Security Commission Report, Redefining Security, 28 Feb 1994, p. 56
-- That part of security concerned with physical measures designed to safeguard personnel; to
prevent unauthorized access to equipment, installations, material, and documents; and to safeguard them
against espionage, sabotage, damage, and theft. (JP 1-02 and JP 6-0, Joint Communications Systems,
10 Jun 2010)
-- Also, the security discipline concerned with physical measures designed to: protect personnel;
prevent unauthorized access to facilities, equipment, material, and documents; and defend against
espionage, terrorism, sabotage, damage, and theft. (IC Standard 700-1, 4 Apr 2008)
Physical Security Investigation. All inquires, inspections, or surveys of the effectiveness of controls and
procedures designed to provide physical security; and all inquires and other actions undertaken to obtain
information pertaining to physical threats to DoD personnel or property. (JP 1-02)
Physical Surveillance. A systematic and deliberate observation of a person by any means on a
continuing basis, or the acquisition of a nonpublic communication by a person not a party thereto or
visibly present thereat through any means not involving electronic surveillance. (DoD 5240.1-R, Dec
1982) Also see surveillance.
Surveillance, the job of following and observing designated persons without being noticed, is
intrinsic to counterintelligence.
-- William R. Johnson, Thwarting Enemies at Home and Abroad (2009)
For DoD CI see Chapter 9, Procedure 9 - Physical Surveillance, DoD 5240.1-R, Procedures
Governing the Activities of DoD Intelligence Components that Affect United States Persons,
7 Dec 1982
256
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
-- Also, physical surveillance (not requiring a court order): the deliberate observation… of persons,
places, or events, on either a limited or continuous basis, in areas where there may or may not be a
reasonable expectation of privacy. (FBI Domestic Investigations and Operations Guide, 15 Oct 2011)
-- Also, physical surveillance (with a warrant or court order): a physical search constitutes any
physical intrusion within the United States into premises or property (including examination of the interior
of property by technical means) that is intended to result in the seizure, reproduction, inspection, or
alteration of information, material, or property, under circumstances in which a person has a reasonable
expectation of privacy. (FBI Domestic Investigations and Operations Guide, 15 Oct 2011, p. 18-152)
Piracy. An illegal act of violence, depredation (e.g., plundering, robbing, or pillaging), or detention in or
over international waters committed for private ends by the crew or passengers of a private ship or aircraft
against another ship or aircraft or against persons or property on board such ship or aircraft. (JP 1-02)
Pitch.
[In intelligence usage] the effort made to recruit a source. (HDI Lexicon, April 2008)
Placement. An individual’s proximity to information of intelligence interest. (JP 1-02 and JP 2-01.2,
CI & HUMINT in Joint Operations, 16 Mar 2011 w/ chg 1 dated 26 Aug 2011) Also see access;
placement & access.
-- Also, the rationale for a HUMINT source or operational asset’s presence in an operational area.
(Defense HUMINT Enterprise Manual 3301.002, Vol II Collection Operations, 23 Nov 2010)
Placement and Access (P&A). An individual’s proximity to and ability to collect information of intelligence
interest. (HDI Lexicon, April 2008) Also see access.
Plain Text. Unencrypted information. (CNSSI No. 4009, National Information Assurance Glossary,
26 April 2010)
Planned Target. Target that is known to exist in the operational environment, upon which actions are
planned using deliberate targeting, creating effects which support commander's objectives. (JP 3-60,
Joint Targeting, 13 Apr 2007)
Planning. The ability to establish a framework to employ resources to achieve a desired outcome or
effect. (Joint Capability Areas Taxonomy & Lexicon, 15 Jan 2008)
-- Also, the process by which commanders (and the staff, if available) translate the commander’s
visualization into a specific course of action for preparation and execution, focusing on the expected
results. (Army FM 3-0, Operations, Feb 2008)
Planning and Direction. In intelligence usage, the determination of intelligence requirements,
development of appropriate intelligence architecture, preparation of a collection plan, and issuance
of orders and requests to information collection agencies. (JP 1-02 and JP 2-01, Joint and National
Intelligence Support to Military Operations, 5 Jan 2012)
Planning Order (PLANORD). A planning directive that provides essential planning guidance and directs
the initiation of execution planning before the directing authority approves a military course of action.
