GCFA · Question #248
Which of the following are known as the three laws of OPSEC? Each correct answer represents a part of the solution. Choose three.
The correct answer is A. If you are not protecting it (the critical and sensitive information), the adversary wins! B. If you don't know the threat, how do you know what to protect? C. If you don't know what to protect, how do you know you are protecting it? The three laws of OPSEC establish that protecting critical information requires knowing what to protect, understanding the threat, and actively safeguarding that information.
Question
Which of the following are known as the three laws of OPSEC? Each correct answer represents a part of the solution. Choose three.
Options
- AIf you are not protecting it (the critical and sensitive information), the adversary wins!
- BIf you don't know the threat, how do you know what to protect?
- CIf you don't know what to protect, how do you know you are protecting it?
- DIf you don't know about your security resources you cannot protect your network.
How the community answered
(41 responses)- A76% (31)
- D24% (10)
Why each option
The three laws of OPSEC establish that protecting critical information requires knowing what to protect, understanding the threat, and actively safeguarding that information.
The first law of OPSEC states that failure to actively protect critical and sensitive information concedes the advantage to the adversary, establishing protection as a non-negotiable operational imperative. This law defines the ultimate consequence of OPSEC failure and provides the overarching justification for the entire discipline.
The second law establishes that threat identification is a prerequisite for effective OPSEC - without knowing what the adversary seeks, defenders cannot properly prioritize or direct their protection efforts. Understanding the threat shapes every subsequent OPSEC decision and determines which information requires the most rigorous safeguards.
The third law requires a clear definition of what constitutes critical information, because without knowing what needs protection it is impossible to verify whether protection measures are actually being applied. This law drives the critical information identification process that is the foundation of any OPSEC program.
Awareness of security resources is a general network defense principle and is not one of the three formal laws of OPSEC, which focus on critical information identification, threat awareness, and active protection rather than resource inventory.
Concept tested: Three formal laws of Operations Security OPSEC
Source: https://www.cdse.edu/catalog/elearning/IF011.html
Topics
Community Discussion
No community discussion yet for this question.