# The Department of Homeland Security Intelligence Enterprise: Operational Overview and Oversight Challenges for Congress

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/crs%3AR40602

## Record

- **Collection:** Congressional research report
- **Document type:** CRS Report
- **Published:** March 19, 2010
- **Citation:** R40602

## Text

The Department of Homeland Security
Intelligence Enterprise: Operational Overview
and Oversight Challenges for Congress
(name redacted)
Specialist in Organized Crime and Terrorism
March 19, 2010

Congressional Research Service
7-....
www.crs.gov
R40602

CRS Report for Congress
Prepared for Members and Committees of Congress

The Department of Homeland Security Intelligence Enterprise

Summary
The primary mission of the Department of Homeland Security (DHS, the Department) is to
“prevent terrorist attacks within the United States, reduce the vulnerability of the United States to
terrorism, and minimize the damage, and assist in the recovery from terrorist attacks that do occur
in the United States.” Since its inception in 2003, DHS has had an intelligence component to
support this mission and has been a member of the U.S. Intelligence Community (IC).
Following a major reorganization of the DHS (called the Second Stage Review or “2SR”) in July
2005, former Secretary of Homeland Security, Michael Chertoff established a strengthened Office
of Intelligence and Analysis (I&A) and made the Assistant Secretary for Information Analysis
(now Under Secretary for Intelligence and Analysis) the Chief Intelligence Officer for the
Department. He also tasked I&A with ensuring that intelligence is coordinated, fused, and
analyzed within the Department to provide a common operational picture; provide a primary
connection between DHS and the IC as a whole; and to act as a primary source of information for
state, local and private sector partners.
Today, the DHS Intelligence Enterprise (DHS IE) consists of I&A, two headquarters elements
supported by I&A, and the intelligence elements of six DHS operational components: U.S.
Customs and Border Protection (CBP), U.S. Immigration and Customs Enforcement (ICE). U.S.
Citizenship and Immigration Services (USCIS), the Transportation Security Administration
(TSA), U.S. Coast Guard (USCG), and U.S. Secret Service (USSS).
Congress made information sharing a top priority of the Department’s intelligence component in
the Homeland Security Act of 2002 and underscored its importance through the Intelligence
Reform and Terrorism Prevention Act of 2004. Since the 2SR reorganization, Congress imposed
additional requirements for intelligence analysis; information sharing; department-wide
intelligence integration; and support to state, local, tribal governments, and the private sector
through the Implementing Recommendations of the 9/11 Commission Act of 2007.
On February 11, 2010, the Senate confirmed President Obama’s selection of Caryn Wagner to
serve as Under Secretary for Intelligence and Analysis. As she assumes responsibility for the
DHS IE, Congress will likely be interested in the progress of integration of the Department’s
intelligence components and the quality and relevance of the intelligence DHS IE produces for
front line law enforcement and security officials who are responsible for protecting America and
its people. In February, DHS produced its first Quadrennial Homeland Security Review (QHSR),
a comprehensive assessment outlining its long-term strategy and priorities for homeland security
and guidance on the Department’s programs, assets, capabilities, budget, policies, and authorities.
The next step in the Department’s QHSR process is to conduct a “bottom-up review” to
systematically link strategy to program to budget. The results of that review will be particularly
important as Congress considers an authorization bill for DHS.
This report provides an overview of the DHS IE both at headquarters and within the components.
It examines how DHS IE is organized and supports key departmental activities to include
homeland security analysis and threat warning; border security; critical infrastructure protection;
support to, and the sharing of information with, state, local, tribal, and private sector partners. It
also discusses several oversight challenges and options for Congress to consider on these issues.
This report may be updated.

Congressional Research Service

The Department of Homeland Security Intelligence Enterprise

Contents
Introduction ................................................................................................................................1
Office of Intelligence and Analysis (I&A) ...................................................................................4
The Homeland Security Intelligence Mission ........................................................................4
I&A Customers .....................................................................................................................5
Integrating the DHS IE..........................................................................................................6
Homeland Security Intelligence Council (HSIC) .............................................................7
Budget ............................................................................................................................7
I&A Organization..................................................................................................................8
The Analysis Mission......................................................................................................8
I&A Intelligence Products .........................................................................................9
Intelligence Support To State, Local, Tribal Officials, and the Private Sector ................. 11
State and Local Fusion Center Program................................................................... 11
Intelligence Threat Assessment and Coordination Group (ITACG) .......................... 12
Mission Integration ....................................................................................................... 14
Integrated Border Intelligence Program (IBIP) ........................................................ 15
National Applications Office (NAO). ...................................................................... 15
Homeland Infrastructure Threat and Risk Analysis Center (HITRAC) ................................. 16
Operations Coordination and Planning Directorate (OPS)—Intelligence Division................ 18
U.S. Customs and Border Protection (CBP) Intelligence Element .............................................. 20
CBP Office of Intelligence and Operations Coordination (OIOC) ........................................ 21
CBP Intelligence Support to DHS and CBP Missions. ......................................................... 21
At Ports of Entry........................................................................................................... 22
National Targeting Center (NTC) ............................................................................ 24
NTC—Passenger (NTCP) ....................................................................................... 24
NTC—Cargo (NTCC)............................................................................................. 24
Between POE’s. ............................................................................................................ 25
Border Field Intelligence Center (BORFIC) .................................................................. 26
Air and Marine Operations Center (AMOC).................................................................. 27
Intelligence Driven Special Operations (IDSO) ............................................................. 27
Immigration and Customs Enforcement (ICE) Intelligence Element .......................................... 28
Office of Intelligence .......................................................................................................... 29
Intelligence Programs Division ..................................................................................... 30
Border Violence Intelligence Cell (BVIC) ............................................................... 30
Border Enforcement Security Task Forces (BEST) .................................................. 31
Armas Cruzadas...................................................................................................... 31
Operation Firewall .................................................................................................. 31
Collection Management and Requirements Division...................................................... 32
Field Intelligence Groups (FIG) .................................................................................... 32
Human Smuggling and Trafficking Center (HSTC) ............................................................. 33
U.S. Citizenship and Immigration Services (USCIS) Intelligence Element................................. 34
The USCIS Intelligence Branch .......................................................................................... 35
Transportation Security Administration (TSA) Intelligence Element .......................................... 36
TSA Office of Intelligence (TSA-OI) .................................................................................. 37
TSA-OI Analysis .......................................................................................................... 37
Field Intelligence Officer Program ................................................................................ 38

Congressional Research Service

The Department of Homeland Security Intelligence Enterprise

TSA-OI Support to TSA Security Activities ........................................................................ 39
Airline Passenger Pre-Screening ................................................................................... 39
No Fly and Selectee Lists........................................................................................ 39
Secure Flight........................................................................................................... 41
Support to the Federal Air Marshal Service (FAMS)...................................................... 42
The U.S. Coast Guard (USCG) Intelligence Element ................................................................. 43
Maritime Domain Awareness............................................................................................... 43
Coast Guard Intelligence and Criminal Investigations.......................................................... 44
Assistant Commandant for Intelligence and Criminal Investigations.................................... 45
USCG Cryptologic Program.......................................................................................... 45
Coast Guard Counterintelligence Service (CGCIS)........................................................ 46
Coast Guard Investigative Service (CGIS)..................................................................... 46
Other Key USCG Intelligence Organizations....................................................................... 46
The Coast Guard Intelligence Coordination Center (ICC) .............................................. 46
COASTWATCH ........................................................................................................... 47
Maritime Intelligence Fusion Centers (MIFC) ............................................................... 47
Area and District Intelligence Staffs .............................................................................. 47
Sector Intelligence Staffs (SIS)...................................................................................... 48
U.S. Secret Service (USSS) Protective Intelligence and Assessment Division ............................ 48
USSS Organizational Structure............................................................................................ 49
Protective Intelligence and Assessment Division (PID)........................................................ 49
National Threat Assessment Center (NTAC)........................................................................ 50
Oversight Challenges and Options for Congress ........................................................................ 51
Support to State and Local Fusion Centers .......................................................................... 52
Joint Fusion Center Program Management Office (JFC PMO)....................................... 52
Sustainment Funding..................................................................................................... 52
Information Technology Infrastructure .......................................................................... 53
Quadrennial Homeland Security Review (QHSR) ............................................................... 53
Evolving Risks.................................................................................................................... 54

Figures
Figure 1. Current Department of Homeland Security Organization ..............................................2
Figure 2. Office of Intelligence and Analysis Organizational Chart ..............................................9
Figure 3. Homeland Infrastructure Threat and Risk Analysis Center (HITRAC)......................... 17
Figure 4. Directorate of Operations Coordination and Planning Organization ............................ 19

Contacts
Author Contact Information ...................................................................................................... 57

Congressional Research Service

The Department of Homeland Security Intelligence Enterprise

Introduction
A primary mission of the Department of Homeland Security (DHS, Department) is to “prevent
terrorist attacks within the United States, reduce the vulnerability of the United States to
terrorism, and minimize the damage, and assist in the recovery from terrorist attacks that do occur
in the United States.1 The current organization of the Department is displayed at Figure 1.
To support this mission, DHS has had an intelligence component since its inception in 2003. The
Homeland Security Act of 2002, assigned the original DHS intelligence component—the
Directorate of Information Analysis and Infrastructure Protection—with responsibility to receive,
analyze, and integrate law enforcement and intelligence information in order to— “(A) identify
and assess the nature and scope of terrorist threats to the homeland; (B) detect and identify threats
of terrorism against the United States; and (C) understand such threats in light of actual and
potential vulnerabilities of the homeland.”2
Congress also made information sharing a top priority of the new DHS intelligence organization,
requiring it “to disseminate, as appropriate, information analyzed by the Department within the
Department, to other agencies of the Federal government with responsibilities related to
homeland security, and to agencies of State and local government and private sector entities, with
such responsibilities in order to assist in the deterrence, prevention, preemption of, or response to,
terrorist attacks against the United States.”3
Following the release of the 9/11 Commission Report in 2004, which identified a breakdown in
information sharing as a key factor contributing to the failure to prevent the September 11, 2001
attacks,4 Congress underscored the importance it attached to information sharing at all levels of
government. The Intelligence Reform and Terrorism Prevention Act of 20045 required the
President to “create an information sharing environment for the sharing of terrorism information
in a manner consistent with national security and with applicable legal standards relating to
privacy and civil liberties,”6 and “to designate an individual as the program manager responsible
for information sharing across the Federal Government.”7
In July 2005, following “a systematic evaluation of the Department’s operations, policies and
structures”8 (commonly called the Second Stage Review or “2SR”), former Secretary of
Homeland Security, Michael Chertoff, initiated a major reorganization of DHS. In his remarks
describing the reorganization, he noted that “…intelligence lies at the heart of everything that we

1

P.L. 107-296, Nov. 25, 2002, §101b(1), 116 STAT. 2142.
Ibid., §201d(9), 116 STAT. 2147.
3
Ibid., §201d(1), 116 STAT. 2146.
4
National Commission on Terrorist Attacks Upon the United States, The 9/11 Commission Report, July 22, 2004,
pp. 353-356 and 416-418. http://www.9-11commission.gov. Hereafter: 9/11 Commission Report.
5
P.L. 108-458, Dec. 17, 2004.
6
Ibid, §1016b(1), 118 STAT. 3665.
2

7

Ibid, §1016f(1), 118 STAT. 3667. The Program Manager-Information Sharing Environment (PM-ISE), is functionally
aligned within the Office of the Director of National Intelligence (ODNI).
8
DHS, “Secretary Michael Chertoff U.S. DHS Second Stage Review Remarks,” press release, July 13, 2005.
http://www.dhs.gov/xnews/speeches/speech_0255.shtm. Hereafter: Chertoff, “DHS Second Stage Review Remarks.”

