|
|
FM 2-22.2 (FM 34-60)
Counterintelligence
October 2009
DISTRIBUTION RESTRICTION: Distribution authorized to U.S. Government agencies only because it requires
protection in accordance with AR 380-5 or as specified by DCS G-3 Message DTG 091913Z MAR04. This
determination was made on 22 May 2008. Contractor and other requests must be referred to ATTN: ATZS-CDI-D,
U.S. Army Intelligence Center, Fort Huachuca, AZ 85613-7017, or via email at ATZS-FDC-D@conus.army.mil.
DESTRUCTION NOTICE: Destroy by any method that will prevent disclosure of contents or reconstruction of the
document in accordance with AR 380-5.
Headquarters, Department of the Army
FOR OFFICIAL USE ONLY
*FM 2-22.2 (FM 34-60)
Field Manual
Headquarters
Department of the Army
No. 2-22.2 (34-60)
Washington, DC, 21 October 2009
Counterintelligence
Contents
Page
PREFACE
vii
Chapter 1
COUNTERINTELLIGENCE MISSION, STRUCTURE, AND
ORGANIZATION
1-1
Army Counterintelligence
1-1
Counterintelligence Special Agent
1-1
Tenets of Counterintelligence
1-1
Counterintelligence Core Competencies
1-3
Counterintelligence Mission
1-4
Counterintelligence Structure
1-5
2X
1-6
Counterintelligence Coordinating Authority
1-7
U.S. and Department of Defense Counterintelligence Community
1-13
Army Counterintelligence Levels of Employment
1-14
Chapter 2
COUNTERINTELLIGENCE INVESTIGATIONS
2-1
Investigative Personnel
2-1
Counterintelligence Investigation Objectives
2-1
Investigative Authority
2-2
Counterintelligence Investigative Jurisdiction
2-3
Incidents of Counterintelligence Interest
2-4
Counterintelligence Investigative Control and Oversight
2-6
Counterintelligence Investigation Types and Categories
2-7
Investigative Process
2-10
Records Checks
2-21
Counterintelligence Interviews
2-27
Counterintelligence Investigative Reports and Files
2-43
DISTRIBUTION RESTRICTION: Distribution authorized to U.S. Government agencies only because it requires
protection in accordance with AR 380-5 or as specified by DCS G-3 Message DTG 091913Z MAR04. This
determination was made on 22 May 2008. Contractor and other requests must be referred to ATTN: ATZS-CDI-D,
U.S. Army Intelligence Center, Fort Huachuca, AZ 85613-7017, or via email at ATZS-FDC-D@conus.army.mil.
DESTRUCTION NOTICE: Destroy by any method that will prevent disclosure of contents or reconstruction of the
document in accordance with AR 380-5.
*This publication supersedes FM 34-60, 3 October 1995.
i
FOR OFFICIAL USE ONLY
Contents
Chapter 3
COUNTERINTELLIGENCE OPERATIONS
3-1
General
3-1
Advice and Assistance Programs
3-1
Covering Agent Program
3-2
Counterintelligence Support to Research and Technology Protection
3-2
Counterintelligence Support to Acquisition and Special Access Programs
3-3
Counterintelligence Red Team Operations
3-3
Counterintelligence Support to Treaty Verification
3-4
Counterintelligence Support to Antiterrorism and Protection
3-4
Threat Assessments and Vulnerability Assessments
3-5
Counterintelligence Support to Homeland Defense and Civil Support
Operations
3-6
Counterintelligence Support to Joint Terrorism Task Force
3-7
Counterintelligence Support to Counterdrug Operations
3-7
Counterintelligence Support to Information Superiority
3-7
Counterintelligence Support to Military Deception
3-8
Counterintelligence Support to Psychological Operations
3-9
Counterintelligence Support to Electronic Warfare
3-9
Counterintelligence Support to Operations Security
3-10
Counterintelligence Support to Counterpropaganda
3-10
Counterintelligence Support to Counterdeception
3-11
Counterintelligence Support to Physical Security
3-11
Counterintelligence Support to Physical Destruction
3-11
Counterintelligence Support to Information Assurance
3-12
Counterintelligence Support to Civil-Military Operations
3-12
Counterintelligence Support to Public Affairs
3-13
Counterintelligence Support to Computer Network Operations
3-13
Chapter 4
COUNTERINTELLIGENCE COLLECTION PROGRAM
4-1
General
4-1
Counterintelligence Collection Program
4-2
Counterintelligence Debriefings, Screening, and Liaison
4-3
Control of Source Information
4-10
Unit Counterintelligence Requirements Management
4-11
Standing Counterintelligence Collection Requirements
4-12
Counterintelligence Support to Threat and Vulnerability Assessments
4-12
Chapter 5
ANALYSIS, TOOLS, AND PRODUCTION
5-1
General
5-1
Anomalies, Signatures, and Patterns
5-3
Counterintelligence Threat Analysis
5-3
Counterintelligence Support to Intelligence Preparation of the Battlefield
5-5
Counterintelligence Operational Analysis
5-8
Analytical Tools
5-9
Production
5-20
ii
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Contents
Chapter 6
TECHNICAL COUNTERINTELLIGENCE SERVICES AND SUPPORT
6-1
Technical Investigative Techniques
6-1
Electronic Surveillance
6-1
Investigative Photography and Video Recording
6-2
Laboratory Analysis
6-2
Polygraph Support
6-2
Technical Surveillance and Countermeasures Program
6-5
Deception Identification and Detection (Biometrics)
6-7
Computer Forensics
6-8
Support to Information Tasks (Computer Network Operations)
6-9
Chapter 7
CYBER COUNTERINTELLIGENCE
7-1
General
7-1
Cyber Counterintelligence Support to Core Functions
7-1
Cyber Threat Briefings
7-5
Computer Network Incident Categories
7-6
Cyber Indicators of Counterintelligence Interest
7-8
Recognizing Potential Evidence
7-9
Search and Seizure
7-9
Chapter 8
INVESTIGATIVE LEGAL PRINCIPLES
8-1
Intelligence Oversight
8-1
Jurisdiction
8-2
Criminal Law
8-4
Evidence
8-5
Rights Amendment
8-8
Investigative Authority
8-12
Crimes and Incidents Within Counterintelligence Investigative Jurisdiction
8-16
Chapter 9
COUNTERINTELLIGENCE REPORTING
9-1
Tenets of Reporting
9-1
Reports Management
9-1
Report Categories
9-2
Reporting Architecture
9-4
Information Sharing and Release
9-6
Appendix A
COUNTERINTELLIGENCE PROGRAM ADMINISTRATION
A-1
Appendix B
CONTRACTOR SUPPORT TO COUNTERINTELLIGENCE ACTIVITIES
B-1
Appendix C
INTERPRETER SUPPORT TO COUNTERINTELLIGENCE ACTIVITIES
C-1
Appendix D
FBI DELIMITATIONS AGREEMENT
D-1
Appendix E
COUNTERINTELLIGENCE INVESTIGATIVE REPORT WRITING GUIDE
E-1
Appendix F
PREDEPLOYMENT AND MISSION PLANNING
F-1
Appendix G
COUNTERINTELLIGENCE SUPPORT TO MULTINATIONAL
OPERATIONS
G-1
Appendix H
AUTOMATION, COMMUNICATION, AND EQUIPMENT
H-1
Appendix I
COUNTERINTELLIGENCE SPECIAL AGENT APPLICATION
INFORMATION PACKET
I-1
21 October 2009
FM 2-22.2
iii
FOR OFFICIAL USE ONLY
Contents
Appendix J UNIT CUSTODIAN BADGE AND CREDENTIALS HANDBOOK
J-1
GLOSSARY
Glossary-1
REFERENCES
References-1
INDEX
Index-1
Figures
Figure
1-1. Neutralization versus exploitation
1-2
Figure
1-2. 2X organization
1-7
Figure
2-1. Investigative life cycle
2-11
Figure
2-2. Indicators of espionage
2-13
Figure
2-3. Example of an interview room setup
2-33
Figure
3-1. Counterintelligence operations
3-2
Figure
3-2. Counterintelligence support to Army information tasks
3-8
Figure
5-1. Intelligence process
5-1
Figure
5-2. Example of a time event chart
5-10
Figure
5-3. Analysis Notebook theme line chart
5-10
Figure
5-4. Example of an association matrix
5-11
Figure
5-5. Example of an association matrix symbology
5-11
Figure
5-6. Example of an activities matrix
5-12
Figure
5-7. Example of a link analysis diagram
5-13
Figure
5-8. Example showing deceased person
5-14
Figure
5-9. Example of person with suspected alias
5-14
Figure
5-10. Example of person with confirmed alias
5-14
Figure
5-11. Example of nonpersonal entity
5-14
Figure
5-12. Confirmed linkage
5-14
Figure
5-13. Suspected linkage
5-15
Figure
5-14. Legend on connectivity line
5-15
Figure
5-15. Connectivity between persons
5-15
Figure
5-16. Example of mutually associated members
5-16
Figure
5-17. Connection between organizations and events
5-16
Figure
5-18. Connectivity between persons but not the organization
5-17
Figure
5-19. Association with an entity
5-17
Figure
5-20. Person with greatest number of personal associations
5-17
Figure
5-21. Person with next highest number of personal associations
5-18
Figure
5-22. Confirmed personal associations
5-18
Figure
5-23. Example of activities, organization, and nonpersonal entities
5-18
Figure
5-24. Analyst Notebook link diagram showing information from an activity
matrix
5-19
Figure 5-25. Analyst Notebook link diagram showing nonpersonal relationship
5-19
iv
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Contents
Figure
5-26. Analyst Notebook hierarchy layout
5-20
Figure
9-1. Reporting architecture
9-5
Figure D-1. FBI delimitations agreement contents
D-1
Figure E-1. Example of a CI incident report
E-16
Figure E-2. Example of an IMFR—interview
E-24
Figure E-3. Example of an IMFR—personnel files checks
E-35
Figure E-4. Example of an IMFR—records checks
E-39
Figure E-5. Example of an IMFR—intelligence files checks
E-41
Figure E-6. Example of an IMFR—law enforcement records checks
E-43
Figure E-7. Example of a transmittal letter for an ROI
E-51
Figure E-8. Example of an ROI
E-52
Figure E-9. Example of an SOI
E-55
Figure E-10. Privacy Act of 1974 advisement statement
E-57
Figure E-11. Perjury warning
E-58
Figure E-12. Secrecy affirmation statement
E-59
Figure F-1. Appendix 3 (CI) to Annex B (Intelligence) to an OPORD
F-4
Figure I-1. Information sheet—CI (MOS 35L)
I-2
Figure I-2. Applicant information sheet
I-7
Figure I-3. CI special agent application—minimum qualifications
I-9
Figure I-4. CI applicant processing checklist
I-11
Figure I-5. CI special agent applicant interview process
I-12
Figure I-6. Orientation statement
I-14
Figure I-7. Instructions for the contingency statement and compositions
I-16
Figure I-8. Final interview
I-18
Figure I-9. Final interview guide
I-19
Figure I-10. CI applicant interview biographic sheet
I-22
Figure I-11. Interviewing agent’s post-interview requirements
I-32
Figure I-12. Statement of interview
I-33
Figure I-13. CI applicant HRC memorandum
I-38
Figure J-1. Email receipt for badge and credentials materials shipped to a unit
J-3
Figure J-2. Email receipt for CI badge and credentials hand-carried to a unit
J-4
Figure J-3. Email 1 example—hand-carry transfer coordination process
J-6
Figure J-4. Email 2 example—gaining unit responds to the initial email
J-7
Figure J-5. Email 3 example—hand-carry authorization email from ITRADS
J-7
Figure J-6. Email 4 example—gaining unit receipts for the badge and credentials
J-7
Figure J-7. Email 5 example—ITRADS acknowledgment of transfer
J-8
Figure J-8. Unit badge and credentials inventory memorandum format
J-9
Figure J-9. Receipt and responsibility statement format
J-11
Figure J-10. Example of badge and credentials return memorandum format
J-13
Figure J-11. Badge and credentials request memorandum format
J-14
21 October 2009
FM 2-22.2
v
FOR OFFICIAL USE ONLY
Contents
Figure J-12. Request for USAI representative credentials
J-15
Figure J-13. Misuse of badge and credentials materials—initial report format
J-16
Figure J-14. Misuse of badge and credentials materials—final report format
J-17
Figure J-15. Loss of badge and credentials materials—initial report format
J-18
Figure J-16. Loss of badge and credentials materials—final report format
J-19
Figure J-17. Additional duty appointment badge and credentials custodians
J-20
Figure J-18. Request to establish a USAI badge and credentials account
J-21
Figure J-19. Request for revalidation of badge and credentials account
J-23
Tables
Table 1-1. Counterintelligence coordinating authority functions
1-8
Table 1-2. Operations support cell functions
1-10
Table 1-3. Operational management team functions
1-10
Table 1-4. Counterintelligence team functions
1-12
Table E-1. Personal data
E-2
Table E-2. Military ranks and civilian titles
E-4
Table E-3. Physical description
E-4
vi
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Preface
This manual provides doctrinal guidance, techniques, and procedures for the employment of counterintelligence
(CI) special agents in the Army. It outlines—
• CI investigations and operations.
• The CI special agent’s role within the intelligence warfighting function.
• The importance of aggressively countering foreign intelligence and security services (FISS) and
international terrorist organizations (ITO).
• The roles and responsibilities of those providing command, control, and technical support to CI
investigations and operations.
• The need for effective dissemination of CI reports and products and the importance of cross-
cueing other intelligence disciplines.
• The significance of cultural awareness as a consideration to counter the foreign intelligence threat.
This manual expands upon the information in FM 2-0 and supersedes FM 34-60. It is consistent with doctrine in
FM 3-0, FM 5-0, FM 100-15, and JP 2-0. When published, FM 2-22.2 will provide further information on CI
activities when Army forces are employed in tactical operations.
This manual provides the doctrinal guidance for CI special agents, commanders, and staffs of the military
intelligence organizations responsible for planning and executing CI missions. It also serves as a reference for
personnel developing doctrine and tactics, techniques, and procedures; materiel and force structure; institutional
and unit training; and standing operating procedures for CI activities at all Army echelons.
FM 2-22.2 is intended for use by CI special agents, commanders, staff officers, military intelligence personnel,
and Government civilian and contract employees charged with responsibility for CI activities and operations. It
is also intended for commanders and staffs of joint and multinational commands, U.S. Naval and Marine forces,
units of the U.S. Air Force, and the military forces of multinational partners. This manual applies to the
spectrum of conflict and operational themes.
This manual applies to the Active Army, the Army National Guard/Army National Guard of the United States,
and the U.S. Army Reserve unless otherwise stated, and Federal employees and contractor personnel employed
by the Services to engage in CI activities.
For the purposes of this manual, the term special agents or agents refers to an enlisted Soldier in military
occupational specialty 35L, a warrant officer in WO area of concentration (AOC) 351L, a commissioned officer
in AOC 35E, or their Federal civilian employee counterpart.
Headquarters, U.S. Army Training and Doctrine Command is the proponent for this publication. The preparing
agency is the U.S. Army Intelligence Center and Fort Huachuca. Send written comments and recommendations
on DA Form 2028 (Recommended Changes to Publications and Blank Forms) directly to Commander, ATZS
CDI-D (FM 2-22.2), U.S. Army Intelligence Center, 550 Cibeque Street, Fort Huachuca, AZ 85613-7017: by
email to ATZS-FDC-D@conus.army.mil or submit an electronic DA Form 2028.
21 October 2009
FM 2-22.2
vii
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 1
Counterintelligence Mission, Structure, and Organization
Counterintelligence is information gathered and activities conducted to identify,
deceive, exploit, disrupt, or protect against espionage, other intelligence activities,
sabotage, or assassinations conducted for or on behalf of foreign powers,
organizations, or persons, or their agents, or international terrorist organizations or
activities (EO 12333).
Counterintelligence (CI) includes all actions taken to detect, identify, track, exploit,
and neutralize the multidiscipline intelligence activities of adversaries. It is a key
intelligence community contributor to protect U.S. interests and equities.
ARMY COUNTERINTELLIGENCE
1-1. CI focuses on negating, mitigating, or degrading the foreign intelligence and security services (FISS)
and international terrorist organizations (ITO) collection threat that targets Army interests through the
conduct of investigations, operations, collection, analysis, production, and technical services and support.
1-2. CI analyzes the threats posed by FISS and the intelligence activities of nonstate actors such as
organized crime, terrorist groups, and drug traffickers. CI analysis incorporates all-source information and
the results of CI investigations and operations to support a multidiscipline analysis of the force protection
threat.
COUNTERINTELLIGENCE SPECIAL AGENT
1-3. The CI special agent has the distinct mission of detecting, identifying, countering, and neutralizing
FISS and ITO threats directed towards the Army through the execution of all CI functions. CI special
agents should not be confused with human intelligence (HUMINT) collectors, military occupational
specialty (MOS) 35M, and warrant officer (WO) area of concentration (AOC) 351M. They are specifically
trained and certified for, tasked with, and engage in the collection of information from individuals
(HUMINT sources) for the purpose of answering HUMINT-specific requirements. Although CI and
HUMINT personnel may use similar methods, their missions are separate and distinct. Commanders should
not use them interchangeably. Using CI personnel for HUMINT missions degrades the Army’s ability to
protect its forces, information, and critical technology that provides the Army operational and technological
superiority over existing and future adversaries.
Note. For the purpose of this FM, a CI special agent consists of enlisted personnel in MOS 35L,
WOs in AOC 351L, commissioned officers in AOC 35E, and their Federal civilian employee
counterparts.
TENETS OF COUNTERINTELLIGENCE
1-4. The National Security Act of 1947, codified under Title 50, USC § 401a, designates CI as an
intelligence activity. While one of the CI cornerstones is the conduct of investigations, Title 50, USC
highlights—the best long-term solution to counter the FISS and ITO collection threats is offensively
exploiting the situation to identify all the participants, and undermining the FISS and ITO’s ability to
collect effectively on Army equities through control of the participants and information. Neutralization of a
21 October 2009
FM 2-22.2
1-1
FOR OFFICIAL USE ONLY
Chapter 1
FISS and ITO threat through exposure, changes to systemic procedures, or criminal prosecution should
always be the secondary consideration. Neutralization inhibits Army CI’s ability to fully identify all the
participants and assess the damage caused to national security; however, all CI investigative activities
should be conducted at a prosecutorial standard to preserve the legal integrity and admissibility of
evidence. Figure 1- 1 shows criminal versus intelligence approach to CI operations.
Figure 1-1. Neutralization versus exploitation
1-5. The Department of Defense (DOD) defines CI as a multidiscipline function to counter the full range
of FISS and ITO collection activities. However, the only FISS and ITO intelligence platform that Army CI
can offensively and proactively counter is their HUMINT capability. Signals intelligence, imagery
intelligence, or other technical collection activities are generally standoff platforms. CI can only provide
assessments on the capabilities and make recommendations for countermeasures to mitigate the threats.
The facts presented make Army CI focused generally on counter-HUMINT activities.
1-6. CI is the fusion of intelligence, security, and law enforcement functions into a single element that
thinks like a FISS and ITO entity, and employs a broad range of functions to protect Army personnel,
property, information, operational intentions, and critical technologies. This ensures operational and
technological superiority over existing and future adversaries. Although proper CI employment protects
national defense information, proper CI employment can also undermine the adversaries’ understanding
and knowledge of U.S. policies and objectives and make them react predictably if Army CI can effectively
control the adversary’s abilities to collect against U.S. interests. The following elements support the
different CI objectives:
Intelligence (exploitation)—CI sensitive and investigative source operations.
Security
(deter, detect, identify, counter)—advice and assistance, briefings, debriefings,
screenings, security program inspections.
Law enforcement (neutralize)—CI investigations.
1-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
COUNTERINTELLIGENCE CORE COMPETENCIES
1-7. CI core competencies are interrelated, mutually supporting, and can be derived from one another. No
single competency can defeat the FISS and ITO intelligence collection threat targeting U.S. interests, in
general, and Army interests, specifically. The CI core competencies include—
Operations.
Investigations.
Collection.
Analysis and production.
Intelligence analysis.
Operational analysis.
OPERATIONS
1-8. CI operations are broadly executed CI activities that support a program or specific mission. CI
operations use one or more of the core CI competencies discussed below. CI operations can be offensive or
defensive, and they are derived from, transitioned to, or used simultaneously—depending on the scope,
objective, or continued possibility for operational exploitation. CI operations fall into two categories: CI
support operations and CI sensitive operations.
INVESTIGATIONS
1-9. CI investigations are conducted when national security crimes are allegedly committed by anyone
under CI authority. The primary objective of any CI investigation is the identification, exploitation, or
neutralization of threats directed against the Army. CI investigations are also conducted to identify
systemic security problems that may have damaging repercussions to Army operations and national
security interests.
COLLECTION
1-10. CI collection is the systematic acquisition of information concerning the FISS and ITO intelligence
collection threat targeting Army equities. CI elements conduct collection activities to support the overall CI
mission. CI collection is conducted by using sources, elicitation, official liaison contacts, debriefings,
screenings, and open-source intelligence to obtain information that answers the standing
counterintelligence collection requirements
(SCICRs) or other collection requirements based upon
commanders’ requirements. Although CI and HUMINT have a collection mission, there are distinct
differences between their collection objectives. HUMINT focuses on answering the commander’s critical
information requirements (CCIRs) concerning the plans, intentions, capabilities, and disposition of the
adversary, as a whole.
1-11. CI specifically targets the FISS and ITO intelligence collection threat targeting U.S. forces. CI
collection is conducted to understand how FISS and ITO are targeting U.S. forces, so countermeasures can
be identified and recommended to commanders and program managers to protect personnel, mission,
resources, and technology. Collection is only one of five CI functions; whereas, collection is HUMINT’s
only mission.
ANALYSIS AND PRODUCTION
1-12. CI analysis is used to satisfy the supported commander’s intelligence requirements and to provide
focus and guidance to CI operations. CI analysis and production can be accomplished at any level in which
Army CI assets are assigned to counter the FISS and ITO collection threat; support protection of U.S.
personnel, property, and operations; protect the research and development of critical technologies; and
support Army information tasks to protect U.S. forces information systems.
21 October 2009
FM 2-22.2
1-3
FOR OFFICIAL USE ONLY
Chapter 1
Intelligence Analysis
1-13. CI analysis provides the supported commander with situational awareness and understanding of the
operational environment. CI analysis should be focused on predictive assessments of FISS and ITO plans,
intentions, and capabilities. This allows the commander to make informed decisions on the protection
posture and targeting to neutralize or exploit those threats to the advantage of U.S. forces. Accurate CI
analysis also increases the visibility of proactive and effective CI support and establishes credibility with
the supported commander. This in turn leads the commander to trust and rely upon the CI assets and often
give them more flexibility to execute CI operations.
Operational Analysis
1-14. Operational analysis allows the operational management elements
(2X, counterintelligence
coordinating authority
[CICA] and operational management team
[OMT] leaders) to gauge the
effectiveness and success of their subordinate operational CI teams. This is done through assessments on
source production (quantity and quality), source vetting (reliability, accuracy, response to control), and
requirements coverage. Operational analysis also allows operational managers to deconflict CI operations
and to provide direction and focus to eliminate redundancy and/or increase the efficiency of the CI teams.
TECHNICAL SERVICES AND SUPPORT
1-15. CI technical services are used to assist the CI core competencies of investigations, collections, and
operations or to provide specialized technical support to a program or activity. The proliferation of
sophisticated collection technology, surveillance, and
“eaves-dropping” devices available in the
commercial markets enable any FISS and ITO with the ability to increase their capability and effectiveness
in collecting on Army interests.
1-16. To mitigate this increasing threat requires a specialized expertise. CI organizations with technically
trained CI special agents are chartered with providing this unique technical capability to augment and
provide specialized support to the CI mission. This includes CI special agents trained to—
Perform technical surveillance countermeasures (TSCM).
Perform cyber CI activities that provide protection to information networks as well as identify
vulnerabilities and attempted intrusions into Army and DOD computer networks.
Perform CI scope polygraph examinations.
Provide support to Army information tasks.
COUNTERINTELLIGENCE MISSION
1-17. The mission of Army CI is to conduct aggressive, comprehensive, and coordinated operations,
investigations, collection, analysis and production, and technical services. This CI mission is conducted
worldwide to detect, identify, assess, counter, exploit, or neutralize the FISS and ITO collection threat to
the Army and DOD to protect the lives, property, or security of Army forces. Army CI has four primary
mission areas:
Counterespionage (CE).
Support to protection.
Support to research and technology protection (RTP).
Cyber CI.
COUNTERESPIONAGE
1-18. CE detects, identifies, counters, exploits, or neutralizes the FISS and ITO collection threat targeting
Army and DOD equities or U.S. interests. CE programs use both investigations and collection operations to
1-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
conduct long-term operations to undermine, mitigate, or negate the ability of FISS and ITO to collect
effectively on Army equities. CE programs also affect the adversarial visualization and decisionmaking
concerning the plans, intentions, and capabilities of U.S. policy, goals, and objectives. The goal of CE is
to—
Limit the adversary’s knowledge of U.S. forces, plans, intentions, and capabilities through
information denial.
Limit the adversary’s ability to target effectively U.S. forces by disrupting their collection
capability.
COUNTERINTELLIGENCE SUPPORT TO PROTECTION
1-19. CI support to protection ensures the survivability and mission accomplishment of Army and DOD
forces.
1-20. CI’s objective in supporting protection is to—
Limit the compromise and exploitation of personnel, facilities, operations, command and
control (C2), and operational execution of U.S. forces.
Negate, mitigate, or degrade adversarial planning and targeting of U.S. forces for exploitation
or attack.
Support the war on terrorism.
SUPPORT TO RESEARCH AND TECHNOLOGY PROTECTION
1-21. Support to RTP is focused on preventing the illegal diversion or loss of critical technology essential
to the strategic advantage of the U.S.
1-22. CI’s objective in supporting RTP is to—
Protect critical technology information from adversarial countermeasures development.
Ensure U.S. technological overmatch against existing and future adversaries.
CYBER COUNTERINTELLIGENCE
1-23. Cyber CI protects information networks and provides an offensive exploitation capability against
adversarial networks to ensure information superiority of U.S. forces.
1-24. CI’s objective in conducting cyber CI activities is to—
Maintain U.S. forces information dominance and superiority over existing and future
adversaries.
Protect critical information networks from adversarial attack or exploitation.
Undermine adversarial information operations, systems, and networks.
COUNTERINTELLIGENCE STRUCTURE
1-25. CI organizations and Army force structure are designed to support the modular force construct
through scalable teams, operations management, and technical control packages. CI elements assigned to
battlefield surveillance brigades, divisions, corps, Army Service component commands (ASCCs), and
strategic units are capable of operating at all echelons and throughout full spectrum operations. The joint
2X organizational and operational concept has been established in Army force structure to decentralize CI
operational approval and execution. As the primary force provider for the DOD CI in contingency and
combat operations, the establishment of the 2X and the CICA throughout the Army ensures a trained and
21 October 2009
FM 2-22.2
1-5
FOR OFFICIAL USE ONLY
Chapter 1
experienced cadre of CI professionals capable of filling Army, joint, and combined 2X and CICA/task
force CI coordinating authority (TFCICA) positions.
2X
Note. 2X denotes the 2X staff officer at all echelons—S-2X (brigade), G-2X (division, corps,
ASCC), J-2X (joint task force), C-2X (combined task force), and Army G-2X (Department of
the Army [DA] level).
1-26. The 2X is the CI and HUMINT manager authorized to coordinate, deconflict, and synchronize all CI
and HUMINT missions in the area of operations (AO). The 2X manages CI and HUMINT intelligence
requirements including HUMINT collection requirements, time-sensitive collection requirements, report
evaluations with source-directed requirements, and source assessments. Although the 2X section may be
structured differently at each echelon, there is always a requirement for three components—CICA, a
HUMINT operations cell (HOC), and an operations support cell (OSC). Figure 1-2 provides a graphic
depiction of the 2X organization. The 2X is responsible for—
Participating in predeployment or deployment planning for CI and HUMINT assets to support
operations.
Coordinating, through the HOC and CICA/TFCICA, all CI and HUMINT activities to support
intelligence collection and the intelligence aspects of protection for the deployed commander.
Managing collection requirements for CI and HUMINT in coordination with intelligence,
surveillance, and reconnaissance (ISR) synchronization.
Providing specific CI and HUMINT collection plans to the collection manager for integration
into the ISR plan.
Coordinating and deconflicting all CI and HUMINT operations within the AO.
Serving as the release authority for CI and HUMINT reporting.
Releasing reports to the Distributed Common Ground System-Army (DCGS-A) only after
ensuring all technical control measures for reporting have been met.
1-27. The 2X is a commissioned officer with a CI or HUMINT AOC (35E/F). Within joint and combined
force commands, the J/C-2X may be either an Army, Navy, Air Force or Marine Corps officer or civilian
depending upon the requirements of the approved joint manning document. (See TC 2-22.303 for details on
the 2X.)
1-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
Figure 1-2. 2X organization
COUNTERINTELLIGENCE COORDINATING AUTHORITY
1-28. The CICA is the coordinating authority for all CI activities assigned or attached to Army CI assets
within their unit or AOs. The CICA for Army divisions and corps will normally be a senior 351L CI WO.
At the ASCC or theater level, the CICA may be a senior CI WO, CI officer (35E) or equivalent Military
Intelligence Civilian Excepted Career Program (MICECP) government civilian employee.
1-29. Within joint and combined force commands, the TFCICA may be an Army, Navy, Air Force, or
Marine Corps WO, officer, or civilian depending on the requirements of the approved joint manning
document. Army CICA components are generally comprised of four personnel (a CI WO and three enlisted
CI Soldiers); however, size and structure may vary depending on the unit and mission. Units engaged in
operational and strategic missions may have a higher standard of grade for CICAs including the use of
appropriately credentialed government civilian employees. CICA personnel may be attached, assigned, or
under operational control (OPCON).
1-30. Regardless of echelon or Service component, the CICA’s mission is to manage, coordinate, and
synchronize all CI activities in the designated AO. The CICA exercises technical control over all CI entities
and deconflicts CI activities with higher, lower, and adjacent CI elements. The CICA accomplishes all
responsibilities through coordination with the operational units and other
2X staff elements.
(See
TC 2-22.303 for details on the CICA.) See table 1-1 (page 1-8) for the functions performed by CICA.
