Files
mosaic/output/manuals/01_HUMINT_Operations.md
T

32 KiB

HUMINT Operations Manual

Synthesized from: Allen Dulles "Some Elements of Intelligence Work," FM 2-22.3, JSOU Report 12-3, CIA tradecraft manuals (declassified), Grugq OPSEC analyses

Classification: OPEN SOURCE — compiled from publicly available and declassified materials


Table of Contents

  1. Foundations
  2. The Agent Recruitment Cycle
  3. Elicitation
  4. Agent Handling & Communication
  5. Cover & Legend Discipline
  6. Clandestine Organization Structure
  7. Counter-Intelligence
  8. Case Studies & Lessons Learned
  9. Operational Checklists

Chapter 1: Foundations

1.1 The Nature of HUMINT

Human Intelligence is the oldest form of intelligence collection. It is also the most dangerous, the most unreliable, and the most valuable. Every other collection discipline — SIGINT, IMINT, MASINT, OSINT — tells you what is happening. HUMINT tells you why, and sometimes what will happen next.

HUMINT operations rest on a simple premise: people with access to secrets can be persuaded to share them. The persuasion may take many forms — ideology, money, coercion, ego, revenge — but the fundamental transaction is always human. This makes HUMINT operations simultaneously powerful and fragile. A single relationship built over years can produce intelligence that no satellite or intercept can match. A single mistake — a careless phone call, an unnoticed surveillance team, a compromised colleague — can destroy an entire network and cost lives.

1.2 The Dulles Principles

Allen Dulles, director of the CIA from 1953 to 1961, wrote a set of operational principles that remain the foundation of Western intelligence tradecraft. These principles, titled "Some Elements of Intelligence Work," distill decades of operational experience into rules that are deceptively simple and absolutely non-negotiable.

The Cardinal Rules:

  1. Security above all. "The greatest of them all is security. All else must be subordinated to that." This is not a suggestion. It is the single principle from which all others flow. Every decision in an operation must be evaluated first through the lens of security.

  2. Security is in the small things. "It consists in carrying out daily tasks with painstaking remembrance of the tiny things that security demands. The little things are in many ways more important than the big ones. It is they which oftenest give the game away." The operative who leaves a classified document on a desk for thirty seconds, who mentions a colleague's name to a taxi driver, who forgets to check a mirror on the way to a meeting — this operative will eventually be caught. Security is not an occasional effort. It is a permanent state of mind.

  3. Practice makes permanent. "The man or woman who does not indulge in the daily security routine, boring and useless though it may sometimes appear, will be found lacking in the proper instinctive reaction when dealing with the bigger stuff." When the pressure comes — and it will — you will fall back on your training. If your training is sloppy, your reaction will be sloppy. Practice security routines until they are automatic. Then practice more.

  4. Never admit. "Even though you feel the curious outsider has probably a good idea that you are not what you purport to be, never admit it. Keep on playing the other part. It's amazing how often people will be led to think they were mistaken." Cover is maintained not by perfection but by consistency. People doubt their own suspicions. Give them reason to keep doubting.

  5. Vanity kills. "The next greatest vice is that of vanity. Its offshoots are multiple and malignant. Besides, the man with a swelled head never learns." The operative who needs to feel clever, who drops hints about their secret life, who takes unnecessary risks to prove their capability — this operative is a liability. The best operatives are invisible. They have no need for recognition.

  6. No hours. "In this job, there are no hours. That is to say, one never leaves it down. It is lived. One never drops one's guard." Every social occasion is an opportunity to lay a false trail, to pick up information, to make a useful acquaintance. The operative who compartmentalizes their life into "on duty" and "off duty" has already made a fundamental error. You are always on.

  7. The telephone is the enemy. "The greatest material curse to the profession, despite all its advantages, is undoubtedly the telephone. It is a constant source of temptation to slackness." Always assume every conversation is listened to. Never discuss operations by phone. If you must use a phone, think out what you will say before you dial. Better yet: "Make a day's journey, rather than take a risk, either by phone or post."

  8. Alcohol and sex are operational vulnerabilities. "Booze is naturally dangerous. So also is an undisciplined attraction for the other sex. The first loosens the tongue. The second does likewise. It also distorts vision and promotes indolence." This is not moralizing. It is operational reality. Both are primary vectors for compromise and recruitment by hostile services.