(JP 5-0, Joint Operation Planning, 11 Aug 2011) Also see execute order (EXORD).
Plant.
[In intelligence usage,]
1) to insert information into a target’s intelligence channel; 2) an individual
infiltrated into a foreign organization (a penetration); 3) a forged document provided to a foreign
organization. (CIA in D&D Lexicon, 1 May 2002)
257
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Planted Information. False or misleading information that the target has been permitted or helped to
collect. (CIA in D&D Lexicon, 1 May 2002)
Platform. In collection parlance, the conveyance for collection sensors.
Plausible Denial. Official disclaimer supported by a believable cover story. (CIA in D&D Lexicon, 1 May
2002) Also see plausible deniability.
Plausible Deniability. The concept that allows the United States government, specifically the U.S.
president himself, to claim no knowledge of or involvement in a covert action that goes public, particularly
if it has gone badly. (James M. Olson, Fair Play: The Moral Dilemmas of Spying, 2006)
Pocket Litter. The usual litter found in pockets: coins, tickets, keys, etc. In this case, pocket litter is
planted so that if the agent is caught, incidental-looking items will reinforce his cover story. (TOP
SECRET: The Dictionary of Espionage and Intelligence, 2005)
Police Information. All available information concerning known and potential enemy and criminal threats
and vulnerabilities collected during police activities, operations, and investigations. Analysis of police
information produces police intelligence. (ATTP 3-39.20, Police Intelligence Operations, Jul 2010)
Police Intelligence. Police intelligence results from the application of systems, technologies, and
processes that analyze applicable data and information necessary for situational understanding and
focusing policing activities to achieve social order. (ATTP 3-39.20, Police Intelligence Operations,
Jul 2010)
Political Intelligence. Intelligence concerning foreign and domestic policies of governments and the
activities of political movements. (JP 1-02)
Polygraph and Credibility Assessment (PCA). The overarching term covering programs, research,
training, and procedures that employ technologies to assess an individual’s truthfulness with the aid of
technical devices that measure physiological data or behavioral activity. (DoDI 5210.91, PCA Procedures,
12 Aug 2010 with chg 1 dated 15 Oct 2013) Also see polygraph examination.
Polygraph Examination. A process that encompasses all activities that take place between a polygraph
examiner and examinee during a specific series of interactions. (DoDD 5210.48, PCA Program, 25 Jan
2007 with change 2 dated 15 Nov 2013) Also see credibility assessment; polygraph instrument.
-- Also, a highly structure technique conducted by specialty trained CI personnel certified by proper
authority as polygraph examiners. (Army FM 2-22.2, CI, Oct 2009)
Polygraph - Greek for “many writings
The most significant contribution of the polygraph is its success in eliciting information and its value
as a deterrent; however, the polygraph should be one of several investigative tools.
-- Webster Commission Report (A Review of FBI Security Programs), March 2002 (p. 68)
________________________
The polygraph is a multichannel instrument that records changes in respiration, cardiovascular
activity, and skin resistance in response to questions. According to polygraph theory, when a
subject gives a false response to a relevant question…, the physiological reaction will be greater
than the reaction to others questions (control or irrelevant questions). However, contrary to popular
belief, there is no physiological response that is unique to deception. The reactions measured by
the polygraph can be caused by a variety of emotions. This fact underlies much of the controversy
surrounding the polygraph. […]
258
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Two types of polygraphs are currently used in personnel security screening the counterintelligence-
scope( CI-scope) polygraph and the full-scope polygraph. The CI-scope polygraph focuses on
espionage, sabotage, terrorism, mishandling classified information, and unauthorized contacts with
representatives of foreign governments. […] Screening polygraphs arguably have a deterrent
effect.