21 October 2009
FM 2-22.2
1-7
FOR OFFICIAL USE ONLY
Chapter 1
Table 1-1. Counterintelligence coordinating authority functions
CICA performs the following functions
•
Coordinate and staff all CFSO proposals with the Army component or JTF approval authority, and U.S. national
agency representatives.
•
Serve as the single focal point for all matters associated with CI in the area of intelligence responsibility. The CICA
tracks CI activities and keeps the 2X informed, in turn the 2X keeps the C/J/G/S-2 and commander informed.
•
Exercise technical control of all CI entities and coordinate all CI activities in the area of intelligence responsibility.
Coordinate with MI unit commanders who possess CI assets that execute CI activities in the AO.
•
Coordinate and deconflict all CI source operations with the source registry manager in the area of intelligence
responsibility.
•
Ensure a robust CI education and awareness training program by coordinating CI refresher training, as required,
and by ensuring the establishment of CI reporting channels and procedures in the area of intelligence
responsibility.
•
Implement the intelligence program for all CI activities in the theater in accordance with AR 381-10.
Note. The MILDEPs always remain in control of CI investigations. The ATCICA and ACICA provide investigative
technical control of all Army CI-conducted investigations. Army CI investigative reports pass through the CICA and 2X
while simultaneously passing through the ATCICA and ACICA.
•
Keep the 2X, C/J/G/S-2, and commander informed on the status of CI activities.
•
Coordinate with the analytical element and the ISR synchronization staff to identify and refine requirements for CI
collection, operations, or investigations.
•
Ensure CI reporting is disseminated to the analytical element for inclusion in the all-source picture, as appropriate.
•
Develop and disseminate requirements, orders, and RFIs to CI entities in the area of intelligence responsibility.
•
Ensure registration of all CI sources with the OSC or other designated source registry manager. (If there is no
OSC, the CICA will maintain the source registry.)
•
Routinely evaluate CI source operations to ensure proper handling by CI special agents, source ability to satisfy
requirements, and to determine value of continuing the operation.
•
Ensure exploitation opportunities are preserved while conducting VAs and other protection initiatives.
•
Ensure investigations are planned, coordinated, and executed in accordance with applicable directives and
regulations.
•
Establish and maintain connectivity with the supporting ATCICA for investigative oversight of Army CI-conducted
investigations.
•
Participate in the operations staff targeting process to provide input on the placement, access, availability of
sources, and reporting reliability of CI sources that support targeting. (For more information, see appendix B.)
•
Ensure CI support is provided to the JIDC and DHAs in the area of intelligence responsibility.
•
Establish quality control and execute release of all CI reporting.
•
Routinely provide feedback to all CI entities in the area of intelligence responsibility regarding collection activities,
operations, and investigations.
•
After a determination has been made to release a detainee, ensure detainee screening is performed to determine
the detainee’s suitability as a potential lead for CI or other collection activities.
•
Interact with the HOC and OSC to ensure CI activities do not conflict with HUMINT activities in the area of
intelligence responsibility.
•
Conduct liaison with the PMO and intelligence entities conducting liaison with HN LEAs to ensure CI activities are
coordinated and deconflicted.
•
Conduct liaison with HN and U.S. national level CI organizations.
•
Provide staff oversight to LEPs screening activities within the area of intelligence responsibility.
•
Provide technical oversight and guidance for coordination or approval requests of CI operations that require
approvals outside the local approval authority.
•
Recommend to the supported C/J/G/S-2 and maneuver commander the designation of an MI unit or intelligence
staff element, as appropriate, to serve as the repository for CI badge and credentials in the area of intelligence
responsibility. The MI unit or intelligence staff element should have responsibility for accountability and issue of CI
badge and credentials.
•
Coordinate requests for CI technical services (cyber CI unit, TSCM, and polygraph support).
ACICA-Army CI coordinating authority
JTF-joint task force
AO-area of operations
LEA-law enforcement agency
ATCICA-Army theater CI coordinating authority
LEP-locally employed person
CI-counterintelligence
MI-military intelligence
CFSO-CI force protection source operations
MILDEP-military department
DHA-detainee holding area
OSC-operations support cell
HN-host nation
PMO-Provost Marshal Office
HOC-HUMINT operations cell
RFI-requests for information
ISR-intelligence, surveillance, and reconnaissance
TSCM-technical surveillance countermeasures
JIDC-Joint Interrogation and Debriefing Center
VA-vulnerability assessment
1-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
HUMAN INTELLIGENCE OPERATIONS CELL
1-31. The HOC is an element within the C/J/G/S-2X section that manages all HUMINT military source
operations and related HUMINT activities, including debriefing, interrogation, screening, contact
operations, and document and media exploitation (DOMEX) liaison. (See TC 2-22.303 for details on
HOCs.)
OPERATIONS SUPPORT CELL
1-32. The OSC is an element within the C/J/G/S-2X section that manages overall 2X section operations,
performs office administration functions, and accomplishes tasks that support both the CICA and HOC.
The OSC serves as the operations officer and office manager for the 2X section. Each echelon with a 2X is
also required to have an OSC. If the OSC is not authorized or resourced, the 2X determines how and by
whom the OSC functions will be accomplished.
1-33. When the OSC is authorized or resourced, it works directly for the 2X. At lower echelons (for
example, Stryker brigade combat team [SBCT] and brigade combat team [BCT] level), an OSC may not be
authorized or resourced and may have to be task-organized to provide this capability. At higher echelons,
an OSC is required given the span of control, the number of CI special agents and HUMINT collectors
being managed, the amount of CI and HUMINT requirements, the large volume of reporting, and the
increased burden of administrative requirements. (See TC 2-22.303 for details on the OSC.)
1-34. When established, the OSC requires intelligence personnel. Personnel qualified for an OSC
assignment include all-source intelligence officers (35D), CI officers (35E), HUMINT officers (35F), CI
technicians
(351L), HUMINT technicians
(351M), area intelligence technicians
(351Y), HUMINT
collectors (35M), CI special agents (35L), and Army, MICECP, and defense civilians. Civilians should be
job series
0132, intelligence operations specialist
(CI or HUMINT), or job series 0134, intelligence
operations technician (CI or HUMINT). Qualified contractors can be assigned to an OSC in an appropriate
supporting role such as a portal manager or in a reports officer position. The OSC handles common tasks
and functions that support the CICA and HOC. See table 1-2 (page 1-10) for the functions performed by
OSC.
21 October 2009
FM 2-22.2
1-9
FOR OFFICIAL USE ONLY
Chapter 1
Table 1-2. Operations support cell functions
OSC performs the following functions
•
Provide 24-hour watch for the 2X section and serve as the central communications hub for the 2X section when
deployed. Serve as the primary point of entry for all reporting from all outside echelons and elements. Maintain 2X
section computer systems and communications equipment to ensure connectivity to CI and HUMINT entities in the
area of intelligence responsibility.
•
Receive and track responses to all RFIs from all echelons.
•
Manage administrative support to the 2X section including in-and-out processing, tracking of efficiency reports and
awards, and maintaining office files, as appropriate.
•
Coordinate logistic support and accounts for 2X section property.
•
Maintain a transmittal log for all requests and responses to and from external agencies, staffs, and authorities.
•
Coordinate movement of 2X section personnel with the C/J/G/S-3, dispatch and track 2X section vehicles, track
and account for 2X section personnel in a travel status.
•
Serve as the 2X section’s interface with the analytical element and ISR synchronization element. The OSC
manages the intelligence cycle for the 2X section by receiving requirements and--
Ensuring the requirements are clear.
Advising the ISR synchronization element on the appropriateness of the received or forthcoming requirements.
Helping to ensure that the best CI and HUMINT assets are tasked to satisfy the requirements.
Ensuring that resulting reporting is appropriately disseminated to requestors.
•
Manage SDRs and release of IIRs.
•
Manage the intelligence property book, ICFs, and the Source Incentive Program.
Note. Army regulations require that separate individuals manage the ICF and Source Incentive Program, unless an
exception is granted by the Army G-2.
•
Maintain the consolidated source registry and reports databases, and assist the CICA and HOC in deconflicting
MSO.
•
Coordinate with the linguist support section regarding linguist support to CI and HUMINT entities.
•
Coordinate with the C/J/G/S-2 operations section and C/J/G/S-3 regarding release of FRAGOs, as required.
CICA-CI coordinating authority
HUMINT-human intelligence
FRAGO-fragmentary order
MSO-military source operations
HOC-HUMINT operations cell
OSC-operations support cell
ICF-intelligence contingency fund
RFI-request for information
IIR-intelligence information report
SDR-source-directed requirement
ISR-intelligence, surveillance, and reconnaissance
Counterintelligence Operational Management Team
1-35. The OMT is the first operational management element that provides technical control and oversight
to subordinate CI teams. The OMT manages subordinate CI teams to ensure operational execution and
direction, quality and control of reporting, and satisfaction of intelligence requirements. An OMT can
manage between one to four CI teams depending on the operational pace, mission, and geographic
requirements. OMTs generally consist of four personnel (a 351L, CI WO and three 97L, CI enlisted
Soldiers), but size and structure may vary depending on the unit and mission.
1-36. Units engaged in operational and strategic missions may also have a higher standard of grade for
OMTs including the use of appropriately credentialed government civilian employees. OMT personnel may
be attached, assigned, or under OPCON. OMTs and subordinate CI teams may be assigned or attached
from higher echelon units to lower echelon units. Depending on mission requirements, CI OMTs may be
held at the next higher echelon of the subordinate CI teams. CI OMTs will not normally be located below
the brigade level. (See TC 2-22.303 for details on the OMT.) See table 1-3 for the functions performed by
OMT.
Table 1-3. Operational management team functions
OMT performs the following functions
•
Disseminate all intelligence or time-sensitive information to the supported or responsible command channels for
action or operational consideration.
•
Provide guidance and technical control to operational activity.
•
Provide collection and operational focuses for CI teams.
•
Provide quality control and report dissemination to subordinate CI teams.
1-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
Table 1-3. Operational management team functions (continued)
OMT performs the following functions
•
Receive, edit, and provide feedback on all administrative reports, such as readiness status and operational reports,
and on intelligence reports, such as IIRs, submitted by subordinate teams.
•
Ensure CI reporting and related traffic is fused into all-source intelligence.
•
Conduct CI analysis and assist in mission analysis for the supported commander.
•
Coordinate CI activities with the CICA and with CI element commanders in the area of intelligence responsibility.
•
Perform liaison with HN and U.S. national level security, intelligence, and law enforcement organizations.
•
Inform respective CICA when Army CI elements are conducting CI investigative activities within the purview of AR
381-20.
•
Act as a conduit between subordinate CI teams, the CICA, and 2X, and the supported unit headquarters.
•
Provide administrative support to subordinate CI teams, including reporting mission and equipment status to the
CICA or HOC and the supported unit headquarters.
•
Educate the supported commander on the subordinate teams’ capabilities.
•
Integrate subordinate CI teams directly into the maneuver commander’s ISR planning.
AR-Army regulation
IIR-intelligence information report
CICA-CI coordinating authority
ISR-intelligence, surveillance, and reconnaissance
HOC-HUMINT operations cell
HN-host nation
Counterintelligence Team
1-37. The CI team conducts CI investigations, CI collection (debriefings, source operations, liaison, and
screening), CI analysis, and CI technical services support to protect the supported unit from threat
intelligence activities.
1-38. The CI team provides the supported commander, through 2X channels, a capability to help protect
the force and affect the adversaries’ understanding of friendly force operational capabilities. The CI team
also provides capabilities to help answer CCIRs and SCICRs related to FISS and ITO collection activities
targeted against the supported unit, Army, and DOD equities.
1-39. A CI team generally consists of four 35L, CI noncommissioned officers (NCOs), and enlisted
Soldiers. Units engaged in operational and strategic missions may also have a higher standard of grade for
CI teams including the use of appropriately credentialed government civilian employees. Specialized CI
teams, including technical counterintelligence (TCI), cyber CI, and polygraph teams, may vary in size and
composition (2- to
3-person military or civilian teams) based on mission requirements and unit
organization. CI teams—
May be attached, assigned, or under OPCON.
May be attached or assigned from higher echelon units to lower echelon units.
Are typically assigned at division and above levels; however, they may be attached or
assigned at brigade level depending upon mission requirements.
1-40. Table 1-4 (page 1-12) lists the functions performed by the CI team.
21 October 2009
FM 2-22.2
1-11
FOR OFFICIAL USE ONLY
Chapter 1
Table 1-4. Counterintelligence team functions
OSC performs the following functions
•
Prepare and submit command reports, such as readiness status reports that provide status of equipment,
personnel, and ICF in accordance with supporting OMT SOPs.
•
Prepare protected reports, such as contact reports, in accordance with OMT SOPs, that document each source
contact.
Disseminate contact reports to supporting OMT for review or comment.
Maintain contact report files on every source.
Provide contact report files to relief team during relief in place or transfer of authority.
•
Prepare and submit intelligence reports, such as spot reports, using the SALUTE format, and IIRs in accordance
with OMT SOPs.
•
Assist in the production of threat and vulnerability assessments. This function provides support to evaluations of
installations and operating bases with MP, CA, engineers, and medical units to identify the intelligence threat to the
operating location. The VA identifies weaknesses in operational and physical security procedures and recommends
countermeasures to mitigate intelligence collection on friendly forces, limiting the ability of adversaries to plan and
conduct hostile acts against U.S. and multinational activities and locations.
•
Conduct CI analysis to support mission requirements and contribute to the all-source common operational picture.
To verify adequate area coverage, use backwards planning and source profiling to choose CI targets. Develop and
use CI target overlays and other CI analytical tools that illustrate the CI situation, identify CI gaps, and help refocus
CI collection efforts.
•
Conduct CI debriefings. This function involves the systematic questioning—using direct and indirect questioning
techniques—of individuals to procure information that answers specific CI collection requirements. Sources for
debriefing include friendly forces (for example, MP, CA, engineers, and medical units), U.S. and non-U.S. civilians
including members of NGOs, refugees, displaced persons, and local inhabitants. The CI team regularly and
systematically debriefs all ISR assets.
•
Conduct CI investigations within the jurisdictional boundaries of Army CI regulations and the guidelines of AR 381
10, AR 381-12 and AR 381-20. Regularly coordinate with the supporting staff judge advocate to ensure
investigations are conducted to support eventual trial and prosecution, if necessary, and in compliance with all
DOD policy and U.S. laws.
•
Conduct CI screenings. CI screenings serve two purposes:
Collect information of CI interest or to collect established information requirements through the interview of
indigenous, third-country nationals, foreign expatriates, or U.S. military personnel in the AO.
Interview and assess the suitability and security risks of employing potential candidates with U.S. forces to
support LEP screening programs at installations and forward operating bases.
•
Conduct CI collection. This function includes activities focused on identifying adversary intelligence threats that
target U.S. and multinational interests. CI collection is conducted through use of sources and other multimedia
sources to obtain information that impacts the supported unit. CI collection activities will not be used as a substitute
for Army HUMINT collection. “Collect” specific information or develop leads that can obtain information concerning
adversary intelligence collection requirements, adversary capabilities, adversary personalities, and adversary
methods of operation targeting U.S. and multinational forces.
•
Register all CI contacts through the OMT and CICA in the source registry. Disseminate CI administrative, technical,
and intelligence reports through the OMT and CICA.
•
Conduct CI liaison with U.S., multinational, and host-nation military and civilian agencies, including NGOs, for the
purpose of obtaining information of CI interest and to coordinate and deconflict CI activities. Liaison activities are
designed to ensure a cooperative operating environment for CI elements and to develop CI leads for further
exploitation.
Maintain constant contact with the supported S-2 to identify intelligence requirements, information gaps, and
to deconflict operations within the support commander’s AOs.
Maintain constant contact with other ISR assets (scouts, PSYOP, CA, and MP) to coordinate and deconflict
operations in adjacent AOs and cross-checks collected information.
•
Support the CI Education and Awareness Training Program by coordinating with the S-2 to present CI awareness
training to all units in the area of intelligence responsibility. CI teams should be the focal point for all CI training to
identify incidents of CI interest and educate Army personnel about their responsibilities to report incidents outlined
in AR 381-12. The CI Education and Awareness Training Program supports the commander’s overall protection
program.
•
Provide CI technical service support, such as polygraph, TSCM, computer forensics, to the supported unit when
properly trained and equipped personnel are available.
AO-area of operations
MP-military police
CA-civil affairs
HUMINT-human intelligence
CI-counterintelligence
NGO-nongovernmental organization
CICA-CI coordinating authority
OMT-operational management team
DOD-Department of Defense
PSYOP-psychological operations
ICF-intelligence contingency fund
SALUTE-size, activity, location, unit, time, equipment
IIR-intelligence information report
SOP-standing operating procedure
ISR-intelligence, surveillance, and reconnaissance
TSCM-technical surveillance countermeasures
VA-vulnerability assessment
1-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
U.S. AND DEPARTMENT OF DEFENSE COUNTERINTELLIGENCE
COMMUNITY
1-41. Each of the following organizations serve the U.S. and DOD intelligence community, specifically in
CI matters:
Office of the National Counterintelligence Executive (ONCIX).
Federal Bureau of Investigation (FBI).
Central Intelligence Agency (CIA).
Deputy Under Secretary for Defense (DUSD), Counterintelligence and Security (CI&S).
Defense CI and HUMINT Center.
Counterintelligence staff officer (CISO).
OFFICE OF THE NATIONAL COUNTERINTELLIGENCE EXECUTIVE
1-42. The ONCIX is subordinate to the Office of the Director of National Intelligence (DNI). The ONCIX
serves as the U.S. Government executive agent for all CI matters and is responsible for developing the CI
strategy for the U.S. CI community including DOD CI elements. The ONCIX advises the DNI on CI
program budgets and evaluations to ensure the CI community is properly funded to execute operations that
support national policy and strategic priorities. The ONCIX establishes priorities for CI collection,
investigations, and operations to—
Exploit and defeat FISS and ITO collection activities directed against U.S. interests.
Protect and sustain U.S. intelligence systems and agencies.
Neutralize and exploit adversarial intelligence activities targeting the armed forces.
FEDERAL BUREAU OF INVESTIGATION
1-43. The FBI is the investigative arm of the Department of Justice and is a member of the intelligence
community under the provisions of Title 50, USC The FBI is the lead U.S. Government agency for CI
within the United States. Army CI often conducts joint CI investigations with the FBI when the offense or
the subject falls within the investigative jurisdiction of Army CI.
CENTRAL INTELLIGENCE AGENCY
1-44. The CIA is the lead U.S. Government agency responsible for foreign intelligence and CI activities
outside the United States. However, most CIA CI activities are focused on protecting the integrity and
security of CIA operations from compromise. Army CI collection and operations outside the United States
must be deconflicted with the CIA to avoid intelligence conflicts and ensure unity of the intelligence effort.
DEPUTY UNDER SECRETARY FOR DEFENSE, COUNTERINTELLIGENCE AND SECURITY
1-45. The DUSD (CI&S) is responsible for providing oversight of the DOD CI Program and making
recommendations on policy issues to the DUSD for intelligence. DUSD (CI&S) serves as the OSD staff
focal point for all issues relating to DOD CI initiatives. DUSD (CI&S) also interacts with other DOD staff
elements, the National Counterintelligence Executive and other national agencies to help direct and shape
CI strategies.
DEFENSE COUNTERINTELLIGENCE AND HUMAN INTELLIGENCE CENTER
1-46. In August 2008, the DOD simultaneously disestablished the CI Field Activity and activated the
Defense CI and HUMINT Center, which is under the direction of the Defense Intelligence Agency (DIA).
21 October 2009
FM 2-22.2
1-13
FOR OFFICIAL USE ONLY
Chapter 1
The new center has no law enforcement function. It manages CI programs for DOD and integrates
overlapping CI and HUMINT operational and support areas.
COUNTERINTELLIGENCE STAFF OFFICER
1-47. The CISO serves as an advisor on CI matters to the combatant command J-2 and commander. The
CISO assists in providing oversight on all the command’s CI activities and ensuring all command plans and
operational planning include CI operations, requirements, and tasking when appropriate. The CISO also
provides management and deconfliction of CI collection, production, investigations, operations, and
technical services capabilities within their theater or area of responsibility.
1-48. The CISO establishes combatant command CI priority intelligence requirements (PIRs) to support
the commander’s information requirements. When a combatant command is designated as a joint task force
(JTF) command headquarters, the CISO can serve as the TFCICA until joint manning documentation
establishes a recurring requirement to fill that position for the duration of the operation. CISOs may also be
documented in ASCC staffs as required and authorized.
ARMY COUNTERINTELLIGENCE LEVELS OF EMPLOYMENT
1-49. CI is critical to Army operations at all echelons, across the spectrum of conflict. Army CI can and
will execute all five CI core competency functions from the tactical to strategic operational environments.
The only difference in the operational execution is generally what mission areas are being supported. Even
CI special agents providing CI technical services and support are leveraged to provide their unique
capabilities during stable peace and during major combat operations.
1-50. All Army commanders, including commanders of MI units, need to be educated by senior CI and
HUMINT personnel to clearly define the distinctions between the two disciplines to ensure the effective
use of both disciplines to support the unit’s mission. Since CI personnel have been used instead as
HUMINT collectors during the past 15 years, senior CI special agents have failed to articulate the CI’s true
mission to their commanders and how proper employment of CI is a warfighting enabler. This failure to
articulate—combined with a lack of HUMINT resources and an increased reliance on human-derived
information as a catalyst for military operations execution—has blurred the identity of CI, especially at the
tactical level.
STRATEGIC AND DEPARTMENTAL CI
1-51. Strategic operations are conducted by CI elements supporting national and DOD missions (for
example, support to North Atlantic Treaty Organization [NATO] and special operations and missions).
Strategic CI also conducts compartmented investigations and operations to affect the knowledge of FISS
and ITO regarding contingency operations and defense information. Strategic CI executes the full range of
CI functions and missions including CI investigations and operations, offensive counterintelligence
operations, RTP, special access program support, treaty verification, and technical CI services (polygraph,
TSCM, and computer forensics). Strategic CI also supports special operations forces and special mission
units within the scope of applicable national, DOD, and DA policies and regulations. Strategic and
departmental CI assets generally conduct the following activities:
Advice and assistance—assist unit security managers and commanders with knowledge on
security programs and provide details on reporting potential FISS and ITO targeting and
incidents of CI interest.
Education and awareness—provide FISS and ITO threat and Army program briefings to
educate unit personnel, satisfy mandatory training requirements, and generate potential leads
for incidents of CI interest.
Threat assessments (TAs) and vulnerability assessments (VAs)—conduct collection and
analysis of FISS and ITO threat data for a specific unit, facility, operation or activity to
1-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
provide the supported commander knowledge on protection and security posture and make
countermeasures recommendations to overcome deficiencies.
CI investigations—exploit or neutralize potential FISS and ITO collection threats targeting
Army and DOD equities.
CI collection—detect and identify FISS and ITO intelligence collection activities targeting
U.S. forces and to devise other CI initiatives to counter, exploit, or neutralize the FISS and
ITO collection capability.
Army G-2X
1-52. At the departmental level, the Army G-2X is the executive agent for all Army CI activities including
policy implementation, operational oversight, intelligence funding programs, and Army staff level
management. It coordinates with other military Service and national agency intelligence and CI services to
coordinate CI strategies and mutually supporting activities, including joint CI operations and investigations.
The Army G-2X is responsible for making recommendations to the DA G-2 concerning all budgetary
issues concerning CI and HUMINT.
1-53. The Army G-2X provides oversight and guidance to Army CI elements. It staffs and coordinates
approval of CI operational concepts and plans, as outlined in AR 381-20, to ensure they meet legal
sufficiency satisfy validated requirements. The Army G-2X also provides oversight of all approved Army
CI operational concepts and plans. It manages and maintains the Army’s centralized CI and HUMINT
source registry and product library, as part of a joint Service CI and HUMINT database. The Army G-2X
coordinates functional and technical support services, as well as comprehensive worldwide FISS and ITO
threat analysis products. The Army G-2X collaborates with theater and maneuver CI staff and field
elements to ensure unity of the CI effort and efficient use and employment of Army CI assets.
Army Counterintelligence Coordinating Authority
1-54. The ACICA is subordinate to the Army G-2X and is responsible for implementing and enforcing
U.S. and DOD policy within the Army and providing oversight and technical control of all Army CI
activities. The ACICA reviews, staffs, and coordinates all special investigative and collection techniques
requested by Army CI elements. ACICA is responsible for approving all Army CI investigations, and for
reviewing, staffing, and coordinating all CI operational plans and concepts with the appropriate agencies
and approval authorities. It coordinates with other U.S. Government and military CI agencies to assist in
the development and implementation of national CI strategies.
Intelligence and Security Command
1-55. The Army Intelligence and Security Command (INSCOM) executes departmental and operational CI
activities with guidance from the Army G-2X. INSCOM has the responsibility for administrative C2 of all
MI brigades supporting their respective theaters. INSCOM CI assets are task-organized and operationally
employed based on mission and geographic requirements. Most MI brigades organize their CI assets into
detachments with subordinate field or resident offices.
OPERATIONAL
1-56. Operational level CI assets are generally assigned to ASCC or combatant command organizations
and are focused on a specific theater. CI, at the operational level, is primarily focused on CE and CI support
to protection. Operational CI assets are instrumental in protecting bases of operations from infiltration,
collection, planning, and targeting by FISS and ITO entities. Although operational CI elements have a vital
mission to counter the FISS and ITO threat on a daily basis, they may be tasked to deploy and support
contingency or combat operations. This is especially true in large-scale combat operations when the size,
scale, and scope of the operation exceeds the capability of organic tactical CI assets to provide adequate
support in the AO. When required, operational CI assets may be tasked to support strategic CI operations.
Operational CI assets generally conduct the following activities:
21 October 2009
FM 2-22.2
1-15
FOR OFFICIAL USE ONLY
Chapter 1
Advice and assistance—assist unit security managers and commander’s with knowledge on
security programs and provide details on reporting potential FISS and ITO targeting and
incidents of CI interest.
Education and awareness—provide FISS and ITO threat and CI awareness briefings to
educate unit personnel, satisfy mandatory training requirements, and generate potential leads
for incidents of CI interest.
TAs and VAs—conduct collection and analysis of FISS and ITO threat data for a specific
unit, facility, operation, or activity to provide the supported commander knowledge on
protection and security posture and make countermeasures recommendations to overcome
deficiencies.
CI screening—vet locally employed persons (LEPs) in overseas and deployed locations for
suitability to work, protection liabilities, associations, or contacts that may allow them to be
used in other CI collection initiatives.
CI investigations—exploit or neutralize potential FISS and ITO collection threats targeting
Army and DOD equities.
CI collection—detect and identify FISS and ITO intelligence collection activities targeting
U.S. forces and devise other CI initiatives to counter, exploit, or neutralize the FISS and ITO
collection capability.
Theater Army G-2X
1-57. The theater Army G-2X is the principal advisor to the theater Army G-2 and commander for all CI
and HUMINT matters. The theater Army G-2X consists of the G-2X staff officer, theater HOC, Army
theater counterintelligence coordinating authority (ATCICA), and OSC. It provides guidance and oversight
based upon Army G-2X directives and theater requirements. It provides technical control, operational
coordination, and CI oversight of all theater Army CI and HUMINT elements. The theater Army G-2X also
coordinates technical support services, source registration and national level product support with the Army
G-2X. Regional analysis and production is provided to theater consumers and forwarded to the Army G-2X
for inclusion into the national database.
Army Theater Counterintelligence Coordinating Authority
1-58. The ATCICA is subordinate to the theater G-2X and is responsible for providing direct oversight,
guidance, and technical control of all Army CI collection, investigative, and operational activities within
their theaters of operations, including CI elements assigned to tactical organizations. ATCICA is
responsible for reviewing and staffing all requests for special investigative and collection techniques and
investigative and operational plans and concepts. The ATCICA is the interface between subordinate Army
CI operational management elements and the ACICA. It is responsible for implementing Army CI policy as
directed by the ACICA and Army G-2X. It conducts liaison with other U.S. Government, military, and
host-nation (HN) intelligence, security, and law enforcement agencies (LEAs) to coordinate and deconflict
CI activities.
Military Intelligence Brigade
1-59. MI brigades provide operational support to the separate ASCCs. CI elements in MI brigades support
combatant commanders. Operational level CI activities and functions include: investigations, collection,
analysis and production, and technical services and support. CI elements must be capable of quickly
transitioning from a peacetime mission to crisis operations to support combatant commander requirements.
Theater CI assets conduct Army, joint, and multinational operations in designated theaters. Operational
elements may also be deployed to support or reinforce operating forces.
1-16
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Mission, Structure, and Organization
TACTICAL
1-60. Tactical level CI generally denotes all CI assets assigned to Army division and below echelons
(BCTs, and divisions). CI at the tactical level is primarily focused on CI support to protection to their
supported commander’s during operations. CI assets at the tactical level are instrumental in protecting
bases of operations from infiltration, collection, planning, and targeting by FISS and ITO entities.
1-61. Tactical level CI assets generally do not have a robust peacetime mission since their focus is
providing support to their Army forces parent organization; however, in some cases, operational and
strategic CI elements may formally request their support on a case-by-case basis or through formal written
agreements. Even during peacetime, garrison operations tactical CI assets are essential in providing advice
and assistance to their supported command. Depending on the size, scale, and scope of ongoing operations,
operational and strategic CI assets may also be tasked to augment tactical operations. CI assets assigned to
tactical units generally conduct the following activities:
Advice and assistance—assist unit security managers and commanders with knowledge on
security programs and provide details on those CI assets that can respond to FISS and ITO
targeting.
Education and awareness—provide FISS and ITO threat and CI awareness briefings to
educate unit personnel, satisfy mandatory training requirements, and generate potential leads
for CI elements chartered to conduct investigations during peacetime.
TAs and VAs—conduct collection and analysis of FISS and ITO threat data for a specific
unit, facility, operation, or activity to provide the supported commander knowledge on
protection and security posture and make countermeasures recommendations to overcome
deficiencies.
CI screening—vet LEPs in overseas and deployed locations for suitability to work, protection
liabilities, associations, or contacts that may allow them to be used in other CI collection
initiatives.
CI investigations—identify potential CI investigation requirements and triage those incidents
for other CI assets chartered to conduct the investigation. This can be accomplished during
peacetime and contingency or combat operations. During contingency or combat operations,
the chartered CI element may request the assistance of tactical CI personnel to fulfill
investigative requirements. Tactical CI assets generally do not have the resources to
effectively execute a complex CI or CE investigation.
