Military reference books and manuals (2009-2023, Volume 7) - page 17

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 7)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     15      16      17      18     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 7) - page 17

 

 

Chapter 6
terrain on friendly maneuver. Intelligence requirements generally associated with offensive operations
are—
z
Determine what type of defense the enemy is employing.
z
Determine location, disposition, and orientation of enemy defense.
z
Determine enemy commander’s end state, objectives, decision points, and centers of gravity.
z
Determine enemy commander’s intent.
z
Identify terrain and weather that supports enemy defensive operations.
z
Identify terrain and weather that supports friendly movement and maneuver.
z
Determine the impact of civil considerations and displaced civilians on friendly and enemy
operations.
z
Identify the enemy’s disruption zone, to include counterreconnaissance forces, artillery, and
electronic warfare assets.
z
Identify the enemy battle zone.
z
Identify the enemy support zone, to include logistics and administrative elements, counterattack
forces, and reserve forces.
ANALYTIC SUPPORT TO DEFENSIVE OPERATIONS
6-5. A defensive task is a task conducted to defeat an enemy attack, gain time, economize forces, and
develop conditions favorable for offensive or stability tasks (ADRP 3-0). Defensive operations retain
decisive terrain or deny the enemy access to a vital area, attrite or fix the enemy as a prelude to offensive
operations, counter a surprise action by the enemy, or increase the enemy’s vulnerability by forcing the
enemy to concentrate his forces. (See ADRP 3-90).
6-6. The principal difference between defensive operations and other decisive action is the focus and
degree of detail of analysis required for determining the enemy’s offensive framework and the effects of
terrain on friendly defensive operations. Intelligence requirements generally associated with defensive
operations are—
z
Determine, locate, and/or track the enemy’s main and supporting efforts and likely enemy
avenues of approach and mobility corridors.
z
Locate and/or track enemy reserves.
z
Locate and/or track enemy reconnaissance assets.
z
Identify enemy’s use of special munitions.
z
Locate and/or track enemy close air support.
z
Identify enemy deception operations.
z
Determine enemy commander’s end state, objectives, decision points, and centers of gravity.
z
Determine enemy commander’s intent.
z
Identify defensible terrain.
z
Determine the impact of civil considerations and displaced civilians on friendly and enemy
operations.
6-7. Offensive operations are either force oriented or terrain oriented. Force-oriented operations focus on
the threat. Terrain-oriented operations focus on seizing and retaining control of the terrain and facilities.
Detailed IPB products, such as a modified combined obstacle overlay with intervisibility lines or an event
template, must be developed. (See FM 2-01.3 and FM 3-55 for more information on conducting IPB,
information collection, and the role of all-source in defensive operations.)
6-8. Analysts are involved in all aspects of the military decisionmaking process and IPB. Several analytic
techniques support activities and information requirements associated with defensive operations.
ANALYTIC SUPPORT TO STABILITY OPERATIONS
6-9. Stability operations is an overarching term encompassing various military missions, tasks, and
activities conducted outside the United States in coordination with other instruments of national power to
6-2
ATP 2-33.4
18 August 2014
Analytic Support to Decisive Action
maintain or reestablish a safe and secure environment, provide essential governmental services, emergency
infrastructure reconstruction, and humanitarian relief (JP 3-0).
6-10. The principal difference between stability operations and other decisive action is the focus and
degree of detail of analysis required for the civil aspects of the environment. Unlike major combat, an
environment dominated by offensive and defensive operations directed against an enemy force, stability
operations encompass various military missions, tasks, and activities that are not enemy-centric.
6-11. FM 3-07 constitutes the Army’s current doctrine on stability operations. In order to conduct the
analysis required for this type of operation, leaders, staffs, and Soldiers must understand the nature of
stability operations and the intelligence requirements associated with it.
6-12. Constant awareness and shared understanding of civil considerations about the environment are
crucial to long-term operational success in stability operations. Analysts should classify civil considerations
(ASCOPE) into logical groups (tribal, political, religious, ethnic, and governmental). Intelligence analysis
during operations that focus on the civil population as a center of gravity requires a different mindset and
different techniques than an effort that focuses on defeating an adversary militarily.
6-13. Some situations (particularly crisis-response operations) may require analysts to focus primarily
upon the effects of terrain and weather, as in the case of natural disasters or upon the resulting human
catastrophe after a natural disaster. Disasters (such as wind storms, hurricanes, typhoons, floods, tsunamis,
wild fires, landslides, avalanches, earthquakes, and volcanic eruptions) may occur without warning.
Human-caused catastrophes (such as civil conflict, acts of terrorism, sabotage, or industrial accidents) may
develop over time. The speed at which an event occurs will dictate how analysts will conduct their
assessments and with whom they will share their intelligence. (See FM 2-01.3 and FM 3-55 for more
information on conducting IPB, information collection, and the role of all-source in stability operations.)
ANALYTIC SUPPORT TO DEFENSE SUPPORT OF CIVIL AUTHORITIES
6-14. DSCA is support provided by U.S. Federal military forces, Army civilians, contract personnel and
component assets, and National Guard forces (when the Secretary of Defense, in coordination with the
Governors of the affected states, elects and requests to use those forces in Title 32, U.S. Code, status). This
support is in response to requests for assistance from civil authorities for domestic emergencies, law
enforcement support, and other domestic activities, or from qualifying entities for special events. (See
JP 3-28 for more information on DSCA support.)
6-15. DSCA is a task that takes place only inside the United States. Some DSCA tasks are similar to
stability tasks. DSCA is always conducted in support of another primary or lead Federal agency and
consists of four tasks:
z
Provide support for domestic disasters.
z
Provide support for domestic civilian law enforcement.
z
Provide support for domestic chemical, biological, radiological, or nuclear incidents.
z
Provide other designated domestic support.
6-16. The Attorney General of the United States has lead responsibility for criminal investigations of
terrorist acts or terrorist threats by individuals or groups inside the United States. The Attorney General
typically acts through the Federal Bureau of Investigation and cooperates with other Federal departments
and agencies engaged in activities to protect national security. The Attorney General and these departments
and agencies coordinate the activities of other members of the law enforcement community to detect,
prevent, preempt, and disrupt terrorist attacks against the United States.
6-17. The types of intelligence support required for successful DSCA operations are the same as those
required for successful offense, defense, and stability operations. Analysts support the commander’s
decisionmaking process by answering pertinent commander’s critical information requirements and PIRs.
Analysts supporting DSCA leverage traditional Department of Defense and other government information
capabilities while assuring strict adherence to all legal frameworks. One major difference that an analyst
must consider is that only unclassified information can be exchanged between Department of Defense and
law enforcement.
18 August 2014
ATP 2-33.4
6-3
Chapter 6
6-18. In DSCA, analysts are expected to provide an analysis of the physical environment, weather impacts,
terrorist threats, and chemical, biological, radiological, or nuclear hazards. Instead of conducting IPB,
analysts conduct a modified intelligence preparation of the operational environment or situation assessment
whereby the analyst continuously analyzes information regarding terrain, weather, and civil considerations.
This is critical in the development of an event template or event matrix.
6-19. It is also important that analysts assigned to support a DSCA mission understand the roles and
responsibilities of interagency partners, National Guard personnel, and Federal government intelligence
personnel, as well as the intelligence assets, platforms, and analytical capabilities provided by these
organizations. All collection must be done in coordination with the Attorney General’s designated lead.
ANALYTIC TECHNIQUES IN DECISIVE ACTION
6-20. Intelligence analysis in the Army is not usually conducted as an individual effort; it is done as a team
or analytic element. Different situations require the application of different and often multiple techniques.
Although no two analysts may employ the same techniques to reach a conclusion, experience has shown
there are preferred techniques. The most significant factors when conducting intelligence analysis during
any decisive action are time and whether or not the intelligence element is equipped to conduct the
appropriate analytic techniques. Although there are other factors, both the accuracy and resolution of
intelligence analysis are dependent upon time.
6-21. Analysts may find some techniques more or less useful for certain operations. Tables 6-1, 6-2, and
6-3 on pages 6-5 through 6-8 provide a quick reference guide to how each of the basic structured analytic
techniques (see chapter 3) and diagnostic analytic techniques (see chapter 4) may be employed and the
operation in which they are most often used. These tables are to be used as a guide and not intended to limit
an analyst’s creativity in choosing appropriate techniques.
6-4
ATP 2-33.4
18 August 2014
Analytic Support to Decisive Action
Table 6-1. Use of basic diagnostic analytical techniques
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Sorting
• Review of large
• Any stage.
X
X
X
amounts of data.
• Generating hypotheses
• Review of multiple
(brainstorming, ACH).
categories of
• Functional analysis.
information.
• Situational logic.
Matrices
• Isolating critical
• ACH.
X
X
data.
• Link analysis.
• Enabling analytic
• Various pattern
focus.
analysis.
Threat
Reviewing most likely
• Indicators.
X
X
X
Intentions
and reasonable
• ACH.
Matrix
alternatives.
• Functional analysis.
• Situational logic.
Event
Visualizing structure,
• Indicators.
X
X
Mapping
delineating events in
• Brainstorming.
a scenario.
Event Trees
Clarifying alternative
• Chronologies and
X
X
event sequences with
timelines.
potential future
• Indicators.
outcomes.
• ACH.
• Various pattern
analyses.
Subjective
Identifying potential
• Bayesian analysis.
X
X
X
Probability
actions of threat,
• Rules of verification.
neutral, and friendly
entities.
Weighted
Identifying potential
• Bayesian analysis.
X
X
X
Ranking
actions of threat,
• Subjective probability.
neutral, and friendly
• Rules of verification.
entities.
Deception
Helping to determine
• All other analytic
X
X
X
Detection
when to look for
techniques.
deception.
Key
Making assumptions
• All other analytic
X
X
X
Assumptions
explicit and
techniques.
Check
understood.
Quality of
Evaluating the
• All other analytic
X
X
X
Information
completeness of
techniques.
Check
available information.
Indicators
Identifying potential
• All other analytic
X
X
X
actions of threat,
techniques.
neutral, and friendly
entities.
ACH analysis of competing hypotheses
DSCA defense support of civil authorities
18 August 2014
ATP 2-33.4
6-5
Chapter 6
6-22. Table 6-2 provides a quick reference guide to how each of the core analytic techniques (see chapter 5)
may be employed and the operations in which they are most often used.
Table 6-2. Use of core Army analytical techniques
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Brainstorming
• Identifying potential
Delphi techniques.
X
X
actions of threat,
neutral, and friendly
entities.
• Developing
information collection
strategies.
• Developing targeting
strategies.
Comparison
Identifying potential
• Modeling.
X
X
X
actions of threat, neutral,
• Scientific method
and friendly entities.
Mathematical
Determining the
Functional analysis.
X
X
X
Analysis
capabilities and
limitations of an
organization.
Situational
Identifying potential
Generation of
X
X
X
Logic
actions of threat, neutral,
alternative futures.
and friendly entities.
Analyzing Complex Networks and Associations
Link Analysis
Evaluating relationships
• Various pattern
X
X
X
between organizations
analyses.
and individuals.
• Network analysis.
• Social network
analysis.
Network
Developing high-payoff
• Various pattern
X
X
X
Analysis
targets and high-value
analyses.
targets.
• Network analysis.
• Social network
analysis.
Sociometrics/
Evaluating the effect of
• Various pattern
X
X
X
Social
civil considerations.
analyses.
Network
• Network analysis.
Analysis
• Social network
analysis.
Pattern Analysis
Chronologies
Organizing events or
• Event trees.
X
X
X
and Timelines
actions.
• Link analysis.
• Indicators.
• Pattern analysis.
• Network analysis
• Situational logic.
• Pattern of life
analysis.
6-6
ATP 2-33.4
18 August 2014
Analytic Support to Decisive Action
Table 6-2. Use of core Army analytical techniques (continued)
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Pattern
Analyzing threat, neutral,
• Event trees.
X
X
X
Analysis Plot
and friendly entity
• Link analysis.
Sheet
patterns of behavior.
• Indicators.
• Pattern analysis.
• Network analysis.
• Situational logic.
• Pattern of life
analysis.
Incident
Analyzing threat, neutral
• Event trees.
X
X
X
Overlay
and friendly entity
• Link analysis.
patterns of behavior.
• Indicators.
• Pattern analysis.
• Network analysis.
• Situational logic.
• Pattern of life
analysis.
Time Event
Analyzing threat, neutral
• Event trees.
X
X
X
Chart
and friendly entity
• Link analysis.
patterns of behavior.
• Indicators.
• Pattern analysis.
• Network analysis.
• Pattern of life
analysis.
Pattern of Life
Analyzing threat, neutral
• Event trees.
X
X
X
Analysis
and friendly entity
• Link analysis.
patterns of behavior.
• Indicators.
• Various pattern
analysis.
• Link analysis.
• Network analysis.
• Social network
analysis.
6-23. Appendix A discusses emerging analytic techniques in the Army. These emerging techniques include
contrarian, imaginative, and structured analytic techniques. Additionally, center of gravity analysis,
functional analysis, and modeling techniques are described more fully in FM 2-01.3.
6-24. Table 6-3 on page 6-8 provides a quick reference guide to how each of the contrarian, imaginative,
structured analytic techniques, and analytic techniques discussed in FM 2-01.3 may be employed and the
operations in which they are most often used.
18 August 2014
ATP 2-33.4
6-7
Chapter 6
Table 6-3. Use of emerging and other structured analytical techniques
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Devil’s
Highlighting
Any technique;
X
X
X
Advocacy
weaknesses
often employs a
and fallacy in
technique NOT
current
employed by the
analytical
original analytic
assessments.
team.
Team A/
Comparing and
All other analytic
X
X
X
Team B
contrasting two
techniques.
equally valid
analytic
assessments.
High-Impact/
Highlighting a
All other analytic
X
X
Low-
seemingly
techniques.
Probability
unlikely event
that would have
major
consequence.
“What if”
Determining
All other analytic
X
X
Analysis
indicators
techniques; the
through
result is often
imagined
Indicators.
“hindsight.”
Red Hat
Seeking
All other analytic
X
X
X
Analysis
forecast actions
techniques; the
of the enemy as
result is often
if the analyst
Indicators.
were the
enemy.
Counterfactual
Analyzing
All other analytic
X
X
Reasoning
threat, neutral
techniques.
and friendly
entity patterns
of behavior and
their causes.
Outside-In
Identifying
• Situation logic.
X
X
Thinking
potential
• ACH.
actions of
• Comparison.
threat, neutral,
and friendly
• Probability.
entities.
• Subjective
Developing
probability.
information
collection
strategies.
Developing
targeting
strategies.
6-8
ATP 2-33.4
18 August 2014
Analytic Support to Decisive Action
Table 6-3. Use of emerging and other structured analytical techniques (continued)
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Threat
A dedicated
All other analytic
X
X
Emulation Red
team with
techniques; the
Team
specialized
result is often
training seeking
Indicators.
to forecast
actions of the
enemy.
Red Team
A decision
All other
X
X
support group
structured
designed to
analytic
ensure
techniques and
alternative
more.
perspectives
are considered
in
decisionmaking.
Alternative
Identifying
Situational logic.
X
X
Future
potential
Analysis
actions of
threat, neutral,
and friendly
entities.
Morphological
Identifying
Situational logic.
X
X
Analysis with
potential
Multiple
actions of
Scenarios
threat, neutral,
Generation
and friendly
entities.
Analysis of
Identifying
• Applying
X
X
X
Competing
potential
theory.
Hypotheses
actions of
• Comparison.
threat, neutral,
• Generation of
and friendly
alternative
entities.
futures.
Applying
Analyzing
• ACH.
X
Theory
threat, neutral,
• Comparison.
and friendly
• Bayesian
entity patterns
analysis.
of behavior.
Delphi
Determining
Brainstorming.
X
X
Techniques
second- and
third-order
effects of threat,
neutral, and
friendly actions.
Futures Wheel
Determining
• Situational
X
X
X
second- and
logic.
third-order
• Brainstorming.
effects of threat,
neutral, and
friendly actions.
18 August 2014
ATP 2-33.4
6-9
Chapter 6
Table 6-3. Use of emerging and other structured analytical techniques (continued)
Technique
Used for:
Often used with:
Offensive/
Stability
DSCA
Defensive
Knowledge
Developing
• Systemology.
X
X
X
Planning
information
• Network
collection
analysis.
strategies.
Rules for
Identifying
• Bayesian
X
X
X
Verification
potential
analysis.
actions of
• Probability.
threat, neutral,
• Subjective.
and friendly
entities.
Systemology
Developing
• Knowledge
X
X
high-value
planning.
targets and
• Network
high-payoff
analysis.
targets.
Center of
Developing
• Network
X
X
X
Gravity
threat
analysis.
Analysis
characteristics
• Mathematical
and threat
analysis.
models.
Functional
Developing
Mathematical
X
X
X
Analysis
threat charac-
analysis.
teristics and
threat models.
Modeling
Identifying
• Comparison.
X
X
X
potential
• Scientific
actions of
method.
threat, neutral,
and friendly
entities.
ACH analysis of competing hypotheses
DSCA
defense support of civil authorities
ANALYTIC SUPPORT TO UNIQUE ACTIVITIES
6-25. The Army engages in a variety of unique activities which may lend themselves to specific analytic
techniques. These unique activities do not alter how analytic techniques are employed; only the information
considered in the analytic processes changes.
BUILDING PARTNERSHIP CAPACITY
6-26. Unified action may require inter-organizational efforts to build the capacity of partners to secure
populations, protect infrastructure, and strengthen institutions as a means of protecting common security
interests. Building partner capacity is the outcome of comprehensive inter-organizational activities, programs,
and engagements that enhance the ability of partners for security, governance, economic development,
essential services, rule of law, and other critical Government functions. Army security cooperation activities
enable other inter-organizational coordination to build partner capacity for governance, economic
development, essential services, rule of law, and other critical government functions. Through its presence
along the range of military operations, the Army is involved in many of these activities during military
engagement, limited interventions, peace operations, irregular warfare, and major combat operations.
