OPSEC monitoring
OPSEC monitoring is the continuous process of evaluating intelligence collection methodologies and counterintelligence. It is necessary to monitor policies, procedures, and methods for effectiveness because an unevaluated OPSEC implementation can lead to a false and dangerous sense of security. OPSEC monitoring is not a program that should exist within your CTI program; rather, it should exist inside your information security organization with frequent stakeholder interaction between the two organizations.
The OPSEC monitoring program that evaluates CTI organizations should measure the maintenance of the appropriate OPSEC procedures and how the corporate policies around OPSEC are utilized. These activities should include, but not be restricted to, the following:
- Using appropriate information security systems to prevent system compromise.
- Using technical OPSEC procedures to ensure non-attribution during collection operations.
- Using identity OPSEC...