Congressional Research Service

1

The Department of Homeland Security Intelligence Enterprise

do.”9 In an effort to improve how DHS manages its intelligence and information sharing
responsibilities, he established a strengthened Office of Intelligence and Analysis (I&A) and
made the Assistant Secretary for Information Analysis (now Under Secretary for Intelligence and
Analysis) the Chief Intelligence Officer (CINT) for the Department. He also tasked I&A with
ensuring that intelligence is coordinated, fused, and analyzed within the Department to provide a
common operational picture; provide a primary connection between DHS and the Intelligence
Community (IC) as a whole; and to act as a primary source of information for state, local and
private sector partners. 10
Figure 1. Current Department of Homeland Security Organization

Source: DHS, July 18, 2008.

In testimony to a House of Representatives hearing shortly after his selection, the first DHS
CINT, stated that “[m]y goal and my role as chief intelligence officer is to see that Homeland
Security intelligence, a blend of traditional and nontraditional intelligence that produces unique
and actionable insights, takes its place along the other kinds of intelligence as an indispensable
tool for securing the nation. 11

9

Ibid.
Ibid.
11
U.S. Congress, Joint Hearing of the Intelligence, Information Sharing, and Risk Assessment Subcommittee of the
House Committee on Homeland Security and the Terrorism, Human Intelligence, Analysis, and Counterintelligence
Subcommittee of the House Permanent Select Committee on Intelligence, “DHS Second Stage Review: The Role of the
Chief Intelligence Officer,” Testimony of Charles Allen, DHS Chief Intelligence Officer, 109th Cong., 2nd sess.,
October 19, 2005. Hereafter: Allen Testimony, Oct. 19, 2005.
10

Congressional Research Service

2

The Department of Homeland Security Intelligence Enterprise

He also set five priorities: Improving the quality of intelligence analysis across the department;
integrating the DHS IE; strengthening support to state, local, and tribal authorities and the private
sector; ensuring that DHS IE takes its place in the IC; and solidifying the relationship with the
Congress; and improving transparency and responsiveness.12
Since the 2SR reorganization, Congress imposed additional requirements on DHS through the
Implementing Recommendations of the 9/11 Commission Act of 2007:13
•

Integrate information and standardize the format of intelligence products
produced within DHS and its components.14

•

Establish department-wide procedures for review and analysis of information
provided by state, local, tribal, and private sector elements; integrate that
information into DHS intelligence products, and disseminate to Federal partners
within the Intelligence Community.15

•

Evaluate how DHS components are utilizing homeland security information and
participating in the Information Sharing Environment. 16

•

Establish a comprehensive information technology network architecture to
connect various DHS elements and promote information sharing. 17

•

Establish a DHS State, Local, and Regional Fusion Center Initiative to establish
partnerships with state, local, and regional fusion centers.18

•

Coordinate and oversee the creation of an Interagency Threat Assessment and
Coordination Group that will bring state, local, and tribal law enforcement and
intelligence analysts “to work in the National Counterterrorism Center (NCTC)19
with Federal intelligence analysts for the purpose of integrating, analyzing and
assisting in the dissemination of federally-coordinated information….”20

The DHS IE consists of those elements within DHS that have an intelligence mission. These
include I&A, the Homeland Infrastructure Threat and Risk Analysis Center, and the Intelligence
Division of the Office of Operations Coordination and Planning (all located at the DHS
headquarters), and the intelligence elements of six operational components: U.S. Customs and
Border Protection (CBP), U.S. Immigration and Customs Enforcement (ICE), U.S. Citizenship
and Immigration Services (USCIS), Transportation Security Administration (TSA), U.S. Coast
12

Ibid.
P.L. 110-53, Aug. 3, 2007.
14
Ibid, §204a, 121 STAT. 307.
15
Ibid, §204(c)(1)A, 121 STAT. 307.
16
Ibid, §204(d)(2)A, 121 STAT. 308.
17
Ibid, §205a, 121 STAT. 308.
18
Ibid, §511, 121 STAT. 317-18.
13

19
NCTC was established by Executive Order (E.O.) 13354 in Aug. 2004, and codified in Section 1021 of the
Intelligence Reform and Terrorism Prevention Act of 2004. It is the primary U.S. Government organization for
integrating and analyzing all intelligence pertaining to counterterrorism (except for information pertaining exclusively
to domestic terrorism). Through its Directorate of Strategic Operational Planning, it is also the executive branch lead
for counterterrorism planning. See NCTC, About the National Counterterrorism Center. http://www.nctc.gov/about_us/
about_nctc.html
20
P.L. 110-53, §521, 121 STAT. 328.

Congressional Research Service

3

The Department of Homeland Security Intelligence Enterprise

Guard (USCG), and U.S. Secret Service (USSS). The Department and USCG are statutory
members of the IC. 21
On February 11, 2010, the Senate confirmed President Obama’s selection of Caryn Wagner to
serve as Under Secretary for Intelligence and Analysis. As she assumes responsibility for the
DHS IE, Congress will likely be interested in the progress of integration of the Department’s
intelligence components and the quality and relevance of the intelligence DHS IE produces for
front line law enforcement and security officials who are responsible for protecting America and
its people.
Also in February, DHS published its first Quadrennial Homeland Security Review (QHSR),22 a
comprehensive assessment outlining its long-term strategy and priorities for homeland security
and guidance on the Department’s programs, assets, capabilities, budget, policies, and authorities.
The next step in the Department’s QHSR process is to conduct a “bottom-up review” to
systematically link strategy to program to budget. The results of that review will be particularly
important as Congress considers an authorization bill for DHS.
Some have argued that there is a broad homeland security intelligence enterprise that
encompasses not only the DHS IE, but other organizations at the Federal, state, local, tribal, and
private sector levels that collect and analyze homeland security information and disseminate
intelligence products. This report will focus on the DHS IE both at headquarters and within the
components; how it is organized; and how it supports key departmental activities to include
homeland security analysis and threat warning, border security, critical infrastructure protection,
and support to and the sharing of information with state, local, tribal, and private sector partners.
It will also discuss oversight challenges and options for Congress to consider on these issues.

Office of Intelligence and Analysis (I&A)
The Homeland Security Intelligence Mission
According to its December 2009 Strategy, the mission of I&A is “To strengthen DHS and its
partners’ ability to perform homeland security functions by accessing, integrating, analyzing, and
sharing timely and relevant intelligence and information, while protecting the privacy, civil rights,
and civil liberties of the people I&A serves.23 It accomplishes this by ensuring that information
related to homeland security threats is collected, analyzed, and disseminated to the full spectrum
of homeland security customers in the Department, at state, local, and tribal levels, in the private
sector, and in the IC.”24 The Under Secretary for I&A is the Chief Intelligence Officer for the
Department and is responsible to lead I&A and the entire DHS IE. The Under Secretary is also
21
There are 16 statutory members of the IC: the Departments of Energy, Justice (Drug Enforcement Administration),
Homeland Security, State, and Treasury; the Central Intelligence Agency, Defense Intelligence Agency, Federal
Bureau of Investigation, National Geospatial-Intelligence Agency, National Reconnaissance Office, National Security
Agency; and the intelligence components of the U.S. Army, Navy, Marines, Air Force, and Coast Guard. See 50 U.S.C.
401a(4)(k).
22
DHS, Quadrennial Homeland Security Review Report: A Strategic Framework for a Secure Homeland,
February 2010. Available at http://www.dhs.gov/xlibrary/assets/qhsr_report.pdf. Hereafter: DHS QHSR Report.
23
DHS Office of Intelligence and Analysis Strategy, Dec. 2009. Hereafter: I&A Strategy, Dec. 2009.
24
DHS, Office of Intelligence and Analysis. http://www.dhs.gov/xabout/structure/gc_1220886590914.shtm.

Congressional Research Service

4

The Department of Homeland Security Intelligence Enterprise

the Department’s chief information sharing officer and is responsible for implementing the
objectives of the PM-ISE within DHS.25
To accomplish its mission, I&A participates in all aspects of the intelligence cycle“ – the process
by which information is acquired, converted into finished intelligence, and made available to
policymakers. Generally the cycle comprises five steps: planning and direction, collection,
processing, analysis, and production and dissemination.”26 It is an iterative process in which
collection requirements based on national security threats are developed, and intelligence is
collected, analyzed, and disseminated to a broad range of consumers.
DHS does not generally engage in traditional foreign intelligence collection activities such as
imagery intelligence, signals intelligence, human intelligence, measurement and signatures
intelligence, and foreign open source intelligence. 27 But, as former Secretary Chertoff has noted:
Intelligence, as you know, is not only about spies and satellites. Intelligence is about the
thousands and thousands of routine, everyday observations and activities. Surveillance,
interactions—each of which may be taken in isolation as not a particularly meaningful piece
of information, but when fused together, gives us a sense of the patterns and the flow that
really is at the core of what intelligence analysis is all about....28

I&A combines the unique information collected by DHS components as part of their operational
activities (e.g., at airports, seaports, and the border) with foreign intelligence from the IC; law
enforcement information from Federal, state, local, and tribal sources; private sector data about
critical infrastructure and key resources; and information from domestic open sources to develop
homeland security intelligence. 29 This encompasses a broad range of homeland security threats. It
includes border security information to counter human smuggling and trafficking, cargo data to
prevent the introduction of dangerous items, information to protect critical infrastructure against
all hazards, information about infectious diseases, and demographic data and other research about
‘violent radicalization.’30

I&A Customers
The DHS I&A Strategy identifies its core customers as the President; Secretary of Homeland
Security; DHS Components; State, Local, Tribal, and Private Sector Partners (through State and
Major Urban Area Fusion Centers); the IC; and Federal Interagency Partners.31 In short, I&A’s

25
Office of Management and Budget, Budget of the United States Government: Fiscal Year 2010, (Washington, DC:
U.S. Government Printing Office, 2009), p. 507. Hereafter: OMB: USG FY10 Budget.
26
Jeffrey T. Richelson, The U.S. Intelligence Community, 5th ed, (Boulder, CO: Westview Press, 2008), pp. 3-4.
Hereafter: Richelson, The U.S. Intelligence Community.
27
For a detailed description of each of these collection disciplines, see Ibid, chapters 7-12.
28
Chertoff, “DHS Second Stage Review Remarks.”
29
For a discussion of the concept of homeland security intelligence, see CRS Report RL33616, Homeland Security
Intelligence: Perceptions, Statutory Definitions, and Approaches, by (name redacted).
30
Congress has defined ‘violent radicalization’ as “the process of adopting or promoting an extremist belief system for
the purpose of facilitating ideologically based violence to advance political, religious, or social change.” H.R. 1955,
Violent Radicalization and Homegrown Terrorism Prevention Act of 2007, §899(a)(2).
31
I&A Strategy, Dec. 2009.