CI collection—detect and identify FISS and ITO intelligence collection activities targeting
U.S. forces and to devise other CI initiatives to counter or neutralize the FISS and ITO
collection capability. CI collection is only conducted in contingency or combat operational
environments and when approved by the CICA.
CORPS/DIVISION/BRIGADE G-2X
1-62. The G/S-2X is the principal advisor to the supported commander for all CI and HUMINT matters
within the AO. The G/S-2X consists of the G/S-2X staff officer, HOC, and the CICA. At lower echelons
(for example, SBCT and BCT level), an OSC may not be authorized or resourced and may have to be task-
organized to provide this capability.
21 October 2009
FM 2-22.2
1-17
FOR OFFICIAL USE ONLY
Chapter 1
1-63. The G/S-2X provides direct technical control and oversight to all CI and HUMINT assets within the
unit and area of intelligence responsibility. The G/S-2X—
Coordinates and deconflicts all CI and HUMINT activities between higher, lower, and
adjacent 2X elements.
Is responsible for providing and maintaining a consolidated source registration for all CI and
HUMINT elements within the area of intelligence responsibility and providing source data to
the next higher echelon 2X element.
Coordinates requests for technical support services, source registration, and higher level
analytical support with the next higher echelon 2X element.
Must have knowledge of CI and HUMINT resources and capabilities for all military, DIA,
and U.S. Government agencies. The G-2X must be able to transition from an Army force
operation to functioning as a J-2X if the unit is designated as a JTF headquarters.
Corps/Division Counterintelligence Coordinating Activity
1-64. The corps/division CICAs are directly subordinate to their respective corps/division G-2X element.
The CICA provides direct oversight and control for all CI activities within the supported unit and area of
intelligence responsibility. The CICA is responsible for coordinating and deconflicting all CI activities with
next higher echelon CICA. It conducts liaison with other U.S. Government, military, and HN intelligence,
security, and LEAs within their area of intelligence responsibility to coordinate and deconflict CI activities.
The CICA—
Reviews and provides quality control and dissemination of all CI reporting from subordinate
CI elements.
Provides operational analysis to focus CI activities, assess responsiveness and effectiveness of
CI activities, and ensures coverage of information requirements for their supported
commander.
Must have knowledge of the CI resources and capabilities of all military, DIA, and U.S.
Government agencies.
Must be able to transition from an Army force operation to functioning as a TFCICA if the
unit is designated as a JTF headquarters.
Corps/Division Counterintelligence Elements
1-65. CI assets supporting division and JTF operations are generally leveraged from battlefield surveillance
brigades (BFSBs). The G-2X at division will provide CI investigation and operational oversight along with
technical control of CI elements supporting division elements. The division G-2X will coordinate CI
activities through the JTF J-2X in theater and the theater CICA and senior CISO. The division G-2X is
trained and equipped to act as a J-2X if the division is designated as the JTF command element during a
contingency operation. At corps/division level, the BFSB MI battalion has three companies with CI assets.
The C&E company has one CI OMT that controls three CI teams. Each CI team consists of four enlisted CI
Soldiers. The C&E company’s mission is to provide general support coverage for the division. Each of the
two CI and HUMINT companies has two CI teams and no CI OMT. The CI and HUMINT company’s
mission is to provide its assets in direct support to the BCTs.
Brigade Combat Team
1-66. Within a BCT are no organic CI OMTs or CI teams in the MI company. CI support assigned or
attached to the BCT includes an OMT or is controlled by the BCT S-2X/CICA. CI teams assigned or
attached to the BCT conduct operations in a direct support role throughout the BCT’s AO.
1-18
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Chapter 2
Counterintelligence Investigations
Counterintelligence
(CI) investigations are conducted to detect, identify, assess,
counter, neutralize, or exploit the foreign intelligence and security services (FISS)
and international terrorist organizations (ITO) threat to the Army and Department of
Defense (DOD). The first priority for all CI investigative situations is to assess for
possible exploitation. Offensive exploitation of situations or persons involved
wittingly or unwittingly in providing information to a FISS and ITO entity provides
the best long-term solution for controlling damage to national security, fully
exploiting or understanding the threat to Army and DOD equities, and degrading the
adversarial collection activity. If a situation or person cannot be controlled to the
advantage of Army CI, neutralization of the threat through exposure or prosecutorial
measures will be pursued.
INVESTIGATIVE PERSONNEL
2-1. CI investigations are conducted only by CI personnel who have been trained and certified by the
Army Intelligence Center and Fort Huachuca
(USAIC&FH). Additionally, only those CI personnel
assigned or attached to units with a CI investigative mission are authorized to conduct a preliminary inquiry
(PI) or a full field investigation (FFI). Personnel authorized to conduct CI investigations are commissioned
officers who possess area of concentration (AOC) 35E; warrant officers (WOs) who possess AOC 351L;
enlisted military occupational specialty (MOS) personnel who possess MOS 35L and have been issued
badge and credentials; or by Army civilian employees in career field 0132, who are assigned to CI units,
have been school-trained, and are issued badge and credentials. (See AR 381-20 for more information on
training and badge and credentials requirements.)
2-2. Local national and contract investigators employed by overseas Army CI units that have been issued
military intelligence (MI) representative credentials may support the investigative effort through analysis,
research, and by obtaining documentation. They will not be primary or sole investigators on any
investigation.
2-3. Contractors are not authorized to perform CI investigations and operations. They are authorized to
support CI activities that include conducting CI analysis, forensic examinations and analysis, translations
and interpretations, CI database maintenance, CI awareness briefings, CI threat assessments
(TAs),
vulnerability assessments (VAs), and CI screenings of contract linguists.
COUNTERINTELLIGENCE INVESTIGATION OBJECTIVES
2-4. CI investigations are essential to counter threat collection efforts targeting Army equities. CI places
emphasis on investigative activity to support force and technology protection, homeland defense,
information assurance, and security programs. CI investigations focus on resolving allegations of known or
suspected acts that may constitute national security crimes under U.S. law or the Uniform Code of Military
Justice (UCMJ).
21 October 2009
FM 2-22.2
2-1
FOR OFFICIAL USE ONLY
Chapter 2
2-5. The initial objective of CI investigations is to identify people, organizations, and other entities
engaging in national security crimes and to determine the full nature and extent of damage to national
security. The intent is to develop information of sufficient value to permit its use in the appropriate civil or
military court. However, investigations should not be limited to the production of evidence. Investigative
reports should include all relevant information as it pertains to the person or incident involved in the
investigation. CI investigations are conducted to—
Identify people, organizations, and other entities engaging in national security crimes that
impact Army equities.
Determine the full nature of national security crimes within the authority and jurisdiction of
Army CI.
Prove or disprove allegations or indications that person or persons are engaged in national
security crimes or incidents of CI interest.
Prevent the loss, control, or compromise of sensitive or classified defense information and
technology.
Protect the security of Army personnel, information, operations, installations, and technology.
Acquire and preserve evidence used to support exploitation, prosecution, or any other legal
proceedings or punitive measures resulting from CI investigations.
Detect and identify terrorist activities that may present a threat to Army, DOD, and national
security.
2-6. CI investigations must conform to applicable U.S. laws and DOD and DA regulations. CI special
agents must report information accurately and completely. They maintain files and records to allow transfer
of an investigation without loss of control or efficiency. Coordination with other CI or law enforcement
organizations ensures that investigations are conducted as rapidly as possible. It also reduces duplication
and assists in resolving conflicts when jurisdictional lines are unclear or overlap. CI investigative activity
must be discreet, ensuring the rights and privacy of individuals involved, as well as the preservation of all
investigative prerogatives. This is required to protect the rights of individuals and to preserve the security
of investigative techniques.
2-7. CI special agents need to have a thorough understanding of all investigative techniques and planning,
approval processes, and legal requirements before requesting and initiating any type of CI investigative
activity. A lack of understanding in any one of these areas may potentially invalidate any investigation
from a prosecutorial standard and may jeopardize the ability to exploit a threat to the United States.
INVESTIGATIVE AUTHORITY
2-8. DODI 5240.04 and AR 381-20 are the source documents for policy on the conduct of CI
investigations in DOD and Army, respectively. In addition, the Delimitations Agreement of
1979
establishes jurisdictional boundaries and operational procedures that govern the conduct of CI activities by
the DOD CI organizations in conjunction with the Federal Bureau of Investigation (FBI).
2-9. SIA represents the investigative acts an agent conducts without the Army CI coordinating authority
(ACICA) opening an investigation. It allows the CI special agent to gather enough information to provide a
detailed CI incident report concerning all incidents within the purview of CI investigative authority. This
allows adjudication by the ACICA or the responsible Army theater CI coordinating authority (ATCICA) to
determine whether further investigative activities are required or a CI incident report is submitted to the
ATCICA. SIA is not to be used to circumvent case control mechanisms or to expedite cases.
2-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
2-10. CI SIA includes—
Interviewing the source or best sources or other persons knowledgeable of the suspected
incident to establish facts of the incident, fully identify subjects, identify all associated
persons, and additional investigative leads.
The conduct of records checks including local agency checks (LACs) and military agency
checks (MACs), Army personnel and unit records, and local intelligence files to fully identify
the subject or subjects of the incident.
Collection and retention of physical evidence not requiring approval under the provisions of
AR 381-10.
CI debriefing of returned special category absentees, defectors, detainees, and repatriated
prisoners of war (POWs) in the special agent’s AO immediately upon notification.
Monitoring command inquiries for incidents that may be of CI interest.
Note. Under no circumstances will the subject or potential subject be interviewed without prior
approval from ATCICA or ACICA.
COUNTERINTELLIGENCE INVESTIGATIVE JURISDICTION
2-11. In accordance with EO 12333, DODD 5240.1-R and 5240.2, and AR 381-20, Army CI has
investigative authority concerning criminal statutes under USC Title 18 and corresponding criminal articles
in the UCMJ or incidents of CI interest, if the subject or potential subject meets the CI investigative
jurisdiction. Army CI has primary jurisdiction, concurrent jurisdiction, or joint jurisdiction in investigative
matters under the provisions of AR 381-20.
PRIMARY AUTHORITY
2-12. Army CI has investigative primacy for the national security crimes and incidents of CI interest listed
below when they are committed by persons identified as subjects. If either the subject, potential subject,
incident, or crime falls outside Army CI jurisdiction, Army CI may still retain joint investigative
responsibilities.
Sedition.
Aiding the enemy by providing intelligence to the enemy.
Spying.
Espionage.
Subversion.
Treason.
Terrorism activities or materiel support to a known or suspected terrorist organization or
person (DCS G-2, G-2 Memorandum (S//NF), 24 August 2005).
Incidents of CI interest.
Note. Under no circumstances will the subject or potential subject be interviewed without prior
approval of the ACICA.
21 October 2009
FM 2-22.2
2-3
FOR OFFICIAL USE ONLY
Chapter 2
CONCURRENT AUTHORITY
2-13. CI investigating elements will coordinate with other agencies to ensure efficient exchange of
investigative information when the element discovers information that may also fall under the investigative
purview or jurisdiction of another agency. Army CI will concurrently investigate the following incidents
when a CI interest has been established:
Sabotage.
Incidents of CI interest.
JOINT AUTHORITY
2-14. Army CI may seek joint investigative authority with the agreement of the other military or civilian
law enforcement agencies (LEAs) and the ATCICA or ACICA for—
National security crimes involving other DOD affiliated individuals when Army equities
exist.
Incidents of CI interest.
SUBJECTS
2-15. Inside the United States, Army CI is responsible for investigations of active duty U.S. military
personnel. The FBI is responsible for investigations of all civilian personnel, private DOD contractors, and
their employees. Army CI has primary investigative jurisdiction for retired personnel, active and inactive
Reservists, and National Guard members when the act or acts under investigation occurred while the
individual was on Active Duty status.
2-16. Outside the United States, Army CI has investigative jurisdiction over active duty military personnel
and their family members, current and former DOD civilian employees and their family members, current
and former foreign national employees and their family members, and DOD contractors and their family
members, subject to coordination with the FBI, CIA, or host government agencies; retired military
personnel; Army Reserve personnel; members of the National Guard while in the performance of DOD
duties; and foreign nationals who are applicants for DOD employment.
INCIDENTS OF COUNTERINTELLIGENCE INTEREST
2-17. The following is not an all-inclusive list of incidents of CI interest:
The activities of ITO or material support to an ITO or person. Terrorist organizations are
specified in DCS, G-2 Memorandum (S//NF), dated 13 February 2007, Operational Planning
List (OPL) 2005 (U), as revised.
Unreported contact with foreign government personnel, persons or groups involved in foreign
terrorism or intelligence, or unauthorized requests for classified or sensitive unclassified
information.
Unauthorized disclosure of classified information or material. Not all incidents in this
category may meet the threshold for a CI investigation. However, those that do will often
include other indicators of espionage that are identified associated with the incident or when
there are acts which are known methods of operations of FISS and ITO entities. Investigations
are conducted to ascertain those entities involvement. CI special agents may also act to secure
classified material and to determine if the actions of the subject were an act of omission or
commission. The command requirements to report compromises or conduct inquiries as
specified in AR 380-5, chapter VI, may also apply to these incidents.
Matters developed as a result of counterintelligence scope polygraph (CSP) examination as
specified in AR 381-20.
2-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Military personnel or DAC employees who perform unofficial travel to those countries
designated in the operational planning list, who have unauthorized contact with official
representatives of foreign countries, or who contact or visit foreign diplomatic facilities
without authorization.
Attempts by authorized users of information systems to gain unauthorized access.
Known, suspected or attempted intrusions into classified or unclassified information systems
when there is reasonable suspicion of foreign involvement or it has not been ruled out.
Unauthorized removal of classified material or possession of classified material in
unauthorized locations.
Special category absentees (SCAs), which include those absent without leave (AWOL),
deserters defectors, and military absentees who have had access to TS, SCI, SAP information,
or TS cryptographic access or an assignment to a special mission unit within the year
preceding the absence. CI special agents will conduct investigations of the circumstances
surrounding the absences of SCA personnel using the guidelines presented in this manual.
Army military, civilian, or overseas contractor personnel declared AWOL and deserters who
had access within the preceding year to TS, SCI, critical military technology as defined in
AR 381-20, chapter 7, SAPs; personnel who were assigned to a special mission unit;
personnel in the DA Cryptographic Access Program (DACAP); and personnel with access to
critical nuclear weapons design technology.
Army military, civilian, or overseas contractor personnel who go absent without authority,
AWOL, or deserters who do not have assignments or access; however, there are indications of
FISS and ITO contact or involvement in their absence.
DA military and civilian personnel who defect and those persons who are absent without
authorization and travel to or through a foreign country other than the one in which they were
stationed or assigned.
DA military and civilian personnel detained or captured by a government, group, or adversary
with interests inimical to those of the United States. Such personnel will be debriefed upon
return to U.S. control.
Attempted or actual suicide or suspicious death of a DA member if they have an intelligence
background, were assigned to an SMU, or had access to classified information within the year
preceding the incident, or where there are indications of FISS and ITO involvement.
Suspected or actual unauthorized acquisition or illegal diversion of military critical
technology, research and development information, or information concerning an Army
acquisition program. If required, Army CI will ensure all appropriate military and civilian
intelligence and LEAs are notified. Army CI will also ensure Army equities are articulated
and either monitor the status of the agency with primary jurisdiction or coordinate for joint
investigative authority.
Impersonation of intelligence personnel or unlawful possession or use of Army intelligence
identification, such as badge and credentials.
Communications security (COMSEC) insecurities, except those which are administrative in
nature. (See AR 380-40, chapter 7.)
Suspected electronic intrusions or eavesdropping devices in secure areas which could be used
for technical surveillance. DA personnel discovering such a device will not disturb it or
discuss the discovery in the area where the device is located.
Willful compromise of clandestine intelligence personnel and CI activities.
21 October 2009
FM 2-22.2
2-5
FOR OFFICIAL USE ONLY
Chapter 2
COUNTERINTELLIGENCE INVESTIGATIVE CONTROL AND
OVERSIGHT
2-18. The Deputy Chief of Staff, G-2 (DCS G-2), exercises DA staff oversight and technical authority for
all CI activities and is responsible for appointing Army G-2X. The Army G-2X is the Army’s executive
agent for all Army CI activities at the Army staff level. On behalf of the DCS G-2, the Army G-2X
formulates policies for the conduct, management, direction, and control of CI investigations.
2-19. For the Army G-2, the Army G-2X maintains the ACICA who provides daily technical management,
control and oversight for all Army CI functions, including, investigations, collection, operations, projects,
programs, collection, reporting and analysis. The ACICA exercises technical control and coordination for
all Army CI elements and is the ultimate case control over all investigations.
2-20. The ACICA exercises technical control, review, coordination, and oversight of Army CI controlled
activities. The ACICA has specific responsibility to—
Act as the ultimate approval authority to open or initiate and close or terminate CI
investigations.
Assign case control numbers for tracking and operations security (OPSEC) purposes.
Serve as the single focal point for all CI investigative referrals to or operational coordination
with national intelligence, CI, and LEAs, Office of Personnel Management (OPM).
Provide CI expertise to outside continental United States
(OCONUS) ASCCs in the
establishment of ATCICA when directed.
Refer information which is not under Army CI investigative jurisdiction and which does not
involve Army equities to appropriate security, intelligence, or LEAs.
Review of CI investigative and operational reports for quality assurance and intelligence
oversight.
Coordinate for review of legal sufficiency.
Ensure that closed, completed, or terminated case files, project files, source dossiers records,
and reports are properly classified or declassified and retired to the U.S. Army Investigative
Records Repository (USAIRR).
In coordination with appropriate ATCICA, review information derived from active and
terminated CI investigations to ensure any information meeting intelligence reporting
requirements is properly submitted using IIR format.
Maintain a database for all Army CI investigations.
2-21. The ATCICA is responsible for providing the ASCC with the technical expertise to ensure that CI
activities are conducted in a competent, legal, and proper manner within their AOR. The ATCICA will
perform the following functions:
Serve as the central focal point for monitoring the conduct of CI controlled activities within
an AOR.
Assignment of case control numbers to CI preliminary inquiries for tracking and OPSEC
purposes.
Coordinate with the ACICA opening and closing CI investigations, and be responsive to
requirements of and direction from ACICA.
Provide theater-wide technical management, control, and oversight of all Army CI activities,
including investigations. This includes activities conducted by non-INSCOM CI units and
elements operating in a deployed status in the ATCICA AOR.
2-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Act as the principal Army interface with the theater joint or combatant commander on all CI
activities.
Provide action or information copies to ACICA on all CI investigative reporting, including CI
incident reports, investigative plans (IPs), and requests for approval for special investigative
techniques in accordance with AR 381-10.
Task investigative elements within theater and pass lateral leads to other ATCICA elements,
with an information copy to the ACICA.
Ensure all 381-10 procedural requests are reviewed by the command legal officer or SJA and
intelligence officer before being forwarded to approval officials.
2-22. Commanders of units with a CI investigative mission are responsible for ensuring that the ACICA
has full knowledge of all CI investigations. The commander has responsibility to—
Ensure all CI units and personnel submit all CI reporting to the ATCICA and respond to
tasking from the ATCICA and ACICA using the most direct channel.
Ensure the ATCICA is informed of all significant CI investigations and operations so that the
ATCICA and ACICA are properly prepared to inform or brief the chain of command.
COUNTERINTELLIGENCE INVESTIGATION TYPES AND
CATEGORIES
2-23. CI investigations focus on a person, incident, or systemic issue that are of potential interest to CI.
The subject and type of incident identified during the initial reporting of a CI matter will often determine
the type of investigation required as well as the scope of the investigation, resources, and various types of
investigative techniques required to effectively investigate and resolve the incident. Investigations
generally begin as incident investigations concerning acts or activities which are committed by, or involve,
known or unknown persons or groups. The amount of information obtained during lead development
concerning persons involved and the threat posed to Army equities will determine the type of investigation
that will be conducted.
LIMITED COUNTERINTELLIGENCE ASSESSMENT
2-24. Army CI investigative elements conduct investigative activity under limited CI assessment (LCA) in
response to information which normally does not require the submission of a CI incident report in
accordance with AR 381-12, paragraphs 3-1, 3-2 and 3-3, but which still represents a potential CI threat to
the Army and DOD. LCA investigative objectives are to quickly collect available information through
relatively nonintrusive means to clarify and establish CI interest, or to effectively determine that no CI
threat information exists. Army CI investigative elements may engage in the following investigative
activities under LCA, consistent with their assigned CI investigative mission:
Collect publicly available information, as well as information from online services and
resources available to and as approved for use by the reporting CI element.
Conduct records checks with military units and offices, including Army personnel and finance
centers, for example:
Checks with other federal, state, and local law enforcement and intelligence
organizations.
Checks with HN law enforcement and intelligence organizations OCONUS.
Reviews Army CI and Army intelligence files and databases.
Collect and retain items for evaluation as physical evidence not requiring approval under the
provisions of AR 381-10.
21 October 2009
FM 2-22.2
2-7
FOR OFFICIAL USE ONLY
Chapter 2
Interview previously established Army CI sources and liaison contacts. This does not allow
for the new tasking of those recruited assets.
Accept information voluntarily provided by any military, government, or private persons or
entities. Army CI special agents may always accept and review voluntarily provided
information or materials to determine potential CI interest.
Interview or request information (other than under pretext) from Army affiliated persons and
members of the public and private entities. Interviews or RFIs from non-Army affiliated
personnel or entities are authorized, subject to existing coordination requirements with other
agencies or authorities, such as the FBI in the continental United States (CONUS), and CIA
chiefs of station and HN authorities OCONUS in accordance with an existing Status of Forces
Agreement (SOFA). In areas without a SOFA or in contingency areas, local commanders will
provide appropriate guidance. Interviews of investigative subjects, potential subjects, or any
other persons which would require a rights warning are not authorized during investigative
activities associated with LCA.
Provide assistance to inquiries of supported commands conducted in accordance with
AR 380-5 and AR 15-6 when related to matters of possible CI interest. Army CI investigative
assistance to support such command inquiries will be limited to those activities identified
above, and may be conducted in coordination with the appropriate commander or
investigating officer. Additionally, Army CI special agents may participate in AR 380-5 and
AR 15-6 investigative interviews only upon request by the command investigating officer.
Army CI may not provide any assistance to investigating officers to support AR 380-5 and
AR 15-6 investigations when no indication of possible CI interest exists, except as identified
in AR
381-20. Army CI investigative personnel will ensure command investigative
representatives fully understand that Army CI investigative assistance is conducted under
authority of Army CI and not the command. AR 381-20 currently authorizes Army CI
personnel to provide investigative advice to command security investigations.
2-25. Investigative activity under LCA is authorized for 60 days upon written approval by an Army CI
special agent at or above the grade of O3/CW3/GG13 who occupies the position of commander, leader, or
operations officer of an Army CI detachment, resident office, region, or other field element of an INSCOM
major subordinate command (MSC) or the 650th MI Group. LCA approvals will be forwarded within 3
days for informational purposes to the INSCOM MSC/650th MI Group headquarters. Army CI special
agents in possession of CI badge and credentials who are not assigned to INSCOM MSC/650th MI Group
elements may conduct LCA investigative activities only upon written approval from the covering ATCICA
or the ACICA.
2-26. In support of contingency deployments, the ATCICA or ACICA may grant temporary LCA approval
authority to CI special agents at the grade of O3/CW3/GG13 or above, who are assigned to leadership or
staff positions in non-INSCOM MSC/650th MI Group elements. LCA investigations will not exceed 60
days, unless specifically approved by the ATCICA, ACICA or an INSCOM MSC/650th MI Group
commander based on written justification for the continued LCA investigative activity. Once terminated,
results of LCA activity will be reported to respective INSCOM MSC/650th MI Group headquarters or the
covering ATCICA by means of an executive summary or information paper which will include, at a
minimum, the initial case predication, a summary of investigative results, and the reason for termination.
2-27. Investigative activities conducted under LCA will be documented within five work days via a
memorandum for record (MFR) using locally assigned case control numbers and maintained in a standard
investigative case file. Investigative reporting under LCA will not normally be archived in the USAIRR
unless specifically required by the ACICA, ATCICA, or the INSCOM MSC/650th MI Group commander.
If the matter progresses to a preliminary or full investigation, all investigative reporting under the LCA will
be incorporated into the main preliminary or full investigative case file. At a minimum, investigative
reporting under LCA will be maintained in accordance with the requirements under the Army Records
Information Management System (ARIMS).
2-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
2-28. All activities conducted under LCA are subject to provisions of AR 381-10 regarding the collection,
retention, and dissemination of U.S. person information, and will be regularly inspected under
organizational inspection programs regarding their scope, management, and execution. All Army CI
investigative elements will report statistics on a quarterly basis to their respective INSCOM MSC/650th MI
Group headquarters or covering ATCICA concerning the number of LCA’s initiated and terminated during
the reporting period.
2-29. Army CI investigative elements will not utilize LCA as the basis for delaying or not submitting a CI
incident report or local threat report as required by AR 381-12. After submission of a CI incident report,
investigative elements will await case determination by the ACICA, ATCICA, or INSCOM MSC/650th MI
Group headquarters before continuing investigative activity. If no preliminary or full investigation is
opened as the result of a CI incident report, investigative elements have the authority to continue LCA
activities to clarify or expand on information of possible CI interest.
PRELIMINARY INQUIRIES
2-30. A PI is a limited scope inquiry concerning reported incidents of CI interest to ascertain if a threat to
national security exists; or a criminal offense within Army CI authority has occurred and warrants further
CI investigative actions or resources. A PI can be locally approved by the CI investigating unit’s
responsible ATCICA after the submission of an CI incident report has been submitted. PIs may include the
conduct of all investigative activities under SIA as well as the following:
Interviews of sources other than the subjects or potential subjects to identify the subject.
Regional, state, or HN records checks and National Crime Information Center (NCIC)
queries.
ACICA approval—pretext or subject interviews.
When timing is critical and the action is approved by an official specified by AR 381-10,
chapter 9, emergency surveillance may be conducted to identify a known or suspected agent,
or official of foreign power or known or suspected member of a terrorist group. (See
AR 381-20.)
2-31. PIs will be conducted at the direction of the responsible ATCICA. The ACICA, with the responsible
ATCICA, will decide dispositions of all PIs. Disposition may include the following:
Continuance or extension of PI.
Transition to an FFI.
Transfer of investigative interest to another investigative agency based upon priority of
authority or investigative responsibility.
Closure of the investigation if it is determined that no matters of CI interest are involved.
2-32. A PI must either be closed or transitioned to an FFI within six months, unless an extension is
approved by the ACICA. If a reported incident or allegation has sufficient merit upon CI incident reporting,
a PI need not be conducted as a precursor to the approval of an FFI.
FULL FIELD COUNTERINTELLIGENCE INVESTIGATIONS
2-33. FFIs are conducted when specific facts have been identified that someone under Army CI authority
has committed or allegedly committed a national security crime or incident of CI interest.
2-34. An FFI may be initiated with the concurrence of the ACICA after the submission of a CI incident
report.
2-35. The ATCICA is responsible for monitoring all investigative activities of opened FFIs within their
AOR and to coordinate all requests for all special investigative techniques with appropriate approving
21 October 2009
FM 2-22.2
2-9
FOR OFFICIAL USE ONLY
Chapter 2
authority within AR 381-10 and to consult with the ACICA concerning the status and investigative activity
for all FFIs within their AOR.
2-36. The ACICA may designate an FFI as a high priority based upon the significance of the investigation
and threat to Army equities involved. Commander’s of CI units who have an open FFI that has been
designated as high priority by the ACICA will ensure that the FFI takes precedence over all other CI
functions and will allocate appropriate levels of resources, manpower, and effort to the FFI.
SPECIAL CATEGORY ABSENTEE INVESTIGATIONS
2-37. SCA are personnel considered AWOL, deserters, defectors, and military absentees who are of
potential interest to CI. CI investigative focus in SCA investigations is to determine if any national defense
information was compromised or the offense was conducted at the direction or with the support of a foreign
government, military, or intelligence agency or a known terrorist entity. Army CI SCA investigations are
conducted to determine the following:
Circumstances and motivation of the absence.
Evidence of foreign intelligence or terrorist involvement or indications of potential espionage
or subversion at the behest of a foreign entity.
Indications of loss or compromise of classified or national defense information.
Indications of or potential for defection or travel to or through a foreign country.
Any connections in or with persons in foreign countries, including relatives.
Depending upon the SCA status, AWOL, deserter or defector, refer to this manual for specific
debriefing criteria.
2-38. Primary investigative jurisdiction for Army personnel declared AWOL rests with the Provost
Marshal. Should the military member be declared a deserter, the U.S. Army Criminal Investigations
Command (USACIC) assumes primary jurisdiction. Although Army CI does not have primary jurisdiction
in SCA cases, Army CI may investigate for the reasons under CI investigative control and oversight.
2-39. When a CI element is notified of the absence of an SCA meeting, a CI incident report, citing the
SCA as the subject, will be submitted within 72 hours to the responsible ATCICA. If the subject is not
immediately returned to U.S. military control, the ACICA will make a determination to designate the case
OPEN or TERMINATED.
2-40. CI elements need to establish a close working relationship with all PMOs, MP, and criminal
investigation units within their AOR to ensure that these units are aware of the topics of potential CI
interest that should be referred to CI.
INVESTIGATIVE PROCESS
2-41. The CI investigation process consists of lead development, planning and approval, investigative
activities, and termination or transfer. See figure 2-1 for the investigative life cycle.
2-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Figure 2-1. Investigative life cycle
LEAD DEVELOPMENT
2-42. A proactive CI program at all echelons, tactical to strategic, is required to educate military members
(Soldiers, civilians, and contractors) and generate CI leads. Military members often do not understand what
types of incidents are of interest to CI and may also not understand their reporting obligations under the
provisions of AR 381-12. All five functions of CI (investigations, operations, collection, analysis, and
technical services) can be used to identify and generate potential CI investigative leads.
2-43. A proactive CI program should, at a minimum, consist of an aggressive education and awareness
program, close and professional relationship with supported commanding officers and unit security
managers or officers. In addition to generating potential CI investigative leads, these activities can also
support CI collection activities to answer SCICRs or unit CCIRs.