6-27. Army security cooperation activities foster the development of information and intelligence- sharing
agreements, enable a common understanding of the threat environment, support information sharing on
disaster response issues, and establish procedures necessary to prevent the compromise of sensitive
information. (See FM 3-22 for more information on Army security cooperation activities.)
6-10
ATP 2-33.4
18 August 2014
Analytic Support to Decisive Action
6-28. Analysts involved in security cooperation activities must be prepared to teach analysis to their
counterparts and encourage them to participate in analyzing, preparing, and briefing the analysis to the
foreign unit commander. This instruction could involve any number of analytical techniques and should be
gauged to complement the foreign partner’s intelligence capability and capacity.
PROTECTION
6-29. Protection relates to those actions taken by the commander to preserve the force in order to apply
maximum combat power. Preserving the force includes protecting personnel
(combatants and
noncombatants), physical assets, and information of the U.S. and multinational military and civilian
partners. The protection warfighting function facilitates the commander’s ability to maintain the force’s
integrity and combat power. Protection is a continuing activity; it integrates all protection capabilities to
safeguard bases, secure routes, and protect forces. Protection actions considered by the analyst include
antiterrorism, operations security, information protection, area security, air and missile defense, and
personnel recovery.
6-30. Protection can be achieved through knowledge and understanding. An intelligence summary may
provide Soldiers with indicators or warnings of a specific threat tactic. This knowledge may result in force
preservation if actions are taken that prevent or reduce the probability of the enemy’s actions. Analysts use
mission variables and assessments of environmental threats and hazards to determine when and where
protection can be achieved through reinforcing action and application or through complementary effect.
6-31. Analysts must evaluate the situation and determine the most appropriate analytic techniques to
employ analysis in support of the protection warfighting function.
SYNCHRONIZE INFORMATION-RELATED CAPABILITIES
6-32. Synchronize information-related capabilities (formerly known as inform and influence activities) is
defined as the integrating activities within the mission command warfighting function that ensure themes
and messages designed to inform domestic audiences and influence foreign friendly, neutral, threat, and
enemy populations are synchronized with actions to support unified land operations. Synchronize
information-related capabilities incorporates components and enablers expanding the commander’s ability
to use other resources.
(See ADP 6-0 for more information on synchronizing information-related
capabilities.)
6-33. Components of synchronize information-related capabilities are military capabilities or activities
specifically designed to influence and inform select leaders, decisionmakers, and audiences whose behaviors
and perceptions are deemed integral to mission success. Commanders are not restricted to just these
components when synchronizing information-related capabilities. Commanders may add or subtract enablers
as the situation dictates. The components of synchronize information-related capabilities are—
z
Public affairs.
z
Military information support operations.
z
Soldier and leader engagement.
z
Military deception.
6-34. Enablers of synchronize information-related capabilities refers to military capabilities or activities
whose primary purpose can be used to conduct information-related operations. Common enablers include
operations security, civil affairs operations, combat camera, and cyber/electromagnetic activities.
6-35. Planning functions for synchronizing information-related capabilities depend on the intelligence
warfighting function for three reasons:
z
The intelligence warfighting function plans much of the Army’s information collection that
helps define the information environment and identifies potential audiences or physical targets
for consideration.
z
Intelligence provides real-time insight into the adversary’s synchronization of information-
related capabilities.
z
Intelligence provides capabilities that support the collection of metrics for effects-based assessment.
18 August 2014
ATP 2-33.4
6-11
Chapter 6
6-36. Intelligence analysis may be conducted in support of all the components and enablers of
synchronizing information-related capabilities, as designated by the commander. Analysts must evaluate
the situation and their commander’s objective and intent and determine the most appropriate analytic
techniques to employ in support of synchronizing information-related capabilities.
6-12
ATP 2-33.4
18 August 2014
Chapter 7
Analytic Support to Unique Missions
This chapter describes the analytic support required in the unique missions of
counterinsurgency, counter-improvised explosive devices, and site exploitation.
OVERVIEW
7-1. The Army engages in a variety of unique operations that may lend themselves to specific analytic
techniques. As with analytic support to decisive action, analytic techniques do not change; only the
information considered in the analytic processes changes.
7-2. Intelligence analysis support to any operation involves separating useful information from
misleading information, using experience and reasoning, and reaching an assessment or conclusion based
on fact and/or sound judgment. The conclusion is based on the intelligence analyst’s experience, skill,
knowledge, and understanding of the operation; knowledge of the various intelligence disciplines;
information collection; an understanding of all the threats within an operational environment; and an in-
depth understanding of the threat’s military and political structure. Intelligence analysis must support the
commander, staff, and targeting.
7-3. As discussed in chapter chapters 3 through 7, analysts must evaluate the circumstances and choose an
appropriate analytic technique. (See FM 3-55 for doctrine on information collection and FM 2-01.3 for
information on IPB. See also intelligence doctrine on planning requirements and assessing collection.)
7-4. As with any analysis, the most significant factor effecting analysis is time. Time includes both the
span of time the analyst has to conduct analysis of a problem and how timely the final analytic assessment
is to the decisionmakers. The unique operations are often especially time constrained for the
decisionmakers and the analyst. Therefore, care must be taken to ensure quality analytic assessments are
provided in a timely manner.
COUNTERINSURGENCY
7-5. Analytic support to counterinsurgency operations must facilitate understanding of the operational
environments, placing emphasis on the populace, host nation, and insurgents. The memory aid of ASCOPE
refers to the six categories of civil considerations
(see figure 3-1 on page 3-4). Analytic techniques
successfully employed are functional analysis, link analysis, modeling, pattern analysis, situational logic,
and network analysis. Counterinsurgency may involve highly organized paramilitary groups, loosely
structured nodes, or both.
7-6. Using activities and association matrices, analysts can pinpoint the optimal targets for further
intelligence collection, identify key personalities within an organization, and considerably increase the
understanding of an organization and its structure. While producing an assessment in a counterinsurgency
environment is primarily an intelligence responsibility, it requires close coordination with operations, civil
affairs, public affairs, and military information support operations to be effective.
7-7. Intelligence analysis in a counterinsurgency environment must include consideration of the AO’s
distinguishing attributes—terrain, society, infrastructure, and the threat. Analysts should identify and
understand the environmental characteristics from a counterinsurgent, insurgent, and host-nation
population’s perspective to facilitate understanding of the operational environment.
18 August 2014
ATP 2-33.4
7-1
Chapter 7
COUNTER-IMPROVISED EXPLOSIVE DEVICE
7-8.
(FOUO) Analytic support to counter-improvised explosives device (CIED) operations must facilitate
the development of IED networks and nodes and support to targeting those networks. Conducting
predictive intelligence in asymmetrical operations has truly proven to be a difficult task. It is improbable, if
not impossible, to determine with any degree of certainty that an IED will certainly be detonated at a
precise location at a given time; this is regardless of the amount of available data, collection asset, or other
information.
7-9. Intelligence analysis is the mental process of receiving and interpreting old and new information (raw
data) from designated collection assets as well as from open sources (civilians, Soldiers on the battlefield,
or civil affairs), and integrating that information into the overall view of the operational environment.
7-10. (FOUO) Two of the basic types of analysis used at all echelons in CIED operations are individual
component analysis and nodal component analysis. Both types of analysis can be subdivided into near-,
intermediate-, and long-term analysis.
z
Individual component analysis actions focus on what the individual (the one) is doing near,
intermediate, and long term.
z
Nodal component analysis actions focus on multiple people of importance in an AO; this
analysis develops an understanding of interrelationships between them and the ideas and beliefs
driving their actions.
7-11. (FOUO) Both types of analysis differ in that individual component analysis information provides
threat warning and metrics of enemy capabilities, while nodal component analysis provides intelligence for
network targeting.
7-12. (FOUO) Once the analyst has determined how the IED network is constructed, it is also important to
understand how the various activity nodes interact with one another. The goal is to produce a model of the
threat IED operations that captures the processes present in the threat IED network. Intelligence briefs on
threat activity within each node should be analyzed to produce signatures and vulnerabilities. This mapping
will produce a list of capability gaps that will be the basis for funding priorities.
7-13. (FOUO) Figure 7-1 is an example of an IED activity model. For purposes of this illustration, analytic
techniques successfully employed are functional analysis, link analysis, modeling, pattern analysis,
situational logic, and network analysis. Table 7-1, which is not all-inclusive, lists possible nodes located in
an IED network. Some IED networks will contain each node listed; others may have more nodes or not
include nodes. Analysts must understand each node will be structured differently.
7-14. An analyst must determine what is moving between elements and nodes; how actions are executed;
and how much materiel is being transferred. (Refer to chapter 5 for a discussion on link analysis, pattern
analysis, situational logic, and network analysis. See FM 2-01.3 for more information on functional
analysis and modeling.)
7-15. Once modeling has taken place, the result should assist in understanding a specific AO for a specific
snapshot in time. The models are constantly evolving and can be adapted by the analyst to assist in
understanding any operational environment.
7-2
ATP 2-33.4
18 August 2014
FOR OFFICIAL USE ONLY
Analytic Support to Unique Missions
Figure 7-1. Example of an improvised explosive device activity model
Table 7-1. Possible nodes located in an improvised explosive device network
FOUO
LEADERSHIP FUNCTION—When determining what type of activities may take place, consider:
International Support
Emir or front commander level leader of a country, a stateless leader, or a
and Leadership:
transnational influence directing the political agenda, directing information operations
directing funds to the nodes.
Local Leadership:
Leadership of a cell that carries out processes contained in the other nodes.
Facilitation of the factory to make improvised explosive devices (IEDs) includes
training grounds, money transfers, and/or messengers. Target selection to produce
the desired effects for the information campaign.
National and/or Regional
Emir or front commander level leader of a region directing the political agenda,
directing of information operations, directing funds to the nodes. Knowledge of the
Leadership:
respective populations and terrain providing efficient use of resources. Local target
type selection for the information campaign.
PLANNING FUNCTION—When determining what type of activities may take place, consider:
Adaptation and/or
Take ideas from the assessment node and try out the concepts. Research and
Research and
development will include adapting to effective multinational force countermeasures.
Development
Recruiting
People at all levels that recruit willingly, or force coerced people, into performing tasks in
the other nodes. Looking for all skill levels. Finding and smuggling militants into the joint
operations area who are willing to be messengers, emplacers, or suicide bombers.
Surveillance
Watching multinational and U.S. forces for target selection opportunities and viability
of locations. Surveillance also verifies or denies timelines, friendly and enemy tactics,
techniques, and procedures.
Training
Willing or coerced people are evaluated and trained to act in other nodes.
FOUO
18 August 2014
ATP 2-33.4
7-3
FOR OFFICIAL USE ONLY
Chapter 7
Table 7-1. Possible nodes located in an IED network (continued)
FOUO
LOGISTICS FUNCTION—When determining what type of activities may take place. Consider:
Inventory
Storage and maintenance of completed IEDs while waiting for orders to ingress and
emplace.
Manufacture
Bombmakers take raw materials from storage and construct the desired type of IED
and deliver it to the inventory node.
Procurement
Acquisition and production of bomb components, purchased or stolen. Local support
that is directly related to construction, emplacement, detonation, and expertise on
new bombmaking techniques.
Storage
Secure storage of components before they are used to build an IED.
EXECUTE FUNCTION—When determining what type of activities may take place, consider:
Assessment
Use the cataloged effects collected in the observation node to quantify the
performance of the device type. Generate ideas on how to make the device better
and provide it to the adaptation and/or research and development node.
Detonation
Initiation of the IED using arming signals from monitoring node and fusing signals
from victim. Output is the physical effect on the victim.
Egress
After detonation, and/or after friendly forces arrive, removal of evidence and
personnel to a secure location. Movement post-detonation of the personnel who
carried out the detonation includes anyone who was there to observe the attack and
report combat assessment.
Emplace
Burying or disguising the IED, running the wires for arming switches, placing the
antenna for reception from the monitoring point. For vehicle-borne improvised
explosive devices, parking or driving the car next to the target. For suicide bomber,
walking the IED to the target.
Ingress
Moving the IED from the inventory location to the detonation point using a secure
transport mechanism and using care not to detonate IED.
Monitor
Observation of IED location from a secure vantage point. Output is the arming signal to
the IED. Performed to keep the IED secure and protect assets until target is present.
Observe
Observation and cataloging of the effect on the target, simply data collection, no
assessment or analysis.
SUPPORT FUNCTION—When determining what type of activities may take place, consider:
Domestic Support
Local populace support and supporting infrastructure that are involved with dual use
items. Noncombatant support in the form of food, shelter, and water that supports
activities in other nodes.
Post-Detonation
Use of media images to engender support for international fundraising and local
Information Activities
support. Any use of the media to lend support to the local threat. Use of speeches by
international leaders, footage from recent attacks, and/or interviews with citizens.
FOUO
SITE EXPLOITATION
7-16. Site exploitation is a series of activities to recognize, collect, process, preserve, and analyze
information, personnel, and/or materiel found during the conduct of operations (JP 3-31). Site exploitation
contributes to exploitation, defined as taking full advantage of any information that has come to hand for
tactical, operational, or strategic purposes.
7-17. A sensitive site is described as a geographically limited area with special diplomatic, informational,
military, or economic sensitivity to the United States. The S-2 has additional planning and support
considerations for a sensitive site due to national and strategic implications. (See ATTP 3-90.15 and
JP 3-31 for additional information on sensitive site exploitation.)
7-4
ATP 2-33.4
18 August 2014
FOR OFFICIAL USE ONLY
Analytic Support to Unique Missions
7-18. Complementary enablers and capabilities that support intelligence analysis for site exploitation are—
z
Collaboration and the intelligence warfighting function.
z
Biometrics and biometrics-enabled intelligence.
z
Law enforcement.
z
Defense Forensics Enterprise and forensic-enabled intelligence.
z
Chemical, biological, radiological, and nuclear.
z
Explosive ordnance disposal assets.
z
Joint Improvised Explosive Device Defeat Organization (also called JIEDDO) capabilities.
z
Joint Improvised Explosive Device Defeat Organization Knowledge Information Fusion
Exchange (also called JKNIFE).
z
Expeditionary forensic laboratories.
z
Military Intelligence companies’ multifunctional teams.
z
Counterinsurgency Targeting Program.
z
Counter Radio-Controlled IED Electronic Warfare.
z
Counter-IED Operations Integration Center.
z
International CIED teams.
7-19. The collection and analysis of items of forensic value have become vital to the intelligence and
targeting efforts, but are only useful if the value of the materiel is recognized. Exploitation depends on
individuals who have a fundamental awareness of the importance of the information potential of items
available for collection onsite. The decision regarding what materiel to collect and exploit should primarily
be based on the contextual significance of the items.
7-20. Site exploitation provides information that allows the commander and staff to identify and engage
friendly, neutral, and hostile networks that influence the operational environment. The information
provided by site exploitation can be used to build a detailed knowledge of a network’s relational dynamics
and to do so within the context of a dynamic operational environment. Techniques successfully employed
in analysis of information derived from site exploitation include—
z
Association matrix, which portrays the existence of an association
(known or suspected)
between individuals.
z
Activities matrix analysis, which shows the relationships in large datasets by establishing the
similarities between the nodes and links in a network of people.
z
Pattern analysis, which is used to show the location of the results of a site exploitation and the
time. This tool supports site exploitation targeting to answer the question of where and when
certain materiel is detected and collected.
7-21. When supporting site exploitation, intelligence analysts should share data, information, and
intelligence through proper channels with other intelligence organizations. These intelligence organizations
will assist the analyst in analyzing the information, material, and persons gathered through site exploitation
and produce intelligence.
7-22. Archived data can be a valuable source of information and may aid future targeting, intelligence
analysis, and/or support to legal proceedings. In addition, archived data can provide historical context to
current and future operations and enhanced opportunities to respond to critical requests for information.
7-23. Units must establish connectivity with intelligence organizations, explosive ordnance disposal,
theater laboratories, and other organizations to access the appropriate archived data. Harmony is the
primary archive database. It is the national intelligence database for foreign document and media
exploitation and translations management. It is the single, comprehensive bibliographic reference for all
available primary source foreign technical and military documents and their translations. Harmony supports
tactical through strategic users. It is available to all units with access to SECRET Internet Protocol Router
Network, Joint Worldwide Intelligence Communications Systems (also called JWICS), and StoneGhost
networks.
18 August 2014
ATP 2-33.4
7-5
This page intentionally left blank.
Appendix A
Emerging Analytic Techniques
This appendix discusses some of the more common techniques in use at the strategic
and operational levels. The techniques often incorporate multiple basic structured
analytic techniques in combination with diagnostic techniques. These techniques
discussed are categorized under contrarian techniques, imaginative techniques, and
structured analytic techniques although there is often overlap in specific techniques.
OVERVIEW
A-1. Emerging analytic techniques are not new. As discussed in this publication, emerging techniques are
those that are beginning to be used in the Army but are not so common as to be used regularly at all
echelons. These techniques may originate in the Defense Intelligence Agency, the Central Intelligence
Agency, business, academics, and other organizations, and areas of expertise. Army analysts are finding
some of the techniques, often in a modified format, to bring value to analytic assessments.
CONTRARIAN TECHNIQUES
A-2. Contrarian techniques challenge ongoing assumptions and broaden possible outcomes. They help the
analyst to understand intentions of adversaries especially when not clearly stated or known. Contrarian
techniques look at the problem from different (often multiple) perspectives, and in so doing allow analysts
to better accept analytic critique and grant greater avenue to explore and challenge analytical arguments
and mindsets. Proper technique application helps analysts ensure preconceptions and assumptions are
thoroughly examined and tested for relevance, implication, and consequence.
A-3. There are many contrarian techniques; however, this manual discusses only the following:
z
Devil’s advocacy.
z
Team A/Team B.
z
High impact/Low probability analysis.
z
“What If” analysis.
z
Red Hat analysis.
z
Counterfactual reasoning.
DEVILS ADVOCACY
A-4. Devil’s advocacy is a process for critiquing a proposed analytic assessment, judgment, plan, or
decision, usually by a single analyst not previously involved in the deliberations that led to the proposed
assessment.