  9. Write it down, but carefully. "When you have conducted an interview or made arrangements for a meeting, write it all down and put it safely away for reference. Your memory can play tricks." But: "Learn to write lightly; the 'blank' page underneath has often been read. Be wary of your piece of blotting paper. If you have to destroy a document, do so thoroughly. Carry as little written matter as possible, and for the shortest possible time. Never carry names or addresses en clair."

  10. Carelessness is irreversible. "The greatest vice in the game is that of carelessness. Mistakes made generally cannot be rectified." In most professions, you can recover from a mistake. In intelligence, a single error can burn a network that took a decade to build.


Chapter 2: The Agent Recruitment Cycle

2.1 Overview: SADRAT

The recruitment of a human intelligence source follows a cycle known by various mnemonics. The most common is SADRAT:

  • Spot — Identify potential sources
  • Assess — Evaluate suitability and vulnerability
  • Develop — Build the relationship
  • Recruit — Make the pitch
  • Agent handling — Run the source
  • Terminate — End the relationship

Each phase has distinct tradecraft requirements and risks. Rushing through phases or skipping them entirely is the most common cause of recruitment failure.

2.2 Spotting

Spotting is the identification of individuals who have access to desired intelligence and may be susceptible to recruitment. Good spotting is the foundation of everything that follows. Recruit the wrong person and you waste months or years. Recruit the right person and you win the intelligence war.

Access is primary. The most cooperative source in the world is useless if they cannot access the intelligence you need. Before evaluating personality, motivation, or vulnerability, answer one question: does this person have access?

Types of access:

  • Direct access — the person handles, sees, or creates the target information
  • Indirect access — the person knows someone who has direct access
  • Environmental access — the person is in a position to observe the target environment

Spotting methods:

  1. Official contact — Diplomatic receptions, conferences, trade shows, academic exchanges. These provide natural cover for initial contact.
  2. Third-party referral — An existing source identifies a potential new source. This is often the most productive method but carries risk if the referrer is compromised.
  3. Cold approach analysis — Study of organizational charts, publications, social media, and public records to identify officials with access. This produces candidates who may never have been contacted by an intelligence service.
  4. Walk-ins — Volunteers who approach with an offer. These are simultaneously the most valuable and the most dangerous potential sources. Every walk-in must be assessed for the possibility that they are a dangle — a controlled source sent by hostile counterintelligence.

2.3 Assessment

Assessment determines whether a spotted individual is suitable for recruitment and how to approach them. The assessment phase can last weeks, months, or years depending on the target's significance and the operational environment.

The MICE Framework

The classic framework for understanding recruitment motivation:

Money — Financial pressure, greed, lifestyle expectations beyond income. The most common and most reliable motivator. People who need money are predictable. People who want money are manageable. Look for: living beyond means, gambling debts, expensive divorce, addiction, sudden financial obligations.

Ideology — Belief that sharing information serves a higher purpose. The volunteer spy who believes their government is corrupt, their cause is just, or their information will prevent harm. Ideological recruits are often the most productive but also the most unpredictable. They may decide at any time that the higher purpose no longer justifies the risk. Look for: political dissatisfaction, moral objections to employer's activities, ideological alignment with your cause.

Compromise/Coercion — Leverage based on information the target wants kept secret. Extramarital affairs, financial crimes, hidden political affiliations, sexual orientation in hostile environments. Coercion produces immediate compliance but breeds resentment and unreliability. Use it as a last resort and always provide a face-saving framework. "We're not forcing you — we're giving you the opportunity to do the right thing."

Ego — The need to feel important, respected, or appreciated. The mid-level bureaucrat who has been passed over for promotion, the technical expert whose contributions go unrecognized, the official who believes they should be making policy rather than implementing it. Ego-driven sources are managed by making them feel valued. "You're the only person who really understands this issue."

Modern additions to MICE:

  • Revenge — Personal grievance against employer, colleague, or institution
  • Adventure — Thrill-seeking, desire for excitement in a boring life
  • Conscience — Similar to ideology but more personal; the whistleblower who cannot live with what they know

Assessment process:

  1. Identify the primary motivator (there may be more than one)
  2. Evaluate access level and quality
  3. Assess reliability indicators (stability, discretion, consistency)
  4. Identify vulnerabilities that hostile CI could exploit
  5. Evaluate the risk/reward ratio of recruitment
  6. Develop an approach strategy tailored to the individual

2.4 Development

Development is the gradual building of a relationship that will support a recruitment pitch. This is where patience is tested and careers are made. The development phase transforms a target from a stranger into someone who trusts you enough to commit espionage.

