{"title":"Operations security: the missing link","authors":"D. B. Nickell","doi":"10.1109/CCST.1989.751962","DOIUrl":null,"url":null,"abstract":"Operations Security (OPSEC) comprises a rational approach, complementary to physical, personnel, and information security disciplines, to the identification and protection of critically important technology and information. OPSEC incorporates elements of operations and decision analysis, and draws on the skills of intelligence and security specialists to provide managers with a realistic basis for directing security activities. OPSEC is concerned with identifying and protecting information which adversaries could otherwise exploit to the agency or corporate detriment. For the first time in literature, we describe the means to quantify and evaluate the effectiveness of an OPSEC system and introduce the concept of a \"window of ambiguity.\" Through this approach we show that the higher the degree of uncertainty about the validity of available information, the more effective the OPSEC program. OPSEC is unique in that it places the responsibility for critical security decisions firmly in the hands of senior management, arming them with the information they need to make those decisions and the techniques essential to implementing them. OPSEC thus represents the missing link among management's objectives, a complex physical and information security system, and a totally effective, integrated security program.","PeriodicalId":288105,"journal":{"name":"Proceedings. International Carnahan Conference on Security Technology","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1989-10-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings. International Carnahan Conference on Security Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCST.1989.751962","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Operations Security (OPSEC) comprises a rational approach, complementary to physical, personnel, and information security disciplines, to the identification and protection of critically important technology and information. OPSEC incorporates elements of operations and decision analysis, and draws on the skills of intelligence and security specialists to provide managers with a realistic basis for directing security activities. OPSEC is concerned with identifying and protecting information which adversaries could otherwise exploit to the agency or corporate detriment. For the first time in literature, we describe the means to quantify and evaluate the effectiveness of an OPSEC system and introduce the concept of a "window of ambiguity." Through this approach we show that the higher the degree of uncertainty about the validity of available information, the more effective the OPSEC program. OPSEC is unique in that it places the responsibility for critical security decisions firmly in the hands of senior management, arming them with the information they need to make those decisions and the techniques essential to implementing them. OPSEC thus represents the missing link among management's objectives, a complex physical and information security system, and a totally effective, integrated security program.