Background: operations security
Operational security (OPSEC) or operations security is a process that identifies critical information to determine whether friendly actions can be observed by enemy intelligence, determines if information obtained by adversaries could be interpreted to be useful to them, and then executes selected measures that eliminate or reduce adversary exploitation of friendly critical information.
The term "operations security" was coined by the United States Armed Forces during the Vietnam War.
1 source for this section
Vietnam
In 1966, United States Admiral Ulysses Sharp established a multidisciplinary security team to investigate the failure of certain combat operations during the Vietnam War. This operation was dubbed Operation Purple Dragon, and included personnel from the National Security Agency and the Department of Defense.
When the operation concluded, the Purple Dragon team codified their recommendations. They called the process "Operations Security" in order to distinguish the process from existing processes and ensure continued inter-agency support.
3 sources for this section
- 1Operational security — Wikipedia, revision 1372110504
- 2"PURPLE DRAGON: The Formations of OPSEC". Information Assurance Directorate. National Security Agency. Archived from the original on March 23, 2021. Retrieved June 15, 2016.
- 3"The Origin of OPSEC- from the dragon's mouth". www.opsecprofessionals.org. Archived from the original on 3 July 2016. Retrieved 2016-06-16.
NSDD 298
In 1988, President Ronald Reagan signed National Security Decision Directive (NSDD) 298. This document established the National Operations Security Program and named the Director of the National Security Agency as the executive agent for inter-agency OPSEC support. This document also established the Interagency OPSEC Support Staff (IOSS).
Private-sector application
The private sector has also adopted OPSEC as a defensive measure against competitive intelligence collection efforts.
1 source for this section
IT security
NIST SP 800-53 defines OPSEC as the "process by which potential adversaries can be denied information about capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence of the planning and execution of sensitive activities."
The source notesEvidence & further reading5 sources
- Operational security — Wikipedia, revision 1372110504 Wikipedia contributors · Reference source · accessed 2026-09-22
- "PURPLE DRAGON: The Formations of OPSEC". Information Assurance Directorate. National Security Agency. Archived from the original on March 23, 2021. Retrieved June 15, 2016. iad.gov · Reference source · link imported 2026-09-22
- "The Origin of OPSEC- from the dragon's mouth". www.opsecprofessionals.org. Archived from the original on 3 July 2016. Retrieved 2016-06-16. opsecprofessionals.org · Reference source · link imported 2026-09-22
- "About the IOSS". National OPSEC Program. Interagency OPSEC Support Staff. Retrieved June 15, 2016. iad.gov · Reference source · link imported 2026-09-22
- "SC-38. OPERATIONS SECURITY". Security and Privacy Controls for Information Systems and Organizations (Information security standard). Joint Task Force. p. 323. doi:10.6028/NIST.SP.800-53r5. doi.org · Reference source · link imported 2026-09-22
Selected and reformatted from Operational security, by its contributors, under CC BY-SA 4.0. Revision 1372110504. Sections and formatting have been shortened; the linked revision provides the full context and contributor history. This reference text remains under the same license. Its additional citation links are imported from that revision and have not been independently checked here.