-- Joint Security Commission, Redefining Security: A Report to the Secretary of Defense and the Director
Central Intelligence, 28 Feb 1994, pp.61-70
______________________________
The evidence is overwhelming that the polygraph, in the hands of a skilled examiner, is a very
useful tool to elicit information from an applicant or an employee that might otherwise be obtained
only after lengthy and costly investigation—or not at all.
-- DCI’s Blue Ribbon Panel on the Polygraph, CIA’s Use of Polygraph in Personnel Screening,
Redacted Copy approved for public release 29 May 2012. Copy available at:
______________________________
For additional information, see --
“Your Polygraph Examination” at:
Committee to Review the Scientific Evidence on the Polygraph, The Polygraph and Lie Detector
(Washington, DC: National Academies Press, 2003).
Ken Alder, The Lie Detector: The History of an American Obsession (New York: Free Press, 2007)
John F. Sullivan, Gatekeeper: Memories of a Polygraph Examiner (Washington, DC: Potomac
Books, 2007)
Also see the American Polygraph Association (APA) web site at <http://www.polygraph.org/>
Polygraph Instrument. A diagnostic instrument to measure and record respiration, electrodermal, blood
volume, and heart rate responses to verbal or visual stimuli. (DoDI 5210.91, Polygraph and Credibility
Assessment Procedures, 12 Aug 2010 with chg 1 dated 15 Oct 2013) Also see polygraph examination.
PORTICO. The nickname for the DoD Counterintelligence Community’s enterprise information capability
that promotes information sharing and provides standardized CI activity reporting across the Department.
PORTICO operates in a secure network environment and facilitates standardization of DoD CI business
processes by providing a common interface for shared results of core CI functions (i.e., collection,
investigations, analysis & production, operations, and functional services).
Port Security. The safeguarding of vessels, harbors, ports, waterfront facilities, and cargo from internal
threats such as destruction, loss, or injury from sabotage or other subversive acts; accidents; thefts; or
other causes of similar nature. (JP 1-02 and JP 3-10, Joint Security Operations in Theater, 3 Feb 2010)
Positive Intelligence. A term of convenience sometimes applied to foreign intelligence to distinguish it
from foreign counterintelligence. (ICS Glossary, 1978)
-- Also, information gathered concerning a foreign power that is significant to national security, foreign
relations, economic interest, and other plans and policies of a government. (CI Community Lexicon)
In the early 1900’s military intelligence consisted of two separate fields of endeavor: positive
intelligence and negative intelligence. Positive intelligence focused on “seeking information on our
enemies or potential enemies” and negative intelligence focused on “preventing enemies or
potential enemies from acquiring information of value about the United States.” Following World
War I, the term negative intelligence was replaced by counterintelligence.
-- Source: Bruce W. Bidwell, History of the MI Division… Army General Staff: 1775 - 1941 (1986)
259
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Posse Comitatus Act. Prohibits search, seizure, or arrest powers [by] US military personnel [in civilian
law enforcement matters in the US unless authorized by legislation]. Amended in 1981 under Public Law
97-86 to permit increased DoD support of drug interdiction and other law enforcement activities [Title 18,
USC § 1385]. (JP 1-02)
Posse Comitatus Act (PCA) places strict limits on the use of federal military personnel for law
enforcement. Enacted in 1878, PCA prohibits the willful use of the US Army (and later, the US Air
Force) to enforce laws, except as authorized by the Congress or the US Constitution. Although the
PCA, by its terms, refers only to the Army and Air Force, DoD policy extends the prohibitions of the
Act to the US Navy and Marine Corps, as well.
Specifically prohibited activities include: interdiction of a vehicle, vessel, aircraft, or similar activity;
search and/or seizure; arrest, apprehension, “stop-and-frisk” detentions, and similar activities; and
use of military personnel for surveillance or pursuit of individuals, or as undercover agents,
informants, investigators, or interrogators. Additionally, federal courts have recognized exceptions
to the PCA. These common law exceptions are known as the “military purpose doctrine” and the
“indirect assistance” exceptions.