Congressional Research Service

5

The Department of Homeland Security Intelligence Enterprise

customers range from the Chief Executive all the way to individual border patrol agents, Coast
Guard seamen, and airport screeners.
According to Under Secretary Wagner, “A primary role of I&A is to share intelligence and
information with our partners at the state, local, tribal, and private sector levels. It is our job to
meaningfully convert what may appear to be bits of unrelated information into a product that
helps protect our communities.”32 State, local, and tribal law enforcement are “first preventers” of
terrorism and require timely and actionable intelligence to respond to threats. They also need
intelligence about the latest terrorist tactics and techniques so that they know what to look for and
what to do when they encounter suspicious behavior or dangerous items. In addition, I&A
supports the operators of the nation’s publicly and privately-owned critical infrastructure with
threat information and other intelligence that supports their risk management decision making.
Former Under Secretary Charles Allen noted that “virtually any terrorist attack on the homeland
that one can imagine must exploit a border crossing, a port of entry, a critical infrastructure, or
one of the other domains that the department has an obligation to secure. DHS Intelligence must
learn and adapt faster than the enemy, so that our department with all its partners in the federal,
state, and local levels of government and the private sector have the information edge they need
to secure our nation.”33
I&A is a full partner within the IC and represents DHS on several IC committees. The Under
Secretary, for example, is a member of the Director of National Intelligence (DNI)34 Executive
Committee. I&A contributes analytic staff to the National Counterterrorism Center (NCTC). The
office also contributes items to the President’s Daily Brief35 providing a unique homeland security
perspective on terrorism and other threats to the United States to the nation’s leaders.

Integrating the DHS IE
Among the many challenges for DHS since its founding has been the integration of 22 legacy and
newly-created agencies. This also includes the integration of intelligence activities of the
Department’s operational components whose intelligence organizations predate the establishment
of DHS. These intelligence elements were created to support the operational missions of their
respective components and were tailored accordingly.
One of the objectives of the Department’s 2005 2SR reorganization was to enhance integration to
include its intelligence effort. The Under Secretary for I&A is also the Chief Intelligence Officer
for the entire Department. Congress also made the Under Secretary responsible to “establish the
32

U.S. Congress, House Committee on Appropriations, Subcommittee on Homeland Security, DHS Intelligence
Programs and the Effectiveness of State and Local Fusion Centers, Statement of Caryn Wagner, Under Secretary for
Intelligence and Analysis, 111th Cong., 2nd sess., Mar. 4, 2010, p. 3. Hereafter: Wagner Testimony, Mar. 4, 2010.
33
Allen Testimony, Oct. 19, 2005.
34
The DNI serves as the head of the IC and is the principal advisor to the President, the National Security Council, and
the Homeland Security Council for intelligence matters related to national security. The position was created by
Congress in Section 1011 of the Intelligence Reform and Terrorism Prevention Act of 2004. The DNI Executive
Committee consists of the heads of the IC member agencies.
35
The PDB compiles the IC’s highest level intelligence analysis targeted at the key national security issues and
concerns of the President. It is given only to the President, the Vice President, and a very select group of Cabinet-level
officials designated by the President. See CIA, “Directorate of Intelligence Products.” https://www.cia.gov/offices-ofcia/intelligence-analysis/products.html

Congressional Research Service

6

The Department of Homeland Security Intelligence Enterprise

intelligence collection, processing, analysis, and dissemination priorities, policies, processes,
standards, guidelines, and procedures for the intelligence components of the Department.”36

Homeland Security Intelligence Council (HSIC)
The heads of the DHS intelligence components do not report to the Under Secretary, but to their
respective component chiefs. However, pursuant to the Implementing Recommendations of the
9/11 Commission Act of 2007, they are required to advise and coordinate closely with the Under
Secretary on their activities in support of the intelligence mission of the Department. 37
The HSIC was established to serve as the mechanism to provide senior-level direction for
Department-wide intelligence activities and to promote integration efforts. It is chaired by the
Under Secretary and is comprised of the key intelligence officials in applicable DHS components.
In March 2010 testimony, Under Secretary Wagner, stated that the HSIC “... now reflects a
broader range of DHS activities that require intelligence support” and
... is focused on governance-level, enterprise-wide objectives, such as collaboratively
defining intelligence activities for the Department’s Bottom Up Review; and developing new
tools for conducting DHS Intelligence Enterprise program reviews. The HSIC oversaw the
completion of the first coordinated, Enterprise-wide analytic production plan, which builds
on the expertise of the operational components to produce products in their areas, deconflicts
competing efforts, and helps focus analytic efforts on QHSR priorities.38

Budget
I&A is funded through the classified National Intelligence Program (NIP), formerly known as the
National Foreign Intelligence Program. For budgetary purposes, intelligence spending is divided
between the NIP; and the Military Intelligence Program that supports the Secretary of Defense’s
intelligence- and counterintelligence-related responsibilities. 39 The DNI does not publicly
disclose details about the intelligence budget,40 but consistent with Section 601 of the
Implementing Recommendations of the 9/11 Commission Act of 2007 (P.L. 110-53), the DNI
reported that the aggregate amount appropriated to the NIP for FY2009 was $49.8 billion. 41
As part of its responsibility to integrate Department intelligence activities, the Under Secretary
for I&A is responsible for presenting a consolidated intelligence budget to the Secretary. DHS
operational component intelligence activities are generally not part of the NIP—therefore they are
not classified—with the exception of the activities of the Coast Guard’s National Intelligence
36
P.L. 110-53, August 3, 2007, §531, 121 STAT. 3332-3. Amends §201 of the Homeland Security Act of 2002 by
adding paragraphs 18 and 19.
37
Ibid, §503, 121 STAT. 311-2. Amends the Homeland Security Act of 2002 by adding §207.
38
Wagner Testimony, Mar. 4, 2010, p. 5.
39
DOD Financial Management Regulation 7000.14_R, June 2007, p. 16-2. http://www.fas.org/irp/agency/dod/
finman.pdf.
40
The bulk of overall intelligence spending is contained within the DOD budget. Spending for most intelligence
programs is described in classified annexes to intelligence and national defense authorization and appropriations
legislation. All Members of Congress have access to these annexes, but must make special arrangements to read them.
See DNI, The Intelligence Budget Process. http://www.intelligence.gov/2-business_nfip.shtml
41
Office of the DNI News Release No. 33-09, “DNI Releases Budget Figure for 2009 National Intelligence Program,”
Oct. 30, 2009.

Congressional Research Service

7

The Department of Homeland Security Intelligence Enterprise

Element.42 Those budgets are listed within each component’s appropriation, however they are
generally co-mingled with other operational activities.43 Within the FY2009 homeland security
appropriation, the total I&A budget figure (classified) is combined with the budget figure for
operational activities (unclassified) within the Analysis and Operations category.44

I&A Organization
I&A is led by an Under Secretary, a position subject to Senate confirmation. The Under Secretary
also serves as the department’s Chief Intelligence Officer. Caryn Wagner assumed this position on
February 11, 2010. The Under Secretary is supported by a Principal Deputy Under Secretary,
currently Mr. Bart R. Johnson, who served as Acting Under Secretary from May 2009-February
2010.
The current I&A organization is at Figure 2. However to support the strategic goals of its
December 2009 Strategy and the homeland security missions described in the Department’s
QHSR report, I&A intends to realign organizationally in 2010.

The Analysis Mission
I&A is focused on five “analytic thrusts” aligned with the principal threats to the Homeland:45
border security, including narcotics trafficking, alien and human smuggling, and money
laundering; radicalization and extremism; particular groups entering the United States that could
be exploited by terrorists or criminals; critical infrastructure and key resources; and weapons of
mass destruction (WMD) and health threats.
Following a 2009 comprehensive evaluation of its analytic capabilities and functions, I&A has
informed Congress that its analysis and production resources have been prioritized to:
•

Realign analytic resources to improve and expand support to [the] state, local,
and tribal consumer base.

•

Develop an analytic capability and methodology for assessing Suspicious
Activity Reporting data.

•

Create a centralized analysis group to meet the intelligence and information
needs of the Secretary and Department components, including improved
coordination and information sharing.

•

Augment [the] border security analytic capability.

•

Strengthen our collaboration and consultation with other producers of
intelligence and information products.46

42

For a discussion of the USCG National Intelligence Element, see the USCG section of this report.
See CRS Report R40642, Homeland Security Department: FY2010 Appropriations, coordinated by (name redacted)
and (name redacted).
44
Ibid, Table 6, p. 10.
45
DHS I&A, “Homeland Security Analytic Priorities.” http://www.dhs.gov/xabout/structure/gc_1220886590914.shtm
46
U.S. Congress, House Committee on Homeland Security, Subcommittee on Intelligence, Information Sharing, and
Terrorism Risk Assessment, I&A Reconceived: Defining a Homeland Security Intelligence Role, Statement of Bart. R.
(continued...)
43

Congressional Research Service

8

The Department of Homeland Security Intelligence Enterprise

Figure 2. Office of Intelligence and Analysis Organizational Chart

Source: DHS I&A, March 2009.

