I figured I'd post a couple of items that fascinated me when they were published during the course of the last couple of years.
First, as I've found myself in a very entrepeneurial mindset over the last year or so, I found How to Get a Real Education by Dilbert author Scott Adams to be fascinating. Adams discusses lessons in entrepeneurship and other topics that he learned in college through activities, vice actual coursework. When I was an undergrad, I found that many of my extracurricular activities taught me far more than many of my required courses. That goes for both practical and abstract lessons; for example, working as a DJ at the campus radio station offered me lessons in technical troubleshooting and keeping good records, as well as teaching me followership and cooperation with people with whom I had little in common. While Adams' points don't apply directly to security, I've found that security professionals often benefit from experience and methods that are found outside the classroom.
Second, Dr. Tim Kane authored an excellent article in The Atlantic, entitled Why Our Best Officers Are Leaving. The Heritage Foundation hosted a discussion on the topic. I found Dr. Kane's discussions of the standards by which we ought to be measuring our officers (and, by extension, our officer candidates) poignant. My own goal of becoming a naval officer ended in its infancy in part due to the Navy's standards, and I have known a number of my peers whose careers have either stagnated or ended due to the military's sometimes arbitrary standards for officer recruitment and retention. Dr. Kane's research raises questions about whether the current standards are best suited to produce and retain the best possible officer corps for our military. Both the article and the discussion are excellent.
That's it for today.
Saturday, November 24, 2012
Friday, November 23, 2012
Time to Play Catch-Up
As followers of the Operation Highlander blog will already know, I've got quite a bit on my plate right now. That said, I'd like to start paying a bit more attention to this blog. Most of what I'm currently involved with on a daily basis doesn't apply directly to the major functional areas of risk management, but a lot of the news stories I follow for school or for my own situational awareness relate back to one functional area or another.
I've also found myself working on some cool projects in my spare time that can tie back into risk management. One of them was the Google Reader project I mentioned in my last post. Another has been manipulating the data in my GPS using Wikimapia, Easy GPS, and Windows Notepad. (I find that I rarely need anything more than a web browser, Notepad, and Microsoft Excel to complete most tasks.) The GPS work relates back to an article and slide deck I read a couple of years ago about honesty traces, which can be a great Anti-Terrorism/Force Protection technique.
Anyway, I've got a good backlog of links and topics for this blog, I've made an effort to get ahead on posts for the Operation Highlander blog, and I'm in good shape on my school and extracurricular projects, so I'll try to spend the next few weeks posting some content to this one. I hope everyone out there finds it helpful.
I've also found myself working on some cool projects in my spare time that can tie back into risk management. One of them was the Google Reader project I mentioned in my last post. Another has been manipulating the data in my GPS using Wikimapia, Easy GPS, and Windows Notepad. (I find that I rarely need anything more than a web browser, Notepad, and Microsoft Excel to complete most tasks.) The GPS work relates back to an article and slide deck I read a couple of years ago about honesty traces, which can be a great Anti-Terrorism/Force Protection technique.
Anyway, I've got a good backlog of links and topics for this blog, I've made an effort to get ahead on posts for the Operation Highlander blog, and I'm in good shape on my school and extracurricular projects, so I'll try to spend the next few weeks posting some content to this one. I hope everyone out there finds it helpful.
Saturday, October 13, 2012
Google Reader for Situational Awareness
Note: This is a rewrite of a post on the Operation Highlander blog that was originally written for the benefit of my classmates.
One of the most critical elements of good security is situational awareness. Modern technology has made the collection of information about security concerns easier, but it can still be time-consuming, particularly when presented with the "vacuum cleaner problem": the abundance of information sometimes makes it difficult to sift through all of the data available to find what's relevant and discard what's irrelevant.