Exceptions and/or circumstances not falling under PCA include:
1) Actions that are taken for the primary purpose of furthering a military or foreign affairs function
of the United States;
2) Federal troops acting pursuant to the President’s Constitutional and statutory authority to
respond to civil disorder;
3) Actions taken under express statutory authority to assist officials in executing the laws,
subject to applicable limitations; and
4) Civil Disturbance operations authorized by statute.
The PCA does not apply to National Guard forces operating in state active duty or Title 32 USC
status, nor to the USCG, which operates under Title 14 USC authority.
For an overview of the Posse Comitatus Act, see CRS Report R42659, The Posse Comitatus Act
and Related Matters: The Use of the Military to Execute Civilian Law (16 Aug 2012), by Charles
Doyle and Jennifer K. Elsea; copy available at: <http://www.fas.org/sgp/crs/natsec/R42659.pdf >
Also see Craig T. Trebilcock, The Myth of Posse Comitatus, October 2000; copy available at:
Also see DoDI 3025.21, Defense Support of Civilian Law Enforcement Agencies, 27 Feb 2013.
Preliminary Credibility Assessment Screening System (PCASS) Instrument. A diagnostic instrument used
during an interview capable of monitoring, recording, and/or measuring electrodermal and vasomotor
activity. The PCASS instrument uses an algorithm to evaluate the physiological responses recorded by
the two components. (DoDI 5210.91, PCA Procedures, 12 Aug 2010 with change 1 dated 15 Oct 2013)
Only certified personnel may conduct PCASS examinations. Also IAW current DoD policy the
PCASS will not be used to test U.S. persons.
Preliminary Inquiry. An unobtrusive review of the facts and circumstances of an incident or allegation to
determine if the preliminary information or circumstances is sufficient to warrant the initiation of an
investigation or referral to an investigative entity. The limited objective will be determined by the policy
of individual agencies and may include the collection of information from other agencies and/or other
records such as travel, financial, HR, security, and badgeing [sic], etc.; which may be used to make an
informed determination if the incident involved is part of a pattern. (ONCIX Insider Threat Detection -
Glossary) Also see counterintelligence investigation, counterintelligence inquiry, investigation;
preliminary counterintelligence investigation; Section 811 referral.
Within DoD the proper term of use is Counterintelligence Inquiry or CI Inquiry; see DoDI
O-5240.21, Counterintelligence Inquiries, 14 May 2009 with change 2 dated 15 Oct 2013.
260
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Preliminary Investigation [counterintelligence related]. A limited scope inquiry into the circumstances
surrounding a reported incident or matter of potential CI interest to determine if there are specific facts
giving reason to believe that a threat to national security may exist or if a full field CI investigation is
warranted. (AR 381-20, Army CI Program, 25 May 2010)
Preparation of the Environment (PE). An umbrella term for operations and activities conducted by
selectively trained special operations forces to develop an environment for potential future special
operations. (JP 3-05, Special Operations, 18 Apr 2011)
President’s Daily Brief (PDB). An all-source, analytic document produced for the President of the United
States and members of his/her Cabinet and senior staff. Production is overseen by the ODNI with
contributions from the Intelligence Community.
Preventive Deployment. The deployment of military forces to deter violence at the interface or zone of
potential conflict where tension is rising among parties. Forces may be employed in such a way that they
are indistinguishable from a peace operations force in terms of equipment, force posture, and activities.