Principles of development:

  1. Natural contact. Every meeting must have a plausible reason unrelated to intelligence. Business, social, academic, cultural — the reason must be genuine enough to withstand scrutiny.

  2. Gradual escalation. Start with innocuous topics. Gradually introduce subjects closer to the target's area of knowledge. Never jump from small talk to classified information. The progression should feel natural to the target.

  3. Reciprocity. Share information to get information. People who feel they are in a one-sided conversation become suspicious. Provide non-sensitive information that makes the target feel the exchange is balanced.

  4. Build dependency. Create a relationship where the target values your friendship, your contacts, your resources, or your understanding. By the time you make the pitch, the target should feel that saying no would damage something they value.

  5. Test incrementally. Before the formal pitch, test the target's willingness to share sensitive information through increasingly specific questions. If they share willingly, they may already be psychologically recruited before the formal ask.

2.5 Recruitment

The recruitment pitch is the moment of maximum risk and maximum opportunity. Everything that follows depends on what happens in this conversation.

Before the pitch:

  • Ensure you have completed a thorough SDR (Surveillance Detection Route) — see Manual 02
  • Choose a location that is private, secure, and offers plausible cover for the meeting
  • Have a clear understanding of what you are asking and what you are offering
  • Prepare for all possible responses: acceptance, rejection, anger, panic, negotiation
  • Have a fallback position if the initial pitch is rejected

The pitch itself:

  1. Frame the ask. Do not say "I want you to spy for us." Frame it in terms the target will accept: "I'd like to formalize our information exchange," "Your insights are valuable and I want to make sure they reach the right people," "There's an opportunity for you to make a real difference."

  2. Appeal to the identified motivator. If money: be specific about compensation. If ideology: emphasize the impact of their contribution. If ego: stress how uniquely qualified they are. If compromise: present the choice as the target having agency, not being coerced.

  3. Establish the rules. Communication methods, meeting schedules, security protocols, reporting requirements. The target needs structure. Ambiguity breeds anxiety, and anxious sources make mistakes.

  4. Address fear. Every potential source is afraid. Afraid of being caught, of prison, of shame, of violence. Acknowledge the fear. Explain the security measures that protect them. Do not minimize the risk — they know the risk. Instead, demonstrate competence in managing it.

  5. Get a commitment. The pitch must end with a clear answer and a clear next step. "Can I count on you?" followed by "Our next meeting will be..."

2.6 Agent Handling

Once recruited, a source must be managed — tasked, debriefed, paid, motivated, and protected. The handler-source relationship is the backbone of HUMINT operations.

Communication:

  • Establish primary and backup communication methods (see Manual 03: Covert Communications)
  • Set regular meeting schedules with security protocols for cancellation/emergency
  • Use dead drops for routine material, personal meetings for tasking and debriefing
  • Every meeting preceded by SDR (see Manual 02)

Tasking:

  • Be specific about what you need. Vague requirements produce useless intelligence.
  • Prioritize. Do not overwhelm the source with requests.
  • Explain why the information matters when possible — motivated sources produce better intelligence.
  • Never task a source to do something that increases their exposure beyond acceptable risk.

Security:

  • Compartment the source's identity. Minimize the number of people who know who they are.
  • Vary meeting locations, times, and methods.
  • Monitor for changes in the source's behavior, access, or environment that might indicate compromise.
  • Have an exfiltration plan. If the source is compromised, you must be able to get them out.

Chapter 3: Elicitation

3.1 What Elicitation Is

Elicitation is the extraction of information through conversation without the target realizing that intelligence collection is taking place. It is the art of getting people to tell you things they shouldn't, while believing they are having a normal conversation.

Unlike interrogation, which is overt, elicitation is covert. The target never knows they were debriefed. This makes elicitation both repeatable and deniable.

3.2 Core Techniques

Flattery / Appeal to expertise. "You're clearly the person who understands this best. How does the new system actually work?" People love to demonstrate their knowledge. Position yourself as impressed and slightly ignorant. The target will fill the gap.

Provocative statement. State something slightly wrong about the target's area of expertise. "I heard the new encryption protocol only covers external communications." The target's instinct to correct you will produce real information. "Actually, it covers everything including internal traffic between..."

