Booz Allen — Security & Compliance Division
Field Personnel Security Protocols
Standard operating procedures for communications, operational security, and information protection for field intelligence personnel and contractors.
1. Purpose and Scope
This document establishes the security protocols and standard operating procedures for all field intelligence personnel, contractors, and affiliates operating under Booz Allen and its partner agencies. These protocols are designed to protect classified information, safeguard operational integrity, and ensure the personal security of all personnel deployed in the field.
Compliance with these protocols is mandatory for all personnel holding a security clearance of Secret or above. Failure to adhere to these standards may result in disciplinary action, revocation of security clearance, termination of employment, and potential criminal prosecution.
2. Classification Levels and Access
All field personnel are assigned a security classification level based on their role, assignment, and operational requirements. Access to information is granted on a need-to-know basis.
- Top Secret / SCI — Access to sensitive compartmented information. Reserved for senior field intelligence officers and specialized operatives.
- Top Secret — Access to information that could cause exceptionally grave damage to national security if disclosed.
- Secret — Access to information that could cause serious damage to national security if disclosed.
- Confidential — Access to information that could cause damage to national security if disclosed.
3. Personnel Vetting and Continuous Evaluation
All field personnel undergo rigorous background investigations prior to deployment. This includes but is not limited to:
- Comprehensive criminal background check (federal, state, and international)
- Financial history review and credit assessment
- Psychological evaluation and fitness for duty assessment
- Polygraph examination (for Top Secret / SCI clearance holders)
- Foreign contact and travel history review
- Reference verification (personal and professional)
Clearance holders are subject to continuous evaluation. Any significant life changes, foreign travel, or unusual financial activity must be reported to the Security & Compliance Division within 48 hours.
4. Operational Security (OPSEC)
Field personnel must maintain strict operational security at all times. This includes protecting information about assignments, locations, methodologies, and personnel identities.
4.1 Identity Protection
- Field personnel operating under cover identities must not reveal their true affiliation with Booz Allen or partner agencies.
- Personal social media accounts must not reference current assignments, locations, or colleagues.
- Photographs taken in operational areas are strictly prohibited without prior authorization.
- Personal relationships formed during deployment must be reported to the Security Office.
4.2 Travel Security
- All international travel must be pre-approved by the Security & Compliance Division.
- Personnel must vary routes and times to avoid establishing patterns.
- Travel documents must be secured at all times and never left unattended.
- Use of public Wi-Fi networks is prohibited without VPN encryption.
4.3 Physical Security
- Classified materials must be stored in approved security containers when not in use.
- Personnel must conduct regular sweeps of living quarters and workspaces for surveillance devices.
- Tail awareness and counter-surveillance techniques must be practiced at all times.
- Emergency destruction procedures for classified materials must be reviewed monthly.
5. Communication Security (COMSEC)
All communications involving classified or sensitive information must be conducted through approved, encrypted channels. Unauthorized communication methods pose a significant risk to operational security and personnel safety.
5.1 Authorized Communication Devices
The following devices have been approved by the Security & Compliance Division for field use. These devices employ military-grade encryption and are configured to prevent unauthorized interception.
- Thuraya Satsleeve Secure Mobile Terminal (Model XT-900) — Satellite-based communication device with 256-bit AES encryption. No camera capability. Designed for use in remote locations without cellular infrastructure.
- Motorola SecureTalk Encrypted Handset (Model ST-450) — Terrestrial radio communication device with frequency-hopping spread spectrum technology. No camera or data transmission capability. Range: 15 miles.
- L3Harris Secure Tablet (Model T7-S) — Encrypted data terminal for receiving and transmitting classified documents. No front-facing camera. Rear camera disabled by default. Wi-Fi and Bluetooth permanently disabled.
Note: All authorized devices are configured without front-facing camera capability. Visual data transmission is disabled by default in accordance with agency security standards. This configuration is mandatory and cannot be modified by end users.
5.2 Authorized Communication Methods
- Encrypted text messaging through approved devices only
- Secure voice calls through approved devices only (subject to monitoring)
- Encrypted email through the agency intranet
- Secure file transfer through approved data terminals
- In-person verbal communication in secured spaces
6. Prohibited Communication Activities
The following activities are strictly prohibited for all field personnel. These restrictions apply at all times while personnel are on active assignment, regardless of location or circumstance.
- Video calls of any kind (FaceTime, WhatsApp Video, Zoom, Skype, Google Meet, Microsoft Teams, etc.)