(JP 3-07.3, Peace Operations, 17 Oct 2007)
Prisoner of War (POW or PW). A detained person (as defined in Articles 4 and 5 of the Geneva
Convention Relative to the Treatment of Prisoners of War of August 12, 1949) who, while engaged in
combat under orders of his or her government, is captured by the armed forces of the enemy. (JP 1-02
and JP 3-50. Personnel Recovery, 20 Dec 2011)
Private Information. Data, facts, instructions, or other material intended for or restricted to a particular
person, group, or organization. (Army Techniques Publication 2-22.9, Open-Source Intelligence, 10 Jul
2012)
Private Sector. An umbrella term that may be applied in the United States and in foreign countries to any
or all of the nonpublic or commercial individuals and businesses, specified nonprofit organizations, most
of academia and other scholastic institutions, and selected nongovernmental organizations. (JP 3-57,
Civil Military Operations, 8 Jul 2008)
Privacy Act. The Privacy Act of 1974 (5 U.S.C. 552a) establishes a code of fair information practices that
governs the collection, maintenance, use, and dissemination of personally identifiable information about
individuals that is maintained in systems of records by federal agencies. A system of records is a group of
records under the control of an agency from which information is retrieved by an individual’s name or by
some other identifier assigned to the individual. The Privacy Act requires that agencies provide public
notice of their systems of records through publication in the Federal Register. The Privacy Act prohibits
the disclosure of information from a system of records absent the written consent of the individual who is
the subject of the information search, unless the disclosure is pursuant to one of 12 statutory exceptions.
The Privacy Act also provides individuals with a means by which to seek access to and amend their
records and sets forth various agency record-keeping requirements. (ODNI, U.S. National Intelligence -
An Overview 2011)
For DoD policy see DoD Regulation 5400.11-R, DoD Privacy Act Program.
The Privacy Act regulates the way certain types of information may be acquired and used by the
Federal Government and provides certain rights to individuals whose information is acquired by the
government.
A 240-page overview of the Act can be found at: <http://www.justice.gov/opcl/1974privacyact.pdf>
Proactive TSCM. CI-focused TSCM targeting using a risk-based approach with the goal of identifying and
exploiting technical collection efforts targeting DoD interests. (DoDI 5240.05, TSCM, 3 Apr 2014)
261
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Probable Cause. Would a prudent individual believe that a fact is probably true. (Congressional
Research Memorandum, Subject: Probable Cause, Reasonable Suspicion, and Reasonableness
Standards in the Context of the Fourth Amendment and the Foreign Intelligence Surveillance Act,
30 Jan 2006; at <http://www.fas.org/sgp/crs/intel/m013006.pdf >) Also see reasonable belief.
-- Also, 1) To search: A reasonable belief that a crime has been committed and that the person,
property, or evidence sought in connection with the crime is located in the place or on the person to be
searched; and/or 2) To apprehend: A reasonable belief that a crime has been committed and that the
person to be apprehended committed it. (AR 190-20, Military Police Investigations, 1 Nov 2005)
Probable Cause / Reasonable Belief
The facts and circumstances are such that a trained and experienced reasonable person would
hold the belief.
• Fact Specific / Situation Dependant
• Must be based on facts and circumstances that can be articulated
• Can be based on experience, training and knowledge as it applies to the facts
and circumstances
“Hunches” and “intuitions” don’t count
• Often requires education of non-intelligence personnel
-- Briefing, Legal Fundamentals for Counterintelligence Professionals,
Staff Judge Advocate, US Army Intelligence and Security Command, nd. circa 2012
Probe. In information operations, any attempt to gather information about an automated information
system or its on-line users. (JP 3-13, Information Operations, 13 Feb 2006) Also see information
operations.
-- Also, [In computer usage / information operations] a technique that attempts to access a system to
learn something about the system. (CNSSI No. 4009, National Information Assurance Glossary, 26 April
2010)
Processing. A system of operations designed to convert raw data into useful information. (JP 2-0, Joint
Intelligence, 22 Oct 2013)
Processing and Exploitation. In intelligence usage, the conversion of collected information into forms
suitable to the production of intelligence. (JP 1-02 and JP 2-01, Joint and National Intelligence Support to
Military Operations, 5 Jan 2012)
Production. The preparation of reports based on analysis of information to meet the needs of intelligence
users (Consumer’s) within and outside the Intelligence Community. (CIA, A Consumer’s Guide to
Intelligence, July 1995) Also see intelligence production.
-- Also, conversion of information into intelligence through the integration, analysis, evaluation, and
interpretation of data from all available sources and the preparation of intelligence products in support
of known or anticipated user requirements. (AR 381-20, Army CI Program, 25 May 2010)
Production results in the creation of intelligence, that is, value-added actionable information tailored
to a specific customer. In government parlance, the term ‘finished intelligence” is reserved for
products issued by analysts responsible for synthesizing all available sources of intelligence,
resulting in a comprehensive assessment of an issue or situation, for use by senior analysts or
decision makers.
