FM 2-22.2 (FM 34-60) Counterintelligence (October 2009) - page 2

 

  Index      Manuals     FM 2-22.2 (FM 34-60) Counterintelligence (October 2009)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..      1      2      3      ..

 

 

 

FM 2-22.2 (FM 34-60) Counterintelligence (October 2009) - page 2

 

 

Counterintelligence Collection Program
UNIT COUNTERINTELLIGENCE REQUIREMENTS MANAGEMENT
4-45. Unit requirements managers will—
Develop ISR synchronization requirements plans to satisfy the CI collection requirements of
the supported commander.
Plan and oversee the CI collection operations designed to support current and future military
operations.
Ensure that CI collection requirements are effectively communicated to those conducting
collection or source operations.
Track, monitor, and evaluate the effectiveness of the collection mission and provide statistical
data on collection sources, activities, and reporting as required.
4-46. Collection planning is an important part of the management of CI collection operations because it
determines how a collection requirement will be satisfied. Collection planning is essential to maximizing
resources, ensuring responsiveness, properly focusing collectors, and minimizing risk.
4-47. The Army CI requirements manager will ensure that collection elements with the appropriate
capability, resources, and location are tasked to satisfy levied requirements. Providing input to the ISR
synchronization requirements plan requires knowledge of FISS and ITO, the availability of resources for
collection, collection priorities, and geographic areas where the collection activity will be accomplished.
4-48. ISR plans should be modified as frequently as dictated by world events, military operations, new
requirements, and modifications to existing requirements due to intelligence gaps. CI collection to support
ASCC or joint operations normally will be documented in the CI appendix to an OPLAN and will be
executed under an OPORD. The typical CI collection plan may be organized including the following
elements:
Mission. Identity of CI collection requirements to support a mission, operation, geographic
area, or command.
Concept of operation. Identity of collection element; C2 structure; collection focus.
Coordination. ATCICA, 2X, chief of station, chief of mission, and OGAs.
Operational considerations. Source restrictions, OPSEC measures.
Administrative support requirements. Reporting system, communications architecture,
operational reporting requirements.
Operational expenses. Projected ICF expenditures, expense codes, incentives, appointment
of alternate custodians, accountability procedures.
4-49. ISR plans should assess the capabilities of the CI collection element by addressing the following
issues:
Capability. The capability of the collection element to satisfy the requirement and the
existence of a source which can answer the requirement.
Access. Whether the collection element has the ability to access the source.
Resources. The resources available to the collection element to accomplish the required
collection and the identity of any additional resources.
Source development potential. The capability of the collection element to develop a source
where none exists.
Priorities. The relative priority of new requirements compared to those already levied.
21 October 2009
FM 2-22.2
4-11
FOR OFFICIAL USE ONLY
Chapter 4
STANDING COUNTERINTELLIGENCE COLLECTION
REQUIREMENTS
4-50. SCICRs serve as the basis for CI collection planning and implementation. SCICRs are promulgated
by DIA J-2 CI based on general collection themes identified by the intelligence community and coordinated
with CI analysts throughout DOD. All Army CI elements, within the limits of their mission, assigned
priorities, resources, location, and collection capability, have an obligation to collect and report the
following categories of information:
Foreign intelligence activities.
Technology transfer.
WMD.
Transnational terrorist groups.
Cyber espionage.
COUNTERINTELLIGENCE SUPPORT TO THREAT AND
VULNERABILITY ASSESSMENTS
4-51. TAs and VAs are studies conducted by CI personnel to provide a supported command or agency a
picture of the FISS and ITO threat or the unit or agency’s susceptibility to FISS and ITO intelligence
collection. TAs are focused on known or suspected FISS and ITO collection capabilities in a specific
geographic area and can be used for educational and security planning purposes. TAs are standalone
documents. VAs are conducted on a specific target
(for example, command, agency, installation,
subordinate element, headquarters, operation, facility, or program) and are tailored to the needs of each
requestor. The objective of the VA is to provide a supported command or agency a realistic tool with which
to evaluate internal protection or security programs, and to provide a decisionmaking aid for the
enhancement of these programs. VAs must include a TA.
4-52. TAs include—
General political, social, and economic demographics for the target area that may be exploited
by a FISS and ITO element to conduct operations.
Known or suspected associations between FISS and ITO elements and governmental agencies
or personnel who may indicate support, direction, or funding of FISS and ITO elements.
Governmental and civilian populace attitudes (positive or negative) towards U.S. policies or
culture.
Specifics on known or suspected FISS and ITO elements including—
Identities of known members.
Identities of leadership members.
Capabilities, plans and intentions.
Methods of operation.
Previous acts, situations, or events for which the FISS and ITO has been responsible, has
taken credit, or has been associated.
4-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Collection Program
4-53. VAs include—
Evaluating adversarial intelligence multidiscipline intelligence collection capabilities,
collection and other activities, and CCIRs.
Identifying friendly activity patterns (physical and electronic), friendly physical and electronic
signatures, and resulting profiles.
Monitoring or collecting communication and electronics (C&E) transmissions to aid in VAs,
and providing a more realistic and stable basis from which to recommend countermeasures.
Identifying vulnerabilities based upon analysis of collected information and recommendations
of countermeasures.
Analyzing the effectiveness of implemented countermeasures.
21 October 2009
FM 2-22.2
4-13
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 5
Analysis, Tools, and Production
Intelligence analysis is the cognitive process of receiving and interpreting
information from every available asset, and integrating that information into the
overall view of the operational environment. Analysis requires organization of
information into categories and identifiable patterns
(relationships among the
categories), based on the information collection requirements. Intelligence analysis is
the art of knowing and understanding the enemy’s doctrine, culture, weapon
capabilities, TTP, religion, beliefs, and idiosyncrasies. In addition, an intelligence analyst
is fully aware and knowledgeable of the limitations and capabilities of U.S. forces.
GENERAL
5-1. In order for commanders to effectively complete the operations process, they must have information and
intelligence. The intelligence process satisfies this need by providing the commander with intelligence regarding
the threat, operational environment, and the situation. Four steps constitute the intelligence process: plan,
prepare, collect, and produce. Additionally, there are four activities that occur across the four steps of the
intelligence process: generate intelligence knowledge, analyze, assess, and disseminate. The four continuing
activities plus the commander’s input drive, shape, and develop the process. They can occur at any time during
the process. The intelligence process steps and intelligence continuing activities are applied to CI to ensure
synchronization with the all-source intelligence mission and collection. (See figure 5-1.)
Figure 5-1. Intelligence process
21 October 2009
FM 2-22.2
5-1
FOR OFFICIAL USE ONLY
Chapter 5
5-2. Intelligence analysis also involves separating useful information from extraneous information, using
experience and reasoning, and reaching a conclusion based on fact and/or sound judgment. The conclusion
is based on the intelligence analyst’s experience, skill, and knowledge of the various intelligence
disciplines; ISR; an understanding of the operational environment; CCIRs; and an in-depth understanding
of the adversary’s behavior patterns. The intelligence analyst’s knowledge must encompass many things;
for example, the analyst—
Interprets the intelligence reached throughout the intelligence analysis process.
Realize that if not disseminated and exploited, the intelligence becomes useless.
Knows friendly organizations, systems, doctrine, and tactics as well as those of coalition
partners.
5-3. Analysis is not proprietary to the trained intelligence analyst. CI special agents, commanders, and
leaders must conduct analysis to provide input into the intelligence process and to help drive the operations
of all CI elements. CI analysis, tools, and production are essential elements in supporting CI activities;
investigations, collection, and technical services and support. CI analysis of the FISS and ITO collection
threat is critical to the establishment of protection measures by commanders at all levels.
5-4. Intelligence and threat analysis also provides focus for the implementation of CI support to the
combatant command during military operations. CI analysis supports operational planning and provides
direction to CI activities. CI analysis conducted in the 2X CI analytical cell concentrates on satisfying local
PIRs, and on redirecting CI collection efforts. (See TC 2-33.4 for more information on intelligence
analysis.)
5-5. The following are some areas that may be addressed in conducting CI analysis:
Multidiscipline FISS and ITO operations.
Activities and disinformation or deception operations.
Illegal sale, transfer, or acquisition of DOD-controlled technologies, including WMDs.
Terrorism, sabotage, unauthorized penetration or degradation of computer systems and related
security threats.
5-6. CI analysis involves the actions taken to evaluate the information provided by all CI sources at a
given echelon to determine interrelationships, trends, and contextual meaning. While called
“single
discipline,” the analyst reviews and incorporates, as necessary, information from other disciplines and all-
source analysis to provide a contextual basis for the CI analysis. Single-discipline CI analysis is conducted
primarily by the analysis and control element (ACE). CICAs and CI OMTs also conduct analysis to a lesser
degree, based on the information from CI sources at their echelon.
5-7. Analysis does more than simply restate facts; it puts information into context as it applies or affects
the consumer. CI analysis uses the analytical principles of processing data inputs, factoring different
variables, and developing a hypothesis that is the foundation for predictive analysis. This in turn is used
during the MDMP, COA development, operational planning and the targeting process. The analyst
formulates a hypothesis based on available data, assesses the situation, and explains what the data means in
logical terms that the user can understand. There are two basic thought processes used mutually by analysts
to study problems and reach conclusions: induction and deduction.
5-8. Induction is the process of formulating hypotheses on the basis of observation or other evidence. It
can best be characterized as a process of discovery when the analyst is able to establish a relationship
between events under observation or study. Induction, or plausible reasoning, normally precedes deduction
and is the type of reasoning analysts are required to perform most frequently.
5-9. Deduction is the process of reasoning from general rules to particular cases. The analyst must draw
out, or analyze, the premises to form a conclusion. Deductive reasoning is sometimes referred to as
demonstrative reasoning because it is used to demonstrate the truth or validity of a conclusion based on
certain premises.
5-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
5-10. CI analysis assists the G-2 in the identification and characterization of the human component of FISS
and ITO intelligence collection operations and its effects on friendly and enemy operations. It carefully
examines the various component groups and their predicted reaction to friendly force operations.
5-11. The CI analytical effort assists the overall all-source process by helping to identify specific actions
and motivational factors that should strengthen the local population’s support of the United States or at
least weaken its support of the enemy and to provide information on the transient (refugees, displaced
persons, third-country nationals) population and its effects on friendly and enemy operations. In addition to
the above, analysts—
Closely examine the current and potential threat to identify all factors, such as morale,
motivation, training, and beliefs that would both positively and negatively affect adversary
capabilities.
Identify formal and informal leaders of hostile, neutral, and friendly groups and how their
influence is likely to affect operations.
Develop overlays, databases, and matrices, as required, to support intelligence preparation of
the battlefield (IPB). These overlays may represent a wide variety of intelligence issues,
including operational environment infrastructure
(for example, electrical power grid),
population density; ethnic, religious, or tribal affiliation; and no-strike or collateral damage.
Provide their products to the C/J/G/S-2, the all-source analysts and CI analysts of the ACE,
the HOC, the C/J/G/S-2X, and CI collection units as required.
ANOMALIES, SIGNATURES, AND PATTERNS
5-12. A critical component of CI analysis is the incorporation of different anomalies, signatures, or patterns
that may be indicative of FISS and ITO targeting of U.S. forces.
Anomalies are irregular or unusual activities that may cue the analyst on the existence of FISS
and ITO activity. Anomalies may consist of repeated but subtle tests of systemic or security
procedures (for example, an LEP who attempts to work in areas for which they are not
cleared).
Signatures are indicators of potential FISS and ITO methods of operations including static
surveillance of U.S. forces installations, elicitation of LEPs or Service members.
Patterns are repeated incidents that may be similar in nature or dissimilar events that occur in
a specific location or time span that may indicate potential FISS and ITO targeting or
information exploitation.
5-13. Analysis of anomalies, signatures, and patterns can allow analysis to help drive CI activities and
develop pro-active operations to negate, mitigate, degrade, or exploit FISS and ITO collection activities.
COUNTERINTELLIGENCE THREAT ANALYSIS
5-14. CI analytical products provide information to support commanders, their staff, and unit. CI analysis
is an integral part of CI collection. CI analysis occurs throughout the CI collection process but can be
divided into four primary categories: analytical support to operational planning and targeting, operational
analysis and assessment, source analysis, and single-discipline CI analysis and production.
5-15. The CI analyst uses the tools and skills identified in this chapter and in TC 2-33.4. The intelligence
analyst focuses on “how we see the opposition” and “how the opposition sees us.” The CI analyst must also
focus on how to counter the opposition’s collection efforts. Where the intelligence analyst is a subject
matter expert on the opposition, the CI analyst, in addition to having an in-depth understanding and
expertise on foreign intelligence collection capabilities, must have a good working knowledge of our own
force. The CI analysis assets of the ACE must be fully integrated into the DCSG-A. They require access to
21 October 2009
FM 2-22.2
5-3
FOR OFFICIAL USE ONLY
Chapter 5
all-source data that is applicable to CI analytical products. The principles and techniques identified in TC 2
33.4 apply equally in CI analysis.
5-16. CI analysis and production is focused on FISS and ITO threat collection activities that include
HUMINT, SIGINT, geospatial intelligence (GEOINT), and TECHINT. The focus of the CI analysis of
each of these disciplines is not only on the threat entity or entities operating in the area but also on the
intelligence products most likely being developed through their collection activities. While analysis is
purely a cognitive process, the ability to organize and manipulate data to maximize the efficiency of the
analytical process should be fully automated (data storage, sorting, and filing). The process of countering
each of these disciplines involves—
Threat assessment.
Vulnerability assessment.
Development of countermeasures options.
Countermeasures implementation.
Countermeasures evaluation.
COUNTER-HUMINT ANALYSIS
5-17. The CI analytical effort should attempt to identify the threat HUMINT cycle (collection, analysis,
production, targeting) and threat personalities. To produce a complete product, the CI analyst may need
access to considerable data and require significant resources. The CI analyst will require collection in the
areas of subversion, espionage, sabotage, terrorism, and HUMINT supported activities.
5-18. Collection of friendly data is also required to substantiate analytical findings and recommendations.
Consistent with time, mission, and availability of resources, efforts must be made to provide an analytical
product that identifies threat collection efforts.
COUNTER-SIGINT ANALYSIS
5-19. The CI analyst requires SIGINT data collection to support VA and countermeasures evaluation.
Validation of vulnerabilities (data collectable by threat SIGINT) and the effectiveness of implemented
countermeasures (a before-and-after comparison of electromagnetic spectrum and data) will be nearly
impossible without active and timely collection as a prerequisite to analysis. The CI analyst requires a
comprehensive, relational database consisting of threat SIGINT systems, installations, methodology, and
associated SIGINT cycle data.
5-20. In addition, all friendly C&E systems and user unit identification must be readily available, as well as
a library of countermeasures and a history of those previously implemented countermeasures and results.
Ideally, the CI analyst should, at any given time, be able to forecast threat SIGINT activity. However, such
predictions must rely upon other CI, HUMINT, SIGINT, and GEOINT collection as well as access to
adjacent friendly unit CI files. Information on threat SIGINT must be readily accessible from intelligence
elements higher as well as lower in echelon than the supported command.
COUNTER-GEOINT ANALYSIS
5-21. This type of analysis requires the analyst to have an in-depth knowledge of the supported
commander’s plans, intentions, and proposed AO as far in advance of commitment as possible. The analyst
must have access to all available data and intelligence on threat GEOINT methodology, systems, and
processing as well as in-depth information on commercial satellite systems and their availability to the
foreign consumer.
5-22. The analyst attempts to define the specific imagery platform deployed against U.S. forces and the
cycle involved (time based) from time of imaging through analysis to targeting. Knowledge of threat
intelligence cycle to targeting is critical in developing countermeasures to defeat, destroy, or deceive threat
5-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
GEOINT. For ground-based, HUMINT-oriented GEOINT
(video cassette recorders, digital video
recorders), cellular phone cameras, news media organizations) the CI team will be required to collect the
data for the analyst.
5-23. This type of information cannot be reasonably considered to exist in any current database. However,
collection to support CI (over-flights of friendly forces by friendly forces) during identified, critical, and
GEOINT vulnerable times will validate other CI findings and justify countermeasures. This “collection”
will be of immense value to the analyst and the supported commander in determining what, if anything,
threat imagery has captured. It must be done within the established or accepted threat activity cycle.
COUNTER-TECHINT ANALYSIS
5-24. The CI analyst requires TECHINT data collection to support VA and countermeasures evaluation.
Validation of vulnerabilities (data collectable by threat TECHINT) and the effectiveness of implemented
countermeasures (a before-and-after comparison of electromagnetic signatures and data) will be nearly
impossible without active and timely collection as a prerequisite to analysis. The CI analyst requires a
comprehensive, relational database consisting of threat TECHINT systems, capabilities, and methodology.
5-25. Ideally, the CI analyst should be able to forecast threat TECHINT activity; however, such predictions
must rely upon other CI, HUMINT, SIGINT, and GEOINT collection. Information on threat TECHINT
must be readily accessible from specialized intelligence elements to assist in providing comprehensive
assessment to the supported command.
COUNTERINTELLIGENCE SUPPORT TO INTELLIGENCE
PREPARATION OF THE BATTLEFIELD
5-26. CI supports IPB by providing demographic information, FISS and ITO threat data that impacts the
friendly force commander’s MDMP. CI input to the IPB process also assists in the targeting process and
can result in cross-cueing of other assets to satisfy the CCIRs.
OPERATIONAL PLANNING
5-27. The effectiveness of CI operations depends largely on the planning that precedes the operation.
Operational planning includes establishing the role of CI in the operation; integration with combat forces;
establishing operational and intelligence reporting architectures; and identifying CI support to assist in
establishing information dominance through the execution of CI functions and the denial of information to
the adversary. Early in the planning process, the CICA and 2X directs the efforts to obtain information on
the FISS and ITO intelligence, sabotage, terrorism, and subversion capabilities.
5-28. This information allows the development of OPSEC, AT and protection measures to protect the
tactical advantage and prevent surprise of U.S. forces during predeployment, transit, and engagement.
During predeployment planning, the CICA and 2X should develop as much information as possible
concerning the FISS and ITO threat to U.S. forces. This allows the CICA and 2X to develop a CI targets
list. The CI targets list identifies those personalities, organizations, and installations that must be seized,
exploited, or protected to provide information dominance in the operational environment. Once on the
ground in the theater AO, the CI targets list will assist in the immediate targeting of FISS and ITO
capabilities to negate, mitigate, or degrade the adversary’s ability to collect on U.S. forces; develop
countermeasures; and plan and target U.S. forces for attack or information exploitation.
PERSONALITIES
5-29. These are persons who are a threat to security, whose intentions are unknown, or who can assist the
intelligence and CI efforts of the command. Personalities are grouped into these three categories. For ease
in identification, a color code indicates the category. Colors currently in use are black, white, and gray,
respectively.
21 October 2009
FM 2-22.2
5-5
FOR OFFICIAL USE ONLY
Chapter 5
Black List
5-30. The black list is an official CI listing of actual, suspected, or potential enemy collaborators,
sympathizers, intelligence agents, and other persons whose presence threatens the security of the friendly
forces (see JP 1-02). Black list includes—
Known or suspected enemy or hostile espionage agents, saboteurs, terrorists, political figures,
and subversive individuals.
Known or suspected leaders and members of hostile paramilitary, partisan, or guerrilla
groups.
Political leaders known or suspected to be hostile to the military and U.S. political objectives
or an allied nation.
Known or suspected officials of enemy governments whose presence in the theater of
operations poses a security threat to U.S. forces.
Known or suspected enemy collaborators and sympathizers whose presence in the theater of
operations poses a security threat to U.S. forces.
Known enemy military or civilian personnel who have engaged in intelligence, CI, security,
police, or political indoctrination activities among troops or civilians.
Other personalities indicated by the G-2 as automatic arrestees. Included in this category may
be local political personalities, police chiefs, and heads of significant municipal and national
departments or agencies, and tribal or clan leaders.
Gray List
5-31. The gray list contains the identities and locations of those personalities whose inclinations and
attitudes toward the political and military objectives of the U.S. cannot be determined based upon current
intelligence. Regardless of their political inclinations or attitudes, personalities may be gray listed when
they are known to possess information or particular skills required by U.S. forces. These people are the
“unknowns.” They may be individuals whose political motivations require further exploration before they
can be used effectively by U.S. forces. Examples of individuals who may be included in this category are—
Potential or actual defectors from the hostile cause whose bona fides have not been
established.
Individuals who have resisted, or are believed to have resisted, the enemy government and
who may be willing to cooperate with U.S. forces, but whose bona fides have not been
established.
Scientists and technicians suspected of having been engaged against their will in enemy
research projects of high technology programs.
White List
5-32. The white list contains the identities and locations of individuals who have been identified as being
of intelligence or CI interest and are expected to be able to provide information or assistance in existing or
new intelligence areas. They are usually in accordance with, or favorably inclined toward, U.S. policies.
Their contributions are based on a voluntary and cooperative attitude. Decisions to place individuals on the
white list may be affected by the combat situation; critical need for specialists in scientific fields, and such
theater intelligence needs as may be indicated from time to time. Examples of individuals who may be
included in this category are—
Former political leaders of a hostile state who were deposed by the hostile political leaders.
Intelligence agents employed by U.S. or allied intelligence agencies.
5-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
Key civilians in areas of scientific research, who may include faculty members of universities
and staffs of industrial or national research facilities, whose bona fides have been established.
Leaders of religious groups and other humanitarian groups.
Other persons who can materially and significantly aid the U.S. political, scientific, and
military objectives and whose bona fides have been established.
INSTALLATIONS
5-33. Installations on the CI targets list are any building, office, or field position that may contain
information or material of CI interest or which may pose a threat to the security of the command.
Installations of CI interest include—
Those that are or were occupied by enemy espionage, sabotage, or subversive agencies or
police organizations, including prisons and detention centers.
Those occupied by enemy intelligence, CI, security, or paramilitary organizations including
operational bases, schools, and training sites.
Enemy communication media and signal centers.
Nuclear research centers and chemical laboratories.
Enemy political administrative headquarters.
Public utilities and other installations to be taken under early control to prevent sabotage.
Production facilities, supply areas, and other installations to be taken under control to prevent
support to hostile guerrilla and partisan elements.
Embassies and consulates of hostile governments.
ORGANIZATIONS
5-34. Any group that is a potential threat to the security of the friendly force must be neutralized, rendered
ineffective, or exploited for a greater good. Groups or organizations that are of concern to CI during tactical
operations include—
FISS and ITO organizations.
National and local political parties or groups known to have aims, beliefs, or ideologies
contrary or in opposition to those of the United States.
Paramilitary organizations, including students, police, military veterans, and former
combatant groups known to be hostile to the United States.
Hostile sponsored organizations or groups whose objectives are to create dissension and
spread unrest among the civilian population in the AO.
TARGETING PROCESS
5-35. Targeting is the process of selecting targets and matching the appropriate response to them, including
operational requirements and capabilities. The purpose of targeting is to disrupt, delay, or limit threat
interference with friendly COAs; it requires coordinated interaction between operations and intelligence
planning cells. Targeting is based on the enemy’s assets that provide him an advantage, friendly scheme of
maneuver, and tactical plans. CI support to the targeting process include the development of CI targets list
to identify those FISS and ITO persons, organizations, facilities, or installations that must be exploited
through raid and capture to gain additional intelligence or neutralization to disable or destroy, negate,
mitigate, or degrade the adversary’s ability to collect on U.S. forces.
21 October 2009
FM 2-22.2
5-7
FOR OFFICIAL USE ONLY
Chapter 5
5-36. The CICA and the 2X need a positive way to keep track of the status of CI targets. A CI target list is
used to ensure targets are seized, exploited, or controlled in a timely manner. The plan is keyed to the
scheme of maneuver and lists targets as they are expected to appear. When more targets appear than can be
exploited, a priority list is used to denote which target takes priority.
Priority one targets—represent the greatest threat to the command. They possess the greatest
potential source of information or material of intelligence or CI value. Priority one targets
must be exploited or neutralized first.
Priority two targets—of lesser significance than priority one. They are taken under control
after priority one targets have been exploited or neutralized.
Priority three targets—of lesser significance than priority one or two. They are to be exploited
or neutralized as time and personnel permit. This might be accomplished through either
investigations or operations.
INTELLIGENCE CORROBORATION
5-37. Before commitment of combat power to neutralize priority one targets, intelligence used to identify,
locate, and fix those targets should be corroborated through other intelligence sources (US military or
Government agencies and HN entities, when applicable) or disciplines (GEOINT, SIGINT, HUMINT).
5-38. This corroboration assists in validating the target and avoids wasted effort and resources of combat
forces attempting to neutralize a target that is no longer present, active, or occupied.
COUNTERINTELLIGENCE OPERATIONAL ANALYSIS
5-39. Analysis is also used to help direct and focus CI elements to ensure all information requirements are
being answered and to adjust collection focus and operational methodologies to provide better support to
the commander. The CICA and the 2X support the C/J/G/S-2 by expanding the CCIRs that can be
answered through CI collection into ISR tasks that can be answered by a human source and that can be
tasked to a specific collection entity.
5-40. The CICA and the 2X provide this information to support the development of the CI collection plan
and its integration into the overarching ISR plan. The CICA normally establishes a list of prioritized
standing indicators, and supplements this with ISR tasks developed to answer specific CCIRs. The standing
indicators are incorporated into the ACE’s all-source analysis team’s list of indicators that point to a pattern
or COA. Each standing indicator is integrated with other indicators and factors so that analysts can detect
patterns and establish threat intentions.
COUNTERINTELLIGENCE INTEGRATION INTO THE ISR PLAN
5-41. One of the primary functions of the CICA and 2X is to deconflict CI operations throughout the area
of intelligence responsibility and to synchronize all CI assets to eliminate unneeded overlap and duplication
of effort or intelligence fratricide. This includes providing input to the ISR plan to integrate CI assets and
ensure unity of the intelligence effort among all organic and adjacent CI elements and other intelligence
disciplines.
COUNTERINTELLIGENCE OPERATIONAL CONTROL AND GUIDANCE
5-42. The 2X serves as the requirements manager for Army CI and HUMINT entities within their area of
intelligence responsibility. Through the use of operational analysis, the
2X can determine what
requirements have been answered; identify information gaps and what CI assets and/or documented sources
can be tasked to satisfy IRs.
5-43. When a CI team has fulfilled a specific requirement, the 2X can analyze its AO and its active sources
and re-direct the team’s mission focus to cover information gaps. The2X can also analyze all intelligence
5-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
reporting as well as historical information, assessments, and demographics data to develop source profiles
that can be provided to CI teams to use for developing new sources of information to answer SIRs.
ANALYTICAL TOOLS
5-44. CI analysis uses tools to archive, fuse, and correlate data to produce analytical products. Some tools
can also be used as products themselves to graphically depict information for easier comprehension by the
consumer. There are three basic analytical techniques and automated tools that are particularly useful to
single-discipline CI analysis. They are the time event chart, matrices, and the link analysis diagram.
5-45. Each of these tools takes fragmented bits of information and organizes them to create a chart or graph
that can easily be read. CI collectors and analysts can use automated computer programs such as Analyst’s
Notebook or Crime Link to produce these tools or they can create them on paper. Computer programs are
faster to use than previous methods and have the added advantage of producing a product that can be
shared easily and rapidly over networks and portals. The diagrams in this chapter represent the tools that
can be produced using automated programs.
TIME EVENT CHART
5-46. A time event chart is a method for placing and representing individual or group actions
chronologically. It uses symbols to represent events, dates, and the flow of time. Normally, triangles are
used to depict the beginning and end of the chart and may be used within the chart to indicate particularly
critical events such as an ideological shift or change. Rectangles, used as event nodes, store administrative
