GSEC · Question #38
Which of the following is the FIRST step in performing an Operational Security (OP5EC) Vulnerabilities Assessment?
The correct answer is E. Identification of critical information. The OPSEC five-step process always begins with identifying critical information because every subsequent step - threat analysis, vulnerability analysis, risk assessment, and countermeasures - depends on first knowing what must be protected.
Question
Which of the following is the FIRST step in performing an Operational Security (OP5EC) Vulnerabilities Assessment?
Options
- AAssess the threat
- BAssess vulnerabilities of critical information to the threat
- CConduct risk versus benefit analysis
- DImplement appropriate countermeasures
- EIdentification of critical information
How the community answered
(37 responses)- A8% (3)
- B3% (1)
- C11% (4)
- D3% (1)
- E76% (28)
Why each option
The OPSEC five-step process always begins with identifying critical information because every subsequent step - threat analysis, vulnerability analysis, risk assessment, and countermeasures - depends on first knowing what must be protected.
Assessing the threat is the second OPSEC step and cannot be meaningfully performed until critical information has been identified in step one.
Assessing vulnerabilities of critical information is the third step and presupposes that both critical information (step 1) and threats (step 2) are already known.
Risk versus benefit analysis is the fourth step and requires completed threat and vulnerability assessments from the preceding steps before it can be conducted.
Implementing countermeasures is the fifth and final step; applying measures before completing all prior analysis steps would be arbitrary and potentially misdirected.
Identification of critical information is the mandatory first step because without knowing which information is sensitive and operationally significant, analysts have no basis to assess threats against it, identify how it could be exposed, or determine what countermeasures are warranted. The entire OPSEC process is scoped and driven by what is identified in this initial step.
Concept tested: OPSEC five-step process - first step identification
Source: https://www.cisa.gov/opsec
Topics
Community Discussion
No community discussion yet for this question.