-- DIA, Intelligence Essentials for Everyone, June 1999
___________________________
Production is the development of intelligence through the analysis of collected information and
existing intelligence. Analysts create intelligence products, conclusions, or projections regarding
threats and relevant aspects of the operational environment to answer known or anticipated
requirements in an effective format.
-- ADRP 2-0, Intelligence, Aug 2012, p. 3-7
262
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Production Requirement (PR). A customer's formal request for analytic support, identifying the topic or
issue of interest, type of information or analysis required, date required, preferred format, and
classification. (DoDI 5240.18, CI Analysis & Production, 17 Nov 2009 with change 1 dated 15 Oct 2013)
-- Also, an intelligence requirement that cannot be met by current analytical products resulting in
tasking to produce a new product that can meet this intelligence requirement. (JP 2-0, Joint Intelligence,
22 Oct 2013)
Proliferation. The transfer of weapons of mass destruction, related materials, technology, and expertise
from suppliers to hostile state or non-state actors. (JP 1-02 and JP 3-40, Combating WMD, 10 Jun 2009)
Program Protection Plan (PPP). A risk-based, comprehensive, living plan to protect CPI that is
associated with an RDA program. (DoDI 5200.39, CPI Protection within the DoD, 16 Jul 2008 with
change 1 dated 28 Dec 2010) Also see counterintelligence support plan (CISP); critical program
information (CPI).
Note: DoDI 5200.39 is under revision. A proposed draft definition for PPP: a risk-based,
comprehensive, living plan to identify and protect CPI and mission-critical functions and
components associated with an RDA program.
____________________
Program Protection is the integrating process for managing risks to advanced technology and
mission-critical system functionality from foreign collection, design vulnerability or supply chain
exploit/insertion, and battlefield loss throughout the acquisition lifecycle.
The purpose of the PPP is to help programs ensure that they adequately protect their technology,
components, and information. The PPP is used to develop tailored protection guidance for
dissemination and implementation throughout the program for which it is created. The layering and
integration of the selected protection requirements documented in a PPP provide for the integration
and synchronization of CPI protection activities throughout DoD.
Once a PPP is in place, it should guide program office security measures and updated as threats
and vulnerabilities change or are better understood. Appendix B to the PPP is the
Counterintelligence Support Plan (CISP), which should be cited/referenced here.
See “Program Protection Plan Outline & Guidance,” Version 1.0, July 2011; copy available on
line at:
Prominent Individual. Someone who is widely known and has a favorable public reputation.
(DoDD S-5200.37, Management & Execution of Defense HUMINT, 9 Feb 2009)
Propaganda. Any form of adversary communication, especially of a biased or misleading nature,
designed to influence the opinions, emotions, attitudes, or behavior of any group in order to benefit the
sponsor, either directly or indirectly. (JP 1-02 and JP 3-13.2, Psychological Operations, 7 Jan 2010)
Proprietaries. A term used… to designate ostensibly private commercial entities capable of doing
business which are established and controlled by intelligence services to conceal governmental affiliation
of intelligence personnel and/or governmental sponsorship of certain activities in support of clandestine
operations. (Senate Report 94-755, Book I - Glossary, 26 Apr 1976)
Protection. The ability to prevent, mitigate adverse effects of attacks on personnel (combatant /non-
combatant) and physical assets of the United States, allies, and friends. (Joint Capability Areas
Taxonomy & Lexicon, 15 Jan 2008)
-- Also, preservation of the effectiveness and survivability of mission-related military and nonmilitary
personnel, equipment, facilities, information, and infrastructure deployed or located within or outside the
boundaries of a given operational area. (JP 1-02 and JP 3-0, Joint Operations, 11 Aug 2011)
263
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Protective Service Detail. Trained and armed protective security officials capable of providing continuous
protection for a designated individual. (DoDI 2000.12, DoD AT Program, 1 Mar 2012 w/ change 1 dated 9
Sep 2013)
Protective Intelligence (PI). CRIMINT [criminal intelligence] used to identify, analyze, and provide leads
for investigation into various direct and indirect threats to DoD personnel and property. It may provide
further details about persons who may have the interest, motive, intention, and capability of mounting
attacks against the DoD and its personnel. Additionally, it can aid DoD LEAs in gauging the potential
threat to and vulnerability of a targeted individual or property and may be used in determining or
preventing violence. (DoDI 5525.18, Law Enforcement Criminal Intelligence in DoD 18 Oct 2013)
Protective Measures. Those actions, procedures, or designs implemented to safeguard protected
information. (DSS Glossary)
Provocation. Activity designed to induce an individual, organization, intelligence service, or governments
to take action damaging to itself. (FBI FCI Terms) Also see dangle; double agent.