data and indicate significant events or activities. Drawing an “X” through the event node may highlight
noteworthy or important events.
5-47. Each of these symbols contains a sequence number, date (day, month, and year of the event), and
may, if desired, contain a file reference number. The incident description written below the event node is a
brief explanation of the incident and may include team size and type of incident. Arrows indicate time flow.
5-48. By using these symbols and brief descriptions, it is possible to analyze the group’s activities,
transitions, trends, and particularly operational patterns in both time and activity. If desired, the event nodes
may be color coded to indicate a particular event or type of event to aid in pattern recognition. The time
event chart is the best analytical tool for pattern analysis. Figure 5-2 (page 5-10) shows the symbology used
to create a time event chart. Figure 5-3 (page 5-10) shows a time event chart as depicted in Analyst
Notebook.
MATRICES
5-49. Construction of a matrix is the easiest and simplest way to show the relationships between a number
of similar or dissimilar associated items. The items can be anything that is important to a collection effort
such as people, places, organizations, automobile license plates, weapons, telephone numbers, or locations.
5-50. In analysis, matrices are often used to identify “who knows whom,” or “who has been where or done
what” in a clear concise manner. There are two types of matrices used in human analysis: the association
matrix, used to determine existence of relationships between individual human beings, and the activities
matrix, used to determine connectivity between individuals and any organization, event, address, activity,
or any other nonpersonal entity. The graphics involved in constructing the two types of matrices differ
slightly, but the principles are identical.
Association Matrix
5-51. An association matrix shows connections between key individuals involved in any event or activity.
It shows associations within a group or associated activity. Normally, this type of matrix is constructed in
the form of an equilateral triangle having the same number of rows and columns. Personalities must be
listed in exactly the same order along both the rows and columns to ensure that all possible associations are
correctly depicted. An alternate method is to list the names along the diagonal side of the matrix. This type
21 October 2009
FM 2-22.2
5-9
FOR OFFICIAL USE ONLY
Chapter 5
of matrix does not show the nature, degree, or duration of a relationship, only that a relationship exists. The
purpose of the matrix (see figure 5-4) is to show the analyst who knows whom and who are suspected to
know whom. In the event that a person of interest dies, a diamond is drawn next to the deceased’s name on
the matrix.
Figure 5-2. Example of a time event chart
Figure 5-3. Analysis Notebook theme line chart
5-52. The analyst uses a dot or closed (filled-in) circle to depict a strong or known association as shown in
figure 5-5. A known association is determined by direct contact between one or more persons. Direct
contact is determined by several factors. Direct associations include—
Face-to-face meetings.
Telephonic conversations in which the analyst is sure who was conversing with whom.
Members of a cell or other group who are involved in the same operations.
5-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
5-53. Suspected or weak associations in which there are indicators that individuals may have had
associations but there is no way to confirm that association; this is depicted with an open circle. Examples
of suspected associations are—
A known party calling a known telephone number (the analyst knows to whom the telephone
number is listed), but it cannot be determined with certainty who answered the call.
A face-to-face meeting where one party can be identified, but the other party can only be
tentatively identified.
Figure 5-4. Example of an association matrix
Figure 5-5. Example of an association matrix symbology
5-54. The rationale for depicting suspected associations is to get as close as possible to an objective
analytic solution while staying as close as possible to known or confirmed facts. If a suspected association
is later confirmed, the appropriate adjustment may be made on the association matrix. A secondary reason
for depicting suspected associations is that it may give the analyst a focus for tasking limited intelligence
collections assets to confirm the suspected association. An important point to remember about using the
21 October 2009
FM 2-22.2
5-11
FOR OFFICIAL USE ONLY
Chapter 5
association matrix is that it will, without modification, show only the existence of relationships; not the
nature, degree, or duration of those relationships.
Activities Matrix
5-55. Figure 5-6 shows a rectangular array of personalities compared against activities, locations, events,
or other appropriate information. The kind and quality of data that is available to the collector determines
the number of rows and columns and their content. The analyst may tailor the matrix to fit the needs of the
problem at hand or add to it as the problem expands in scope. This matrix normally is constructed with
personalities arranged in a vertical listing on the left side of the matrix, with events, activities,
organizations, addresses, or any other common denominator arranged along the bottom of the matrix.
5-56. The activities matrix is critical for the study of a group’s internal and external activities, external ties
and linkages, and even modus operandi. As with the association matrix, confirmed or “strong” associations
between individuals and non-personal entities are shown with a solid circle or dot, while suspected or
“weak” associations are illustrated by an open circle.
Figure 5-6. Example of an activities matrix
5-57. Using matrices, the analyst can pinpoint the optimal targets for further intelligence collection,
identify key personalities within an organization, and considerably increase the analyst’s understanding of
an organization and its structure. Matrices can be used to present briefings or to store information in a
concise and understandable manner within a database. Matrices augment but cannot replace SOPs or
standard database files. It is possible, and sometimes productive, to use one matrix for all associations.
LINK ANALYSIS DIAGRAM
5-58. The link analysis diagram shows the connections between people, groups, or activities. The
difference between matrices and link analysis is roughly the same as the difference between a mileage chart
and a road map. The mileage chart (matrix) shows the connections between cities using numbers to
5-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
represent travel distances. The map (link analysis diagram) uses symbols that represent cities, locations,
and roads to show how two or more locations are linked to each other. Figure 5-7 is an example of a link
analysis diagram.
Figure 5-7. Example of a link analysis diagram
5-59. As with construction of association matrices, there are certain rules of graphics, symbology, and
construction that must be followed. Standardization is critical to ensuring that everyone constructing, using,
or reading a link analysis diagram understands exactly what the diagram depicts. Circles and lines are
arranged so that no lines cross whenever possible. Often, especially when dealing with large groups, it is
very difficult to construct a line diagram in which no lines cross. In these cases, every effort should be
made to keep the number of crossings at an absolute minimum. The standard rules follow.
21 October 2009
FM 2-22.2
5-13
FOR OFFICIAL USE ONLY
Chapter 5
5-60. Persons are shown as open circles with the name written inside the circle. Deceased persons are
depicted in either open circles, with a diamond next to the circle representing that person (as in figure 5-8)
or as open diamonds with the name written inside the diamond.
Figure 5-8. Example showing deceased person
Persons known by more than one name (alias or AKA) are shown as overlapping circles with
names in each circle (as shown in figure 5-9) or both names are simply listed in the same
circle.
Figure 5-9. Example of person with suspected alias
If the alias is suspected, a dotted line is used to depict the intersection. If the alias is
confirmed, the intersection is shown with a solid line (as shown in figure 5-10).
Figure 5-10. Example of person with confirmed alias
Nonpersonal entities
(organizations, governments, events, locations) are shown as
appropriately labeled rectangles (as shown in figure 5-11).
Figure 5-11. Example of nonpersonal entity
Solid lines (see figure 5-12) denote confirmed linkages or associations.
Figure 5-12. Confirmed linkage
5-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
Dotted lines (see figure 5-13) show suspected linkages and associations.
Figure 5-13. Suspected linkage
Footnotes can be shown as a brief legend on the connectivity line (see figure 5-14).
Figure 5-14. Legend on connectivity line
Each person or non-personal entity is depicted only once in a link analysis diagram. Figure 5
15 shows only connectivity between persons.
Figure 5-15. Connectivity between persons
5-61. The analyst can easily determine from the diagram that Alpha knows Bravo, Bravo knows Charlie
and Delta. Bravo is suspected of knowing Echo, and Charlie knows Delta, Bravo, and Echo. Although the
same information could be shown on a matrix, it is easier to understand when depicted on a link analysis
diagram. As situations or investigations become more complex, the ease in understanding a link analysis
diagram becomes more apparent. In almost all cases, the available information is first depicted and
21 October 2009
FM 2-22.2
5-15
FOR OFFICIAL USE ONLY
Chapter 5
analyzed on both types of matrices, which are then used to construct a link analysis diagram for further
analysis.
5-62. Link analysis diagrams can show organizations, membership within the organization, action teams or
cells, or participants in an event. Since each individual depicted on a link analysis diagram can be shown
only once, and some individuals may belong to more than one organization or take part in more than one
event, squares or rectangles representing non-personal entities may have to overlap.
5-63. Figure 5-16 demonstrates that Ralph and Fred are both members of the “Red Fighters,” and that
Ralph is also a member of the “Students for Peace.” Further, since Ralph and Fred are shown in the same
“box,” it is a given that they are mutually associated.
5-64. There is more to overlapping organizations than is immediately obvious. At first glance, the overlap
indicates only that an individual may belong to more than one organization or has taken part in multiple
activities. Further study and analysis would reveal connections between organizations, connections between
events, or connections between organizations and events, either directly or through persons. The diagram in
figure 5-16 reveals a more complex connection between organizations and personnel.
Figure 5-16. Example of mutually associated members
5-65. The analysis diagram in figure 5-17 shows a connection between organizations and events to which
an individual belongs or is associated. In this case, a national government runs a training camp for
terrorists. Ahmed, a member of the terrorist group, is associated with the training camp, and participated in
the bombing attack. From this diagram, one can link the supporting government to the bombing through the
camp and the participant.
Figure 5-17. Connection between organizations and events
5-66. When, as is often the case, an organization or incident depicted in a link analysis diagram contains
the names of more than one individual, it is not necessary to draw a solid line between those individuals to
indicate connectivity. It is assumed that individual members of the same cell or participants in the same
activity know each other, and the connection between them is therefore implied. If the persons are not
mutually associated, they cannot be placed in the same “box.” Another solution must be found to depict the
situation; that is, show the persons as associated with a subordinate or different organization or activity.
5-67. A final set of rules for link analysis diagrams concerns connectivity between individuals who are not
members of an organization or participants in an activity, but who are somehow connected to that entity.
Two possibilities exist: First, the individual knows a member or members of the organization, but is not
5-16
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
associated with the organization itself; or second, the person is somehow connected with the organization
or activity but cannot be directly linked with any particular member of that entity.
In the first case, the connectivity line is drawn only between the persons concerned as
depicted in figure 5-18.
Figure 5-18. Connectivity between persons but not the organization
In the second case, where Smith is associated with the entity, but not the persons who are
members of entity, the situation is shown as depicted in figure 5-19.
Figure 5-19. Association with an entity
5-68. The steps in constructing a link analysis diagram are as follows:
Step 1. Raw data or fragments of information are organized into logical order. Names of
individuals, organizations, events, and locations are compiled on appropriate lists. At this
point, a time event chart may be completed to assist in understanding the information and to
arrange events into chronological order.
Step 2. Information is entered onto the appropriate matrices, graphically displaying “who is
associated with whom” and “who is associated with what.”
Step 3. Drawing information from the database and intelligence reports, and relationships
from the matrices, the link analysis diagram can be constructed. The best method to start the
link analysis diagram is to—
Start with the association matrix and determine which person has the greatest number of
personal associations. Depict that person in the center of the page (see figure 5-20).
Figure 5-20. Person with greatest number of personal associations
21 October 2009
FM 2-22.2
5-17
FOR OFFICIAL USE ONLY
Chapter 5
Determine which person has the next highest number of personal associations. Depict
that person near the first person as shown in figure 5-21.
Figure 5-21. Person with next highest number of personal associations
Use the association matrix and show all confirmed and suspected personal associations
(see figure 5-22).
Figure 5-22. Confirmed personal associations
5-69. After all personal associations have been shown on the link analysis diagram, the analyst uses the
activities matrix to determine which activities, organizations, or other non-personal entities need to be
depicted by appropriate rectangles (as shown in figure 5-23). Having done so, the lines of connectivity
between persons within the rectangles may be removed to prevent clutter. (It is assumed that participants in
the same activity or members of the same cell are acquainted.)
Figure 5-23. Example of activities, organization, and nonpersonal entities
5-70. After completion of the matrices and the link analysis diagram, the analyst makes recommendations
about the group’s structure, and areas can be identified for further collection. Collection assets are
employed to verify suspected connections, ID key personalities, and substantiate or refute the conclusions
and assessments drawn from the link analysis that has been done. The link analysis diagram and thorough
analysis of the information it contains can reveal a great deal about an organization. It can identify the
group’s leadership, its strong and weak points, and operational patterns. The analyst can use these to predict
future activities. Figures 5-24 through 5-26 show link analysis diagrams and association matrices using
Analyst Notebook.
5-18
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
Figure 5-24. Analyst Notebook link diagram showing information from an activity matrix
Figure 5-25. Analyst Notebook link diagram showing nonpersonal relationship
21 October 2009
FM 2-22.2
5-19
FOR OFFICIAL USE ONLY
Chapter 5
Figure 5-26. Analyst Notebook hierarchy layout
5-71. For more information on other analytical tools, see TC 2-33.4.
PRODUCTION
5-72. CI is an integral part of the IPB process and overall analytical effort. CI is responsible for a variety of
products that support the analysis of the adversary’s plans, intentions, and capabilities. These products can
affect the commander’s MDMP or assist in shaping operations of the broader CI mission.
COUNTERINTELLIGENCE ESTIMATE
5-73. The CI estimate is a composite study containing information from each functional area pertaining to
a specified contingency area. It is a dynamic document prepared during peacetime and refined and updated
continuously. The CI estimate addresses all friendly AOs. The CI estimate contributes to the IPB process.
Types of information contained in these estimates vary depending on the contingency area. They generally
contain discussions on friendly deployment (including friendly critical nodes) and enemy intelligence
collection capabilities and operations (such as sabotage or unconventional warfare). The following are
examples of FISS and ITO information found in an estimate:
Structure.
Key personalities.
Methods of operation.
Collection capabilities.
Targeting.
5-20
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Analysis, Tools, and Production
THREAT ASSESSMENT
5-74. A threat assessment is the analysis of the FISS and ITO threat directed towards friendly critical nodes
and targets. Some of these friendly targets will be identified almost out of common sense, but others will
require a concerted analytical effort. In preparing the CI estimate, the team should first concentrate on
identifying friendly critical nodes and targets and then examine the known or potential FISS and ITO
threat. It should then evaluate the target with respect to their relative criticality, accessibility, vulnerability,
and the potential effect of their destruction or degradation in operational effectiveness.
SOURCE PROFILES
5-75. Source profiling is another analytical technique that incorporates both the IPB process with
operations analysis. Source profiling is assessing what type of person can satisfy standing information
requirements to support the commander’s MDMP. While there are negative connotations associated with
“profiling,” source profiling is designed to maximize the time and resources of CI teams and prevent
fishing expeditions by CI special agents hoping to stumble across a good source of information.
Developing a source profile is an operational planning tool that can be developed by CI OMTs to
operationally focus CI teams.
5-76. Source and demographic overlays can assist in the development of source profiles. CI elements with
source profiles can plan missions to put their team into environments where they are most likely to come
into contact with someone who can answer a requirement. Once in that environment, the CI element can
rapidly evaluate potential sources during elicitation operations and prioritize those persons who may be a
potential source of information. Source profiling must factor in the following variables to identify the
optimum source for information requirements satisfaction:
Demographics. What ethnicity, tribal affiliation, age, or profession of a source would be able
to satisfy the information requirement based upon the situation and/or AO.
Placement. The proximity of the potential source in relation to the environment where he
could potentially obtain the information (geographically, culturally).
Access. The ability of a source to obtain direct or indirect information that satisfies a
requirement.
Motivation. The convictions, ideologies, or compensatory incentives that would induce a
person to cooperate with and provide information to an Army CI element.
Control. The character traits or attributes of a source that would permit him to respond to
direction and proactively assist U.S. forces.
21 October 2009
FM 2-22.2
5-21
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 6
Technical Counterintelligence Services and Support
The conduct of investigations is enhanced significantly by the use of existing and
emerging technical procedures and techniques, all of which are designed to simplify
and shorten the time required to complete certain investigative tasks while ensuring
that all evidence, no matter how seemingly insignificant, is thoroughly evaluated. CI
units may have access to personnel skilled in technical investigative techniques from
higher supporting echelons as well as from within their own ranks.
TECHNICAL INVESTIGATIVE TECHNIQUES
6-1. Technical investigative techniques can contribute materially to the overall investigation. They can
assist in providing the commander with timely, factual information on which to base decisions. Specially
trained CI special agents conduct TCI investigations to detect clandestine surveillance systems, use
polygraph to detect human deception, and employ computer forensics methodologies to investigate known
or suspected foreign intrusions into DOD or Army networks.
6-2. All of these personnel are also trained and experienced CI special agents. With the proper approval,
CI special agents may employ, or request the proper agency to employ the following activities:
Electronic surveillance.
Investigative photography and video recording.
Laboratory analysis.
Polygraph support.
TSCM.
Deception identification and detection (biometrics).
Computer forensics.
Support to information tasks.
ELECTRONIC SURVEILLANCE
6-3. Electronic surveillance is the use of electronic devices to monitor or record conversations, activities,
sound, or electronic impulses. Electronic surveillance requires approval as specified in AR 381-10, chapter
5. Requests for electronic surveillance and concealed monitoring activities conducted to support an
approved CI investigation must be processed through the ATCICA for staffing and coordination with the
appropriate approval authority based upon the criteria outlined in AR 381-10, chapters 5 and 6. Electronic
surveillance activities will only be conducted by organizations approved by DA G-2X to support this type
of activity.
21 October 2009
FM 2-22.2
6-1
FOR OFFICIAL USE ONLY
Chapter 6
INVESTIGATIVE PHOTOGRAPHY AND VIDEO RECORDING
6-4. A photograph or video recording may be valuable as evidence since it presents facts in pictorial form
and creates realistic mental impressions. It may present evidence more accurately than a verbal or written
description. Photographs permit consideration of evidence which, because of size, bulk, weight, or
condition, cannot be brought into the courtroom. Photography and video recording in CI investigations
include—
Identification of individuals. CI special agents perform both overt and surreptitious
photography and video recording. This is considered concealed monitoring and requires
approval specified in AR 381-10, chapter 6.
Recording of incident scenes. Agents photograph overall views and specific shots of items at
the incident scene.
Recording activities of suspects. Agents use photography and video recording to provide a
record of a suspect’s activities observed during surveillance or cover operations. This is
considered concealed monitoring and requires approval specified in AR 381-10, chapter 6.
6-5. To qualify as evidence, photographs and video recordings must be relevant to the case. A person who
is personally acquainted with the locale, object, person, or thing represented must verify the photograph or
video recording. This is usually the photographer. The agent will support photographs and video recordings
used as evidence by notes made at the time of the photography. These notes provide a description of what
the photograph includes. The notes will contain—
The case number, name of the subject and the time and date that the photographs or video
recordings were taken.
Technical data, such as lighting and weather conditions and type of film, lens, and camera
used.
Specific references to important objects in the photograph.
These notes may be retained on a form such as a photo data card.
6-6. Physical surveillance, including photography and video recording, requires approval as specified in
AR 381-10, chapter 9.
LABORATORY ANALYSIS
6-7. We must anticipate the use of false documentation and secret writing by foreign intelligence agents
in many CI investigations. Detection requires specially trained personnel and laboratory facilities. The CI
unit SOP should list how this support is obtained.
POLYGRAPH SUPPORT
6-8. The polygraph examination is a highly structured technique conducted by specially trained CI
personnel certified by proper authority as polygraph examiners.
6-9. AR 195-6 covers the polygraph program while AR 381-20 covers intelligence polygraphs and
describes general applicability, responsibilities, and use of polygraph, records processing, and selection and
training of DA polygraph examiners.
6-10. AR 381-20 authorizes intelligence polygraphs for CI investigations, foreign intelligence and CI
operations, access to SCI, exculpation in CI investigations; and CSPE to support certain programs or
activities listed in AR 381-20.
6-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Technical Counterintelligence Services and Support
6-11. The conduct of the polygraph examination is appropriate, with respect to investigations, only when—
All investigative leads and techniques have been completed as thoroughly as circumstances
permit.
The subject of the investigation has been interviewed or thoroughly debriefed.
Verification of the information by means of polygraph is deemed essential for completion or
continuation of the investigation.
6-12. Do not conduct a polygraph examination as a substitute for securing evidence through skillful
investigation. The polygraph examination is an investigative aid and can be used to determine questions of
fact, past or present. CI special agents cannot make a determination concerning an individual’s intentions or
motivations, since these are states of mind and not fact. However, consider the examination results along
with all other pertinent information available. Polygraph results will not be the sole basis of any final
adjudication. Intelligence polygraph examinations are conducted to—
Determine the suitability, reliability, or credibility of agents, sources, or operatives of foreign
intelligence or CI operations.
Determine the initial and continued eligibility of individuals for access to programs and
activities authorized CSPE support.
6-13. The polygraph examination consists of three basic phases: pretest, in-test, and post-test.
During the pretest, appropriate rights advisements are given and a written consent to undergo
polygraph examination is obtained from all examinees who are suspects or accused. Advise
the examinee of the Privacy Act of 1974 and the voluntary nature of examination. Conduct a
detailed discussion of the issues for testing and complete the final formulation of questions to
be used during testing.
During the in-test phase, ask previously formulated and reviewed test questions and monitor
and record the examinee’s responses by the polygraph instrument. Relevant questions asked
during any polygraph examination must deal only with factual situations and be as simple and
direct as possible. Formulate these questions so that the examinee can answer only with a yes
or no. Never use or ask un-reviewed questions during the test.
If responses indicate deception, or unclear responses are noted during the test, conduct a post-
test discussion with the examinee in an attempt to elicit information from the examinee to
explain such responses.
6-14. A polygraph examiner may render one or more of four possible opinions concerning the polygraph
examination:
No opinion. This is based on the fact that the examiner did not pose enough questions to
make a determination.
Inconclusive. This is based on the fact that the completed test results did not support the
ability to make a determination of significant response or no significant response.
No significant response (NSR). This is defined as a judgment by the examiner that the
physiological responses of the examinee were indicative of veracity and the Polygraph
Quality Control Office (PQCO) supports this conclusion.
Significant response
(SR). This is defined as a judgment by the examiner that the
physiological responses of the examinee were indicative of deception and the PQCO supports
this decision.
6-15. Certain mental or physical conditions may influence a person’s suitability for polygraph examination
and affect responses during testing. CI special agents should report any information they possess
concerning a person’s mental or physical condition to the polygraph examiner before scheduling the
examination. Typical conditions of concern are—
21 October 2009
FM 2-22.2
6-3
FOR OFFICIAL USE ONLY
Chapter 6
Mental disorders of any type.
Any history of heart, respiratory, circulatory, or nervous disorders.
Any current medical disorder, including colds, allergies, or other conditions
(such as
pregnancy or recent surgery).
Use of drugs or alcohol before the examination.
Mental or physical fatigue.
Pain or physical discomfort.
6-16. To avoid such conditions as mental or physical fatigue, do not conduct prolonged or intensive
questioning immediately before a polygraph examination. The CI special agent tells the potential examinee
to continue taking any prescribed medication and bring it to the examination. Based on information
provided by the CI special agent and the examiner’s own observations, the polygraph examiner decides
whether a person is fit to undergo examination by polygraph.
6-17. When the CI special agent asks a person to undergo a polygraph examination, the person is told that
the examination is voluntary and that no adverse action can be taken based solely on the refusal to undergo
examination by polygraph. Further, the person is informed that no information concerning a refusal to take
a polygraph examination is recorded in any personnel file or record.
6-18. The CI special agent will not attempt to explain anything concerning the polygraph instrument or the
conduct of the examination. If asked, the CI special agent should inform the person that the polygraph
examiner will provide a full explanation of the instrument and all procedures before actual testing and that
all test questions will be fully reviewed with the potential examinee before testing.
6-19. Conduct polygraph examinations in a quiet, private location. The room used for the examination
must contain, as a minimum, a desk or table, a chair for the examiner, and a comfortable chair with wide
arms for the examinee. The room may contain minimal, simple decorations; must have at least one blank
wall; and must be located in a quiet, noise-free area. Ideally, the room should be soundproof. Visual or
audio monitoring devices may be used during the examination; however, the examiner must inform the
examinee that such equipment is being used and if the examination will be monitored or recorded in any
manner.
6-20. Normally only the examiner and the examinee are in the room during examination. When the
examinee is an accused or suspect female and the examiner is a male, a female witness must be present to
monitor the examination. The monitor may be in the examination room or may observe through audio or
visual equipment if such is available.
6-21. On occasion, the CI special agent must arrange for an interpreter to work with the examiner. The
interpreter must be fluent in English and the required language, and have a security clearance appropriate to
the classification of material or information to be discussed during the examination. The interpreter should
be available in sufficient time before the examination to be briefed on the polygraph procedures and to
establish the proper working relationship.
6-22. AR 195-6 describes polygraph reports, records to be maintained, and records distribution. The CI
special agent must provide the examiner with all files, dossiers, and reports pertaining to the investigation
or operation before the examination and must be available to answer any questions the examiner may have
concerning the case.
6-23. The CI special agent will not prepare any agent reports concerning the results of a polygraph
examination. This does not include information derived because of pre-test or post-test admissions, nor
does it include those situations where the CI special agent must be called upon by the examiner to question
the subject concerning those areas which must be addressed before the completion of the examination.
6-24. The polygraph examiner will prepare a polygraph examination report detailing the facts and
circumstances of the examination. A copy of the report may be provided to the CI special agent. Such
copies must be destroyed within three months following completion of the investigation or operation. The
6-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Technical Counterintelligence Services and Support
original report will be forwarded to and maintained by the U.S. Army Investigative Records Repository
(USAIRR), Fort Meade, MD. Request polygraph support in accordance with INSCOM Pamphlet 381-6.
TECHNICAL SURVEILLANCE AND COUNTERMEASURES
PROGRAM
6-25. The Army TSCM contributes to information superiority by preventing, detecting, and neutralizing
foreign intelligence and security systems (FISS) and international terrorist organizations (ITO) efforts to
gain access to classified national security information and sensitive but unclassified information.
TEMPEST refers to the evaluation and control of compromising emanations from telecommunications and
automated information systems. TEMPEST countermeasures are designed to prevent FISS and ITO
exploitation of compromising emanations by containing them within the space of the equipment or facility
processing classified information.
6-26. TSCM is concerned with the intentional effort to gather intelligence by foreign intelligence activities
by inserting covert or clandestine devices into a U.S. facility, or by modifying existing equipment within
that area. For the most part, intelligence gained through the use of technical surveillance means information
will be accurate, as people are unaware they are being monitored. At the same time, the implanting of such
technical surveillance devices is usually a last resort.
6-27. FISS and ITO elements use all available means to collect sensitive information. One way they do this
is by using technical surveillance devices, commonly referred to as “bugs” and “taps.” Such devices have
been found in U.S. facilities worldwide. Security weaknesses in electronic equipment used in everyday
work have also been found worldwide. FISS and ITO easily exploits these weaknesses to collect sensitive
or classified conversations as well as the information being processed. They are interested in those things
said in (supposed) confidence, since they are likely to reveal future intentions. It should be stressed that
