HOMELAND SECURITY FUNDAMENTALS
CLASSIFICATION: UNCLASSIFIED // TRAINING USE ONLY
🏛️

HOMELAND SECURITY FUNDAMENTALS

Systematic framework for understanding, assessing, and countering threats to national infrastructure, civil society, and sovereign institutions.

ℹ️ This training module covers national security and public safety principles applicable to government, defense, and critical infrastructure professionals across any national context. All scenarios are unclassified and for educational purposes only.
16
CRITICAL SECTORS
12
THREAT CATEGORIES
5
COA FRAMEWORKS
DEFINITION & SCOPE

National Security encompasses the whole-of-government effort to prevent, protect against, mitigate, respond to, and recover from threats and hazards facing the state. It integrates domestic intelligence, border security, infrastructure protection, emergency management, and cybersecurity into a unified national security posture.

FIVE MISSION PILLARS
PREVENT — Counter terrorism and security threatsPrimary
PROTECT — Safeguard borders and infrastructureHigh
MITIGATE — Reduce impact of threatsMedium
RESPOND — Emergency response and crisis managementHigh
RECOVER — Restore systems and servicesOngoing
THREAT SPECTRUM
  • Terrorism — Domestic & International
  • Cybersecurity attacks on critical systems
  • Natural hazards & disaster events
  • Pandemics & biological threats
  • Radiological / nuclear incidents
  • Chemical & HAZMAT emergencies
  • Foreign intelligence / espionage
  • Transnational organized crime
KEY PRINCIPLES
  • Risk-informed resource allocation
  • Whole-of-government integration
  • Intelligence-led operations
  • Layered defense architecture
  • Public-private partnership
  • Civil liberties preservation
  • Interoperability across agencies
  • Resilience by design
🏗️

CRITICAL INFRASTRUCTURE SECTORS

16 sectors designated as critical. Disruption would have debilitating effects on security, national economic security, or public health and safety.

Energy, Communications, and Water sectors are identified as tier-1 dependencies. Cascading failure in any one can render all 15 others non-functional.
SECTOR INTERDEPENDENCY MAP

Click any sector above to view dependencies and risk profile.

⚠️

THREAT TAXONOMY

Structured classification of all threat categories across the homeland security domain, enabling systematic analysis and tailored response planning.

ALL THREATS
PHYSICAL
CYBER
CBRN
HUMAN
NATURAL
🔴

INTERNAL THREAT LANDSCAPE

Threats originating from within national borders, including domestic extremism, insider threats, and subversion of institutions.

🚨 Internal threats are statistically more difficult to detect due to pre-existing access, cultural familiarity, and established trust relationships. Early indicators are often ambiguous.
🔵

EXTERNAL THREAT LANDSCAPE

Threats originating beyond national borders, including state-sponsored operations, transnational terrorism, and cross-border infiltration.

📊

THREAT MATRIX PLOT

2D and matrix-based visualization of threats by likelihood versus consequence severity. Interactive plotting tool.

LIKELIHOOD × CONSEQUENCE MATRIX
🔴 CRITICAL   🟠 HIGH   🟡 MEDIUM   🟢 LOW   🔵 MINIMAL
5×5 RISK MATRIX

CONSEQUENCE →

↑ LIKELIHOOD
INTERACTIVE THREAT PLOTTER
LIKELIHOOD (1–10) 6
CONSEQUENCE (1–10) 7
DETECTABILITY (1–10) 4
🔎

THREAT ASSESSMENT PROCESS

Structured methodology for evaluating threats using intelligence, context, and analytical frameworks to support decision-making.

ASSESSMENT STAGES
STAGE 1
Threat Identification
Collection and identification of potential threats through HUMINT, SIGINT, OSINT, and partner reporting. Establish threat actor profiles.
STAGE 2
Capability Analysis
Assess adversary capabilities: resources, weapons, tradecraft, and operational reach. Distinguish intent from capability.
STAGE 3
Vulnerability Assessment
Identify gaps in current defenses, potential attack vectors, and critical nodes susceptible to exploitation.
STAGE 4
Risk Estimation
Combine likelihood, consequence, and vulnerability into a risk score. Prioritize threats for resource allocation.
STAGE 5
Recommendation & Dissemination
Produce intelligence products, decision-support packages, and threat advisories for policymakers and operators.
ASSESSMENT MODELS
  • CARVER Matrix — Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability
  • MSHARPP — Mission, Symbolism, History, Accessibility, Recognizability, Population, Proximity
  • ACH Method — Analysis of Competing Hypotheses to reduce analytical bias
  • STRIDE — Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation (cyber)
  • PMESII-PT — Political, Military, Economic, Social, Info, Infrastructure, Physical, Time
ANALYTICAL STANDARDS
  • Source reliability and information credibility rating (A–F / 1–6)
  • Alternative hypothesis consideration mandatory
  • Confidence levels stated: High / Moderate / Low
  • Dissent recorded and preserved in assessment record
THREAT SCORE CALCULATOR
THREAT CAPABILITY 7
ADVERSARY INTENT 8
OPPORTUNITY (ACCESS) 5
EXISTING VULNERABILITY 6
6.5
THREAT SCORE
HIGH THREAT
📐

RISK QUANTIFICATION MODEL

Mathematical and semi-quantitative frameworks for converting qualitative threat assessments into actionable risk scores.