21 October 2009
FM 2-22.2
2-11
FOR OFFICIAL USE ONLY
Chapter 2
THE COUNTERINTELLIGENCE AWARENESS AND REPORTING PROGRAM
2-44. The CI Awareness and Reporting Program is an education, awareness, and reporting program to help
identify potential incidents of CI interest. The program is a primary factor in obtaining information that is
the basis for initiating CI investigations in response to suspected national security crimes under Army CI
jurisdiction. AR 381-12 requires Army personnel, both civilian and military, to report matters of potential
interest to CI. This program also mandates CI awareness training be scheduled by all units on an annual
basis with the supporting CI office. CI training of personnel assigned to all units is subject to inspection by
the Inspector General (IG) office as well as under the Command Inspection Program. CI awareness
briefings should be given by qualified CI special agents whenever possible. CI awareness presentations
should, at a minimum, contain—
FISS and ITO collection methods of operation.
Criminal penalties for the various national security crimes under CI authority.
Type of situations and CI incidents of additional matters of CI interest that should be reported
(see AR 381-12, chapter 3).
Indicators of espionage (see figure 2-2).
Reporting procedures, responsible CI elements, and the 1800 CALL SPY program.
Initial Reporting.
2-45. The CI Awareness and Reporting Program, along with persons who have good situational awareness
of CI reporting requirements, will generally be the initial source for identifying indicators or anomalies for
incidents under the purview of CI authority.
Note. When operationally feasible, all CI incidents will be reported by the investigating CI
special agent within 72 hours after receipt of the information. If the reported information
identifies an imminent threat to U.S. forces, then the information needs to be reported
immediately through command channels with a follow-up report provided to the ACICA or
ATCICA.
2-46. All initial reports will be reported directly to the ACICA and a courtesy copy provided
simultaneously to the responsible ATCICA and the chain of command (if the investigating agent belongs to
an operational CI unit). If the investigating CI special agent is unsure whether the reported incident meets
the criteria of those reportable matters specified in AR 381.12, a report will be submitted to the ACICA and
ATCICA for a determination. The investigating CI special agent will obtain as much information as
possible from the initial source including—
Pertinent details of the suspected incident, date, time, time span, locations, suspected acts,
conversational details, information involved.
Personal information concerning known additional sources of the reported incident, witnesses
to the incident or subjects or potential subjects involved in the incident. A person is
considered known when they can be identified by at least a first and last name and unit of
assignment or employment location).
Physical descriptions of unidentified witnesses to the incident or subjects or potential subjects
involved in the incident.
Personal information concerning the source of the information.
PLANNING AND APPROVAL
2-47. Due to the legal complexities involved in CI investigations, investigative planning and approval has
to be detailed and meticulous to maintain the legal integrity of the case and/or to compartmentalize the
2-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
knowledge of the incident to allow for potential exploitation of the incident. The ACICA will review and
approve all IPs and subject interview plans (SIPs) submitted by the investigating element.
Figure 2-2. Indicators of espionage
21 October 2009
FM 2-22.2
2-13
FOR OFFICIAL USE ONLY
Chapter 2
2-48. If the ACICA determines that a CI incident report merits CI investigation, it will direct that one be
initiated and, except for full field CI investigations, the responsible ATCICA will maintain technical
control, management, and oversight of all investigative activities within their AOR. All investigative
reporting, plans, and requests for special investigative techniques will be forwarded to the ATCICA for
review and quality control before submission to the ACICA for higher levels of approval or before
forwarding to the approving authority. Interagency investigative coordination will be the responsibility of
the CI element on the ground. If problems with interagency cooperation arise, they will be forwarded to the
appropriate element commander to raise the issue to the appropriate agency headquarters.
Investigative Plan
2-49. The IP is the document that provides a detailed road map on the conduct of CI investigations
including all investigative participants, all investigative activities required, all resources and external
support required, and all interagency or legal coordination required to successfully resolve the incident. IPs
are living documents and may require revision due to information development and case direction. All
updates or revisions will be forwarded to and approved by the ACICA before implementation.
2-50. An IP is required in all open FFIs for investigative actions. IPs are not usually required for a PI;
however, the responsible ATCICA may direct the submission of an IP based upon the circumstances of the
PI. An IP is prepared by the lead agent in collaboration with the senior supervisory CI special agent and the
ATCICA. The IP is used to outline and request approval for investigative authority; however, some
investigative activities may require submission of additional documentation for coordination and approval.
The submission date for the IP will be directed by the responsible ATCICA and unit SOPs. Note that in
especially sensitive or high visibility cases IP approval may rest with a higher headquarters, ASCC,
ACICA, or Headquarters, DA (HQDA) level. While the format for IPs may vary slightly between all the
ATCICAs, the content of the IP will, at a minimum, include the following:
References. The subject block or title for the CI incident report and any subsequent
investigative reports that precipitated the opening of the investigation by the ACICA.
Title. The subject block with the assigned Army case control number assigned by the ACICA
in the investigation opening message.
Background. A synopsis of the incident under investigation.
Investigative objectives. Identification of subjects and relationships between subjects and
FISS and ITO; confirming, mitigating, or refuting the suspected allegations concerning the
subjects; the nature and/or extent of the compromise of classified information or technology;
to assess the damage to national security; determine the involvement and methodologies of
FISS and ITO.
Investigative actions. All projected activities required to conduct the investigation and
resolve the incident including records checks (local and military), interviews of all persons
who may be able to provide details concerning the incident, all persons who may be
considered witnesses to the incident and subjects interviews, any projected approvals for
interviews, general or investigative techniques, submission of final report of investigation
(ROI).
Joint investigative coordination. All activities conducted with or supported by external
military, civilian, or HN agencies during the course of the investigation.
ICF. The projected amount of funds required to support all investigative activities through the
life of the investigation.
Coordination required. All activities by external agencies required to support the
investigation which may include technical support for special investigative techniques; legal
coordination before subjects interview; coordination for apprehension, detention, and searches
by the appropriate approval authority.
2-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Updating Investigative Plans
2-51. An IP will be updated when there is a change in focus of the investigation, or a major occurrence that
sheds new light on the evidence or shows a new direction for the investigation to follow. To avoid
confusion and errors in communications, there can be only one IP as the sole investigative guide for
planned or projected investigative activity in the affected case. Therefore, an updated IP must supersede all
previous versions. The lead agent and the desk officer must assume that, in the natural course of an
investigation, developed facts and information will dictate a revision to the IP. A revised IP can be written
at any time. It is not necessary to wait for the ATCICA or ACICA to update IP. At or near the transition
from one phase to another, the entire case should be reviewed to ensure it remains focused, the
investigative activity supports the objectives and follow-on activities are appropriate. It is not necessary to
finish every investigative action in the original approved IP before submitting an updated IP or to finish all
investigative actions in the original IP before starting the investigative actions requested and approved in
the updated IP.
Joint Investigative Plans
2-52. IPs are required for the Army CI portion of joint investigations. Investigative planning in joint
investigations can be problematic. Other military and other government agencies (OGAs) do not have the
same organizational culture or administrative requirements as Army CI. In some cases their planning
process is more diffuse and approval levels are much lower. Early and frequent coordination is the key to
avoiding misunderstandings and miscommunication. This is critical in joint investigations where Army CI
is not the lead agency.
2-53. IPs in joint investigations will be prepared in the normal format and provided to the supervisory
agent for the lead agency for coordination and concurrence. In cases in which Army CI participates in a
joint investigation with another agency, it will document the action with a written agreement between the
parties. In either case it will be reflected in the IP forwarded to the ATCICA for approval with the name of
the lead agency official and date of concurrence. Field agents should be aware that coordination and
discussion may occur at multiple headquarters levels on their investigations. The joint IP is the foundation
of common understanding regarding the investigation and is the basis for all coordination at higher levels.
Subject Interview Plan
2-54. Once the ACICA has directed or granted approval for a subject interview of a CI investigation, the
CI element will develop a SIP. The purposes of the SIP are—to ensure the agent is familiar with all
information obtained during the course of the investigation and clearly understands the goals of the subject
interview; serves as a mechanism to identify and coordinate outside support as required; serves as approval
to actually schedule and conduct the subject interview, and may serve as the vehicle for legal review of the
subject interview proposal.
2-55. It is not required including specific questions in the SIP; however, depending on the complexity of
the issues to be discussed this can often be helpful. At a minimum, before conducting the interview the
agent should develop a topical outline that can be used to ensure all subject interview objectives and
requirements are met. If it is likely that a polygraph examination will follow the subject interview, the
polygraph detachment should review the case file and suggest questions for inclusion in the SIP to ensure
an effective polygraph. The ATCICA, or a CI supervisor with the delegated authority, will approve all SIP
in writing, before their execution. The SIP will include the following:
Title. The subject block with the assigned Army case control number assigned by the ACICA
in the investigation opening message.
Background. A synopsis of the incident under investigation.
Investigation objectives. Lists all the goals of the subject interview including—
21 October 2009
FM 2-22.2
2-15
FOR OFFICIAL USE ONLY
Chapter 2
Obtaining information to confirm, mitigate, or refute, for example, the possibility the
subject promised to provide, caused to be provided, and/or provided restricted U.S.
defense information to unauthorized personnel in an unauthorized manner.
Identifying the subject’s affiliation with any other foreign entity; that subject deliberately
compromised or willfully disclosed classified U.S. defense information.
Ascertaining that the subject engaged in any national security crime. Investigative
objectives also include identifying FISS and ITO methods of operation and the extent of
damage caused to national security.
Results of the investigation to date. A brief synopsis of all investigative activities and the
corresponding results preceding the subject interview.
Purpose of the interview. Identification of all persons involved in the suspected allegations;
the extent of compromise; all the details concerning the suspected allegations; assessment for
potential exploitation.
Administrative information. Include all participants in the subject interview, date, location
and whether or not the interview will be audio or video recorded.
Conduct of the interview. Include introductions, identification, rights warning or waiver and
other administrative procedures, topical areas of the interview or, if required by the ATCICA,
a line of questioning; closure of the interview including assessment on subject disposition
(released, released to his chain of command or detention or apprehension by appropriate
authorities).
Coordination required. Any type of external CI coordination required to support the
interview including the SJA for legal advice on charges; MP for possible custody assumption;
any joint participants (for example, Army CID or FBI).
Lead agent. Name, title, and contact information for the investigating agent conducting the
interview.
Requesting Special Investigative Techniques
2-56. All requests for the below listed special investigative techniques will be submitted through the
ATCICA to the ACICA for coordination and approval by the appropriate authority. AR 381-10 provides
detailed guidance on the separate approval authorities for all special investigative techniques both in the
United States and abroad. The IP may discuss the potential use of special investigative techniques, but will
not be used as the vehicle to document, coordinate, and approve these techniques.
Note. No special investigative techniques will be conducted unless coordinated by the ACICA
and approved by the responsible authority.
2-57. When considering the use of a special investigative technique to support a CI investigation, the least
intrusive means of achieving the goals of the investigation must be the primary consideration. If a more
intrusive special investigative technique is used other than one that would or could reasonably achieve the
same investigative result, the legal integrity of the CI investigation may be subject to challenge or dismissal
during potential criminal proceedings. The following special investigative techniques are used to support
CI investigations:
Procedure 5—Electronic Surveillance.
Procedure 6—Concealed Monitoring.
Procedure 7—Physical Searches.
Procedure 8—Mail Searches and Examination.
2-16
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Procedure 9—Physical Surveillance.
Procedure 10—Undisclosed Participation.
Staff Judge Advocate Coordination
2-58. While the primary objective in all established CI investigations is exploitation, if the situation does
not allow for Army CI to control the situation, then the threat has to be neutralized. In cases where
prosecution is a possibility, CI investigative personnel should consult with the SJA throughout the
investigation, after coordination with the ACICA and obtaining command approval. Continuous legal
consultation during the investigation will support the prosecution’s case and provide insight to the
investigating CI special agent regarding case direction. SJA can assist the CI investigative process by—
Providing legal advice for unique situations, such as offenses rarely charged or pursued.
Helping to clarify or resolve multiagency jurisdiction disputes and questions.
Assisting with identifying specific criminal offenses for individual cases.
Coordinating with the CI special agent to discuss interview legalities, rights warning waivers,
and hostile interview courses of action (COAs).
Assisting with the legal coordination and approval for apprehension, detention, and search
warrants with prior coordination and approval of the ACICA.
Preparing criminal proceedings.
Providing intelligence oversight review for proposed CI activities.
Providing advice and assistance in the preparation of proposals for special investigative
techniques.
2-59. All CI investigations will be conducted to a prosecutorial standard in accordance with applicable
U.S. laws and DA and DOD regulations. CI investigations of national security crimes must produce
findings which are accurate, concise, and legally sufficient for admission into a court of military or civil
law. Investigations must be conducted in accordance with the principles of law and the rules of evidence
which govern the prosecution of any criminal activity. AR 195-5 and FM 3-19.13 cover the legal aspects of
gathering, handling, documenting, and controlling evidence. CI personnel must have a thorough
understanding of the legal principles and procedures involved in conducting an investigation for three
reasons:
To strictly apply them in all investigative activity.
To ensure prosecutorial integrity even during emergency circumstances that does not permit
the opportunity to seek legal guidance before exercising investigative authority.
To provide the CI special agent an experience base to recognize those cases where specific
guidance, assistance, and/or approval must be obtained before executing any further
investigative activities.
2-60. Basic legal principles will always apply to CI investigative situations. Legal principles are designed
to ensure that the legal rights of subjects or suspects are observed. It is important to ensure that the potential
ability to prosecute any given case is not jeopardized by illegal or improper CI investigative techniques. In
addition, CI personnel involved in investigative activities must obtain advice and assistance from the SJA
or legal officer to implement recent court decisions interpreting statutes and regulations.
INVESTIGATIVE ACTIVITIES
2-61. All investigations will vary in scope, objective, and resources to successfully resolve the incident
under investigation. The IP is the primary planning tool to spur a logical thought process to identify all the
various types of investigative activities that should be considered to conduct the investigation. Investigative
21 October 2009
FM 2-22.2
2-17
FOR OFFICIAL USE ONLY
Chapter 2
activities should be tailored to each investigation. Investigative activities should be sequenced to ensure a
swift and successful completion of the investigation. The following are those general investigative
activities that will be common to most CI investigations.
Files and records checks for pertinent information.
Individual interviews for additional information and leads.
Exploitation of new leads and consolidation of all available data for analysis and planning a
COA.
Interview of the subject to prove or disprove the allegations.
Requests for assistance (RFAs) for CI support or investigative activities from other law
enforcement, security, or intelligence agencies.
2-62. Detailed planning is the key to preserving OPSEC and preventing the premature disclosure of the
investigation. The OPSEC objective is to ensure that the subject not be aware that anything is going on
until the subject interview; otherwise, the subject will likely change his patterns or habits that could disrupt
the investigation and potentially destroy any evidence required for prosecution.
2-63. While preparing the IP, the least intrusive method for obtaining information concerning the incident
or subject should always be the primary consideration. The least intrusive method will be the one which
allows the CI special agent to obtain the necessary information to prove or disprove the allegations against
the subject, while obtaining the necessary probable cause needed to justify more intrusive collection
techniques. IPs are progressive, and more intrusive investigative techniques may be required based upon
the complexity and legal sufficiency needed to support the investigation and any follow-on legal
proceedings. Investigative activities addressed in the IP should consider the following:
Sequence investigative activity from least to most visible. The closer the investigation gets to
the subject the higher the risk to jeopardizing the legal credibility of the investigation.
Use less visible, less intrusive techniques to establish the subject’s social network and
patterns. Detailed knowledge of how the subject lives day-to-day life is critical to OPSEC
planning.
Carefully identify “best sources” for required information and approach the fewest people
possible to develop critical information. There is always time to interview additional
witnesses after subject becomes aware.
Be cognizant of how much information you are giving away as you collect evidence. Do not
reveal specific accusations or details to witnesses. When conducting records checks, consider
asking for information about the subject’s entire section or unit vice solely focusing on the
subject.
Remember that your presence alone can reveal your interest.
Consider the use of ruses and cover stories. A survey can sometimes be used to develop
general information about the subject’s workplace and work habits.
When making inquiries or conducting interviews the CI special agent should refrain from
using threatening terms such as espionage or terrorism. For example, the CI special agent
should address the investigation as an inquiry into an incident of CI interest, security matter,
or violation. This will usually gain more cooperation from witnesses or persons with
knowledge of the subject or incident being investigated.
Always have a backup plan if the subject discovers your investigative interest. Examples:
What would change? Would simultaneous interviews of friends and co-workers now be
appropriate? How about an early subject interview? Do you want to conduct searches before
the subject can hide or destroy evidence? Is the subject likely to flee? Do you have enough
evidence and do you know how to have the subject detained if necessary.
2-18
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Media Inquiries
2-64. Be prepared for inquiries by local, national, or foreign media. In some cases subjects themselves will
contact local media in an effort to undermine an investigation. Under no circumstances will CI special
agents respond to media inquiries without the consent and approval of the responsible ACICA. The
standard response to such requests will be to refer the caller to INSCOM or other appropriate Public Affairs
Office (PAO), followed by immediate telephonic notification to the ATCICA that a media request has been
received. Any appropriate response to media requests will be developed and coordinated at the DA level.
Each office should maintain the name and phone number of their current appropriate PAO and should
ensure the local PAOs are also aware of this information.
“BIGOT” Cases and Close Hold Investigative Activity
2-65. In some instances, a case, due to its sensitivity or the sensitivity of the information involved, will
require that it be handled on a strict need-to-know basis. These cases are often referred to as BIGOT cases
because access to them is controlled by a BIGOT list. In this type of case, investigative actions are
sometimes tasked directly to the field element by the ATCICA and all responses are returned directly to the
ATCICA only. The ATCICA will notify the appropriate chain of command that a close-hold action has
been initiated, identify the action element involved, and estimate the approximate degree of field element
involvement. ATCICA will notify the chain of command upon completion of the close-hold action.
Handling Sensitive Compartmented Information Material in Investigations
2-66. All agents will keep their eyes open to the possible involvement of sensitive compartmented
information (SCI) in their investigations.
2-67. Indicators that this might become an issue, include—
Subject has a TS/SCI security clearance with SCI access.
Subject is assigned to an intelligence unit or holds an intelligence MOS.
Subject works in a sensitive compartmented information facility (SCIF).
Reportable incidents that occur in SCIFs.
The presence of unmarked information which deals with subject matter which has a high
probability of being SCI (for example, SIGINT, HUMINT, cryptography).
2-68. Upon determining the involvement or potential involvement of SCI information in an investigation,
the lead agent will coordinate with the local Special Security Office (SSO) for appropriate storage of the
SCI information. The lead agent will wrap and seal the SCI material being stored in the SSO against access
by personnel without the need to know.
2-69. Such protection will be afforded information until a final determination is made as to the
classification of the information involved. If possible SCI material of investigative interest will be stored
separately and in a security container accessible only by the CI special agents assigned to the case. A two-
drawer safe, a drawer in a container where each drawer has a lock, or a “drop safe” are preferable.
2-70. The lead agent will notify the responsible ATCICA immediately upon determining the actual or
potential involvement of SCI material in an investigation. All review and handling of SCI material involved
in a CI investigation will be conducted in a SCIF. The Defense Courier Service and approved facsimiles
(faxes) between SSOs are the only two authorized methods of transmittal of SCI material. The lead agent
will contact the local SSO for assistance. The ATCICA will provide the lead agent with final disposition
instructions for all SCI material obtained during a CI investigation. These instructions will include the
procedures for addressing SCI material within a ROI.
21 October 2009
FM 2-22.2
2-19
FOR OFFICIAL USE ONLY
Chapter 2
Special Access Program
2-71. AR 380-381 governs the security of SAPs in the Army. A SAP is an approved security program
imposing strict controls on individual access and dissemination of information. These controls are
selectively applied to especially sensitive Army programs involving military research and development,
activities, or operations. Agents will be familiar with the indicators of SAPs (for example, special handling
instructions, special caveats, nicknames, and code words).
2-72. The ATCICA will be notified by the most expeditious means available regarding the involvement of
SAP information in an investigation. AR
380-381 requires that the possible compromise of SAP
information be reported within 24 hours to the Technology Management Office (TMO), HQDA. Whenever
investigating agents encounter potential SAP material during the course of their duties, the material will be
brought under immediate control, inventoried, and handled as evidence. Exposure to the material and
knowledge of its involvement will be strictly limited.
SAP Read-On
2-73. The ATCICA and lead agent will identify the requirements for SAP read-on (additional agents,
technicians, and desk officers) to conduct an investigation involving SAP material. Unless otherwise
indicated, no SAP case will be run without read-on for key management and oversight personnel. This may
include, but is not limited to, all CI special agents participating in or conducting investigative activities to
support the investigation, command personnel as required and ATCICA or ACICA providing direction and
oversight for that particular CI investigation. SAP read-on will be conducted with the appropriate SAP
control officer.
Case Files
2-74. Two case files will be maintained on SAP investigations. One will be kept at the collateral level and
the other will contain the SAP material. When an IMFR or other documents must contain SAP information,
a dual reporting system will be followed. The investigating agent will submit two reports: one containing
the SAP information and one containing collateral, sanitized information.
Reports of Investigations
2-75. On termination of the investigation, two ROIs will be prepared. One ROI will contain all case
documentation, including the code word material. It will be retired through the TMO or the Special
Records Information Activity (SRIA). The second ROI will contain only the sanitized material. This will be
submitted through normal channels for retirement in the IRR. The collateral report will be a one-for-one
match to the SAP report, unless a specific document cannot be included. In the latter case, a statement will
be provided, generically describing the document and the information contained therein. The collateral
version will make reference to the SAP version and provide a location, point of contact (POC), and
telephone number for anyone required to view the complete record.
Security Procedures
2-76. SAP security procedures will be strictly adhered to in the conduct of a SAP investigation. Storage,
handling, transmission and accountability of SAP information, physical security requirements, and other
SAP security procedures will apply. Normal secure communication means is usually acceptable, as long as
only cleared personnel are involved in the process (for example, a fax).
TERMINATION OR TRANSFER
2-77. Terminated case files. Upon receipt of a message from the ATCICA terminating investigative
activity, the CI investigating element will take the following actions:
If directed, an ROI will be completed and forwarded, along with all original signature
investigative documentation and summary of information (SOI), to the responsible ATCICA.
2-20
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Ensure original signature investigative documentation includes the original CI incident
reports, IMFRs, original exhibits, and originals of other documents predicating the
investigation.
Ensure supporting documentation is retained in the field dossier, including case logs, copies
of the final correct CI incident report, ATCICA and ACICA message with operational interest
determination, any tasking messages, copies of all IMFRs, documentation of any phone
conversations between ATCICA and agent concerning the case, ACICA response
memorandums, and copies of Summaries of Information.
2-78. Open/Terminated (operational interest assumed). Forward all original signature investigative
reporting to the ATCICA. Retain supporting documentation for a minimum of one year from operational
interest determination date. Due to OPSEC sensitivities, caution should be exercised in retaining theses file
past the one-year mark. In no instance should follow-on coordination or support to the exploiting unit be
filed with the original report.
2-79. Open/Terminated (transferred). Transferred CI cases occur when a CI investigation is initiated by
one CI office (based upon ATCICA or ACICA approval) but a majority of the investigative activity will
take place in another CI element’s AO. In these instances, copies of the CI incident report (DA Form 2823
[Sworn Statement], and any ACICA correspondence transferring the case) will be maintained on file with
the initiating CI element. All original documentation will be forwarded to the CI office designated as the
lead investigating element by the ATCICA or ACICA. All transferred cases will be maintained on file until
the case has been closed by the ATCICA or ACICA, the ATCICA or ACICA directs otherwise.
2-80. Referred. When information is determined to be under the purview of another agency, the
information will be retained only long enough to refer the information to that agency. Forward all original
signature investigative documents to the ATCICA upon transfer decision. No information concerning a
U.S. person in referred cases will be retained in the local intelligence files. Referred cases containing no
information on a U.S. person may be retained for as long as deemed necessary to support CI operations,
subject to annual intelligence oversight inspections.
2-81. Terminated (pending ROI). Forward completed ROI (both hardcopy and softcopy) and all original
signature documentation to ATCICA upon termination of investigative activity. Retain a complete copy of
the ROI, all investigative reporting, and all supporting documents in the field dossier in suspense until
notification of case closure (acceptance of ROI by IRR).
2-82. Closed. The lead element will maintain the complete field dossier until the date of destruction
designated by ATCICA in the case closure message. Under no circumstances will the field element destroy
a case file before this date without prior written approval of the ATCICA. The lead element will label the
field case file with the following:
“DO NOT DESTROY PRIOR TO ________.” (Destruction date,
normally one year from case closure for field dossiers, will be provided by ATCICA or ACICA in the case
closure message.) The original field dossier may be retained past this date until no longer needed to support
current operations not to exceed six years. Upon notification of a decision to prosecute or take adverse
administrative action against the subject, place the field dossier back in suspense until action is resolved.
Retention periods begin again upon notification completion of legal or administrative action.
2-83. Case file destruction. ARIMS allows longer periods of retention of field files and offers the agent
wider latitude in what to keep. Files must be reviewed annually in accordance with AR 381-10. To ensure
no important or original signature paperwork is destroyed, CI investigative elements will contact their
ATCICA before destroying any investigative documents or material. The ATCICA will assist in
determining if destruction is the appropriate action. Most problems with file destruction arise when CI
investigating elements fail to forward original signature documents, copies of SOIs, or exhibits with IMFRs
before case file destruction.
RECORDS CHECKS
2-84. The examination of files and records for pertinent information on the subjects of the investigation is
the first action in most CI investigations. Records checks are conducted to identify indicators or anomalies
21 October 2009
FM 2-22.2
2-21
FOR OFFICIAL USE ONLY
Chapter 2
to substantiate or refute allegations or indications that a person or persons may be engaging in acts that
constitute treason, spying, espionage, and/or subversion. Indicators and anomalies are based upon historical
commonalities of persons involved in national security crimes, incidents of CI interest, or fit a profile of
someone who may be cooperating with a FISS and ITO. Records checks should begin with local unit files
and expand including a broad range of U.S. and HN law enforcement records that consist of civilian
agencies that maintain records concerning the subject’s personal background.
2-85. There are occasions when documented information or evidence is best obtained through other
investigative means. Some recorded data could be wrong, out of date, or simply misinterpreted due to
human error; however, the possibility of intentional deception or false information in both official and
unofficial records must always be considered. Not all information contained in official government or
civilian files should be considered absolutely true and should be corroborated via other records analysis and
investigative activities.
2-86. If the record is to be used in a court or board proceeding, the manner in which it is collected, copied,
extracted, or preserved will have a bearing on its use as evidence. Handling and storage for all information
collected to support a CI investigation will adhere to the rules of evidence.
2-87. There is a risk factor with records checks. Exposure of the subject’s name and the fact that he is
under investigation may alert the subject. Due to the sensitivity of CI investigations, the subject’s name
may be submitted in a list of persons to mask the true focus of the records check and investigation. The
investigating agent should examine all records requested and appear to review all records equally so the
true target of the examination is not exposed to observant records custodians or other bystanders. CI special
agents using this method during the course of approved investigative activities should exercise extreme
caution to not use or retain any data on U.S. persons that would be in violation of AR 381-10, chapters 2
and 3.
GAINING ACCESS
2-88. A variety of procedural methods are available to the CI special agent to obtain access to and copies
of records of investigative interest. The type of information being requested, the privacy rights afforded that
type of information, and the nature of the agency holding it drive the decision on which method is
appropriate. In general, government records are easier to get. Records of commercial companies are more
difficult to obtain, often require formal written requests, and may require authorization by a high-level
Army official, especially where specific privacy rights have been established in the law (for example,
telecommunications and financial records). Checks can be either consensual or nonconsensual.
Nonconsensual checks of records that have been afforded specific privacy rights under USC are the most
difficult to obtain.
Informal request. A verbal, or unofficial written request, by the CI special agent for access
to records of interest. These requests are most often used for MACs and LACs where an
existing liaison relationship exists and authority to access the records will not be questioned
or can be established simply by the CI special agent’s official status and authority with badge
and credentials and regulatory reference.
Access with consent. In cases where formal privacy rights have been afforded to a record, it
can almost always be accessed with consent of the subject. Subjects may even be willing to
give consent if they believe information in the record will refute, explain, or mitigate
allegations against them. Usually this consent must be in writing and frequently, depending on
the type of record, may require a specific form. This often occurs during the later stages of CI
investigations, when the subject is already aware that he is under investigation.
Formal written requests. Most national agency checks (NACs) and checks of commercial
company records are requested formally in writing. Formal requests may take a number of
forms. For example:
NACs are typically requested electronically or by memorandum, almost always through
the ATCICA or ACICA.
2-22
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Nonconsensual checks of commercial company records are requested by formal
memorandum. These memorandums certify that the agency presenting them has the
authority under a specific section of the USC to obtain the records and has met the legal
thresholds required to exercise their authority. These memorandums are strictly formatted
and often require specific approval authorities and signatures depending on the language
in the supporting section of the USC Authorities differ depending on the type and subject
matter of the record and the matters being investigated (for example, foreign CI versus
terrorism).
Other formal written requests are simple requests for voluntary cooperation from
commercial companies. These are used for travel related and general businesses. While
the companies involved do not have to grant access, they are not prohibited by law from
doing so.
Warrants, subpoenas, and court orders. In some cases the only way to obtain access to a
record is through a warrant or court order. This is the most formal method of obtaining access
and is complex and time consuming. Warrants and court orders may be sought from military,
federal, or the Foreign Intelligence Surveillance Court or a grand jury as appropriate. In joint
investigations the Army will usually defer to the FBI to obtain a warrant or court order.
Access to records by MI investigators. AR 381-20, paragraph 8-15a, provides regulatory
authority for access to Army records. Upon presentation of badge and credentials, CI special
agents will be permitted access to Army records under the provisions of AR
340-21,
paragraph 3-1a, as required for the conduct of CI investigations or operations. Additionally,
AR 210-10, paragraph 10-7, applies. They are also authorized to make extracts or transcripts
of specific information obtained. Access to records of other Federal agencies is provided for
in 5 USC 552a (b)(7).
2-89. Checks are generally categorized by whether they are conducted with a government agency or a
commercial entity. Government checks are further divided into MACs or civilian government agencies. A
distinction is also made between LACs and NACs. Checks of commercial companies which hold records of
investigative interest are often described by topical category
(for example, financial institutions,
telecommunications providers, travel-related services). More importantly, however, is whether the USC has
afforded specific privacy rights to that type of record and what exceptions have been allowed for CI and CT
purposes under the law. For example, the disclosure of both financial and telecommunications records are
generally prohibited with specific exceptions.