vulnerabilities are not just audio, but include video camera signals and data. Devices are usually placed to
make their detection almost impossible without specialized equipment and trained individuals.
6-28. The purpose of the TSCM program is to locate and neutralize technical surveillance devices that have
been targeted against U.S. Government sensitive or secure areas. The TSCM program includes all measures
taken to reduce the technical surveillance threat. The secondary, and closely interrelated purpose, is to
provide commanders and department heads with a comprehensive evaluation of their facilities’ technical
and physical security postures. The Director of Central Intelligence established the requirement for a
comprehensive TSCM program. Indoctrination of personnel concerning the technical surveillance threat
and the role of the individual in the success of the TSCM program is key.
6-29. The TSCM program includes four separate functions, each with a direct bearing on the program:
Detection. TSCM investigations are designed to detect the presence of technical surveillance
devices, technical security hazards, or physical security weaknesses that would permit the loss
of sensitive information.
Nullification. Nullification includes both passive and active measures used to neutralize or
negate devices that are found. An example of passive nullification is soundproofing.
However, soundproofing that covers only part of a room is not very helpful. Excessive wires
must be removed, as they could be used as a transmission path from the room. Nullification
also refers to those steps taken to make the emplacement of technical surveillance systems as
difficult as possible.
Isolation. This refers to the establishment of special areas for the conduct of activities
involving sensitive information, and the exclusion or close control of all uncleared personnel.
Isolation may involve the designation of a smaller special area with appropriate physical and
other security barriers or the isolation of an entire building.
Education. Individuals must know the FISS and ITO threat and their responsibilities before a
technical surveillance device is detected or suspected. Additionally, people need to be alert to
21 October 2009
FM 2-22.2
6-5
FOR OFFICIAL USE ONLY
Chapter 6
what is going on in and around their area, particularly during construction, renovations, and
installation of new equipment.
6-30. The TSCM program consists of CI technical investigations and services
(such as surveys,
inspections, preconstruction advice and assistance) and technical security threat briefings. TSCM
investigations and services are highly specialized CI investigations and are not to be confused with
compliance-oriented or administrative services conducted to determine a facility’s implementation of
various security directives.
TECHNICAL SURVEILLANCE COUNTERMEASURES SURVEY
6-31. This is an all-encompassing investigation. This investigation is a complete electronic, physical, and
visual examination to detect clandestine surveillance systems. A by-product of this investigation is the
identification of physical and technical security weaknesses, which could be exploited by FISS and ITO.
TECHNICAL SURVEILLANCE COUNTERMEASURES INSPECTION
6-32. Normally, once a TSCM survey has been conducted, it will not be repeated. If TSCM personnel note
several technical and physical weaknesses during the survey, they may request and schedule an inspection
at a later date. In addition, they will schedule an inspection if there has been an increased threat posed to
the facility or if there is some indication that a technical penetration has occurred in the area. DODD
5240.5 specifically states that no facility will qualify automatically for recurrent TCI support.
6-33. Preconstruction assistance is designed to help security and construction personnel with the specific
requirements needed to ensure that a building or room will be secure and built to standards. As with other
technical areas, it is much less expensive and more effective to build in good security from the initial stages
of a new project. This saves money by precluding costly changes later on.
6-34. Army activities request TSCM support:
When requesting or receiving support, the facility being inspected must be complete and
operational, unless requesting preconstruction advice and assistance. If any new equipment is
introduced into the secure area or if access controls are not practiced, the TSCM investigation
may be negated.
Fully justified requests of an emergency nature, or for new facilities, may be submitted at any
time, but should be submitted at least 30 days before the date the support is required.
Unprogrammed requests will be funded by the requestor. Each request for unprogrammed
TSCM support must be accompanied by a funding number to defray the costs of temporary
duty (TDY) and per diem.
The compromise of a TSCM investigation or service is a serious security violation with
potentially severe impact on national security. Do not compromise the investigation or service
by any action, which discloses to any person, especially one inside the facility, that TSCM
activity will be, is being, or has been conducted within a specific area. Unnecessary
discussion of a TSCM investigation or service, particularly within the subject area, is
especially dangerous because—
If a listening device is installed in the area, such discussion can alert persons who are
conducting the surveillance and permit them to remove or deactivate their devices. When
deactivated, such devices are extremely difficult to locate and may require
implementation of destructive search techniques.
In the event a TSCM investigation or service is compromised, the TSCM team chief will
terminate the investigation or service at once. Report the circumstances surrounding the
compromise of the investigation or service to the head of the serviced facility, the
appropriate Army command, ASCC, and the INSCOM TSCM program director. TSCM
personnel will not reschedule an investigation or service until the cause and impact of the
6-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Technical Counterintelligence Services and Support
compromise have been evaluated by the TSCM CI special agent, the appropriate agency
head, and the INSCOM TSCM program director.
6-35. When a TSCM surveyor inspection is completed, the requestor is usually given reasonable assurance
that the surveyed area is free of active technical surveillance devices or hazards. The TSCM inspector will
inform the requestor—
About all technical and physical security vulnerabilities with recommended regulatory
corrective actions.
That it is impossible to give positive assurance that there are no devices in the surveyed area.
That the security of the TSCM investigation will be nullified by the admission to the secured
area of unescorted persons who lack the proper security clearance.
6-36. The TSCM investigation will also be negated by failing to maintain continuous and effective
surveillance and control of the serviced area; allowing repairs or alterations by persons lacking the proper
security clearance or not under the supervision of qualified personnel; or introducing new furnishings or
equipment without a thorough inspection by qualified personnel.
6-37. Report immediately the discovery of an actual or suspected technical surveillance device via a secure
means from a different facility/location. All information concerning the discovery will be handled at a
minimum of SECRET. Installation or unit security managers will request an immediate investigation by the
supporting CI unit or supporting TSCM element.
DECEPTION IDENTIFICATION AND DETECTION (BIOMETRICS)
6-38. Biometrics as a characteristic is a measurable biological and behavioral characteristic that can be
used for automated recognition. Biometrics as a process is an automated method of recognizing a person
based on a physiological or behavioral characteristic. Among the features measured are face, fingerprints,
hand geometry, handwriting, iris, retinal, vein, and voice. Biometric technologies are becoming the
foundation of an extensive array of highly secure identification and personal verification solutions. As the
level of security breaches and transaction fraud increases, the need for highly secure identification and
personal verification technologies is becoming apparent.
6-39. Identification specific mission areas that CI detection and identification processes and technologies
support include, but are not limited to, the following:
Countering foreign intelligence through the detection, identification, and neutralization of
espionage activities.
Support to military readiness and conduct of military operations through protection,
including—
Surveillance of air, land, or sea areas adjacent to deployed U.S. forces, sufficient to
provide maximum warning of impending attack.
Indication of hostile intelligence penetration or attempts at penetration.
Support to law enforcement efforts to suppress CT.
Identification and affiliation of terrorist groups.
Assessment of group capabilities, including strengths and weaknesses.
Locations of terrorist training camps or bases of operations.
Weapons and technologies associated with identified terrorist elements.
21 October 2009
FM 2-22.2
6-7
FOR OFFICIAL USE ONLY
Chapter 6
IDENTIFICATION
6-40. Biometrics can assist combat units in identifying and tracking the friendly, neutral, and hostile
elements within their AO. From a CI perspective, biometrics provides a tool used to identify and database
persons during screening operations. CI could also use investigative and forensic activities to obtain
fingerprints obtained after a bomb or IED detonation, which may allow for the identification of the bomb
maker. This type of intelligence would facilitate targeting and threat negation to support protection, AT,
and CT.
6-41. Biometric capabilities are required to identify, database, and track personalities during CI operations
and for the conduct of accurate analysis. Biometric signatures would incorporate several physiological
criteria
(deoxyribonucleic acid [DNA]; voice recognition; and stress, iris, facial, fingerprint data) to
significantly enhance intelligence operations and analysis to support protection, AT programs, and CT.
DECEPTION
6-42. Biometric signatures will increase the ability to identify, track, and validate AT and CT intelligence
sources through physiological identification and indications of deception. Fingerprint, iris, and facial
recognition will be available for fielding to operational units. The system uses—
A fingerprint scanner, iris scanner, and digital camera for data input.
Recognition software for identification based on physiological criteria.
Database software to archive information for recognition and identity comparison.
COMPUTER FORENSICS
6-43. Computer forensics is conducted to—
Discover and recover evidence related to espionage, terrorism, or subversion against the
Army.
Develop CI investigative leads.
Collect and report intelligence.
Support exploitation efforts.
6-44. Processing and examining digital media evidence is a tedious and time-consuming process which
requires specialized training and equipment. Failure to properly process and examine digital media
evidence could corrupt the evidence or yield the evidence inadmissible during future legal proceedings.
Due to the complexities of cyber investigations, computer forensics support to CI investigations will only
be conducted by specially trained and qualified personnel assigned to cyber CI elements in each theater.
6-45. Requests for computer forensic support will be made through the appropriate ATCICA. Requests for
assistance will include detailed descriptions of the digital media evidence to be seized and examined and
will be germane to the approved CI investigative objectives.
6-46. Every CI special agent is responsible for identifying the need for computer forensics support to their
investigations. Computer forensics examinations involve a methodical process which, depending on the
size and complexity of the digital media evidence, may take a significant amount of time to complete.
Computer forensic operations cannot be rushed and therefore investigative time lines may need to be
adjusted to accommodate the time required to complete the support. If a CI special agent is in doubt about
the capabilities of, or when to leverage, cyber CI units, the agent should contact his ATCICA for guidance.
6-47. Authorized search and seizure activities during an approved CI investigation involving digital media
evidence will be conducted by trained and qualified personnel assigned to specific Army intelligence cyber
CI units. Some digital media evidence seizures are simple and clear. However, many mobile devices (such
6-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Technical Counterintelligence Services and Support
as cell phones and PDAs) that can transmit and receive data, or requires a constant source of power to
prevent data loss, require special handling techniques to preserve the evidentiary data.
SUPPORT TO INFORMATION TASKS (COMPUTER NETWORK
OPERATIONS)
6-48. The acquisition, possession, management, and control of information are essential to managing the
AO. The goal of friendly forces is to achieve information dominance while controlling information the
adversary sees, hears, and collects. CNO are critical in establishing information superiority. CNO
incorporates defensive information tasks to protect U.S. and coalition information systems while
simultaneously executing offensive information tasks to deny, disrupt, and defeat the adversary’s
information systems. CNO assists the commander in shaping the operational environment and achieving
tactical and strategic objectives by affecting the decisionmaking processes of adversarial commanders,
combatants, and the civilian populace. Overall, operational continuity and mission success require
coordination and synchronization of CNO and intelligence plans and operations to ensure mutual support.
6-49. Army CI includes CI special agents who are technical experts in automation, network operations,
Internet technologies, and computer forensics. Cyber CI personnel play a key role in Army CNO initiatives.
CI supports CNO by—
Identifying and analyzing FISS and ITO capabilities that may pose a threat to U.S. automation
networks and architecture.
Examining different applications and software used by an adversary.
Identifying IP addresses, net users, locations, hardware and peripherals, and artificial
constructs.
Identifying adversary CNO capabilities and providing targeting analysis and planning
assistance.
Conducting TAs and VAs to protect U.S. forces automation networks.
21 October 2009
FM 2-22.2
6-9
FOR OFFICIAL USE ONLY
This page intentionally left blank.
Chapter 7
Cyber Counterintelligence
Cyber CI refers to the use of techniques and measures to identify, exploit, or
neutralize adversarial operations that use information resources as the primary
tradecraft methodology. Cyber CI activities include three primary subdisciplines:
computer forensics support to CI investigations, CI network intrusion investigations,
and cyber CI operations.
GENERAL
7-1. Cyber CI missions are conducted by specially trained and equipped CI personnel who are assigned to
designated cyber CI units. Cyber CI techniques and methods can, and should, be employed in all phases of
CI investigations and operations. All CI special agents should know, and plan for the opportunities to
leverage cyber CI capabilities in the pursuit of their investigative and operational objectives.
7-2. Like traditional CI activities, cyber CI focuses on countering foreign intelligence and security
systems (FISS) and international terrorist organizations (ITO) collection activities targeting information or
material concerning U.S. personnel, activities, operations, plans, equipment facilities, publications,
technology, or documents, either classified or unclassified, without official consent of designated U.S.
release authorities.
CYBER COUNTERINTELLIGENCE SUPPORT TO CORE
FUNCTIONS
7-3. The U.S. military’s reliance on network centric operations as well as the availability of inexpensive
commercial technology to even the smallest of U.S. adversaries has created a significant vulnerability to
U.S. military operations. FISS and ITO has increased the targeting of U.S. military networks to collect
information, exploit vulnerabilities, and to attack our networks. This threat has resulted in a requirement for
specially trained CI special agents who can detect, identify, counter, exploit, or neutralize FISS and ITO
threats that occur in cyberspace.
COMPUTER FORENSICS SUPPORT
7-4. Computer forensics support to CI investigations includes the proper seizure, processing, examination,
and analysis of digital media evidence to support approved CI investigative objectives. The use of various
information systems (including but not limited to computers, networks, mobile computing devices, cellular
phones, PDAs) permeates the Army work environment. These information systems, as well as other forms
of digital media, are used to store, process, and distribute Army information. These data repositories can
easily be concealed and used for data exfiltration, thus potentially making them excellent sources of
evidence related to the crime of espionage.
21 October 2009
FM 2-22.2
7-1
FOR OFFICIAL USE ONLY
Chapter 7
7-5. Processing and examining digital media evidence is a tedious and time-consuming process which
requires special training and equipment. Failure to properly process and examine digital media evidence
could corrupt the evidence or yield the evidence inadmissible. Therefore, computer forensics support to CI
investigations will only be conducted by specially trained and qualified CI special agents. Computer
forensics will be conducted by these qualified personnel to—
Discover and recover evidence related to espionage, terrorism, or subversion against the
Army.
Develop CI investigative leads.
Collect and report intelligence.
Support exploitation efforts.
7-6. Requests for computer forensic support will be made through the appropriate ATCICA. Requests for
assistance will include detailed descriptions of the digital media evidence to be seized and examined. The
requests for assistance will be germane to the approved CI investigative objectives.
7-7. Every CI special agent is responsible for identifying the need for computer forensics support to their
investigations. Computer forensics examinations involve a methodical process which, depending on the
size and complexity of the digital media evidence, may take a significant amount of time to complete.
Computer forensic operations cannot be rushed and therefore investigative time lines may need to be
adjusted to accommodate the time required to complete the support.
7-8. Some digital media evidence seizures are simple and clear. However, many mobile devices (such as
cell phones and PDAs) that can transmit and receive data or need a constant source of power to prevent
data loss require special handling techniques to preserve the evidentiary data.
7-9. If a CI special agent is in doubt about the capabilities of, or when to leverage, cyber CI units, the
agent should contact his ATCICA for guidance. All CI special agents will operate in accordance with the
appropriate regulations to—
Ensure that any handling of digital media during CI investigations is performed only by
qualified cyber CI special agents or information system specialists.
Notify or request assistance from properly trained cyber CI special agents as soon as practical
after the initiation of an investigation.
Ensure that their actions are not detrimental to the preservation of digital evidence.
COUNTERINTELLIGENCE NETWORK INTRUSION INVESTIGATIONS
7-10. CI network intrusion investigations involve collecting, processing, and analyzing evidence related to
adversarial penetrations of Army information systems. These specialized CI investigations are generally
conducted independently of other traditional CI investigations. However, given the jurisdictional issues
which involve the Internet, network intrusion investigations may require coordination with other U.S. and
foreign government intelligence and law enforcement entities.
7-11. Threats to Army information systems can range from exploitation of vulnerabilities in information
systems which allow adversaries to penetrate Army computers and collect critical information, to trusted
insiders who either willingly or unwittingly enable adversarial forces to exploit these critical infrastructure
resources. Any adversary with the motive, means, opportunity, and intent to do harm poses a potential
threat. Threats to Army information resources may include disruption, denial degradation, ex-filtration,
destruction, corruption, exploitation, or unauthorized access to computer networks and information systems
and data. Cyber CI units are uniquely qualified to investigate and counter these threats.
7-12. All CI network intrusion investigations will be coordinated, to the extent necessary, with the
USACIDC, specifically the Cyber Criminal Investigations Unit (CCIU). This coordination is necessary to
7-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
ensure that investigative activities are not duplicated and that each organization does not impede or disrupt
each other’s investigative or prosecutorial options.
7-13. A CI network intrusion investigation may be initiated under, but not necessarily be limited to, the
following circumstances:
Known, suspected, or attempted intrusions into classified or unclassified information systems
by unauthorized persons.
Incidents which involve intrusions into systems containing or processing data on critical
military technologies, export controlled technology, or other weapons systems related
RDT&E data.
Intrusions which replicate methods associated with foreign intelligence or adversary
collection or which involve targeting that parallels known foreign intelligence or adversary
collection requirements.
7-14. The purpose for conducting a CI network intrusion investigation will be to—
Fully identify the FISS and ITO entity involved.
Determine the FISS and ITO objectives.
Determine the FISS and ITO tools, techniques, and procedures used.
Assist the appropriate authorities with determining the extent of damage to Army and
Department of Defense equities.
7-15. If the network intrusion appears to originate from a trusted insider who is under Army jurisdiction
and appears to be working for an adversary, the ATCICA or ACICA may authorize an FFI for the purposes
of legally prosecuting the subject or to develop the situation to enable neutralization or exploitation of the
foreign threat. If it is determined the activity is purely criminal in nature and does not constitute a threat to
national security, CI will refer the matter to the appropriate criminal law enforcement organization.
CYBER COUNTERINTELLIGENCE OPERATIONS
7-16. Cyber CI operations rely on cyber mechanisms to collect against, neutralize, or exploit an FISS and
ITO threat. Since the FISS and ITO threats to Army information systems are prevalent and very aggressive,
cyber CI operations should be designed to assertively counter these pervasive threats.
7-17. Cyber CI units may conduct CI operations in accordance with appropriate regulations to deter, detect,
neutralize, and/or support the exploitation of FISS and ITO threats. All proposed cyber CI operations will
be documented as a CI special operational concept or CI project and submitted for command and legal
endorsement before being forwarded to G-2 for approval.
7-18. The 1st Information Operations Command provides cyber CI elements to support TAs and VAs and
red team evaluations. INSCOM provides additional personnel allotments to each theater major subordinate
command to provide a dedicated CI LNO to each of the theater regional computer emergency response
teams.
7-19. Cyber CI operations include conducting cyber-based collection activities focused on cyber terrorist
and foreign intelligence threats that target U.S. interests. In addition to traditional CI collection, which is
conducted through the use of sources and other human or multimedia sources, cyber CI collection is
primarily conducted via the global information grid to obtain information that impacts the supported unit.
Cyber CI collection can result from ongoing CI investigations and/or operations or serve to initiate further
CI investigations and/or operations. The goal of cyber CI collection is to provide timely actionable threat
intelligence to the supported commander.
21 October 2009
FM 2-22.2
7-3
FOR OFFICIAL USE ONLY
Chapter 7
Liaison
7-20. Cyber CI elements conduct liaison with U.S., multinational, and HN military and civilian agencies,
including NGO, for the purpose of obtaining information of cyber CI interest and coordinating or de-
conflicting CI activities. Liaison activities are designed to ensure a cooperative operating environment for
cyber CI elements and to develop leads for further exploitation. This is equally true for liaison conducted
for cyber CI purposes.
7-21. CI special agents conduct debriefings of friendly force, HN, or the local population who may have
information of CI interest regarding adversary intelligence collection or targeting efforts focused on U.S.
and multinational interests. Traditional CI special agents conducting this type of collection can provide
support to the commander’s operational plans and integrated information tasks (information engagement,
command and control warfare, information protection, operations security, and military deception), as well
as identifying targets for additional cyber collection operations.
7-22. CI special agents work jointly with HUMINT collectors during screening operations to identify
civilians in the operational environment, detainees, and other noncombatants who may have information of
CI interest to develop leads. During the course of traditional screening operations, if computer software or
media is obtained from detainees, cyber CI special agents can be used in a DOMEX role to screen the
media for time-sensitive, actionable intelligence information.
Support to Analysis and Production
7-23. CI analysis is used to provide timely, accurate, and relevant all-source assessments regarding the
actual and potential foreign intelligence and terrorist threat to DOD, with the objective of protecting DOD
personnel, plans, information, research and technology, critical infrastructure, and other national security
interest.
7-24. Cyber CI analysis is a uniquely technical discipline. The cyber environment differs from the
traditional operational environment in that it is worldwide and “virtual” in nature, not theater specific. In
addition to traditional CI analytical work concerning the terrorist and FISS and ITO organizations and
operations, it requires detailed technical knowledge of information systems, Army networks, and the global
information grid.
7-25. Analysis occurs at all levels from tactical to strategic, but cyber CI analysis is operational and
strategic in nature. Because of the uniqueness of the operational environment, and the joint nature of the
defenders, cyber CI analysis is conducted by many non-CI activities as well as the Cyber Intelligence
Center of the 1st Information Operations Command and the ACIC for the Army.
7-26. At the tactical level, CI teams focus their efforts on supporting mission requirements. These tactical
CI teams have a role in providing CI support to all the information tasks. They may provide support to
CNO by performing initial incident responder duties when a dedicated cyber CI unit is not available.
7-27. Cyber CI products consist of, but are not limited to, IIRs, target nomination, CI input to TAs and
VAs, CI estimates and appendices to OPLANs and OPORDs. Finalized intelligence derived from cyber CI
activities may be incorporated into joint and national intelligence databases, assessments, and analysis
products, but must be provided in a timely manner to the supported commanders on the ground. Cyber CI
production takes place at all levels.
Support to Technical Services
7-28. CI organizations with technically trained cyber CI special agents are chartered with providing unique
technical capabilities to augment CI investigations, collection, and operations. These cyber CI technical
capabilities are not used as substitutes for traditional CI activities, but support traditional CI techniques
employed to counter and neutralize foreign (adversary) intelligence CNO activities.
7-29. In addition to supporting technical CI investigative and operational activities, cyber CI special agents
perform highly technical analytical and investigative operations to support Army CNO. Cyber CI special
agents are specially trained in the areas of computer operations, network theory and administration, and
7-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
forensics, and are instrumental in maintaining U.S. information dominance. The reliance on networked
systems will result in greater emphasis being placed on information assurance.
CYBER THREAT BRIEFINGS
7-30. In accordance with AR 381-10 and appropriate regulations cyber threat briefings are a periodic
requirement. Cyber threat briefings should—
Demonstrate CI’s understanding of the regulatory purpose and responsibilities regarding
cyber issues.
Be tailored to the audience.
Identify the cyber threat and what they are targeting.
Indicate what is reportable.
Outline responsibilities.
Provide examples of the cyber threat.
Seek to influence behaviors of those being briefed.
7-31. A good cyber threat briefing engages the audience, uses mixed media to “grab” the attention of the
audience, has easily remembered themes and goals, encourages feedback, and challenges the audience to
think like a CI agent. Finally, emphasize the importance of utilizing security patches. Over 90 percent of
intrusions into Army networks are due to a lack of patching.
7-32. The trusted insider is the most serious threat to DOD information systems security. The following list
of indicators that could be associated with an insider threat should be addressed during threat briefings to
CI customers:
Unauthorized attempts to elevate privileges.
Unauthorized sniffers.
Suspicious downloads of sensitive data.
Unauthorized modems.
Unexplained storage of encrypted data.
Anomalous work hours and/or network activity.
Unexplained modification of network security-related operating system settings.
Unexplained modification of network security devices such as routers and firewalls.
Malicious code that attempts to establish communication with systems other than the one
which the code resides.
Unexplained external physical network or computer connection.
Unexplained modifications to network hardware.
Unexplained file transfer protocol (FTP) servers on the inside of the security perimeter.
Unexplained hardware or software found on internal networks.
Network interface cards that are set in a “promiscuous” or “sniffer” mode.
Unexpected open maintenance ports on network components.
Any unusual activity associated with network-enabled peripheral devices, such as printers and
copiers.
21 October 2009
FM 2-22.2
7-5
FOR OFFICIAL USE ONLY
Chapter 7
Any unusual or unexplained activity focused on transfer devices authorized for moving data
across classification boundaries.
Unexplained attacks appearing to originate from within the local network.
Attacks against specific network devices, such as intrusion detection systems, originating
internal to the local network.
Unexplained scans for vulnerabilities originating internal to the local network.
Serious vulnerabilities remaining uncorrected after multiple notifications to the responsible
individual to correct the problem.
Unusual interest in network topologies (firewalls, security hardware or software, inter-site
connectivity, trust relationships).
Unexplained interest in penetration and/or vulnerability testing of the network.
Unexplained hidden accounts or expected levels of privilege.
Unauthorized attempts to elevate privileges.
Attempts to introduce software unapproved for the computing environment.
Individuals with access displaying undue affluence, unexplained travel, unexplained foreign
contacts, unwillingness to take vacation, unwillingness to allow someone to assume their
duties, exploitable conduct, abnormal behavior, unexplained and/or extensive technical
computer-related knowledge.
Unauthorized modem connections.
Encrypted telephonic communication on lines not specifically identified as normally used for
encrypted traffic.
Excessive, unusual, and/or unexplained computer connections over the telephone
infrastructure to foreign countries (as identified by traffic analysis or other means).
Unexplained devices associated with the telephone infrastructure or the connections between
the telephone and computing infrastructures.
Open remote maintenance ports in telephone infrastructure devices.
COMPUTER NETWORK INCIDENT CATEGORIES
7-33. Computer network incidents are identified by category depending on what type of incident occurs. If
the incident is deemed a crime, law enforcement takes the investigative lead. If it is determined the incident
is of a foreign threat nature, CI will conduct the investigation. The nine categories of computer network-
related incidents are listed below:
Category 1Root level intrusion (incident). Unauthorized privileged access (administrative
or root access) to a DOD system.
Category 2User level intrusion (incident). Unauthorized non-privileged access (user level
permissions) to a DOD system. Automated tools, targeted exploits, or self-propagating
malicious logic may also attain these privileges.
Category 3Unsuccessful activity attempt (event). Attempt to gain unauthorized access to
the system, which is defeated by normal defensive mechanisms. Attempt fails to gain access
to the system (for example, attacker attempt valid or potentially valid username and password
combinations), and the activity cannot be characterized as exploratory scanning. Can include
reporting of quarantined malicious code.
7-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Category 4Denial of service (incident). Activity that impairs, impedes, or halts normal
functionality of a system or network.
Category 5Noncompliance activity (event). This category is used for activity that due to
DOD actions (either configuration or usage) makes DOD systems potentially vulnerable (for
example, mission security patches, connections across security domains, installation of
vulnerable applications). In all cases, this category is not used if an actual compromise has
occurred. Information that fits this category is the result of non-compliant or improper
configuration changes or handling by authorized users.
Category 6Reconnaissance (event). An activity (scan or probe) that seeks to identify a
computer, an open port, an open service, or any combination for later exploitation. This
activity does not directly result in a compromise.
Category 7Malicious logic (incident). Installation of malicious software (for example,