In the last year, I've become an avid user of Google Reader. Google Reader is an RSS aggregator. What that means is that you can plug the links from the RSS feeds of your favorite news websites, blogs, and personal interest sites, and they'll all aggregate to a single point. This allows users to go to a single website, and then either read their news in the Google Reader "reader pane", or open individual links for further detail. Here are a couple of videos to introduce you to Google Reader:
By using Google Reader, I'm able to cut my daily news review times down considerably. Google Reader makes it easy to scroll through articles that aren't of interest, and to read the ones that are relevant to my interests. It also allows me to download podcasts efficiently, and keeps me abreast of websites I might otherwise forget about. I know of at least one U.S. Coast Guard organization that uses Google Reader to aggregate open-source intelligence, I'm reasonably sure that I know of another DoD activity that does the same, and I suspect that the guys at Small Wars Journal use it or something similar when assembling their daily SWJ Roundup. Had I gotten on the ball sooner, Google Reader would have made me a lot more efficient at several of the duties I was tasked with in the Middle East. I can't speak to its accessibility on Apple devices, but I've had great results reviewing my feed on Android devices like my Motorola Droid 4 and my Kindle Fire.
Here's a list of some of the RSS feeds I aggregate to Google Reader so that I can maintain my situational awareness of global security developments:
Mainstream News:
BBC News - Middle East (RSS)
BBC News - NE Scotland, Orkney & Shetland (RSS)
CNN.com - WORLD (RSS)
CNN.com - WORLD/Middle East (RSS)
The Guardian (RSS)
Times Of Oman (RSS)
Oman Observer (RSS)
Kuwait Times (RSS)
Arab Times (RSS)
Specialty News and Blogs:
1913 Intel (RSS)
CNAS: Abu Muqawama (RSS)
CNN Security Clearance Blog (RSS)
Michael J. Totten (RSS)
Michael Yon (RSS)
Spacewar.com (RSS)
Site Intelligence Group - Jihadist News (RSS)
Small Wars Journal (RSS)
The Long War Journal (Site-Wide) (RSS)
Understanding War (RSS)
The Guardian: Julian Borger's global security blog (RSS)
Wired.com: Danger Room (RSS)
Wired.com: Threat Level (RSS)
Podcasts:
BBC Xtra Arabic Podcasts (RSS)
BBC Documentaries (RSS)
BBC Global News Podcast (RSS)
BBC Newshour (RSS)
KCL Department of War Studies' Podcast (RSS)
Past Events - The Heritage Foundation (RSS)
Military Flickr Feeds:
Flickr: Defence Images (RSS)
Flickr: Official U.S. Navy Imagery (RSS)
Flickr: The U.S. Army (RSS)
Flickr: United States Marine Corps Official Page (RSS)
A final point: Google Reader also allows users to export and import their feeds from one Google account to another through a simple XML file download/upload. If anyone reading this is interested in saving time by importing my feed file and then adding their own additional selections, let me know and I'll be happy to E-mail it to you.
One of the most critical elements of good security is situational awareness. Modern technology has made the collection of information about security concerns easier, but it can still be time-consuming, particularly when presented with the "vacuum cleaner problem": the abundance of information sometimes makes it difficult to sift through all of the data available to find what's relevant and discard what's irrelevant.
In the last year, I've become an avid user of Google Reader. Google Reader is an RSS aggregator. What that means is that you can plug the links from the RSS feeds of your favorite news websites, blogs, and personal interest sites, and they'll all aggregate to a single point. This allows users to go to a single website, and then either read their news in the Google Reader "reader pane", or open individual links for further detail. Here are a couple of videos to introduce you to Google Reader:
By using Google Reader, I'm able to cut my daily news review times down considerably. Google Reader makes it easy to scroll through articles that aren't of interest, and to read the ones that are relevant to my interests. It also allows me to download podcasts efficiently, and keeps me abreast of websites I might otherwise forget about. I know of at least one U.S. Coast Guard organization that uses Google Reader to aggregate open-source intelligence, I'm reasonably sure that I know of another DoD activity that does the same, and I suspect that the guys at Small Wars Journal use it or something similar when assembling their daily SWJ Roundup. Had I gotten on the ball sooner, Google Reader would have made me a lot more efficient at several of the duties I was tasked with in the Middle East. I can't speak to its accessibility on Apple devices, but I've had great results reviewing my feed on Android devices like my Motorola Droid 4 and my Kindle Fire.