Facts
A-5. Devil’s advocacy is most effective when used to challenge an analytic consensus or a key assumption
regarding a critically important intelligence question. On those issues that one cannot afford to get wrong,
devil’s advocacy can provide further confidence that the current analytic line will hold up to close scrutiny.
Individual analysts can often assume the role of the devil’s advocate if they have some doubts about a
widely held view; or a leader might designate an analyst to challenge the prevailing wisdom in order to
reaffirm the group’s confidence in those assessments.
18 August 2014
ATP 2-33.4
A-1
Appendix A
A-6. In some cases, the analyst or a team can review a key assumption of a critical judgment in the course
of their work, or a separate analytic product can be generated that arrays all the arguments and data that
support a contrary assessment or hypothesis.
A-7. The devil’s advocacy process can highlight weaknesses in a current analytic judgment or help to
reaffirm the analyst’s confidence in the assessment by—
z
Explicitly challenging key assumptions to see if they will not hold up under some circumstances.
z
Identifying any faulty logic or information that would undermine the key analytic judgments.
z
Presenting alternative hypotheses that would explain the current body of information available to
analysts.
A-8. Successful application of devil’s advocacy could result in—
z
Determining the current analytic line was sound.
z
Determining the argument is still the strongest, but there are areas where further analysis is
needed.
z
Determining some serious flaws in logic or supporting evidence that suggests the analytic line
needs to be changed.
A-9. Devil’s advocacy challenges a single strongly held view by building the best possible case for an
alternate explanation. The analyst would apply it to challenge an analytic consensus or a key assumption
regarding a critical intelligence question, and the value added in using this specific technique is that it
highlights weaknesses in current analytic judgment or helps to reaffirm one’s confidence in that current
analytic judgment.
The Method
A-10. The devil’s advocate is charged with challenging the proposed assessment by building the strongest
possible case against it. There is no prescribed procedure, but the following steps should be followed at a
minimum:
z
Outline the main points and key assumptions and characterize the evidence supporting current
analytic view.
z
Select one or more assumptions that appear the most susceptible to challenge.
z
Review the data used to determine questionable validity, possible deception, and the existence of
gaps.
z
Highlight evidence that supports an alternative hypothesis or contradicts current thinking.
z
Present findings that demonstrate flawed assumptions, poor evidence, or possible deception.
Devil’s Advocacy Tips
A-11. The devil’s advocate should keep the following in mind as the problem set or assessment is
examined:
z
What were the analytic processes used to create this assessment?
z
What are the sources of uncertainty within the assessment?
z
What are the critical assumptions within the assessment?
z
What is the diagnosticity of the evidence provided or cited within the assessment?
z
Does any of the evidence appear anomalous? Where perhaps does it deviate from the norm of
what we would expect to see?
z
Were there any changes in the broad environment in which events are happening (or have
happened)?
z
Was an alternative decision model used within the assessment? If so, can you see why and where
it was applied? Perhaps we cannot clearly see how a conclusion or finding was reached nor
understand the assessment’s rational process.
z
Availability of cultural expertise.
A-2
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
z
Are there indicators of possible deception that the assessment failed to address or provide
suitable explanation?
z
Are there any remaining information gaps present (within the assessment) that hinder analytic
ability to bring the assessment to a decisive conclusion? Do those information gaps still exist or
do we now possess more relevant data?
A-12. The devil’s advocate should consider drafting a separate contrarian paper and/or assessment that lays
out the arguments for a different analytic conclusion if the review uncovers major analytic flaws. The
devil’s advocate must be sure any products generated clearly lay out the conventional wisdom and are
identified as an explicitly devil’s advocate project to avoid confusion with the current accepted analytic
assessment.
TEAM A/TEAM B
A-13. Team A/Team B is a process for comparing, contrasting, and clarifying two or more equally valid analytic
assessments. This is done by multiple teams of analysts, each working along different lines of analysis. Team
A/Team B involves separate analytic teams that contrast two (or more) views or competing hypotheses.
Facts
A-14. If there are at least two competing views within an analytic office, then Team A/Team B analysis can
be the appropriate technique to use to clarify the issue. Analysts or the analytic team leader applies this
technique to challenge (if not clarify) two or more competing views or opinions. The value added in using
this specific technique is that its usage can help opposing groups see merit in the other groups’ perspective.
This reduces friction and helps narrow the differences so everyone gets their say.
Note. If opposing positions are well established, it can be useful to place analysts on teams that
will advocate positions they normally do not support; forcing analysts to argue the other side
tends to make them more aware of their own mindset.
A-15. Developing a full-blown Team A/Team B requires a significant commitment of analytic time and
resources. Consider carefully if the analytic issue merits the attention.
The Method
A-16. There are two distinct phases within the method: analytic phase and debate phase. The steps within
the analytic phase are—
z
Step 1. Identify the two or more competing hypotheses.
z
Step 2. Form teams and designate individuals to develop the best case for each hypothesis.
z
Step 3. Review information that supports each respective position.
z
Step 4. Identify missing information that would support or bolster their hypotheses.
z
Step 5. Prepare structured argument with an explicit discussion of—
„ Key assumptions.
„ Key piece of evidence.
„ Articulation of the logic behind the argument.
A-17. The debate phase is an oral presentation of the alternative arguments and rebuttals in parallel fashion.
The steps within the debate phase are—
z
Step 1. Set aside the time for a formal debate or an informal brainstorming session.
z
Step 2. Have an independent jury of peers listen to the oral presentation and be prepared to
question the teams regarding their assumptions, evidence, and/or logic.
z
Step 3. Allow each team to present its case, challenge the other team’s arguments, and rebut the
opponent’s critique of its case.
z
Step 4. The jury considers the strength of each presentation and recommends possible next steps
for further research and collection efforts.
18 August 2014
ATP 2-33.4
A-3
Appendix A
HIGH IMPACT/LOW PROBABILITY
A-18. High impact/low probability analysis highlights a seemingly unlikely event that would have a major
consequence if it occurred. Conducting high impact/low probability analysis sensitizes analysts to the
potential impact of seemingly low probability events that would have major repercussions.
Facts
A-19. Mapping out the course of an unlikely, yet plausible, event can uncover hidden relationships between
key factors and assumptions; it can also alert analysts to oversights in the mainstream analytic line. High
impact/low probability allows analysts to explore the consequences of an event not deemed likely by
conventional wisdom without having to challenge the mainline analytic judgment or to argue with others
about how likely an event is to occur. This technique provides a tactful method of communicating a
viewpoint some might prefer not to hear.
A-20. An examination of the unthinkable allows an analyst to develop indicators that may provide early
warning of a shift in the situation. By periodically reviewing these indicators, an analyst is more likely to
counter any prevailing mindset that such a development is highly unlikely.
The Method
A-21. An effective high impact/low probability analysis involves the following steps:
z
Step 1. Define the high-impact outcome clearly. This process is what will justify examining
what may be deemed a very unlikely development.
z
Step 2. Devise one or more plausible pathways to the low probability outcome. Be as precise as
possible, as it may aid in developing indicators for later monitoring.
z
Step 3. Insert possible triggers or changes in momentum if appropriate (such as natural disasters,
economic or political shocks).
z
Step 4. Brainstorm plausible but unpredictable triggers of sudden change.
z
Step 5. Identify for each pathway a set of indicators or observables that helps anticipate that
events are playing out a specific way.
z
Step 6. Identify factors that would deflect a bad outcome or encourage a positive one.
A-22. Once the list of indicators has been developed, the analyst must review it periodically.
“WHAT IF ANALYSIS
A-23. “What if” analysis imagines that an unexpected event has occurred with potential major impact.
Then, with the benefit of hindsight, the analyst figures out how this event could have come about and what
the consequences might be.
Facts
A-24. “What if” is similar to high impact/low probability analysis, but it does not dwell on the
consequences of the event as much as it accepts the significance and moves directly to explaining how it
might come about. It also creates an awareness that prepares the analyst to recognize early signs of a
significant change.
A-25. Using this technique is important when a judgment rests on limited information or unproven
assumptions. It can also shift focus from asking whether an event will occur, to working from the premise
that it has occurred, and letting the analyst determine how it might have happened. This opens the mind to
think in different ways and allows the analyst to develop indicators that may be monitored.
The Method
A-26. Like other contrarian methods, “what if” analysis must begin by stating the conventional analytic line
and then stepping back to consider what alternative outcomes are too important to dismiss, no matter how
unlikely.
A-4
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
A-27. The steps within “what if” analysis look similar to the steps within the high impact/low probability
analytic technique once the analyst has established the event itself:
z
Step 1. Assume the event has happened or is already happening.
z
Step 2. Select some triggering events that permitted the scenario to unfold to help make the
“what if” more plausible (for example, the death of a leader, a natural disaster, an economic
event that might start a chain of other events).
z
Step 3. Develop a chain of reasoning based on as much on logic as on evidence to explain how
this outcome could have come about.
z
Step 4. Think backwards from the event in concrete ways, specifying what must actually occur
at each stage of the scenario.
z
Step 5. Identify one or more plausible pathways to the event; it is likely that more than one will
appear possible.
z
Step 6. Generate a list of indicators or signposts in order to detect the beginnings of the event.
z
Step 7. Consider the scope of positive and negative consequences and their relative impact.
z
Step 8. Monitor the indicators you have developed on a periodic basis.
RED HAT ANALYSIS
A-28. Analysts seek to forecast the actions of a threat or a competitor. In doing so, they need to avoid the
common error of mirror imaging, the natural tendency to assume that others think and perceive the world in
the same way as they do. Red hat analysis is a useful technique for trying to perceive threats and
opportunities as others see them, but this technique alone is of limited value without significant cultural
understanding of the threat involved.
Facts
A-29. The chances of a red hat analysis being accurate are better when one is trying to foresee the behavior
of a specific person who has the authority to make decisions. Authoritarian leaders as well as small,
cohesive groups (such as terrorist cells) are obvious candidates for this type of analysis.
A-30. Red hat analysis is a reframing technique that requires the analyst to adopt—and make decisions
consistent with—the culture of a foreign leader or group. This conscious effort to imagine the situation as
the target perceives it helps the analyst gain a different and usually more accurate perspective on a problem
or issue. Reframing the problem typically changes the analyst’s perspective from that of an analyst
observing and assessing, to that of a leader who must make decisions within the operational culture.
The Method
A-31. On issues that lend themselves to red hat analysis, gather a team of analysts with in-depth knowledge
of the operating environments, the target’s personality, and the style of thinking used. The team should
consist of people who might have experienced the culture, shared the ethnic backg1round, or have worked in
a similar environment. It is desirable, although not absolutely necessary, to include those who understand
the target’s language. Once established, the team members should—
z
Present the team members with a situation and ask them how they would respond were they the
threat.
z
Emphasize the need to avoid mirror imaging. The question is not, “What would you do if you
were in the threat’s place?” but,
“How would this person or group in that culture and
circumstance most likely think, behave, and respond to the situation?”
z
In presenting the results, describe the alternative considered and the rationale for selecting the
path the person or group is most likely to take.
A-32. Red hat analysis is usually organized and done by any analyst or analyst team that needs to
understand or forecast threat behavior and that has or can gain access to the required cultural experience.
Red hat analysis exploits the available resources to develop the best possible analysis of a threat’s intent.
18 August 2014
ATP 2-33.4
A-5
Appendix A
COUNTERFACTUAL REASONING
A-33. Counterfactual reasoning is an analytic method that is useful for discovering the relationships
between possible events and their most plausible outcomes. It essentially combines two of the contrarian
techniques already discussed:
z
High impact/low probability analysis, which discusses what could occur and the resultant
consequences.
z
“What if” analysis, which reframes the question, assuming that the surprise event has occurred
and then looks backward to identify those key actions, that taken in a timely manner might
possibly prevent it from happening in the first place.
Facts
A-34. Counterfactual reasoning is conducted for several purposes:
z
Facilitate causal analysis. Many scenarios rely upon causal events as indicators. An
understanding of the most significant causal forces leads to more relevant analysis and
assessments.
z
Overcome deterministic biases. Analysts can reduce the possibility of hindsight bias by
proactively determining potential futures as if they had already happened, determining how they
might have occurred, and looking for indicators.
z
Incorporate creativity into the analytic process. Analysts can avoid a lack of imagination or
openness to other possibilities.
z
Ground strategic assessment. Many strategies, and analyses of them, are grounded in a series of
counterfactual claims about alternate possibilities, their consequences, and the relationships
between them.
The Method
A-35. Counterfactual reasoning is performed through four stages: zero through three.
Stage Zero—Establish Event Context
A-36. Stage zero begins with the determination or arrival at the focal question driving the analysis.
Essentially the focal question contains or alludes to an issue’s primary driver that may have either near- or
long-term application towards an intelligence problem. The analyst should have an understanding of the
context for the possible event, to include the causal backg1round. When thinking causal background, think
of it within the context of the relationship between cause and effect. The overriding purpose and objective
of stage zero is estimating the (typically) ten most critical causal forces influencing the topic at present.
A-37. The key steps of stage zero are—
z
Ask, “What affects the question?”
z
Determine focal question to drive analysis.
z
Ensure the analyst understands the context for the possible event.
z
Think in context of the relationship between cause and effect.
z
Determine approximately ten most critical causal forces.
z
Determine causal history. What elements or drivers affect the question?
Stage One—Establish Antecedent Scenario
A-38. In stage one the analyst constructs the antecedent scenario or “what if” back story that sets the
potential event in motion. The analyst thinks in terms of likely or required precursor events that point
towards and/or generates the possible event. The purpose is to identify two to three deviations from the
original ten casual forces that could combine to bring about the possible event.
A-6
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
A-39. The key steps of stage one are—
z
Ask: “How can the event occur?”
z
Examine causal history. Key on a small number of causal forces in the causal history and their
potential deviations.
z
Re-engage current trends and understand what change is required for the event to occur.
Determine which trends would have to decrease, continue, or increase to facilitate the event.
z
Consider alternative ways in which the event could occur. Determine other antecedent scenarios.
Stage Two—Determine Event Compatibility
A-40. In stage two, the analyst determines if there is any ripple effect of the possible event upon any
remaining casual forces. This is to determine if there is any dramatic shift of those remaining casual forces.
Also, those shifts potentially serve as either a primary indicator or as a signpost of change dynamic that has
impact on the probability of the possible events as well as potential after-event consequences.
A-41. In stage two, the analyst looks for those items or trends that are compatible with the possible event
and thinks in terms of intermediate states (or that intermediate period between the time of the antecedent
event and the time of the possible consequences).
A-42. The key steps of stage two are—
z
Select intermediate states.
z
Evaluate the secondary effects, tertiary effects, and beyond of the possible event on the causal
forces not considered.
z
What new events and/or trends may emerge as a result of the event occurring? What are the
secondary and tertiary effects of these?
Stage Three—Drawing Consequent Scenarios
A-43. In stage three, the analyst transitions to the ultimate objective of the process—to draw potential or
likely conclusions from the possible event. Specifically, the analyst drafts several follow-on scenarios or
aftermath-related events that could potentially emerge if or once the possible events become a reality.
A-44. The purpose of this stage is to explore three-to-five scenarios consistent with the antecedent scenario
(and intermediate states) as well as the outcomes common to multiple scenarios.
A-45. The key steps of stage three are—
z
Generate several scenarios derived from the possible consequences of the event occurring. It is
recommended the analyst develop three possible scenarios or COAs.
z
Determine possible consequences of each of the scenarios generated.
z
Determine commonalities between the consequences for each scenario to determine possible
trends.
IMAGINATIVE TECHNIQUES
A-46. Imaginative thinking techniques aim at developing new insight, different perspectives, and/or
alternative outcomes. They aid the analyst in generating new ideas, broaden possible outcomes, and reduce
the chance of unforeseen outcomes. Imaginative techniques look at the problem from different (often even
multiple) perspectives and allow the analyst to better forecast and assess potential COAs. Additionally,
proper application of imaginative techniques can help identify differences in perspective and different
assumptions among analytic team members.
A-47. There are many imaginative techniques; however, this publication discusses only the following:
z
Brainstorming.
z
Outside-In Thinking.
z
Red Team Analysis.
z
Alternative Future Analysis.
z
Morphological Analysis with Multiple Scenarios Generation.
18 August 2014
ATP 2-33.4
A-7
Appendix A
BRAINSTORMING
A-48. Analysts use the brainstorming technique in the same manner as it is used for developing situational
understanding and conclusions as discussed in chapter 5.
Facts
A-49. Brainstorming should be a very structured process to be most productive. An unconstrained, informal
discussion might produce some interesting ideas, but usually a more systematic process is the most
effective way to break down mindsets and produce new insights.
The Method
A-50. In particular, the process involves a divergent thinking phase to generate and collect new ideas and
insights, followed by a convergent phase in which ideas are grouped and organized around key concepts.
The following are some of the simple rules to follow:
z
Never censor an analyst’s ideas no matter how unconventional they might sound.
z
Find out what prompted the thought, as it might contain the seeds of an important connection
between the topic and an unstated assumption.
z
Take the time to brainstorm correctly. It usually takes one hour to establish the method used to
ensure the group is comfortable and able to exhaust the conventional wisdom on the topic. Only
then will the truly creative ideas begin to emerge.
z
Involve someone outside the group who does not share the same educational backg1round,
culture, technical knowledge, or mindset as the core group but who is familiar with the topic.
This fosters creative ideas.
OUTSIDE-IN THINKING
A-51. Analysts find this technique most useful at the conceptualization of an analytic project, when the goal
is to identify all the critical, external factors that could influence how a particular situation will develop. It
works well for a group of analysts responsible for a range of functional and/or regional issues. When
assembling a large database that must identify a number of information categories or database fields, this
technique can aid in visualizing the entire set of categories that might be needed in a research effort. Often
analysts realize too late that some additional information categories will be needed and then must go back
and review all previous files and recode the data. With a modest amount of effort, outside-in thinking can
reduce the risk of missing important variables early in the analytic process.