I&A Intelligence Products
I&A produces numerous products for its customers. In 2008, there was a realignment and
standardization of the I&A finished intelligence product line which now include:
•

Homeland Security Threat Assessment (HSTA). This is an annual threat
assessment that represents the analytical judgments of DHS and assesses the
major threats to the homeland for which the nation must prepare and respond.
This includes the actions, capabilities, and intentions of domestic and foreign
terrorists and extremists and the possible occurrence of systemic threats. It
focuses on domestic extremists, international terrorists operating in the homeland
or directing attacks against it, and systemic threats such as pandemics and
transnational criminal organizations.47 The HSTA is produced in classified and
“Unclassified/For Official Use Only” versions.

•

Intelligence Warning. Contains urgent intelligence.

•

Intelligence Note. Contains timely information or analysis on a current topic.

•

Homeland Security Assessment. Consists of in-depth analysis on a topic.

•

Homeland Security Monitors. These are produced monthly in collaboration with
the components and may be classified or unclassified. Examples include:
•

Border Security Monitor

(...continued)
Johnson, Acting Under Secretary for Intelligence and Analysis, 111th Cong., 1st sess., Sep. 24, 2009, pp. 7-8. Hereafter:
Johnson Testimony, Sep. 24, 2009.
47
DHS, Homeland Security Threat Assessment, Executive Summary, Aug 2007, p. 1.

Congressional Research Service

9

The Department of Homeland Security Intelligence Enterprise

•

Cyber Security Monitor

•

Cuba-Gram

•

Reference Aids. These are less analytical and more descriptive. For example, they
might describe what an anthrax lab looks like or the latest on improvised
explosive devices (IED) and fuses. They contain photos and diagrams and inform
law enforcement and first responders what to look for and what actions to take if
they are encountered.

•

Perspective. These are longer term analytic pieces.

•

Joint Homeland Security Assessment/FBI Intelligence Bulletin. These are joint
reports done in conjunction with the FBI.

I&A also produces Homeland Intelligence Reports (HIR) which contain information that has yet
to be fully evaluated. These are similar to the Intelligence Information Report (IIR)48 produced by
other IC agencies. An HIR could contain information related to border encounters, information
shared by a state or local fusion center, or other information of homeland security interest. There
are also Homeland Security Intelligence Reports (HSIR) that are produced by the DHS
component agencies. HSIR’s, however, do contain some analysis.
I&A makes the products of its analysis available to state and local officials through classified and
unclassified intelligence networks:49 The Homeland Security Information Network (HSIN) is a
secured, web-based platform that facilitates Sensitive But Unclassified information sharing and
collaboration between federal, state, local, tribal, private sector, and international partners. It is
managed by the DHS Directorate of Operations Coordination and Planning. The HSIN platform
was created to interface with existing information sharing networks to support the diverse
communities of interest engaged in preventing, protecting from, responding to, and recovering
from all threats, hazards and incidents under the jurisdiction of DHS.50 It provides real-time,
interactive connectivity between states and major urban areas and the National Operations Center
(NOC).51
There are five community of interest portals on HSIN: Emergency Management, Critical Sectors,
Law Enforcement, Multi-Mission Agencies, and Intelligence and Analysis (HSIN-Intelligence).
The latter portal provides state, local, and tribal authorities access to unclassified intelligence
products. The Homeland Security State and Local Intelligence Community of Interest (HS-SLIC)
is a nationwide, virtual community of intelligence analysts that operates on a special portal on the
HSIN network. The system contains collaborative tools such as discussion thread, chat tool, and
secure messaging through which analysts collaborate. HS-SLIC has members from 45 states, the
48
An IIR is the primary vehicle used to provide human intelligence information to the consumer. It utilizes a message
format structure that supports automated data entry into intelligence community databases. See JP 1-02, DOD
Dictionary of Military and Associated Terms, Apr. 12, 2001, (as amended Oct. 17, 2008), p. 271. http://www.dtic.mil/
doctrine/jel/doddict/. Hereafter: DOD Dictionary.
49
Allen Testimony, Sep. 24, 2008.
50
See DHS, HSIN, Feb. 10, 2009. http://www.dhs.gov/xinfoshare/programs/gc_1156888108137.shtm
51
The NOC, located at the DHS Headquarters in Washington, D.C., operates on a 24/7 basis as the primary nationallevel hub for domestic incident management, operations coordination, and situational awareness. It is staffed by
numerous Federal, state, and local agencies and fuses law enforcement, national intelligence, emergency response and
private sector reporting. The NOC also has an Intelligence Watch and Warning (IWW) cell staffed with analysts from
I&A. See OMB: USG FY10 Budget, p. 507.

Congressional Research Service

10

The Department of Homeland Security Intelligence Enterprise

District of Columbia, and seven Federal agencies. The Under Secretary has established a
governance board for HS-SLIC with strong participation by state and local officials.
The Homeland Secure Data Network (HSDN) provides access to collateral Secret-level terrorismrelated information. This includes NCTC Online, a classified repository that serves as the
counterterrorism community’s library of terrorism information. 52 I&A has deployed HSDN
terminals to 33 state and local fusion centers and intends to install terminals in all of the fusion
centers as soon as security requirements are met.53

Intelligence Support To State, Local, Tribal Officials, and the Private Sector
A longstanding challenge for the department is the focus of I&A analysis and the
relevance of its products to state, local, tribal, and private sector customers.54 For
example, at a homeland security forum in early 2008, some state and local participants
expressed unhappiness with the flow of intelligence from DHS. According to the forum’s
findings, published in the journal Homeland Security Affairs, “[t]he Department had
become ‘irrelevant’ to states and localities as a source of intelligence, because that
intelligence lacks timeliness and adds so little value to local terrorism efforts. Another
participant noted that ‘the stream of intelligence from DHS is useless ... ’”55 Among
efforts to address the issue, former Under Secretary Allen established a State and Local
Fusion Center (SLFC) Pilot Project Team in 2006 to work with six fusion centers56 in five
states to enhance DHS support.

State and Local Fusion Center Program
In an effort to strengthen intelligence and information sharing and analysis capabilities following
the 9/11 attacks, states and major urban areas established intelligence fusion centers.57 Congress
has defined fusion centers as a “collaborative effort of two or more Federal, state, local, or tribal
government agencies that combines resources, expertise, or information with the goal of
maximizing the ability of such agencies to detect, prevent, investigate, apprehend, and respond to
criminal or terrorist activity.”58 At the end of 2009, there were 72 DHS/FBI designated state and
Urban Area Security Initiative (UASI) fusion centers.59
52
NCTC, NCTC and Information Sharing, September 2006. http://74.125.95.132/search?q=cache:7wjkyv3tA0J:www.nctc.gov/docs/report_card_final.pdf+NCTC+Online&cd=1&hl=en&ct=clnk&gl=us
53
Wagner Testimony, Mar. 4, 2010. p. 3.
54
The Government Accountability Office (GAO) has ongoing work regarding I&A’s efforts to support information
sharing with state, local, and tribal government agencies. GAO expects to report on the results of this work later in
2010.
55
Paul Stockton and Patrick S. Roberts, “Findings from the Forum on Homeland Security After the Bush
Administration: Next Steps in Building Unity of Effort,” Homeland Security Affairs, Vol. IV, No. 2,, June 2008, p.6.
56
Pilot sites were the Boston Regional Intelligence Center and the Commonwealth Fusion Center in Massachusetts, the
Florida Fusion Center, the New York State Intelligence Center, the Statewide Terrorism and Intelligence Center in
Illinois, and the Regional Terrorism Threat Analysis Center in Sacramento, California.
57
For a full discussion of fusion centers, see CRS Report RL34070, Fusion Centers: Issues and Options for Congress,
by John Rollins. For an informative discussion of one of the earliest efforts at local law enforcement collaboration and
intelligence fusion and analysis, see John Sullivan and Alain Bauer, Los Angeles Terrorist Early Warning Group,
published by the Los Angeles County Sheriff’s Department in 2008.
58
P.L. 110-53, §511, 121 STAT. 322. Amends Homeland Security Act of 2002 by adding §210A(j).
59
National Criminal Intelligence Resource Center; Tallahassee, Florida; Nov. 4, 2009.

Congressional Research Service

11

The Department of Homeland Security Intelligence Enterprise

Congress mandated that DHS support fusion centers in the Implementing Recommendations of
the 9/11 Commission Act of 2007.60 Through the DHS State, Local, and Regional Fusion Center
Initiative, I&A supports these centers by providing operational, analytic, reporting, and
management advice and assistance; training; information technology systems and connectivity;
and intelligence officers and analysts to participating fusion centers to the maximum extent
practicable.61
I&A intelligence officers assigned to fusion centers are responsible for providing intelligence
support, including briefings to state and local officials; reviewing and analyzing suspicious
activity reports and writing HIRs based on state and local information; supporting the
development of state and local intelligence products; posting material on the HSDN and the HSSLIC portal; and reaching back to I&A for intelligence products and IT resources.
As of March 2010, there are 57 officers deployed to fusion centers and Under Secretary Wagner
has stated that DHS plans to deploy a total of 76 officers (there would be more than one officer at
some fusion centers) by the end of FY2010.62 In interviews of several fusion center directors for
this report, those that had I&A officers assigned to their centers were pleased with the
contributions they were making. The directors who did not have an officer assigned were anxious
to get one. 63

Intelligence Threat Assessment and Coordination Group (ITACG)
Another program intended to improve the focus, relevance, and accessibility of federal
intelligence products for state, local, and tribal officials is the ITACG. In 2007, Congress amended
the Homeland Security Act by directing the establishment of the ITACG at NCTC to “improve
information sharing within the scope of the Information Sharing Environment ...with state, local,
tribal, and private sector officials.”64 Among the objectives of the ITACG is to provide a formal
mechanism to inject a state, local, tribal and private sector perspective about the types of
intelligence products they need and how these products should be produced and disseminated in
order to be of greatest value for these officials.
The ITACG consists of two elements, an ITACG Advisory Council to set policy and develop
processes for the integration, analysis and dissemination of federally-coordinated information;
and an ITACG Detail comprised of state, local, and tribal homeland security and law enforcement
officers and intelligence analysts detailed to work at NCTC with federal intelligence analysts.65
The Under Secretary for I&A, as the Secretary’s designee, was directed to establish and maintain
the ITACG Detail and assign a senior intelligence officer from the department, who would report
directly to the Director of NCTC and manage the Detail on a day-to-day basis.66