Assumed knowledge. Speak as if you already know most of the answer, but leave a gap. "So the deployment in the northern district uses the standard configuration, but I've heard the southern district has a different setup..." The target confirms, denies, or elaborates — all useful.

Quid pro quo. Share something first. It doesn't have to be classified or even sensitive — just interesting enough to create a sense of reciprocal obligation. "We've been seeing unusual network traffic from [country X]. Have you noticed anything similar?"

Bracketing. State a range and let the target narrow it. "The project budget is somewhere between five and fifty million, right?" The target will instinctively narrow: "It's closer to twenty." Now you know.

Deliberate ignorance. Play completely dumb. Ask simple, open-ended questions that require detailed explanation. "I've never understood how your organization's approval process works. Can you walk me through it?" People explaining processes reveal structure, personnel, and vulnerabilities.

The drunk friend. Not about actually being drunk, but about creating an atmosphere of casual, unguarded conversation. Late-night conferences, after-dinner drinks, informal social gatherings. People say more when they feel the conversation is "off the record."

3.3 Principles

  1. Never ask a direct question about the target information. Direct questions trigger security awareness. Indirect approaches bypass it.
  2. Let the target feel like the expert. You are the student. They are the teacher. This flatters their ego and makes them want to demonstrate knowledge.
  3. Multiple sessions. One conversation rarely produces actionable intelligence. Build the picture over multiple interactions. Each conversation adds fragments.
  4. Social settings. Alcohol genuinely does lower inhibitions. Use social occasions strategically, but never lose your own control while trying to reduce theirs.
  5. Listen more than you talk. The target should be doing 70-80% of the talking. Your role is to guide, not interrogate.

Chapter 4: Agent Handling & Communication

4.1 Communication Methods

The most dangerous part of any intelligence operation is communication between handler and source. This is when both parties are most exposed. Every communication method involves a trade-off between security and convenience. Always err on the side of security.

Hierarchy of communication security (most to least secure):

  1. Dead drop with pre-arranged signal (no contact, no timing correlation)
  2. Brush pass in public (sub-second contact, no meeting)
  3. Personal meeting at secure location after SDR (necessary for debriefing)
  4. Courier via trusted third party
  5. SRAC (Short Range Agent Communications) device
  6. Encrypted digital communication (creates metadata)
  7. Telephone (never for operational content)

See Manual 03: Covert Communications for detailed procedures.

4.2 Meeting Protocols

Pre-meeting:

  1. Conduct full SDR (2-4 hours minimum in hostile environment)
  2. Confirm "black" status (no surveillance detected)
  3. Arrive at meeting location via planned route
  4. If meeting is canceled (danger signal observed), execute emergency protocol

During meeting:

  1. Keep meetings short. The longer you are together, the greater the risk.
  2. Cover story for the meeting must be plausible if observed.
  3. Debrief first (collect intelligence), then task (assign new requirements).
  4. Address source morale and security concerns.
  5. Handle payments if applicable.
  6. Set next meeting date, time, location, and backup.
  7. Establish danger signals for next meeting.

Post-meeting:

  1. Depart separately, via different routes.
  2. Conduct counter-surveillance on departure.
  3. Write up meeting notes at the earliest secure opportunity.
  4. File intelligence reports through proper channels.
  5. Assess any security concerns from the meeting.

Chapter 5: Cover & Legend Discipline

See Manual 05: Cover and Identity for comprehensive treatment. Key principles:

5.1 Cover Levels

  • Light cover: Alias name only. Suitable for brief, low-risk contacts.
  • Medium cover: Alias with supporting documentation (ID, business cards, backstopped phone number). Suitable for extended contact in permissive environments.
  • Deep cover: Full legend with years of backstory, employment history, social media presence, and established pattern of life. Required for hostile environments and long-term penetration operations.

5.2 The Dulles Rule on Cover

"Do not overwork your cover to the detriment of your jobs; we must never get so engrossed in the latter as to forget the former."

Cover is not an afterthought. It is the foundation that makes everything else possible. An operative without solid cover is a tourist, not a spy.


Chapter 6: Clandestine Organization Structure

6.1 Cell Structure

The fundamental unit of clandestine organization is the cell: a small group of individuals who work together and are isolated from other cells by compartmentation. Cell structure provides resilience against penetration. When one cell is compromised, the damage stops at the cell boundary.

Structural compartmentation: Each cell knows only its adjacent cells. A member of Cell A knows Cell A's members and has contact with one member of Cell B. That is all. Cell A does not know that Cell C exists.