RISK FORMULA
RISK = THREAT × VULNERABILITY × CONSEQUENCE
where each factor is scored 1–10 and normalized to a 0–1000 composite
RESIDUAL RISK = INHERENT RISK × (1 - CONTROL EFFECTIVENESS)
Residual risk persists after all controls are applied. Accept, transfer, or escalate per policy threshold.
RISK TOLERANCE BANDS
ACCEPTABLE (0–200)Monitor
TOLERABLE (201–400)ALARP
MODERATE (401–600)Mitigate
HIGH (601–800)Urgent
CRITICAL (801–1000)Escalate
RISK RESPONSE STRATEGIES
  • AVOID — Eliminate the activity causing the risk
  • REDUCE — Apply controls to lower likelihood or consequence
  • TRANSFER — Assign risk to another entity (insurance, partner)
  • ACCEPT — Tolerate residual risk within defined thresholds
  • ESCALATE — Refer decision to higher authority when risk exceeds mandate

COURSE OF ACTION ANALYSIS

Structured decision-making process for identifying, comparing, and selecting response options to homeland security threats.

COA DEVELOPMENT PROCESS
STEP 1 — ANALYZE
Mission & Threat Analysis
Define mission parameters, threat characteristics, METT-TC factors (Mission, Enemy, Terrain, Troops, Time, Civil Considerations).
STEP 2 — GENERATE
COA Development
Generate at least two feasible courses of action. Each COA must be Suitable, Feasible, Acceptable, Distinguishable, Complete (SFADC).
STEP 3 — WARGAME
COA War Gaming
Simulate adversary responses to each COA using action-reaction-counteraction cycles. Identify strengths and weaknesses.
STEP 4 — COMPARE
COA Comparison & Decision Matrix
Score each COA against weighted criteria. Recommend the COA with the highest overall score to the decision authority.
STEP 5 — APPROVE
Decision & Order Production
Commander/Director approves selected COA. Operations order issued with tasks, timing, resource allocation, and contingencies.
COA COMPARISON MATRIX — CYBER ATTACK SCENARIO
CRITERION WEIGHT COA-1: PASSIVE MONITOR COA-2: ACTIVE DEFENSE COA-3: OFFENSIVE RESPONSE
Speed of Effect30% ★★☆ (2) ★★★ (3) ★★★ (3)
Legal Authority25% ★★★ (3) ★★★ (3) ★☆☆ (1)
Collateral Impact20% ★★★ (3) ★★☆ (2) ★☆☆ (1)
Deterrence Value15% ★☆☆ (1) ★★☆ (2) ★★★ (3)
Resource Efficiency10% ★★★ (3) ★★☆ (2) ★☆☆ (1)
WEIGHTED SCORE 2.45 / 3.0 2.65 / 3.0 ✓ 1.85 / 3.0
RECOMMENDED: COA-2 ACTIVE DEFENSE — Highest weighted score. Balances speed of effect with legal authority and acceptable collateral risk. Proceed to OPLAN development.
🛡️

MITIGATION MEASURES

Layered controls mapped to threat categories, covering prevention, detection, response, and recovery across all 16 critical sectors.

PREVENTION
DETECTION
RESPONSE
RECOVERY
🔄

CONTINUITY OF OPERATIONS

Plans and procedures to ensure the continuation of essential functions across all threat environments.

COOP PLANNING ELEMENTS
  • Essential Functions — Identify and prioritize minimum viable operations
  • Orders of Succession — Pre-designated leadership continuity chain
  • Delegations of Authority — Emergency decision-making authorities
  • Alternate Facilities — Primary, alternate, contingency, emergency sites
  • Interoperable Communications — Redundant comms across all scenarios
  • Vital Records — Protection and accessibility of mission-critical data
  • Human Capital — Personnel accountability and welfare plans
  • Test, Training, Exercise — Annual validation cycle with AAR
RECOVERY TIMELINE PHASES
0–12 HRS
Immediate Response
Life safety, incident stabilization, COOP activation, emergency notifications.
12–72 HRS
Short-Term Recovery
Essential function restoration, damage assessment, resource request, public messaging.
72 HRS–30 DAYS
Intermediate Recovery
Infrastructure repair, displaced personnel, economic stabilization, sector coordination.
30 DAYS+
Long-Term Recovery
Rebuild, lessons learned integration, policy revision, resilience investment.
INCIDENT COMMAND STRUCTURE
📖

GLOSSARY OF TERMS

Authoritative definitions for homeland security, threat assessment, and COA analysis terminology.