60

P.L. 110-53, §511, 121 STAT. 318. Amends Homeland Security Act of 2002 by adding §210A(a).
Ibid. 121 STAT. 319. Amends Homeland Security Act of 2002 by adding §210A(b) and (c).
62
Wagner Testimony, Mar. 4, 2010. p. 3.
63
Comments to CRS by state and local officials, 2008.
64
P.L. 110-53, §521, 121 STAT. 328. Amends Homeland Security Act of 2002 by adding §210D(a).
65
Ibid. Amends Homeland Security Act of 2002 by adding §210D(b).
66
Ibid, 121 STAT. 330. Amends Homeland Security Act of 2002 by adding §210E.
61

Congressional Research Service

12

The Department of Homeland Security Intelligence Enterprise

One historical barrier to the sharing of intelligence information with state, local, and tribal
officials has been the need to protect the sources and methods used to obtain the intelligence
information. The requirement for security clearances and “the need to know” principle have been
cited as impediments to access by these officials. But, as one observer has pointed out, “The local
deputy or officer is not interested in the sources of the information nor the means that were
utilized to obtain it. The deputy or officer does need the tactic, technique, procedure, method, or
resource being reported on to ensure he or she recognizes precursors of an attack when
encountered on the streets.”67 The ITACG Detail is intended to educate and advise NCTC
analysts about state, local, tribal, and private sector requirements, and then assist those analysts in
the preparation of versions of the products at the lowest possible level of classification to make
them accessible to those customers.
As of November 2009, the Detail consists of five state and local law enforcement officers and a
fire services officer. The Detail and the Advisory Council have agreed on the need for increased
representation, specifically in the areas of tribal operations; homeland security planning and
operations at the State and local level; health and human services; and State and local intelligence
analysis. The intent is to grow the ITACG Detail to a full complement of ten SLT
representatives.68
The ITACG Detail has been operational since late January 2008, so it may be too early to judge
how effective it has been in influencing the IC’s production and dissemination of intelligence
products at a level of classification useful for state, local, tribal, and private sector consumers. In
its November 2009 report to Congress on the ITACG, the PM-ISE reported the following
achievements of the ITACG detail:69
•

Informs and helps shape IC products for state and local agencies by reviewing,
and when appropriate, providing comments during the drafting phase of the
process. Since its inception, the Detail has participated in the production of 214
intelligence products.

•

Created the Roll Call Release (RCR), a collaborative For Official Use Only
(FOUO) product produced by DHS, FBI, and the Detail. The product is written
specifically for state, local, and tribal (SLT) “street-level” first responders and
focuses on terrorist tactics, techniques, procedures, terrorism trends, and
indicators of suspicious activity. The success of this product can be measured by
its incorporation into SLT-created publications and from the interest the product
has also drawn from international law enforcement partners. Since the product
line was created in December 2008, 26 RCRs have been published.

•

Works closely with NCTC’s Operations Center in the preparation of the
Terrorism Summary (TERRSUM). The TERRSUM is a daily, SECRET- level
digest of intelligence deemed to be of potential interest to SLT entities. Since its
inception in June 2008, over 350 TERRSUM products have been published.

67
U.S. Congress, House Committee on Homeland Security, Subcommittee on Intelligence, Information Sharing, and
Terrorism Risk Assessment, A Report Card on Homeland Security Information Sharing, Testimony of Lee Baca,
Sheriff, Los Angeles County, 110th Cong., 2nd sess., September 24, 2008, p. 3.
68
Program Manager for the Information Sharing Environment; Report on the ITACG, Second Report for the Congress
of the United States, the Secretary of Homeland Security, the Attorney General, and the Director of National
Intelligence, Nov. 2009, pp. 6-7. http://www.ise.gov/docs/ITACG_Status_Report_PM_ISE_FINAL_24Nov09.pdf
69
Ibid, pp. 10-11.

Congressional Research Service

13

The Department of Homeland Security Intelligence Enterprise

Approximately 45 percent of the articles included in the TERRSUMs have been
suggested by the ITACG Detail.
•

The ITACG Intelligence Guide for First Responders was developed by SLT and
federal members of the ITACG to assist SLT first responders in accessing and
understanding federal intelligence reporting. The guide helps first responders
understand IC jargon and acronyms, provides awareness of what information is
available to them, how to access this information, and to help them understand
threat reporting. The guide has been posted to several Internet websites and
official unclassified portals. In addition, the guide has been mailed to over 16,000
police departments and 32,000 fire departments across the United States, Guam,
Puerto Rico, and the Virgin Islands.

A senior police official at a major police department commented that “the ITACG is a good step
forward, but the problem is that the IC still has a ‘Cold War’ mindset. The culture needs to
change.” He did, however, acknowledge being told by a law enforcement member of the ITACG
Detail that “when he [the Detail member] reviews products and highlights things, ‘the light bulbs
are coming on at NCTC.’ It is beginning to manifest itself in how the product is written, focusing
on the right priorities.”70
However, one senior police official is concerned that “the ITACG is limited to editing intelligence
and returning those products to originating agencies where the information may or may not reach
state and local law enforcement personnel.”71 This police official recommends that the ITACG
“be authorized as an approved dissemination point for state and local fusion centers nationwide.
ITACG liaison personnel are necessary to maintain a flow of current intelligence and must have
authority to release information to state and local agencies.”72

Mission Integration
This Office of the Deputy Under Secretary for Mission Integration (DU/S-M) is responsible for
DHS IE integration activities; policies governing enterprise-wide production and standardization
of reports; the I&A Strategic Plan; training, and the implementation of a comprehensive
information systems architecture.73 As part of its integration responsibilities, the DU/S-M is
responsible for program review, department-level analysis, and cross-cutting intelligence
initiatives. The DU/S-M also chairs the Intelligence Career Management Board that reports to the
HSIC and is responsible for developing core competencies for the intelligence cadre of the
Department. It does this through a document called the Learning Road Map that describes the
tasks intelligence professionals perform, lists the training courses and other opportunities to learn
the tasks, and provides measures to assess performance.74

70

Interview with CRS, Aug. 6, 2008.
U.S. Congress, House Committee on Homeland Security, Subcommittee on Intelligence, Information Sharing, and
Terrorism Risk Assessment, The Future of Fusion Centers: Potential Problems and Dangers, Testimony of Leroy D.
Baca; Sheriff, Los Angeles County, 111th Cong., 1st sess., April 1, 2009, p. 3.
72
Ibid, p. 4.
71

73

A progress report on the department’s efforts to establish a comprehensive information technology network
architecture was submitted to Congress last year. See DHS I&A, Homeland Security Information Technology Network
Architecture Progress Report, April 15, 2008.
74
DHS I&A, Learning Road Map for Intelligence Professionals – Analytics. p. 3.

Congressional Research Service

14

The Department of Homeland Security Intelligence Enterprise

The DU/S-M organization also manages I&A responsibilities for the Department’s
Counterintelligence (CI) Program and the Integrated Border Intelligence Program.

Integrated Border Intelligence Program (IBIP)
I&A established the IBIP to enhance its support to border security activities. Under the program,
additional personnel and support infrastructure have been committed to support all of the
Department’s border security operations. The program is designed to link DHS intelligence
resources, and those of state and local partners, with the IC in order to deliver actionable
intelligence to front-line operators and to fuse national intelligence with law enforcement
information.
An important initiative within the IBIP is the Homeland Intelligence Support Team (HIST). The
first HIST team was deployed in 2007 to El Paso, Texas. It consists of intelligence officers from
I&A whose mission is to coordinate and facilitate the delivery of national intelligence and
enhance information fusion to support DHS operational missions at the border. In this regard it
serves as a bridge between the national and field levels and between I&A and the component
intelligence staffs at the border. It can also push/pull information from state and local law
enforcement officials. The HIST also helps provide context to I&A analysts on topics such as
border violence. Its focus areas are alien smuggling, border violence, weapons trafficking, illicit
finance, drug trafficking, and the nexus between crime and terrorism. Its location at the El Paso
Intelligence Center (EPIC)75 gives the HIST staff immediate access to each of the DHS
operational components plus 15 other Federal, state, and local agencies.
I&A has also increased staffing of the “Borders Branch” within I&A’s analytic element. One
senior I&A official cited this as an example of an evolving focus away from purely terrorism
issues to enhanced support for specific departmental concerns. In 2005, there were only three
analysts working border issues. By mid-2008, there were 20 on the border team. In the same three
years, I&A increased the production of HIR’s from 600, of which 3% were related to the border,
to 3,563 in FY2008,76 of which 22% were border related.77

National Applications Office (NAO).
For more than 30 years, the Civil Applications Committee (CAC) has facilitated requests by civil
agencies to make use of space-based imaging and remote sensing capabilities in support of
traditional mapping applications, as well as a broad range of resource management,

75

EPIC was established in 1974 as an intelligence center to collect and disseminate information relating to drug, alien,
and weapon smuggling in support of field enforcement entities throughout the region. Following 9/11, counterterrorism
also became part of its mission. In response to increased multiagency needs, EPIC has developed into a fully
coordinated, tactical intelligence center supported by databases and resources from member agencies. It is jointly
operated by the Drug Enforcement Administration (DEA) and CBP. Other agencies represented at EPIC include ICE;
USCG; USSS; DOD, Department of the Interior; FBI; Bureau of Alcohol, Tobacco, Firearms and Explosives; U.S.
Marshals Service; Federal Aviation Administration; National Drug Intelligence Center; Internal Revenue Service;
National Geospatial–Intelligence Agency; Joint Task Force–North; Joint Interagency Task Force–South; Texas
Department of Public Safety; Texas Air National Guard; and the El Paso County Sheriff’s Office. See DEA, El Paso
Intelligence Center. http://www.usdoj.gov/dea/programs/epic.htm
76
DHS, DHS Annual Performance Report, FY2008-10, p. 99. http://www.dhs.gov/xlibrary/assets/cfo_apr_fy2008.pdf
77
Interview with I&A senior manager, June 19, 2008.

