Core Doctrine
- Deny collection by making it hard
- Detect intrusion by making it visible
- Deceive adversaries by feeding controlled information
Threat Actors
- Watch foreign intelligence services
- Guard against insiders and extremists
- Treat criminals and sensors as collectors
The CI Pillars
- Build awareness of threat and vulnerabilities
- Secure sensitive information and relationships
- Detect collection efforts early
You Leak Data
- Vary movement patterns and routines
- Mind communication content, timing and metadata
- Shrink your digital footprint and devices
Collection Methods
- Expect surveillance and human sources
- Assume SIGINT and cyber intrusion
- Treat open source as adversary fuel
Indicators
- Note repeated encounters and probing questions
- Flag rapid trust-building or isolation attempts
- Treat patterns, not single signs, as warnings
Emission Control
- Limit what you transmit
- Eliminate unnecessary signals
- Refuse pressure toward insecure channels
Countermeasures
- Control access, information and movement
- Apply tradecraft to every action
- Endure by staying ahead of evolving threats