Trojan, backdoor, virus, or worm).
Category 8Investigating (event). Events that are potentially malicious or anomalous
activity deemed suspicious and warrants, or is undergoing, further review. No event will be
closed out as a category 8. Category 8 will be re-categorized to appropriate categories 1
through 7 or 9 before closure.
Category 9Explained anomaly (event). Events that are initially suspected as being
malicious but after investigation are determined not to fit the criteria for any of the other
categories (for example, system malfunction or false positive).
7-34. At a minimum, categories 1, 2, 4, and 7 incidents are reported to DOD law enforcement and/or CI.
All incidents involving potential or actual compromise of classified systems or networks are reported
through standard CND technical reporting channels.
7-35. AR 25-2 and AR 381-12 outline the commander’s requirements for reporting such incidents to law
enforcement and CI. Title 18, USC, authorizes those who monitor DOD networks for defensive purposes to
share the results of that monitoring with law enforcement and CI. Cyber incident reporting should identify
the following relevant information when available:
Intruder and the victim system.
Originating IP address and path to the victim system used by the intruder.
Owner of the originating IP address.
Date and time of the intrusion and the duration the intruder had access to the victim system.
(Use Zulu time.)
Degree of access obtained by the intruder (for example, user or root level access).
Classification level, function
(for example, web server, domain name server), operating
system, and IP address of the victim system.
Any external security systems, such as ASIM, Netranger, or any other monitoring system—
this is done for additional sources—and did the monitoring system detect the activity and alert
appropriate personnel.
The hacking technique used in the incident or intrusion.
How the technique exploited the victim system (use great detail).
If the technique exploited a known vulnerability in the information system; if so, provide
details about the vulnerability.
If the system had a security patch or update available that could have prevented the incident
and why the patch was not utilized.
21 October 2009
FM 2-22.2
7-7
FOR OFFICIAL USE ONLY
Chapter 7
If the technique is being used to target other systems or networks and details about the other
victims and systems.
History of the technique and if it is being used by known hackers or other organizations
known to be involved in CNO, including FISS and ITO.
Results of any inquiry or investigation into the incident.
Defensive and investigative actions taken in response to the incident.
Extent of the damage, both actual and potential, caused by the incident.
Any links between the incident and any previous incidents on DOD systems.
If the victim has been the victim of previous incidents (provide details).
CYBER INDICATORS OF COUNTERINTELLIGENCE INTEREST
7-36. Unexplained anomalies occur on DOD networks on a daily basis. Some of the anomalies that may be
of CI interest are listed below:
Encrypted data or net flows.
Unusual login times or failures.
Unauthorized modification of system files and logs.
Unauthorized modification of firewall rules.
Unexplained connectivity—physical or network.
Anomalous hardware and software.
Network interface card in “promiscuous” or “sniffer” mode.
Unusual network traffic on internal network.
Scanning activity, internal or external.
Uncorrected vulnerabilities after multiple notifications.
Unusual interest in network or systems configuration
(topologies,
firewalls,
security
measures, trust relationships).
Unusual interest in penetration or vulnerability testing.
Unexplained hidden accounts or levels of privilege.
Attempts to introduce unauthorized software.
Attempts to obtain an exception to security policy.
Unauthorized attempts to gain access.
Attempts to exceed authorized access or elevate privileges.
Vendor-initiated attempts to install or upgrade hardware or software.
Unexplained activity of programs or processes.
Unexplained connectivity of programs or processes.
Unexplained storage of encrypted files.
Unauthorized modem connections.
Excessive, unusual, and/or unexplained foreign connectivity (network or modem).
Open remote maintenance ports on automated telephone switchboards.
7-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
RECOGNIZING POTENTIAL EVIDENCE
7-37. Although CI desires to ultimately exploit a situation to further develop information about adversarial
personnel, cells, leadership, and TTP, the opportunity for an arrest or detainment may eventually evolve
from any situation, and the proper handling of evidence will play a major role in ensuring prosecution and
punishment. Computers and digital media are increasingly involved in cases of espionage and/or terrorism.
In these cases, the computer may be contraband, fruits of the crime, a tool of the offense, or a storage
container holding evidence of the offense.
7-38. Investigation of any activity that may be of CI interest may produce electronic evidence. Computers
and related evidence range from the mainframe computer to the pocket-sized personal data assistant (PDA)
to the floppy diskette or CD, a video gaming system, television with built-in recording chip, or the smallest
electronic chip device. Images, audio, text, and other data on these media are easily altered or destroyed. It
is imperative that CI special agents recognize, protect, seize, and search such devices in accordance with
applicable policies, guidelines, and procedures. The following questions need to be answered to determine
the role of the computer in relation to the offense:
Is the computer contraband or fruits of a crime?
Was the computer software or hardware stolen?
Is the computer system a tool of the offense?
Was the system actively used by the accused to commit the offense?
Were fake IDs or other counterfeit documents prepared using the computer, scanner, or
printer?
Is the computer system only incidental to the offense; that is, being used to store evidence of
the offense?
Is a terrorist using the system to maintain contacts or rosters?
Is the computer system both instrumental to the offense and a storage device for evidence?
Did the hacker use the computer to attack other systems and also to store stolen DOD
information?
7-39. Once the computer or electronic device role in the offense is understood, the following essential
questions need to be answered:
Is there probable cause to seize hardware?
Is there probable cause to seize software?
Is there probable cause to seize data?
Where will the search be conducted:
Is it practical to search the computer system on site or must the examination be conducted
at a field office or laboratory?
Is it essential for the investigation to do a surreptitious mirror imaging of the hard drive
rather than a search and seizure?
Considering the massive storage data on today’s systems, how will computer forensics
experts search the data in an efficient, timely manner?
SEARCH AND SEIZURE
7-40. In preparation for search and seizure of electronic systems, it is essential to keep in mind that using
evidence obtained from a seizure in a legal proceeding requires—
21 October 2009
FM 2-22.2
7-9
FOR OFFICIAL USE ONLY
Chapter 7
Appropriate collection techniques to avoid altering or destroying evidence.
Forensic examination of the system completed by trained cyber CI personnel in a timely
manner with expert testimony available at trial.
Note. Preparation for search and seizure must include a review of AR 381-10, chapter 7, to
determine how to proceed to obtain approval.
7-41. CI special agents must determine if the search warrant or the consent search is more practical for a
particular situation.
The search warrant allows for the search, seizure, and examination of electronic evidence as
predefined under the warrant. This method is preferred and consistently is met with the least
resistance at the scene and in the courts.
A consent search and/or seizure allows the individual giving consent an opportunity to
withdraw consent at any time during the search and seizure. Continued consent is typically
difficult to ensure if the examination process is conducted at a later date and another location.
It would be advisable to contact the prosecutor when executing consent searches for
computers for this reason.
7-42. Search warrants for electronic storage devices typically focus on two primary sources of information:
Electronic storage device search warrant
(search and seizure of hardware, software,
documentation, user notes, and storage media).
Service provider search warrant (service records, billing records, subscriber information).
Request information via appropriate search warrant, subpoena, or court order from a variety
of providers (wireless or cellular service, satellite service, electronic data storage, financial
institution, Internet, pager).
7-43. Once the computer’s role is understood and legal requirements are fulfilled, CI special agents must—
Secure the scene:
Agent safety is paramount.
Preserve area for potential evidence and/or fingerprints.
Immediately restrict access to computers and attached peripherals. (Keep in mind there
are many methods to remotely access computers.)
Secure the computer as evidence:
If computer is off, do not turn it on.
If computer is on, consult a computer forensics specialist. If a specialist is not available,
photograph the screen, then disconnect all power sources and unplug from the back of the
computer. Interrupting power from the back will defeat an uninterruptible power supply.
Laptops often have battery power supplies. If the laptop does not shutdown when the
power cord is removed, locate and remove the battery pack. The battery is commonly
placed on the bottom, and there is usually a button or switch that allows for the removal
of the battery. Once the battery is removed, do not return it to or store it in the laptop.
Removing the battery will prevent accidental start-up of the laptop.
Place evidence tape over each drive slot.
Photograph or diagram and label back of computer components with existing
connections.
Label all connector and cable ends to allow reassembly as needed.
7-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
If transporting is required, package components and transport or store components as
fragile cargo.
Keep away from magnets, radio transmitters, and other potentially damaging elements.
Collect instruction manuals, documentation, and notes.
(User notes may contain
passwords.)
For networked computers, consult a computer specialist for further assistance. Secure the
scene and do not let anyone touch the system except personnel trained to handle network
systems. Pulling the plug could result in severe damage to the system or network, disruption
of legitimate business, or create liability.
7-44. Other electronic devices may contain viable evidence associated with a national security crime of
interest to CI. Unless an emergency exits, do not access any device that may be seized. Should it be
necessary to access the device, note all actions associated with the manipulation of the device to document
the chain of custody and protect the integrity of the evidence.
7-45. Wireless telephones provide users with mobile communications using various protocols and formats
(for example, code division multiple access, time division multiple access, global system for mobile) in
various frequencies (for example, 900 MHz, 1.2 GHz).
Potential evidence contained in wireless telephone devices include—
Numbers called.
Names and addresses.
Caller ID for incoming calls.
Other information contained in the memory of the wireless telephone device include—
Phone and pager numbers.
Names and addresses.
PIN numbers.
Voice mail access numbers.
Voice mail password.
Debit card numbers.
Calling card numbers.
Email and Internet access information.
Service provider information.
On-screen image, which may contain other valuable information.
A wireless telephone, which may also serve as a PDA.
Information on financial and retail transactions.
If the phone is on, do not turn it off:
Turning off the phone could activate a lockout feature.
Write down all information on display and photograph if possible.
Power down before transport if transport is likely to take so long the device will lose
complete battery power.
21 October 2009
FM 2-22.2
7-11
FOR OFFICIAL USE ONLY
Chapter 7
If the device is off, do not turn it on:
Turning it on could alter evidence on the device.
Upon seizure, deliver device to an expert as soon as possible.
Delays in conducting the examination may result in loss of information if power supply
becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Anticipate a compulsory process (for example, subpoena) for the service provider to
supply additional information.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-46. Cordless telephones provide users with freedom of movement with the wireless handheld transmitter
or receiver as long as the user remains within the range of the telephone base station. The base station
serves as the connection between the wireless device and the physical wire connection for telephone
service.
Potential evidence contained in cordless telephone devices include—
Numbers called.
Numbers stored for speed dial.
Caller ID for incoming calls.
Other information in the memory of cordless telephones include—
Phone and pager numbers.
Names and addresses.
PIN numbers.
Voice mail access number.
Voice mail password.
Debit card numbers.
Calling card numbers.
On-screen image, which may contain valuable information.
If the phone is on, do not turn off:
Turning off the phone could activate a lockout feature.
Write down all information on display and photograph if possible.
Power down before transport if transport is likely to take so long the device will lose
complete battery power.
If the device is off, do not turn it on:
Turning it on could alter evidence on the device.
Upon seizure, deliver device to an expert as soon as possible.
Delays in conducting the examination may result in loss of information if power supply
becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
7-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Anticipate a compulsory process (for example, subpoena) for the service provider to
supply additional information.
Be aware that some home systems are becoming network connected.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-47. Answering machines provide users with a means to capture messages from callers unable to reach
the device owner or operator. Some answering machines double as a phone. These devices store messages
on tape or in digital memory.
Potential evidence contained in answering machines include—
Incoming and outgoing messages.
Home systems are becoming network connected.
Numbers called.
Numbers stored for speed dial.
Caller ID for incoming calls.
The same type of information in memory as the cordless phones.
If the device is on, leave it on:
Turning off the device could activate a lockout feature.
Some have remote access and must be disconnected from the line as soon as possible
(incoming calls can delete evidence).
Write down all information on display (photograph if possible).
If possible, use a tape recorder to record saved messages.
Power down if transport would take so long that device would lose total battery power.
If the device is off, leave it off:
Turning it on could alter evidence.
Upon seizure, deliver device to an expert as soon as possible.
Delays in conducting the examination may result in loss of information if power supply
becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Anticipate a compulsory process (for example, subpoena) for the service provider to
supply additional information.
Be aware some home systems are becoming network connected.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-48. Caller ID devices collect caller information. Often these devices display incoming calls and record
established numbers of recent incoming call records.
Potential evidence contained on caller ID devices include—
Telephone and subscriber information from incoming telephone calls.
Date and time of incoming calls.
21 October 2009
FM 2-22.2
7-13
FOR OFFICIAL USE ONLY
Chapter 7
If the device is on, leave it on:
Interruption of the power supply to device may cause loss of data if not protected by
internal battery back-up.
Document all stored data before seizure or loss of data may occur.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-49. Electronic paging devices are becoming more sophisticated and some have evolved into two-way
messaging systems. The pagers that provide such features receive wireless information and transmit
information as well.
Potential evidence contained in paging devices must be handled carefully.
Numeric pagers receive only numeric digits (can be used to communicate numbers and
code).
Alphanumeric pagers receive numbers and letters and carry full text.
Voice pagers transmit voice communications, sometimes in addition to alphanumeric
communication.
Two-way pagers contain incoming and outgoing messages.
Once a pager is no longer in proximity to suspect, turn it off.
Note. Continued access to electronic communications over a pager without proper authorization
can be construed as unlawful interception of electronic communications (consult legal).
Delays in conducting the examination may result in loss of information if power supply
becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
May also require service provider search warrant to obtain additional information.
Turn it off if necessary.
Change batteries if necessary.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-50. Fax machines provide the user with the ability to transmit documents via phone line from one point
to another.
Fax machines can contain—
Speed dial list.
Stored faxes (incoming and outgoing).
Fax transmission logs (incoming and outgoing).
Header line.
Clock setting.
If the fax machine is off, leave it off. If Fax is on, leave it on if possible:
Powering down may cause loss of last number dialed and/or stored Faxes—see
manufacturer’s manual if possible to power down.
7-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Record saved data before powering off if necessary.
Take photographs.
Other considerations regarding Fax machines:
Record telephone line number Fax is plugged into.
Record network line number Fax is plugged into.
Header line should be the same as the phone line (user sets the header line).
Some Fax machines are also copiers, scanners, and printers.
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-51. Smart cards and magnetic stripe cards serve many functions, but possess similar characteristics. Both
cards interface with a reader device capable of interpreting information stored on the magnetic stripe or
computer chip embedded in the plastic card. The most familiar application of these technologies is the
credit card. These technologies lend themselves to many additional applications because they are capable of
storing any kind of information. These applications include, but are not limited to, driver’s licenses, hotel
room keys, passports, benefit cards, and security door passes. These technologies can also exist on a card
together. (Example uses: point of sale transactions, ATM capabilities.)
7-52. There are two basic types of smart cards:
First is a memory card which is merely a digital storage device capable of holding large stores
of information.
Second is a microprocessor card which is basically a small computer capable of completing a
number of calculations.
7-53. The functionality provided in these cards allows for more robust security in protecting embedded
information. The card readers for these cards can also be contact or proximity based. Uses include direct
exchange of value between card holders, exchange value over the Internet, storing data or files similar to a
computer, wireless telephones, and satellite service devices.
7-54. Magnetic stripe cards can be identified by a black or brown strip that runs across a card. To
accurately read the information, magnetic stripe readers must include the capability to read the various
tracks. This technology can also be used in a paper or disposable format such as metro passes or parking
passes.
7-55. Circumstances raising suspicion concerning smart and magnetic stripe cards include—
Numerous cards with different names or same issuing vendor.
Signs of tampering (cards are found in the presence of computer or other electronic devices).
7-56. Questions that must be answered when encountering smart or magnetic stripe cards include—
To whom is the card issued (valid card holder)?
Who issued the card?
What are the uses of the card?
Why does the person have numerous cards?
Is there a device or computer present that can alter the card?
7-57. When seizing smart or magnetic stripe cards—
Photograph the card.
Label and identify characteristics of the card.
21 October 2009
FM 2-22.2
7-15
FOR OFFICIAL USE ONLY
Chapter 7
Detect possible alterations or tampering during initial examination.
Identify who possessed the card and exactly where it was found (separation from genuine
identification and cards may help establish intent).
7-58. ID card printers offer users the ability to print graphics and information onto a plastic card. They can
be used to produce counterfeit false identification. ID card printers—
Contain stored data.
Should not be powered down if found on unless necessary.
Should be checked to see if connected to network, are stand alone, or are portable.
With instruction manuals, power chargers, power cables, and any peripherals belonging to the
device should be seized.
7-59. Scanners allow for the creation of a computer image of documents, papers, or items placed on the
scanner bed. Some scanners are also copiers, printers, and Fax machines. Scanners—
Contain stored data.
Should not be powered down if found on unless necessary.
With instruction manuals, power chargers, power cables, and any peripherals belonging to the
device should be seized.
7-60. Printers allow for the hardcopy creation of items generated by computers. There are many printer
technologies including laser, ink jet, thermal dye, and dot matrix. Printers—
Contain stored data.
Should not be powered down if found on unless necessary.
Should be checked to see if connected to network, are standalone, or are portable.
7-61. Other considerations regarding printers:
Record telephone line number system is plugged into.
Record network line number system is plugged into.
Some printers are also copiers, scanners, and Fax machines.
Seize the instruction manual, power charger, power cables, and any peripherals belonging to
the device.
7-62. Copiers allow for the duplication of items placed on the copying surface. Copy machines contain—
Speed dial lists.
Stored copies (incoming and outgoing).
Data files (complete images or documents from computers in a network environment).
Copy transmission logs (incoming and outgoing).
Header line.
Clock setting.
7-63. Other considerations for copiers:
If found on, do not turn off unless necessary.
Check to see if it is network connected, standalone, or portable.
Record telephone line number system is plugged into.
7-16
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Record network line number system is plugged into.
Some copiers are also printers, scanners, Fax machines.
Seize the instruction manual, power charger, power cables, and any peripherals belonging to
the device.
7-64. Compact disk duplicators and labelers allow for the mass creation of compact disks. When used
inappropriately, these devices may be used for sedition and/or subversion support operations.
Compact disk duplicators and labelers contain stored data.
If found on, do not turn off unless necessary.
These systems may be connected to the network, may be standalone, or may be portable.
Some networked systems contain proprietary hard drives that store images.
Seize the instruction manual, power charger, power cables, and any peripherals belonging to
the device.
7-65. Digital cameras, video, and audio media can be recorded as analog or digital information. Many
different formats of media are available within both analog or digital. Devices may be standalone,
networked, personal, home entertainment, or business (for example, text, still images, graphics, date/time,
author, system used).
7-66. Some devices may have basic personal computing functions or may be a computer device itself.
Devices are found as portable and fixed devices, but can be easily moved. Devices may store data directly
to internal memory and/or removable media. If device is found off, do not turn it on. If found on, consult a
specialist.
7-67. If no specialist is available—
Identify and secure recorded media and media system.
If recorded media needs to be reviewed immediately, do not pause tape media unless
absolutely necessary. Pausing tape media, both video and audio, causes irreversible wear
(damage) to the tape resulting in poor image and/or audio quality.
Immediately secure record tabs on the media to prevent accidental overwrite (recording).
7-68. Securing the system or device:
Photograph device (screen or display), then disconnect all power sources; unplug from the
back of the device. If unable to do so, recover and consult with a specialist as soon as
practical.
Place evidence tape over areas of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
Label all connector and cable ends to allow reassembly as needed.
If transport is required, package components and transport or store components as fragile
cargo.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Seize the instruction manual, power charger, power cables, and any peripherals belonging to
the device.
21 October 2009
FM 2-22.2
7-17
FOR OFFICIAL USE ONLY
Chapter 7
7-69. Electronic gaming devices now provide users with greater functionality and are increasingly more
comparable with a computer. Electronic gaming devices—
May contain stored data—text, images, audio, video, other.
May have Internet access information including emails.
May contain basic personal computing functions.
Should not be turned on if found in off position.
May be found in the on position; in this case, consult a specialist if possible. If a specialist is
not available—
Photograph device (screen or display), then disconnect all power sources; unplug from
the back of the device. If unable to do so, recover and consult with a specialist as soon as
practical.
Place evidence tape over areas of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
Label all connector and cable ends to allow reassembly as needed.
If transport is required, package components and transport or store components as fragile
cargo.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
7-70. Home electronic devices provide users with a greater degree of interaction with the device. The
devices range from interactive television guides to smart kitchen appliances, such as microwaves, that store
messages for other family members or refrigerators that keep track of food in its inventory. Home
electronic devices—
May contain stored data (for example, text, images, audio, video, other).
May contain Internet access information including emails.
May have telephone capabilities.
May perform basic personal computing functions.
May be standalone or networked either at home or through an off-site location.
Should not be turned on if found in off position.
May be found in the on position; in this case, consult a specialist if possible. If specialist is
not available—
Photograph device (screen or display).
Play back and record with a tape recorder if device has a readily discernable audio
playback feature.
Disconnect all power sources; unplug from the back of the device. If unable to do so,
recover and consult with a specialist as soon as practical.
Place evidence tape over areas of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
7-18
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Label all connector and cable ends to allow reassembly as needed.
If transport is required, package components and transport or store components as fragile
cargo.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
Ensure care is given to the ability of these systems to be remotely accessed. These
systems are typically operated through a service provider. Data may not be stored on the
system.
May require a service provider search warrant to obtain additional information.
7-71. GPSs provide users with the ability to locate their position on the Earth’s surface by measuring
signals transmitted by satellites. These devices assist with navigation and can integrate maps to help users
travel from one point to another. GPSs—
May store data including text, images, and maps.
May have Internet access information.
May contain a two-way radio capability.
May have telephone capabilities.
May contain routes and marked locations.
Can keep track of time lines.
Should not be turned on if found in off position.
Can be found as an integrated part of other portable devices (for example, palm devices, mini-
notebooks, notebook PCs, and digital cameras).
May be found in the on position; in this case, consult a specialist if possible. If specialist is
not available—
Photograph device (screen or display), then disconnect all power sources; unplug from
the back of the device. If unable to do so, recover and consult with a specialist as soon as
practical.
Place evidence tape over areas of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
Label all connector and cable ends to allow reassembly as needed.
If transport is required, package components and transport or store components as fragile
cargo.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
21 October 2009
FM 2-22.2
7-19
FOR OFFICIAL USE ONLY
Chapter 7
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
Ensure care is given to the ability of these systems to be remotely accessed. These
systems are typically operated through a service provider. Data may not be stored on the
system.
7-72. PDAs and handheld computers provide users with much of the functionality of full-size personal
computers, but are small in size. Palm devices—
May store data including text, images, and maps.
May have Internet access information including emails.
May contain directories.
May have basic personal computing functions.
May be standalone or networked within a home or an off-sight location.
Can keep track of time lines.
Should not be turned on if found in off position.
May be found in the on position; in this case, consult a specialist if possible. If specialist is
not available—
Photograph device (screen or display), then disconnect all power sources; unplug from
the back of the device. If unable to do so, recover and consult with a specialist as soon as
practical.
Place evidence tape over areas of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
Label all connector and cable ends to allow reassembly as needed.
If transport is required, package components and transport or store components as fragile
cargo.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
Ensure care is given to the ability of these systems to be remotely accessed. These
systems are typically operated through a service provider. Data may not be stored on the
system.
Keep away from magnets, radio transmitters.
May require a service provider search warrant to obtain additional information.
7-73. Security systems are installed as protective measures and are often positioned in strategic locations
and can prove to be valuable information for an investigation. Security systems—
May store data including text, images, and maps.
May include time stamp information.
May be standalone or networked via the Internet or a private network.
Should not be tampered with except by a trained specialist.
7-20
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Cyber Counterintelligence
Must be secured. If a specialist is not available, immediately secure recorded data (for
example, videotape media) and collect as much of the following information as possible:
Make and model.
Personal computer-based system or video-based system.
Number of cameras.
Type of cameras.
Locations of system.
Location of cameras.
Recording media.
Media stored and archived.
Photographs or video of system.
7-74. Vehicle computer devices provide users with many computer features within their vehicle. They may
contain stored data such as text, images, maps, audio, Internet access information, telephone capabilities,
routes, marked locations, time lines, and emails. The device can be portable or fixed.
If the device is found off, do not turn it on. If it is found on, consult a specialist. If a specialist
is not available—
Photograph the device (screen or display), then disconnect all power sources (unplug
from back of device). Most systems are built into the vehicle’s interior, integrated into the
dash or console areas making it impractical to remove. Actual data may even be stored
elsewhere in the vehicle.
Place evidence tape over area of access (for example, drive slots and media slots).
Photograph or diagram and label back of components with existing connections.
Label all connector and cable ends to allow reassembly as needed.
Conduct examination as soon as possible to avoid possible loss of information if power
supply becomes insufficient through battery or internal power supply.
Take appropriate care in the handling and storage (for example, cold or dampness).
Seize the instruction manual, power charger, power cables, and any peripherals belonging
to the device.
Ensure care is given to the ability of these systems to be remotely accessed. These
systems are typically operated through a service provider. Data may not be stored on the
system. These systems may be integrated with many systems including communications,
navigation, security, safety, entertainment, personal computing, Internet, digital audio
and imaging into networked environments supported at the home, workplace, public
services, and portable devices. They may also require a service provider search warrant to
obtain addition information.
7-75. Storage media is used to store data from an electronic device. Some devices have fixed storage space
located within the device. This form of storage requires a means of interfacing to another source to transfer
the data when necessary. Many devices of today have capabilities for both fixed (internal) storage or
memory and the ability to also store data solely or simultaneously to removable storage media. Removable
media is used to transfer and store data.
7-76. Some of these media types come in many variations, and there are numerous other types currently in
use that are not as prevalent and even more are being introduced into the market on a regular basis.
21 October 2009
FM 2-22.2
7-21
FOR OFFICIAL USE ONLY
Chapter 7
Although there are some standards, the following list is some of the more common and well-established
media types found in the consumer and commercial marketplace:
Floppy disk.
Mini-disk.
Flash memory card.
External hard drive.
Digital linear tape.
High-density floppy disk.
Compact disk (CD) LS-120 (super disk).