Congressional Research Service

15

The Department of Homeland Security Intelligence Enterprise

environmental climate natural disaster, and remote sensing applications.78 In its September 2005
report, a DNI study group unanimously recommended that the scope of the CAC be expanded
beyond civil applications to include homeland security and law enforcement applications. In May
2007, the DNI designated DHS to be executive agent and functional manager of the NAO whose
mission is to facilitate the use of IC technological assets for those purposes. 79 I&A placed this
office within the DU/S-M organization.
The establishment of this office, however, has been controversial.80 In 2008, Congress prohibited
the use of funds “to commence or continue operations of the NAO until the Secretary of
Homeland Security certifies in FY2009 that NAO programs comply with all existing laws,
including all applicable privacy and civil liberties standards and that clear definitions of all
proposed domains are established and auditable.”81 Congress also required the Government
Accountability Office (GAO) to review the certification and report to Congress.82
After the Obama Administration took office, DHS revisited the need for an NAO program. On
June 23, 2009, after a five-month review, which the department stated was conducted in
coordination with its law enforcement, emergency management, and intelligence partners,
Secretary Napolitano announced her decision to end the NAO program.83
The CAC will continue to foster information sharing for the civil community and will seek to
provide CAC members access to the skills and information necessary to protect and maximize the
use of assets; facilitate relationships between the Civil and the Intelligence communities to
identify and document their requirements; and expand a monthly inter-community forum for
technology and information exchange to a much broader audience. 84

Homeland Infrastructure Threat and Risk Analysis Center
(HITRAC)
HITRAC is the Department’s infrastructure-intelligence fusion center. It is not a formal part of
I&A, but is jointly resourced and managed by I&A and the Office of Infrastructure Protection, an
office within the DHS National Protection and Programs Directorate. HITRAC’s mission is to
produce and disseminate timely and meaningful threat- and risk-informed analytic products that
can effectively influence the development of infrastructure protection strategies. 85 Its use of
78

U.S. Department of the Interior, Budget Justifications and Performance Information Fiscal Year 2011, pp. I-17-18.
http://www.doi.gov//budget/2011/data/greenbook/FY2011_USGS_Greenbook.pdf . Hereafter: DOI, Budget
Justification, FY2011.
79
DHS, Fact Sheet: National Applications Office, Aug. 15, 2007. http://www.dhs.gov/xnews/releases/
pr_1187188414685.shtm
80
For further background on the controversy surrounding the NAO, see CRS Report RL34421, Satellite Surveillance:
Domestic Issues, by (name redacted) and (name redacted).
81
P.L. 110-329, Sep. 30, 2008, §518(a)2.c.
82

An initial certification review was completed by GAO in 2008. See GAO memo to Congressional Committees, Nov.
6, 2008.
83
DHS Press Release, “Secretary Napolitano Announces Decision to End National Applications Office,” June 23,
2009. http://www.dhs.gov/ynews/releases/pr_1245785980174.shtm
84
DOI, Budget Justification, FY2011, p. I-18.
85
DHS, HITRAC Briefing for CRS on programs and services.

Congressional Research Service

16

The Department of Homeland Security Intelligence Enterprise

intelligence and infrastructure expertise to support risk management decision making is illustrated
at Figure 3.
Figure 3. Homeland Infrastructure Threat and Risk Analysis Center (HITRAC)

Source: DHS HITRAC, Dec. 29, 2008.

HITRAC is organized into two divisions responsible for the Center’s principal functions.86 The
Risk Analysis Division performs infrastructure risk analysis and prioritization to support decision
making. The division manages Congressionally-mandated and priority initiatives, including the
Tier 1 and Tier 2 Program87 and the Critical Foreign Dependencies Initiative (CFDI).88 The Threat
Analysis Division provides three services: critical infrastructure threat analysis, cyber threat
86

Ibid.

87

The Tier 1/Tier 2 Program is intended to identify the Nation’s most critical, highly consequential assets and systems.
The over 3,000 Tier 1/Tier2 assets and systems are those that, if disrupted, could create a combination of significant
casualties, major economic loss, and/or widespread disruptions in governance and nationally critical missions. The Tier
1/Tier 2 Lists are the key components of the Urban Areas Security Initiative and State Homeland Security Grant
Programs’ infrastructure index, as well as other key infrastructure protection programs. See DHS, National Critical
Infrastructure Prioritization Program, Tier 1 and Tier 2 Program Overview. http://www.nonaiswa.org/wordpress/wpcontent/uploads/2009/03/national.ppt
88
CFDI identifies important foreign infrastructure that if attacked or destroyed would critically impact the U.S. The
prioritized National Critical Foreign Dependencies List (NCFDL) currently contains over 300 assets and systems in
over 50 countries. See DHS, Fact Sheet: Critical Infrastructure and Homeland Security Protection Accomplishments,
Sep. 5, 2008. http://www.dhs.gov/xnews/releases/pr_1220878057557.shtm

Congressional Research Service

17

The Department of Homeland Security Intelligence Enterprise

analysis, and regional threat analysis including threat assessments to support the Committee on
Foreign Investment in the United States (CFIUS).89
HITRAC products90 include State Threat Assessments that support the State Homeland Security
Grant Program; Regional Infrastructure Assessments; Strategic Sector Assessment that provide an
overall assessment of potential terrorist threats to critical infrastructure and key resources;
Quarterly Suspicious Activity Analysis of suspicious incident reports to identify signs or patterns
of activity that might pose a threat; Infrastructure Intelligence Notes that provides the private
sector with a timely perspective on events, activities, or information of importance to support
their specific sector-level security planning; and Homeland Security Assessments and Joint
Homeland Security Assessments that communicate intelligence information that impacts the
security of U.S. persons and infrastructure.

Operations Coordination and Planning Directorate (OPS)—
Intelligence Division
In an effort “to improve its operations coordination and planning capability for non-routine,
multi-Component operations to protect, prevent, respond to, and recover from significant threats
and hazards,91 former Secretary Chertoff in 2008 directed the enhancement of an already extant
DHS organization—OPS—which was built on the foundation of the former Office of Operations
Coordination. I&A provides staff to the OPS Intelligence Division, including its director.
A persistent challenge for the Department since its founding has been the integration of 22 legacy
and newly-created agencies. Although the Homeland Security Act of 2002 transferred most
operational responsibilities to DHS, many of these components derive their authorities from
earlier legislation. 92 The execution of these authorities and responsibilities provides them with
nominal operational independence. The Department has sought to develop a robust, departmentwide operations planning and coordination capability to support DHS integration. But, when
operational activities involve only one or two components or routine operations, the need and
incentive for “department-level” planning and coordination is diminished.

89
CFIUS is an interagency committee chaired by the Secretary of the Treasury that reviews transactions that could
result in control of a U.S. business by a foreign person in order to determine the effect of such transactions on the
national security of the United States. The DHS Directorate of Policy reviews each case and makes a recommendation
to the Secretary of Homeland Security regarding the DHS position on the case. HITRAC prepares risk assessments to
support the Directorate of Policy’s review. See Department of the Treasury, Office of Investment Security, CFIUS,
Feb. 20, 2009.
90
DHS, HITRAC Information Briefing to CRS, Dec. 12, 2008.
91

DHS, Memorandum from Secretary Chertoff to DHS Components, “Enhancement of DHS Operations Coordination
and Planning Capability,” May 22, 2008, p. 1. Hereafter: Chertoff Memo, May 22, 2008.
92
For example, the statutory authority for most Federal disaster response activities especially as they pertain to the
Federal Emergency Management Agency (FEMA), is the Robert T. Stafford Disaster Relief and Emergency Assistance
Act, P.L. 100-707, Nov. 23, 1988. Authority for immigration enforcement and administration is the Immigration and
Nationalization Act of 1952 (codified as amended at 8 U.S.C. §1101); Customs authorities are generally derived from
the Tariff Act of 1930, June 17, 1930 (see 19 U.S.C. §§1461, 1467, 1496, 1581, and 1582). Section 114(d) of the
Aviation and Transportation Security Act of 2001, P.L. 107-71, Nov. 19, 2001, (now codified as 49 U.S.C. §114),
assigned TSA responsibility for security of all modes of transportation. The USCG derives authority for its 11 mission
programs from many statutes. The authority, for example, to make inquiries, examinations, inspections, searches,
seizures, and arrests upon the high seas and U.S. territorial waters is 14 U.S.C. §89.

Congressional Research Service

18

The Department of Homeland Security Intelligence Enterprise

A further imperative for department-wide operational planning and coordination is to support
crisis and contingency planning and operations to support the Secretary of Homeland Security in
his/her HSPD-5 role as the principal Federal official for domestic incident management.93 That
role not only involves coordinating activities within DHS and its components, but also all
“Federal operations within the United States to prepare for, respond to, and recover from terrorist
attacks, major disasters, and other emergencies.”94
The Intelligence Division at OPS is staffed by selected I&A personnel who provide timely,
tailored intelligence products and services to support Departmental and interagency plans and
operational coordination efforts. The division reaches back to, coordinates with, and leverages
I&A parent elements, I&A representatives at state and local fusion centers, component
intelligence organizations, and IC agencies as required, for threat-related intelligence, analysis,
and other support.95 How the division is integrated into the OPS structure is shown in Figure 4.
Figure 4. Directorate of Operations Coordination and Planning Organization

Source: DHS OPS, June 22, 2008.

93
According to Homeland Security Presidential Directive (HSPD)-5, Management of Domestic Incidents, February 28,
2003: “To prevent, prepare for, respond to, and recover from terrorist attacks, major disasters, and other emergencies,
the United States Government shall establish a single, comprehensive approach to domestic incident
management....The Secretary of Homeland Security is the principal Federal official for domestic incident
management.” http://www.fas.org/irp/offdocs/nspd/hspd-5.html
94
HSPD-5, paragraph 4.
95
Chertoff Memo, May 22, 2008, p. 2.

Congressional Research Service

19

The Department of Homeland Security Intelligence Enterprise

In short, the key function of the OPS Intelligence Division is the application of intelligence
research and analysis to conditions on the ground that must be considered for effective planning
and operations and the development of a Common Intelligence Picture (CIP).
Former Secretary Chertoff provided insight into what a Common Intelligence Picture for DHS
should look like:
Understanding the enemy’s intent and capabilities affects how we operate at our borders,
how we assess risk in protecting infrastructure, how we discern the kind of threats for which
we must be prepared to respond…. We need to have a common picture across this
Department, of the intelligence that we generate and the intelligence that we require. We
need to fuse that information and combine it with information from other members of the
intelligence community, as well as information from our state and local and international
partners.96

Contributing to the development of a Common Intelligence Picture for the department as a whole
is one of the important roles for the OPS Intelligence Division.

U.S. Customs and Border Protection (CBP)
Intelligence Element
CBP is the agency responsible for securing the nation’s borders at and between ports of entry
(POE).97 It was established in 2003, as a result of the Homeland Security Act of 2002,
consolidating the inspection and patrol functions of the legacy U.S. Customs Service, the
Immigration and Naturalization Service (INS), the U.S. Border Patrol (BP), and the Animal and
Plant Health Inspection Service (APHIS).98 CBP’s primary mission is to prevent the entry of
terrorists and the instruments of terrorism into the United States. But it also has responsibility to
prevent illegal immigration; regulate and facilitate international trade; collect import duties;
enforce U.S. trade and drug laws; and protect Americans and U.S. agricultural and economic
interests by preventing the importation of harmful pests, diseases, and contaminated, diseased,
infested, or adulterated agricultural and food products.
CBP accomplishes its various missions by inspecting persons and goods to determine if they are
authorized to enter the United States. CBP officers and Border Patrol agents intercept illegal
narcotics, firearms, counterfeit merchandise, and other types of contraband. They also interdict
unauthorized aliens and enforce more than 400 laws and regulations at the border.