Here's a list of some of the RSS feeds I aggregate to Google Reader so that I can maintain my situational awareness of global security developments:
Mainstream News:
Specialty News and Blogs:
Podcasts:
Military Flickr Feeds:
A final point: Google Reader also allows users to export and import their feeds from one Google account to another through a simple XML file download/upload. If anyone reading this is interested in saving time by importing my feed file and then adding their own additional selections, let me know and I'll be happy to E-mail it to you.
Tuesday, October 2, 2012
Personal Security, Online and In Person
I apologize for the delay in posting over here. As anyone who's following the other blog will know, I've been busy in Scotland, getting settled into my postgraduate program in Strategic Studies as well as life in general in Scotland. Unfortunately, security never sleeps, and there have been a number of items, varying in degree of tragedy and severity, that merit mention.
Beginning with the most absurd: David Axe reports at Wired.com that Taliban agents are posing online as "attractive women". While most of us aren't concerned with Taliban infiltration on a daily basis, this story is a good reminder that people online aren't always who they say they are. It's also to keep in mind that there's a spectrum: on the one end, you Taliban posing as beautiful women, or Nigerian princes who want to give you money. On the other end, you may have something fairly benign: a potential suitor being disingenuous about their weight or age, perhaps. One of the more outlandish claims I've ever heard about Craigslist is that most of the supposedly attractive women posting there are actually homosexual men trying to con straight men into sending inappropriate pictures of themselves. I can't speak to the accuracy of that claim, but regardless, it's a good reminder to be careful of the information you share online.
A friend sent me the second item for today, from the National Association of Realtors: 10 Things a Burglar Doesn't Want You to Know. It has some great tips for securing your home - and, not surprisingly, the advice can help with more than just burglars. The NAR also has a home security website and an RSS feed. One item that's not included in the list: get a dog.
I intend to express some thoughts about the recent events in Benghazi, Libya and Camp Bastion/Leatherneck, Afghanistan, but it's important to me that I do this properly, something I don't have time to do currently. I'll address one or both of these events in the next post.
Beginning with the most absurd: David Axe reports at Wired.com that Taliban agents are posing online as "attractive women". While most of us aren't concerned with Taliban infiltration on a daily basis, this story is a good reminder that people online aren't always who they say they are. It's also to keep in mind that there's a spectrum: on the one end, you Taliban posing as beautiful women, or Nigerian princes who want to give you money. On the other end, you may have something fairly benign: a potential suitor being disingenuous about their weight or age, perhaps. One of the more outlandish claims I've ever heard about Craigslist is that most of the supposedly attractive women posting there are actually homosexual men trying to con straight men into sending inappropriate pictures of themselves. I can't speak to the accuracy of that claim, but regardless, it's a good reminder to be careful of the information you share online.
A friend sent me the second item for today, from the National Association of Realtors: 10 Things a Burglar Doesn't Want You to Know. It has some great tips for securing your home - and, not surprisingly, the advice can help with more than just burglars. The NAR also has a home security website and an RSS feed. One item that's not included in the list: get a dog.
I intend to express some thoughts about the recent events in Benghazi, Libya and Camp Bastion/Leatherneck, Afghanistan, but it's important to me that I do this properly, something I don't have time to do currently. I'll address one or both of these events in the next post.
Wednesday, August 29, 2012
Resource Security and Risk Management
One of the current hot topics in international politics is resource security. Energy security - specifically fossil fuels - is the most extensively discussed flavor of the issue, but other areas of study include rare earth metals (used in many modern electronics) and even water. Some analysts predict wars revolving around scarce water resources within the foreseeable future.
A few days ago, I ran across this video...
... which reminded me of this podcast from the Department of War Studies at King's College London, which was published in late 2010. The two items provide valuably contrasting points on the topic.