Facts
A-52. Most analysts spend their time concentrating on familiar factors within their field or analytic issues;
that is, they think from the inside—namely, what they control—out to the broader world. Conversely,
thinking from the outside-in begins by considering the external changes that might, over time, profoundly
affect the analysts’ own field or issue. This technique encourages analysts to get away from their immediate
analytic tasks (the so-called inbox) and think about their issues in a wider conceptual and contextual
framework. By recasting the problem in much broader and basic terms, analysts are more likely to uncover
additional factors, an important dynamic, or a relevant alternative hypothesis.
The Method
A-53. The process begins by developing a generic description of the problem or the phenomenon under
study. Then, analysts should—
z
List all the key forces (social, technological, economic, environmental, and political) that could
have an impact on the topic, but over which one can exert little influence (such as globalization,
social stress, the Internet, or the global economy).
z
Focus next on key factors over which an individual or policymaker can exert some influence. In
the business world this might be the market size, customers, the competition, suppliers or
A-8
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
partners; in the government domain it might include the policy actions or the behavior of allies
or adversaries.
z
Assess how each of these forces could affect the analytic problem.
z
Determine whether these forces actually do have an impact on the particular issue based on the
available evidence.
RED TEAM ANALYSIS
A-54. Frequently, analysts face the challenge of forecasting how a foreign leader or decisionmaking group
may behave when it is clear there is a risk of falling into a “mirror-image” problem. That is, analysts can
sometimes believe a foreign leader has the same motives, values, or understanding of an issue that they
hold. Traditional analysis sometimes assumes that foreign leaders or groups will behave rationally and act
as the analysts would if faced with the same threats or opportunities. History has shown that foreign leaders
often respond differently to events because of different cultural, organizational, or personal experiences.
Facts
A-55. Red Team analysis tries to consciously place analysts in the same cultural, organizational, and
personal setting (“putting them in their shoes”) in which the target individual or group operates. Whereas
analysts normally work from the position of the blue (friendly forces), a red team of analysts attempts to
work in the environment of the hostile forces.
A-56. Like devil’s advocacy and Team A/Team B techniques, Red Team analysis is aimed at freeing the
analyst from the prison of a well-developed mindset; in this case, the analyst’s own sense of rationality,
cultural norms, and personal values. Whereas analysts usually operate as observers of a foreign threat, the
Red Team technique transforms the analyst into an enemy operating within the threat’s culture and political
milieu. This form of role-playing is useful when trying to replicate the mindset of authoritarian leaders,
terrorist cells, or other nonwestern groups that operate under very different codes of behavior or
motivations.
A-57. Often this technique can introduce new or different stimuli that might not have been factored into
traditional analysis, such as the target’s familial ties or the international political, economic, and military
pressures felt by the individual. For example, Red Team participants might ask themselves: “What would
my peers, family, or tribe expect me to do? Alternatively, a Red Team analyst might pose the question to
his colleagues: “How do we perceive the external threats and opportunities?” Finally, the Red Team
technique can factor into its analysis the way in which personal power and status might influence a target’s
behavior.
The Method
A-58. Red Team analysis is not easy to conduct. It requires significant time to develop a team of qualified
experts who can think like the threat. The team has to distance itself from the normal analysis and work as
though living in the target’s world. Without sophisticated understanding of the culture, operational
environments, and personal histories of the foreign group, analysts will not be able to behave or think like
the enemy. Analysts can never truly escape their own experiences and mindsets, but this technique can at
least prevent them from falling subconsciously into mirror-imaging.
A-59. On issues that lend themselves to Red Team analysis, a manager needs to build a team of experts
with in-depth knowledge of the operational environments, the target’s personality, and the style of thinking
used. The team should be populated with people who might have experienced the culture, shared the ethnic
backg1round, or have worked in similar operational environments. It is desirable, although not absolutely
necessary, to include those who understand the target’s language. Once established and separated from
traditional analysis, the team members should—
z
Put themselves in the threat’s circumstances and react to foreign stimuli as the target would.
z
Develop a set of first-person questions that the threat would ask, such as: “How would I perceive
incoming information; what would be my personal concerns; or to whom would I look for an
opinion?”
18 August 2014
ATP 2-33.4
A-9
Appendix A
z
Draft a set of analytic papers in which the leader or group makes specific decisions, proposes
recommendations, or lays out COAs. The more these papers reflect the cultural and personal
norms of the target, the more they can offer a different perspective on the analytic problem.
z
Red team analysis avoids the use of qualifying statements and assumes the recipient understands
the paper is aimed more at provoking thought or challenging the conventional understanding of
how a threat thinks.
A-60. For more detailed information on Red Teaming, see the Red Team Handbook, published by the
University of Foreign Military and Cultural Studies in Fort Leavenworth, Kansas. Analysts may also
consider attending one of the Red Team courses offered there.
Red Hat Analysis Versus Red Team Analysis
Red Hat analysis differs from Red Team analysis in that Red Hat analysis can be
conducted or organized by any analyst who needs to understand or forecast foreign
behavior and who has or can gain access to the required cultural experience. Red
Team analysis is usually conducted by a permanent organizational unit or a
temporary group staffed by those well qualified to think like or play the role of a
threat. The goal of Red Hat analysis is to exploit the available resources to develop
the best possible analysis of a threat’s intent. The goal of Red Team analysis is
usually to challenge organizational biases and provide alternative threat COAs.
ALTERNATIVE FUTURE ANALYSIS
A-61. Alternative Futures Analysis (often referred to as scenarios) is most useful when a situation is viewed
as too complex or the outcomes as too uncertain to trust a single-outcome assessment. For example:
z
Analysts must recognize there is high uncertainty on the topic in question.
z
Analysts, and often their customers, recognize that they need to consider a wide range of factors
that might bear on the question.
z
Analysts are prepared to explore a range of outcomes and are not wedded to any preconceived
result.
A-62. Depending on how elaborate the futures project, the effort can amount to considerable investment in
time, analytic resources, and money. A team of analysts can spend several hours or days organizing,
brainstorming, and developing multiple futures; alternatively, a larger-scale effort can require preparing a
multi-day workshop that brings together participants (including outside experts). Such an undertaking often
demands the special skills of trained scenario-development facilitators and conferencing facilities.
Facts
A-63. This technique is a sharp contrast to contrarian techniques, which try to challenge the analysts’ high
confidence and relative certainty about an event or trend. Instead, multiple futures development is a
divergent thinking technique that tries to use the complexity and uncertainty of a situation to describe
multiple outcomes or futures that the analyst and policymaker should consider, rather than to predict one
outcome.
A-64. Alternative Future Analysis is extremely useful in highly ambiguous situations, when analysts
confront not only a lot of known unknowns but also unknown unknowns. What this means is that analysts
recognize there are factors, forces, and dynamics among key leaders that are difficult to identify without the
use of some structured technique that can model how they would interact or behave. As the outcomes are
not known prior to the futures exercise, analysts must be prepared for the unexpected and be willing to
engage in a more freewheeling exchange of views than typically occurs in order to imagine the future.
Given the time and resources involved, scenario analysis is best reserved for situations that could
potentially pose grave threats or otherwise have significant consequences.
A-65. From experience, analysts have found that involving decisionmakers in the alternative futures
exercise is the most effective way to communicate the results of this exploration of alternative outcomes
A-10
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
and sensitize them to key uncertainties. Most participants find the process of developing such scenarios as
useful as any finished product that attempts to capture the results of the exercise. Analysts and
decisionmakers can benefit from this technique in several ways:
z
It provides an effective means of weighing multiple unknown or unknowable factors and
presenting a set of plausible outcomes.
z
It can help to bind a problem by identifying plausible combinations of uncertain factors.
z
It provides a broader analytic framework for calculating the costs, risks, and opportunities
presented to policymakers by different outcomes.
z
It aids analysts and policymakers in anticipating what otherwise would be surprising
developments by forcing them to challenge assumptions and consider possible wild cards or
discontinuous events.
z
It generates indicators to monitor for signs that a particular future is becoming more or less
likely, so that policies can be reassessed.
The Method
A-66. Although there are a variety of ways to develop alternative futures, the most common approach used
in both the public and private sectors involves the following steps:
z
Develop the focal issue by systematically interviewing experts and officials who are examining
the general topic.
z
Convene a group of experts (both internal and external) to brainstorm about the forces and
factors that could affect the focal issue.
z
Select by consensus the two most critical and uncertain forces and convert these into axes or
continuums with the most relevant endpoints assigned.
z
Establish the most relevant endpoints for each factor; for example, if economic growth were the
most critical, uncertain force, the endpoints could be fast and slow or transformative and
stabilizing, depending on the type of issue addressed.
z
Form a futures matrix by crossing the two chosen axes. The four resulting quadrants provide the
basis for characterizing alternative future worlds.
z
Generate colorful stories that describe these futures and how they could plausibly come about.
Indicators can then be developed.
A-67. Participants, especially decisionmakers, can then consider how current decisions or strategies would
fare in each of the four worlds—fast, slow, transformative, stabilizing—and identify alternative policies
that might work better either across all the futures or in specific ones. By anticipating alternative outcomes,
policymakers have a better chance of either devising strategies flexible enough to accommodate multiple
outcomes or of being prepared and agile in the face of change.
MORPHOLOGICAL ANALYSIS WITH MULTIPLE SCENARIOS GENERATION
A-68. Morphological Analysis is a method for structuring and examining all the possible relationships
within an unproven, dynamic, and potentially complex environment. It is best used when—
z
There is little to no information available and surprise conditions are ripe.
z
There is a need to identify that threat variations exists.
z
The analyst needs to specifically understand the potential crisis conditions, to ascertain any
driving force interactions, and to understand the range of potential scenario outcomes.
Facts
A-69. Applying Morphological Analysis, specifically using the Multiple Scenarios Generation technique,
better enables the analyst to forecast multiple scenarios, not just the worst case or nightmare ones but also
those scenarios that represent favorable conditions or circumstances for U.S. forces.I
18 August 2014
ATP 2-33.4
A-11
Appendix A
A-70. n addition, usage of the Multiple Scenarios Generation technique offers ancillary benefits, such as—
z
Enabling the analyst to potentially see when and how a specific scenario is coming to fruition.
z
Aiding in the process of creating key indicator lists so that the command team can set the right
conditions to make the most favorable scenarios become reality.
z
Setting conditions to deny the threat the ability to create those scenarios or circumstances that
may give the threat a decisive edge within the analyst’s AO.
A-71. Morphological Analysis—
z
Aids significantly in both generating a laundry list of potential outcomes and enabling the
analyst to clearly identify and select those outcomes that are more credible or warrant greater
attention.
z
Focuses both analysts and leaders on those key actions necessary in order to prepare for future
events so the right prevention or risk migration orientation is achieved or satisfied.
z
Broadens the analyst’s view of low probability/high impact developments and, in turn, often
forces a more objective viewpoint, thus lessening the chances the analyst dismisses or discounts
a scenario or key driver based at face value.
A-72. Multiple Scenarios Generation—
z
Identifies all the possible scenarios and combination of driving forces at play for a given
problem. The analyst’s primary objective through application of this technique is to reduce the
unforeseen potential regarding the intelligence challenge or issue at hand.
z
Aids in identifying the extreme cases of interaction between an issue’s drivers.
z
Is similar to the Alternative Future Analysis technique; however, the significant difference is that
Multiple Scenarios Generation involves more than one matrix.
z
Uses multiple two-by-two matrices and pairs combinations of multiple key drivers. Each two-
by-two matrix generates four scenarios, thus multiple matrices provide multiple potential
scenarios that may emerge from the focal question.
z
Reduces the tendency for the analyst to potentially miss an outcome. Once the analyst generates
the scenarios in this format, the analyst is able to revisit the issue via quick screen snapshots.
This minimizes the potential to labor over a scenario individually looking for more detailed
analysis. Additionally, the analyst is more likely to pay attention to driver or indicator impacts
on events if or when they are unfolding in a manner not previously anticipated.
The Method
A-73. Morphological Analysis works through the two principles of decomposition and forced association.
Analysts should start by decomposing the problem, defining a set of key parameters or dimensions of the
problem, and then breaking down each of those dimensions further into relevant forms or states the
dimension can assume.
A-74. The principle of forced association then requires every element be paired with and considered in
connection with every other element in the morphological space. This serves to narrow the possibilities and
allows the analyst to focus on those combinations within the realm of possibility.
A-75. When applied using Multiple Scenarios Generation, the process is as follows:
z
First the analyst should define the issue at hand.
z
Next the analyst should identify all the key factors, forces, or events influencing the issue; this is
referred to as the drivers. The analyst should define the ends of the spectrum for each driver (less
versus most extreme circumstances) and pair the drivers in two-by-two matrices.
z
Once the analyst identifies all the driver variations, the analyst should establish scenarios for
each combination; that is, within each quadrant in the matrix.
z
The analyst then selects those scenarios that portray a compelling or challenging future that has
not been considered and develops indicators to track whether one of the scenarios is developing.
A-12
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
Note. Remember that as indicators are developed to aid in scenario tracking, the analysts may
see synergy between certain drivers that may be indicative of extreme cases of interaction
between drivers of an issue. The Multiple Scenarios Generation technique proves extremely
useful when used in conjunction with the counterfactual reasoning method.
A-76. Morphological Analysis is a method for structuring and examining all the possible relationships
within an unproven, dynamic, and potentially complex environment. Using Morphological Analysis in
combination with Multiple Scenarios Generation aids in reducing unforeseen potential and identifying
extreme cases of interaction between an issue’s drivers. Generating multiple scenarios in this format gives
the analyst the advantage of revisiting a given scenario via quick screen snapshots, minimizing the potential
to labor over each individually looking for more detailed analysis. This technique is extremely useful in
concert with other analytic techniques, particularly counterfactual reasoning.
STRUCTURED ANALYTIC TECHNIQUES
A-77. The following techniques have been used by intelligence personnel at strategic levels for some time
and are being employed to some degree at operational and tactical levels. Each of the techniques may
provide additional insight into an intelligence problem. Analysts may find it useful to combine these
techniques with others discussed in this publication. Although some of these techniques discussed below do
not have a specific methodology, each has its own merits:
z
Analysis of competing hypotheses.
z
Applying theory.
z
Delphi technique.
z
Futures wheel.
z
Knowledge planning.
z
Rules for verification.
ANALYSIS OF COMPETING HYPOTHESES
A-78. The Central Intelligence Agency developed ACH in the 1970s as an intelligence methodology to
evaluate multiple competing hypotheses and to foster unbiased conclusions. It is currently still in use by
national-level intelligence analysts in various fields who are required to make judgments on areas where
there is a high risk of error when drawing conclusions. ACH is emerging as a tool that may be effective at
the operational and tactical levels in aiding Army commanders and staffs in analyzing complex problems
such as those found in stability operations.
A-79. The goal of ACH is to produce the best possible conclusion when analyzing uncertain data. As an
emerging intelligence methodology relative to the operational and tactical Army, there is conflicting data
available on how well it can be integrated into Army operations. (For more information on ACH, see
Richard Heuer’s Psychology of Intelligence Analysis. This resource can be accessed on the Central
Intelligence Agency Web site on Nonsecure Internet Protocol Router Network [also called NIPRNET].)
Facts
A-80. ACH is an eight-step procedure grounded in basic insights from cognitive psychology, decision
analysis, and the scientific method. The steps are discussed in paragraph A-83. It is a surprisingly effective,
proven process that helps an analyst to avoid common analytic pitfalls. Because of its thoroughness, it is
particularly appropriate for controversial issues when analysts want to leave an audit trail to show what
they considered and how they arrived at their judgment. When working on difficult intelligence issues,
analysts are, in effect, choosing among several alternative hypotheses:
z
Which of several possible explanations is the correct one?
z
Which of several possible outcomes is the most likely one?
A-81. This publication uses the term “hypothesis” in its broadest sense as a potential explanation or
conclusion that is to be tested by collecting and presenting evidence. ACH requires an analyst to explicitly
18 August 2014
ATP 2-33.4
A-13
Appendix A
identify all the reasonable alternatives and evaluate them against each rather than evaluate their plausibility
one at a time.
A-82. The way most analysts begin analysis is to pick out what they suspect intuitively is the most likely
answer, then look at the available information from the point of view of whether or not it supports this
answer. If the evidence seems to support the favorite hypothesis, analysts become confidant in their
decision and look no further. If it does not, they either reject the evidence as misleading or develop another
hypothesis and go through the same procedure again. Intelligence analysts call this a “satisficing” strategy.
Satisficing means picking the first solution that seems satisfactory, rather than going through all the
possibilities to identify the very best solution. There may be several seemingly satisfactory solutions, but
there is only one best solution. The principal concern here is that if analysts focus mainly on trying to
confirm one hypothesis they think is probably true, they can easily be led astray when there is so much
evidence to support their point of view. They fail to recognize that most of this evidence is also consistent
with other explanations or conclusions, and these other alternatives have not been explored.
The Method
A-83. Simultaneous evaluation of multiple, competing hypotheses is difficult to do. To retain three to five
or even seven hypotheses in working memory and note how each item of information fits into each
hypothesis is beyond the mental capabilities of most people. It takes far greater mental agility than listing
evidence supporting a single hypothesis that was pre-judged as the most likely answer. It can be
accomplished, though, with the help of the simple procedures discussed here:
z
Step 1. Identify the possible hypotheses to be considered. Use a group of analysts with
different perspectives to brainstorm the possibilities. Psychological research into how people go
about generating hypotheses shows that people are actually rather poor at thinking of all the
possibilities. If individuals do not even generate the correct hypothesis for consideration,
obviously they will not get the correct answer.
z
Step 2. Make a list of significant evidence and arguments for and against each hypothesis.
In assembling the list of relevant evidence and arguments, these terms should be interpreted
broadly. They refer to all the factors that have an impact on judgments about the hypotheses. Do
not limit yourself to concrete evidence in the current intelligence reporting. Also include your
own assumptions or logical deductions about another people or groups or country's intentions,
goals, or standard procedures. These assumptions may generate strong preconceptions as to
which hypothesis is most likely. Such assumptions often drive the final judgment, so it is
important to include them in the list of evidence.
z
Step 3. Prepare a matrix with hypotheses across the top and evidence down the side.