96

Chertoff, “DHS Second Stage Review Remarks.”

97

A “Port of Entry” or POE, is an officially designated location (seaports, airports, and or land border locations) where
CBP officers or employees are assigned to accept entries of merchandise, clear passengers, collect duties, and enforce
the various provisions of CBP and related laws. Ports also perform agriculture inspections to protect the United States
from potential carriers of animal and plant pests or diseases that could cause serious damage to America’s crops,
livestock, pets, and the environment. See CBP, “Ports of Entry and User Fee Airports.” http://www.cbp.gov/xp/cgov/
trade/trade_outreach/ports.xml.
98
P.L. 107-296, Subtitles C and D.

Congressional Research Service

20

The Department of Homeland Security Intelligence Enterprise

CBP Office of Intelligence and Operations Coordination (OIOC)
In October 2007, CBP reorganized its intelligence and anti-terrorism functions by establishing the
OIOC headed by an Assistant Commissioner. It provides intelligence support to CBP’s effort to
detect, identify, target, and interdict terrorists, terrorist threats, weapons of mass destruction
(WMD), illegal aliens and alien smuggling groups, narcotics traffickers, and other criminals
attempting to penetrate or use the borders of the United States to facilitate their illegal activities.99
The Assistant Commissioner for OIOC is also responsible for managing the coordination of field
operations among and beyond CBP elements and for CBP’s continuity of operations program.100
The OIOC also functions as the situational awareness hub for CBP providing timely and relevant
information and actionable intelligence to operators and decision-makers. The OIOC is divided
into four divisions, Incident Management, Field Coordination, Analysis and Targeting, and
Intelligence and Situational Awareness. OIOC analysts are stationed at its headquarters and are
posted to other agencies in a liaison capacity, such as NCTC, the NJTTF, and the Human
Smuggling and Trafficking Center (HSTC).

CBP Intelligence Support to DHS and CBP Missions.
CBP intelligence operations are designed to support the full range of CBP missions, particularly
its primary mission of preventing the entry of terrorists and the instruments of terrorism. To that
end, the CBP OIOC is engaged in the entire intelligence cycle, including planning, collection,
processing, production, and dissemination of “all source” information and intelligence to support
CBP’s operational elements, as well as their partners within DHS and other government
agencies.101
Although CBP does not engage in traditional foreign intelligence collection activities, it receives
information from DHS I&A, the IC, and law enforcement agencies. In addition, CBP gathers and
analyzes large amounts of data concerning persons and cargo inbound to the U.S. as well as
information derived from the apprehensions of illegal aliens, drug seizures, and other border
enforcement activities. For example, CBP collects advance passenger information (API)102 for all
air and ship passengers and crew traveling to or from the United States. During its border
inspection activities, CBP officers may also examine documents, books, and other printed
material, as well as computers disks, hard drives, and other electronic or digital storage
devices. 103 All of this data is a unique source of operational intelligence that is potentially very
99

CBP, “OIOC Organizational Information.” http://www.cbp.gov/xp/cgov/about/organization/assist_comm_off/
Ibid.
101
CBP, “Commissioner’s Message – New Office of Intelligence and Operations Coordination,” July 23, 2007.
100

102

API data consists of the information on the biographical page of the person’s passport, plus additional information
on the flight or voyage generated by the airline or shipping line. API includes the traveler’s surname, first name, and
any middle names; date of birth; gender; citizenship; and type of travel document used for identification, document
number, and place of issue. API also includes departure point and time, arrival point and time, and air carrier and flight
number.
103
A CBP officer’s border search authority is derived from federal statutes and regulations, including 19 C.F.R. 162.6,
which states that, “All persons, baggage and merchandise arriving in the Customs territory of the United States from
places outside thereof are liable to inspection by a CBP officer.” Unless exempt by diplomatic status, all persons
entering the United States, including U.S. citizens, are subject to examination and search by CBP officers. Source:
CBP, “CBP Authority to Search,” June 12, 2008. Hereafter: “CBP Authority to Search.” http://www.cbp.gov/xp/cgov/
travel/admissibility/authority_to_search.xml

Congressional Research Service

21

The Department of Homeland Security Intelligence Enterprise

useful to other Federal agencies with national security missions. The border environments in
which the CBP offices operate illustrate how intelligence supports DHS and CBP mission
activities.

At Ports of Entry
CBP officers conduct screening activities to determine the admissibility of persons and goods and
interdict dangerous people, dangerous items, and contraband. Given the volume of people and
goods seeking entry into the U.S. every year, it is impractical for CBP to physically inspect every
person or shipment that arrives at a U.S. port.104 Therefore, CBP analyzes trade data and cargo,
crew, and passenger manifest information to ‘target’ its inspection resources towards those
persons or cargo shipments that potentially pose the highest risk. Intelligence from other Federal
agencies, in the form of ‘lookouts,’ and other law enforcement and intelligence reporting, is also
reviewed.
The targeting mechanism used by CBP is the Automated Targeting System (ATS). ATS is
composed of six modules that focus on exports, imports, passengers and crew (airline passenger
and crew on international flights, passengers and crew on sea carriers), private vehicles crossing
at land borders, and import trends over time. These modules employ weighted rule sets105 to
identify high-risk passengers and cargo shipments.
In the cargo environment, ATS employs these rule sets to assign scores based on factors
associated with risk. Above a certain threshold risk score, cargo is subject to further inspection.106
A variety of data107 is used within ATS to perform risk analysis. For cargo, ATS uses data from the
Automated Commercial System (ACS), Automated Broker Interface (ABI), Automated Manifest
System (AMS), and the new Automated Commercial Environment. 108

104

In FY2009, at 327 ports of entry, CBP inspected over 361 million travelers; 109 million cars, trucks, buses, trains,
vessels, and aircraft; encountered 224,000 inadmissible aliens; seized more than 1.5 million pounds of illegal narcotics;
and seized over 1.5 million prohibited meat, plant materials or animal products, including 166,727 agricultural pests.
Source: CBP, Securing America’s Borders – CBP 2009 Fiscal Year in Review, November 24, 2009.
http://www.cbp.gov/xp/cgov/newsroom/news_releases/archives/2009_news_releases/nov_09/11242009_5.xml
105
These rules are developed using sophisticated concepts of business activity intended to identify suspicious or
unusual behavior. See DHS Chief Privacy Officer, Privacy Impact Assessment (PIA) CBP ATS, November 22, 2006., p.
3. Hereafter: DHS Privacy Impact Assessment on ATS.
106
National targeting thresholds are set by the National Targeting Center and are evaluated and adjusted in response to
intelligence and analysis.
107
Data include electronically filed bills, entries, and entry summaries for cargo imports; shippers’ export declarations
and transportation bookings and bills for cargo exports; manifests for arriving and departing passengers; land border
crossing and referral records for vehicles crossing the border, airline reservation data; non-immigrant entry records; and
records from secondary referrals, incident logs, suspect and violator indices, and seizures. A full list of data by module
can be found at DHS Privacy Impact Assessment on ATS, Appendix A, pp. 25-27.
108
ACS is the legacy system used by CBP to track, control, and process all commercial goods imported into the United
States. ABI is the part of ACS that permits qualified participants to file import data electronically. AMS is used by
carriers to file advance declarations of their international containers and cargo contents. ACE is CBP’s new import and
export cargo manifest processing system intended to facilitate trade and strengthen border security. Deployed in phases,
ACE will be expanded to provide cargo processing capabilities across all modes of transportation and replace existing
systems with a single, multi-modal manifest system for land, air, rail and sea cargo in a secure, paper-free, web-enabled
environment. See CBP, “ACE At a Glance Fact Sheet,” Oct. 7, 2009. http://www.cbp.gov/xp/cgov/newsroom/
fact_sheets/trade/ace_factsheets/ace_glance_sheet.xml

Congressional Research Service

22

The Department of Homeland Security Intelligence Enterprise

The passenger component of ATS (ATS-P) processes traveler information against other
information available to ATS, and applies threat-based scenarios comprised of risk-based rules to
assist CBP officers in identifying individuals who require additional screening or in determining
whether individuals should be allowed or denied entry into the United States. The risk-based rules
are derived from discrete data elements, including criteria that pertain to specific
operational/tactical objectives or local enforcement efforts.
Unlike in the cargo environment, ATS-P does not use a score to determine an individual’s risk
level. Instead, it compares Passenger Name Record (PNR) 109 and information in the following
databases against lookouts and patterns of suspicious activity identified by analysts based upon
past investigations and intelligence.
•

Treasury Enforcement Communications System (TECS)110

•

Advance Passenger Information System (APIS)111

•

Non Immigrant Information System (NIIS)112

•

Suspect and Violator Indices (SAVI)113

•

Department of State visa databases114

•

Passenger Name Record (PNR) systems

This risk assessment is an analysis of the threat-based scenario(s) that a traveler matched when
traveling on a given flight. These scenarios are drawn from previous and current law enforcement
and intelligence information. This analysis is done in advance of a traveler’s arrival to or

109

PNR is the information contained within the computerized reservation systems of air and sea carriers. PNR data
include, but are not limited to full itinerary; co-travelers; contact information; travel agency, form of payment; seat
assignment; bag tag numbers, and changes to the reservation. A full list of PNR data fields is at DHS Privacy Impact
Assessment on ATS, Appendix B, p. 28.
110
TECS is a computerized information system designed to identify individuals and businesses suspected of, or
involved in violation of Federal law. Resident on TECS at the CBP Data Center is the Interagency Border Information
System (IBIS) which tracks information on suspected individuals, businesses, vehicles, aircraft, and vessels and
includes terrorist and other law enforcement lookouts, and visa, immigration, and border crossing data. TECS also
provides access to the FBI’s National Crime Information Center (NCIC) and the National Law Enforcement
Telecommunication Systems (NLETS), the latter of which provides direct access to state motor vehicle departments.
See “CBP Authority to Search;” and Department of Treasury, “System of Records Notice,” 66 Federal Register 53029,
Oct. 18, 2001.
111
APIS is the electronic data interchange system for air carrier transmission to CBP of electronic passenger, crew
member, and non-crew member manifest data. See DHS, “Advance Electronic Transmission of Passenger and Crew
Member Manifests for Commercial Aircraft and Vessels; Final Rule,” 72 Federal Register 48320, Aug. 23, 2007.
Hereafter referred to as DHS Advance Electronic Transmission of Manifests Final Rule, Aug. 23, 2007.
112
The NIIS is a repository of records tracking persons arriving in or departing from the United States as nonimmigrant visitors. See USCIS, System Notice for Non Immigrant Information System. http://www.uscis.gov/portal/site/
uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=
f63fd0676988d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=
34139c7755cb9010VgnVCM10000045f3d6a1RCRD&survey=1
113
SAVI consists of records of individuals suspected of or who have violated Customs laws. See Department of
Treasury, “System of Records Notice,” 66 Federal Register 53025 and 53031, Oct. 18, 2001.
114
These include the Consular Lookout and Support System (CLASS), used by State Department to house information
about people who have violated the terms of their visas; and the Consolidated Consular Database (CCD), which
integrates State Department information used by foreign visa officers.