LOCAL AGENCY CHECK
2-90. A LAC is a records or files check of official or publicly available information retained by any local
office or government agency within the AO of the field element conducting the check. These records may
include holdings and databases maintained by local and state LEAs, local courts, and local offices of
federal agencies. Some examples include files and databases maintained by—
Local police departments.
State police.
Regional police and law enforcement networks.
JTFs (for example, joint terrorism task forces [JTTFs]).
State Department of Motor Vehicles.
Tax assessment offices.
Bureau of vital statistics (birth and death records).
Voter registration records.
Public utilities.
21 October 2009
FM 2-22.2
2-23
FOR OFFICIAL USE ONLY
Chapter 2
Local courts.
Local offices of the U.S. Postal Service.
Local offices of federal agencies.
Schools and universities.
MILITARY AGENCY CHECK
2-91. A MAC is a records or files check conducted at any military agency within the AO of the field
element conducting the check. In accordance with AR 340-21, the DA Privacy Program allows disclosure
of records to officers and employees of DOD who have a need for the record in the performance of their
duties. This authority applies to records on Army installations. Military service records of current and past
members of the armed services of most nations are detailed and usually accurate. MACs include, but are
not limited, to the following:
Personnel network.
Joint Personnel Security Adjudication System.
Unit and installation security manager.
Unit S-1 and resource management officer.
MP or PMO.
Post Vehicle Registration Office.
MP investigations.
MP customs.
Local and regional CID offices.
Local offices of other military service law enforcement or intelligence offices.
Military finance and personnel offices.
Military medical facilities.
Post Dishonored Check Office.
Post education center.
Civilian Personnel Office (employment and finance information).
Post locator.
Worldwide locator.
Defense Eligibility Enrollment System.
Defense Manpower Data Center.
MEDICAL RECORDS CHECKS
2-92. Medical record checks are considered a LAC or MAC depending on the status of the facility holding
the record. For active duty military, the most readily available source for medical information is the
servicing or local medical treatment facility. CI special agents should be aware that in-patient and
psychological treatment records may be retained at the facility that provided treatment and may not always
be fully reflected in outpatient records. For retired and separated Service members records may be located
at the Army Personnel Center (ARPERCEN) records facility in St Louis, MO. Medical record checks
should be done when one or more of the following exist:
2-24
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
A suicide investigation. (This is rare and would usually be conducted as part of the USACIDC
investigation.)
Source states subject was directed for counseling for a problem which began to affect work
habits.
Information obtained during the course of the investigation indicates subject has been or is
being treated for a medical condition or drug or alcohol problem to stop self-destructive
behavior that was affecting work and life.
Directed by ATCICA or ACICA.
In a CSPE investigation for medical indication as to why the subject could not pass the
polygraph examination (for example, effect of prescription medications).
2-93. CI special agents will not directly review medical records. The review will be done by the medical
facility’s reviewing medical officer. Information in psychiatric evaluation files generally will not be made
available to special agents, but a medical authority will review and discuss the contents in general. It is
suggested that Army Intelligence brief the medical officer before the review on what type of information
Army intelligence needs out of the records. This is considered a record check even though the medical
officer is doing the record review. The following information of the reviewing medical officer should be
noted in introductory paragraph: Name, rank, position, medical facility name, and address.
2-94. If the subject is in possession of his medical record, discretely contact the commander of the medical
facility and/or the subject’s commander to have the medical records returned to the medical facility for
review.
2-95. Should medical personnel refuse, attempt to determine if the file contains any type of information
that would adversely affect the individual’s suitability for access to classified information.
Note. In the above instance, the issue of suitability is related to the subject’s possible inability to
properly handle classified information or his willingness to compromise it.
CIVILIAN MEDICAL RECORDS
2-96. To conduct a check of civilian medical records, a warrant, subpoena, or written release from the
subject is required. Civilian medical records are considered privileged information and will not be released
to investigators except as indicated above.
2-97. Under no circumstances will previously executed personal records release forms (Defense Security
Service [DSS] or OPM forms) from personnel security investigations be used in the conduct of CI
investigations.
2-98. Any agent who determines that civilian medical, financial, or educational checks are required during
the course of an investigation will submit an updated IP to ATCICA outlining the reason for the check.
2-99. If the records are deemed essential to the investigation, the ATCICA will assist in obtaining the
required approvals or warrant.
NATIONAL AGENCY CHECKS
2-100. NACs are formal requests to federal agencies for searches of their records and supporting
databases and files for information of investigative interest. NACs include DOD agencies as well as other
federal agency holdings. NACs may be requested by the field element through the ATCICA. In accordance
with local SOPs, the ATCICA will request NACs directly or through the ACICA and will submit and track
all requests to other federal agencies at the headquarters level. Field elements will not attempt to initiate a
NAC directly, with the exception of NCIC checks as outlined below. These types of requests add confusion
to an already complicated process. Examples of national agencies that can be checked are listed below:
21 October 2009
FM 2-22.2
2-25
FOR OFFICIAL USE ONLY
Chapter 2
DOD:
Defense Central Index of Investigations.
DOD IG.
Defense Manpower Data Center.
Defense Industrial Security Clearance Office.
Directorate for Industrial Security Clearance Review.
FBI:
Criminal records.
Intelligence records.
FBI fingerprint checks (requires a fingerprint card).
Bureau of Alcohol, Tobacco, Firearms, and Explosives.
Federal Prison System.
Federal Aviation Administration, DOT.
Social Security Administration.
CIA.
DHS:
Immigration and Customs Enforcement.
Border and Transportation Security Agency.
U.S. Coast Guard.
U.S. Treasury Department:
Internal Revenue Service.
U.S. Secret Service.
Financial Crimes Enforcement Center (FINCEN).
State Department:
Security Division.
Passport Division.
Intelligence and Research Division.
Military Departments:
Army.
Army Crime Records Depository (ACRD).
USAIRR.
National Guard Bureau.
Air Force.
Navy.
OPM.
2-26
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
NATIONAL CRIME INFORMATION CENTER
2-101. While technically a NAC, in accordance with AR 381-20, all CI investigative elements will access
and use NCIC terminals locally, wherever possible. On military installations NCIC access can usually be
obtained at the local MP station, PMO, or installation security office. Access can also be arranged via
liaison with local police departments, JTTFs, or other LEAs with NCIC access.
PROCEDURES
2-102. NACs are considered investigative actions and must be recorded by IMFR, regardless of the status
of the investigation at the time the NAC results and/or investigative dossiers are received. Resulting IMFRs
must be filed with the ROI. The IMFR for investigative dossiers will contain sufficient information in the
introductory paragraph to identify the file for retrieval if necessary. The body of the report will contain
sufficient detail to state the contents of the file, and not merely reflect that the file “contained no derogatory
information,” “no information pertinent to this investigation,” or “no significant information.” NACs are
conducted and investigative dossiers are reviewed for information that will—
Confirm or expand on information already known and/or reported.
Determine known or suspected FISS and ITO affiliation.
Attempt to identify someone.
Obtain background or lead data.
COUNTERINTELLIGENCE INTERVIEWS
2-103. As part of their investigation, CI special agents conduct interviews. Each situation dictates the type
of interview the CI special agent use when interviewing a subject:
Noncustodial interview.
Custodial interview.
Walk-in interview.
Source or witness interview.
Subject interview.
NONCUSTODIAL INTERVIEW
2-104. Noncustodial interviews are conducted when subjects are interviewed without depriving them of
their freedom in any significant manner (for example, arrest or detention). Subjects voluntarily consent to
an interview and are advised that they may depart at any time. Exercise caution during these interviews so
as not to impart suggestions of confinement or restraint, either through the type of room used (for example,
bars on windows, locked doors), statements of the interviewing agent, or by the number of agents
participating in the interview.
CUSTODIAL INTERVIEW
2-105. Custodial interviews are conducted when subjects are interviewed following a formal arrest or
detention. Subjects are made fully aware of their deprivation of freedom or of their “in custody” status.
WALK-IN INTERVIEW
2-106. Interviewees are regarded as walk-in sources when they have knowledge of a national security
crime or incident within the purview of Army CI, and they report their knowledge to the local Army CI
office. The walk-in interview may provide information that results in a CI incident report.
21 October 2009
FM 2-22.2
2-27
FOR OFFICIAL USE ONLY
Chapter 2
SOURCE OR WITNESS INTERVIEW
2-107. Interviewees who may have knowledge of a national security crime or incident of CI interest are
considered sources. Interviewees who may have actually witnessed a reported national security crime or
incident of CI interest are considered witnesses. Persons providing access to records or any other type of
documentation to support the investigation are also considered as sources. Depending on the attitude or
association of the source or witness to the subjects, a source or witness can be cooperative, uncooperative,
or even hostile.
SUBJECT INTERVIEW
2-108. The person who has committed or allegedly committed a national security crime or incident of CI
interest is the subject. During CI investigations there can be one or multiple subjects. Due to the legal
complexities involved in CI investigations and the potential for criminal proceedings, thorough preparation
and consultation with the ATCICA, ACICA, and SJA should always be a priority to ensure all legal
considerations and individual rights are observed and the prosecutorial integrity of the investigation is
maintained.
INTERVIEW PREPARATION
2-109. Interviewing persons knowledgeable of, witnesses to, or involved in, alleged national security
crimes or incidents within Army CI purview is the basis of all CI investigations. Interviews can
successfully resolve suspected allegations when conducted meticulously and with all legal requirements or
can jeopardize the ability to neutralize or exploit threats to national security. Thorough preparation for
interviews is critical to establishing the CI special agent’s authority and professional credibility to
interviewees. While walk-in interviews cannot be planned, the CI special agent’s knowledge of procedures,
laws, policies, and investigative techniques will help during a walk-in interview.
SOURCE OR SUBJECT ASSESSMENT
2-110. After the initial walk-in, the investigating CI special agent will begin preparing for follow-on
source and potential subject interviews. Agents must anticipate and mentally prepare for the interviews that
may range from cooperative to hostile. Most walk-in interviews are cooperative since the interviewee is
volunteering the information. However, source interviews may be cooperative or hostile depending on the
attitude of the interviewee or relationship between the source and subject.
2-111. If interviewees are resentful of people in authoritative positions or have a close relationship with
the subject, they may be uncooperative and hostile during the interview. The investigating CI special agent
should be firm, but professional, and establish authority. Subjects in subject interviews are often
uncooperative or hostile. People confronted with allegations of criminal activities are naturally defensive
and confrontational. Senior-ranking subjects may be resentful of an interviewer or accuser whom they
perceive is junior to them in age or rank. The investigating CI special agent should anticipate hostile
reactions during subject interviews; however, these reactions should not impact professionalism or
tactfulness during the interview. The CI special agent’s professionalism, knowledge, and interpersonal
skills are instrumental to manage the interview—induce interviewee cooperation and exploit interviewee’s
knowledge.
TELEPHONIC CONTACT WITH SOURCE OR SUBJECT
2-112. When making telephonic contact with a source or subject to arrange to coordinate an interview, the
investigating agent has to balance security of the investigation while providing the minimum amount of
information to induce cooperation. The CI special agent should conduct telephonic contacts as follows:
Identification. Identify themselves and ask for the prospective source or subject’s rank (if
military) and name.
2-28
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Source or subject identification. Verify that they are talking to the prospective source or
subject.
Reason for contact. Explain they are investigating or conducting an inquiry into a security
matter and that they would like to arrange to speak with the interviewee. Using verbiage like
“matter of national security,” CI special agent,” or
“CI investigation” may spook the
prospective source or subject. The CI special agent will never provide details of a CI
investigation over the phone.
Obtain agreement. The prospective source or subject may believe he does not have any
knowledge of an incident or security-related matter. The CI special agent needs to stress the
importance of the interviewee’s cooperation and that the prospective source or subject would
be assisting the special agent in resolving a sensitive security matter.
Establish interview. Establish the date, time, and location of the interview and ensure the
prospective source or subject has directions to the interview. Ensure the prospective source or
subject understands that the interview may last one to two hours. If the prospective source or
subject is hesitant about being away from his place of employment for that long, offer other
alternatives such as during lunch or before or after duty hours.
Provide security warning. Advise the prospective source or subject of the official nature of
the interview and that they are not to disclose their cooperation with anyone, including their
supervisor. If they are adamant that their supervisor or chain of command should know, the
special agent should obtain contact data for those persons and coordinate with the ATCICA
for these contacts.
Provide re-contact information. Provide official cellular or telephone numbers should the
prospective source or subject need to contact the CI special agent before the interview.
Summarize. Reiterate security warning, date, time, and location of the interview and thank
the prospective interviewee for his time.
INVESTIGATIVE AIDS
2-113. CI investigative interviews are complex and time consuming. Regardless of the level of
experience, investigating CI special agents should never go into an interview thinking they will be able to
remember all the different protocols, legal warnings, and documentation required to complete an interview
and still be able to effectively exploit all the information a source or subject may know.
2-114. Investigative aids assist in the exploitation of information. Investigative aids include Known and
Unknown Person, Location, and Vehicle Identification sheets. CI special agents may also develop
investigative aids for actions and objects (documents, electronic media) as these may likely be a part of a
CI incident. Aids allow for full identification of persons involved in the incident that assist with future
investigative activities, including records checks, and help in completing all documentation required during
the investigation.
Known person identification:
Name.
Rank and title.
Component.
Social security number.
Date and place of birth.
Duty position.
Duty location.
21 October 2009
FM 2-22.2
2-29
FOR OFFICIAL USE ONLY
Chapter 2
Unit of assignment.
Residence.
Permanent change of station date.
Temporary duty date.
Expiration of term of service (ETS) date.
Security clearance.
Level of daily access to classified information.
Special access—SCI only.
Unknown person identification:
Sex—male, female.
Race—Caucasian, Black, Asian, Other.
Skin color—dark, tan, white.
Skin complexion—smooth, pock-marked.
Age—within a 5-year range.
Height—within a 2-inch range.
Weight—within a 10-pound range.
Build and posture—small, medium, and stooped.
Hair—black, brown, grey, blond, red, bald.
Eyes—brown, black, blue, grey, green.
Dress—headwear, upper- to lower-body wear, foot wear, jewelry (top to bottom).
Distinguishing characteristics—physical handicap, tattoos, body piercing,
scars,
birthmarks, moles.
Location identification:
Room number and name.
Floor number.
Building number and name.
Street address (intersection).
Nearby landmarks.
Surrounding area description.
Installation.
City.
State.
Country.
ZIP code.
2-30
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Vehicle identification:
Make.
Model.
Year—can use time span.
Color.
License plate number.
License plate state.
Distinguishing characteristics—stickers, damage, other.
U.S. military installation decals—include associated color labels denoting, civilian,
enlisted, officer.
INTERVIEW AGENDA
2-115. An interview agenda is another type of investigative aid that allows investigating CI special agents
to decide how they want the flow of the interview to go. Interview agendas allow investigating CI special
agents to manage the interview and serve as a road map to key them on the completion of mandatory
documentation and security warnings required during the interview process.
2-116. Interviews are conducted based upon the experience level of the investigating CI special agent and
how he likes to transition between different topical areas. For example, some investigating CI special
agents like to complete all administrative documentation (for example, Privacy Act of 1974, Secrecy
Affirmation) at the beginning of the interview, complete information exploitation, and follow up with
executing the Sworn Statement and final security warning. Other investigating CI special agents may prefer
to conduct all the information exploitation, get source data, cover all administrative documentation, and
then execute the Sworn Statement and issue the security warning.
2-117. When using interview agendas, the investigating agent should always keep it concealed or out of
sight. If a source recognizes the agent is relying on this document to complete the interview, it may
undermine the credibility and professionalism of the investigating agent, and may result in the source being
more cautious, confrontational or uncooperative. The amount of detail the agenda contains is left to the
discretion and amount of experience of the investigating CI special agent. The following is an example of
an interview agenda:
ID source.
Present badge and credentials.
Synopsis of the information.
Detailed account of the incident by the source.
Use of Interrogatives.
Privacy Act of 1974.
Secrecy Affirmation.
Sworn Statement.
Security Warning.
21 October 2009
FM 2-22.2
2-31
FOR OFFICIAL USE ONLY
Chapter 2
INTERVIEW ROOM SETUP
2-118. It is important to determine what physical setting or environment will be most conducive to
gaining the trust and confidence of the source and will produce the most truthful and meaningful
information. Interviews can be and frequently are conducted in a myriad of settings, locations, and
environments. It is completely acceptable to conduct an interview at a source’s place of work, home, or
other location where he may feel more comfortable. Comfort sometimes allows a subject to talk more
openly and freely, which can greatly benefit the investigative process.
2-119. A subject interview needs to be strictly planned and controlled. A subject interview should rarely,
if ever, be conducted in an area where the subject works, socializes, or feels secure. The location selected
for a subject interview should provide complete privacy (free from distraction or disruption). Interview
rooms should not be equipped with phones, outside windows, wall ornamentation, and so forth. In addition
to these requirements, the room should be strategically arranged to ensure the most practical and conducive
environment. If the room is equipped with a two-way mirror, the subject should not face directly toward it.
This serves as a constant reminder that someone may be monitoring the interview.
2-120. Interview rooms should be equipped with a desk and at least three chairs if using an assisting agent
or four chairs if an interpreter is used. The interviewing CI special agent should be located directly across
from the interviewee. If an assisting agent is used for note taking or witnessing, they should be located to
the side of the interviewing CI special agent, far enough away so they are not in direct line of sight of the
interview.
2-121. When possible, the interview chair should be a four-legged chair with no arm rests. This removes
any potential psychological barriers or defense mechanisms and allows for easier recognition of body
posture and physiological indicators of deception during the interview. Additionally, investigating CI
special agents should use a hydraulic-type chair to manipulate their level above the interviewee to establish
a psychological dominance and position of authority. If using an interpreter, they should be placed to the
side and slightly behind the interviewee to ensure that their focus is directed towards the investigating CI
special agent. If the room is equipped with video recording equipment, it should be mounted in a corner
with visibility on the interviewee’s face, yet still out of direct eyesight so that it is not a distracter.
Figure 2-3 shows an example of a room setup.
RECORDING INTERVIEWS
2-122. As a general rule, Army CI does not record interviews. Taping interviews requires prior written
approval of the responsible ATCICA. The ATCICA will coordinate this action with the unit intelligence
oversight officer and SJA. A careful risk or gain assessment must be done to ensure the benefits expected
by taping the interview outweigh potential risks to the investigation. There is a significant logistical and
administrative burden involved with such activities.
2-123. Additionally, when the intent of an investigation is to prove a criminal act, a written report
accompanied by an incriminating signed sworn statement is sufficient. No value is added by including a
recorded confession. More often than not, the recording becomes a target for the defense to accuse
wrongdoing on behalf of the investigating agency or prosecution. Interviews and debriefings of subject as
part of a plea bargain or after the trial is complete for the purpose of conducting damage assessment are
common. Taping interviews should be considered when—
Interviews are conducted in foreign languages.
An interpreter is used.
Interviews are lengthy.
Interview topics are technical or extremely complicated in nature.
2-32
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Information Exploitation
2-124. At the beginning of an interview, the investigating agent will have the interviewee provide a
detailed explanation of the incident starting with the earliest relevant date and time concerning the incident.
The investigating CI special agent will not interrupt and will take very few notes. This helps the
interviewee refresh his memories and mentally recount the incident. After this initial dialogue, the
investigating agent will have the interviewee go back to the beginning of the incident and slowly have him
or her recount the details while the investigating agent takes detailed notes.
2-125. The interview should flow sequentially to develop a logical time line of what happened. As the
interviewee provides details concerning the incident and reveals other information, the special agent should
make a note and follow-up with a separate line of questioning of that lead or string after the current topic
has been fully exploited.
Figure 2-3. Example of an interview room setup
21 October 2009
FM 2-22.2
2-33
FOR OFFICIAL USE ONLY
Chapter 2
2-126. When asked for specific dates, times, and locations, the interviewee may not be able to provide
exact information. In this case the investigating CI special agent needs to identify the details as precisely as
possible. If the interviewee cannot remember a specific date, the agent needs to gradually broaden time
spans to a day of the week, week, month, or time of year, or even season, to get the most precise
information available.
Note Taking
2-127. Accurate, detailed, legible, and properly sequenced notes are critical in articulating the information
obtained during all interviews. During the interview, as information is developed, if the interviewee
provides another lead or string that requires exploitation, make a note in the margin, fully develop the
current topic, and go back and exploit the lead or string provided earlier. This helps maintain the tempo of
the interview, limits interviewee confusion by disrupting a sequence of events, and makes it easier to
transcribe the notes into a report or sworn statement. If the interviewee is providing details about a specific
event and mentions a name, for example, “John”, do not interrupt to request John’s personal identifying
information. Make a note. After exhausting the current topic, go back and follow-up with questions
concerning John.
Backup Information
2-128. Part of the interview preparation is to have prepared copies of all administrative and legal
documentation that may be required in a particular interview. These include copies of the Privacy Act of
1974, DA Form 2823 (Sworn Statement), DA Form 3881 (Rights Warning Procedure/Waiver Certificate),
and Consent to Release Forms and Secrecy Affirmations. The investigating agent should have blank copies
of all these documents available as well as ones that have all areas that require signatures and/or initials
highlighted to ensure they are properly documented during the interview. Copies of the DA 3881 should
also be available during walk-in and source or witness interviews since there may be times when these
interviewees, although cooperative, may implicate themselves in a criminal offense. During subject
interviews, investigating CI special agents should also have a copy of all charges (Title 18, USC, and
UCMJ) available to explain why their suspected actions are viewed as criminal offenses.
Questioning Techniques
2-129. How an investigating CI special agent asks questions in an interview is also important. Good
questioning techniques limit confusion of the interviewee; maintain the tempo and control of the interview;
and save time by limiting repetitive clarifying questions.
2-130. Direct questioning using the basic interrogatives who, what, when, where, why, and how” is the
most efficient way to exploit information in most interviews. Investigating CI special agents will never use
compound or leading questions. The investigating agent should avoid asking questions like these:
WRONG. Can you spell John’s name? This creates two questions and two answers. The
initial question and the answer, which will usually be Yes or No, and the follow-up question,
spell John’s name.
RIGHT. Spell John’s name.
WRONG. You saw John take the classified document home, right?
RIGHT. Who took the classified document home; or did you see John take the classified
document home?
WRONG. Was John in the office and who was with him?
RIGHT. Was John in the office? (After the answer, ask the follow-up: Who was with him?)
2-131. Elicitation is the use of generalized questions to ascertain someone’s knowledge on a particular
topic. In some cases of source or witness interviews where it is unknown whether the interviewee has
knowledge concerning the incident, it may be necessary to begin elicitation to ascertain his knowledge of
2-34
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
the incident. If the interviewee has no information concerning an incident under investigation, then the
investigating CI special agent will not have given away any circumstances surrounding the incident that
could be compromised later on.
2-132. To elicit an interviewee’s knowledge, the interviewing agent may simply ask, “do you know of any
security incident that may have happened in a specific timeframe?” or “where were you on this date and did
you notice anything suspicious?” Once the interviewee has acknowledged knowing about the incident in
question, the investigating agent may then begin asking direct questions.
INDICATORS OF DECEPTION
2-133. Detection of deception is not a simple process, and it normally takes years of experience before a
CI special agent can readily identify deliberate deceit. Inconsistencies in the source’s actions or words do
not necessarily indicate a lie, just as consistency is not necessarily a guarantee of the truth. However, a
pattern of inconsistencies or unexplainable inconsistencies normally indicate deceit.
Internal Inconsistencies
2-134. Frequently when an interviewee is lying, the investigating CI special agent will be able to identify
inconsistencies in the time line, the circumstances surrounding key events, or other areas within the
questioning. For example, the interviewee may spend a long time explaining something that took a short
time to happen, or a short time telling of an event that took a relatively long time to happen. These internal
inconsistencies often indicate deception.
2-135. Body language does not match verbal message. An extreme example of this would be the
interviewee relating a harrowing experience while sitting back in a relaxed position. The investigating CI
special agent must be careful in using this clue since body language is culturally dependent. Failing to
make eye contact in the United States is considered a sign of deceit while in some Asian countries it is
considered polite.
Lack of Extraneous Detail
2-136. Often false information will lack the detail of truthful information, especially when the lie is
spontaneous. The investigating agent needs to ask follow-up questions to obtain the detail. When the
interviewee is unable to provide the details that he knows, it is an indicator of deceit. If the interviewee
does provide this additional information, it needs to be checked for internal inconsistencies and verified by
repeat questions.
Repeated Answers with Exact Wording and Details
2-137. Often in the case of subjects, if he plans to lie about a topic, the subject will memorize answers or
details. If the interviewee always relates an incident using exactly the same wording or answers repeat
questions identically (word for word) to the original question, it may be an indicator of deceit. In an
extreme case, if the interviewee is interrupted in the middle of a statement on a given topic, he will have to
start at the beginning to “get his story straight.”
Physical Cues
2-138. The interviewee may display physical signs of nervousness such as sweating or nervous
movement. These signs may be indicators of deceit. The fact that an individual is being questioned may in
itself be cause for some individuals to display nervousness. The investigating agent must be able to
distinguish between this type of activity and nervous activity related to a particular topic. Physical reaction
to a particular topic may simply indicate a strong emotional response rather than lying, but it should key the
agent to look for other indicators of deceit.
2-139. Failure to answer the question asked. When an interviewee wishes to evade a topic, he will often
provide an answer that is evasive and not in response to the question asked. For example, if the interviewee
21 October 2009
FM 2-22.2
2-35
FOR OFFICIAL USE ONLY
Chapter 2
is asked, “Were you in the office when the document was taken?” and he replies, “I was in the office that
day,” he has truthfully answered a question, but has avoided being put into a position that may implicate
him in the incident. Or when a person repeats a question, it may be a stall tactic while trying to think of a
plausible answer to the question.
Source Confidentiality
2-140. Sources may be reluctant to talk to CI special agents based on a fear of becoming involved in a
legal proceeding, having to face cross-examination, or reprisal by the subject. Rapport building,
reassurance, appeals to duty and encouragement to do the right thing are the preferred method for obtaining
cooperation.
2-141. However, if a source is still apprehensive about cooperating, investigating CI special agents can,
under the provisions of the Privacy Act of 1974 protect source’s identity and grant confidentiality to ensure
the source’s identity is not revealed outside official or law enforcement channels. This protection would
include any documentation petitioned from external agencies outside law enforcement and military
channels under the FOIA. The Privacy Act of 1974 caveat and requests for confidentiality will be annotated
within investigative reports. Confidentiality should be offered as a last resort, and not until it is apparent to
the investigating CI special agent that rapport building, reassurance, appeals to duty, and encouragement to
do the right thing do not dissuade the source’s reluctance to provide answers to the investigating CI special
agent’s questions.
REQUIRED VERBAL WARNINGS DURING INTERVIEWS
2-142.
The following verbal warnings are required during interviews:
Security Warning (to be administered to all interviewees after each interview session).
“Sir/ma’am, the matter that we have discussed today is regarded by the Department of the
Army as extremely sensitive in nature. In order to protect the integrity of this investigation,
we request that you not discuss this matter with anyone outside the official investigative
channels of this office. Thank you for your cooperation.”
Follow-Up Security Warning (given at the end of follow-up interviews with the same
person). “I want to thank you again for not discussing this official and very sensitive matter
with anyone outside the official investigative channels of this office.”
Telephonic Security Warning. “Despite the fact that I have provided you with limited
information concerning this matter, I ask you not to discuss this matter outside the official
investigative channels of this office. Thank you for your cooperation.”
Consent to Release Under the FOIA. “I need to inform you that the information we have
discussed today will be made into an official report and that report will become part of official
U.S. Government files. Under the provisions of the Freedom of Information Act, any U.S.
person mentioned in this report may request a copy of those files once the case is closed,
adjudicated, and made a part of official U.S. Government records. Do you have any
objections to having your name released as the provider of this information?” (Use this
warning for walk-in and source only.)
Oath of Truthfulness for Subject Interviews. “The Department of the Army desires that
this interview be conducted under oath. Are you willing to be interviewed under oath? Do you
swear or affirm that the information you are about to provide in this interview is the truth, the
whole truth, and nothing but the truth?”
Title 18, USC for Perjury Warning for Subject Interviews. “I must inform you that under
the provisions of Title 18, USC, or Uniform Code of Military Justice (depending upon the
status of the interviewee), if you willingly and knowingly provide false or misleading
information, you could be subjected to additional criminal charges and penalties punishable
by 5 years of imprisonment or fined or both. Do you understand this?” (Request signature.)
2-36
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
CONDUCTING THE WALK-IN INTERVIEW
2-143. Walk-in interviews are conducted when a person voluntarily approaches a CI special agent to
report an incident of CI interest or national security crime within the CI investigative authority and
jurisdiction. During the walk-in interview, the CI special agent thoroughly develops the information
provided by the volunteer to identify specifics of the incident (dates, times, locations), description or
identity of a witness or person with knowledge of the incident, and the description or identity of the persons
involved in the incident. There are four phases of the walk-in interview:
Approach.
Information development.
Sworn statement.
Termination.
Approach Phase
2-144. The approach phase of the interview allows the CI special agent to confirm the source’s identity, to
introduce himself to the source, and to assure the source that he is in fact talking to a representative of the
appropriate agency. Specifically—
Receive the source into the office and tell them who you are. It is not necessary to present
yourself as a special agent, or even your military affiliation, at this time. For example, “Hi.
My name is
What can I do for you?”
Allow the source to provide a brief summary of the incident he wishes to report. Do not take
copious notes at this time because the information may not be in CI jurisdiction.
2-145. Any source (walk-in, telephone caller, or written message) who volunteers information, the
collection of which is unauthorized by AR 381-10, will be referred to the proper authorities. These sources
and the information they provided are referred to as unsolicited sources and unsolicited information. If
possible, all unsolicited sources will be fully identified and, if the information volunteered is of no interest
to Army intelligence but may be of interest to another agency, the source will be referred to the appropriate
agency.
2-146. Once you have determined that the source has a genuine need to talk to a CI special agent, identify
yourself as such and show him or her your credentials. In return, request the source’s military ID Card, or
picture ID, to ensure his identity. Ensure the source matches the description and photograph on the ID card.
2-147. If the individual provides information that reveals a potential threat to a high-level Government
official, the information must be reported through command channels.
Information Development Phase
2-148. This phase allows the special agent to clarify information, identify and exploit information of CI
interest, pursue leads, develop any espionage indicators, and obtain sketches if necessary.
