Back to glossaryCyber

OPSEC (operational security)

Process of identifying and protecting information that, if it reached an adversary, would allow them to deduce intentions, capabilities or vulnerabilities.

Definition

OPSEC is a term of American military origin, formalized under the name Operation Purple Dragon during the Vietnam War in the mid-1960s, when US commands realized that the Viet Cong appeared to systematically anticipate their operations, not through classical espionage but by cross-referencing fragmentary information available from open sources. The five-step OPSEC process, identifying critical information, analyzing threats, analyzing vulnerabilities, assessing risks and applying countermeasures, was adopted by presidential directive NSDD-298 in 1988 and gradually diffused into the civilian world of information security. In this context, OPSEC denotes the set of practices aimed at not inadvertently revealing exploitable information to an adversary: not announcing incident-response engagement dates on social media, not publishing screenshots revealing software versions or internal usernames, and not leaving revealing metadata in published documents. In cyber insurance, an organization's OPSEC is assessed at underwriting: external communication about technologies used, open positions or past incidents constitutes an information surface exploitable by an attacker, and advanced underwriting questionnaires now include questions about the insured's communication practices. Ironically, poorly trained attackers often compromise their own operations through bad OPSEC practices, email address reuse, use of traced commercial services, which feeds the work of threat intelligence teams.

Example

A threat intelligence analyst identifies the probable developer of a ransomware strain by cross-referencing their forum pseudonym with a Gmail address used when registering for a developer conference in 2017, a Bitcoin address whose transactions trace back to a KYC exchange, and a LinkedIn job posting for a position matching their skills. The attacker's poor OPSEC enables attribution that years of technical analysis had not provided.

Related terms
Also known as

OPSEC, sécurité opérationnelle, operational security, compartimentage de l'information