Rare earth metals provide a good case study for some of these phenomena. For those readers who are unaware, rare earth metals are a range of heavy metals whose properties make them indispensable in the manufacture of modern electronics. While they are found in several locations, the vast bulk of rare earth metals are exploited from mines in China. In recent months, China has been accused of restricting rare earth metal exports. As these materials are critical not only for consumer electronics, but also for systems vital to international security, the potential decline in availability relative to demand could become a serious international issue, similar in many respects to the supply and sourcing of fossil fuels. The potential risk affects not only the price, but the actual international availability of the critical commodity in question.
At the same time, the increased risk to global supply makes the potential exploitation of other sources of rare earth metals more lucrative. For example, Japan reported a number of months ago that it had located a source of rare earths in the Pacific seabed - a source that has become lucrative enough to exploit due to the Chinese lockdown on their supplies. According to Wired, it has also compelled the Pentagon to research new ways to mine rare earth metals, and I've also heard (but unfortunately, don't remember the source) that technical experts are also researching methods of manufacturing modern electronics without rare earths.
Of course, the world is seldom so simple: for example, there are allegations that the rare earth mineral coltan has fueled a war in the Democratic Republic of Congo. Additionally, the the mining and refinement of rare earth metals is an ecologically hazardous process. This introducing environmental concerns as an additional limiting factor on sources outside of developing nations, in the same way that environmentalism has limited the use of both traditional fossil fuels and the proliferation of nuclear energy.
The lesson, of course, is that while the so-called "invisible hand" can impact the management of risk, even in matters of resource security, it is ultimately subordinate to human factors.
A few days ago, I ran across this video...
... which reminded me of this podcast from the Department of War Studies at King's College London, which was published in late 2010. The two items provide valuably contrasting points on the topic.
Rare earth metals provide a good case study for some of these phenomena. For those readers who are unaware, rare earth metals are a range of heavy metals whose properties make them indispensable in the manufacture of modern electronics. While they are found in several locations, the vast bulk of rare earth metals are exploited from mines in China. In recent months, China has been accused of restricting rare earth metal exports. As these materials are critical not only for consumer electronics, but also for systems vital to international security, the potential decline in availability relative to demand could become a serious international issue, similar in many respects to the supply and sourcing of fossil fuels. The potential risk affects not only the price, but the actual international availability of the critical commodity in question.
At the same time, the increased risk to global supply makes the potential exploitation of other sources of rare earth metals more lucrative. For example, Japan reported a number of months ago that it had located a source of rare earths in the Pacific seabed - a source that has become lucrative enough to exploit due to the Chinese lockdown on their supplies. According to Wired, it has also compelled the Pentagon to research new ways to mine rare earth metals, and I've also heard (but unfortunately, don't remember the source) that technical experts are also researching methods of manufacturing modern electronics without rare earths.
Of course, the world is seldom so simple: for example, there are allegations that the rare earth mineral coltan has fueled a war in the Democratic Republic of Congo. Additionally, the the mining and refinement of rare earth metals is an ecologically hazardous process. This introducing environmental concerns as an additional limiting factor on sources outside of developing nations, in the same way that environmentalism has limited the use of both traditional fossil fuels and the proliferation of nuclear energy.
The lesson, of course, is that while the so-called "invisible hand" can impact the management of risk, even in matters of resource security, it is ultimately subordinate to human factors.
Saturday, June 30, 2012
Maritime Risk Management
One of the growing markets in international risk management is maritime private security. A recent book on the topic is Maritime Private Security: Market responses to piracy, terrorism and waterborne security risks in the 21st century, edited by Claude Berube and Patrick Cullen. Berube and Cullen lectured on the topic at the Heritage Foundation in March. You can watch a video of the event or download the podcast here.
Although the rise of piracy in the vicinity of Somalia garners most of the current news attention, risk management professionals monitor security threats in a variety of other key areas. These include maritime bottlenecks such as the Straits of Gibraltar, Hormuz, and Malacca, and the Panama and Suez Canals. A July 2010 attack on a Japanese tanker in the Strait of Hormuz may have been linked to al Qaeda, and investigative journalist Richard Miniter has tied al Qaeda to several disrupted plots to attack shipping in the Strait of Malacca. Berube and Cullen's presentation goes into further detail on implications and strategies for maritime risk management efforts for the foreseeable future.