Clarify All Information
2-149. An example of clarifying all information would be if the source informs you of a vehicle that was
identified during the incident. Attempt to obtain all descriptive data on the vehicle. Persons not known by
name to the source must be identified by description (sex, height, weight, manner of dress, hair color, eye
color, and any distinguishing marks).
21 October 2009
FM 2-22.2
2-37
FOR OFFICIAL USE ONLY
Chapter 2
Pursue Leads
2-150. Ascertain who else was in the area at the time of the incident or who else has knowledge of the
incident. Attempt to identify these individuals and where they work. By talking to several people that were
in the area at the time of the incident, accurate facts can be obtained and a logical conclusion can be made.
Develop Espionage Indicators
2-151. Fully develop any espionage indicators. Espionage indicators provide a general idea as to the type
of individual that may be investigated. The source may not have personal knowledge of the subject;
however, ask the source if he has any knowledge about the subject concerning the following:
Finances. Have they received any letters of indebtedness or unpaid bills? Do they have any
financial problems? Do they have a problem paying bills? Do they appear to be spending
more money than they make?
Life-styles. Do they live life “in the fast lane”? Are they quiet individuals who keep to
themselves? What interests do they have?
Hobbies. Have they ever talked about their likes or dislikes outside the workplace? Do they
collect any objects? Do they belong to any organizations outside the military?
Associates. With whom do they associate during the duty day? With whom do they associate
after duty hours? With whom do they work? Who can provide more information concerning
subjects?
Foreign connections. Do they have any U.S. relatives living abroad? Do they have any
foreign contacts, business connections, own any foreign property?
Foreign travel (other than official military travel). What foreign travel have they taken?
Where do they go? How often to they travel? What are there reasons for traveling abroad?
Loyalty and allegiance. Do their personal beliefs, statements, actions, or associations
indicate they may not be loyal to the U.S. military or Government?
Work habits. Do they have the combinations to the security containers in the office? Have
they ever had any security violations? Do they volunteer for extra work? Do they volunteer
for sensitive assignments? Do they excessively use the copier? Have they ever been cited for a
security violation? Do they often work late or come in to work early? Are they signed for a set
of keys to the building or office?
Emotional, mental, and personality disorders. Do they have any known or suspected
emotional, mental, or personality disorders that may affect their behavior or actions or cause
them to be susceptible to influence or coercion?
2-152.
A sketch of the incident area generally assists in understanding the incident, as well as allows time
to formulate additional questions. Ask the source to provide a sketch of the area; ensure that all markings
on the sketch are those of the source. The following are some basic guidelines for sketches. Have the
source—
Title the sketch and annotate the date and time of the location of the incident.
Indicate the compass direction North if the sketch is of an outside location. If the direction is
not known, use cross-street information.
Indicate where all persons involved were located.
Indicate any obstacles that would have deterred their line-of-sight to the incident.
Print their full name, sign, and annotate the date the sketch was drawn.
2-38
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
2-153. After all the information has been fully developed, review your notes with the source to ensure you
have accurately annotated all information. Remember to ask the source if he has any further information to
add.
Sworn Statement
2-154. Request a DA Form 2823. The best policy is for the investigating CI special agent to type the
sworn statement from the notes of the interview. Have the source check for accuracy, correct any mistakes,
and have the source sign the DA Form 2823. It is allowable to have sources hand write their own sworn
statement. Make arrangements for the source to return and sign the sworn statement after it is prepared by
the CI special agent. Upon final execution of the sworn statement, reiterate the official and sensitive nature
of the investigation.
Termination Phase
2-155. During this phase, the special agent will finalize all the administrative procedures and ensure he
has all the necessary information to complete the reports. In particular—
Have the source read the provisions of the Privacy Act of 1974 and answer any questions he
may have about it.
Obtain a full identification of the source. Basic identification includes full name, SSN,
military rank or civilian pay grade, date and place of birth, duty position, unit of assignment,
place of residence, ETS, date of last CI awareness briefing, and security clearance.
Ask the source why he reported the incident. Sometimes, the source’s motivation may provide
more insight as to the validity of the information. Some of the basic motives why individuals
report possible CI incidents to CI include ideology, compromise (fear or protection), and ego
(revenge or elitism).
Ask the source if he has any objection to your contacting him for further information. If the
source has no objection, ask if he prefers to be contacted at work or at home. If the source
does have objections, try to inform the source that the information discussed should be
considered as a part of an official CI investigation, and the details of the interview or the
information concerning the incident are not to be discussed with anyone else.
Inform the source that the information can be obtained through the FOIA and explain the
consent to release process. If the source has already talked to several individuals, get
identifying information on them to list in the report. Normally, it is not desirable to have
numerous individuals know about an incident or pending or ongoing investigation. The fewer
people who have knowledge of the incident (outside official channels), the less chance there is
of a compromise.
Give the source a Security Warning and have him sign a Secrecy Affirmation Statement (or
Non-Disclosure Agreement).
Thank the source for the information provided.
CONDUCTING A SOURCE OR WITNESS INTERVIEW
2-156. Sources or witnesses are those persons who may have observed, heard, or have knowledge of a CI
incident or national security crime within CI investigative authority and jurisdiction. Sources and witnesses
are normally identified during the conduct of a walk-in interview. Source or witness interviews are
conducted using the same basic principles used in the conduct of a walk-in interview.
Approach Phase
2-157. During the approach phase, the CI special agent confirms the source’s identity. After introductions,
the CI special agent determines whether the source has knowledge or information regarding the CI
21 October 2009
FM 2-22.2
2-39
FOR OFFICIAL USE ONLY
Chapter 2
investigation. Conducting a source interview is similar to conducting a walk-in interview. CI special
agents—
Identify themselves, first, by using their special agent credentials—name and organization—
and then by showing their credentials to the source.
Identify the source or witness by verbally verifying the source or witness’s name and rank and
requesting picture identification, such as a military ID card. Identity verification is at the CI
special agent’s discretion.
Explain the purpose and official nature of the interview and ensure explicit investigation
details are not revealed.
2-158. Determine if the source was at the location of the incident during the reported timeframe or if he
has any knowledge concerning a security incident at a particular location during a specific timeframe. If he
was or does not have any information, ascertain if he knows of anyone who was there. Ask why someone
would believe that he was there.
2-159. If the source states that he was at the scene, proceed with the interview. Ensure that the source
understands that the U.S. Government considers his presence and all matters discussed during the interview
to be official in nature and they are not to be discussed with anyone outside official channels. Determine if
the source has discussed the incident with anyone and tell the source that he is not to discuss the matter
further.
2-160. Provide the source with the appropriate Privacy Act Advisement.
Information Development Phase
2-161. This phase allows you to clarify information, identify and exploit information of CI interest,
pursue leads, develop any espionage indicators, and obtain sketches if necessary. Ask direct questions that
elicit narrative responses.
2-162. If the case is such that the number of those knowledgeable of the issue is very limited, or, if the
lead sheet specifies the conduct of a discreet investigation, the source interview may require some changes
in conduct including the following:
Ask indirect questions that will elicit the appropriate responses.
Use methods to conceal the identities of other sources to prevent the source from finding out
the issue at hand. Never lie to the source.
Allow the source to tell his story in narrative format all the way through. Note taking should
be kept to a minimum. Focus your attention on the source and listen to his story.
Do not make any promises other than a promise of confidentiality.
Ask clarifying questions. Review the story with the source to ensure that you have the
complete story. Do not assume that you know what this source means or knows, based on
previous information or interviews.
Cover all information. All information or incidents previously brought to your attention
should be fully covered to ensure that you have this source’s observations. Any new
information the source identities should be fully developed. Basic questioning techniques
come in to play. The six basic interrogatives form the basis for you questions.
Fully develop espionage indicators of finances, lifestyle, hobbies, associates, foreign relatives,
foreign travel, and work habits (see figure 2-2 [page 2-13]).
During the interview, determine if there are any new leads and fully identify leads mentioned
by the source.
2-40
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Obtain full identification of the source. Basic identification includes full name, SSN, date and
place of birth, duty position, unit of assignment, place of residence, home and work telephone
numbers, ETS, and security clearance. Before obtaining the SSN, ensure you have provided a
Privacy Act of 1974 statement covering the four main points.
Review your notes before asking for a sworn statement.
Sworn Statement
2-163. Request a DA Form 2823. The best policy is for the investigating CI special agent to type the
sworn statement from the notes of the interview. Have the source check for accuracy, correct any mistakes
and have the source sign the sworn statement. It is allowable to have the source hand write his own sworn
statement. Make arrangements for the source to return and sign the sworn statement at a later date and time
if required. Upon final execution of the sworn statement, reiterate the official and sensitive nature of the
investigation.
Termination Phase
2-164. During this phase, the special agent will finalize all the administrative procedures and ensure he
has all the necessary information to complete the reports. In particular—
Determine if the source has any objections to being re-contacted. Verify his resident address
and home and work telephone number for re-contact if not obtained while developing all of
their personal information.
Reiterate security by reminding the source of the official nature of the interview and the
matter discussed.
Issue the Consent to Release.
Issue the Secrecy Affirmation.
Thank the source for his time and cooperation.
CONDUCTING THE SUBJECT INTERVIEW
2-165. Subjects are those persons suspected to be involved in a CI incident or national security crime
within CI investigative authority and jurisdiction. Subjects are normally identified during the walk-in or
source or witness interviews. Although the subject interview is conducted using the same basic principles
as the walk-in and source or witness interviews, there is more legal coordination conducted before the
interview. The subjects are advised of their rights before questioning them regarding the incident or crime.
Approach Phase
2-166. The approach phase allows you to confirm the subject’s identity through verification of a form of
identification. Introduce yourself as a CI special agent and present your badge and credentials and explain
the circumstances of the interview. The approach phase for the subject interview differs from the walk-in
and source or witness interviews in that you need to advise the person of their rights due to the allegations
involved. The subject interview is predicated on exhaustion of all other interviews and investigative
activities
(unless otherwise directed by the ATCICA), approval of a SIP by the ATCICA, and prior
coordination with the SJA and appropriate authorities if detention is anticipated.
Note. Go over hypothetical situations. subject may state he did not do it, or refuse to talk, or
admit he is guilty, become hostile or confrontational, or confess to a crime you knew nothing
about. Be prepared to handle any of the situations that may arise. Know what your authority is
and be prepared to exercise that authority.
21 October 2009
FM 2-22.2
2-41
FOR OFFICIAL USE ONLY
Chapter 2
2-167. Explain to the subject the general purpose of the interview and reiterate the confidential nature of
the interview. Inform the subject you have received information indicating him as a subject in a CI
investigation. The interview allows him the opportunity to explain, refute, or mitigate questionable or
misleading information received during the conduct of the investigation.
2-168. Administer DA Form 3881. Do not question the subject until proper advisement of legal rights and
voluntary waiver of those rights has been accomplished. Request subject read and sign a DA Form 3881 to
acknowledge receipt of the explanation of rights and record the individual’s decision to exercise or waive
the right to remain silent and to consult counsel. It is suggested to administer the rights advisement early in
the interview because of the details of the suspected or accused charges involved, and this is usually the
peak of anxiety for the subject.
2-169. Once the subject agrees to talk with you, the tension in the interview will generally, not always,
subside. If the subject invokes his rights upfront, your time will not have been wasted in delaying the
circumstances of the interview while having him fill out all the other documentation. Even if the subject
waives his right to counsel initially, he can invoke his rights later in the interview. When this occurs, you
must stop questioning the subject and consult with SJA on disposition.
Perjury Warning Provisions of Title 18, USC Before questioning the subject concerning the
allegations, inform the subject of Title 18, USC “I need to inform you of Title 18, United
States Code. Should you willfully provide false information, you could be subject to a $5,000
fine, up to 10 years in prison, or both.”
Privacy Act Advisement. Have the subject read the Privacy Act Advisement. Verbally
inform subject that the Privacy Act of 1974 requires that each individual who is asked to
provide personal information be advised of the following four salient points:
Authority by which the information is being collected.
Principal purpose for which the information will be used.
Routine uses for the information.
Voluntary nature of disclosing information and the possible repercussions of failure to do
so.
Note. Have the subject sign a copy of the Privacy Act Advisement to retain for your records. If
subject wants a copy, provide it.
Information Development Phase
2-170. When conducting subject interviews, consider the following:
Do not make off-the-record or unofficial remarks in the interview or any promises or
commitments to subject that are beyond your legal authority.
Avoid statements or representations which may be construed as opinion or advice to the
subject about past, present, or future actions. Do not argue with the subject or express
personal viewpoints on any matter.
Interview and question the subject concerning the matter under investigation. Use your
interview plan and the questions you developed during your planning and preparation process
to fully explore and develop the area of interest to establish the facts surrounding the
allegations.
Use basic interview techniques. When questioning the subject, it is imperative you obtain
direct responses to ALL allegations. Verify and complete previously developed information;
after which, fully develop any other and all information.
2-42
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Review your notes. When you are confident all investigative requirements are satisfied and all
the information has been fully exploited, inform the subject that you are going to review your
notes together to ensure accuracy. If there is anything you forgot or have incorrectly recorded
it, give the subject the opportunity to clarify or provide additional information. Review your
notes whenever you feel it is necessary to clarify information provided.
Sworn Statement
2-171. Request a DA Form 2823 from the subject. The best policy is for the investigating agent to type
the sworn statement from the notes of the interview. Have the subject check for accuracy, correct any
mistakes, and have the subject sign the DA Form 2823. If the subject refuses to sign the sworn statement,
annotate that on the form, sign it, and retain it in the dossier. It is allowable to have the subject hand write
their own sworn statement. The subject’s sworn statement will be prepared before rendering any decision
on the disposition (release or detention) of the subject.
Terminate the Interview
2-172. When terminating the interview, address the following:
Ask the “catch-all” question. When you are confident all investigative requirements are
satisfied and all relevant and/or derogatory information has been fully exploited, ask the
subject if there is anything he would like to add to the interview. If the subject adds
something, record the information and continue to ask the question “Is there anything else you
wish to add?” Repeat this line of questioning until a negative response is obtained.
Polygraph. Ask the subject if he is willing to submit to a polygraph examination.
Security warning. Provide the subject with a security warning (Non-Disclosure Statement).
State “I need to remind you that the information we have discussed during the interview is to
be considered confidential and official in nature and should not be discussed with anyone
outside the investigative channels of this office.”
Thank the subject. To maintain the established rapport, thank the subject and terminate the
interview.
Determine proper disposition of subject (release or detain). If the anticipated direction of
the interview has changed, consult with SJA before making a final decision on the disposition.
COUNTERINTELLIGENCE INVESTIGATIVE REPORTS AND FILES
2-173. Personnel involved in CI operations and CI or CE investigative activity will maintain complete and
accurate records. Records will be maintained in accordance with the ARIMS contained in AR 25-400-2.
LOCAL INVESTIGATIVE CASE CONTROL LOGS
2-174. To facilitate tracking, storage, retrieval, and suspense of records pertinent to CI investigative
activities in their AOR, all investigative elements should maintain case control logs reflecting all
investigations of all types and scope including RFAs. Case logs may contain as many fields as necessary
for local needs. Common fields include cross-references to FBI and other agency control numbers,
nicknames when assigned, and nicknames for supporting source operations or special collection techniques
when assigned. At a minimum these logs will contain the following items of information:
Local case control numbers (LCCNs).
ACICA control numbers (ASCCNs).
Incident or personal subject block.
Case opening date.
21 October 2009
FM 2-22.2
2-43
FOR OFFICIAL USE ONLY
Chapter 2
Current case status (including date for OPEN or SUSPENDED, OPEN or TERMINATED,
REFERRED and CLOSED investigations).
FIELD DOSSIER
2-175. The most important investigative file is the field dossier, which is usually divided by sections. It is
the investigating CI special agent’s file and frequently the most complete of the duplicative copies of the
case file maintained at the various levels of oversight and command. It contains the original signature
copies of IMFRs, statements, and other evidentiary documents. A well-organized field file is the foundation
of a strong case. While field dossiers will be established based upon ATCICA requirements and unit SOPs,
the following is the general content of most dossiers.
2-176. The most critical document in terms of continuity of investigative effort and institutional memory
of an investigation is the agent’s log. The log is maintained on a DA Form 1594 (Daily Staff Journal or
Duty Officer’s Log), or electronic equivalent, and is filed in the front of Section 2 of the field dossier. It can
be either handwritten or typed, and is often maintained in softcopy and printed and placed into the field
dossier periodically.
2-177. The first entry in the log is the case opening message that opened the case. Everything is entered
into the Agent’s log as it is entered into the field dossier, the CI incident report, IMFRs, ATCICA
administrative memorandums, tasking memorandums, MFRs, conversation records, important emails,
summary of briefings, legal and intelligence oversight reviews, and other relevant documents. Additionally,
important actions that should be documented but do not generate a report should be annotated; for example,
supervisory case reviews. All numbers on the log should be consecutive starting with # 1. On each
document in the lower right corner, write in pencil the log number which corresponds to the log entry. Each
incident should be annotated on DA Form 1594 as follows:
Section 1—CI incident report. File a copy of the CI incident report or any other documenta
tion which was used as predication for opening the case. The other documentation could be an
FBI letterhead memorandum (LHM), poly report referral from ACICA, memorandum from
ACICA, request from DSS, or other directive memorandum. Copies of all the IMFR should
be kept in this area in reverse chronological order. In this section put the LHM requesting a
joint investigation if applicable.
Section
2—ATCICA and ACICA administrative messages. File all administrative
memorandums that are sent to the field. All tasking memorandums to the field concerning this
case are filed here in reverse chronological order. Place DA Form 1594 (on which every
action is logged) on top of this section to maintain a chronological listing of significant case
activity, both administrative and investigative.
Section 3—planning documents and outstanding requests. File all IPs, SIPs, and lateral
leads to other field offices requested by the investigating CI special agents in this section, as
well as lateral leads and requests for NACs concerning this investigation. Also file all emails
requesting extensions on the suspense and discussions on the case, procedure requests, and
administrative memorandums from the field.
Section 4—investigative memorandums for record. File copies of all IMFRs in reverse
chronological order. FBI FD-302 forms, which are used to report or summarize interviews
conducted, are considered the equivalent of IMFRs in joint investigations.
(In joint
investigations with any other service or agency, any report written by the other service is
considered equivalent to an IMFR.)
Section
5—MISC. File fully filled-out conversation records, ACIC analysis reports,
investigating CI special agent’s analysis, and miscellaneous emails in reverse chronological
order. An investigative memorandum for record will be used to record verbal coordination
pertinent to the investigation.
2-44
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Section 6—original signature documents. Place original signature documents in this section
immediately upon creation. Copies of any original signature documents should be made and
put in section 4. Field elements will retain original documents of all reports and exhibits in a
field case file throughout the duration of the investigation. Original reports and exhibits will
not be destroyed, defaced, or mutilated.
Counterintelligence Incident Report
2-178. The CI incident report, usually generated by a walk-in source, is forwarded through the ATCICA
to the ACICA for a determination on whether or not to open an investigation. Copies of all CI incident
reports will be retained by the investigating element in accordance with AR 25-400-2 until destruction is
authorized and/or in accordance with unit SOPs.
Investigative Memorandum for Record
2-179. The investigative memorandum for record (IMFR) records information obtained because of
various investigative activities, including source interviews, others knowledgeable interviews, subject
interviews, and records checks. The CI special agent likewise prepares the IMFR and forwards it through
channels to the appropriate ATCICA. An IMFR is produced after each completed investigative activity and
forwarded to the ATCICA. Copies of all IMFRs will be retained by the investigating element until the
investigation is completed and maintained on file in accordance with AR 25-400-2 until destruction is
authorized and/or in accordance with unit SOPs.
Report of Investigation
2-180. The ROI serves as an executive summary of investigative results reported in IMFRs and exhibits.
ROIs are required for any investigation that goes beyond the interviews of the original sources of
information and local and military agency checks. The ROI highlights investigative efforts to either
confirm or refute espionage indicators or allegations. The report should be concise, ensuring pertinent
results are emphasized. The agent preparing the ROI cites investigative findings to explain, refute, or
support allegations or incidents in which espionage activity is suspected. Copies of all ROIs will be
retained by the investigating element until the investigation is completed and maintained on file in
accordance with AR 25-400-2 until destruction is authorized and/or in accordance with unit SOPs.
Summary of Information
2-181. The SOI is a formal method of providing information to agencies and elements outside Army
intelligence investigative channels. The agencies may include local and national level agencies, as well as
unit commanders or LEAs. Typically, the SOI is used to provide information to the agency or organization
that has primary jurisdiction and responsibility for responding to the incident. The SOI provides a summary
of the referred incident and the results of any Army intelligence investigative activities. As examples, upon
case termination, the ATCICA may task the lead agent to pass an SOI to the FBI for further investigation;
or to a unit commander for further inquiry or action under the UCMJ. This chapter is intended to provide a
standardized format and basic guidance for the preparation, passage, and tracking of the SOI. Once Army
intelligence passes an SOI to the responsible agency or element, it must follow-up and determine what
actions were taken as the result of the SOI’s passage. The result must be reported to the responsible
ATCICA via an administrative message, as soon as available.
Letter of Transmittal
2-182. The first part of the SOI consists of a transmittal memorandum. This memorandum is prepared on
letterhead stationery and conforms to the guidance in AR
25-50. There are two different versions
depending on if the agency receiving the SOI is within the military or a non-DOD agency. This transmittal
memorandum is used to briefly explain the circumstances surrounding the acquisition of the information,
reason for providing the information to the addressee, and Army intelligence concerns and desires.
21 October 2009
FM 2-22.2
2-45
FOR OFFICIAL USE ONLY
Chapter 2
2-183. The transmittal memorandum may be classified or unclassified, depending upon content, although
agents should try to keep the transmittal memorandum unclassified. The transmittal memorandum provides
all professional administrative information, comments, and recommendations, which does not belong in the
SOI itself. Case control numbers should not be provided in the covering memorandum nor is it necessary to
provide or cross-reference actual case titles. The SOI transmittal memorandum will be signed by the senior
CI special agent.
Actual Summary of Information
2-184. The SOI is prepared on plain bond paper and is unsigned. The SOI summarizes the information
reported and developed by Army intelligence. The ASCCN or LCCN will be positioned directly below the
subject line, in the same format as IMFRs. It is not necessary to specifically identify sources of information
unless it is anticipated that the receiving agency of the SOI will need to contact or further question the
original Army intelligence sources.
Note. This is why it is important when interviewing a source to cover the four basic points of the
Privacy Act of 1974, with emphasis that such information or identification may be provided, as
necessary, to other responsible agencies.
Privacy Act of 1974
2-185. This advisement shows that subjects and sources understand their rights under the Privacy Act and
the voluntary nature of furnishing any personal information to special agents. The Privacy Act statement is
maintained in the local case file and is NOT forwarded as an exhibit to be archived with the ROI. There is
no regulatory requirement to advise non-U.S. persons of the provisions of this act. Privacy Act advisements
are not required in interviews with foreign nationals in overseas areas. The investigating element will retain
copies of all Privacy Act statements until the investigation is completed; they will be maintained on file in
accordance with AR 25-400-2 until destruction is authorized and/or in accordance with unit SOPs.
Sworn Statement
2-186. The sworn statement is a primary evidentiary document within the investigative case file. It
records a voluntary statement made by a source, subject, or accused, under oath or affirmation. When
properly completed, it is a legal document and lends credibility to any information furnished. The sworn
statement is attached to the IMFR as an exhibit and is unaltered from when the subject, source, or accused
wrote it. The sworn statement is filed with the IMFR as an exhibit. It is usually unclassified, unless the
subject or source puts classified information into it. The investigating element will retain copies of all DA
Forms 2823 until the investigation is completed; they will be maintained on file in accordance with AR 25
400-2 until destruction is authorized and/or in accordance with unit SOPs.
Rights Warning
2-187. DA Form 3881 records the fact that a U.S. person was advised of individual rights under the Fifth
Amendment to the U.S. Constitution, or rights under Article 31, UCMJ. It is used when questioning a
suspected or accused individual concerning a criminal act or national security crime of which they are
suspected or accused. This form is also used for military subjects who incriminate themselves during
interviews or for military subjects and accused persons who are interviewed or are asked to provide
information of a possibly incriminating nature. It further records the individual decision to exercise or
waive those rights. When used, it is attached to the IMFR as an exhibit.
2-188. Procedures for advising a person of their legal rights are fully explained on the reverse side of DA
Form 3881. The investigating element will retain copies of all DA Forms 3881 until the investigation is
completed and maintained on file in accordance with AR 25-400-2 until destruction is authorized and/or in
accordance with unit SOPs.
2-46
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Investigations
Secrecy Affirmations
2-189. This affirmation shows that a source or subject who is involved in some form of CI activity
understands that disclosure of the nature or existence of the activity is prohibited without the express
approval of Army intelligence. The Secrecy Affirmation is maintained in the local case file and is NOT
forwarded as an exhibit to be archived with the ROI. The investigating element will retain copies of all
secrecy affirmations until the investigation is completed and maintained on file in accordance with
AR 25-400-2 until destruction is authorized and/or in accordance with unit SOPs.
Exhibits Cover Sheets
2-190. Exhibits are documentation or physical evidentiary materials which support the information
provided in an IMFR. This evidence may be in the form of records, such as identification documents,
affidavits, statements, photographs, transcripts of interviews, photo copies, sketches (made by either the
special agent or other persons), pamphlets, newspaper clippings, sound recordings, surveillance logs,
DA Forms 4137 (Evidence/Property Custody Document) and
2823, computer memory devices, or
transcripts concerning the analysis of information storage medium.
2-191. Exhibits augment and support, but do not replace the IMFR. An exhibit cover sheet is used to
identify exhibits, usually documents, collected during the course of an investigative activity. This cover
sheet identifies the specific investigation to which the exhibit relates, control number, date of related IMFR,
and a description of the exhibit.
2-192. Special agents will provide a copy, or reasonable description, of all exhibits to the ATCICA when
the IMFR is submitted. If the investigative activity was conducted as an RFA, a copy of the exhibit will be
retained in the field case file of the investigating unit; the original IMFR and exhibit, with the exhibit cover
sheet, will be sent to the ATCICA. Investigating CI special agents will maintain the original copy of all
exhibits other than RFAs, which will be maintained at ATCICA for inclusion in the ROI, when ATCICA
terminates the case.
2-193. Exhibit cover sheets are transmitted with the exhibit and the IMFR reporting the results of
investigative activity in which the exhibit material was collected. Exhibit Cover sheets are maintained in
the local case file, along with the corresponding exhibit. The investigating element will retain copies of all
exhibits until the investigation is completed and maintained on file in accordance with AR 25-400-2 until
destruction is authorized and/or in accordance with unit SOPs.
Requests for Assistance
2-194. RFAs, lateral leads, and call spy hotline taskings are all requests for assistance documents. Field
elements will file case material relating to lateral leads originating from another theater ATCICA, Federal
LEAs, HN CI or police agency, or a sister service, in the appropriate investigative case folder. Original
reports and exhibits will be forwarded to the lead agent or appropriate ATCICA within five work days after
completion of tasking, or as directed by ATCICA.
2-195. Field elements will confirm receipt of all original copy case material from the field element or
ATCICA generating the request. Each field office will maintain a file containing all taskings from the
ATCICA, requests from other agencies, and any IMFRs, MFRs, or CI incident reports written to support
these taskings. Before destroying these files ensure all original signature documents not originating at the
ATCICA have been transmitted to the ATCICA. Copies of original signature investigative documents and
supporting documentation will be retained for one year from last action. If the field element desires to
retain the file, a retention determination will be sought from the responsible unit intelligence oversight
officer.
21 October 2009
FM 2-22.2
2-47
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 3
Counterintelligence Operations
Army CI supports full spectrum operations. CI elements focus on and dedicate their
efforts to detecting, identifying, neutralizing, and/or exploiting adversary intelligence
elements attempts to collect information on U.S. forces. CI is information gathered
and activities conducted to protect against espionage, other intelligence activities,
sabotage, or assassinations conducted by or on behalf of foreign governments or
elements of foreign organizations, persons, or international terrorist activities.
GENERAL
3-1. CI operations are activities designed to detect, identify, assess, counter, exploit, and/or neutralize the
intelligence collection activities of FISS and ITO entities targeting Army equities. The objective for all CI
operations is to disrupt or deny FISS and ITO targeting; provide support to specific Army programs; or CI
support to various types of military operations. CI operations generally use a combination of the core CI
functions (investigations, collection, analysis and production, and technical services and support) to reach
the objective.
3-2. However, all core CI functions are mutually supporting and one function may transition to or initiate
one or more of the other functions. For example, an on-going collection activity may reveal a possible CI
incident which requires the conduct of a CI investigation; or during the analysis of compiled CI information
a potential lead may be identified who may be used as a source to gather information on local insurgent
collection activities. CI operations can be either offensive or defensive in nature and generally use
investigative and/or collection activities to fulfill the object of the program. Figure 3-1 (page 3-2) shows
types of CI operations. CI operations fall into two categories:
Counterintelligence sensitive operations. Proactive and targeted activities that involve
direct or indirect operations against a known or suspected FISS and ITO threat. Offensive CI
operations are governed by AR 381-47 (S). Refer to this manual for detailed information
concerning CI projects, investigative source operations, defensive source operations (DSO),
and CFSO.
Counterintelligence support operations. DSO and offensive CI operations (OFCO) support
Army operations, force and technology protection, security projects, and information
programs. These programs are aimed at supporting the protection programs and formal
security programs of Army commanders at all levels.
ADVICE AND ASSISTANCE PROGRAMS
3-3. Advice and assistance programs are conducted by CI teams at all levels to improve the security
posture of supported organizations. These programs aid security managers in developing, sustaining, or
improving security plans and SOPs. Advice and assistance can help identify and neutralize threats to
security from FISS and ITO who attempt to obtain information about U.S. forces, programs, and
operations. These programs provide threat information and identify specific vulnerabilities to security
beyond the capability of a security manager. Advice and assistance can include but is not limited to—
Conduct of inspections, security planning, resolution of security problems, or development of
classification guides.
CI surveys, technical inspections, and preconstruction technical assistance.
21 October 2009
FM 2-22.2
3-1
FOR OFFICIAL USE ONLY
Chapter 3
Training, providing CI materials, and training security managers on CI programs.