Analyze the diagnosticity of the evidence and arguments; that is, identify which items are most
helpful in judging the relative likelihood of alternative hypotheses. Step 3 is perhaps the most
important element of this analytical procedure. It is also the step that differs most from the
natural, intuitive approach to analysis, and, therefore, the step an analyst is most likely to
overlook or misunderstand. The procedure for step 3 is to take the hypotheses from step 1 and
the evidence and arguments from step 2 and put this information into a matrix format, with the
hypotheses across the top and evidence and arguments down the side. This gives an overview of
all the significant components of the analytical problem.
z
Step 4. Refine the matrix. Reconsider the hypotheses and delete evidence and arguments
that have no diagnostic value. The exact wording of the hypotheses is obviously critical to the
conclusions one can draw from the analysis. By this point, you will have seen how the evidence
breaks out under each hypothesis, and it will often be appropriate to reconsider and reword the
hypotheses. For example:
„ Are there hypotheses that need to be added or finer distinctions that need to be made in
order to consider all the significant alternatives?
„ If there is little or no evidence that helps distinguish between two hypotheses, should they
be combined into one?
z
Step 5. Draw tentative conclusions about the relative likelihood of each hypothesis. Proceed
by trying to disprove hypotheses rather than prove them. In step 3, you worked across the
A-14
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
matrix, focusing on a single item of evidence or argument and examining how it relates to each
hypothesis. Now, work down the matrix, looking at each hypothesis as a whole. The matrix
format gives an overview of all the evidence for and against all the hypotheses, so you can
examine all the hypotheses together and have them compete against each other for your
approval.
z
Step 6. Analyze how sensitive your conclusion is to a few critical items of evidence. Consider
the consequences for your analysis if that evidence were wrong, misleading, or subject to a
different interpretation. In step 3 you identified the evidence and arguments that were most
diagnostic, and in step
5 you used these findings to make tentative judgments about the
hypotheses. Now, go back and question the few linchpin assumptions or items of evidence that
really drive the outcome of your analysis in one direction or the other. For example:
„ Are there questionable assumptions that underlie your understanding and interpretation?
„ Are there alternative explanations or interpretations?
„ Could the evidence be incomplete and, therefore, misleading?
z
Step 7. Report conclusions. Discuss the relative likelihood of all the hypotheses, not just the
most likely one. If your report is to be used as the basis for decisionmaking, it will be helpful for
the decisionmaker to know the relative likelihood of all the alternative possibilities. Analytical
judgments are never certain. There is always a good possibility of their being wrong.
Decisionmakers need to make decisions on the basis of a full set of alternative possibilities, not
just the single most likely alternative. Contingency or fallback plans may be needed in case one
of the less likely alternatives turns out to be true.
z
Step 8. Identify milestones for future observation that may indicate events are taking a
different course than expected. Analytical conclusions should always be regarded as tentative.
The situation may change, or it may remain unchanged while you receive new information that
alters your appraisal. It is always helpful to specify in advance things one should look for or be
alert to that, if observed, would suggest a significant change in the probabilities. This is useful
for intelligence consumers who are following the situation on a continuing basis. Specifying in
advance what would cause you to change your mind will also make it more difficult for you to
rationalize such developments, if they occur, as not really requiring any modification of your
judgment.
A-84. Three key elements distinguish analysis of competing hypotheses from conventional intuitive
analysis:
z
Analysis starts with a full set of alternative possibilities, rather than with a most likely alternative
for which the analyst seeks confirmation. This ensures that alternative hypotheses receive equal
and fair treatment.
z
Analysis identifies and emphasizes the few items of evidence or assumptions that have the
greatest diagnostic value in judging the relative likelihood of the alternative hypotheses. In
conventional intuitive analysis, key evidence may also be consistent with alternative hypotheses;
it is rarely considered explicitly and is often ignored.
z
Analysis of competing hypotheses involves seeking evidence to refute hypotheses. The most
probable hypothesis is usually the one with the least evidence against it, not the one with the
most evidence for it. Conventional analysis generally entails looking for evidence to confirm a
favored hypothesis.
18 August 2014
ATP 2-33.4
A-15
Appendix A
Example of Analytical Effectiveness of
Analysis of Competing Hypotheses
The analytical effectiveness of Analysis of Competing Hypotheses (ACH) becomes
apparent when considering the Indian nuclear weapons testing in 1998. According to
Admiral Jeremiah, the intelligence community had reported: “There was no indication
the Indians would test in the near term.”
Such a conclusion by the community would fail to distinguish an unproven hypothesis
from a disproved hypothesis. The intelligence communities’ conclusion that because
the Indians were not testing nuclear weapons now does not disprove the hypothesis
India may test nuclear weapons in the future.
If the ACH procedure had been used, one of the hypotheses would certainly have
been that India is planning to test in the near term but will conceal preparations for
the testing to forestall international pressure to halt such preparations.
Careful consideration of this alternative hypothesis would have required evaluating
India’s motive, opportunity, and means for concealing its intention until it was too late
for the United States and others to intervene. It would also have required assessing
the ability of U.S. intelligence to see through Indian denial and deception if it were
being employed. It is hard to imagine that this would not have elevated awareness of
the possibility of successful Indian deception.
A-85. A principal lesson in the above scenario is whenever an intelligence analyst is tempted to write the
phrase, "there is no evidence that ...," the analyst should ask this question: If this hypothesis is true, can I
realistically expect to see evidence of it? In other words, if India were planning nuclear tests while
deliberately concealing its intentions, could the analyst realistically expect to see evidence of test planning?
The ACH procedure leads the analyst to identify and face these kinds of questions.
A-86. Once an analyst has gained practice in applying ACH, it is quite possible to integrate the basic
concepts of this procedure into the normal analytical thought process. In that case, the entire eight-step
procedure may be unnecessary except on highly controversial issues.
A-87. There is no guarantee that ACH or any other procedure will produce a correct answer. The result still
depends on fallible intuitive judgment applied to incomplete and ambiguous information. ACH does,
however, guarantee an appropriate process of analysis. This procedure leads the analyst through a rational,
systematic process that avoids some common analytical pitfalls. It increases the odds of getting the right
answer, and it leaves an audit trail showing the evidence used in the analysis and how this evidence was
interpreted. If others disagree with the analyst’s judgment, the matrix can be used to highlight the precise
area of disagreement. Subsequent discussion can then focus productively on the ultimate source of the
differences.
A-88. A common experience is that ACH attributes greater likelihood to alternative hypotheses than would
conventional analysis. People become less confident of what they thought they knew. In focusing more
attention on alternative explanations, the procedure brings out the full uncertainty inherent in any situation
that is poor in data but rich in possibilities. Although such uncertainty is frustrating, it may be an accurate
reflection of the true situation. The ACH procedure has the offsetting advantage of focusing attention on
the few items of critical evidence that cause the uncertainty or which, if they were available, would
alleviate it. This can guide future collection, research, and analysis to resolve the uncertainty and produce a
more accurate judgment.
APPLYING THEORY
A-89. Applying theory begins with the formulation of a theory based on the evaluation of other examples of
the same phenomenon. This technique is based on the supposition that when a given set of conditions arise,
certain other conditions will follow. One of the advantages of this methodology when applied to
intelligence analysis is that it economizes thought. By identifying the key elements of a problem, applying
theory enables an analyst to sort through a mass of less significant detail. Applying theory enables the
analyst to see beyond transient developments, to recognize which trends are superficial and which are
A-16
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
significant, and to foresee future developments for which there may be little concrete evidence at the
moment.
A-90. Applying theory can be used to analyze threat, neutral, and friendly entity patterns of behavior when
a large quantity of data is available on an entity going back over time. Applying theory is effective in
situations where analysts are attempting to predict how large constructs such as nations, religions, or ethnic
groups may act or react. (For example, an insurgency begins to develop in Turkey. Analysts apply what
they know about other countries that have experienced and dealt with the same problem to predict how
Turkey will react militarily and politically.)
DELPHI TECHNIQUE
A-91. The Delphi technique is a systematic, interactive forecasting method that relies on a panel of
independent analysts. The analysts answer questionnaires in two or more rounds. After each round, a
facilitator provides an anonymous summary of the analysts’ conclusions from the previous round as well as
the reasons they came to those conclusions. Analysts are encouraged to revise their earlier answers in light
of the replies of other analysts on the panel. The goal is to decrease division and converge towards a
commonly agreed upon answer. Finally, the process is stopped after a predefined stop criterion (for
example, number of rounds, achievement of consensus, and stability of results). The mean or median scores
of the final rounds determine the results.
Facts
A-92. Usually participants maintain anonymity. Their identity is not revealed even after the completion of
the final report. This stops individuals from dominating others in the process by using their authority or
personality. It frees individuals, to some extent, from their personal biases and minimizes the "bandwagon
effect" or "halo effect." The Delphi Technique also allows individuals to freely express opinions and
encourages open critique and admission of errors to revise earlier judgments.
The Method
A-93. An analyst, serving as the moderator, sends a questionnaire to a panel of experts who may be in
different locations. The experts respond and are usually asked to explain their responses briefly. The
moderator collates the results from this first questionnaire, identifying common and conflicting viewpoints.
The moderator then sends the collated responses back to all panel members, requesting them to reconsider
their responses based on what they see and learn from the other experts’ responses and explanations. Panel
members may also be asked to answer another set of questions, which may or may not be based on the
collated answers. If consensus is not reached, the process continues through thesis and antithesis, gradually
working towards synthesis and building consensus.
A-94. Like ACH, Delphi is effective when dealing with complex problems such as those found in
counterinsurgency. For example, given a list of Afghanistan provinces, with a generalized indicator list for
Taliban use of criminal enterprises, the analyst can determine which provinces (in prioritized order with
rationale) are most dangerous to the Afghan government.
FUTURES WHEEL
A-95. A Futures Wheel is a method used by analysts to identify second- and third-order effects of a
potential COA. Analysts are regularly tasked to explore the impact of a proposed operation or COA. In
order to avoid compiling a list that is shallow and incomplete, a Futures Wheel provides a structured
method and visual tool to aid in the analysis. Originally developed in the 1970s to identify the potential
consequences of trends and events, it is also a useful tool to aid in decisionmaking and analyzing the impact
of operations.
18 August 2014
ATP 2-33.4
A-17
Appendix A
Facts
A-96. A Futures Wheel uses structured brainstorming to move from the COA to secondary and tertiary
effects, and potentially beyond. The analyst must first identify the potential COA and place it in the center
of the work space. Examples of COAs are funding construction operations, conducting a raid on a mosque,
or selling arms to a foreign nation. Figure A-1 is an example of the layout of a Futures Wheel.
Figure A-1. Futures wheel example
The Method
A-97. Creating a Futures Wheel method involves three steps:
z
Step 1. Once the COA is identified, the analyst brainstorms possible direct consequences of that
COA. These consequences should be realistic and within the capabilities of the entities
considered. These are first-order effects of the COA.
z
Step 2. The analyst then uses each of the first-order effects as a jumping point for further
brainstorming. These indirect effects of the COA should be realistic, but will not necessarily be
traceable directly to the original COA. These are second-order effects. This may be repeated
further to determine third, fourth, and further orders of effects.
z
Step 3. Once the analyst has completed all desired levels of effects, the Futures Wheel will
present a clear picture of the possible direct and indirect consequences resulting from a chosen
COA. The analyst then considers ways to mitigate and manage negative consequences and
provide them as alternatives for the decisionmaker.
A-18
ATP 2-33.4
18 August 2014
Emerging Analytic Techniques
KNOWLEDGE PLANNING
A-98. Knowledge planning is a dynamic and collaborative methodology for the identification and
satisfaction of critical information needs.
Facts
A-99. Knowledge planning provides a mechanism for linking operational requirements with information
collection strategies and capabilities; that is, linking critical information needs with—
z
Relevant knowledge centers (Defense intelligence enterprise, intelligence warfighting function).
z
Collection assets.
z
Specific target areas.
z
Operational parametric (time-accuracy-resolution).
z
Standing collection requirements.
The Method
A-100. Knowledge planning is comprised of the following steps:
z
Step 1. Review and refine critical information needs (decisionmaker and operations).
z
Step 2. Determine priorities (decisionmaker and operations).
z
Step 3. Determine target areas (decisionmaker and operations).
z
Step 4. Determine critical information needs priority and time, accuracy, resolution parametrics
(decisionmaker and operations).
z
Step 5. Review and refine information and intelligence requirements (intelligence).
z
Step 6. Determine requirements (decisionmaker and operations).
z
Step 7. Determine sensor requirements (intelligence).
z
Step 8. Determine knowledge center requirements (intelligence).
z
Step 9. Determine processing and dissemination requirements (intelligence).
A-101. An example of knowledge planning would be the development of a knowledge plan for a brigade
combat team scheduled to deploy to a foreign country.
RULES FOR VERIFICATION
A-102. Rules for Verification is a problem-solving methodology designed to establish likelihoods, not
certainty, of hypotheses.
Facts
A-103. Rules for Verification can be applied to situation development (updating intelligence assessments),
developing collection strategies, and conducting assessment.
The Method
A-104. There are seven Rules for Verification commonly used by intelligence personnel:
z
Rule 1. A hypothesis is more believable when a consequence of that hypothesis is verified.
When a piece of evidence is verified that is supportive of the hypothesis, the hypothesis becomes
more believable.
z
Rule 2. The credibility of a hypothesis increases as the different means used to test the
hypothesis support it. Hypothesis becomes more creditable when different collection disciplines
verify supporting evidence, or different sources within the same discipline.
z
Rule 3. Confidence in a hypothesis increases as the observable bits of evidence that support the
hypothesis bear some proximity to each other.
18 August 2014
ATP 2-33.4
A-19
Appendix A
z
Rule 4. The credibility of a hypothesis is directly proportional to the number of instances in
which the hypothesis was supported. Simply put, the more verifiable evidence, the greater the
possibility of truth in the hypothesis.
z
Rule 5. Confidence in a hypothesis increases when an incompatible and rival conjecture is
refuted. Very rarely is just one hypothesis considered.
z
Rule 6. Confidence in a hypothesis increases to the extent that it is consistent with another
hypothesis that is highly credible.
z
Rule 7. In instances in which observables support two different hypotheses, the simpler
hypothesis stands a better chance of being true.
A-20
ATP 2-33.4
18 August 2014
Appendix B
Indicators in Decisive Action
This appendix provides examples of indicators used in decisive action. While not an
all-inclusive list of indicators, this appendix assists the analyst in confirming or
denying an action or event in offensive, defensive, and stability operations.
OVERVIEW
B-1. The activities that reveal the intended threat COA are called indicators. (See FM 2-01.3 for more
information on indicators.) An indicator is an activity or lack of activity that confirms or denies the action
or event specified in an intelligence requirement. Intelligence analysts develop indicators. Because the use
of indicators is such an important part of determining threat COAs, it is imperative that all-source
intelligence analysts carefully review all indicators. The tables in this appendix, although exemplary and
not all inclusive, identify the different types of indicators, as well as applicable activities. The examples are
designed to provide a starting point for more in-depth specific analysis for an operation. Development and
refinement of indicators is an important activity that links all-source analysis to planning requirements and
assessing collection.
INDICATOR EXAMPLES
B-2. The following tables in this appendix list various activities and explanations of indicators:
z
Table B-1 on page B-2—Offensive indicators.
z
Table B-2 on page B-3—Defensive indicators.
z
Table B-3 on page B-4—Delaying indicators.
z
Table B-4 on page B-5—Withdrawal indicators.
z
Table B-5 on page B-5—Population indicators.
z
Table B-6 on page B-7—Propaganda indicators.
z
Table B-7 on page B-8—Commodities indicators.
z
Table B-8 on page B-10—Environment-related indicators.
z
Table B-9 on page B-10—IED indicators, observables, and signatures.
z
Table B-10 on page B-11—Threat environment indicators.
z
Table B-11 on page B-11—Recurrance of same-clan indicators.
18 August 2014
ATP 2-33.4
B-1
Appendix B
Table B-1. Offensive indicators
Activity
Explanation
Massing of maneuver elements,
May indicate the main effort by weakening areas of secondary
armor, artillery, and logistic support.
importance.
Deployment of combat elements on
May provide maximum combat power at the point of attack by
a relatively narrow frontage (not
reducing frontages. Likely threat decisive effort.
forced by terrain).
Massing of indirect fire support
May indicate initiation of main effort.
assets.
Extensive artillery preparation of up
Initiates preparation preceding an attack.
to 50 minutes in duration or longer.
Can indicate formation of combined arms assault formations with
Dispersal of tanks and self-propelled
tanks accompanying the leading maneuver elements and artillery
artillery to forward units.
following in bounds.
Provides depth to threat offensive tasks; places friendly support
Surface-to-surface missile units
and unassigned areas in range. May also indicate, when
located forward.
employed alone, harassing or special weapons (chemical)
delivery.
Antiaircraft artillery and mobile
surface-to-surface missiles located
Provides increased protection to massed forces before attack;
well forward with maneuver
extends air defense umbrella forward as units advance.
elements.
Demonstrations and feints.
May precede an attack; may deceive actual point of attack.
Protects assembly areas and forces as they prepare for attack.
Establishment and strengthening of
May be effort to prevent friendly forces from seeing attack
counterreconnaissance screen.
preparations.
Concentration of mass toward one or
May indicate intent for single or double envelopment, particularly
both flanks within the forward area.
if massing units are armor heavy.
Increased patrolling or ground
May indicate efforts to gather detailed intelligence regarding
reconnaissance.
friendly dispositions prior to attack.
Command posts located well
Indicates preparation to command an offensive task from as far
forward; mobile command posts
forward as possible.
identified.
Movement of noncombatants from
Indicates preparation for rapid forward advance of troops and
the area of operations.
follow-on forces.
