ATP 2-33.4, page 46
Intelligence Analysis
Army Techniques Publication: Intelligence Analysis
2014 public edition (Archive.org)
Searchable page text (OCR / PDF)
Chapter 4
THE METHOD
4-9. Analyst should routinely consider that their information base is susceptible to deception. The
possibility cannot be rejected simply because there is no evidence of deception; if done well, the analyst
should not expect to see any evidence upon first examination.
4-10. The analyst should assess key reporting based on four sets of criteria:
@ Does the threat have the motive, opportunity, and means?
= Motive. (What are the threat’s goals?)
= Channels. (What means are available?)
= Risks. (What are the risks of discovery?)
= — Costs. (Can deception be accomplished?)
= Feedback. (Can the threat monitor its use?)
e@ Would this potential deception be consistent with past opposition practices?
= Does the threat have a history of deception?
= Does this deception fit past patterns?
= If not, are there other historical precedents?
= Ifnot, are there changed circumstances that would explain this form of deception?
e@ Do we have cause for concern regarding the susceptibility of manipulation of the threat?
= Is the source reliable?
= Does the source have access?
= Is the source vulnerable to control or manipulation by the threat?
@ What can be learned from the evaluation of evidence?
= How accurate is the source’s reporting?
= Is the whole chain of evidence available?
= Does critical evidence check out?
= Does evidence from one source conflict with others?
= Do other sources of information provide corroborating evidence?
= Is the absence of evidence unusual?
4-11, Analyst have found the following rules helpful in dealing with deception:
e@ Avoid over-reliance on a single source of information.
e@ Seek and heed the opinions of those closest to the reporting.
© Be suspicious of human sources or sub-sources who have not been met with personally or for
whom it is unclear how or from whom they obtained the information.
e Be suspicious of information that appears to be too easy to collect and is too perfect of a picture.
e@ Always look for material evidence (documents, reports, imagery) rather than relying exclusively
upon what someone says.
e Look for a pattern where a source’s information has seemed correct and accurate initially, but
then proven to be false.
e@ Generate and evaluate a full set of hypotheses at the outset of a task.
e Know the limitations as well as the capabilities of collection assets, sources, and potential
deceivers.
4-12. In addition to using the deception detection technique, analysts can also employ the technique of
Analysis of Competing Hypotheses (ACH) discussed in appendix A. In this case, analysts would explicitly
pose deception as one of the multiple explanations for the presence or absence of information.
KEY ASSUMPTIONS CHECK
4-13. A key assumption is any hypothesis that analysts have accepted to be true and which forms the basis
of the assessment. For example, military analysis may focus exclusively on analyzing key technical and
4-2 ATP 2-33.4 18 August 2014
Chapter 4
4-2
ATP 2-33.4
18 August 2014
THE METHOD
4-9. Analyst should routinely consider that their information base is susceptible to deception. The
possibility cannot be rejected simply because there is no evidence of deception; if done well, the analyst
should not expect to see any evidence upon first examination.
4-10. The analyst should assess key reporting based on four sets of criteria:
Does the threat have the motive, opportunity, and means?
Motive. (What are the threat’s goals?)
Channels. (What means are available?)
Risks. (What are the risks of discovery?)
Costs. (Can deception be accomplished?)
Feedback. (Can the threat monitor its use?)
Would this potential deception be consistent with past opposition practices?
Does the threat have a history of deception?
Does this deception fit past patterns?
If not, are there other historical precedents?
If not, are there changed circumstances that would explain this form of deception?
Do we have cause for concern regarding the susceptibility of manipulation of the threat?
Is the source reliable?
Does the source have access?
Is the source vulnerable to control or manipulation by the threat?
What can be learned from the evaluation of evidence?
How accurate is the source’s reporting?
Is the whole chain of evidence available?
Does critical evidence check out?
Does evidence from one source conflict with others?
Do other sources of information provide corroborating evidence?
Is the absence of evidence unusual?
4-11. Analyst have found the following rules helpful in dealing with deception:
Avoid over-reliance on a single source of information.
Seek and heed the opinions of those closest to the reporting.
Be suspicious of human sources or sub-sources who have not been met with personally or for
whom it is unclear how or from whom they obtained the information.
Be suspicious of information that appears to be too easy to collect and is too perfect of a picture.
Always look for material evidence (documents, reports, imagery) rather than relying exclusively
upon what someone says.
Look for a pattern where a source’s information has seemed correct and accurate initially, but
then proven to be false.
Generate and evaluate a full set of hypotheses at the outset of a task.
Know the limitations as well as the capabilities of collection assets, sources, and potential
deceivers.
4-12. In addition to using the deception detection technique, analysts can also employ the technique of
Analysis of Competing Hypotheses (ACH) discussed in appendix A. In this case, analysts would explicitly
pose deception as one of the multiple explanations for the presence or absence of information.
KEY ASSUMPTIONS CHECK
4-13. A key assumption is any hypothesis that analysts have accepted to be true and which forms the basis
of the assessment. For example, military analysis may focus exclusively on analyzing key technical and