COVERING AGENT PROGRAM
3-4. CI CAP support is the technique of assigning a primary supporting CI special agent to a command or
agency. This agent will conduct all routine liaisons and provide advice and assistance with the supported
element. It ensures detailed familiarity with the supported element’s operations, personnel, security, and
vulnerabilities, and in turn provides the element with a POC for reporting matters of actual or potential CI
interest. The CAP also allows the CI special agent to provide services that are tailored to the individual
organization’s mission.
Figure 3-1. Counterintelligence operations
COUNTERINTELLIGENCE SUPPORT TO RESEARCH AND
TECHNOLOGY PROTECTION
3-5. CI support to research and technology protection (RTP) prevents the illegal diversion or loss of DOD
critical technology. RTP entails identifying, assessing, and developing countermeasures to FISS and ITO
targeting, exploitation, or the illegal diversion of Army and associated DOD technologies, systems, and
components. CI support to RTP utilizes the full range of CI activities, to support and protect critical
program information. CI support to RTP will span the entire life of the program, from concept, through
development and fielding, to expiration of the technology or system. The Army G-2X is the program
manager for CI support to RTP in the Army. CI support to RTP includes—
Providing FISS and ITO threat information and analysis to all personnel and agencies
associated with an RTP program.
Providing support to TAs and VAs for an RTP.
Identifying and developing countermeasures to protect the supported program.
3-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
Providing tailored threat awareness briefings to program personnel.
Debriefing program personnel who have been in contact with representatives of foreign
governments, international organizations or other foreign contractors, or attending
symposiums or trade shows which may have brought them in contact with potential FISS and
ITO collectors.
Conducting joint investigations with other security or LEAs supporting the program to
prevent the loss of technology or compromise of the program.
Conducting damage assessments of programs that have potentially been compromised.
Developing a tailored counterintelligence support plan (CISP) for the supported program.
COUNTERINTELLIGENCE SUPPORT TO ACQUISITION AND
SPECIAL ACCESS PROGRAMS
3-6. Army CI provides support to research, development, technology, and evaluation
(RDT&E);
acquisition elements through the Acquisition System Protection Program to prevent the illegal diversion or
loss of critical military and defense technology. Acquisition systems protection integrates all security
disciplines, CI, and other defensive methods to deny FISS and ITO collection efforts and prevent
unauthorized disclosure to deliver our forces uncompromised combat effectiveness over the life of the
system. CI support is provided to protect U.S. technology throughout the acquisition process.
3-7. SAPs usually involve military acquisition, intelligence, and operations and support activities. When
applicable, CI support to SAPs extends to government and industrial security enhancement; DOD
contractors and their facilities in coordination with DSS as appropriate; and the full range of RDT&E
activities; military operations; and intelligence activities for which DA is the proponent or the DOD
executive agent. INSCOM is responsible for providing the life cycle support and maintaining the
capability, experienced personnel, and resources for CI support to SAPs. For more information on SAPs
see AR 380-381.
3-8. The CI support plan (CISP) is a formal agreement between the supporting CI element and the
supported program manager. The CISP identifies the roles, resources, and activities that Army CI will
provide to the supported program as well as all coordination with program elements or other agencies
involved with the program. The CISP should be reviewed annually and changes should be made whenever
there are significant changes to the program. All CISPs will be reviewed by the Army G-2X or ACICA.
There are two types of CISPs:
Program. Programs that develop critical program information.
Facility. Any facility used for research and development associated with critical program
information.
COUNTERINTELLIGENCE RED TEAM OPERATIONS
3-9. Upon request by a commander or program manager, CI personnel may plan and execute a simulation
of FISS and ITO targeting, such as an installation, operation, or program. Such simulations are informally
known as red team operations. Red team operations identify weaknesses in systemic or security programs
that could be exploited by FISS and ITO. Upon completion of a red team operation, a formal assessment
will be given to the commander that also includes countermeasures and/or recommendations to overcome,
reduce, or mitigate vulnerabilities. There is no single structure or composition for a red team. Red team
operations include, but are not limited to, the following:
Open-source collection. Often open-source collection will help the red team establish a
profile of the unit or agency as well as key personnel and to formulate a collection plan.
“Dumpster diving.” This is a search of unit trash which can provide details on past, present,
and future mission activities, biographic data on assigned personnel, and unit structure.
21 October 2009
FM 2-22.2
3-3
FOR OFFICIAL USE ONLY
Chapter 3
Elicitation. This involves conducting elicitation among target personnel where they socialize
or congregate to obtain information on the target unit or organizations mission, capabilities, or
plans.
Technical collection. This operation includes COMSEC monitoring, electronic, and/or
technical surveillance with the approval of the commander or program manager, and the
approvals required by AR 380-53 and AR 381-10.
3-10. Because of the complexity and high resource requirements, red team operations generally should be
limited to extremely sensitive activities, such as SAPs and RTPs, although red team operations may be
useful with major tactical exercises and military operations. Commanders must ensure compliance with
laws, policy, and regulations when employing technical collection techniques to support red team
operations. All red team operations will be approved by the CICA before execution.
COUNTERINTELLIGENCE SUPPORT TO TREATY VERIFICATION
3-11. A security consequence of arms control is an overt presence of FISS and ITO at U.S. facilities. CI is
concerned with non-treaty related activities of foreign visits to Army installations and protecting
installation activities not subject to treaty verification. CI personnel provide advice and assistance to
installation commanders and debrief personnel who may have come in contact with inspectors. The
Defense Threat Reduction Agency has overall responsibility for CI support to treaty verification. INSCOM,
with Army Forces Command support, is responsible for treaty verification support within CONUS. ASCC
and combatant command CI elements are responsible for treaty verification that affects unified, Army
component, or allied commands.
COUNTERINTELLIGENCE SUPPORT TO ANTITERRORISM AND
PROTECTION
3-12. Title 50, USC § 401a, implemented the National Security Act of 1947. It defines CI as “information
gathered, and activities conducted, to protect against espionage, other intelligence activities, sabotage, or
assassinations conducted by or on behalf of foreign governments or elements thereof, foreign organizations,
or foreign persons, or international terrorist activities.” Army CI is responsible for identifying terrorist
indications and warning (I&W) to Army equities; however, countering and neutralizing terrorist activities
is a multi-agency task under the Army’s antiterrorism (AT) program (AR 525-13). (See also AR 381-20,
chapter 9.)
3-13. Terrorism is defined as the calculated use of unlawful violence or threat of unlawful violence to
instill fear that is intended to coerce or to intimidate governments or societies in the pursuit of goals that are
generally political, religious, or ideological. Combating terrorism has two major subcomponents: AT and
counterterrorism (CT). As defined by DOD—
Antiterrorism are those defensive measures used to reduce the vulnerability of individuals and
property to terrorist acts, including limited response and containment by local military and
civilian forces.
Counterterrorism are those operations that include the offensive measures taken to prevent,
deter, preempt, and respond to terrorism.
3-14. Army CI is a key contributor in preventing and deterring terrorist activities targeting Army and DOD
interests. Army CI supports the AT program through the execution of all the CI functions (investigations,
collection, analysis and production, and technical services and support). Army CI generally focuses on the
FISS and ITO intelligence collection and targeting activities directed at Army equities to provide I&W of
exploitation or potential attacks. Unless assigned to a CT unit, Army CI is continually engaged in an AT
role to help detect and identify FISS and ITO collection threats and terrorism I&W. AR 525-13 stipulates
that the Army will—
3-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
Conduct foreign intelligence collection and CI activities to collect and disseminate
information on foreign threats against the Army.
Sustain an intelligence capability to monitor and report on the activities, intentions, and
capabilities of FISS and ITO and other foreign threat groups in accordance with applicable
regulations and directives.
Maintain a capability to report and disseminate, time-sensitive information concerning the
foreign threat against Army personnel, facilities, and other assets.
Provide supported Army commanders with information concerning the foreign threat against
their personnel, facilities, and operations consistent with the provisions and limitations of
AR 381-10 and other applicable regulations and directives.
Include foreign threat information in briefings on CI in accordance with AR 381-12.
Serve as the Army intelligence liaison representative to Federal, state, and local agencies and
host country Federal, state, and local-level agencies to exchange foreign threat information.
3-15. The role of CI is to support the commander’s requirements to preserve essential secrecy and to
protect the force directly or indirectly. To be most effective, CI should be thoroughly integrated into the
commander’s operational planning and preparation. The CI mission makes it an ever-present AT enabler
through the routine execution of its functions. However, CI can tailor its functions to provide support to AT
and protection specific operations including—
Screening LEPs working on OCONUS military installations.
Tailoring security education and awareness briefings and programs.
Conducting travel and foreign contact briefings and debriefing programs.
Supporting TAs and VAs.
Providing FISS and ITO threat analysis and products.
Conducting CI investigations and collection that impact AT and protection.
THREAT ASSESSMENTS AND VULNERABILITY ASSESSMENTS
3-16. AR 525-13 requires commanders, down to battalion level, to appoint an AT officer who serves as his
advisor on all AT matters. The AT officer is the catalyst for implementing the AT program within the unit.
The AT officer is responsible for obtaining support to the unit’s AT program to include scheduling and
coordinating VAs to assess the unit’s protection postures. VAs are conducted by multiple agencies with
differing areas of subject matter expertise including—
Physical security.
Explosive ordnance disposal.
Engineering.
CI.
Information management.
Law enforcement.
Medical.
3-17. While Army CI has been synonymous with the term “force protection” for many years, protection is
an Army program and a commander’s responsibility. AR 525-13 provides guidance to unit and installation
commanders to conduct VAs to identify weaknesses in security and protection posture and to provide
countermeasures recommendations.
21 October 2009
FM 2-22.2
3-5
FOR OFFICIAL USE ONLY
Chapter 3
3-18. The unit AT and protection officer is the focal point for coordinating and obtaining support for the
conduct of VAs on critical facilities, operations, and infrastructure within their unit. The focus of VAs is to
determine the unit’s ability to protect personnel, information, and critical resources by detecting or
deterring threat attacks and failing that, to protect by delaying or defending against threat attacks.
3-19. Additionally, these assessments will verify compliance with applicable Army and combatant
command standards. CI support to the conduct of AT and protection VAs consists of producing a TA and
making countermeasures recommendations in the final VA report concerning specific areas related to
countering or negating known or suspected collection targeting of the supported command.
3-20. TAs are products focused on the leadership, structure, capability, methods of operations, targeting
focus, and activities of known or suspected FISS and ITO for a specific area or location. A TA is a stand
alone document. TAs are produced from existing intelligence analysis as well as information developed
through all CI functions and liaison with other security, intelligence, and LEAs.
3-21. A VA is a detailed assessment for a specific target; unit, facility, mission-essential vulnerable area
(MEVA), C2 nodes, installation, activities, or operation. The role of CI to support a VA should be threat
based. Some questions to consider are—
What groups are targeting personnel and equipment?
What methods are these groups using to gain access to the post?
How are they collecting information?
What do they already know about our operations?
3-22. The CI focus in a VA is not only on the known, suspected, or potential FISS and ITO threat to the
target but also on weaknesses in systemic procedures that could be exploited by FISS and ITO to collect on
the target and potentially exploit or attack the target. The VA should also include CI countermeasures
recommendations to the commander on how to neutralize, reduce, or mitigate those vulnerabilities to
enhance the target’s posture and minimize threats to his personnel, facilities, and operations. Specific areas
of CI interest in VAs are—
Physical security. Physical barriers, access controls, guard force procedures and how they
can be penetrated or bypassed by FISS and ITO operatives.
Personnel security. Access to classified or restricted areas, clearance procedures to mitigate
the ability of a FISS and ITO operative to remove information or coerce someone with
placement and access to remove information from an installation or facility.
Information security. Document handling, storage, and destruction.
Information systems security and telecommunications security. Vulnerabilities to the
systems and susceptibility to intercept or compromise by a FISS and ITO threat.
OPSEC. Signatures, patterns, movement, or activities that can provide an indication of plans,
intentions, or capabilities.
COUNTERINTELLIGENCE SUPPORT TO HOMELAND DEFENSE
AND CIVIL SUPPORT OPERATIONS
3-23. Under the provisions of the Posse Comitatus Act, Federal U.S. military forces are restricted from
assisting in policing or law enforcement activities except when authorized to do so. Because Army CI
authority is narrowly focused, the role of CI in domestic operations is very limited. Generally, the role of
CI is limited to—
Conducting liaison with local, state, and federal security, intelligence, and LEAs.
Providing FISS and ITO threat and vulnerability analysis to the supported military unit.
3-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
Sharing information between DOD and the supported unit or agency.
3-24. During national disaster and civil disturbances, the potential collection threat to Army equities is
remote. During these types of operations, CI is strictly limited to conducting liaison between civilian LEAs
and the supporting military unit to obtain any protection information that could affect the ability of the
supporting military unit to effectively execute its mission.
COUNTERINTELLIGENCE SUPPORT TO JOINT TERRORISM TASK
FORCE
3-25. The JTTF program was established in September 2001. The JTTF is a task organization of multiple
different law enforcement, security, intelligence, and defense agencies to detect, identify, and counter
terrorist activities against U.S. interests. Army CI is an active participant in the JTTF program. The role of
Army CI includes—
Providing FISS and ITO threat analysis.
Identifying any FISS and ITO threat information that may impact Army equities.
Conducting or supporting joint investigations with other national agencies, with the
appropriate approval, which may affect Army equities.
COUNTERINTELLIGENCE SUPPORT TO COUNTERDRUG
OPERATIONS
3-26. The military participates in counterdrug operations under the provisions of the National Drug Control
Strategy. Military forces may be employed in a variety of operations to support other agencies responsible
for detecting, disrupting, interdicting, and destroying illegal drugs and the infrastructure
(personnel,
material, and distribution systems) of illicit drug trafficking entities. Military counterdrug efforts support
and complement rather than replace counterdrug efforts of Federal, state, and local LEAs in cooperation
with foreign governments. CI support to counterdrug operations is generally restricted to—
Conducting liaison with local, state, and Federal security, intelligence, and LEAs.
Providing threat and vulnerability analysis of international drug organizations that threaten the
security of U.S. forces.
COUNTERINTELLIGENCE SUPPORT TO INFORMATION
SUPERIORITY
3-27. Information superiority is an evolving concept and operational strategy within the context of Army
operations. As a result, Army doctrine will continue to change to reflect changes in TTP, operational focus,
and execution. Existing information superiority doctrine identifies CI as a core supporting element of the
information tasks conducted to protect U.S. forces networks while simultaneously degrading the
adversary’s networks and decisionmaking process. Information superiority is an integrating strategy that
incorporates several existing DOD missions within a theater of operations to ensure U.S. commanders
obtain information superiority over their adversaries. These tasks are designed to protect our information,
information systems, and decisionmaking process (offensive tasks), ultimately resulting in U.S. information
superiority. Information superiority is the operational advantage derived from the ability to collect, process,
and disseminate an uninterrupted flow of information while exploiting or denying an adversary’s ability to
do the same.
3-28. The information tasks identified in FM 3-0 are information engagement, C2 warfare, information
protection, OPSEC, and military deception. CI is specifically identified as a capability that can support
these tasks. CI support is essential to the execution of the information tasks at all echelons (tactical,
operations and strategic). Although FM 3-0 only identifies CI as a capability that supports the OPSEC task,
21 October 2009
FM 2-22.2
3-7
FOR OFFICIAL USE ONLY
Chapter 3
CI can support all the information tasks using one or more of the CI functions of investigations, collection,
analysis and production, and technical services and support. Figure 3-2 shows the CI support to Army
information tasks.
3-29. CI is instrumental in collecting and analyzing information about the adversary’s intelligence assets,
capabilities, processes, and intent that can affect U.S. information superiority. CI can provide the
commander with the understanding of what the FISS and ITO collects and believes. This allows operational
planners to tailor information tasks to manipulate the adversary decisionmaking process and affect the
outcome of future adversary actions.
Figure 3-2. Counterintelligence support to Army information tasks
COUNTERINTELLIGENCE SUPPORT TO MILITARY DECEPTION
3-30. Military deception comprises those actions executed to deliberately mislead adversary military
decisionmakers as to friendly military capabilities, intentions, and operations; this causes the adversary to
take specific actions (or inactions) that will contribute to the accomplishment of the friendly mission. CI
support to military deception is designed to deliberately neutralize, degrade, mislead, or manipulate
adversary intelligence services. CI support to military deception assists in identifying an adversary’s
intelligence services; for example:
Assessment of U.S. capabilities, intentions, operations or likely COAs.
Susceptibility to U.S. military deception.
3-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
Capability to detect deception.
Conduits in which military deception information may be passed.
Collection assets and capabilities that may be targeting U.S. military deception plans.
3-31. This information can be collected through CI source operations, CI investigations, CI debriefings of
DOD personnel, and CI screenings of local national workers and contract linguists. Information of this type
collected from detainees is of CI interest and should be channeled as such. CI threat analysis (CITA) can
help determine if the adversary is susceptible to or have indicators of our military deception operations.
COUNTERINTELLIGENCE SUPPORT TO PSYCHOLOGICAL
OPERATIONS
3-32. PSYOP are planned operations that convey selected information and indicators to foreign audiences
to influence their emotions, motives, objective reasoning, and ultimately to influence the behavior of
foreign governments, organizations, groups, or individuals to support U.S. national objectives. CI support
to PSYOP consists of countering adversarial HUMINT targeting of U.S. PSYOP and providing CITA for
counter-SIGINT analysis pertinent to PSYOP. Information provided by CI can assist the commander and
staff in developing a U.S. PSYOP strategy with the ability to counter, deter, neutralize, exploit, or at least
mitigate the adversary’s PSYOP program.
3-33. The first message presented to the general population is often the one that is perceived to be the most
truthful and consequently the one that bears more credence. Imagine an adversary gaining access to our
PSYOP message before its release and preempting that message with one of their own. The successful
execution of PSYOP requires CI to be knowledgeable of the adversary’s intelligence collection threat and
their intent to collect against friendly PSYOP. CI products pertinent to PSYOP planning include current CI
reporting, CI estimates, and country studies.
3-34. CI assets at all echelons should continually be provided with information about specified PSYOP
missions to ensure CI investigations, local national and contract linguist screenings, collection, targeting,
and products that support PSYOP remain current. CI assets not only answer the interrogatives concerning
adversarial intelligence targeting of a U.S. PSYOP operation but also may be able to provide feedback
about threat reactions to U.S. PSYOP messages to ascertain the effectiveness of the U.S. PSYOP mission.
COUNTERINTELLIGENCE SUPPORT TO ELECTRONIC WARFARE
3-35. Electronic warfare (EW) is any military action involving the use of electromagnetic and directed
energy to control the electromagnetic spectrum or to attack the enemy (JP 3-13.1). The three major
components of EW are electronic protection (EP), electronic warfare support (ES), and electronic attack
(EA). CI provides support to EW via its inherent collection of information about the adversary EW
program and their intent to direct their EW assets against U.S. forces SIGINT vulnerabilities and
communications security complacency.
3-36. Source operations can collect information on the adversary’s EW plans and their use of the
electromagnetic spectrum including the targeting of U.S. SIGINT. CI collection can also determine what
knowledge adversary intelligence has of U.S. forces SIGINT vulnerabilities and any complacency shown
on the part of U.S. personnel in regards to COMSEC measures.
3-37. CI threat analysts can use that information and analytical techniques and procedures to develop an
electronic summary of the battlefield, which can assist decisionmakers in developing the U.S. forces EW
plan. CITA during EW planning consists of a 5-step process: development of a database, a threat
assessment, a vulnerability assessment, countermeasures options development, and countermeasures
evaluation.
21 October 2009
FM 2-22.2
3-9
FOR OFFICIAL USE ONLY
Chapter 3
COUNTERINTELLIGENCE SUPPORT TO OPERATIONS SECURITY
3-38. OPSEC denies the enemy the information needed to correctly assess friendly capabilities, plans, or
intentions. OPSEC is a process beginning with identifying essential elements of friendly information
(EEFIs) or critical information and analyzing friendly actions attendant to military operations and other
activities. The results of that analysis is used to identify those actions or indicators that can be observed by
adversary intelligence that could be interpreted or pieced together to derive EEFIs for use by adversaries.
3-39. The next step is to select and execute measures that eliminate or reduce to an acceptable level the
vulnerabilities of friendly actions to adversary exploitation. The five actions involved in the OPSEC
process are—
Identifying EEFIs or critical information.
Analyzing the adversary.
Analyzing U.S. vulnerabilities.
Assessing risk.
Applying appropriate OPSEC measures.
3-40. CI support to OPSEC entails identifying adversary intelligence, TTP, collection methods, analysis,
and exploitation capabilities that target our EEFIs, and then developing countermeasures.
3-41. CI investigations, CI source operations, debriefing of DOD personnel, and screenings of local
nationals and contract linguists can determine what EEFIs are being targeted by foreign intelligence and
what adversary collection methods and capabilities are being utilized to collect EEFIs. Additionally, cyber
CI elements can perform Internet open-source collection and DOD network and systems analysis to
determine OPSEC vulnerabilities and provide support to the conduct of Army network threat and VAs. The
information provided by CI will aid the OPSEC planners in identifying and protecting EEFIs, identifying
OPSEC indicators, and developing OPSEC measures.
3-42. In accordance with AR
530-1, the Commander, INSCOM, will provide data on the foreign
intelligence threat, terrorist threat, and CI support to OPSEC programs for Army units, ASCCs, direct
reporting units, and above. The INSCOM elements will provide information updates, but will not write
threat assessments for the supported command or agency. (The supported organization’s intelligence staff
element performs this function.) Due to changes in AR 530-1, CI support to OPSEC at echelons above
corps and echelons corps and below will occur as resources permit. CI may also provide threat briefings
and training concerning the protection of U.S. classified information.
COUNTERINTELLIGENCE SUPPORT TO COUNTERPROPAGANDA
3-43. Propaganda is any form of communication to support national objectives designed to influence the
opinions, emotions, attitudes, or behavior of any group to benefit the sponsor, either directly or indirectly. It
is normally directed at the U.S., multinational partners, and key audiences in the AO. Propaganda
operations are deliberately designed to attack the will of nations to resist and Soldiers to fight.
Propagandists seek to mix truth and lies in a way that listeners cannot detect.
3-44. Counterpropaganda operations are structured to detect and counter adversary attempts to convey
selected messages to U.S. and allied audiences to influence their emotions, motives, objective reasoning,
and ultimately the behavior of governments, organizations, groups, and individuals. Counterpropaganda
operations identify adversary propaganda, contribute to situational awareness, and serve to expose
adversary attempts to influence friendly populations and military forces.
3-45. CI supports counterpropaganda efforts by providing planners with information regarding adversary
propaganda operations. It is possible CI elements may learn of an adversary’s impending propaganda
message before the adversary’s release of that information. This would provide DOD with a chance to
preempt their message with one of our own. CI identifies adversary propaganda efforts through CI source
operations, CI investigations, and local employee and contract linguist CI screenings.
3-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
COUNTERINTELLIGENCE SUPPORT TO COUNTERDECEPTION
3-46. The objectives of counterdeception are to negate, neutralize, and diminish the effects of or gain an
advantage from an adversary’s deception operation. Knowing what deception methods an adversary has
used in the past is important. Equally important is properly considering tactical indicators and not dismiss
them because they conflict with preconceptions. Dismissing them will enable an adversary’s deception that
plays on those preconceptions to succeed.
3-47. CI analysis provides awareness of an adversary’s posture or intent and identifies an adversary’s
attempt to deceive friendly forces. An adversary’s intelligence collection priority can provide indicators for
their actual collection requirements and also for deception planning and operations. Not only is it necessary
to uncover the adversary’s deception plan but also it is equally important to not allow the adversary to
know we have uncovered their deception plan.
3-48. CI source and screening operations can identify adversary CI and HUMINT operations and ISR
capabilities attempting to find out what we know of their deception plan. The CITA cell can analyze
information we have on the adversary deception plan and provide support to counterdeception.
COUNTERINTELLIGENCE SUPPORT TO PHYSICAL SECURITY
3-49. Physical security is that part of security concerned with physical measures designed to safeguard
personnel; to prevent unauthorized access to equipment, installations, material, and documents; and to
safeguard them against espionage, sabotage, damage, and theft.
3-50. CI support to physical security provides an additional line of defense in a physical security and AT
program through the use of CI source operations, CI screenings, debriefing of DOD personnel, and CI
investigations. CI supports the safeguarding of personnel and the prevention of unauthorized access to
equipment, installation, material, and documents by producing a well-planned, systematic CISP that clearly
identifies the threat. Additionally, CI analysis provides I&W of potential terrorist attacks and information
for proactive CT operations. CI investigations reveal attempts by foreign intelligence entities to use
espionage and sabotage to target U.S. forces.
3-51. Effective CI support to physical security provides decisionmakers with information and timely
warnings of adversary intelligence operations, planning being based on those operations, and likely
adversary COAs targeting DOD assets.
COUNTERINTELLIGENCE SUPPORT TO PHYSICAL
DESTRUCTION
3-52. Physical destruction is the application of combat power to destroy or degrade adversary sources of
information and C2 systems. Effective physical destruction also damages the adversary’s ability to collect,
analyze, retain, and disseminate information. Physical components of the information infrastructure and
supporting functions, such as electric power, communications links, and human operators, are likely
targets. Physical destruction includes direct and indirect fires from ground, sea, and air forces, and may
include both lethal weapons (bullets and bombs) and non-lethal weapons (lasers, microwaves, electron
beam generators). Physical destruction is executed as a planning technique among the integrated elements
that work together to achieve information superiority.
3-53. Through CI collection, operations, investigations, debriefings or analysis, CI may identify threat
collection assets (humans or systems) that are legitimate tactical targets and recommend neutralization by
appropriate sea, land, or air forces.
21 October 2009
FM 2-22.2
3-11
FOR OFFICIAL USE ONLY
Chapter 3
COUNTERINTELLIGENCE SUPPORT TO INFORMATION
ASSURANCE
3-54. Information assurance comprises information tasks that protect and defend information and
information systems by ensuring their availability, integrity, authentication, confidentiality, and non-
repudiation. This includes providing for restoration of information systems by incorporating protection,
detection, and reaction capabilities.
3-55. CI concentrates on the identification of foreign intelligence threats to information systems so system
administrators have the information they need to emplace the proper measures to ensure their availability,
data confidentiality, and the assurance that data has not been altered. In support of information assurance,
CI may provide information on and countermeasures for the following:
Hostile capabilities and intentions including which countries or their surrogates have the
capabilities and the intent to target Army telecommunications and automated information
systems.
Army vulnerabilities including the degree to which telecommunications and automated
systems are vulnerable.
Awareness of techniques including the latest targeting techniques employed by adversaries.
Unauthorized access including deliberate attempted penetration of Army automated data
systems.
3-56. Army cyber CI elements assist Army computer network operations (CNO) with identification of
adversaries who attempt to gain unauthorized access to Army networks and systems. CI can assist elements
within the Army with information assurance by ensuring information holders know the adversary methods,
techniques, and targets regarding our information and information systems.
COUNTERINTELLIGENCE SUPPORT TO CIVIL-MILITARY
OPERATIONS
3-57. Civil-military operations (CMO) are activities of a commander that establish, maintain, influence, or
exploit relations between military forces, governmental and nongovernmental civilian organizations and
authorities, and the civilian populace in a friendly, neutral, or hostile operational area to facilitate military
operations, to consolidate and achieve operational U.S. objectives. CMO are conducted with, by, and
through indigenous populations and institutions, U.S. Government agencies, international organizations,
and other NGOs. CMO support the building of HN capacities to deter or defeat threats to internal stability.
CI support to CMO consists of detecting, exploiting, deterring, or neutralizing adversarial intelligence
collection targeting of CMO plans, operations, personnel, and equipment. The successful execution of
CMO requires current intelligence and CI estimates which serve to provide situational awareness regarding
the threat, help protect the force, and enhance the successful execution of CMO.
3-58. In order to protect the neutral image foreign entities hold regarding CMO, CI conducts limited to no
operations in coordination to support CMO. With the exception of providing CI threat assessments
regarding the locations in which CMO operations occur, CI attempts to dissociate its mission from the
CMO community. This ensures that foreigners will not mistakenly assume that CMO personnel are
operating under the intent and focus that CI personnel operate.
3-59. CI assets may conduct CI screenings of contract linguists or initiate the process of vetting local
nationals assigned to conduct CMO with U.S. forces. The Civil-Military Operations Center (CMOC) serves
as the primary interface between the U.S. armed forces, indigenous population and institutions,
humanitarian organizations, intergovernmental organizations
(IGOs) and NGOs, UN and other
international agencies, multinational military forces, and other agencies of the U.S. Government. CI assets
may coordinate with the CMOC to coordinate, deconflict, and execute debriefing operations with local
3-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Operations
nationals, refugees, or displaced persons identified through the execution of CMO with reportable
information of use to Army CI.
COUNTERINTELLIGENCE SUPPORT TO PUBLIC AFFAIRS
3-60. PA is the public information, command information, and community relations activities directed
toward both the external and internal publics with interest in DOD. PA makes available timely and accurate
credible information so that the public, Congress, and the news media may assess and understand the facts
about national security and defense strategy. Effective PA enhances confidence in the force and its
operations.
3-61. CI support to PA consists of detecting, exploiting, deterring, or neutralizing adversarial targeting of
PA plans, operations, personnel, and equipment. The successful execution of PA operations requires
current intelligence and CI estimates which serve to provide situational awareness regarding the threat,
protect the force, and enhance the execution of PA operations.
3-62. In order to protect the neutral image foreign entities hold regarding PA operations, CI conducts
limited to no operations that may impact PAO. With the exception of providing threat assessments
regarding the CI threat in locations in which PAO will operate, CI attempts to dissociate its mission from
the PAO community. This ensures foreigners will not mistakenly assume that PAO personnel are operating
under the intent and focus that CI personnel operate.
3-63. CI assets will coordinate and integrate the support activity of vetting local nationals and contract
linguists involved with PA operations with U.S. forces.
COUNTERINTELLIGENCE SUPPORT TO COMPUTER NETWORK
OPERATIONS
3-64. CNO comprise computer network defense (CND), computer network attack (CNA), and related
computer network exploitation (CNE) enabling operations. CND is conducted at all levels and consists of
defensive measures to protect and defend information, computers, and networks from disruption, denial,
degradation, or destruction. CNA is operations conducted at the echelon above corps level to disrupt, deny,
degrade, or destroy information resident in computers and computer networks, or the computers and
networks themselves. CNE is done at the echelon above corps level and consists of enabling operations and
intelligence collection to gather data from target or adversary automated information systems or networks.