Often indicates major attacks, particularly against fortified
Extensive conduct of drills and
positions or strongly defended natural or manmade barriers,
rehearsals in unassigned areas.
which require rehearsal of specialized tactics and skills.
Rehearsals are completed and the unit is preparing for offensive
Cessation of drills and rehearsals.
tasks.
Increased activity in supply,
May indicate movement of additional forces to the front to sustain
maintenance, and motor transport
a major attack. Stocking of sustainment items, such as
areas.
ammunition and medical supplies, before an attack.
Increased aerial reconnaissance
Threat effort to collect further intelligence on friendly dispositions
(including unmanned aircraft
or defensive positions.
systems).
Establishment of forward arming and
Preparation for increased sorties for aircraft and faster turnaround
refueling points, auxiliary airfields, or
time and aviation sustainment. Indicates preparation to support
activation of inactive airfields.
offensive tasks with aircraft as far forward as possible.
B-2
ATP 2-33.4
18 August 2014
Indicators in Decisive Action
Table B-1. Offensive indicators (continued)
Activity
Explanation
Clearing lanes through own
Facilitates forward movement and grouping of assault units,
obstacles.
particularly at night, and usually immediately precedes an attack.
Reconnaissance, marking, and
destruction of defending force’s
Indicates where assaults will occur.
obstacles.
Gap-crossing equipment (swimming
vehicles, bridging, ferries, assault
Expect a substantial effort to cross a water obstacle during a main
boats) located in forward areas
attack.
(provided large water obstacle or
gap).
Staging of airborne, air assault, or
Airborne or air assault operations will likely indicate efforts to
special forces with transportation
attack friendly commands, communications, or sustainment
assets such as transport aircraft or
nodes. May indicate a main effort in which airborne forces will link
helicopters.
with ground maneuver forces.
May indicate intent to conduct offensive tasks; however,
Increased signals traffic or radio
increased traffic may be an attempt to deceive. Radio silence
silence.
denies information derived from signals intelligence.
Signals intelligence and electronic
Provides electronic attack and surveillance support for the attack.
warfare assets located forward.
Table B-2. Defensive indicators
Activity
Explanation
Preparation of battalion and
company defensive areas consisting
Indicates intent for holding terrain with defense in-depth, normally
of company and platoon strong
supported by armored counterattack forces.
points.
Extensive preparation of field
fortifications, obstacles, and
Indicates strong positional defense.
minefields.
Attachment of additional antitank
Indicates intent to contest friendly armor in forward positions, and
assets to frontline defensive
attempts to attrite and channel friendly armor into engagement
positions.
areas for armor counterattack forces.
Formation of antitank strong points
May allow penetration of friendly armor into engagement areas.
in depth along avenues of approach.
Will engage armor in depth.
Increases survivability of artillery in the defense. Indicates great
Preparation of alternate artillery
effort to support main defensive area with artillery—no withdrawal
positions.
of maneuver forces from main defense unless defeated.
Concentration of armor units in
Indicates holding armor units in reserve for possible counterattack
assembly areas in the rear of the
or counteroffensive tasks.
main defensive area.
Presence of concentrated antitank
Provides quick reaction capability against armor penetrations of
reserves.
the main defense.
Displacement of sustainment and
Facilitates defensive repositioning, maneuver, and counterattacks
medical units toward the rear area.
(support units are not “in the way”).
Reduces the burden on sustainment support during the battle,
Pre-stocking of ammunition,
reduces vulnerability of interdiction of supplies, and ensures
supplies, and engineer or pioneer
strong points can survive for reasonable periods if bypassed or
equipment in forward positions.
cut off by advancing forces.
18 August 2014
ATP 2-33.4
B-3
Appendix B
Table B-2. Defensive indicators (continued)
Activity
Explanation
Increased depth from the forward
Allows continued employment of artillery during maneuver
line of troops of artillery and surface-
defense without significant rearward displacement.
to-surface missile units.
Increased use of land-line
Implies intent to remain in position because landlines are less
communications—often with
vulnerable to electronic warfare and provide more secure
corresponding decrease in radio
communications.
traffic.
Presence of dummy positions,
Complicates friendly targeting and analysis. Deceives attacking
command posts, and weapons.
force of actual defensive positions and strength.
Air defense more concentrated in
Indicates location of numerous high-value targets, such as armor,
one particular area.
sustainment, artillery, or command posts.
Table B-3. Delaying indicators
Activity
Explanation
Withdrawal from defensive positions
Indicates delaying action to avoid decisive engagements.
before becoming heavily engaged.
Numerous local counterattacks with
limited objectives; counterattacks
Assists disengaging units in contact, rather than an attack to
broken off before position is
restore position.
restored.
Units bounding rearward to new
Indicates units conducting local withdrawals to new positions.
defensive positions, while another
Usually an effort to preserve the defending force and trade space
force begins or continues to engage.
for time.
Maximum firepower located forward,
Intent to inflict casualties thus slowing advance of attacking force
firing initiated at long ranges.
and provide sufficient volume of fire to avoid decisive
engagements. Allows for time to disengage and reposition
defending forces.
Extremely large unit frontages
Indicates delaying action to economize force, allowing larger
compared to usual defensive
formations to withdraw.
positions.
Chemical or biological weapons in
forward areas. Reports of threat in
Indicates possible chemical munitions use. Chemically
chemical protective clothing while
contaminated areas cause significant delays to attacking forces.
handling munitions.
Identification of dummy positions
Indicates defending force using economy of force. Causes
and minefields.
advancing force to determine if mines are live or inert.
B-4
ATP 2-33.4
18 August 2014
Indicators in Decisive Action
Table B-4. Withdrawal indicators
Activity
Explanation
Systematic destruction of bridges,
Denies advancing force the use of infrastructure and installations
communication facilities, and other
in withdrawal areas.
assets.
Establishment of a covering force or
Covers withdrawal of main body; usually consists of a sub-
rear guard.
element of the main force; usually only the rear guard element
engages attacking forces.
Increased rearward movement at
Attempt to avoid contact with the attacking unit in order to
night, particularly during inclement
preserve the force and its combat power.
weather.
Minimal presence of sustainment
Withdrawal of nonessential sustainment and medical assets. It
and medical units.
may also indicate the inability to move depots and dumps.
Establishing and marking withdrawal
Facilitates rapid movement of forces to the rear. Indicates attempt
routes and traffic control points.
to preserve force by conducting an organized and rapid
withdrawal.
Preparation of new defensive
Indicates an attempt to establish new positions along suitable
positions beyond supporting range
terrain before the arrival of deliberately withdrawn forces.
of present positions.
Increased engineer activity and
Mobility operations facilitate a withdrawal by maintaining lines of
stockpiling of explosives in threat
communications for own forces. Demolition preparation indicates
rear area near bridges, tunnels, or
likely destruction of infrastructure in front of attacking force.
built-up areas.
Rearward movement of long-range
Positions long-range artillery in subsequent defensive positions in
artillery.
order to support withdrawal with indirect fire.
Activation of command posts well
Establishes command nodes in the new position and along route
removed (beyond usual norms) from
of march in order to control movement and arrival of forces.
the present battle area. Positioning
of command posts along route of
withdrawal.
Table B-5. Population indicators
Indicators of Aggressive Behavior Within the Population
Identification of agitators, insurgents, and militias or criminal organizations, as well as their supporters
and sympathizers, who suddenly appear in, or move from, an area.
New faces or unknown people in a rural community.
Unusual gatherings among the population.
Disruption of normal social patterns.
Mass migration from urban to rural locations or from rural to urban locations.
Massing of combatants of competing power groups.
Increase in the size of embassy or consulate staffs from a country or countries that support indigenous
disaffected groups, particularly those hostile to the United States or the current intervention.
Increase in neighboring countries of staff and activities at embassies or consulates of countries
associated with supporting indigenous disaffected groups.
Lack of children playing outside in neighborhoods.
Increased travel by suspected subversives or leaders of competing power bases to countries hostile to
the United States or opposed to the current intervention.
Influx of opposition, resident, and expatriate leaders into the area of operations.
Reports of opposition or disaffected indigenous population receiving military training in foreign countries.
Increase of visitors—such as tourists, technicians, business persons, religious leaders, officials—from
groups or countries hostile to the United States or opposed to the current intervention.
18 August 2014
ATP 2-33.4
B-5
Appendix B
Table B-5. Population indicators (continued)
Indicators of Aggressive Behavior Within the Population (continued)
Close connections between diplomatic personnel of hostile countries and local opposition groups.
Communications between opposition groups and external supporters.
Increase of disaffected youth gatherings, such as student protests or demonstrations.
Establishment of organizations of unexplained origin and with unclear or nebulous aims.
Establishment of new organizations that replace an existing organizational structure with identical aims.
Appearance of many new members in existing organizations, such as labor unions.
Infiltration of student organizations by known agitators.
Appearance of new organizations stressing grievances or interests of repressed or minority groups.
Reports of large donations to new or revamped organizations.
Reports of payment to locals for engaging in subversive or hostile activities.
Reports of the formation of opposition paramilitary or militia organizations.
Reports of lists of targets for planned opposition attacks.
Appearance of “professional” agitators in gatherings or demonstrations that result in violence.
Evidence of paid and armed demonstrators’ participation in riots or violent protests.
Significant increase in thefts, armed robberies, and violent crime in rural areas; increase in bank
robberies in urban areas.
Opposition-Directed Aggressive Behavior Within the Population
Refusal of population to pay, or unusual difficulty in collecting rent, taxes, or loan payments.
Trends of demonstrated hostility toward government forces or the mission force.
Unexplained disappearance of the population or avoidance of certain areas.
Unexplained disappearance or relocation of children and adolescents.
Reported incidents of attempted recruitment to join new movements or underground organizations.
Criminals and disaffected youth who appear to be acting with and for the opposition.
Reports of extortion and other coercion by opposition elements to obtain financial support.
Use of fear tactics to coerce, control, or influence the local population.
Surveillance of host-nation government or mission force facilities and personnel.
Activities Directed Against the Government or Mission Force Within the Population
Failure of police and informer nets to report accurate information, which may indicate sources are actively
supporting opposition elements or the sources are intimidated.
Decreasing success of government law enforcement or military infiltration of opposition or disaffected
organizations.
Assassination or disappearance of government intelligence sources.
Reports of attempts to bribe or blackmail government officials, law enforcement employees, or mission
personnel.
Classified information leaked to the media.
Sudden affluence of certain government and law enforcement personnel.
Recurring failure of government or mission force raids on suspected opposition organizations or illegal
activities apparently due to forewarning.
Increased hostile or illegal activity against the government, its law enforcement and military organizations,
foreigners, minority groups, or competing political, ethnic, linguistic, or religious groups.
Demonstrations against government forces, minority groups, or foreigners designed to instigate violent
confrontations with government or mission forces.
Increased antigovernment or mission force rhetoric in local media.
B-6
ATP 2-33.4
18 August 2014
Indicators in Decisive Action
Table B-5. Population indicators (continued)
Activities Directed Against the Government or Mission Force Within the Population (continued)
Occurrence of strikes or work force walkouts in critical industries or geographic areas intended to cast
doubt on the government’s ability to maintain order and provide security and services to the people.
Unexplained loss, destruction, or forgery of government identification cards and passports.
Recurring unexplained disruption of public utilities.
Reports of terrorist acts or extortion attempts against local government leaders and business persons.
Murder or kidnapping of government, military, and law enforcement officials or mission force personnel.
Closing of schools.
Reports of attempts to obtain classified information from government officials, government offices, or
mission personnel.
Table B-6. Propaganda indicators
General Indicators of Negative Propaganda
Dissident propaganda from unidentified sources.
Increase in the number of entertainers with a political message.
Increase of political themes in religious services.
Increase in appeals directed at intensifying general ethnic or religious unrest in countries where ethnic or
religious competition exists.
Increase of agitation on issues for which there is no identified movement or organization.
Renewed activity by dissident or opposition organizations thought to be defunct or dormant.
Circulation of petitions advocating opposition or dissident demands.
Appearance of opposition slogans and pronouncements by word-of-mouth, graffiti, posters, leaflets, and
other means.
Propaganda linking local ethnic groups with those in neighboring countries or regions.
Clandestine radio broadcasts intended to appeal to those with special grievances or to underprivileged
ethnic groups.
Use of bullhorns, truck-mounted loudspeakers, and other public address equipment in “spontaneous”
demonstrations.
Presence of non-media photographers among demonstrators.
Dissident propaganda from unidentified sources.
Propaganda Activities Directed Against the Established Government
Attempts to discredit or ridicule national or public officials.
Attempts to discredit the judicial and law enforcement system.
Characterization of government projects and plans.
Radio and Internet propaganda from foreign countries that is aimed at the target country’s population and
accuses the target country’s government of failure to meet the people’s needs.
18 August 2014
ATP 2-33.4
B-7
Appendix B
Table B-6. Propaganda indicators (continued)
Propaganda Activities Directed Against the Mission Force and Host-Nation Military and Law
Enforcement
Spreading accusations that the host-nation military and police are corrupt and out of touch with the
people.
Spreading accusations that mission force personnel will introduce customs or attitudes that are in
opposition to local cultural or religious beliefs.
Character assassinations of mission, military, and law enforcement officials.
Demands to remove strong anti-position or anti-crime military and law enforcement leaders from office.
Calls for the population to cease cooperating with the mission force or host-nation military and law
enforcement.
Widespread hostile media coverage of even minor criminal violations or incidents involving mission force
personnel.
Accusations of brutality or ineffectiveness, or claims that mission or government forces initiated violence
following confrontations.
Publication of photographs portraying repressive and violent acts by mission force or government forces.
Refusal of business persons and shop owners to conduct business with mission force personnel.
Propaganda Activities Directed Against the Education System
Appearance of questionable doctrine and teachings in the educational system.
Creation of ethnic, tribal, religious, or other interest group schools outside the government educational
system, which propagate opposition themes and teachings.
Charges that the educational system is only training youth to do the government’s bidding.
Student unrest manifested by new organizations, proclamations, demonstrations, and strikes against
authority.
Table B-7. Commodities indicators
Indicators of Negative Food-Related Activities
Diversion of crops or meat from markets.
Unexplained shortages of food supplies when there are no reports of natural causes.
Increased reports of foodstuffs pilfering.
Sudden increase in food prices, possibly indicating an opposition-levied tax.
Spot shortages of foodstuffs in regions or neighborhoods associated with a minority group or weaker
competing interest group, while food supplies are generally plentiful in other areas. Conversely, sudden
local shortages of foodstuffs in rural areas may indicate the existence of an armed opposition group in
that region.
Sudden increase of meat in markets, possibly indicating slaughtered livestock because of a lack of fodder
to sustain them.
Appearance of emergency relief supplies for sale in black markets possibly indicating diversion from
starving population.
Appearance of relief supplies for sale in normal markets in a country or region recently suffering from
large-scale hunger, which may indicate the severity of the food crisis, is diminishing.
Indicators of Negative Arms and Ammunition-Related Activities
Increased loss or theft of weapons from military and police forces.
Discovery of arms, ammunition, and explosives being clandestinely manufactured, transported, or
cached.
Attacks on patrols resulting in the loss of weapons and ammunition.
Increased purchase of surplus military goods.
Sudden increase in prices for arms and ammunitions on the open market.
Reports of large arms shipments destined for neighboring countries, but not intended for that government.
Reports of known arms traffickers establishing contacts with opposition elements.
B-8
ATP 2-33.4
18 August 2014
Indicators in Decisive Action
Table B-7. Commodities indicators (continued)
Indicators of Negative Arms and Ammunition-Related Activities (continued)
Increase in armed robberies.
Reports of thefts or sudden shortages of chemicals, which could be used in the clandestine manufacture
of explosives.
Reports of large open-market purchases of explosives-related chemicals without an identifiable industrial
use.
Appearance of manufactured or smuggled arms from noncontiguous foreign countries.
Indicators of Negative Clothing-Related Activities
Unusual, systematic purchase or theft of clothing materials that could be used for the manufacture of
uniforms or footwear.
Unusual scarcity of clothing or material used in the manufacture of clothing or footwear.
Distribution of clothing to underprivileged or minority classes by organizations of recent or suspect origin.
Discovery of caches of uniforms and footwear or materials that could be used to manufacture uniforms
and footwear.
Increase of males in the streets wearing military style clothing or distinctive markings.
Indicators of Negative Medicine-Related Activities
Large-scale purchasing or theft of drugs and medicines or the herbs used to manufacture local remedies.
Scarcity of drugs and medicinal supplies on the open or black markets.
Diversion of medical aid donations.
Discovery of caches or medical supplies.
Indicators of Negative Communications-Related Activities
Increase in the purchase and use of radios.
Discovery of caches of communication equipment.
Unusual increase in amateur radio or cellular telephone communications traffic.
18 August 2014
ATP 2-33.4
B-9
Appendix B
Table B-8. Environment-related indicators
Indicators of Suspicious Rural Activities
Evidence of increased foot traffic in the area.
Increased travel within and into remote or isolated areas.
Unexplained trails and cold campsites.
Establishment of new, unexplained agricultural areas or recently cleared fields.
Unusual smoke, possibly indicating the presence of a campsite or a form of communication.
Concentration of dead foliage in an area, possibly indicating use of camouflage.
Presence of foot traps, spikes, booby traps, or improvised mines along routes and trails.
Indicators of Suspicious Urban Activities
Apartments, houses, or buildings being rented, but not lived in as homes.
Slogans written on walls, bridges, and streets.
Defacement of government and mission force information signs.
Sabotage of electrical power network, pollution of urban area’s water supply.
Terrorist acts against physical targets such as bridges, dams, airfields, or buildings.
Change of residence of suspected agitators or opposition leaders.
Discovery of message dead drops.
Increased smuggling of currency, gold, gems, narcotics, medical supplies, and arms into urban centers.
Appearance of abnormal amounts of counterfeit currency.
Increase in bank robberies.
Work stoppages or slowdowns in essential industries.
Marked decline in product quality in essential industries.
Marked increase in equipment failures in essential industries.
Unexplained explosions in essential utilities and industries.