Click.
Smart media.
Micro-drive.
Digital audio tape.
Digital video disk.
Zip.
Memory stick.
Removable hard drive.
Magneto optical drive.
7-22
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Chapter 8
Investigative Legal Principles
Within the DOD, the controls on intelligence collection activities are set forth in
DODD 5240.1 and DOD 5240.1-R. The Army’s policy governing intelligence
collection activities is AR 381-10, which implements EO 12333 and the DODD and
publication.
INTELLIGENCE OVERSIGHT
8-1. Intelligence oversight arises from the same source that created EO 12333. AR 381-10 sets forth the
policies and procedures governing the conduct of intelligence collection activities, both by designated
Army intelligence components and by personnel not assigned to an intelligence component which conducts
intelligence collection activities.
8-2. AR 381-10 does not, in and of itself, authorize intelligence activity—it simply sets forth the policies
and procedures for conducting such activities, provided the personnel conducting collection have the
appropriate mission and authority. Generally, intelligence oversight applies only to the collection of
information on U.S. persons. This does not mean that AR 381-10 is inapplicable when conducting
collection against non-U.S. persons; it still applies and sets forth approval authorities for such non-U.S.
person collection. Rather than not applying, authority to collect may be granted at a much lower level, in
most cases, when conducting collection against a non-U.S. person.
COMPETENCE
8-3. The importance of understanding and complying with these policies cannot be overemphasized. It is
imperative that individuals engaged in CI or other intelligence activities read and understand AR 381-10. In
particular, they must understand the following concepts:
The requirement that an Army element must have the mission and authority to conduct
specific intelligence activity before a determination is made regarding the ability to collect
information on a U.S. person.
The definition of the terms “collection” and “U.S. person” (chapter 2).
The retention and dissemination of information about U.S. person (chapters 3 and 4).
The definitions of special collection techniques and what approvals are required (chapters 5
through 9).
The definition of questionable intelligence activities, and the reporting of such activities.
What Federal crimes must be reported, and how.
ROLE OF INTELLIGENCE PERSONNEL IN PROTECTION ACTIVITIES
8-4. AR 381-10 sets forth the role of the SJA as a legal advisor to intelligence personnel. CI special
agents should always seek legal advice from their local supporting SJA on the interpretation and
application of the procedural guidelines contained in the regulation.
8-5. Agents should rely on a trained lawyer’s interpretation when planning to implement any of the
special collection procedures.
21 October 2009
FM 2-22.2
8-1
FOR OFFICIAL USE ONLY
Chapter 8
Basic Understanding
8-6. Because of the nature of their work, CI special agents must understand the basic legal principles.
Decisions made by the CI special agent are frequently guided by legal concepts and can have far-reaching
implications on the investigation, sometimes very negative.
8-7. Understanding the legal principles allows the CI special agent to recognize potential legal pitfalls and
seek assistance before the investigation can be damaged. Only a CI special agent who is familiar with the
governing legal principles is able to recognize and conduct these tasks efficiently, and within the
parameters of the law.
Requirement
8-8. AR 381-10, chapter 14, states that employees shall conduct intelligence activities only pursuant to
and in accordance with EO 12333 and AR 381-10.
8-9. In conducting such activities, employees shall not exceed the authorities granted the employing DOD
intelligence components by law, Executive orders including EO 12333, and the applicable DOD and Army
directives.
Reporting Questionable Activities
8-10. AR 381-10, chapter 15, requires intelligence employees to report any questionable activity that may
be a known or suspected violation of AR 381-10. CI special agents should bear in mind that the definition
of questionable activity is very open-ended: any intelligence activity or related activity that might violate
any law, any Executive order, any Presidential directive, any applicable DOD policy, or any applicable
Army policy.
8-11. Questionable activities must be reported either through command channels or directly to the DA
Inspector General (with a courtesy copy to the DA G-2) within 5 work days. CI special agents should look
to chapter 15 for specific details on reporting questionable activities.
Reporting Federal Crimes
8-12. AR 381-10, chapter 16, requires intelligence employees to report violations of Federal law, both
those committed by intelligence component employees and those committed by non-intelligence
employees. With respect to intelligence component employees, any violation of any Federal law must be
reported. With respect to non-intelligence component employees, the crimes that must be reported are more
limited, and generally focus on crimes involving death or serious bodily injury, or those that constitute a
national security crime. Federal crimes should be reported through the chain of command, and must reach
DA G-2 within five work days.
Note. In addition to the common crimes, there are additional crimes which may create a conflict
for the CI special agent. Unauthorized disclosure of classified material or unauthorized access to
information systems by any person, intelligence or not, must be reported. Unfortunately,
AR 381-10, chapter 16, directs that such reports go through the chain of command, whereas
AR 381-20 and AR 381-12 direct the CI special agent to report a potential CI incident through
the ATCICA to the ACICA. In order to protect himself, the CI special agent should note in the
remarks section of his report that the incident being reported through the ATCICA to the ACICA
is also reportable under AR 381-10, chapter 16, and should be reported to the DA G-2 as such.
JURISDICTION
8-13. Jurisdiction refers to the legal authority of Army CI to conduct investigations of national security
crimes or other service-identified incidents of CI interest affecting Army equities. EO 12333 establishes the
authority for DOD to conduct CI activities to support DOD missions inside and outside the United States.
8-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
Additionally EO 12333 establishes the FBI as the lead agency for CI within the United States and the CIA
outside the United States.
8-14. Title 10, USC, establishes the Secretary of Army’s authority to write regulations and policy to
govern and regulate the activities of the different branches and divisions within the Army, including CI.
However, due to the overlap in CI mission areas within the DOD services and other U.S. Government
agencies, the 1979 Delimitations Agreement amended in 1996, establishes operational primacy for the
different agencies with a CI mission based upon the persons and the incidents involved in a suspected
national security crime.
8-15. The Delimitations Agreement was implemented to establish operational boundaries, deconflict CI
activities among all CI elements in the intelligence community, and define investigative primacy over
specific national security crime incidents. AR
381-20 provides Army specific policy and guidance
concerning Army CI missions and activities including investigations and corresponding investigative
jurisdiction. AR 381-10 provides detailed policy and guidance on the use, justification, and approval
process for special investigative techniques used to support CI investigations. Jurisdiction is derived from
two different criteria: jurisdiction over the person and jurisdiction over the incident.
JURISDICTION OVER THE PERSON
8-16. Jurisdiction over the person refers to the persons involved in suspected national security crimes or
incidents of CI interest that Army CI may focus investigative efforts to confirm or deny their involvement.
Army CI’s jurisdiction is limited to persons subject to the UCMJ, with very few exceptions.
8-17. Generally, that jurisdiction is further limited to Army Soldiers, unless DOD has granted Army CI
geographic jurisdiction over one or more sister services operating on a specific installation or operating
location:
Jurisdiction over the person within the United States:
Active duty Army Soldiers.
Retired Army Soldiers who committed the offense while on active duty.
Members of the Army Reserve (active or inactive) and the U.S. National Guard, provided
the offense occurred while they were on active duty. If the Soldier committed the crime
when they were not in a Title 10 status, Army CI will not have jurisdiction over them.
Jurisdiction over the person outside the United States:
Family members of active duty Army personnel.
Current DAC employees, including HN DAC employees, and their family members. In
some cases, this might also include former DAC employees, depending on whether they
committed the incident while employed by the Army.
Army contractors and their family members, subject to coordination with the FBI, CIA,
and HN. Contractors may or may not be covered by the SOFAs, and their family
members are almost never covered. If not covered by the SOFA, the contractor and/or
family member is completely subject to HN jurisdiction, even if they are U.S. citizens.
However, U.S. citizens that violate Federal criminal law (Title 18, USC) may still be tried
in the United States for such violations. This could mean that both the United States and
the HN have jurisdiction over the crime.
Retirees, Reservists, and National Guard Soldiers regardless of whether they committed
the offense while on active duty. However, as with contractors, if the retirees, reservists,
or National Guard Soldiers are present in that country in a non-Title 10 status, they are
subject to the jurisdiction of that country. Investigations and other actions may require
coordination.
21 October 2009
FM 2-22.2
8-3
FOR OFFICIAL USE ONLY
Chapter 8
Other U.S. citizens. As above, these individuals are subject to the jurisdiction of the HN,
and investigation and other actions require coordination.
Foreign nationals who are applicants for Army employment or are current or former
Army employees are subject to coordination with the HN government. This is a classic
example of where the HN may not assist. However, as an example, a German national
spying against the U.S. forces in Germany is not violating German law, and unless he is a
dual-U.S.-German citizen, he is also not violating U.S. law. As such, while Army CI may
have jurisdiction to investigate the actions of that German citizen, the list of post-
investigative actions are fairly limited.
Foreign nationals not associated with the Army, subject to coordination.
JURISDICTION OVER THE INCIDENT
8-18. Jurisdiction over the incident addresses whether or not the incident which occurred is one which the
agency in question is permitted to investigate or prosecute. CI incident jurisdiction is laid out in AR 381
20. CI incident jurisdiction includes both crimes under the USC, crimes under the UCMJ, and certain non
criminal incidents that have CI implications.
INVESTIGATIVE AUTHORITY
8-19. If both the persons and the incident involved in a CI investigation are within Army CI jurisdiction,
Army CI will have Primary Authority in the investigation. However, if either the person or the incident
falls outside Army CI jurisdiction, the case will be a Concurrent or Joint Authority based upon the
circumstances of the case. (See AR 381-20, chapter 4, for more details on investigative authorities.)
POSSE COMITATUS ACT
8-20. The Posse Comitatus Act prohibits U.S. military Title 10 forces from acting in a police role within
the United States unless approved by Congress. This includes participating in arrests, searches, and seizures
of U.S. persons outside the scope of a lawful Army mission. The Posse Comitatus Act does not affect any
investigations where Army CI has Primary Authority; however, in Concurrent and Joint Authority cases, it
may apply if another civilian LEA is involved due to the circumstances of the case.
CRIMINAL LAW
8-21. Although CI special agents have a fairly limited role in criminal investigations, they must understand
the basics of criminal investigations. In many ways CI investigations parallel criminal investigations; they
are not the same because they differ in purpose and mandate. That said, however, many of the laws that
apply to criminal investigations also apply to CI investigations because they share the same constitutional
foundation. Therefore, CI special agents conduct their investigation in such a way that it does not illegally
strip away a subject’s constitutional rights and result in a dismissal of the case at court-martial.
BEYOND A REASONABLE DOUBT
8-22. In order to secure a conviction against an accused, it is necessary to prove, beyond a reasonable
doubt, that the accused committed the crime of which they are accused. Although no numerical standard
can be given to this phrase, it can be described as an honest, conscientious doubt based on reason and
common sense suggested by the evidence or lack thereof.
8-23. CI special agents understand that the reasonable doubt standard requires more evidence than the
“probable cause” standard. Therefore, although CI special agents may only be required to satisfy the
probable cause standard, they should work with their unit’s assigned SJA to ensure the case is strong
enough to withstand the reasonable doubt standard.
8-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
PROOF AND ELEMENTS
8-24. Every crime is broken up in terms of “elements.” In order to secure a conviction, the government
(trial counsels on behalf of) must prove every element of the crime beyond a reasonable doubt. The CI
special agent must ensure that they review the elements of the crimes they are investigating, as well as
other possible crimes that might apply.
EVIDENCE
8-25. There are several different types of evidence. In terms of their relation to the crime, they are known
as direct or circumstantial. In terms of their relation to the world at large, they are known as physical or
testimonial:
Direct evidence. Evidence that tends to directly prove or disprove a fact that is in issue
(related to an element of the crime).
Circumstantial evidence. Evidence that does not tend to directly prove or disprove a fact in
issue, but instead tends to prove or disprove some other fact or circumstance which alone or
together with other facts allows the military judge or panel to reasonably infer the existence of
the fact in issue. Circumstantial evidence is commonly seen when trying to prove intent or
motivation without a confession.
Physical evidence. Any evidence that can be touched or held. Examples include the
traditional
“smoking gun,” a bloody glove, or DNA evidence. From the CI perspective,
physical evidence can also include photographs or video surveillance placing the subject at
the scene of the dead-drop, the TS documents the subject placed in the dead-drop, or the
money the subject later received for those documents.
Testimonial evidence. Confessions and witness statements:
In the case of confessions, the Army attempts to use the subject’s own words against
them. In order to be able to do so, however, it must be evident and proven that their
confession was knowing and voluntary, and that they were advised of their right to
remain silent. Failure to advise the subject of his rights, or even failure to do so correctly,
can result in the subject’s confession being inadmissible, and in some cases, may result in
other evidence being thrown out as well.
In the case of witness statements, the words of another person who witnessed some action
are used to prove what happened. While Army CI is not required to advise a witness of
his rights, unless they are party to a crime or otherwise admit to committing a crime, the
CI special agent must still ensure that the statement is taken correctly. With witnesses, the
CI special agent will likely have to prove that they are not biased, that they have no
interest in seeing the subject go to jail, that the CI special agent did not pay or coerce
them to say what they did, and that they are trustworthy. This does not mean that their
statement must be consensual, but when a Soldier is ordered to make a statement, the CI
special agent must ensure that such an order is documented.
DEVELOPED EVIDENCE
8-26. This is not, technically speaking, a legally recognized name. It does serve to describe an important
type of evidence, however, as it is usually used to refer to evidence that is developed through investigative
methods, as opposed to evidence found immediately at the scene of the crime.
21 October 2009
FM 2-22.2
8-5
FOR OFFICIAL USE ONLY
Chapter 8
INTENT
8-27. A big piece of many criminal acts, including almost all criminal acts within CI jurisdiction, is intent,
usually referred to as “specific intent” or “criminal intent.” Intent in these circumstances means that the
accused either—
Intended to commit the crime.
Intended the result of the act.
Or in some cases, acted in a fashion that was so outrageous that we can say that they should
have known what would result.
8-28. While there are some acts that are punishable even without intent, the most serious crimes, and
therefore, most serious punishments, almost always require criminal intent.
OTHER EVIDENTIARY CONSIDERATIONS
8-29. In addition to understanding the basic types of evidence, the CI special agent should understand the
basics of admissibility, including some of the rules which prevent evidence from being admitted.
Admissibility
8-30. Admissibility of evidence depends primarily on two factors: Is the evidence relevant, and was the
evidence obtained legally:
Relevance. The Manual for Courts-Martial and Military Rules of Evidence define relevant
evidence as any evidence having a tendency to make the existence of any fact of consequence
more or less probable than it would be without the evidence. In other words, evidence is
relevant when it tends to help prove or disprove an element of the crime.
Legally obtained. Even assuming the evidence is relevant, if it is obtained illegally, it will be
barred from court. Legally obtained includes factors such as whether the CI special agent
advised the subjects of their rights, whether they received proper approval before conducting
the intelligence collection activity, whether the information provided was covered by a
privilege, or whether the evidence is barred by “hearsay” or “fruit of the poisonous tree”
doctrine.
Note. There are different rules governing admissibility of evidence during administrative
proceedings, such as discharge boards. CI investigations will always be conducted using
appropriate legal standards and in a manner which would not jeopardize the potential for
prosecution. In the event that a court-martial is unfeasible, or the decision is made not to pursue
a court-martial, the CI special agent and the SJA will discuss how such decision will affect the
investigation. CI special agents should not, by themselves, act in a fashion that could prevent the
Government from seeking a court-martial. Such actions, without permission from the court-
martial convening authority, could violate the basic rules on intelligence oversight, and may
constitute criminal conduct on the part of the CI special agent.
Hearsay
8-31. Generally, when someone witnesses a crime, that person must testify in court against the accused,
rather than simply giving a written statement of what they saw. Attempting to use just the written statement
is what is known as “hearsay,” which means that we are trying to use their written statement to prove
“truth.” This is commonly seen as a violation of the Constitutional rights of the accused, although there are
some exceptions.
8-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
8-32. If CI special agents are concerned about getting a witness into the court room, they need to discuss
the situation with their SJA as soon as possible. This includes concerns about maintaining the
confidentiality of an informant.
“Fruit of the Poisonous Tree” Doctrine
8-33. The idea behind this doctrine is that CI special agents cannot use illegal evidence to obtain legal
evidence. Evidence that is obtained illegally will poison other evidence if that secondary evidence were
only able to be obtained because of the illegally obtained evidence.
8-34. The most commonly seen variations of this involve a CI special agent’s obtaining an illegal
confession (failure to advise of rights) which allows Army CI to locate physical evidence that would not
otherwise have been found, or a CI special agent who conducts illegal collection (not properly approved,
outside the scope of what was approved), which leads to a confession. In both cases, the secondary
evidence would almost certainly be held to be inadmissible.
Plain View
8-35. One legal concept that can often assist investigators is known as plain view. This is the idea that the
CI special agent is in a location legally and observes evidence of a crime. At that point, the evidence
observed may be collected, and will be admissible.
Authorized collection. Plain view can apply in a variety of situations. The obvious one
includes observing evidence during an authorized procedure 7 search. Less obvious includes
observing evidence during an authorized procedure 5 in which the CI special agent enters the
premises to emplace or retrieve electronic surveillance equipment and notices other evidence
of a crime.
Inspections. Plain view also applies to contraband located during an authorized inspection,
such as an inspection of cars leaving post, a health-and-welfare inspection, or an inspection of
all bags entering or leaving a SCIF.
Problems with plain view. While it is likely that the subject will know about the procedure 7
or inspection, it is entirely possible that the subject is unaware of the procedure 5, and the CI
special agent likely wishes the subject to remain unaware of the procedure 5.
Unfortunately, seizing plain view evidence observed during the procedure 5 may well
alert the subject to the fact that someone has been on the premises, and a smart subject
may reach the correct conclusion—that they are under investigation—and change their
patterns or activities, thus interfering with the investigation.
This does not mean that the CI special agent does not collect the evidence, but instead
means that the CI special agent should seek advice from the special agent in Charge or
ATCICA, as feasible, before actually seizing the evidence. Alternatives include simply
taking photographs of the evidence, and setting forth plans to prevent the evidence from
being further disseminated.
Collection and Processing of Evidence
8-36. One of the keys to ensuring that evidence, otherwise obtained legally, remains admissible is to ensure
that the proper methods of acquisition and processing are used.
21 October 2009
FM 2-22.2
8-7
FOR OFFICIAL USE ONLY
Chapter 8
Collection (acquisition) procedure. Approval to conduct the intelligence collection activity
is only the first step to obtaining evidence legally. The CI special agent will review AR 381
20, AR 195-5, and FM 3-19.13 for guidance on the proper collection of evidence. In addition,
the local CID office may provide advice on proper collection. The CI special agent may also
contact the SJA office for advice on whether or not a proposed collection method is legal or
whether it may interfere with admissibility. These guides will also assist the CI special agent
in recognizing evidence associated with security crimes, planning and conducting
investigative searches for evidence, processing evidence in accordance with Army
regulations, and presenting evidence in a criminal trial.
Preservation of evidence. In addition to properly collecting evidence, it is important that the
proper steps be taken to preserve that evidence. This refers not just the physical preservation
of evidence that can degrade or change but also to taking steps to ensure that evidence is not
tampered with. (See AR 381-20 and FM 3-19.13, chapter 19, for details on managing and
controlling evidence.)
RIGHTS AMENDMENT
8-37. According to UCMJ, article 31(b), anyone subject to the UCMJ may not elicit self-incriminating
statements from anyone else subject to the manual until that person has been advised of his rights indicated
therein. UCMJ, article 31(b), requires the subject to be informed as to the nature of the accusation, that he
does not have to make any statements regarding the offense, and that any statements made by him may be
used as evidence against him.
CONSTITUTIONAL BASIS
8-38. The Constitutional basis for the Rights Advisement lies with the
5th and
6th Amendments,
summarized as “no one may be compelled to testify against themselves; they must be informed of the
charges against them; and they are entitled to legal counsel.” These rights are often referred to as
“Miranda” rights, based on the case of U.S. v. Miranda. As a result of Miranda, the U.S. Supreme Court
held that LEAs must advise a subject or accused of their rights before conducting an interrogation or
interview.
ADMISSIBILITY OF ADMISSIONS
8-39. Rights advisement is critical because a subject’s confession or admission, if obtained by unlawful
coercion or by inducement likely to affect its truthfulness will be inadmissible. There is no relief from the
requirements of UCMJ, article 31(b), and failure to comply will result in the suppression of all statements.
The UCMJ reads, “No statements obtained from any person in violation of this article, or through the use of
coercion, unlawful influence, or unlawful inducement may be received in evidence against him (her) in trial
by court-martial.”
BASIC DEFINITIONS
8-40. There are several definitions that are key to understanding rights advisement. The bottom line is that
any time someone is held in custody because they are the suspected of a crime, and while in custody they
are interrogated by a Government agent, that person must be advised of their rights before being
questioned, and they must make a knowing, intelligent, and voluntary waiver of their rights before they can
be questioned.
Custody
8-41. These rights do not take effect unless the subject is in custody. Custody is not the same as
apprehension, however. Custody simply implies that the subject’s freedom of movement has been
restricted, that the subject does not feel free to simply walk away at will. This is particularly sensitive in the
military, where the requirements of custom and military law require a Soldier of junior rank to remain in
8-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
the presence of the NCO or officer (as long as that NCO or officer is senior) until that NCO or officer
dismisses them.
8-42. When a witness enters the CI special agent’s office, they are generally free to leave. When a subject
enters, however, they usually are not free to leave until the CI special agent has obtained basic information
about the incident or subject invokes their right to remain silent. In circumstances where the subject is
reluctant to speak with Army CI but does not specifically invoke his rights, the CI special agent should
contact the SJA for further guidance.
Interrogation
Note. The term interrogation in this FM refers to those types of interviews or situations used to
collect data to support a criminal CI investigation. Any reference to interrogation should not be
confused with the systematic collection of intelligence information from EPW/detainees during
U.S. military operations. Intelligence interrogations are only authorized to be conducted by
35M/351M or personnel trained and certified in accordance with DOD Directive 3115.09 and
FM 2-22.3. CI may debrief EPW/detainees to obtain information of CI value.
8-43. Interrogation is any word or action designed or likely to elicit an incriminating response.
Interrogation does not have to be in the form of a question-statement, and, in some cases, silence or body
language may be enough. The case of Brewer v. Williams (1977) was a famous example, in which the
arresting officer, sent to pick up Williams (the subject) in another state, was advised that Williams would
make a statement in the presence of his attorney. The officer, upon picking up Williams, did not read him
his rights and did not ask him any questions. Instead, during the drive back, he simply made statements
concerning some of what the police knew, including where the body was believed to have been hidden.
8-44. The officer finished by giving what has since become known as the “Christian Burial Speech” in
which he stated that Williams was the only one that could guarantee that the young girl he had killed would
receive a proper Christian Burial. At no time did the detective ever ask Williams a question—he simply
made statements. However, the statements, and the guilt they created, led Williams to direct the detective to
the site where he had hidden the body. Upon review, the courts determined that the detective had violated
Williams’ 5th Amendment Rights by interrogating him.
Subject/Accused
8-45. Advising someone of their rights is required when the person being questioned is suspected or
accused of a crime. If the person is simply a witness, they are not a suspect or accused, and it is not
necessary to advise them of their rights. However, during the questioning of a witness or someone not
suspected or accused, the person incriminates himself or makes an admission to any crime, the questioning
will be stopped and the person will be advised of his rights.
8-46. After the rights advisement, the questioning may continue if the person waives his rights. In cases
like this, the CI special agent should also contact the SJA depending upon the nature of the admission. The
key here for the CI special agent is simply to ask the question: Do I have probable cause to believe that the
individual I am questioning is suspected of committing a crime? If the answer is yes, treat that person as a
subject.
8-47. This is not limited to crimes within CI jurisdiction, and it is possible for a CI special agent, while
conducting an interview, to destroy another agency’s case by failing to advise the subject of his rights when
the subject starts to confess to a crime outside CI jurisdiction. CI special agents should be sensitive to this,
and if they hear something that sounds like a confession or admission, they should stop and seek advice
from the SJA office before continuing with the interview. Part of the interview process also involves
advising the person of what they are suspected or accused of doing. This should be fairly specific. If the
subject is advised of one crime, but admits to another during the interview, the CI special agent should stop
and re-advise the subject on the other crime as well.
21 October 2009
FM 2-22.2
8-9
FOR OFFICIAL USE ONLY
Chapter 8
Government Agent
8-48. Government agents include any official acting in a law enforcement capacity. This includes the
obvious CID, MP, and MP investigators. It also includes CI special agents while conducting CI
investigations. Finally, it includes others designated by law or regulation to serve as investigators. In the
military, this also includes individuals who act in an official disciplinary capacity, such as NCOs and
officers, particularly those in the chain of command.
FAILURE TO ADVISE
8-49. The failure to advise a subject of his rights can have a significant impact on the case against them,
particularly in a CI investigation. As discussed above, while some incidents under CI jurisdiction do not
require proving intent, the most serious crimes do require proof of intent. The easiest method for proving
intent is through a confession. Failing that, intent can be proven circumstantially, but that is considerably
more difficult. On top of the difficulties in proving intent, having a confession thrown out may also result
in other evidence being held inadmissible, as discussed above.
WAIVER
8-50. As mentioned above, the waiver must be knowing, intelligent, and voluntary. This means that the
subjects must understand what they are doing and saying. They cannot be under the influence of any drug
(legal or illegal) or under the influence of alcohol. They cannot even be under the influence of medication
that impairs their judgment. They must also be old enough to make a waiver—typically 18.
8-51. A waiver is an area that receives intense scrutiny from the courts, and if defense makes a credible
argument that the subject did not make a knowing, intelligent, voluntary waiver, it shifts to the Government
to prove that it was. If the CI special agent has any reason to believe that the subject is not capable of
making a knowing, intelligent, voluntary waiver, including any reason to believe that the subject is under
the influence of any drug or alcohol, the CI special agent needs to terminate the interview.
8-52. The CI special agent can work with the unit to have a blood test performed. If the individual appears
confused as to his rights or his status, the CI special agent needs to make every reasonable effort to remove
the confusion. If the CI special agent is still not comfortable that the subject understands his rights, the CI
special agent should stop the interview and seek legal advice. If the CI special agent is satisfied that the
subject understands his rights, the CI special agent will have the subject complete the waiver portion of the
DA Form 3881.
SUBSEQUENT INVOCATION
8-53. Even assuming the subject waives his rights, he may still invoke them later during the interview or
before a future interview. The subject should be read his rights before every interview, just to be certain. If
the subject invokes his rights after previously waiving them, the CI special agent must terminate the
interview. Failure to terminate may result in the loss of the entire statement. The CI special agent should
also not attempt to persuade the subject to continue with the interview.
SPONTANEOUS STATEMENTS
8-54. Spontaneous statements are statements made by a person in a situation in which the person has some
freedom of movement, but has not been advised of his rights. In situations where spontaneous statements
are made, the CI special agent will stop the interview and advise the person of his rights and attempt to
obtain a waiver and statement after the advisement.
COERCION
8-55. Coercion is strictly prohibited in the conduct of all CI investigations and investigative activities to
comply with prosecutorial standards ensure legal admissibility. The courts become concerned when the
8-10
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
subjects are put in a position where they may feel compelled to confess or make a statement based upon an
atmosphere of duress, futility, or insurmountable disadvantage. Even attempting to “persuade” the subject
to confess will usually receive significant scrutiny by courts and may render any statements or confessions
inadmissible in criminal proceedings.
METHODOLOGY