Although the rise of piracy in the vicinity of Somalia garners most of the current news attention, risk management professionals monitor security threats in a variety of other key areas. These include maritime bottlenecks such as the Straits of Gibraltar, Hormuz, and Malacca, and the Panama and Suez Canals. A July 2010 attack on a Japanese tanker in the Strait of Hormuz may have been linked to al Qaeda, and investigative journalist Richard Miniter has tied al Qaeda to several disrupted plots to attack shipping in the Strait of Malacca. Berube and Cullen's presentation goes into further detail on implications and strategies for maritime risk management efforts for the foreseeable future.
Thursday, June 21, 2012
Using Comedy to Illustrate OPSEC
A few years ago, I attended the National Operational Security Conference. In one of the lectures I attended, the speaker played a clip from an old episode of Saturday Night Live that aired during the Persian Gulf War. You can read the transcript of that sketch here, and anyone who uses Netflix can view it online (Saturday Night Live: The 1990's, Season 16: Ep. 12 (Kevin Bacon)). It's a good illustration of the challenges faced by anyone whose job is to disseminate information to the public while protecting information that could be potentially damaging.
The military term for protecting critical information from exploitation by an enemy is Operational or Operations Security, or "OPSEC". The military goes to great lengths to train personnel of all stripes to protect information that could be useful to adversaries, and a legion of Public Affairs Officers are specially trained to provide relevant information to the public without divulging secrets that could jeopardize personnel or operations. In the corporate world, this is accomplished by strategic communications specialists. Although the military stakes are often higher, companies take the control of information very seriously. Improper disclosure of sensitive data about a corporation or other organization could encourage corporate espionage, or damage the public's perception. The same is true of the military, with the added risk of endangering the lives of personnel and the effectiveness of missions vital to national security.
The military uses the Five Step OPSEC Process as a tool to help protect sensitive information. The process is as follows:
1) Identify critical information
2) Threat analysis
3) Vulnerability analysis
4) Risk assessment
5) Implement OPSEC Measures
The best OPSEC principle I've ever heard is called "The New York Times Rule", or the "Karachi Corollary". When determining whether information should be protected or released, ask yourself: "Would I want this information to be published on the front page of the New York Times? What about on the screen in an Internet cafe in Karachi, Pakistan?" More often than not, the answer is "no".
As with any functional area of security, the best advice is to err on the side of caution. If you think that a piece of information could be useful to an adversary, it probably could be. Organizations with security concerns should do their best to promote a culture of awareness and caution.
The military term for protecting critical information from exploitation by an enemy is Operational or Operations Security, or "OPSEC". The military goes to great lengths to train personnel of all stripes to protect information that could be useful to adversaries, and a legion of Public Affairs Officers are specially trained to provide relevant information to the public without divulging secrets that could jeopardize personnel or operations. In the corporate world, this is accomplished by strategic communications specialists. Although the military stakes are often higher, companies take the control of information very seriously. Improper disclosure of sensitive data about a corporation or other organization could encourage corporate espionage, or damage the public's perception. The same is true of the military, with the added risk of endangering the lives of personnel and the effectiveness of missions vital to national security.
The military uses the Five Step OPSEC Process as a tool to help protect sensitive information. The process is as follows:
1) Identify critical information
2) Threat analysis
3) Vulnerability analysis
4) Risk assessment
5) Implement OPSEC Measures
The best OPSEC principle I've ever heard is called "The New York Times Rule", or the "Karachi Corollary". When determining whether information should be protected or released, ask yourself: "Would I want this information to be published on the front page of the New York Times? What about on the screen in an Internet cafe in Karachi, Pakistan?" More often than not, the answer is "no".
As with any functional area of security, the best advice is to err on the side of caution. If you think that a piece of information could be useful to an adversary, it probably could be. Organizations with security concerns should do their best to promote a culture of awareness and caution.
Subscribe to:
Posts (Atom)