Establishment of roadblocks or barricades around neighborhoods associated with opposition elements.
Attempts to disrupt public transport through sabotage.
Malicious damage to industrial products or factory machinery.
Table B-9. Improvised explosive device indicators, observables, and signatures
Indicators of Basic Improvised Explosive Device (IED) Indicators, Observables, and Signatures
Vehicles following convoys for a long distance and then pulling off to the side of the road.
Dead animals along the roadways.
Freshly dug holes along the roadway (possible future IED report).
New dirt or gravel piles.
Obstacles in roadway used to channel the convoy.
Personnel on overpasses.
Signal with flares or city lights (turned off or on) as convoy approaches.
Absence of the ordinary children in the area, merchants at a market.
Key Indicators, Observables, and Signatures (Indicating Something is About to Happen)
Dramatic changes in population from one block to the next.
Dramatic changes in illumination (lights) from one area to the next during hour of limited visibility.
Absence of children when normally present.
Identification of markings indicated in intelligence reports of an IED site.
New dirt or gravel piles.
B-10
ATP 2-33.4
18 August 2014
Indicators in Decisive Action
Table B-10. Threat environment indicators
Indicator
Information Objective
What groups (tribes, clans) are local rivals?
How intense is the rivalry?
What are the relative strengths or external alliances of rival groups?
Local Conflict Casualty
U.S. presence or host government?
Do locals normally carry arms?
Does group rivalry parallel rivalry within the host government?
Table B-11. Recurrence of same-clan indicators
Indicator
Information Objective
Is clan native to the area? If so, where does clan reside, in which villages?
How big is the clan, how many male adults?
Who is the acknowledged chief?
Do or did any members of clan have positions in former regime? Who are
they? Do any of them have access to arms or ammunition? Where is their
cache or source?
Do any of them provide training to other relatives?
What are the usual economics of the clan?
Recurrence of Same Clan
Can the clan exploit these activities to gain arms or facilitate or conceal
Name Among Detainees
their operations?
Has any relative been killed by U.S. or multinational forces? If so, is there
a current mood of blood vengeance within the clan?
Which mosques do clan members attend? Do the imams follow a
particular doctrine? Is that doctrine radical or moderate? If radical, do the
imams encourage hostility to the U.S. presence?
Has the clan offered protection to any strangers or foreigners? Are these
people recent arrivals or long-term residents? What is the identity and
agenda or business of such people?
18 August 2014
ATP 2-33.4
B-11
This page intentionally left blank.
Glossary
SECTION I - ACRONYMS AND ABBREVIATIONS
ACH
Analysis of Competing Hypotheses
ADP
Army doctrine publication
ADRP
Army doctrine reference publication
AO
area of operations
ASCOPE
area, structures, capabilities, organizations, people, and events
ATP
Army techniques publication
ATTP
Army tactics, techniques, and procedures
CARVER
criticality, accessibility, recuperability, vulnerability, effect, and recognizibility
CIED
counter-improvised explosive device
COA
course of action
DA
Department of the Army
DCGS-A
Distributed Common Ground System-Army
DOD
Department of Defense
DSCA
defense support of civil authorities
FM
field manual
FOUO
For Official Use Only
G-2
assistant chief of staff, intelligence
HVI
high-value individual
IED
improvised explosive device
IPB
intelligence preparation of the battlefield
JP
joint publication
MCS
Mission Command System
PIR
priority intelligence requirement
PMESII
political, military, economic, social, information, and infrastructure
S-2
intelligence staff officer
SIGINT
signals intelligence
SNA
social network analysis
TC
training circular
U.S.
United States
18 August 2014
ATP 2-33.4
Glossary-1
Glossary
SECTION II - TERMS
all-source intelligence
(Army) The integration of intelligence and information from all relevant sources in order to analyze
situations or conditions that impact operations. (ADRP 2-0)
defensive task
A task conducted to defeat an enemy attack, gain time, economize force, and develop conditions
favorable for offensive or stability tasks. (ADRP 3-0)
indications
(joint) In intelligence usage, information in various degrees of evaluation, all of which bear on the
intention of a potential enemy to adopt or reject a course of action. (JP 2-0)
offensive task
A task conducted to defeat and destroy enemy forces and seize terrain, resources, and population
centers. (ADRP 3-0)
site exploitation
(joint) A series of activities to recognize, collect, process, preserve, and analyze information,
personnel, and/or materiel found during the conduct of operations. (JP 3-31)
stability operations
(joint) An overarching term encompassing various military missions, tasks, and activities conducted
outside the United States in coordination with other instruments of national power to maintain or
reestablish a safe and secure environment, provide essential governmental services, emergency
infrastructure reconstruction, and humanitarian relief. (JP 3-0)
Glossary-2
ATP 2-33.4
18 August 2014
References
REQUIRED PUBLICATIONS
These sources must be available to intended users of this publication.
JOINT AND DEPARTMENT OF DEFENSE PUBLICATIONS
JP 1-02. Department of Defense Dictionary of Military and Associated Terms. 8 November 2010.
ARMY PUBLICATIONS
ADP 2-0. Intelligence. 31 August 2012.
ADP 3-0. Unified Land Operations. 10 October 2011.
ADP 5-0. The Operations Process. 17 May 2012.
ADRP 1-02. Terms and Military Symbols. 24 September 2013.
ADRP 2-0. Intelligence. 31 August 2012.
ADRP 3-0. Unified Land Operations. 16 May 2012.
ADRP 5-0. The Operations Process. 17 May 2012.
RELATED PUBLICATIONS
These documents are cited in this manual.
JOINT AND DEPARTMENT OF DEFENSE PUBLICATIONS
Most joint publications are available online at http://www.dtic.mil/doctrine/new_pubs/jointpub.htm.
DOD publications are available at the DOD Issuances Web site: www.dtic.mil/whs/directives.
JP 2-0. Joint Intelligence. 22 October 2013.
JP 3-0. Joint Operations. 11 August 2011.
JP 3-28. Defense Support of Civil Authorities. 31 July 2013.
JP 3-31. Command and Control for Joint Land Operations. 24 February 2014.
ARMY PUBLICATIONS
Most Army doctrinal publications are available online at www.apd.army.mil.
ADP 6-0. Mission Command. 17 May 2012.
ADRP 3-90. Offense and Defense. 31 August 2012.
ATP 3-05.1. Unconventional Warfare. 6 September 2013.
ATTP 3-90.15. Site Exploitation Operations. 8 July 2010.
FM 2-01.3. Intelligence Preparation of the Battlefield/Battlespace. 15 October 2009.
FM 3-07. Stability. 2 June 2014.
FM 3-22. Army Support to Security Cooperation. 22 January 2013.
FM 3-55. Information Collection. 3 May 2013.
FM 27-10. The Law of Land Warfare. 18 July 1956.
18 August 2014
ATP 2-33.4
References-1
References
OTHER PUBLICATIONS
Heuer, Richards J., Jr. Psychology of Intelligence Analysis. Central Intelligence Agency: Center for the
Study of Intelligence, 1999. Available online at https://www.cia.gov/library/center-for-the-
study-of-intelligence/csi-publications/books-and-monographs/psychology-of-intelligence-
analysis/, accessed 15 July 2014.
Intelligence Community Directive Number 203. Analytic Standards. 21 June 2007. Available online at
http://www.dni.gov/index.php , accessed 23 July 2014. Select Intelligence Community>IC
Policies and Reports.
Red Team Handbook. Fort Leavenworth, KS: University of Foreign Military and Cultural Studies.
accessed 23 July 2014. Select Schedules and Handbooks.
Title 32, United States Code. National Guard. Available online at the U.S. House of Representatives
Office of the Law Revision Counsel Web site at http://uscode.house.gov/ , accessed 23 July
2014.
WEB SITES
Central Intelligence Agency. https://www.cia.gov , accessed 15 July 2014.
The Foundation for Critical Thinking. www.criticalthinking.org , accessed 15 July 2014.
RECOMMENDED READINGS
These documents contain relevant supplemental information.
FM 2-0. Intelligence Operations. 15 April 2014.
FM 7-15. The Army Universal Task List. 27 February 2009.
Paul, Richard and Linda Elder. A Guide for Educators to Critical Thinking Competency Standards.
2005. Tomales, CA: Foundation for Critical Thinking. 2005. Available online at
www.criticalthinking.org , accessed 15 July 2014.
U.S. Army Combined Arms Center. http://usacac.army.mil/cac2/CADD/ , accessed 15 July 2014.
SOURCES USED
AR 380-5. Department of the Army Information Security Program. 29 September 2000.
Elder, Linda and Richard Paul. The Thinker’s Guide to Analytic Thinking: How to Take Thinking Apart
and What to Look for When You Do. Tomales, CA: Foundation for Critical Thinking. 2012.
Available online at www.criticalthinking.org , accessed 15 July 2014.
Memorandum, Deputy Chief of Staff, G-3/5/7, DAMO-ODA-A, 30 August 2010, subject: Operations
Security (OPSEC) Guidance for Counter-Improvised Explosive Device (C-IED) and
Improvised Explosive Device Defeat (IEDD). Available online: www.ikn.army.mil , accessed
23 July 2014. Select Applications>IKN Applications>Document Management System
(DMS)>Doctrine (folder)>Policy Memoranda (folder)>OPSEC Guidance.
Paul, Richard and Linda Elder. The Miniature Guide to Critical Thinking: Concepts and Tools. 2009.
Tomales, CA: Foundation for Critical Thinking. 2012. Available online at
www.criticalthinking.org , accessed 15 July 2014.
PRESCRIBED FORMS
None.
REFERENCED FORMS
Unless otherwise indicated, DA forms are available on the Army Publishing Directorate Web site
DA Form 2028. Recommended Changes to Publications and Blank Forms.
References-2
ATP 2-33.4
18 August 2014
Index
Entries are by paragraph number unless indicated otherwise.
High Impact/Low Probability,
analyzing networks and
A
A-18−A-22
associations, 5-26
ACH, 4-10, 4-12, A-78−88
methods
Red Hat Analysis, A-28−A-32
8-step procedure, A-80
link analysis, 5-27, 5-28, 5-49
Team A/Team B
diagnostic analytical technique,
network analysis, 5-48
A-13−A-17
6-22
sociometrics or social
What If Analysis, A-23−A-27
example, A-84
network analysis, 5-91
core Army analytic techniques,
all-source intelligence, 1-9
Army Mission Command System
3-3, 5-2
analyst responsibilities, 4-28,
and DCGS-A functions,
analyzing complete networks
4-59, B-1
1-24−1-26
and associations, 5-2
definition, 1-14
brainstorming, 5-4
automation support to intelligence
steps, 1-6
comparison, 5-13
analysis, 1-22
Analysis of Competing
use of CARVER techniques,
and DCGS-A, 1-23
Hypotheses. See ACH.
5-16
B
conducting pattern analysis,
analytic support to unified land
5-2, 5-99
operations, 6-2
basic structured analytic
developing situational
techniques in decisive action,
techniques, 3-7
understanding and
6-20
event mapping, 3-25-3-31
conclusions, 5-2
to defensive operations, 6-5
event trees, 3-32-3-35
mathematical analysis, 5-20
to defensive operations, 6-8
matrices, 3-14−3-18
situational logic, 5-23
to DSCA, 6-14
use of ASCOPE and PMESII,
to offensive operations, 6-4
3-16
counter-improvised explosive
to stability operations, 6-10
sorting, 3-8-3-13
device. See CIED.
analytic support to unique
subjective probability,
critical and creative thinking, 1-8,
activities, 6-25
3-36−3-44
2-13
building partnership capacity,
threat intentions matrix,
critical thinking skills, 2-15, 2-16
6-26
3-19−3-24
protection, 6-29-6-31
weighted ranking, 3-45−3-51
D
synchronize
basic thinking abilities
DCGS-A
information-related
information ordering, 2-2, 2-3
role in automation support to
capabilities, 6-32−6-36
pattern recognition, 2-2, 2-4
intelligence analysis,
analytic support to unique
reasoning, 2-2, 2-5
1-22-1-29
missions, 7-1
deception rules, 4-11
C
CIED. 7-8−7-15
Defense intelligence enterprise,
CIED
counterinsurgency, 7-5−7-7
1-21
analytical support, 7-8
site exploitation, 7-17−7-23
defense support of civil authorities
collaboration. See also
analytic techniques, 1-8
analytic support process,
intelligence warfighting function.
basic structured, 3-3, 3-6−3-51
6-14−6-19
and automation support, 1-22
core Army, 3-3, 5-2
and DIA, 1-20
defensive operations, 6-5
diagnostic, 4-1, 4-3, 5-2, 6-21,
and dialogue, 1-11
defensive tasks
table 6-1
and the intelligence warfighting
definition, 6-5
emerging, A-1
function, 1-19, 7-18
in decisive actions, 6-2, 6-6,
diagnostic analytic techniques,
6-20, 7-1
collaboration, 1-16, 4-25
4-2, 6-21
in unique missions, 7-2, 7-5,
conducting studies
deception detection, 4-4−4-12
7-8, 7-16
steps, 4-58, 4-59
indicators, 4-27
to support problem solving, 3-1
tasks, 4-60-4-62
key assumptions check, 4-13
analytical pitfalls, 2-32, 3-4, A-87
quality of information check,
contrarian techniques, A-2, A-3
biases, 2-38
4-20
Counterfactual Reasoning,
logic pitfalls, 2-33
A-33−A-45
Director of National Intelligence
Devil’s Advocacy, A-4−A-12
role in analytic thinking, 1-5
18 August 2014
ATP 2-33.4
Index-1
Index
Entries are by paragraph number unless indicated otherwise.
Distributed Common Ground
threat environment, table B-10
R
System-Army. See DCGS-A.
withdrawal, table B-4
reasoning checklist, 2-19
intellectual standards, 2-20
E
reasoning types, 2-5
intellectual traits
abductive reasoning, 2-11,
elements of thought, 2-17−2-21
confidence in reason, 2-22,
2-12
and intellectual standards,
2-30
analogical reasoning, 2-8, 2-9
2-22
fair-mindedness, 2-22, 2-24
deductive reasoning, 2-10
in critical thinking, 2-13, 2-16
intellectual auatonomy, 2-22,
inductive reasoning, 2-6, 2-7
emerging analytic techniques,
2-31
6-23
S
intellectual courage, 2-22, 2-26
emerging analytic techniques, A-1
intellectual empathy, 2-22,
single-source analysis, 1-14
2-27
site exploitation definition, 7-16
G
intellectual humility, 2-22, 2-25
SNA
G-2 role in developing indicators,
intellectual integrity, 2-22, 2-28
purpose, 5-91
4-41
intellectual perseverance,
used in logistical support
2-22, 2-29
I
activities, 5-95
intelligence analysis
used in targeting process, 5-96
IED
steps
used with pattern analysis,
activity model, 7-12, 7-13
evaluate, 1-6
5-92
network, 7-8, 7-12, 7-13
analyze, 1-6, 1-12
social network analysis. See SNA.
imaginative techniques, A-46,
synthesize, 1-6
A-47
stability operations definition, 6-9
intelligence disciplines
alternative future analysis,
in support of analytical efforts,
structured analytic techniques
A-61−A-67
1-12
ACH, A-78−A-88
brainstorming, A-48−A-50
applying theory, A-89, A-90,
intelligence warfighting function,
morphological analysis,
Delphi technique, A-91
1-21, 1-22
A-68−A-76
future wheel, A-95−A-97
and collaboration, 1-19-1-21
outside-in thinking, A-51-A-53
knowledge planning,
and DCGS-A, 1-24-1-29
Red Team analysis, A-54−A-60
A-98−A-101
iimprovised explosive device. See
K
rules for verification,
IED.
key reporting criteria, 4-10
A-102−A-104
indications definition, 4-28
structured analytic techniques,
O
A-77
indicator types
offensive operations, 6-3
commodities, table B-7
T
offensive tasks, definition, 6-3
defensive, table B-2
threat intentions matrix, 3-19
delaying, table B-3
P
environment related, table B-8
types of analysis
pattern analysis tools, 5-102
IED, observables, and
in CIED operations
signatures, table B-9
chronologies timelines,
individual, 7-10
offensive, table B-1
5-103−5-113
nodal, 7-10
population, table B-5
incident overlay, 5-117−5-119
pattern of life analysis,
U
propaganda, table B-6
recurrence of same clan, table
5-120−5-123
unified land operations, 6-2
B-11
plot sheet, 5-114−5-116
Index-2
ATP 2-33.4
18 August 2014
ATP 2-33.4
18 AUGUST 2014
By order of the Secretary of the Army:
RAYMOND T. ODIERNO
General, United States Army
Chief of Staff
Official:
GERALD B. O’KEEFE
Administrative Assistant to the
Secretary of the Army
1421314
DISTRIBUTION:
Active Army, Army National Guard, and United States Army Reserve: Distributed in electronic media
only (EMO).
This page intentionally left blank.
PIN: 104503-000
FOR OFFICIAL USE ONLY
TC 2-50.5
Intelligence Officer’s Handbook
January 2010
DISTRIBUTION RESTRICTION: Distribution authorized to U.S. Government agencies only because it requires
protection in accordance with AR 380-5 and as specified by DCS G-3 Message DTG 091913Z MAR04.
This determination was made on 17 March 2008. Other requests shall be referred to ATTN: ATZS-CDI-D,
U.S. Army Intelligence Center of Excellence, Fort Huachuca, AZ
85613-7017, or via email at:
ATZS-FDC-D@conus.army.mil.
DESTRUCTION NOTICE: Destroy by any method that prevents disclosure of contents or reconstruction of the
document.