8-56. The CI special agent follows a specific methodology when interviewing a subject to ensure the
subject’s confession or admission is admissible.
Forms. The CI special agent will use the DA Form 3881 as a guide when advising a subject
of his rights. CI special agents should never attempt to recite the advisement based on their
memory. If the appropriate forms are not readily available, the CI special agent should delay
the interview until the forms are available. The CI special agents should keep a copy of the
DA Form 3881 printed with their standard case material as a backup.
Read verbatim. The CI special agent should read directly from the form or card, without
deviation, every single time. The CI special agent should follow the script, and obtain the
necessary initials, as outlined in the step-by-step guide in this manual. Following the same
methodology every time helps ensure that statements will be admissible.
Tone of voice. The CI special agent’s tone of voice can be important; if the CI special agent
advises the subject in a fashion that implies that the rights advisement is a meaningless
formality, a court may hold that the subject did not make a knowing, voluntary, and intelligent
waiver.
Downplaying. It is also improper to play down the seriousness of the investigation or play up
the benefits of cooperating. In short, the CI special agent must not (by words, actions, or tone
of voice) attempt to induce the individual to waive his rights. The court would likely hold
such actions as contrary to the purpose of the explanation of rights requirement.
Deception. A CI special agent may emphasize the benefits of cooperation with the
Government, as long as it is not done in a coercive manner.
RIGHT TO COUNSEL
8-57. If, at any time, the subject indicates that he wishes to consult with counsel, stop the interview, even if
the subject has otherwise stated that he is willing to make a statement. If during the waiver process, the
subject indicates that he has spoken with counsel about anything in the last 30 days or so, stop the interview
and consult with SJA.
8-58. The subject may request counsel at any time; even if waived initially, the subject may still change his
mind and request counsel later, just as he may later invoke his right to remain silent. If the subject requests
counsel, the CI special agent should contact his local SJA office immediately after terminating the
interview. Questions concerning re-opening the interview, whether the subject will have a military or
civilian counsel, and the timeframe for obtaining counsel can be answered by the CI special agent’s SJA
advisor.
ADVICE ABOUT THE RIGHTS
8-59. It is possible that the subject will ask the CI special agent for advice about whether or not he should
invoke his rights. While it is not the job of the CI special agent to advise the subject in this fashion, the CI
special agent must keep in mind that advising the subject not to seek counsel, or advising the subject to
make a statement, may be seen as an attempt to pressure the subject to waive his rights and could result in
the statement being inadmissible.
8-60. The CI special agent’s best reply will generally be something along the lines of: “If you are not sure
about waiving your rights, perhaps you should talk to counsel, and we can talk again afterwards.” While
21 October 2009
FM 2-22.2
8-11
FOR OFFICIAL USE ONLY
Chapter 8
that may seem counterproductive from the investigator’s point-of-view, it will protect the admissibility of
statements given.
INAPPLICABLE TO PHYSICAL EVIDENCE
8-61. The 5th Amendment, and article 31, only apply to testimonial evidence. They have no application to,
and do not restrict the collection of, physical evidence, including fingerprints, blood samples, DNA,
handwriting, or voice exemplars based on a standard template. However, the collection of such physical
evidence may require other approvals, and the CI special agent should consult with their SJA.
INVESTIGATIVE AUTHORITY
8-62. CI special agents have several different types of authority when conducting CI investigations. This
includes standing investigative authority, the authority to conduct a search and seizure, the ability to
apprehend or detain a subject, the ability to perform an investigative stop, and the authority to swear a
witness or subject to an oath.
STANDING INVESTIGATIVE AUTHORITY
8-63. In accordance with AR 381-20, CI special agents have standing investigative authority allowing them
to gather sufficient information about an incident to prepare a concise CI incident report. This authority
cannot be exercised past five work days, and in any case terminates once the CI incident report is
submitted. SIA includes the authority to—
Interview the source of the report.
Conduct local agency checks.
Collect and retain physical evidence not requiring approval under AR 381-10.
Debrief returned special category absentees or repatriated POWs.
Monitor command investigations of security violations.
8-64. Under no circumstances, however, may the CI special agent use SIA to interview the subject without
explicit authority from the ACICA.
SEARCH AND SEIZURE AUTHORITY
8-65. CI special agents are authorized to perform search and seizures within U.S. military installations or
facilities, in accordance with AR 381-10, AR 190-22, Military Rules of Evidence, and other applicable
policies. Such searches or seizures must be properly approved by the appropriate commander or Military
Judge. CI special agents may not perform searches or seizures outside DOD installations in the United
States, but may, with permission, accompany the civilian LEA (typically the FBI) who is conducting the
search or seizure. Off-post searches or seizures outside the United States is governed by AR 381-10 and
existing SOFAs.
Constitutional Protection
8-66. U.S. citizens are protected from unreasonable searches or seizures by the 4th Amendment to the
Constitution. Additionally, the Uniform Code of Military Justice provides similar protections for Service
Members. CI searches are addressed in Procedure 7, AR 381-10. Under no circumstances should a CI
special agent attempt to initiate, request or encourage a search outside of Procedure 7 - such a search will
likely be held to be illegal, as approval for a CI search requires additional elements that are not present in
non-CI searches.
8-12
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
Unlawful Searches
8-67. An unlawful search is one made of a person, a person’s house, papers, or effects without probable
cause to believe that the person committed a crime within the jurisdiction of the investigating agency, and
that evidence of the crime would be found in the area to be searched.
Probable Cause
8-68. Although probable cause applies to more than just searches, searches require an additional type of
probable cause—probable cause (reasonable belief based on identifiable and definitive facts) to believe that
the particularly described evidence will be found in the particularly described location to be searched. The
4th Amendment does not permit LEAs to simply ransack the house, person, or papers of a U.S. citizen;
instead, LEAs must have a specific plan for the conduct of the search to minimize the impact with respect
to the Constitutional rights of the person subjected to the search. Probable cause is more than mere
suspicion, more than “good reason to suspect,” or “I have a hunch.” Probable cause requires that the CI
special agent can point to facts supporting his belief, such as photographs, statements, or other factual
evidence.
Legal Searches
8-69. Generally, a legal search is one authorized by the commander or Military Judge, based on probable
cause and evidence. There are a few exceptions, however, that allow searches without requiring probable
cause:
Consent. Consent waives any expectation of privacy. The CI special agent may always
request consent to conduct a search and, if granted, may conduct the search within the limits
of the consent, until consent is withdrawn. If the subject limits the scope of the consent, the CI
special agent must comply with those limitations unless he has a separate authorization or
warrant. If the subject withdraws consent, the CI special agent must terminate the search
unless the CI special agent has a separate authorization or warrant.
Search incident to apprehension. When a subject is apprehended, the CI special agent is
permitted to conduct a brief search of the immediate area within the subject’s reach. While
this is primarily for the safety of the agent, it also allows the agent to locate contraband that
could be easily removed or destroyed. This search includes the subject and easily opened
containers within “lunging distance.” Containers that are locked, or latched in a method that
would prevent their being opened easily may not be searched based on apprehension. Lunging
distance is not an absolute number, but 15 feet can be used as a general rule. When the subject
is apprehended in his automobile, the CI special agent may search the entire passenger
compartment, but may not search the engine area or trunk unless the trunk is not separate
from the passenger compartment, such as with a hatchback. CI special agents may not
conduct searches of off-post quarters in the United States; conducting apprehensions at such
quarters may be seen as an attempt to circumvent this rule.
Search incident to an investigative stop. This is similar to a search incident to apprehension,
but is more limited. Here the purpose is entirely focused on the safety of the officer, with a
very limited exception concerning evidence that can be readily destroyed. Again, the CI
special agent may search the subject, including backpacks or purses. If the stop involves a car,
but the subject steps out of his car, the CI special agent will not be able to search the
passenger compartment. As above, the CI special agent may not conduct searches of off-post
quarters in the United States; conducting investigative stops at such quarters may be seen as
an attempt to circumvent this rule.
21 October 2009
FM 2-22.2
8-13
FOR OFFICIAL USE ONLY
Chapter 8
Documentation
8-70. The CI special agent should obtain the search authorization in writing whenever possible. While it is
possible to obtain verbal authorization, particularly in a time-critical situation, the verbal authorization
should be followed up with a written authorization. Reducing the authorization to writing helps ensure the
admissibility of evidence collected. The CI special agent needs to address several factors in the request,
including the following, and should consult with the SJA for assistance in drafting and processing the
request. Refer to AR 381-10, chapter 7, for more details.
Identification of the person or description of the property to be searched.
A statement of facts to show there is probable cause to believe the subject of the search is—
Engaged in clandestine intelligence activities, sabotage, international terrorist activities,
activities in preparation for international terrorist activities, or conspiring with or
knowingly aiding and abetting a person engaging in such activities, for or on behalf of a
foreign power.
An officer or employee of a foreign power.
Knowingly taking direction from or acting in knowing concert with, and thereby
unlawfully acting for or at the direction of a foreign power.
A corporation or other entity that is owned or controlled directly or indirectly by a
foreign power.
In contact with, or acting in collaboration with, a foreign intelligence or security service,
to provide access to information or material classified by the United States and to which
the subject has access.
A statement of facts to show that the significant foreign intelligence or CI expected to be
obtained cannot be gathered by less intrusive means.
A description of the extent of the search and a statement of facts to show that the search will
involve the least amount of physical intrusion to meet the objective.
A description of the expected dissemination of the product of the search, including the
procedures governing the retention and dissemination of incidentally acquired U.S. person
information.
Scope of the Search
8-71. A search is limited in scope, as described in the request and subsequent authorization or warrant. The
CI special agent must ensure that they stay within the scope of the authorization. Going outside the scope
for any reason, regardless of how logical that reason seems, may cause evidence found to be inadmissible.
If the CI special agent conducting the search has reason to believe that the scope should be expanded, the
CI special agent should stop the search, secure the location, and submit an additional request.
8-72. A classic example of this is a search for TS documents stolen from the SCIF. During the search, the
documents are found in the subject’s office, next to a computer and scanner. While it is logical to assume
that the subject is scanning the documents, such logic does not permit the CI special agent to search or
seize the computer or scanner. Instead, the CI special agent must request that the scope of the authorization
be expanded by submitting the request with the additional details, outlining the additional probable cause
which now involves the computer and scanner, and get authorization, before the items may be seized.
8-14
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
What May Be Seized
8-73. There are several different types of items that may be seized during a search and seizure. These
include—
The stated evidence of the crime.
Other contraband discovered in “plain view” within the scope of the search authorization.
This can include items like drugs or weapons.
Fruits of the crime. Property which has been wrongfully taken or possessed because of the
crime. This could include the case received by the subject after the sale of the TS documents.
Means of commission. This covers tools and other means of committing the crime, which
could include lock-picks, computers, and other tools.
Other related evidence. This focuses on more circumstantial evidence, such as clothing or
other items that may place the subjects at the scene of the crime without themselves being
considered to be tools.
APPREHENSION AND DETENTION AUTHORITY
8-74. CI special agents have the authority to apprehend, and a limited ability to detain, as discussed below.
Apprehension
8-75. CI special agents may apprehend individuals subject to the UCMJ anywhere in the world, on-post or
off-post, when they have probable cause and reasonable belief that the Soldier committed a crime within CI
jurisdiction; however, this will initiate the 120-day time line trial requirement. CI special agents should not
apprehend without consulting with their SJA. If they do so, they must contact their SJA as soon as possible
after the apprehension. Any delay increases the likelihood that the subject’s case will be dismissed.
Detention
8-76. CI special agents may, in some circumstances, detain civilians (persons not subject to the UCMJ),
and hold them long enough to turn them over to the appropriate civilian LEA. Such detention still requires
probable cause and reasonable belief that the civilian committed a crime within CI jurisdiction. CI special
agents may detain civilians inside the United States only on military installations. CI special agents may not
detain civilians in the United States outside a military installation. Outside the United States, the CI special
agent may still detain on military installations. The authority of the CI special agent to detain civilians off
the installation outside the United States requires coordination and authorization by the HN as well as the
required legal documentation. CI special agents should consult with the local SJA.
INVESTIGATIVE STOPS
8-77. Persons subject to the UCMJ: CI special agents may conduct an investigative stop of someone
subject to the UCMJ anywhere in the world, on-post or off-post, based upon a reasonable suspicion (less
than probable cause) that they committed a crime within CI jurisdiction.
8-78. Persons not subject to the UCMJ: CI special agents may conduct an investigative stop of a civilian in
the United States only on the military installation. As above, such a stop requires reasonable suspicion that
they committed a crime within CI jurisdiction. CI special agents may not conduct investigative stops of
civilians off-post within CONUS. OCONUS, the CI special agent may conduct investigative stops on the
installation. The off-post authority is again subject to SOFAs.
21 October 2009
FM 2-22.2
8-15
FOR OFFICIAL USE ONLY
Chapter 8
OATH ADMINISTRATION
8-79. Who may swear: CI special agents, both military and civilian, have the authority to swear a witness
or subject to an oath. The combination of the written statement and the oath renders the statement made an
“official statement,” and if the witness or subject lies in such an official statement, the witness or subject
may be punished for the false official statement, regardless of whether or not a conviction is obtained based
upon the original allegations being investigated by Army CI.
8-80. Title and Authority: The authority to swear a witness or subject to an oath arises from Article 136(b),
UCMJ (for military CI special agents) or 5 USC 303(b) (for civilian CI special agents). It is critical that CI
special agents properly cite the code citation or UCMJ article and properly identify themselves; for
example: “CI special agent, Army.”
CRIMES AND INCIDENTS WITHIN COUNTERINTELLIGENCE
INVESTIGATIVE JURISDICTION
8-81. CI special agents should bear in mind that not all crimes are solely within CI jurisdiction. In some
cases, the CI special agent will be limited to investigating only CI aspects of the crime, or may be required
to conduct the investigation jointly with another agency, or even with the chain of command.
CRIMES UNDER THE UNITED STATES CODE
8-82. Following is a list of crimes, including elements, within CI jurisdiction, that fall under Title 18,
USC—Federal Criminal Law.
Treason and treason-related offenses:
TreasonLevying War, 18 U.S.C § 2381. Elements: (1) Owing allegiance to the United
States (U.S. citizen); and (2) levying war against the United States, including working
with a military force raised to oppose the U.S. Government; assembling and arming a
body of people for the purpose of overthrowing or opposing U.S. Government (overlaps
sedition); or participating in insurrection against, or raising up a body of people to
violently oppose the U.S. Government.
TreasonAid and Comfort, 18 USC § 2381. Elements: (1) Owing allegiance to the
United States (U.S. citizen); and (2) providing aid and comfort to our enemies, including
participating in enemy propaganda; assisting a spy; committing acts of cruelty against
American POWs in an enemy country; or trafficking with known enemies, in time of war,
with knowledge of their hostile mission and intentionally giving aid in executing it.
Misprision of Treason, 18 USC § 2382. Elements: (1) Owing allegiance to the United
States (U.S. citizen); (2) having knowledge of the commission of any treason against the
United States; and (3) concealing and not, as soon as may be, disclosing or making
known the same to the President or to some judge of the United States, or to the governor
or to some judge or justice of a particular State.
Espionage and espionage-related offenses:
Espionage, 18 USC § 794(a). Elements: (1) Communicating, delivering, transmitting, or
attempting the same; (2) national defense information, including sketches, photographs,
blueprints, plans, maps, models, documents, writings, or other information connected
with national defense; (3) to a foreign government, faction, agent, representative, citizen,
and others (recognized or unrecognized); and (4) with the intent, or reason or reason to
believe, that the information will be used to the injury of the United States or to the
advantage of a foreign nation.
Espionage in Time of War, 18 USC § 794(b). Elements: (1) Communicating, delivering,
transmitting, collecting, recording, publishing, or attempting the same; (2) in the time of
8-16
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
war; (3) information with respect to the movement, numbers, description, condition, or
disposition of the Armed forces or war materials of the United States; and (4) with the
intent that the information shall be communicated to the enemy.
Entering Places Connected with National Defense, 18 USC § 793(a). Elements: (1)
Entering, flying over, or obtaining information concerning defense installations, bases,
vessels, aircraft (or any place designated off-limits by proclamation during time of war or
national emergency); (2) for the purpose of obtaining information about national defense;
(3) with the intent, or reason or reason to believe, that the information will be used to the
injury of the United States or to the advantage of a foreign nation.
Gathering Defense Information, 18 USC § 793(b). Elements: (1) Copying, taking,
making, obtaining, or attempting the same; (2) national defense information, including
sketches, photographs, blueprints, plans, maps, models, documents, writings, or other
information connected with national defense; (3) with the intent, or reason or reason to
believe, that the information will be used to the injury of the United States or to the
advantage of a foreign nation.
Unlawfully Receiving Defense Information, 18 USC § 793(c). Elements: (1) Receiving,
obtaining, or agreeing or attempting to receive or obtain; (2) from any person or source
whatever; (3) national defense information, including sketches, photographs, blueprints,
plans, maps, models, documents, writings, or other information connected with national
defense; (4) knowing, or having reason to believe, at the time received or obtain, or the
time of the agreement or intent, that it has, or will be obtained, taken, made, or disposed
of by any person contrary to Title 18, Chapter 37, Espionage.
Transmitting National Defense Information to Unauthorized Persons,
18 USC §
793(d). Elements: (1) Having lawful possession of, access to, control over, or entrusted
with; (2) national defense information, including sketches, photographs, blueprints, plans,
maps, models, documents, writings, or other information connected with national
defense; (3) which the possessor has reason to believe could be used to the injury of the
United States or to the advantage of any foreign nation; (4) willfully communicates,
delivers, transmits, or attempts or causes the same; and (5) to any person not entitled to
receive it.
Unauthorized Retention of National Defense Information by Authorized Persons, 18
USC § 793(d). Elements: (1) Having lawful possession of, access to, control over, or
entrusted with;
(2) national defense information, including sketches, photographs,
blueprints, plans, maps, models, documents, writings, or other information connected
with national defense; (3) which the possessor has reason to believe could be used to the
injury of the United States or to the advantage of any foreign nation; and (4) willfully
retaining the same and fails to deliver it on demand to the officer or employee of the
United States entitled to receive it.
Unauthorized Possession and Transmission of National Defense Information to
Unauthorized Persons, 18 USC § 793(e). Elements: (1) Having unauthorized possession
of, access to, or control over;
(2) national defense information, including sketches,
photographs, blueprints, plans, maps, models, documents, writings, or other information
connected with national defense; (3) which the possessor has reason to believe could be
used to the injury of the United States or to the advantage of any foreign nation; (4)
willfully communicates, delivers, transmits, or attempts or causes the same; and (5) to
any person not entitled to receive it.
Unauthorized Retention of National Defense Information by Unauthorized Persons, 18
USC § 793(e). Elements: (1) Having unauthorized possession of, access to, or control
over; (2) national defense information, including sketches, photographs, blueprints, plans,
maps, models, documents, writings, or other information connected with national
21 October 2009
FM 2-22.2
8-17
FOR OFFICIAL USE ONLY
Chapter 8
defense; (3) which the possessor has reason to believe could be used to the injury of the
United States or to the advantage of any foreign nation; and (4) willfully retains the same
and fails to deliver it on demand to the officer or employee of the United States entitled
to receive it.
Negligent Loss of National Defense Information, 18 USC § 793(f). Elements: (1)
Having lawful possession of, control over, or entrusted with;
(2) national defense
information, including sketches, photographs, blueprints, plans, maps, models,
documents, writings, or other information connected with national defense; and (3)
through gross negligence permitting the same to be lost, stolen, abstracted, destroyed,
removed from its proper place of custody, or delivered to anyone in violation of that trust.
Failure to Report the Loss of National Defense Information,
18 USC § 793(f).
Elements: (1) Having lawful possession of, control over, or entrusted with; (2) national
defense information, including sketches, photographs, blueprints, plans, maps, models,
documents, writings, or other information connected with national defense; and (3)
having knowledge that the same has been lost, stolen, abstracted, destroyed, illegally
removed from its proper place of custody, or delivered to anyone in violation of that trust;
and (4) fails to make prompt report of such loss, theft, abstraction, destruction, illegal
removal, or illegal delivery to his superior officer.
Photographing and Sketching Defense Installations, 18 USC § 795. Elements: (1)
Photographing or otherwise taking a picture of, sketching, drawing, mapping, or creating
a graphical representation of; (2) military and naval installations and equipment that are
vital to the interests of national defense, and therefore require protection against the
general dissemination of information pertaining to them; (3) without first obtaining
permission of the commanding officer of the military or naval installation or equipment,
or higher authority; and
(4) promptly submitting the product obtained to such
commanding officer or higher authority for censorship or such other action as he may
deem necessary.
Use of Aircraft to Photograph Defense Installations, 18 USC § 796. Elements: (1)
Using, or permitting the use of an aircraft or any contrivance used or designed for
navigation or flight in the air; (2) for the purpose of making; (3) a photograph, sketch,
picture, drawing, map, or graphical representation of; and
(4) military and naval
installations and equipment that are vital to the interests of national defense, and therefore
require protection against the general dissemination of information pertaining to them.
Publication and Sale of Photographs of Defense Installations,
18 USC § 797.
Elements: (1) Reproducing, publishing, selling, or giving away any; (2) photograph,
sketch, picture, drawing, map, or graphical representation of; (3) military and naval
installations and equipment that are vital to the interests of national defense, and therefore
require protection against the general dissemination of information pertaining to them;
(4) without first obtaining permission of the commanding officer of the military or naval
installation or equipment, or higher authority; and (5) unless such photograph, sketch,
picture, drawing, map, or graphical representation has clearly indicated thereon that it has
been censored by the proper military or naval authority.
Disclosure of Classified Communications Information to Unauthorized Persons, 18
USC § 798. Elements: (1) Knowingly and willfully; (2) communicating, furnishing,
transmitting, or otherwise making available to an unauthorized person; (3) any classified
communications information, including information pertaining to codes, ciphers,
cryptographic systems, communication intelligence systems or activities of the United
States or any foreign government.
Disclosure of Classified Communications Information, General,
18 USC § 798.
Elements:
(1) Knowingly and willfully;
(2) publishing, or using in any manner
8-18
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
prejudicial to the safety or interest of the United States or for the benefit of any foreign
government to the detriment of the United States; (3) any classified communications
information, including information pertaining to codes, ciphers, cryptographic systems,
communication intelligence systems or activities of the United States or any foreign
government.
Subversion and subversion-related offenses:
Subversion, 18 USC § 2387. Elements: (1) Advising, counseling, urging, or in any
manner causing or attempting to cause insubordination, disloyalty, mutiny, or refusal of
duty by any member of the U.S. military or naval forces; and (2) with intent to interfere
with, impair, or influence the loyalty, morale, or discipline of the military.
Distribution of Subversive Literature to the Military, 18 USC § 2387. Elements: (1)
Distributing or attempting to distribute; (2) any written or printed matter which advises,
counsels, or urges insubordination, disloyalty, mutiny, or refusal of duty by any member
of the U.S. military or naval forces; (3) with intent to interfere with, impair, or influence
the loyalty, morale, or discipline of the military.
Subversion in Time of War, 18 USC § 2388. Elements: (1) Willfully causing or
attempting to cause insubordination, disloyalty, mutiny, or refusal of duty, in the U.S.
military or naval forces, or willfully obstructing the recruiting or enlistment service of the
United States; (2) when the United States is at war; and (3) to the injury of the Service or
the United States.
Subversive Statements in Time of War, 18 USC § 2388. Elements: (1) Willfully making
or conveying false reports or false statements; (2) when the United States is at war; (3)
with intent to interfere with the operation or success of the U.S. military or naval forces
or to promote the success of its enemies.
Sedition and sedition-related offenses:
Rebellion or Insurrection, 18 USC § 2383. Elements: (1) Inciting, assisting, or engaging
in; and (2) any rebellion or insurrection against the U.S. authority or the laws thereof, or
gives aid or comfort thereto.
Seditious Conspiracy, 18 USC § 2384. Elements: (1) Two or more persons in any place
subject to the jurisdiction of the United States; and (2) conspiring to overthrow, put
down, or to destroy by force the U.S. Government, or to levy war against them, or to
oppose by force the authority thereof, or by force to prevent, hinder, or delay the
execution of any U.S. law, or by force to seize, take, or possess any U.S. property
contrary to the authority thereof.
Sedition, 18 USC § 2385. Elements: (1) Knowingly or willfully; (2) advocating, abetting,
advising, or teaching the duty, necessity, desirability, or propriety of overthrowing or
destroying;
(3) the U.S. Government or any State, Territory, District, Possession,
Country, or other political subdivisions; and
(4) by force or violence, or by the
assassination of any officer of any such government.
Seditious Literature, 18 USC § 2385. Element: (1) Printing, publishing, editing, issuing,
circulating, selling, distributing, or publicly displaying any written or printed matter
advocating, advising, or teaching the duty, necessity, desirability, or propriety of
overthrowing or destroying (and attempts to do the same); (2) the U.S. Government or
any State, Territory, District, Possession, Country, or other political subdivisions; (3)
with intent to cause the overthrow or destruction of any such government.
Seditious Organizations—Organizing, 18 USC § 2385. Elements: (1) Organizing or
helping or attempting to organize; (2) any society, group, or assembly of persons who
teach, advocate, or encourage the overthrow or destruction of; (3) the U.S. Government
21 October 2009
FM 2-22.2
8-19
FOR OFFICIAL USE ONLY
Chapter 8
or any State, Territory, District, Possession, Country, or other political subdivisions; and
(4) by force or violence.
Seditious Organizations—Membership,
18 USC § 2385. Elements:
(1) Being or
becoming a member of, or affiliating with; (2) any society, group, or assembly of persons
who teach, advocate, or encourage the overthrow or destruction of;
(3) the U.S.
Government or any State, Territory, District, Possession, Country, or other political
subdivisions; (4) by force or violence; and (5) knowing the purposes of such society,
group, or assembly or persons.
Sabotage and sabotage-related offenses:
Sabotage—Destruction of War Material, 18 USC § 2153. Elements: (1) When the
United States is at war, or during a time of emergency; (2) willfully damaging or
destroying; (3) any war material; (4) with the intent to injure or obstruct the ability of the
United States to carry out war; and (5) at the direction of a FISS and ITO or adversarial
intelligence service.
Sabotage—Production of Defective War Material, 18 USC § 2154. Elements: (1) When
the United States is at war, or during a time of emergency; (2) willfully making,
constructing, or causing to be made or constructed; (3) in a defective manner (and
attempts to do the same); (4) any war material; (5) with the intent to injure, interfere with,
or obstruct, the ability of the United States or any associate nation, to prepare for, or carry
on the war or defense activities, or with reason to believe that the act may injure, interfere
with, or obstruct the United States or any associate nation in preparing for or carrying on
the war or defense activities; and (6) at the direction of a FISS and ITO or adversarial
intelligence service.
Sabotage—Destruction of National Defense Material, 18 USC § 2155. Elements: (1)
Willfully damaging or destroying; (2) national defense material; (3) with the intent to
injure or obstruct the U.S. national defense; and (4) at the direction of a FISS and ITO or
adversarial intelligence service.
Sabotage—Production of Defective National Defense Material,
18 USC § 2156.
Elements: (1) Willfully making, constructing, or causing to be made or constructed; (2)
in a defective manner (and attempts to do the same); (3) any national defense material;
(4) with the intent to injure, interfere with, or obstruct, the U.S. national defense; and (5)
at the direction of a FISS and ITO or adversarial intelligence service.
Terrorism and terrorism-related offenses:
Notes on Terrorism directed Against Army, 18 USC §§ 2331-2339c (chapter 113b).
Terrorism is any activity that involves (see 18 USC §§ 2332(b) and 2339) violent acts,
acts dangerous to human life, acts that are a violation of the U.S. criminal laws or of any
State, or acts that would be a criminal violation if committed within the U.S. jurisdiction
or of any State; or that appear to be intended to intimidate or coerce a civilian population;
influence the policy of a government by intimidation or coercion; or affect the conduct of
a government by mass destruction, assassination, or kidnapping.
Terrorist organizations are those organizations designated as terrorist organizations under