-- Also, activity intended to cause an individual, organization, intelligence service, or government to
take actions that can cause damage to itself. (Spy Book)
Provocation [aka Dangle]
“A provocation is an agent deployed by you to be recruited by an opponent and to perform his or her secret
work under your control as a channel to and weapon against your opponent.”
-- William R. Johnson, Thwarting Enemies at Home and Abroad, Georgetown University Press (2009), p.98
Prudent Risk. A deliberate exposure to potential injury or loss when the commander judges the outcome
in terms of mission accomplishment as worth the cost. (ADRP 6-0, Mission Command, May 2012)
Pseudonym. A code name assigned to an individual, place, or activity to enhance operational,
administrative, and communication security. (AFOSI Manual 71-142, OFCO, 9 Jun 2000)
-- Also, an assigned identity that is used to protect an individual’s true identity. (CNSSI No. 4009,
National Information Assurance Glossary, 26 April 2010)
Psychological Operations (PSYOP). Within DoD: None -- term rescinded. See Military Information
Support Operations (MISO).
Term changed to MISO IAW SECDEF Memo dated 3 Dec 2010.
Public Affairs (PA). Those public information, command information, and community relations activities
directed toward both the external and internal publics with interest in the Department of Defense. (JP 1-02
and JP 3-61, Public Affairs, 25 Aug 2010)
Public Diplomacy. 1). Those overt international public information activities of the United States
Government designed to promote United States foreign policy objectives by seeking to understand,
inform, and influence foreign audiences and opinion makers, and by broadening the dialogue between
American citizens and institutions and their counterparts abroad.
2). In peace building, civilian agency
efforts to promote an understanding of the reconstruction efforts, rule of law, and civic responsibility
through public affairs and international public diplomacy operations. Its objective is to promote and
sustain consent for peace building both within the host nation and externally in the region and in the
larger international community. (JP 1-02 and JP 3-07.3, Peace Operations, 17 Oct 2007)
Public Domain. In open view; before the public at large and not in private or employing secrecy or other
protective measures. (DSS Glossary)
264
Counterintelligence Glossary -- Terms & Definitions of Interest for CI Professionals (9 June 2014)
__________________________________________________________________________________________________
Public Information. Within public affairs, that information of a military nature, the dissemination of which
is consistent with security and approved for release. (JP 1-02 and JP 3-61, Public Affairs, 25 Aug 2010)
Publicly Available Information. Information that has been published or broadcast for public consumption,
is available on request to the public, is accessible on-line or otherwise to the public, is available to the
public by subscription or purchase, could lawfully be seen or heard by any casual observer, is made
available at a meeting open to the public, or is obtained by visiting any place or attending any vent that is
open to the public. (Attorney General Guidelines for National Security Investigations and Foreign
Intelligence Collection, 31 Oct 2003)
--Also, data, facts, instructions, or other material published or broadcast for general public
consumption; available on request to a member of the general public; lawfully seen or heard by any
casual observer; or made available at a meeting open to the general public. (Army Techniques
Publication 2-22.9, Open-Source Intelligence, 10 Jul 2012)
265

 

 

 

 

 

 

 

Content      ..     9      10      11      12     ..