3-65. CI elements tasked with support to CNO must be fully engaged in liaison with U.S. communications
units, computer centers, and computer emergency response teams, as well as U.S. and HN intelligence,
security, and law enforcement communities. Any abnormalities within the cyber world will be initially
detected by these types of personnel who continuously work with systems and networks, and CI must have
access to the information they possess. When possible, liaison with supported units’ system administrators,
help desks, network analysts, facility security managers, maintenance, technology protection personnel,
and/or information system security officers (ISSOs) should occur to generate additional reporting of initial
abnormalities with the physical aspect or within Army systems and networks.
3-66. Once abnormalities have been discovered on Army information systems and/or networks, cyber CI
can begin to assist with the identification, exploitation, and neutralization of adversarial threats to U.S.
information systems, networks, and interests via the Global Information Grid. CI can assist CNO personnel
in detecting and identifying insider threats, destruction of systems, denial of service, compromise of
database information, creation of malicious code, and determination of origin of intrusions. CI elements
have the capability to examine the physical and virtual aspects of network architecture, applications, and
software, Internet protocol
(IP) addresses, users, locations, hardware and peripherals, and artificial
constructs that pose a threat to Army CNO. Some of the specifics of how CI supports CNO are—
Based on intrusion incident notification, provide investigative and analytical efforts to
identify the intruders including the IP addresses, net users, locations, hardware and
peripherals, and artificial constructs.
21 October 2009
FM 2-22.2
3-13
FOR OFFICIAL USE ONLY
Chapter 3
Examine different applications, software, methodologies and TTP used by an adversary.
Assist with identifying and detecting automation threat capabilities and identify U.S.
vulnerabilities and measures for automation software, hardware, and infrastructure protection.
Subsequently establish and maintain an incident database as well as databases of tools,
threats, and fixes associated with intrusions for future trend analysis and to assist operational
planners with COAs and network defenders in formulating system and network defenses.
Assist in the preparation of war plans, contingency plans, and orders by identifying friendly
C2 vulnerabilities and enemy C2 attack capabilities, assessing potential enemy C2 attack
COAs against friendly forces, conducting risk assessments, and building and executing a C2
protect plan.
Provide expertise in seizing electronic evidence including—
Recognizing evidence regarding electronically transferred information.
Preparing for search and seizure of electronic devices.
Conducting search and seizure of electronic devices (computers, wireless, cordless and
cellular telephones, answering machines, electronic pagers, Fax machines, smart cards
and magnetic stripe cards, identification card printers, scanners, printer, copiers, compact
disc duplicators and labelers, digital cameras, video, audio, electronic game devices,
home electronic devices, global positioning systems (GPSs), personal data assistants
(PDAs), handheld computers, blackberries, security systems, video computer devices,
storage media, skimmers, parasites, and other criminal technology. While this list is
extensive, it is not all- inclusive because of new technology being fielded every day.
3-67. Computer network intrusions and CI investigations involving computers, networks, and other
sophisticated technology require CI skills that differ from skills needed in the traditional CI arena.
Therefore, cyber CI activities will be conducted by specially trained, certified, and equipped cyber CI
special agents assigned to theater cyber CI organizations. However, when unable to receive support from
cyber CI personnel, any CI special agent should be able to conduct at least preliminary investigative
activities and search and seizure of electronic evidence operations.
3-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Chapter 4
Counterintelligence Collection Program
EO 12333 provides both a mandate and the authority for DOD components to
conduct CI collection. CI collection is the systematic acquisition of information about
the capabilities, intentions, and activities of foreign intelligence and security systems
(FISS) and international terrorist organizations
(ITO) entities who engage in
espionage, terrorism, sabotage, assassination, subversion, and intelligence collection
targeting Army equities. It may include the acquisition of information on any
adversary which presents a danger to lives, property, or security of forces or
represents an intelligence collection threat to technology, information systems, or
infrastructure.
GENERAL
4-1. Many Army and MI leaders often misunderstand the difference between CI and HUMINT collection.
While both disciplines utilize similar methodologies (talking to a human source) and TTP (tactics used to
collect and exploit the information), the overriding difference between the two collection activities is the
type of information targeted and the objective of the collection.
4-2. CI collection is primarily threat focused. CI collection activities focus on detecting and identifying
the known or suspected FISS and ITO collection targeting U.S. forces either for information exploitation
or for potential targeting. The objective of CI collection is to be able to—
Affect the FISS and ITO knowledge of the plans, intentions, and capabilities of U.S. forces.
Deny FISS and ITO the information to target U.S. forces.
Negate, mitigate, or disrupt the FISS and ITO collection capability.
HUMAN INTELLIGENCE AFFECTS FRIENDLY FORCE’S KNOWLEDGE OF THE ADVERSARY
4-3. HUMINT collection is requirements focused. HUMINT collection activities focus on identifying the
plans, intentions, and capabilities of the adversary to support the commander’s military decisionmaking
process (MDMP). The objective of HUMINT collection is to affect U.S. force’s knowledge of the
adversary.
COUNTERINTELLIGENCE AFFECTS THE ADVERSARY’S KNOWLEDGE OF FRIENDLY FORCES
4-4. The CI collection program is conducted to gather the information the commander needs to make
decisions to support the overall mission and help the commander shape the operational environment. The
commander focuses the CI effort by carefully assigning missions and clearly defining the desired results.
While using CI collection as a means of targeting, the use of single-source reporting could lead to targeting
based on tribal, regional, or cultural differences rather than threat-based targeting. In all instances, CI
reporting should be corroborated by other sources of information and/or intelligence disciplines to
determine accuracy and truthfulness before targeting by the commander.
4-5. Special agents conduct CI collection activities to support the overall mission. These operations use
techniques identified in AR 381-20. AR 381-10 contains 17 chapters that set forth policies and procedures
governing the conduct of intelligence activities by DA personnel.
21 October 2009
FM 2-22.2
4-1
FOR OFFICIAL USE ONLY
Chapter 4
COUNTERINTELLIGENCE COLLECTION PROGRAM
4-6. The Counterintelligence Collection Program
(CICP) encompasses three separate collection
categories. Each category is distinct in the sensitivity and type of information being targeted, the source of
the information, and the approval process required in the execution of the collection activity. The three
categories of collection are offensive counterintelligence operations (OFCO), defensive source operations
(DSO), and counterintelligence force protection source operations (CFSO).
OFSO activities support Army, theater, ASCCs, and local intelligence requirements, as well
as DOD, Joint Chiefs of Staff, combatant command, JTF, and multinational and national
intelligence community strategic requirements to deter, detect, and neutralize espionage.
DSO activities are only employed by units with a CI investigative and operational mission.
DSO will not be employed in combat theaters, but should be proposed through the submission
of a counterintelligence special operations concept (CISOC) and approved by the commander,
INSCOM, or the single designee.
CFSO uses source operations to collect protection, FISS and ITO collection, and threat I&W.
Except for unit training, CFSO is conducted OCONUS to satisfy the supported commander’s
information requirements. CFSO is employed on the basis of a CFSO operations plan
(OPLAN) approved by the supported commander or the C/J/G/S-2X if approval authority has
been delegated by the ASCC or JTF commander.
4-7. Within each CICP category, there are three levels of operational activity. Each level represents the
amount of control a CI special agent has over the operation and its sensitivity. The three levels are casual,
developmental, and controlled:
Casual. One-time sources or casual contacts that can provide atmospheric data, protection,
and threat I&W. The CI special agent has minimal control over the operation beyond planning
and coordination of meetings and debriefing the source regarding knowledge on areas of
interest to the CI special agent. Casual sources—
Include all CI sources established during elicitation, CI screenings, CI debriefings, and
overt liaison with military and government officials.
Are never tasked to gather or obtain information on behalf of U.S. forces; however, those
U.S. forces personnel whose travel and official duties require them to be debriefed may
be pre-briefed before their travel or activity to understand the information requirements
of the CI special agent.
Will be locally coded by the CICA/2X for future reference, to establish a reporting
history and to avoid redundant contacts with multiple intelligence elements. Liaison
contacts will never be considered for developmental and controlled operational activities.
Developmental. Sources which have been routinely contacted and can provide more detailed
information than a casual source. Developmental sources—
Include any contacts within OFCO, DSO, or CFSO who require further assessment to
validate their potential as a controlled source.
Have demonstrated positive views or sentiment towards U.S. forces.
Are never tasked to gather or obtain information on behalf of U.S. forces. Operational
interest must be obtained before transitioning a casual source to a developmental source.
Operational interest is granted after submission of basic source data (BSD) reports and
request for operational interest to the responsible 2X. Records checks are done with all
applicable agencies in the AOR; deconfliction has been conducted by the 2X/CICA; and
permission is granted by the responsible 2X.
4-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Collection Program
Will be locally coded by the CICA/2X for future reference, to establish a reporting
history and to avoid redundant contacts with multiple intelligence elements.
Controlled. Sources who have an established reporting history, are deemed credible, and who
have been vetted by CI elements. Controlled sources have also agreed to meet and cooperate
with the CI special agent for the purpose of providing information. Controlled sources—
Can be tasked to provide the CI special agent with specific information based upon their
employment, social, or geographic associations. Meetings between the CI special agent
and the controlled source will be limited to the CI special agent, the operational
management element, CICA/2X and commander unless otherwise directed by the
commander and 2X. A lead development report (LDR) must be submitted to and
approved by the responsible CICA/2X before transitioning a developmental source to a
controlled source.
May also be referred to as an asset.
COUNTERINTELLIGENCE DEBRIEFINGS, SCREENING, AND
LIAISON
4-8. A majority of the information obtained by CI special agents comes during the course of overt
collection missions. These missions include debriefings, screenings, and liaison.
COUNTERINTELLIGENCE DEBRIEFINGS
4-9. CI debriefings focus on two different types of targets. Debriefing of repatriated U.S. personnel or
SCAs and personnel who are pre-briefed and debriefed as part of an approved CI operation or project. CI
personnel assigned to combat units may also participate in intelligence debriefing of U.S. or coalition
patrols or other tactical elements that may support CCIRs. Debriefings are conducted for two reasons:
As a collection activity that supports CI or other collection reporting requirements with the
information being submitted via an IIR.
Identify potential incidents of CI interest that may be within Army CI investigative authority.
Debriefing of Special Category Absentees
4-10. These debriefings are generally conducted on persons whose intentions and existing evidence, at the
time of the offense, do not support their involvement in the commission of a national security crime or
incident of CI interest. However, due to the nature of their absence and circumstances concerning their
contact with potential FISS and ITO, they should be debriefed to identify incidents of CI interest.
Debriefings of SCA personnel returned to U.S. control will, at a minimum, focus on the following:
Circumstances surrounding their absence, including motivation and planned destination.
Persons or organization the SCA came into contact with or provided assistance to the SCA.
Visits to any foreign diplomatic or government organizations during the absence.
Travel to or through a country during the absence and all activities that occurred during the
travel.
Contact with a representative or agent of a foreign government or terrorist organization.
What type of information, either classified or unclassified, the SCA provided to any
unauthorized person.
21 October 2009
FM 2-22.2
4-3
FOR OFFICIAL USE ONLY
Chapter 4
Debriefing of Defectors
4-11. Debriefing of U.S. defectors under the authority of Army CI will be conducted upon their return to
U.S. control. Debriefings of defectors will be conducted regardless of whether or not they had access to
classified information. Debriefings of defectors will, at a minimum, focus on the following:
Circumstances and motivation surrounding the defection and their planned destination.
Persons or organization with whom the defector came into contact or provided assistance to
the defector.
Full descriptions and identifying data of foreign intelligence officers, interrogators, or other
officials with whom the defector had contact.
Source of funding during the defectors absence.
Whether or not defectors used aliases, false identifications, or concealed their identities. If so,
how and from whom was the documentation obtained?
Identification and disposition of any computer, media, hardware, military equipment and/or
technology or any classified or unclassified documents the defector had possession of or gave
to any unauthorized person.
Travel details including mode of transportation, itinerary, countries traveled to or through, and
means and documentation required to cross international borders.
Details of all interrogations or interviews the defector underwent: details of conversations,
identity and physical descriptions of interrogators, interrogation methods, defector’s
cooperation, interrogator responses to defector’s refusal to answer, cooperate, or inability to
answer a question.
Any attempts to obtain the defector’s assistance in providing information on any U.S. person
or organization, offers to employ the defector in intelligence collection or other activities, and
any arrangements to reestablish contact at a later time.
Nature and extent of any publicity or media exposure given to the defector.
Foreign government’s response to the defector’s presence in another country.
Complete details of any contacts with any other U.S. defectors to include identifying data,
names, physical descriptions, units of assignment, clearance and access to classified
information, family background, places of residence in the United States, last known location,
known or suspected cooperation with foreign intelligence or other officials, reasons for
defection, current attitude concerning their defection.
Debriefing of Repatriated U.S. Prisoners of War or Detainees
4-12. When directed by a higher authority, CI special agents may conduct intelligence debriefings of Army
military, civilian, and contract personnel who have been detained, captured, or imprisoned by foreign
military forces, foreign governments, terrorist groups, or intelligence services. These debriefings will, at a
minimum, focus on the following:
Circumstances of capture or detention.
Physical descriptions and full identifying data of foreign military, intelligence, law
enforcement and government officials, terrorists, key leaders.
Locations of command control facilities, military installations, safe houses, detention facilities
and weapons storage sites.
Description of interrogation techniques, questions asked, and information provided.
4-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Collection Program
If the POW/detainee was directed or asked to perform any activity after release and detainee’s
response.
Identity and location of the POW/detainees or defectors, their treatment, and physical and
mental condition.
Description of any sensitive or classified information, materiel, or equipment captured or
compromised.
Debriefing in Support of a Counterintelligence Project or Operation
4-13. These types of debriefings are generally conducted by operational or theater and strategic CI
elements which maintain a CAP with supported units, CI units who participate in the Tactical Intelligence
and Related Activities Program, or other CI projects or operations approved for specific purposes to
generate CI reporting and lead generation.
4-14. The target of these types of debriefings are Army personnel who conduct official or approved
unofficial travel to areas of intelligence interest or whose official business brings them into contact with
foreign officials or persons. During these types of projects or operations, the CI asset is pre-briefed on
information of CI interest and is given strict instructions on their conduct during the travels or meetings.
The CI asset is then debriefed upon their return to obtain any information of CI or general intelligence
interest.
COUNTERINTELLIGENCE SCREENING
4-15. CI screening is a systematic process for obtaining information of CI interest from a specific person or
target audience. Information of CI interest includes all SCICRs established in AR 381-20, CCIRs, or any
information that includes, but is not limited to, the plans, intentions, capabilities, methods of operation,
personalities, structure, and personal associations with any FISS and ITO entity. CI screening uses a variety
of questioning techniques to obtain information. This includes—
Interviewing methods using basic interrogatives to identify and exploit information of CI
interest.
A structured debriefing format utilizing a prepared question list when the source has
knowledge of a specific topical interest.
Elicitation utilizing a discreet form of questioning which does not let the source know the
specific area of interest of the CI special agent.
4-16. Each of these methods can be used or combined dependent upon the situation. For example, in an
LEP screening process, the CI special agent can prepare specific questions that the source may have
knowledge of. During the screening interview, if the source provides a lead outside the scope of the
debriefing questioning list but of CI interest, the CI special agent can transition to an interview format to
gain all the additional information the source may have on the subject. If the CI special agent believes the
source may have knowledge of other types of information, the CI special agent can probe for other
knowledgeable areas using elicitation techniques.
Note. CI screening normally is non-confrontational unless the source initiates a hostile
environment and forces the CI special agent to maintain control through the exercise of the CI
special agent’s official authority. CI screening should not be characterized or executed using any
of the interrogation approaches defined in FM 2-22.3.
4-17. CI elements should designate CI screening as high priority collection activity which can produce
significant intelligence reporting, identify persons as potential controlled sources, cue other intelligence
assets, and generate leads for potential investigative activities. CI screening is the primary tool used to vet
LEPs for suitability and potential risks to U.S. personnel while employed by U.S. forces. It is also used by
CI personnel to canvass local population centers, traffic control points (TCPs), and refugee or displaced
21 October 2009
FM 2-22.2
4-5
FOR OFFICIAL USE ONLY
Chapter 4
persons migration for information of CI interest. CI screening can also be used to identify potential sources
for the CFSO and DSO programs.
4-18. During the CI screening program the sources may be screened to determine their potential to answer
collection requirements or to identify individuals who match a predetermined source profile. Personnel who
cannot specifically answer CI requirements but may be able to answer other collection requirements can be
identified and the lead passed to a HUMINT collection team (HCT) via a Notice of Intelligence Potential or
other localized procedures identified in unit SOPs.
4-19. Successful CI screening requires dedicated resources and support from the chain of command. Pre
operational planning should include dedicating specific CI assets to be the focal point for coordinating and
conducting all CI screening. All necessary equipment, facilities, and support personnel should also be
identified in OPLANs and coordinated for in advance of executing the CI screening program. For example:
Equipment includes biometric systems used to identify and track LEPs, third-country
nationals or original screened individuals after the screening. This allows CI special agents
and/or intelligence analysts to potentially identify persons associated with events or
intelligence reporting if they have been previously screened.
Facilities include dedicated space that offers privacy and security during the screening
process. CI screenings should not afford those personnel waiting to be screened the
opportunity to hear previous screenings. Lack of privacy allows a potential infiltrator or FISS
and ITO agent the opportunity to hear ongoing screening interviews and formulate plausible
answers and information to evade further scrutiny by CI elements. Pre-screening security
checks of all sources should be conducted to identify potential weapons. In hostile or non-
secure environments, coordination for security forces should be conducted to ensure the safety
of U.S. forces, and the screening audience.
Interpreters should be identified in the pre-operational planning process. This should include
what language and dialects will be required and the number of interpreters based upon
mission requirements. Additionally, any specific security clearance requirements should be
included in the request and planning documents.
Coordination should be included in all OPLANs to delineate responsibilities, identify
supporting organizations and gain command approval. OPLANs should include the CI
screening mission in the conduct of patrols, cordon and search and TCPs. This provides the CI
element the leverage to conduct the mission when local units are apprehensive about CI
personnel operating outside the installation or base camp.
LEP screening should include coordination with the unit protection officer, supporting
MP units, installation security elements, and contracting office. CI Screening of LEPs is
not an employment activity, but rather a decision point to assist the contracting office and
the commander to adjudicate the suitability of a host nation, TCN or other indigenous
person to work for U.S. forces.
If the CI element identifies that the person may be a protection risk based on the person’s
background, activities, or associations of known FISS and ITO entities, the person should
be identified as a protection risk. It is commanders’ responsibility to determine if they are
willing to accept that risk.
Counterintelligence Support to Joint Interrogation and Debriefing Centers
4-20. During combat and other contingency operations, CI normally will be included in the staffing and
support requirements for JIDC operations. While the priority for intelligence collection during JIDC
operations is focused on CCIRs and other HUMINT-specific collection requirements, JDIC operations
offer an excellent opportunity for CI collection. Enemy prisoners of war (EPWs) and detainees held in
JDIC facilities will include FISS and ITO personnel who can answer specific CI requirements including,
4-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Collection Program
but not limited to, the plans, intentions, capabilities, methods of operation, personalities, structure, and
personal associations of FISS and ITO elements targeting U.S. forces.
4-21. CI Special agents supporting JIDC operations will normally sensitize or provide detailed CI
requirements to the JDIC operations element. All interrogation personnel will use these requirements to
identify personnel who have information of CI interest. When an EPW or detainee is identified as having
information of CI interest, the CI special agent will screen the identified person separately from HUMINT
screening and interrogation activities. While there is no prohibition of CI special agents being present
during interrogations conducted by trained and certified interrogators, generally the limited numbers of CI
resources do not permit this approach.
Locally Employed Person Screening
4-22. LEP screening is conducted primarily to identify individuals who may be a security risk. It can,
however, be used as a means to obtain intelligence information or to identify personnel with placement and
access to be used for source operations. LEP screening should be conducted as a precondition to
employment and repeated periodically throughout the course of employment. It should also be conducted
whenever a local employee is promoted or placed in a new job position.
4-23. CI Special agents should coordinate with security and hiring authorities to have CI screenings
conducted as part of the normal hiring process before granting unescorted access to the installation. LEP
screening must be conducted in a secure environment and out of the hearing and sight of other employees.
While conducting the screening the CI special agent should pay special attention to any indicators of
deception. During the screening process, the use of an interpreter is paramount to maintain accuracy in
recording the information obtained from the LEP. Formal written reports of the screening must be
maintained.
4-24. During LEP screenings, several factors must be determined before acceptance for employment.
Following the screening, the CI special agent must assess—
The suitability of the person in relation to the job to be performed. Is the individual attempting
to access an area above the individual’s level of knowledge, skills, and experiences?
Whether the individual has any suspected FISS and ITO associations?
What family associations the person has that could lead to possible hostage situations?
If the person has outside placement and access that could be exploited for potential use as a CI
source?
If the individual has any special skills or languages that may be leveraged to support ongoing
collection missions?
Note. If a person has potential FISS and ITO connections, it does not automatically mean this
person cannot be used as a CI source or exploited by CI units or OGAs. If a person is willing to
cooperate with these units or agencies or is susceptible to control and direction, then
commanders should give consideration to these activities. Persons with potential FISS and ITO
connections could provide information pertinent to ongoing investigations and operations such
as the location of any hostages, personnel behind recent or future attacks, locations of safe
houses or houses used to construct improvised explosive devices (IEDs).
4-25. If an LEP is reported or found through background checks to have derogatory information, a CI
screening should be conducted immediately. The CI special agent should attempt to determine the severity
of the derogatory information and to what extent this information may be exploited. These derogatory
initiated screenings should be recorded electronically and maintained for the protection of the agent. The
information derived because of this screening should be reported to the command and the command of
adjacent units or camps and maintained in local records to preclude the future rehiring of the individual.
21 October 2009
FM 2-22.2
4-7
FOR OFFICIAL USE ONLY
Chapter 4
COUNTERINTELLIGENCE LIAISON
4-26. CI special agents conduct liaison to obtain information, gain assistance, and coordinate or procure
material. The nature of CI activities and the many legal restrictions imposed, including SOFAs or other
agreements, make the collection of intelligence information during peacetime largely dependent on
effective liaison.
4-27. CI special agents use liaison to obtain information and assistance and to exchange views necessary to
understand our liaison counterparts. During transition from increased tension to open hostilities, the liaison
emphasis shifts to support the combat commander.
4-28. CI special agents must establish liaison with appropriate agencies before the outbreak of hostilities.
Information and cooperation gained during this period can have a major impact on the effectiveness of both
intelligence and combat operations. The use of interpreters occurs often in liaison, as foreign language
proficiency is not a requirement for the CI special agent.
4-29. Liaison with appropriate U.S., HN, and allied military and civilian agencies is fundamental to the
success of CI operations and intelligence support to commanders. In many cases, full-time liaison officers
(LNOs) or sections are necessary to maintain regular contact with appropriate organizations and
individuals. In addition to national agencies, numerous local agencies and organizations also provide
assistance and information.
4-30. A basic tenet of liaison is quid pro quo (something for something) exchange. While the CI special
agent sometimes encounters individuals who cooperate due to a sense of duty or for unknown reasons of
their own, an exchange of information, services, material, or other assistance normally is part of the
interaction. The nature of this exchange varies widely, depending on location, culture, and personalities
involved. The spectrum of liaison tasks ranges from establishing rapport with local record custodians to
coordinating sensitive multinational operations at the national level of allied nations. Commanders with CI
assets involved in liaison should provide the following:
Liaison objectives, which are types of information to be collected, methods of operations
unique to the area, and command objectives to be accomplished.
Source coding procedures.
Report numbering system.
Procedures for requesting sanitized trading material information.
Authority under which the specific liaison program is conducted and guidelines for joint and
multinational operations.
SOPs that cover related aspects, such as funding, IIR procedures, source administration, and
AORs and jurisdiction.
4-31. Operational benefits derived from CI liaison include—
Establishing working relationships with various commands, agencies, or governments.
Arranging for and coordinating joint and multinational multilateral investigations and
operations.
Exchanging operational information and intelligence within policy guidelines.
Facilitating access to records and personnel of other agencies not otherwise available. This
includes criminal and subversive files controlled by agencies other than MI. Additionally,
access includes gaining information via other agencies when cultural or ethnic constraints
preclude effective use of U.S. personnel.
Acquiring information to satisfy U.S. intelligence collection requirements.
4-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Collection Program
Limitations on liaison activities. These limitations include—
Prohibitions against collection of specific types of information or against contacting
certain types of individuals or organizations.
Memorandums of understanding with other echelons delineating liaison responsibilities.
Delineation of areas of responsibility of subordinate elements.
Director of Central Intelligence Directives (DCID).
Type, method, and channels of reporting information obtained from liaison activities.
Use of ICF.
4-32. OCONUS, CI liaison provides support to a number of diverse U.S. Government agencies. This
support ranges from conducting tactical operations to fulfilling national level requirements generated by
non-DOD federal agencies. Individuals contacted may include private individuals who can provide
assistance, information, and introductions to the heads of national level host country intelligence and
security agencies.
4-33. In CONUS, CI liaison provides assistance in operations and investigations, precludes duplication of
effort, and frequently provides access to information not available through other CI channels. Agents
should maintain a POC roster or list of agencies regularly contacted. Agencies normally contacted on a
local basis include—
Military G-2, S-2, and personnel sections of units in the area.
G-9 and S-9 representatives.
MP and PMO.
Army CIDC for information relating to incidents that overlap jurisdictions.
Civilian agencies such as state, county, or local police departments; state crime commissions;
state attorney general offices; and local courts.
Local offices of Federal agencies such as the FBI, Immigration and Naturalization Service,
Border Patrol, Drug Enforcement Agency, and similar security agencies.
Appropriate DOD activities such as Naval Criminal Investigation Service and Office of
Special Investigations (OSI) of the U.S. Air Force.
4-34. The DA G-2 is responsible for liaison with the national headquarters of the intelligence community
and other agencies for policy matters and commitments. CG, INSCOM, is the coordinating authority for
liaison with the FBI and other Federal agencies for coordinating operational and investigative matters.
4-35. Many countries exercise a greater degree of internal security and maintain greater control over their
civilian population. For this reason, the national level intelligence and security agencies frequently extend
further into the local community in other countries than they do in the United States. Security agencies may
be distinctly separate from other intelligence organizations, and police may have intelligence and CI
missions in addition to law enforcement duties. In some countries, the police, and usually another civilian
agency, perform the equivalent mission of the FBI in the U.S. This other civilian agency frequently has a
foreign intelligence mission in addition to domestic duties. CI special agents must be familiar with the
mission, organization, chain of command, and capabilities of all applicable organizations they encounter.
4-36. Adapting to local culture is sometimes a problem encountered by the CI special agent involved in
liaison. Each culture has its own peculiar customs and courtesies. While they may seem insignificant to
U.S. personnel, these customs and courtesies are important to local nationals. Understanding a country’s
culture and adhering to its etiquette are very important. What is socially acceptable behavior in the United
States could very well be offensive in other cultures. Knowing the local culture helps the CI special agent
understand the behavior and mentality of a liaison source. It also helps in gaining rapport and avoiding
embarrassment for both the liaison source and the CI special agent. In many cultures, embarrassing a guest
21 October 2009
FM 2-22.2
4-9
FOR OFFICIAL USE ONLY
Chapter 4
causes “loss of face.” This inevitably undermines rapport and may cause irreparable harm to the liaison
effort.
4-37. The CI special agent also must understand the capabilities of agencies other than our own.
Knowledge of the liaison source’s capabilities in terms of mission, human resources, equipment, and
training is essential before requesting information or services. Information exchanged during the conduct of
liaison is frequently sanitized. Information concerning sources, job specialty, and other sensitive material
relating to the originator’s operations may be deleted. This practice is common to every intelligence
organization worldwide and should be taken into account when analyzing information provided by another
agency.
4-38. The CI special agent may have to deal with individuals who have had no previous contact with U.S.
agencies and who are unsure of how to deal with a U.S. intelligence agent. CI special agents must
remember that to the liaison source, they represent the people, culture, and government of the United
States. The liaison source assumes the behavior of the CI special agent to be typical of all Americans.
4-39. The CI special agent may have to adapt to unfamiliar food, drink, etiquette, social custom, and
protocol. While some societies make adjustments for an “ignorant foreigner,” many expect an official
visitor to know local customs. The CI special agent must make an effort to avoid culture shock when
confronted by situations completely alien to the agent’s background. The CI special agent also must be able
to adjust to a wide variety of personalities.
4-40. In some countries, government corruption is a way of life. The CI special agent must be familiar with
these customs if indications of bribery, extortion, petty theft of government goods and funds, or similar
incidents are discovered in the course of liaison. When corruption is discovered, request command
guidance before continuing liaison with the particular individual or organization. Regardless of the
circumstances, exercise caution and professionalism when encountering corruption.
4-41. The CI special agent must know any known or hidden agendas of individuals or organizations.
Occasionally, due to the close professional relationship developed during liaison, a source may wish to
present a personal gift. If possible, the CI special agent should diplomatically refuse the gift. If that is not
possible, because of rapport, accept the gift. Any gifts received must be reported in accordance with AR 1
100. The gift can be kept only if a request is submitted and receives approval.
4-42. Records and reports are essential to maintain continuity of liaison operations and must contain
information on agencies contacted. It is preferable to have a file on each organization or individual
contacted to provide a quick reference concerning location, organization, mission, and similar liaison-
related information. Limit information to name, position, organization, and contact procedures when the
liaison contact is a U.S. person. The CI special agent should obtain consent from the U.S. liaison contact to
maintain general re-contact data for future reference. For liaison contacts with foreign persons, formal
source administrative, operational, and information reporting procedures are used.
CONTROL OF SOURCE INFORMATION
4-43. All collection operations require keeping records on CI military sources. This holds true for liaison
contacts as well as casual or recruited sources. Data on CI military sources will be entered into appropriate
echelon source registries and, in the future, the planned Integrated Defense Source Registry (IDSR). This
type of information, including biographic, motivational, and communications procedures, are maintained in
CI channels.
4-44. Control of source information will not preclude passage of this type of information from one echelon
to another for necessary approvals. In handling source information, strictly adhere to the “need-to-know”
policy. The number of persons knowing about source information must be kept to a minimum. (See
AR 381-20 for more information on the control of source information and CI collection and reporting
activities.)
4-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
////////////////////////////////////////// |
||
|
|
|