Headquarters, Department of the Army
FOR OFFICIAL USE ONLY
This publication is available at:
Army Knowledge Online
General Dennis J. Reimer
Training and Doctrine Digital Library
United States Army Publishing Agency
TC 2-50.5
Training Circular
Headquarters
Department of the Army
No. 2-50.5
Washington, DC, 6 January 2010
Intelligence Officer’s Handbook
Contents
Page
PREFACE
v
Chapter 1
THE INTELLIGENCE WARFIGHTING FUNCTION
1-1
Overview
1-1
Effective Intelligence Characteristics
1-1
Intelligence Categories
1-3
Intelligence Disciplines
1-3
Chapter 2
ROLE OF INTELLIGENCE IN MILITARY DECISIONMAKING
2-1
The Rapid Decisionmaking and Synchronization Process
2-1
The Military Decisionmaking Process
2-1
Chapter 3
INTELLIGENCE PREPARATION OF THE BATTLEFIELD
3-1
Intelligence Preparation of the Battlefield Process
3-1
Step 1—Define the Operational Environment
3-1
Step 2—Describe Environmental Effects on Operations
3-4
Step 3—Evaluate the Threat
3-11
Step 4—Determine Threat Courses of Action
3-23
Chapter 4
G-2/S-2 OPERATIONS
4-1
Overview
4-1
Mobilization
4-1
Deployment
4-2
Employment
4-7
Sustainment
4-8
Redeployment
4-8
Appendix A
INTELLIGENCE READINESS TRAINING
A-1
Appendix B
INTELLIGENCE, SURVEILLANCE, AND RECONNAISSANCE
SYNCHRONIZATION
B-1
DISTRIBUTION RESTRICTION: Distribution authorized to U.S. Government agencies only because it requires
protection in accordance with AR 380-5 and as specified by DCS G-3 Message DTG 091913Z MAR04. This
determination was made on
17 March
2008. Other requests shall be referred to ATTN:
ATZS-CDI-D, U.S. Army Intelligence Center of Excellence, Fort Huachuca, AZ 85613-7017, or via email at
ATZS-FDC-D@conus.army.mil.
DESTRUCTION NOTICE: Destroy by any method that will prevent disclosure of contents or reconstruction of the
document.
i
FOR OFFICIAL USE ONLY
Contents
Appendix C BRIEFING AND DEBRIEFING PROGRAM
C-1
Appendix D
GRAPHIC INTELLIGENCE REPORTS
D-1
Appendix E
INTELLIGENCE SUPPORT TO TARGETING
E-1
Appendix F WEATHER ELEMENTS AND SUPPORT
F-1
Appendix G
INTELLIGENCE RESOURCES
G-1
GLOSSARY
Glossary-1
REFERENCES
References-1
INDEX
Index-1
Figures
Figure
3-1. Examples of ASCOPE characteristics
3-3
Figure
3-2. Example modified combined obstacle overlay
3-5
Figure
3-3. Example weather effects forecast matrix
3-8
Figure
3-4. Example weather impact chart for civil support operations
3-9
Figure
3-5. Example population status overlay
3-10
Figure
3-6. Example offensive threat template
3-13
Figure
3-7. Example defensive threat template
3-14
Figure
3-8. Example threat template for attacks on facilities or base camps
3-14
Figure
3-9. Example threat template in an urban environment
3-15
Figure
3-10. Example incident overlay
3-16
Figure
3-11. Example of a pattern analysis plot sheet
3-16
Figure
3-12. Example time event chart—Southwest Asia
3-17
Figure
3-13. Example association matrix
3-18
Figure
3-14. Example relationship matrix
3-19
Figure
3-15. Example activities matrix
3-20
Figure
3-16. Example link diagram
3-21
Figure
3-17. Example perception assessment matrix
3-23
Figure
3-18. Example situation template
3-26
Figure
3-19. Example event template
3-27
Figure
3-20. Example event matrix
3-27
Figure
3-21. Decision support template
3-28
Figure
3-22. Example high-value target list
3-28
Figure B-1. Relationship of information requirements
B-2
Figure B-2. ISR synchronization activities
B-3
Figure B-3. Example ISR synchronization matrix
B-8
Figure B-4. Example working matrix
B-9
Figure D-1. One-page graphic intelligence summary example
D-2
Figure D-2. Threat unit locations and mission activities (committed)
D-3
Figure D-3. Threat unit locations and mission activities (uncommitted)
D-3
Figure D-4. Threat mission capabilities assessment
D-4
ii
TC 2-50.5
6 January 2010
FOR OFFICIAL USE ONLY
Contents
Figure D-5. Threat problem area symbology
D-4
Figure D-6. Threat air activity symbology
D-5
Figure D-7. Predicted threat activity timelines
D-6
Figure D-8. Significant activities in the area of operations
D-8
Figure D-9. Storyboard example
D-9
Figure D-10. Sample summary of weekly murders
D-10
Figure D-11. Improvised explosive device activity summary
D-11
Figure D-12. Indications and warning reporting
D-12
Figure D-13. Sample detainee rollup
D-13
Figure D-14. Significant dates
D-14
Figure D-15. Predicted threat activity—next 24-48 hours example
D-15
Figure D-16. Sample high-value target list
D-16
Figure D-17. Be on the look-out list example
D-17
Figure E-1. D3A targeting process
E-3
Figure E-2. Examples of high-value targets
E-6
Figure E-3. Example of target selection standards matrix
E-8
Figure E-4. Example of target selection standards matrix used in OIF
E-9
Figure E-5. Example attack guidance matrix
E-10
Figure E-6. D3A versus F3EAD
E-19
Figure E-7. F3EAD methodology
E-19
Figure F-1. Solar radiation
F-4
Figure F-2. Example of a weather forecast chart
F-8
Figure F-3. Sample weather effects critical values
F-9
Figure F-4. National weather service wind chill chart
F-10
Figure G-1. Degree of slope calculator
G-5
Tables
Table 1-1. Intelligence warfighting function tasks
1-2
Table 1-2. Intelligence disciplines
1-4
Table 2-1. The running estimate
2-2
Table 2-2. Intelligence support to the MDMP
2-3
Table 3-1. Step 1—Define the operational environment
3-2
Table 3-2. Step 2—Describe environmental effects on operations
3-4
Table 3-3. Key infrastructure overlay
3-7
Table 3-4. Threat characteristics
3-11
Table 3-5. Step 3—Evaluate the threat
3-12
Table 3-6. Cultural comparison chart
3-21
Table 3-7. Step 4—Determine threat courses of action
3-23
Table 4-1. Intelligence transition factors
4-9
Table A-1. Intelligence factors for reset
A-2
6 January 2010
TC 2-50.5
iii
FOR OFFICIAL USE ONLY
Contents
Table A-2. Intelligence factors for train/ready
A-5
Table A-3. Intelligence factors for available
A-6
Table A-4. Rosetta Stone® language courses
A-7
Table A-5. Training by section/intelligence discipline
A-9
Table B-1. Develop requirements
B-4
Table B-2. Develop ISR synchronization tools
B-6
Table B-3. Support ISR integration
B-10
Table B-4. Disseminate
B-11
Table B-5. Assess ISR operations
B-13
Table B-6. Update ISR operations
B-14
Table C-1. Mission responsibilities
C-2
Table C-2. Key debriefing points
C-3
Table C-3. Debriefing considerations
C-4
Table E-1. Functions of intelligence support to targeting
E-2
Table E-2. Targeting methodology
E-4
Table E-3. Targeting considerations
E-4
Table E-4. High-payoff target list example
E-8
Table E-5. Warfighting function detection capabilities
E-13
Table E-6. Deliver functions and responsibilities
E-14
Table E-7. Battle damage assessment functions
E-17
Table E-8. CARVER technique
E-21
Table E-9. Bulk electric power supply
E-25
Table E-10. Target packet intelligence considerations
E-26
Table F-1. Weather intelligence officer responsibilities
F-1
Table F-2. Integrated meteorological system capabilities
F-2
Table F-3. Effects of weather conditions on military operations
F-3
Table F-4. Light data visibility
F-7
Table F-5. Extreme weather conditions
F-10
Table F-6. Estimating wind speed
F-10
Table F-7. Load-bearing capacity on fresh water ice
F-11
Table F-8. Weather effects on courses of action
F-11
Table F-9. Precipitation terms
F-12
Table F-10. Beaufort wind scale
F-12
Table F-11. Conversion factors
F-13
Table G-1. Land widths shown on U.S. military maps
G-5
Table G-2. Identification ranges
G-5
Table G-3. Route types and military load classifications
G-6
Table G-4. Basic data foot march factors
G-6
iv
TC 2-50.5
6 January 2010
FOR OFFICIAL USE ONLY
Preface
TC 2-50.5 replaces FM 34-8-2, dated 1 May 1998. This publication does not replace the fundamental principles
and tactics, techniques, and procedures contained in the other FM 2-series manuals; however, it does focus on
their application. It is to be used in conjunction with the other FM 2-series manuals and conforms to the
overarching doctrinal concepts presented in FM 3-0 and FM 2-0.
The target audience for this manual is the intelligence officers serving as the G-2/S-2 and their staffs—
intelligence warrant officers, noncommissioned officers, and junior enlisted Soldiers.
TC 2-50.5 applies to the Active Army, the Army National Guard/Army National Guard of the United States,
and the U.S. Army Reserve, unless otherwise stated.
The term intelligence officer generally refers to the G-2/S-2 and other intelligence positions within units and
organizations. The term operations officer generally refers to the G-3/S-3, and other operations positions within
units and organizations.
TC 2-50.5 uses joint terms where applicable. The terms with joint or Army definitions are in the text. They are
italicized and the number of the proponent publication follows the definition.
The use or mention of any commercial or private organization’s name or trademark and the organization’s
services or funds by the Army does not express or imply an endorsement of the sponsor or its products and
services by the Army.
Headquarters U.S. Army Training and Doctrine Command is the proponent of this publication. The preparing
agency is the U.S. Army Intelligence Center of Excellence (USAICoE), Fort Huachuca, AZ. Send written
comments and recommendations on DA Form 2028 (Recommended Changes to Publications and Blank Forms)
to: Commander, ATZS-CDI-D (TC 2-50.5), USAICoE, 550 Cibeque Street, Fort Huachuca, AZ 85613-7017;
by email to ATZS-FDC-D@conus.army.mil; or submit an electronic DA Form 2028.
6 January 2010
TC 2-50.5
v
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 1
The Intelligence Warfighting Function
This chapter discusses the warfighting functions, focusing mainly on the intelligence
warfighting function and its associated tasks, the characteristics of effective
intelligence, and the intelligence categories and disciplines.
OVERVIEW
1-1. The intelligence warfighting function is one of six
The Warfighting Functions
warfighting functions. A warfighting function is a group of
• Movement and maneuver
tasks and systems (people, organizations, information, and
processes) united by a common purpose that commanders
• Intelligence
use to accomplish missions and training objectives (FM 3-0).
• Fires
1-2. The intelligence warfighting function is the related
• Sustainment
tasks and systems that facilitate understanding of the
• Command and control
operational environment. It includes tasks associated with
• Protection
intelligence, surveillance, and reconnaissance operations and
is driven by the commander (FM 3-0). Intelligence is more than just collection; it is a continuous process
that involves analyzing information from all sources and conducting operations to develop the situation.
The intelligence warfighting function includes the following tasks:
Support to force generation.
Support to situational understanding.
Conduct intelligence, surveillance, and reconnaissance (ISR).
Provide intelligence support to targeting and information superiority.
1-3. Table 1-1 (page 1-2) lists the intelligence tasks and subtasks. (See FM 2-0.)
EFFECTIVE INTELLIGENCE CHARACTERISTICS
1-4. The effectiveness of the intelligence warfighting function is measured against the relevant
information quality criteria:
Accuracy. Intelligence must give commanders an accurate, balanced, complete, and objective
picture of the enemy and the operational environment. To any extent possible, intelligence
should accurately identify threat intentions, capabilities, limitations, and dispositions. It should
be derived from multiple sources and disciplines to minimize the possibility of deception or
misinterpretation. Alternative or contradictory assessments should be presented, when necessary,
to ensure balance and bias-free intelligence.
Timeliness. Intelligence must be provided early enough to support operations and prevent
surprise enemy action. It must flow continuously to the commander before, during, and after an
operation. Intelligence organizations, databases, and products must be available to develop
estimates, make decisions, and plan operations.
Usability. Intelligence must be presented in a format that is easily understood or displayed in a
format that immediately conveys the meaning to the consumer.
Completeness. Intelligence briefings and products must convey all the necessary components to
be as complete as possible.
6 January 2010
TC 2-50.5
1-1
FOR OFFICIAL USE ONLY
Chapter 1
Precision. Intelligence briefings and products must provide the required level of detail to answer
the requirements, no more and no less.
Reliability. Evaluate intelligence to determine whether the collected information—used in
intelligence briefings and products—is trustworthy, uncorrupted, and undistorted. Any concerns
should be stated up front.
1-5. Intelligence requires three additional criteria to be effective:
Relevant. Intelligence must support the commander’s concept of the operation and the unit’s
mission. It must be relevant to the capabilities of the unit and the commander’s critical
information requirements (CCIRs) and preferences.
Predictive. Intelligence should inform the commander about what the enemy can do—most
dangerous course of action (COA)—and what the enemy is expected to do—most likely enemy COA.
Tailored. Intelligence should be presented based on the needs of the commanders, subordinate
commanders, and staff. Intelligence should be clear and concise so they can understand, believe,
and act on it. Intelligence should support and satisfy the commander’s priorities.
Table 1-1. Intelligence warfighting function tasks
Support to force generation
Provide intelligence readiness.
Establish intelligence architecture.
Provide intelligence overwatch.
Generate intelligence knowledge.
Tailor the intelligence force.
Support to situational understanding
Perform IPB.
Perform situation development.
Provide intelligence support to protection.
Provide tactical intelligence overwatch.
Provide intelligence support to civil affairs operations.
Support to situational understanding
Note. The police intelligence operations function is not an intelligence discipline. It is a law enforcement function.
However, it is within the critical intelligence task “support situational understanding” that police intelligence operations
best support the MI cycle. Police intelligence operations are essential to this task, particularly where asymmetric
threats (criminal, terrorist, and insurgents) threaten the security of U.S. forces and military operations. This function
supports and enhances the commander’s situational awareness and COP through collection, analysis, and appropriate
dissemination of relevant criminal, police information and criminal intelligence. Police intelligence operations are a vital
tool to law enforcement personnel and criminal investigators who distribute and focus MP and criminal investigations
assets. U.S. codes, EOs, DODDs, and ARs contain specific guidance regarding the prohibition of intelligence
personnel from collecting intelligence on U.S. citizens, U.S. corporations, and non-U.S. citizen residents. Any access
by the intelligence community to information or products—resulting from police intelligence operations directed against
U.S. citizens—should undergo competent legal review.
Conduct ISR
Perform ISR synchronization.
Perform ISR integration.
Conduct reconnaissance.
Conduct surveillance.
Conduct related missions and operations.
Support sensitive site exploitation.
Provide intelligence support to personnel recovery.
Provide intelligence support to targeting and information superiority
Note. This task branch supports both direct and indirect delivery of fires. This task is also linked to
Provide intelligence support to targeting.
Provide intelligence support to Army information tasks.
Provide intelligence support to combat assessment.
AR—Army regulation
IPB—intelligence preparation of the battlefield
COP—common operational picture
ISR—intelligence, surveillance, reconnaissance
DODD—Department of Defense directive
MI—military intelligence
EO—executive order
MP—military police
1-2
TC 2-50.5
6 January 2010
FOR OFFICIAL USE ONLY
The Intelligence Warfighting Function
INTELLIGENCE CATEGORIES
1-6. As discussed in FM 2-0, Army unit intelligence staffs produce and receive, directly or indirectly, six
categories of intelligence support from the U.S. intelligence community. Intelligence categories are
distinguishable primarily by their intelligence product purposes. The categories can overlap and the same
intelligence can be used in each category. Intelligence organizations use specialized procedures to develop
these categories. The following information describes each category and the responsible organization:
Indications and warning (I&W). Analysis of time-sensitive information that could involve a
threat to U.S. and multinational military forces, U.S. political or economic interests, or to U.S.
citizens. While the G-2/S-2 produces I&W intelligence, every Soldier, such as the one
conducting a presence patrol, contributes to the I&W through awareness of the CCIRs and by
reporting related information.
Current intelligence. The G-2/S-2 produces accurate reporting on the current threat situation—
which becomes a portion of the common operational picture (COP)—projects the threat’s
anticipated situation and the implication to friendly operations.
General military intelligence (GMI). GMI focuses on the military capabilities of foreign
countries, organizations, or on topics relating to Armed Forces capabilities, including threat
characteristics (previously order of battle factors) and area or terrain intelligence. The G-2/S-2
develops initial intelligence preparation of the battlefield (IPB) products from various GMI
databases, and then develops and maintains the unit’s GMI database on potential threat forces
and areas of concern based on the commander’s guidance. This database supports the unit’s plan,
preparation, execution, and assessment of operations.
Target intelligence. The analysis of threat units, dispositions, facilities, and systems to identify
and nominate specific assets or vulnerabilities for attack, reattack, or exploit.
Scientific and technical intelligence (S&TI). The collection, evaluation, and interpretation of
foreign engineering science and technology with warfare potential, including military systems,
weapons, weapons systems, materiel, research and development, and production methods. The
G-2/S-2 establishes instructions in standing operating procedures (SOPs), orders, and plans for
handling and evacuating captured enemy material for S&TI exploitation.
Counterintelligence (CI). Identifying and recommending countermeasures against threats by
foreign intelligence services and the ISR activities of nonstate entities, such as organized crime,
terrorist groups, and drug traffickers.
INTELLIGENCE DISCIPLINES
1-7. Intelligence disciplines are categories of intelligence functions. There are nine major intelligence
disciplines:
All-source intelligence.
CI.
Human intelligence (HUMINT).
Geospatial intelligence (GEOINT).
Imagery intelligence (IMINT).
Measurement and signature intelligence (MASINT).
Open-source intelligence (OSINT).
Signals intelligence (SIGINT).
Technical intelligence (TECHINT).
1-8. Table 1-2 (page 1-4) describes the Army’s intelligence disciplines.
6 January 2010
TC 2-50.5
1-3
FOR OFFICIAL USE ONLY

 

 

 

 

 

 

 

Content      ..     15      16      17      18     ..