Functional compartmentation: Tradecraft practices that minimize the operational signature of the organization. Even within a cell, members know only what they need to know for their specific function.

Key insight from JSOU Report 12-3: In the Iraqi insurgency, RAND analyst Bruce Hoffman initially concluded the insurgency was "uncoordinated and disconnected" with "no static wiring diagram." He was wrong. The insurgency was a tightly coordinated clandestine cellular network that applied excellent tradecraft to remain hidden. The visible parts of the network — the cells at the periphery that conducted attacks — practiced poor tradecraft and were detected. But the invisible connections between cells, protected by cut-outs and compartmentation, remained intact. When a frontline cell was destroyed, "a new one will take its place within a couple of weeks at the most."

6.2 Cut-Outs and Impersonal Communication

Cut-outs are mechanisms that prevent direct contact between members of different cells. They ensure that no single compromise can chain through the network.

Passive methods (lower signature):

  • Couriers — most secure method of moving messages and materials. Women and children are often used because they attract less suspicion at checkpoints.
  • Dead drops — one party deposits, another retrieves, no contact (see Manual 03)
  • Coded signals — visual indicators that convey pre-arranged messages

Active methods (higher signature):

  • Radio (detectable emissions)
  • Telephone (metadata collection)
  • Internet (traffic analysis)

The general principle: passive methods for high-threat environments, active methods only when the speed of communication justifies the increased risk.

6.3 Regeneration

Well-designed clandestine networks can regenerate destroyed cells because the organizational knowledge is distributed, not centralized. The cells that face the enemy are expendable. The deep network survives and replaces losses. This is why targeting only the visible cells of an insurgency or criminal organization is futile — you must penetrate the hidden infrastructure.


Chapter 7: Counter-Intelligence

7.1 The Informant Threat

The single greatest threat to any clandestine organization is the informant — a member who reports to the opposition. Technical surveillance can be defeated with tradecraft. Informants bypass all technical countermeasures because they are inside the organization.

As the Grugq writes: "When in doubt, it's a tout."

When a group with robust operational security practices is compromised, and the technical indicators don't explain how, the answer is almost always an informant.

7.2 The Reservoir Dogs SOP (Anti-Informant Tradecraft)

The Grugq analyzed the OPSEC procedures depicted in the film Reservoir Dogs, noting they are based on real SOPs used by Fatah and the Black September Organisation (BSO). These procedures provide effective protection against informants within an operational team:

Procedure 1: Assigned operational aliases. Aliases are assigned by the organization for the duration of the operation. They are random, unique to the operation, and not chosen by the operative. This prevents pattern development across operations and limits the information an informant can gather.

Procedure 2: Just-in-time team assembly. The operational team is formed immediately before the operation and kept isolated until after completion. This minimizes the time window for an informant to report back to their handlers.

Procedure 3: Dedicated independent operational support teams. Surveillance, logistics, and execution are handled by separate teams. Each team knows only their portion of the plan. Compromise of one team does not reveal the complete operation.

Strengths: Limits informant intelligence, protects agents until activation, provides operational compartmentation.

Weaknesses: Ad-hoc teams are less efficient (compressed forming-storming-norming-performing cycle). The organizational leadership who form teams become high-value targets — they know everyone. The team captain is a single point of failure — only person with the complete plan.

7.3 CI Awareness Indicators

Signs that a member may be compromised or may be an informant:

  • Unexplained knowledge of operations they weren't briefed on
  • Changes in financial status inconsistent with known income
  • Unusual interest in operational details beyond their need-to-know
  • Behavioral changes (anxiety, evasion, sudden eagerness to please)
  • Unexplained absences that correlate with opposition activity
  • Advocating for reduced security measures

Chapter 8: Case Studies & Lessons Learned

8.1 PIRA — The Paddy Factor

The Provisional IRA in the early 1970s demonstrated how basic counter-intelligence failures can devastate an organization.

The failures:

  • Members congregated in pubs and sang IRA songs, publicly identifying themselves
  • Members boasted about operations while drunk
  • Members responded to inquiries about their activities with "a nod and a wink"
  • Members marched in pro-IRA rallies
  • Members associated with each other when not on operations (pre-operational contact)

The consequence: British security forces identified known PIRA members through their public behavior. They then monitored these known members. When known members socialized with unknown members at rallies and pubs, the unknown members were identified through surveillance. Link analysis — mapping associations between nodes in a network — expanded the identified membership rapidly.