- Use of personal mobile devices for any work-related communication
- Use of personal devices with camera capability in operational areas
- Photography or video recording in operational areas without prior written authorization
- Transmission of images, video, or audio recordings without prior written authorization
- Use of social media platforms (Facebook, Instagram, X, TikTok, LinkedIn, etc.) for any work-related communication
- Use of commercial messaging applications (WhatsApp, Signal, Telegram, iMessage, etc.) for classified communications
- Discussion of classified information over unsecured lines, including personal phone calls
- Removal of security features or modification of approved devices
- Connection of approved devices to unsecured networks or computers
7. Personal Communication Guidelines
Field personnel are permitted to maintain personal communications with family and approved contacts. However, these communications must adhere to the following guidelines:
- Personal communications must not reference operational details, locations, or personnel identities.
- Personal relationships formed during deployment must be reported to the Security Office within 30 days.
- Personal communications may be subject to monitoring for security purposes.
- Text-based communication is the preferred method for personal correspondence.
- Voice calls should be limited to secure devices and kept brief.
- Under no circumstances should video communication be used for personal correspondence while on active assignment.
- Personal social media accounts must be set to private and must not reference current employment or assignment.
Note: These restrictions are not intended to isolate personnel from their support networks. They are designed to protect both the individual and the mission. Violations of personal communication guidelines are treated with the same seriousness as other security breaches.
8. Data Protection and Information Security
All data, whether classified or unclassified, must be handled in accordance with agency data protection policies.
- Classified data must never be stored on personal devices or unsecured systems.
- All data transfers must be encrypted using approved methods.
- Physical documents must be shredded using cross-cut shredders when no longer needed.
- Digital files must be securely deleted using approved wiping software.
- USB drives and external storage media must be encrypted and stored in approved containers.
- Passwords must be changed every 90 days and must meet complexity requirements.
- Two-factor authentication is required for all agency systems.
9. Violations and Penalties
Violations of these security protocols are taken with the utmost seriousness. Depending on the nature and severity of the violation, consequences may include:
- Verbal or written reprimand
- Mandatory security retraining
- Suspension of security clearance (temporary or permanent)
- Reassignment or restriction of duties
- Termination of employment and contractor status
- Revocation of all agency credentials and access badges
- Financial penalties
- Criminal prosecution under 18 U.S.C. § 798 (Espionage Act) — Maximum penalty: 10 years imprisonment and $250,000 fine
- Criminal prosecution under 18 U.S.C. § 793 (Gathering, transmitting or losing defense information)
- Criminal prosecution under 18 U.S.C. § 1924 (Unauthorized removal and retention of classified documents or material)
- Permanent ineligibility for future government contracts or security clearances
- Loss of pension and retirement benefits (for government employees)
Ignorance of these protocols is not considered a valid defense. All personnel are required to review and acknowledge these protocols annually.
10. Reporting Requirements
Field personnel are required to report the following to the Security & Compliance Division:
- Any suspected violation of security protocols (within 24 hours of discovery)
- Any attempted unauthorized access to classified information
- Any loss or theft of approved devices or classified materials (immediately upon discovery)
- Any suspicious contact or surveillance (within 12 hours)
- Any foreign travel not previously approved (prior to travel if possible)
- Any significant personal life changes (marriage, divorce, financial issues, etc.) within 48 hours
- Any contact with foreign nationals that goes beyond casual interaction
- Any request for information that seems unusual or suspicious
To report a violation or concern:
Contact the Security & Compliance Division immediately at +1 (703) 555-0190 or via encrypted email at security@boozallen-contractor.com. Reports can be made anonymously if preferred. All reports are treated with confidentiality and investigated thoroughly.
11. Training and Acknowledgment
All field personnel must complete the following training requirements:
- Initial Security Protocol Training (prior to deployment)
- Annual Security Refresher Training
- Communication Security (COMSEC) Training (bi-annually)
- Operational Security (OPSEC) Training (bi-annually)
- Counterintelligence Awareness Training (annually)
Personnel must sign an acknowledgment confirming they have read, understood, and agree to comply with these protocols. This acknowledgment is retained in the personnel file and may be used in any subsequent investigation or proceeding.
12. Protocol Updates and Amendments
These protocols are reviewed and updated on a quarterly basis by the Security & Compliance Division. Personnel will be notified of any changes via secure communication channels. It is the responsibility of each individual to stay informed of current protocols and to seek clarification from the Security Office when needed.
The most current version of this document is always available through the agency intranet. Printed copies are considered uncontrolled and should be verified against the digital version before use.