section 219 of the Immigration and Nationality Act (8 USC § 1189). Releases concerning
Terrorist organizations in general can be found at: http://www.state.gov/s/ct/rls/. Fact
sheets on foreign terrorist organizations can be found at: http://www.state.gov/s/ct/rls/fs/.
Country reports on terrorism can be found at: http://www.state.gov/s/ct/rls/crt/.
WMD includes an explosive, incendiary, poison gas, bomb, grenade, rocket (more than
4-oz propellant), missile
(more than ¼-oz explosive or incendiary warhead), mine,
similar device; any weapon designed or intended to cause death or serious bodily injury
8-20
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
through the release, dissemination, or impact of toxic or poisonous chemicals, or their
precursors; any weapon involving a biological agent, toxin, or carrier of the same; or any
weapon that is designed to release radiation or radioactivity at a level dangerous to
human life. WMDs do not include chemical weapons, including toxic chemicals and their
precursors, munitions, or devices specifically designed to cause death or other harm
through toxic properties of those toxic chemicals, or any equipment specifically designed
for use directly in connection with the employment of such munitions or devices.
Jurisdiction requires that acts of terrorism be directed against the Army, or against Army
personnel.
Terrorism—Murder, 18 USC § 2332(a). Elements: (1) Killing a U.S. national while they
are outside the United States; (2) unlawfully; (3) with malice aforethought, including
using poison, lying in wait, or any other kind of willful, deliberate, malicious, or
premeditated killing; or killing in the perpetration of, or attempt to perpetrate, any arson,
escape, murder, kidnapping, treason, espionage, sabotage, aggravated sexual abuse or
sexual abuse, child abuse, burglary, or robbery; or perpetrated as part of a pattern or
practice of assault or torture against a child or children; or perpetrated from a
premeditated design unlawfully and maliciously to effect the death of any human being
other than the person who is killed; and (4) directed against the Army or Army personnel.
Terrorism—Voluntary Manslaughter, 18 USC § 2332(a). Elements: (1) Killing a
U.S. national while the national is outside the United States; (2) unlawfully; (3)
without malice aforethought during a sudden quarrel or in the heat of passion; and
(4) directed against the Army or Army personnel.
Terrorism—Involuntary Manslaughter, 18 USC § 2332(a). Elements: (1) Killing a
U.S. national while the national is outside the United States; (2) unlawfully; (3)
without malice aforethought during the commission of an unlawful act not
amounting to a felony, or in the commission in an unlawful manner, or without due
caution and circumspection, of a lawful act which might produce death; and (4)
directed against the Army or Army personnel.
Terrorism—Attempted Murder, 18 USC § 2332(b). Elements: (1) Attempting to kill a
U.S. national while the national is outside the United States; (2) unlawfully; (3) with
malice aforethought, including using poison, lying in wait, or any other kind of willful,
deliberate, malicious, or premeditated killing; or killing in the perpetration of, or attempt
to perpetrate, any arson, escape, murder, kidnapping, treason, espionage, sabotage,
aggravated sexual abuse or sexual abuse, child abuse, burglary, or robbery; or perpetrated
as part of a pattern or practice of assault or torture against a child or children; or
perpetrated from a premeditated design unlawfully and maliciously to effect the death of
any human being other than the person who is killed; and (4) directed against the Army
or Army personnel.
Terrorism—Conspiracy to Commit Murder, 18 USC § 2332(b). Elements: (1)
Engaging in a conspiracy to kill a U.S. national outside the United States; (2)
unlawfully; (3) with malice aforethought, including using poison, lying in wait, or
any other kind of willful, deliberate, malicious, or premeditated killing; or killing in
the perpetration of, or attempt to perpetrate, any arson, escape, murder, kidnapping,
treason, espionage, sabotage, aggravated sexual abuse or sexual abuse, child abuse,
burglary, or robbery; or perpetrated as part of a pattern or practice of assault or
torture against a child or children; or perpetrated from a premeditated design
unlawfully and maliciously to effect the death of any human being other than the
person who is killed; (4) committing an overt act to affect the conspiracy; and (5)
directed against the Army or Army personnel.
Terrorism—Other Acts, 18 USC § 2332(c). Elements: (1) Engaging in physical
violence outside the United States; (2) with the intent to cause serious bodily injury
21 October 2009
FM 2-22.2
8-21
FOR OFFICIAL USE ONLY
Chapter 8
to a U.S. national, or with the result that serious bodily injury is caused to a national
of the United States; and (3) directed against the Army or Army personnel.
Terrorism—Use of WMDs Against the United States, 18 USC § 2332(a). Elements:
(1) Using, threatening, or attempting or conspiring to use;
(2) without lawful
authority; (3) a WMD; (4) against a U.S. national while the national is outside the
United States; against any person within the United States, where the results of such
use affect, or would have affected, interstate or foreign commerce; or against any
property owned, leased or used by the United States or any of its departments or
agencies; and (5) directed against the Army or Army personnel.
Terrorism—Use of WMDs by U.S. Nationals Outside the United States, 18 USC §
2332(b). Elements: (1) A U.S. national; (2) using, threatening, or attempting or
conspiring to use; (3) without lawful authority; (4) a WMD; (5) outside the United
States; and (6) directed against the Army or Army personnel.
Terrorism—Acts Transcending National Boundaries Involving Persons, 18 USC §
2332(b)(a)(1)(A). Elements:
(1) Engaging in conduct that transcends national
boundaries, including the use of mail, or facilities of foreign or interstate commerce;
(2) which involves the killing, kidnapping, or maiming of, or committing an assault
resulting in serious bodily injury against, or assaulting with a deadly weapon; (3) a
U.S. Government employee, including military, legislative, executive, or judicial
employees, or the employee of any other U.S. department or agency; (4) within the
United States, within the U.S. territorial seas, or within the special maritime or U.S.
territorial jurisdiction; and (5) directed against the Army or Army personnel.
Terrorism—Acts Transcending National Boundaries Involving Property, 18 USC
§ 2332(b)(a)(1)(A). Elements: (1) Engaging in conduct that transcended national
boundaries, including the use of mail, or facilities of foreign or interstate commerce
that; (2) creates a substantial risk of serious bodily injury to any other person by
destroying or damaging; (3) any U.S. Government property, facilities, structures, or
conveyances, or other real or personal property belonging to the U.S. Government;
or where the offense obstructs, delays, or affects foreign or interstate commerce
(including attempt or conspiracy to do the same); (4) within the United States, within
the U.S. territorial seas of, or within the special maritime or U.S. territorial
jurisdiction; and (5) directed against the Army or Army personnel.
Terrorism—Bombing Public Place and Facilities, 18 USC § 2332(f). Elements: (1)
Delivering, placing, discharging, or detonating an explosive or other lethal device;
(2) in, into, or against, (3) a place of public use, a state or government facility, a
public transportation system, or an infrastructure facility;
(4) within the U.S.
jurisdiction as defined by 18 USC § 2332(f); (5) with the intent to cause death or
serious bodily injury, or with the intent to cause extensive destruction of such place,
facility, system, or where such destruction results in, or is likely to result in major
economic loss; and (6) directed against the Army or Army personnel.
Terrorism—Harboring Terrorists, 18 USC § 2339. Elements: (1) Harboring or
concealing; (2) a person who has committed, or is about to commit (or where there is
reasonable grounds to believe that they have committed or are about to commit); (3)
certain Federal crimes of terrorism, as defined by 18 USC §§ 2332(b) and 2339; and
(4) directed against the Army or Army personnel.
Terrorism—Providing Material Support to Terrorists, 18 USC § 2339A. Elements:
(1) Providing material support or resources, including money or financial
instruments, lodging, training, expert advice or assistance, safe-houses, false
documentation of identification, communications equipment, facilities, weapons,
lethal substances, explosives, personnel, transportation, or other physical assets other
than medicine or religious materials; or concealing or disguising the nature, location,
source, or ownership of material support or resources; (2) to a person or group; (3)
knowing or intending that the material support or resources are to be used in
8-22
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
preparation for, or in carrying out; or in preparation for, or in carrying out, the
concealment of an escape from the commission of
(including attempts and
conspiracy to do the same); (4) certain federal crimes of terrorism, as defined by 18
USC §§ 2332(b) and 2339; and (5) directed against the Army or Army personnel.
Terrorism—Providing Material Support to Terrorist Organizations, 18 USC § 2339B.
Elements: (1) Knowingly providing material support or resources, including money or
financial instruments, lodging, training, expert advice or assistance, safe-houses, false
documentation of identification, communications equipment, facilities, weapons, lethal
substances, explosives, personnel, transportation, or other physical assets other than
medicine or religious materials; or concealing or disguising the nature, location, source,
or ownership of material support or resources (including attempts and conspiracy to do
the same); (2) within the United States or subject to the U.S. jurisdiction; (3) to a terrorist
organization, as designated by 8 USC § 1189; and (4) that directs their activities against
the Army or Army personnel.
Terrorism—Financing Terrorism, 18 USC § 2339C(a). Elements: (1) Directly or
indirectly; (2) willfully and unlawfully; (3) providing or collecting funds; (4) with the
intention that such funds be used, or with the knowledge that such funds are to be used, in
full or in part, to carry out; (5) any act intended to cause death or serious bodily injury to
a civilian, or to any other person not taking an active part in the hostilities in a situation
of armed conflict, when the purpose of such act, by its nature or context, is to intimidate a
population, or to compel a government or an international organization to do or to abstain
from doing any act; or where the act constitutes an offense within the scope of a treaty
specific in 18 USC § 2339C(e)(7); and (6) directed against the Army or Army personnel.
Terrorism—Concealing Information Pertaining to the Financing of Terrorism, 18
USC § 2339C(c). Elements: (1) Knowingly concealing or disguising; (2) within the
United States, or subject to the U.S. laws; (3) the nature, location, source, ownership, or
control of any material support, resources, or funds as defined by 18 USC § 2339B; (4)
knowing or intending that the material support, resources, or funds were provided to
persons engaged in terrorism or terrorist acts, to a terrorist organization, or to some
person, group, or organization planning to engage in certain federal crimes of terrorism
(as defined by 18 USC §§ 2332(b) and 2339); in violation of 18 USC § 2339B; or
knowing or intending that such funds or any proceeds of such funds were provided or
collected in violation of 18 USC § 2339C(a); and (5) directed against the Army or Army
personnel.
CRIMES UNDER THE UNIFORM CODE OF MILITARY JUSTICE
8-83. Following is a list of crimes, including elements, within CI jurisdiction, that fall under the UCMJ:
Aiding the Enemy (Treason), Art. 104, UCMJ. Elements: (1) Aiding the enemy; (2) with
arms, ammunition, supplies, money, or other things.
Aiding the Enemy—Harboring or Protecting the Enemy (Treason), Art. 104, UCMJ.
Elements: (1) Harboring or protecting a person; (2) who is an enemy; (3) without proper
authority; (4) knowing that the person being harbored or protected is an enemy.
Aiding the Enemy—Giving Intelligence to the Enemy (Treason), Art. 104, UCMJ.
Elements: (1) Knowingly giving; (2) intelligence information that is true, or implied the truth,
at least in part; (3) to an enemy; (4) without proper authority.
Aiding the Enemy—Communicating with the Enemy, Art. 104 (Treason), UCMJ.
Elements: (1) Communicating, corresponding, or holding intercourse with; (2) an enemy; (3)
knowing that the person was the enemy; (4) without proper authority.
21 October 2009
FM 2-22.2
8-23
FOR OFFICIAL USE ONLY
Chapter 8
Spies—Art. 106, UCMJ. Elements: Any person who in time of war is found lurking as a spy
or acting as a spy in or about any place, vessel, or aircraft, within the control or jurisdiction of
any of the armed forces, or in or about any shipyard, any manufacturing or industrial plant, or
any other place or institution engaged in work in aid of the prosecution of the war by the
United States, or elsewhere.
Espionage—Art. 106a, UCMJ. Elements: (1) Communicating (delivering, transmitting);
(2) national defense information (documents, plans, blueprints); (3) to a foreign government
(faction, agent, representative, citizen); (4) with the intent, or reason or reason to believe, that
the information will be used to the injury of the United States or to the advantage of a foreign
nation.
Mutiny by Violence—Art. 94, UCMJ. Elements: (1) Creating violence or disturbance; (2)
with the intent to overthrow lawful military authority.
Mutiny by Refusal—Art. 94, UCMJ. Elements: (1) Refusing to obey orders; (2) in concert
with another; (3) with the intent to overthrow lawful military authority.
Sedition—Art. 94, UCMJ. Elements: (1) Creating a revolt, violence, or disturbance; (2)
against lawful civil authority; (3) in concert with another; (4) with the intent to overthrow or
destroy that authority.
Failure to Prevent and Suppress Mutiny or Sedition—Art. 94, UCMJ. Elements: (1)
Witnessing an offense of mutiny or sedition; (2) failing to do your utmost to prevent and
suppress the mutiny or sedition.
Failure to Report Mutiny or Sedition—Art. 94, UCMJ. Elements: (1) Knowing, or having
reason to know; (2) that an offense of mutiny or sedition was taking place; (3) failing to take
all reasonable means to inform your superior commission officer or commander of the
offense.
Attempted Mutiny,—Art. 94, UCMJ. Elements: (1) Committing a certain overt act; (2)
with the specific intent to commit mutiny; (3) where the act amounted to more than mere
preparation; and (4) where the act apparently tended to effect the commission of the mutiny.
Destruction of Military Property—Art. 108, UCMJ. Elements: (1) Intentionally; (2)
without authority; (3) damaging or destroying; (4) U.S. military property; (5) of a certain
value; (6) at the direction of a FISS and ITO or adversarial intelligence service.
Defection—Modeled from Desertion—Art. 85, UCMJ). Elements: (1) Leaving your unit
or place of duty; (2) departing the United States or country in which you are stationed; and (3)
Repudiating (rejecting or disowning) the United States and U.S. authority.
Desertion with Intent to Remain Away Permanently—Art. 85, UCMJ. Elements: (1)
Leaving your unit or place of duty; (2) without authority; (3) intending to remain away
permanently; (4) having had access within the last year to TS information, SCI, SAPs, DA
Cryptographic Access Program (DACAP), or were part of a Special Mission Unit; and (5) if
they are apprehended, remaining away until the date alleged.
Absence Without Leave—Art. 86, UCMJ. (Use this as model for personnel who are
missing.) Elements: (1) Absenting yourself from your unit or place of duty; (2) without
authority; (3) for a certain period of time; (4) having had access within the last year to TS
information, SCI, SAPs, DACAP, or were part of a special mission unit.
8-24
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
Security Violation—Information Security, Violation of a Regulation, Art. 92, UCMJ.
Elements: (1) A regulation (AR 380-5) was in effect; (2) the accused had a duty to obey that
regulation; (3) the accused failed to obey that regulation, including (a) failing to safeguard
classified information; (b) the loss or possible compromise of classified information; (c)
unauthorized reproduction of classified information; or (d) failure to properly wrap classified
materials.
Security Violation—Failure to Report CI Incident, Violation of a Regulation, Art. 92, UCMJ.
Elements: (1) A regulation (AR 381-12) was in effect; (2) the accused had a duty to obey that
regulation; (3) the accused failed to obey that regulation.
OTHER INCIDENTS UNDER COUNTERINTELLIGENCE JURISDICTION
8-84. Following is a list of other incidents under counterintelligence jurisdiction (CIJ).
Assassination of Army personnel by nonterrorist organization or individuals:
Committed by military personnel. Use Murder, Art. 118, UCMJ.
Committed by nonmilitary U.S. person under CIJ. Use Murder, 18 USC § 1111.
Committed by nonmilitary non-U.S. person under CIJ. Use Murder, 18 USC § 1111 as a
guide.
Committed by person outside CIJ. Use Murder, 18 USC § 1111 as guide.
Assassination of Army personnel by terrorist organization or individuals:
Committed by military personnel. Use Murder, Art. 118, UCMJ and TerrorismMurder,
18 USC § 2332(a); look to other offenses under 18 USC § 2332 and 18 USC § 2339.
Committed by nonmilitary U.S. person under CIJ. Use TerrorismMurder, 18 USC
§ 2332(a); look to other offenses under 18 USC § 2332 and 18 USC § 2339.
Committed by nonmilitary non-U.S. person under CIJ. Use TerrorismMurder, 18
USC § 2332(a) as a guide; look to other offenses under 18 USC § 2332 and 18 USC
§ 2339.
Committed by person outside CIJ. Use TerrorismMurder, 18 USC § 2332(a) as a
guide; look to other offenses under 18 USC § 2332 and 18 USC § 2339.
Incapacitation of Army personnel by nonterrorist organization or individuals:
Committed by military personnel. Use Kidnapping, Art. 134, UCMJ; Assault or Assault
and Battery, Art. 128, UCMJ.
Committed by nonmilitary U.S. person under CIJ. Use Kidnapping, 18 USC § 1201;
Assault, 18 USC §§ 111 and 113.
Committed by nonmilitary non-U.S. person under CIJ. Use Kidnapping, 18 USC
§ 1201; Assault, 18 USC §§ 111 and 113 as guides.
Committed by person outside CIJ. Use Kidnapping, 18 USC § 1201, Assault, 18 USC §§
111 and 113 as guides.
Incapacitation of Army personnel by terrorist organization or individuals:
Committed by military personnel. Use Kidnapping, Art. 134, UCMJ; Assault or Assault
and Battery, Art. 128, UCMJ; TerrorismOther Acts, 18 USC § 2332(c); look to other
offenses under 18 USC §§ 2332 and 2339.
Committed by nonmilitary U.S. person under CIJ. Use TerrorismOther Acts, 18 USC
§ 2332(c); look to other offenses under 18 USC §§ 2332 and 2339.
21 October 2009
FM 2-22.2
8-25
FOR OFFICIAL USE ONLY
Chapter 8
Committed by nonmilitary non-U.S. person under CIJ. Use TerrorismOther Acts,
18 USC § 2332(c) as a guide; look to other offenses under 18 USC §§ 2332 and 2339.
Committed by person outside CIJ. Use TerrorismOther Acts, 18 USC § 2332(c) as a
guide; look to other offenses under 18 USC §§ 2332 and 2339.
Detention of DA Personnel by a Foreign Government or Hostile Force (with interests
inimical to the United States). Key points: (1) An Army Soldier, Army Civilian employee,
a DA contractor, or a foreign national employed by the Army; (2) is being held against his
will;
(3) by a foreign government, faction, agent, representative, citizen
(recognized or
unrecognized); or member of a hostile force, including a terrorist, terrorist group, or terrorist
organization; (4) with interest inimical to those of the United States; and (5) for any length of
time.
Suicide of DA Personnel. Key points: (1) An Army Soldier, Army Civilian, a contractor
with DA, or a foreign national employed by the Army; (2) holding a security clearance, Secret
or higher; including those with access to SCI, SAPs, who were in the DACAP, or were part of
a special mission unit; and (3) who killed himself.
Attempted Suicide of DA Personnel. Key points: (1) An Army Soldier, Army Civilian
employee, a contractor with DA, or a foreign national employed by the Army; (2) holding a
security clearance, Secret or higher; including those with access to SCI, SAPs who were in the
DACAP, or were part of a special mission unit; and (3) who attempts to kill himself.
Unofficial Travel by Military Members
(and Civilians overseas) to Designated
Countries. Key points: (1) An Army Soldier; and overseas, an Army Civilian employee, a
contractor with DA, or a foreign national employed by the Army; (2) traveling to a country
designated as being of special concern (AR 381-12, appendix B, contains a list, based on
DCID 1/20 (Security Policy Concerning Travel and Assignment of Personnel with Access to
Sensitive Compartmented Information
[SCI]); and
(3) without prior notification or
permission.
Unauthorized Contact by Military Members (and Civilians overseas) with Foreign
Diplomatic Facilities. Key points: (1) An Army Soldier; and overseas, an Army Civilian, a
contractor with DA, or a or a foreign national employed by the Army;
(2) entering,
communicating with, or otherwise having contact with; (3) a foreign diplomatic facility,
including an embassy, consulate, trade office, or press office; (4) without prior notification or
permission.
Unauthorized Contact by Military Members (and Civilians overseas) with Foreign
Diplomatic Officials or Official Representatives. Key points: (1) An Army Soldier; and
overseas, an Army Civilian employee, a contractor with the DA, or a foreign national
employed by the Army; (2) communicating with or having contact with;
(3) officials
representing designated countries of special concern; (AR 381-12 focuses on this narrower
concern, not just contact in general—use list in AR 381-12, appendix B, including diplomatic
representatives, agents, and other employees of the foreign government); and (4) without prior
notification or permission.
Inchoate crimes. Inchoate crimes are not crimes in and of themselves. Instead, they are a
unique body of law that encompasses those acts that go beyond mere planning and tend
towards the commission of a crime. Depending on the acts of the accused, they may be able to
be convicted of the inchoate crime as if they had, in fact, committed the crime they were
planning to commit. Inchoate crimes include attempt, conspiracy, and solicitation.
Note. For Army CI purposes, this FM only addresses inchoate crimes under the UCMJ.
8-26
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Investigative Legal Principles
Attempt—Art. 80, UCMJ:
Attempt occurs when the accused tries to commit a crime, but for reasons beyond their
control, fails. Use the attempted crime as a guide for what acts tend to support the
commission of the crime.
Elements: (1) Committing a certain overt act; (2) where the act is done with the specific
intent to commit a crime under the code; (3) that the act amounts to more than mere
preparation; and (4) that the act apparently tends to effect the commission of the crime.
Note. An example of attempted espionage would be if the subject obtained the password for
JWICS without proper clearance, made contact with a foreign country as a potential buyer, and
arranged the transmission method. If the subject is caught and stopped before actually
transmitting the data, the Army may still be able to convict him of attempted espionage, or at
least attempting one of the espionage-related offenses, such as unlawfully transmitting national
defense information.
Conspiracy, Art. 81, UCMJ:
Conspiracy occurs when the accused enters into an agreement with someone else to
commit a crime. Use the conspired crime as a guide for what acts tend to support the
commission of the crime.
Elements: (1) Entering into an agreement; (2) with one or more persons; (3) to commit
an offense under the code; and (4) while the agreement continued to exist, and while the
accused was still a party to the agreement, the accused or one of the co-conspirators;
(5) committed a certain overt act; and (6) for the purpose of bringing about the object of
the conspiracy.
Note. An example of a conspiracy to commit terrorism would be a Soldier stationed in Germany
who makes contact with the local national guard who provides guard services at the Army and
Air Force Exchange Service, then secures material to create an IED. If the Soldier is stopped
before actually planting the IED, the Army may still be able to convict him of conspiracy to
commit a terrorist act, such as use of a WMD, or bombing of a public place.
Solicitation, Art. 82, UCMJ:
Solicitation under article 82 occurs when the accused solicits or advises another to desert
(Art. 85), commit mutiny (Art. 94), misbehave before the enemy (Art. 99), or commit
sedition (Art. 94). Use the conspired crime as a guide for what acts tend to support the
commission of the crime. Solicitation of other crimes falls under UCMJ, article 134, and
is addressed below.
Elements: (1) Soliciting or advising a person to commit desertion, mutiny, misbehavior
before the enemy, or sedition; (2) with the intent that the offense be committed; and (3) if
the offense solicited was committed or attempted, that the offense was committed or
attempted as the proximate result of the solicitation.
Note. An example of solicitation under Article 82 would be a platoon sergeant who actively
encourages his Soldiers to revolt against their company commander. Even if the Soldiers do not,
in fact, commit mutiny, the platoon sergeant could still be found guilty of solicitation in
violation of article 82.
21 October 2009
FM 2-22.2
8-27
FOR OFFICIAL USE ONLY
Chapter 8
Soliciting Another to Commit an Offense, Art. 134, UCMJ:
Use article 134 for any offense not covered by solicitation under article 82. Use the
conspired crime as a guide for what acts tend to support the commission of the crime.
Elements: (1) Soliciting or advising a person to commit a crime under the code, other
than desertion, mutiny, misbehavior before the enemy, or sedition; (2) with the intent that
the offense be committed; and (3) that, under the circumstances, the conduct of the
accused was to the prejudice of good order and discipline in the armed forces, or was of a
nature to bring discredit upon the armed forces.
Note. An example of solicitation under article 134 would be a Service-member spouse stationed
in Korea who does not have access to classified information, and who requests that his spouse
(who does have access) copy SECRET documents for him, so that he could sell them to the
South Korean government. Even if the documents are never copied or sold, the Service-member
spouse without access could still be found guilty of solicitation under article 134.
8-28
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Chapter 9
Counterintelligence Reporting
CI reporting is generally the culmination of the successful execution of the various
types of CI activities. CI reporting is a critical input to the all-source intelligence
picture and can corroborate other discipline reporting as well as tip and cue other
assets collection activities. Finalized CI reports provide the commander a tangible
product that impacts the MDMP and helps to shape military operations. However, CI
reporting also documents evolving CI operations and investigations and allows
operational management elements to conduct technical control and oversight of
ongoing CI activities.
TENETS OF REPORTING
9-1. Articulation of information obtained during the course of CI activities is a skill that takes time,
repetition, and mentorship to master. CI reports not only have to reflect the information obtained during the
course of CI activities but also must often anticipate the analyst or commander’s questions concerning lack
of detail or information gaps that must be addressed to help further shape the ISR collection effort. The
tenets of reporting include the following:
Accuracy. Convey information from an interview or meeting and transcribe it into a protected
operational or intelligence report. The report writer should never infer or otherwise interpret a
source’s meaning or understanding of the information provided to the CI special agent.
Conciseness. Cover only the facts or information provided by the source. Analysts and
commanders have volumes of information to synthesize to form their operational assessments.
Reports should not be wordy. The information conveyed should be to the point while
providing the full depth of the information.
Clarity. Convey the information in simple wording as possible. Writers should use short
sentences and logically arrange the information so as not to confuse the reader.
Timeliness. Disseminate the information through the appropriate reporting channel in the
most expedient manner as possible. While written reports are preferable, the perishability and
sensitivity of the information may dictate that the information requires reporting via voice
communications with a follow-up written report.
Admissibility. Use standardized formats and legal warnings and verbiage to maintain a
prosecutorial standard in the event the reports are used during criminal proceedings. CI
investigative reports can serve as the CI special agent’s testimony during criminal
proceedings if that person is unavailable. Poorly written, unclear, or confusing investigative
reports can be exploited by defense counsels to portray the reporting CI special agent as inept
in an attempt to confuse or sway a judge or jury in favor of the defendant.
REPORTS MANAGEMENT
9-2. Reports management is the process for ensuring a quality report product, evaluating the information
for its relevance and value to the consumer and its impact on generating new or derivative information
requirements based upon the reported information. The quality and value of report products are critical in
maintaining trust and credibility with the consumers who use those products to drive military operations or
shape U.S. policies and objectives. Reports management entails the following roles and functions.
21 October 2009
FM 2-22.2
9-1
FOR OFFICIAL USE ONLY
Chapter 9
REPORTS OFFICER
9-3. The importance of reports management is often reflected in units with a large reporting mission by
the designation of a reports officer, whose responsibilities include—
Providing administrative and information quality control (QC) for all reports generated by CI
teams.
Assessing information by multiple reporting elements to deconflict information, assess the
value of reporting, and help shape the collection focus provided by operational management
elements.
Coordinating with analysis elements to identify what requirements are being answered,
requirements that need additional emphasis, and assist in the development of new information
requirements based upon credible and corroborated reporting.
Disseminating evaluations to reporting elements to assist them in adjusting their operational
focus and to provide feedback on the quality and value of their previous reporting.
Maintaining reporting statistics to assist operational management elements in refining their
technical authority and operational guidance to subordinate reporting elements.
Assisting operational management elements in assessing source placement, access, value, and
credibility based upon historical reporting. This allows the operational management elements
to make decisions on directing source terminations for subordinate reporting elements.
QUALITY CONTROL
9-4. QC is the oversight of reports production to ensure a quality product is disseminated from the
reporting element to the consumers who use the information. QC ensures that the tenets of reporting are
adhered to by the writers. QC includes the following:
Administrative QC—ensures writers adhere to applicable regulatory guidance and unit SOPs
for format, verbiage, and other administrative criteria that are required in the reports.
Information QC—analyzes the information content to identify inconsistencies within the
report or conflicts with other credible and corroborated reporting.
REPORT EVALUATIONS
9-5. Report evaluations are essential in assessing the quality and value of the report as it relates to the
consumer of the information. Reports evaluations are used by operational management elements to adjust
or refine the collection focus for CI reporting elements.
REQUIREMENTS GENERATION
9-6. CI reporting and reports management also impacts the requirements generation process.
Requirements may be added, deleted, or revised based upon information assessed as credible and
corroborated by other reporting.
REPORT CATEGORIES
9-7. CI elements produce several different types of reports to support their mission. These different
reporting requirements fall into three categories:
Command reports—include unit status reports (USRs) and all reporting requirements
established by a commander (logistical, equipment, personnel) to reflect the unit’s readiness
to execute its assigned mission. Command reports—
Tell the commander where and when assets are conducting missions.
9-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Reporting
Describe unit mission capability.
Respond to administrative and logistical requirements.
Describe support requirements.
Include but are not limited to USRs, mission planning reports, mission status reports, and
equipment status.
Report ICF usage at any echelon where the use of ICF is authorized.
Protected reports—include the various types of CI reports that result from an operational
activity. Protected reports require compartmentalization within the CI operations management
chain (CI team, OMT, CICA, 2X) to protect the identity and details of CI activities. Due to
the sensitivity and legal complexities associated with CI activities, only the technical
authorities for CI activities will have access to the information. This protects the CI special
agent and the source. If a CI activity is compromised due to an information leak, it has the
potential to compromise the viability of the activity; be harmful, if not fatal, to a CI special
agent and especially the source; or undermine the legal and prosecutorial standard of CI
investigations. Protected reports will NOT be released outside
2X channels without
authorization of the responsible 2X officer. This includes commanders of units with CI
personnel assigned or attached. Protected reports include, but are not limited to—
BSD reports—provide the CI operational management element with biographic and
operational information related to a source. BSDs are used at all echelons to collect
biographic information on all contacts.
Contact reports—CI special agents use contact reports to inform their technical authority
(from OMT through C/J/G/S-2X) of all relevant information concerning specific
meetings with sources. Information typically includes the circumstances of the contact
(purpose, locations, time); the operational matters relative to the contact