The lesson: Self-incrimination through public behavior is the most basic CI failure. It doesn't matter how strong your operational security is if your members advertise their affiliation in public. Pre-operational contact — socializing with operational colleagues outside of operations — creates links that surveillance can exploit. One known member in a social group exposes all unknown members.

8.2 Ross Ulbricht / Dread Pirate Roberts — Persona Contamination

The Silk Road case demonstrates what happens when compartmentation between identities fails.

The fatal chain:

  1. Ulbricht created the "altoid" persona to promote Silk Road on forums (Shroomery, BitcoinTalk)
  2. The altoid persona had no backstopping — no dedicated email address — so Ulbricht eventually posted his personal email (rossulbricht@gmail.com) on BitcoinTalk
  3. The "frosty" persona used to administer the Silk Road server was accessed from a location 500 feet from Ulbricht's Gmail login location
  4. Both Ulbricht and DPR shared the same ideology (Austrian School of Economics, mises.org), timezone, and geographic location
  5. Social isolation drove Ulbricht to seek validation on forums, lowering his security discipline

The lesson: Compartmentation between personas must be absolute. A single link — one shared email, one shared ideology publicly expressed, one shared location — can chain identities together. Backstop every persona. Never post personal identifiers from operational personas. And critically: isolation degrades judgment. Underground operatives who have no social life outside their operational community lose perspective and make mistakes.

8.3 Robert Morris — STFU

Robert Morris created the first major internet worm in 1988. He was identified and prosecuted not through technical forensics alone, but because he couldn't stop talking about it.

The failure: Morris briefed his friends — the "Morris Cell" — on all aspects of the worm: how it was developed, how it worked, what vulnerabilities it exploited. He did this at restaurants and social gatherings, including one incident where he jumped on a table to explain the worm's mechanics. His friends were subpoenaed as prosecution witnesses. They had no choice but to testify.

The lesson: STFU. Unless your lawyer instructs you otherwise, say nothing. The rule of thumb for need-to-know: if someone is not actively sharing the risk, they have no need to know. Even those who are sharing the risk should know only the aspects of the operation in which they are directly involved.

8.4 CIA Lebanon — Real-World Anonymity Failure

In late 2011, Hezbollah rolled up a CIA spy ring in Lebanon. The failure was not in encryption or digital security — it was in real-world tradecraft.

What happened: CIA agents had dedicated mobile phones used specifically for communication with their handlers. The phones were kept at static locations. Meetings occurred at pre-arranged locations (reportedly a Pizza Hut). Hezbollah's counter-intelligence identified the pattern: dedicated devices, static locations, predictable meeting schedules.

The lesson: Encryption protects content. It does not protect against traffic analysis, pattern analysis, or behavioral profiling. A dedicated device that only activates for handler communication is itself an anomaly. A static meeting location creates a pattern. Anonymity — hiding the fact that communication is occurring at all — is more important than secrecy of the communication's content.


Chapter 9: Operational Checklists

9.1 Pre-Recruitment Assessment Checklist

  • Target has confirmed access to desired intelligence
  • Primary motivation identified (MICE + additional factors)
  • Secondary motivations identified
  • Vulnerability assessment complete
  • Background investigation shows no CI red flags
  • Target is not a known or suspected dangle
  • Approach strategy developed
  • Cover for initial contact is plausible
  • Risk/reward assessment documented
  • Exfiltration plan exists if recruitment fails badly

9.2 Agent Meeting Checklist

  • SDR conducted (minimum 2 hours in hostile environment)
  • Confirmed "black" — no surveillance detected
  • Meeting location is secure and offers plausible cover
  • Danger signals established with source
  • Debriefing objectives prepared
  • New tasking prepared
  • Payment ready if applicable
  • Next meeting date/time/location/backup prepared
  • Counter-surveillance planned for departure
  • Emergency protocol reviewed

9.3 CI Awareness Checklist

  • All members trained on elicitation recognition
  • Reporting procedures for unusual contacts established
  • Financial monitoring in place for access personnel
  • Need-to-know enforced for all operational information
  • Pre-operational contact minimized
  • Public affiliation indicators eliminated
  • Communication security protocols followed
  • Regular security briefings conducted
  • Informant detection indicators monitored

This manual is a living document. Regenerate with python mosaic.py manual as new sources are collected and extracted.