(topics
discussed, taskings given); reports produced because of the contact; and logistics
expended.
Lead development report—used to inform the HUMINT chain of ongoing operations
directed toward a specific source. LDRs notify them as to what element spotted the
potential source, the current steps in assessing of the source, and the general information
on the potential source.
Investigative reports—include IMFRs and CI incident reports used to report any incident
or national security crime within the authority and jurisdiction of Army CI. For CI
investigations the protected reporting channels include the CI team, CI OMT, TFCICA
(for CI elements operating within a JTF), the ATCICA, and the ACICA to provide
technical authority for all CI investigations conducted by Army CI elements.
Communications plans—developed for source-to-agent and agent-to-source contact.
Source registries—consolidated lists of all sources used by CI teams under the technical
authority of a CICA/2X. Source registries generally include identifying data, location,
and associations with the CI team that if compromised could significantly damage the
intelligence capability of the supported unit.
Miscellaneous—any type of documentation that provides details on the identity of a
source; methods of communication; operational activity; or meeting dates, times, or
locations.
Intelligence reports—include the various types of reports that are produced to disseminate
for intelligence and information purposes. Intelligence reports are disseminated within
intelligence channels for consumers, analysts, and commanders to use to obtain situational
understanding of their respective AOIs. Intelligence reports will always be disseminated
21 October 2009
FM 2-22.2
9-3
FOR OFFICIAL USE ONLY
Chapter 9
within the intelligence reporting channels and protected channels simultaneously. This allows
the operational management elements to maintain visibility over the production of the CI
teams and know all sensitive or inflammatory information this is developed during the course
of CI activities. Intelligence reports include, but are not limited to—
IIRs—used to report all CI information in response to collection requirements. It is used
to expand on information previously reported by spot reports or to report information that
is either too extensive or not critical enough for spot reporting. IIRs are written at any
echelon and
“released” by the appropriate authority before they enter the general
intelligence community. Normally the G-2X will be the releasing authority for IIRs.
At the tactical level, the CI special agents will fill out the complete IIR; however, the
requirements section may link the information collected against a unit requirement rather
than against national requirements. In any case, the report will be forwarded to the OMT.
The team leader will review the IIR, place a copy of the IIR in the source’s dossier and
forward the IIR to the OMT. The OMT reviews the report, requests additional
information as necessary from the originator, adds additional administrative detail, and
forwards the report to the CICA of the supporting C/J/G/S-2X. The CICA and the 2X
review the report, request additional information as required, add any administrative
information, and the 2X releases the report.
In addition to the above, the text information from the IIR can be forwarded to the unit’s
analytical elements and when it contains critical time-sensitive information, such as an
impending attack, it is sent to units which may be affected by the information; however,
it must be clearly marked “unevaluated information, not finally evaluated intelligence.”
Spot reports, using the SALUTE format—standard Army format used to report
information of immediate interest by individuals at any echelon. They are used to report
time-sensitive information that includes protection and threat I&W to the chain of
command. The spot report is the primary means used to report combat information to
units that could be affected by that information. After review by the team leader, spot
reports are sent simultaneously to the supported unit S-2, to the CI team’s responsible CI
OMT, and to the intelligence staff officer of any other tactical unit that may be affected
by the information contained in the spot report. While unit SOPs may provide written
formats, spot reports should be reported by the most expeditious means possible, usually
voice and a follow-up written report. Spot reports are reported simultaneously to the
command protected and intelligence reporting channels.
Any type of format used to disseminate information of intelligence value or that may be
used for protection, threat I&W.
REPORTING ARCHITECTURE
9-8. Many elements serve multiple and overlapping functions within the reporting architecture. Each
element must know its function within the architecture to ensure that information is disseminated
expeditiously to the right place in the right format. This architecture should be established and published
before implementation to avoid confusion. Figure 9-1 shows this reporting architecture of the command
reporting channel, protected reporting channel, and the intelligence reporting channel.
9-9. The command reporting channel includes the CI team, the responsible CI OMT, and the unit
command element the CI team and OMT are assigned or formally attached to on orders. All command
reporting concerning personnel, sustainment, equipment, resources, or unit readiness will be reported from
the CI team to the OMT, then from the OMT to the command element. In situations where the CI team is
located at a subordinate echelon from the OMT, command reports may be required to be submitted
simultaneously from the CI team to the OMT and the command element. The OMT, CICA/2X is
responsible for coordinating command reporting requirements.
9-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Reporting
9-10. The protected reporting channel includes the CI team, the responsible CI OMT, the CICA, and the
2X. All protected reporting concerning information that provides details on the identity of a source,
methods of communication, operational activity or meeting dates, times, and locations will be reported
from the CI team to the OMT, then from the OMT to the CICA, then the CICA to the 2X. The protected
reporting channel is used to protect the details of CI activities and the identities of CI sources. CI teams and
OMTs are not authorized to disclose details of or release information concerning any information reported
within the protected reporting channel unless approved by the responsible CICA and 2X.
9-11. The intelligence reporting channel includes the CI team, the responsible CI OMT and the 2X element
of the support unit. All intelligence reporting concerning information of intelligence value or that may be
used for protection or threat I&W will be reported from the CI team to the OMT, then from the OMT to the
intelligence staff, C/J/G/S-2. Although the intelligence staff, C/J/G/S-2 is the primary consumer of
intelligence reports, all intelligence reporting from CI teams will always be disseminated within the
intelligence reporting channels and protected channels simultaneously. This allows the operational
management elements to exercise technical authority over CI teams under their purview and prevent the
CICA and 2X from being caught off guard by sensitive or inflammatory CI reporting.
Figure 9-1. Reporting architecture
21 October 2009
FM 2-22.2
9-5
FOR OFFICIAL USE ONLY
Chapter 9
INFORMATION SHARING AND RELEASE
9-12. Units must develop SOPs for the passing of information and intelligence to multinational units. Units
will coordinate with Foreign Disclosure Officers, appropriate classification authorities, and higher
headquarters to develop procedures and standards to release reports and information to HN, allied, or
coalition elements. Report writers and editors must ensure that reports that are to be shared with
multinational units contain only releasable information. This will enable reports to have the widest
dissemination. Arrangements are made through the C/J-2X/LNO for distribution. When possible, reports to
be shared with multinational units should be kept to the appropriate classification to ensure the widest
dissemination of the reported information.
9-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Appendix A
Counterintelligence Program Administration
The Army Counterintelligence (CI) Program requires its members to be mature,
intelligent, and personable to carry out the broad range of CI functions to detect,
identify, exploit, and neutralize the foreign intelligence and security systems (FISS)
and international terrorist organizations (ITO) threat targeting U.S. forces. The CI
special agent has to be able to operate independently and be relied upon to make
sound judgments in the absence of higher leadership or supervision. The CI special
agent also has to interact with senior officials of both U.S. and host-nation (HN)
military, civilian law enforcement, intelligence, and security agencies. This requires
that personnel applying for the Army CI Program be among the most professional
and competent Soldiers in the Army. The CI applicant process is extremely important
in ensuring that the CI military occupational specialty (MOS) remains capable, and
that the most qualified and competent personnel are accepted into the Army CI
Program. CI special agents will conduct all interviews and processing of Army CI
Program applicants.
COUNTERINTELLIGENCE APPLICANT PROCESS
A-1. The CI applicant process should never be viewed as something to be done only if a CI special agent
or CI element has time for. Also, it should not be a task handed only to the most inexperienced CI special
agents in a unit. While it is good training to build organizational, planning, and interpersonal skills, the CI
applicant process should be about showcasing our most talented CI special agents to the CI applicant. The
professionalism, maturity, confidence, and competence of the interviewing special agent, may be
instrumental in assisting potential applicants in solidifying their decision to apply for the Army CI
Program.
A-2. CI special agents processing CI applicants will ensure they do not form any positive or negative
biases towards a potential CI applicant. All Soldiers who meet the eligibility requirements to be a CI
special agent should be afforded the opportunity to apply for the CI Program. Failure to meet requirements
or lack of character traits that would preclude them from being a professional and competent CI special
agent will be developed during the course of the CI applicant process.
A-3. The initial interview is the first contact between the prospective CI applicant and the CI special
agent. During the initial interview the CI special agent needs to explain the mission of Army CI, the
eligibility requirements for becoming a CI special agent, the process that must be completed to be accepted
into the Army CI Program, the training and potential assignments.
A-4. CI applicant qualifications include the following:
A physical demands rating of Medium.
A physical profile of 222221.
Normal color vision.
A minimum score of 102 in aptitude area ST/Technical score on the Armed Services
Vocational Aptitude Battery (ASVAB).
A minimum age of 21 years of age for award of MOS 35L accreditation as a CI special agent.
21 October 2009
FM 2-22.2
A-1
FOR OFFICIAL USE ONLY
Appendix A
A security clearance of interim top secret
(TS) with eligibility for access to sensitive
compartmented information (SCI) once TS clearance is granted.
A high school graduate or equivalent.
Possess good voice quality and be able to speak English without an objectionable accent or
impediment.
Never been a member of the U.S. Peace Corps.
No derogatory information in provost marshal, intelligence, military personal records jacket
(MPRJ), or medical records that would prevent the granting of a security clearance in
accordance with AR 380-67.
No records of conviction by court-martial.
No records of conviction by civil court for any offense other than minor traffic violations.
A U.S. citizen by birth.
Members of immediate family (spouse, parents, brothers, sisters, and children) must also
be U.S. citizens. Soldier and immediate family members can be naturalized citizens. If
naturalized, there is no minimum residency requirement.
Soldier and spouse must not have immediate family members who reside in a country
where physical or mental coercion is known to be a common practice, against persons
accused of or acting in the interest of the United States; the relatives of such persons to
whom they may reasonably be considered to be bound by ties of affection, kinship, or
obligation. Near relatives will also include uncles, aunts, grandparents, father-in-law,
mother-in-law, and relationships corresponding to any of the above persons in loco
parentis (AR 630-5 and 37 USC § 501).
Have neither commercial nor vested interest in a country where physical or mental coercion is
known to be a common practice against persons acting in the interest of the United States.
This requirement applies to the Soldier’s spouse as well.
Have an active Army Knowledge Online (AKO) email account. If you do not have an AKO
email account when your packet is sent forward, your packet will not be processed.
To qualify under the bonus extension and retention (BEAR) program (if applicable) the
Soldier must have less than 10 years of service at time of reenlistment on the day of
graduation from school.
A-5.
CI applicant process. The entire CI applicant process can be lengthy endeavor. The amount of time
it takes from initial inquiry to approval and orders production will be significantly affected by the
motivation of the CI applicant to get the required documentation and complete all applicant interviews and
compositions.
A-6. Initial contact and interview. The first contact with a prospective CI applicant may be over the
telephone. The CI special agent taking the call from a prospective applicant should arrange for a face-to
face meeting between the applicant and the CI special agent who will be processing the applicant. During
the initial interview, the applicant should be informed of the minimum qualifications for the Army CI
Program, as well as all the required documentation and the process for applying to the Army CI Program.
The processing CI special agent should refrain from forming any positive or negative biases against any
applicant during the process and especially the first interview. During the initial interview, if the
prospective applicant is serious about pursuing the CI application process, have the applicant complete an
applicant information sheet.
A-7. CI applicant requirements. The entire process for applying to the Army CI Program should be
covered in detail in the first interview including all the required documentation the applicant will be
responsible for completing or coordinating for himself. The actions that must be completed by the CI
A-2
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Program Administration
applicant are broken down into an 11-step process. The CI applicant process is outlined in DA Pam 600-8,
procedure 3-33-1, dated 1 August 1986. A copy of the DA pamphlet can typically be found at personnel
and administration center (PAC) or the servicing personnel servicing company.
Step 1:
Action required by: Individual.
Description of actions: Inform immediate supervisor and unit commander of intention to
volunteer for MI service. Currently not required, but is recommended for the future MI
applicant to take the Defense Language Aptitude Battery (DLAB) test at the education
center.
Step 2:
Action required by: Unit commander/1SG/battalion PAC/personnel services
noncommissioned officer (PSNCO).
Description of actions: Assist Soldier in preparing DA Form 4187 (Personnel Action)
requesting MI training. Privacy Act Statement will be furnished to Soldier before having
individual complete DA Form 4187. (This is done by the PAC.)
Step 3:
Action required by: PSNCO.
Description of actions: Arrange an appointment with the S-2/G-2 or security manager for
completion of SF 86 (Questionnaire for National Security Positions).
Arrange an appointment with the photographic facility. The photograph is to be full
length in class “A” uniform (or their equivalent). No civilian clothing photograph is
required.
Step 4:
Action required by: S-2/G-2/security manager.
Description of actions: Advise all applicants they must undergo a single-scope
background investigation (SSBI). CI applicant must arrange with their S-2/G-2 or unit
security manager to complete the SF 86. The CI applicant must include two SFs 86 in
their packet. One SF 86 will be an original front and back and the second SF 86 a
reproduced copy.
Complete two copies of FD-258 (FBI Fingerprint Card). Ensure all personal history and
physical characteristics blocks are completed and both individual and person taking
fingerprints sign the appropriate signature blocks.
Step 5:
Action required by: Photographic facility.
Description of actions: Prepare 3/4-length photograph of individual in class “A” uniform
(or equivalent).
Step 6:
Action required by: PSNCO.
Description of actions: Upon completion of steps 4 and 5, arrange an appointment with
military personnel office
(MILPO). Have Soldier hand carry DA Form 4187 with
supporting documents to the MILPO.
21 October 2009
FM 2-22.2
A-3
FOR OFFICIAL USE ONLY
Appendix A
Step 7:
Action required by: Personnel management specialist.
Description of actions: Obtain a MPRJ from records branch; verify that Soldier meets
eligibility criteria and prerequisites contained in AR 614-200, section II, chapter
7;
DA Pam 351-4; and the MOS requirements in AR 611-201. Ensure that SF 86, FD-258,
and photograph are attached; prepare forwarding comment to local supporting CI
element. Reproduce and attach one copy of the Soldier’s DA Forms 2 and 2-1 (Personnel
Qualification Record) or enlisted records brief (ERB) to the request.
Step 8:
Action required by: Personnel management supervisor.
Description of actions: Review documents from steps 1 through 7 to ensure tasks are
completed.
Step 9:
Action required by: Personnel management officer.
Description of actions: Review and sign documents as required in steps 1 through 8.
Step 10:
Action required by: Records specialist.
Description of actions: File copy of request for MI training as action pending document
in MPRJ.
Step 11:
Action required by: Personnel management specialist.
Description of actions: Arrange for an interview by an experienced CI special agent. On
day of interview, have Soldier obtain MPRJ for review by CI special agent. Have Soldier
take DA Form 4187 with enclosures to interview.
A-8.
Required documentation. Required documentation in the CI applicant packet includes the
following:
SF 86. This personnel security questionnaire (SSBI) is required of all applicants, regardless of
current security clearance status. In addition, a NAC on applicant’s spouse is required. This is
done through the S-2. The applicant must have signed copies of the back pages of the
questionnaire.
FD-258. FBI fingerprint card.
DA photograph. One DA photograph in class A uniform is all that is required. It need not be
full-length, and no civilian photograph is necessary.
DA Form 4187 (DA Pam 600-8, procedure 3-33-1). It is important that the applicant have
the DA Form 4187 signed by the appropriate commander, and then turned into the
interviewing agent. The DA Form 4187 must accompany the rest of the packet. The THRU
and FROM sections of the DA Form 4187 will be completed as norm, but will be addressed:
TO: “Commander, HRC, ATTN: AHRC-EPB-M, 2461 Eisenhower Avenue, Alexandria, VA
22331-0400.” In section III, part 8, the applicant must check the OTHER block and insert “MI
Application, in accordance with procedure
3-33.” Section IV
- Remarks will contain
applicant “(Rank, LAST NAME) meets all perquisites specified to reclass to MOS 35L.” If
the BEAR program is in effect, another line should be added: “(Rank, LAST NAME) requests
retraining on BEAR program option of CI (35L) in the MI branch.” In section V, ensure
A-4
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Program Administration
applicant’s commander checks the block “Recommend Approval” only. DA will check the
block for “Is Approved” or “Is Disapproved.”
Enlisted records brief. If any additional information, pertinent to the applicant’s
qualifications for MOS 35L, is not recorded in the ERB, include that documentation. For
instance, if a Soldier’s recorded service test (ST) score on the DA Form 2-1 is no longer
current, include a copy of the test results showing the updated ST score.
Privacy Act Advisement. This form will be signed and dated by the applicant at the local MI
office when you come in for the interview.
Defense Language Aptitude Battery test results
(optional, but recommended).
Memorandum from tester at the education center stating the results of the test.
Other documents. Any request for waivers of qualifications and explanations of events that
might reflect negatively on the Soldier’s suitability for the MOS 35L.
AKO email address. It is now required to have an active AKO email account to process for
MOS 35L. If you do not have an AKO account when your packet is sent forward, your packet
will NOT be processed.
A-9. Processing interview. The processing interview is the next major step for a CI applicant to join the
Army CI Program. Due to the significant amount of personal time and actions required for the CI Applicant
process, normally only the most serious applicants will get to this point. The processing interview is the
point in which the interviewing agent will collect all the required documentation required from the CI
applicant.
A-10. During the processing interview, the CI applicant should be afforded the opportunity to withdraw
from the application process. This allows the agent to determine the motivation and fortitude of the
applicant about joining the CI Program. During the processing interview the interviewing agent will have
the CI applicant complete three written exercises. These statements are designed to judge the maturity,
expectations, and written skills of the CI applicant to ensure they have the character traits to complete CI
training and to successfully carry out the duties and responsibilities of a CI special agent.
Contingency statement. The applicant will complete the statement in his own handwriting,
sign and date, in pen.
Motivational composition. The applicant will be given a 10-minute time limit to complete
the motivational composition in pencil stating why he is applying for the position of a CI
special agent.
Biographical composition. The applicant will be given a 45-minute time limit to complete
the biographical composition describing their family background and other influences in their
life; major fields in which they have been employed (for example, sales, office work, farming,
laborer); significant incidents in their life which has affected their personality, character, or
outlook on life; major interests in life and what has been done to develop them.
A-11. Final interview. The final interview is a final information gathering and assessment meeting
between the interviewing agent and the CI applicant. Before the final interview, the interviewing agent will
review all the documentation, security questionnaires, and compositions completed by the CI applicant to
help the interviewing agent explore any gaps in the applicant’s background or potential vulnerability and
weaknesses that would indicate the applicant may be a liability as a CI special agent. During this interview
the interviewing agent will also try to identify those attributes and character traits of the applicant that
would make him an asset in the Army CI Program. As with the processing interview, during the final
interview the CI applicant should be afforded the opportunity to withdraw his packet from consideration to
ensure the applicant is devoted to becoming a CI special agent.
A-12. Processing CI applicant packet. After the final interview is completed, the interviewing agent will
prepare a statement of interview detailing the key points of the interview as well as his recommendation for
approval or disapproval and the reasons why. A letter of transmittal will be prepared. The transmittal letter,
21 October 2009
FM 2-22.2
A-5
FOR OFFICIAL USE ONLY
Appendix A
statement of interview, and all required documentation will be forwarded to the U.S. Army Human
Resources Command (USAHRC). The interviewing agent will contact the applicant and the applicant’s
unit commander to inform them the packet has been forwarded to USAHRC. The interviewing agent
should keep both the applicant and the commander informed as to the status of the process and when the
final approval or disapproval is granted by HRC.
A-13. On-the-job training (OJT). Upon notification of acceptance into the 35L MOS, the CI applicant can
request through his chain of command to attend OJT with the CI element that supported his CI applicant
process. For OJT sessions lasting more than 6 months, attachment orders may be required. For OJT
sessions shorter than six months, DD Form 1610 (Request and Authorization for TDY Travel of DOD
Personnel) are not required but may be desired. The CI applicant can obtain an acceptance letter from the
supporting CI office endorsing his request for OJT. During the OJT time, the CI applicant will remain
assigned to his original unit; however, the CI element providing OJT will provide feedback and bullets for
evaluations.
A-14. Issuance of CI badge and credentials. Newly certified CI special agents are NOT issued CI badge
and credentials during or at the completion of the CI special agents course (CISAC). Their gaining unit will
be responsible for submitting a request justifying the need for CI badge and credentials to the Army CI
Badge and Credentials Program Office, INSCOM Training and Doctrine Support (ITRADS) Detachment,
Fort Huachuca, AZ. ITRADS will adjudicate the request for issuance of the CI badge and credentials.
A-15. Counterintelligence Probationary Program (CIPP). All newly certified CI special agents are
required to complete a one-year probationary period and be favorably recommended for retention in the
Army CI Program by their unit commander. The CIPP period begins immediately upon reassignment to the
first assignment in a CI position.
ARMY COUNTERINTELLIGENCE BADGE AND CREDENTIALS
PROGRAM
A-16. The Army CI Badge and Credentials Program grants the bearer of the CI badge and credentials
special recognition and bona fides during the conduct of official Army CI activities with other U.S. military
and civilian governmental agencies. Because of the special access, official privileges and authority
associated with possession of CI badge and credentials are considered sensitive items requiring the same
strict issue, control, and accountability procedures afforded to weapons or cryptographic items.
A-17. The Army staff CI and HUMINT operations coordinator (G-2X) is the executive agent for the
Army’s CI Badge and Credentials Program. The Army G-2X is responsible for establishing policy
governing the issuance, use, and accountability for CI badge and credentials. ITRADS, Fort Huachuca, AZ,
is the program manager for the CI badge and credentials program.
A-18. Army CI badge and credentials are issued only to persons who—
Have completed a CI qualification course approved by the DA G-2 for the issuance of CI
badge and credentials.
Have been awarded MOS 35L enlisted (formerly 97B), 351L warrant officers (formerly
351B), 35E officers and government civilians in occupation series 0132 (including Army
civilians and members of the MI Civilian Excerpted Career Program [MICECP]).
Are at least 21 years of age.
Are assigned to a CI position requiring the use of CI badge and credentials to accomplish the
unit’s mission.
A-19. Unit custodians. All units who have assigned CI special agents are required to appoint both a
primary and an alternate CI badge and credentials custodian. The CI badge and credentials custodian is
responsible for—
A-6
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY
Counterintelligence Program Administration
Implementing a suspense system for tracking and receipting for inbound CI badge and
credentials materials, whether shipped or hand-carried to the unit.
Receipting for CI badge and credentials materials, by badge and credentials control numbers,
on the same day the CI badge and credentials materials arrive at the unit, whether shipped to
the unit or hand-carried during reassignment.
Coordinating hand-carry transfers, regardless of whether the agent wants to hand-carry, when
the agent is being reassigned to a unit listed on the account custodian list.
Inventorying all unit CI badge and credentials materials semiannually and when the unit’s
primary custodians change.
Retaining all serviceable CI badge and credentials and representative credential cases for CI
badge and credentials materials returned to ITRADS. Unserviceable cases should be cut in
half and thrown away.
A-20. Unit account holders. Unit account holders are the commander or the C/J/G/S-2 of the unit. Unit
account holders have the responsibility of—
Ensuring that the unit has a primary and alternate CI badge and credentials custodian
appointed on orders signed by the commander.
Requesting the establishment of a CI badge and credentials account if there are CI special
agents assigned to the unit or subordinate units for which the unit account holder is
responsible.
Coordinating with the CI badge and credentials program manager to revalidate CI badge and
credentials accounts that have been suspended, de-activated, or otherwise in a dormant state.
COUNTERINTELLIGENCE BADGE AND CREDENTIALS INVENTORIES
A-21. Army CI badge and credentials consist of the following:
MI badge. The MI badge has a control number stamped into the back; this is the number
custodians report on receipts and inventories.
Intelligence credentials. DA Form 3363 (US Army Intelligence Credential Special Agent),
DA Form 3363A (US Army Intelligence Credential Representative), or DA Form 3363-1 (US
Army Intelligence Credential Photograph /Signature). Each form has a 6-digit control number
printed on the reverse side of the card; this is the number custodians will report on all receipts
and inventories.
A-22. Custodians are required to conduct a 100 percent, hands-on, physical inspection and inventory of all
CI badge and credentials materials issued to the unit’s account. This is done semiannually and when the
unit’s primary custodian changes.
A-23. Semiannual inventories must be conducted every six months based upon the schedule produced by
ITRADS and the results forwarded to ITRADS.
A-24. Change of custodian inventories require a joint inventory be conducted between the incoming and
outgoing primary custodians. This joint inventory must be conducted and reconciled with ITRADS before
the physical departure of the outgoing primary custodian, and must be signed by both the incoming and
outgoing primary custodians.
A-25. Custodians may not conduct an inventory using on-hand receipts. When an individual issued CI
badge and credentials materials is not present for an inventory (deployment, extended TDY, other), the
custodian will contact that individual or another responsible person who can verify that the individual still
has the items in his possession, and to confirm all appropriate control numbers to the custodian.
21 October 2009
FM 2-22.2
A-7
FOR OFFICIAL USE ONLY
Appendix A
A-26. Inventories will be prepared in a roster (column) format, alphabetically, with separate columns for
the agent’s name, rank, badge number, and DA Forms 3363, 3363A, and 3363-1 numbers. If the unit is not
responsible for representative credentials, then there will be no requirement for a DA Form 3363A column.
Note. Do not include social security numbers on inventories.
A-27. All inventories faxed to ITRADS must be signed by the custodian who conducted the inventory.
A-28. Because of the signature requirement for change of custodian inventories, they must be faxed to
ITRADS. The signed inventory may be scanned and saved as a .pdf document (Adobe Acrobat readable).
A-29. When CI badge and credentials materials are transferred to another unit’s account or returned to
ITRADS, those items remain on the losing unit’s inventory until the gaining unit’s custodians or ITRADS
receipts for the items.
A-30. The physical inspection of the CI badge and credentials materials is to ensure the badge is not worn,
tarnished, or excessively bent. The credential forms will be inspected to ensure the lamination is not
splitting or they are excessively scratched.
A-31. The unit’s inventory will be compared against the Army’s Central CI Badge and Credentials
Repository database. Once the inventory is reconciled, ITRADS will send an email to the unit custodian
confirming the reconciliation. The email will provide the month and year the unit’s next semiannual
inventory is due, and direct the custodian to print the inventory reconciliation email as the unit’s official
inventory reconciliation documentation. This email is required to be maintained on file by the unit until the
next semiannual or change of custodian inventory is reconciled.
A-32. Individual responsibilities. Individuals issued CI badge and credentials are responsible for the
safeguard, protection, accountability, and use of their CI badge and credentials. Although CI badge and
credentials are issued from ITRADS to the individual’s CI special agent based upon an operational
requirement, unit SOPs may provide for more stringent controls, protection, and accountability of CI badge
and credentials. CI badge and credentials are Army property. Personnel issued CI badge and credentials
will—
Use the CI badge and credentials in accordance with Army policy, doctrine, and unit SOPs to
support their unit’s mission.
Protect and safeguard their CI badge and credentials to ensure accountability.
Execute a statement acknowledging their responsibilities for the use and safeguarding of the
CI badge and credentials when issued and reissued CI badge and credentials.
Immediately report any misuse, loss, or theft of CI badge and credentials to the unit CI badge
and credentials custodian.
Coordinate with the unit CI badge and credentials custodian for the transport or transfer of CI
badge and credentials upon notification of reassignment.
Be knowledgeable of all policies and procedures for the use, protection, and accountability of
CI badge and credentials.
Surrender his CI badge and credentials to the unit CI badge and credentials custodian when
going on leave, TDY, international travel, or any other absence that does not require the use
of CI badge and credentials.
HAND-CARRYING COUNTERINTELLIGENCE BADGE AND CREDENTIALS
A-33. The following are custodian definitions:
Losing unit custodians—custodians for the unit the agent is currently assigned to.
Gaining unit custodians—custodians for the unit the agent is being reassigned to.
A-8
FM 2-22.2
21 October 2009
FOR OFFICIAL USE ONLY

 

 

 

 

 

 

 

Content      ..      1      2      3      ..