Congressional Research Service

23

The Department of Homeland Security Intelligence Enterprise

departure from the United States and becomes one tool available to DHS officers in identifying
illegal activity. 115
It was through application of the ATS-P that CBP officers at the National Targeting Center
selected Umar Farouk Abdulmutallab, who attempted to detonate an explosive device on board
Northwest Flight 253 on December 25, 2009, for further questioning upon his arrival at the
Detroit Metropolitan Wayne County Airport POE.116

National Targeting Center (NTC)
The operational organization that utilizes the ATS to support CBP officers at POE’s is the NTC. It
is not an intelligence organization, it is part of the CBP Office of Field Operations. But it is a
significant consumer of intelligence information, upon which it conducts analysis and bases
recommendations for security actions. It is also a major source of information about passenger
and cargo movements that can be exploited for intelligence purposes.
The NTC grew out of efforts by the legacy U.S. Customs Service to develop targeting techniques
at the port level to detect drug smuggling and currency violations in both the passenger and cargo
environments. Post-9/11, Customs began adapting these targeting practices towards anti-terrorist
and other national security concerns. In November of 2001, following the 9/11 attacks, the NTC
began operations on a 24/7 basis. In March 2007, the NTC was divided into two elements,
NTC–Passenger and NTC–Cargo.

NTC—Passenger (NTCP)
The NTCP works closely with the OIOC and other intelligence and law enforcement
organizations to develop targeting rule sets for ATS-P. They then work with analytical units
located at POE’s to provide targeting information and real-time response to requests from CBP
officers in the field for information on potentially high-risk passengers seeking entry into the
United States.117 One of the most important sources of information analyzed by NTCP is API data
which commercial carriers are required to submit to CBP on all air and ship passengers and crew
traveling to the United States.118 The data is examined to determine possible matches with various
inspection systems and watchlists that include lookouts on known and suspected terrorists or
other persons of interest to U.S. law enforcement agencies.

NTC—Cargo (NTCC)
The NTCC supports efforts to detect and prevent dangerous cargo from entering the United
States. It examines advance electronic manifest information that CBP requires to be submitted for
all modes of transportation.119 It then uses advanced, computerized risk-assessment techniques
115

DHS System of Records Notice for the ATS, p. 6.
Sebastian Rotella, “U.S. Learned Intelligence on Airline Attack Suspect While He Was Enroute.” Los Angeles
Times.com, Jan. 7, 2010. http://articles.latimes.com/2010/jan/07/nation/la-na-airline-terror7-....jan07
117
CBP, Performance and Accountability Report, FY2007, Nov. 13, 2007, p. 17.
116

118
Effective Feb. 18, 2008, carriers must provide CBP with API data in advance of passenger boarding of aircraft or
vessels. See DHS Advance Electronic Transmission of Manifests Final Rule, Aug. 23, 2007.
119
Twenty-four hours in advance of lading for cargo loaded on US-bound vessels; four hours or wheels-up for
(continued...)

Congressional Research Service

24

The Department of Homeland Security Intelligence Enterprise

within ATS to sort the information according to more than 100 variables. Citing security
concerns, federal officials refused to list those variables, but some officials said that the port of
origin, the nature of the cargo, and the track records of the exporter and importer were among the
criteria.120 In addition, the NTCC provides significant support to Cargo Security Initiative ports
where CBP has stationed targeting teams to identity containers for inspection prior to their being
loaded on U.S.-bound vessels.
The NTCC works closely with OIOC to develop targeting rule sets for the cargo component of
ATS. They also collaborate with NTCP who notifies NTCC of any passenger matches to terroristrelated or other law enforcement lookouts. NTCC will then run those matches against various
databases to determine if those individuals are involved with any cargo businesses or specific
cargo shipments.
The NTCC focuses particular attention on types of cargo that could be ingredients for weapons of
mass destruction (WMD), weapons of mass effect, chemical precursors of illegal drugs, and
conventional weapons and explosives. Sweeps based on specified targeting parameters are
conducted daily to target suspect chemical, biological, radiological, conventional weapons,
explosives, and ammonium nitrate shipments.121 In early 2008, working with ICE and DEA, this
targeting identified suspicious bills of lading, which led to the seizure of chemicals associated
with the manufacture of methamphetamines.122 In late 2007, targeting and analysis within NTCC
led to the intercept and seizure of over $3 million worth of assault rifles and small arms destined
for Central America.123

Between POE’s.
While CBP officers work primarily at POE’s, Border Patrol agents patrol vast areas along the
northern and southern international land borders of the United States that lie in between the
POE’s, as well as the coasts of Florida, Puerto Rico, and the U.S. Virgin Islands. The Office of
Air and Marine (A&M ) supports this mission through its operations within the air and maritime
environments. Two centers that provide intelligence support to these operations are the Border
Field Intelligence Center (BORFIC) and the Air and Marine Operations Center (AMOC). In
addition, the Border Patrol has placed intelligence units within each of its 20 Border Patrol
Sectors.124
OIOC supports BP and A&M with real-time intelligence and strategic analyses about the
conveyances, routes, and other methods that undocumented aliens, human smugglers, drug
(...continued)
international air cargo; four hours in advance of arrival for inbound rail cargo; and one hour in advance of arrival for
cargo on inbound trucks (30 minutes in advance of arrival for FAST shipments).
120
Seth Schiesel, “Their Mission: Intercepting Deadly Cargo,” New York Times, Mar. 20, 2003.
121
CBP, “NTCC,” a briefing provided to CRS on July 21, 2008.
122
Ibid.
123
Ibid.
124
The Border Patrol Sectors (listed alphabetically): Blaine, Washington; Buffalo, New York; Del Rio, Texas; Detroit
(Selfridge Air National Guard Base), Michigan; El Centro, California; El Paso, Texas; Grand Forks, North Dakota;
Havre, Montana; Houlton, Maine; Laredo, Texas; Marfa, Texas; Miami, Florida; New Orleans, Louisiana; Ramey,
(Aguadilla), Puerto Rico; Rio Grande Valley, Texas; San Diego, California; Spokane, Washington; Swanton, Vermont;
Tucson, Arizona; and Yuma, Arizona.

Congressional Research Service

25

The Department of Homeland Security Intelligence Enterprise

traffickers, and other criminals use to enter or smuggle persons or contraband into the United
States. An example of this strategic intelligence analysis was an April 2006 report125 co-produced
by CBP and the NCTC. The report, which surveyed the arrest records of “special interest aliens”
(SIA)126 caught at the U.S. southern border, revealed how these individuals entered the U.S. and
how terrorists could exploit such vulnerabilities.
In response to this information, DHS developed and implemented a multi-pronged plan to address
those vulnerabilities. The plan included targeted training and other efforts to eliminate the
proliferation and use of false passports from one African country; and training to build the
detection capabilities of several Western Hemisphere countries that were noted to be used by
SIA’s with false or altered passports in transit to the United States.

Border Field Intelligence Center (BORFIC)
Originally established as the Border Patrol Field Intelligence Center in 2004 in El Paso, Texas,
BORFIC conducts all-source intelligence activities to support the border security mission of the
BP and other DHS and CBP elements to predict, detect, deter, and interdict terrorists, terrorist
weapons, and human traffickers and contraband smugglers entering the United States.127 In
October 2007, the organization was fully integrated into the CBP OIOC and its name changed to
the Border Field Intelligence Center.
BORFIC is responsible for supporting security efforts on both the northern and southern borders.
It exchanges intelligence and law enforcement information with numerous Federal, state, local,
and tribal organizations agencies and actively participates in several interagency and bilateral
groups. These include the El Paso Interagency Intelligence Working Group which includes EPIC,
DOD’s Joint Task Force-North, and the FBI; the Bilateral Interdiction Working Group with
Mexico, the Integrated Border Intelligence Teams (IBETS)128 with Canada, and the Caribbean
Border Interagency Group. BORFIC shares law enforcement intelligence information with state
and local fusion centers through the HS-SLIC portal. In addition, BORFIC has four personnel
assigned to the El Paso Intelligence Center (EPIC) who work in tandem with I&A’s Homeland
Intelligence Support Team also located there.

125

NCTC, SIA Trends Reveal Vulnerabilities Along Route to U.S., Apr. 6, 2006.
The term Special Interest Alien (SIA) covers individuals traveling illegally to the United States and originating in
Afghanistan, Algeria, Bahrain, Bangladesh, Djibouti, Egypt, Eritrea, Indonesia, Iran, Iraq, Jordan, Kazakhstan, Kuwait,
Lebanon, Libya, Malaysia, Mauritania, Morocco, Oman, Pakistan, Philippines, Qatar, Saudi Arabia, Somalia, Sudan,
Syria, Tajikistan, Thailand, Tunisia, Turkey, Turkmenistan, United Arab Emirates, Uzbekistan, Yemen, Gaza, and the
West Bank. See Ibid., p. 1. Countries and territories are presumed to be included on the SIA list due to the connections
of some of their citizens to international terrorism.
127
CBP BORFIC, Briefing for CRS, Dec. 3, 2008.
128
The IBETS are a joint effort of U.S. and Canadian law enforcement and security agencies to combine and
coordinate their intelligence and law enforcement expertise to identify and stop the high-risk movement of people and
goods between the ports of entry on the Canada - United States border. On the Canadian side, IBETS are co-managed
by the Canadian Border Security Agency (CBSA) and the Royal Canadian Mounted Police. U.S. participating agencies
are CBP, ICE, and the USCG. There are IBETs operating in 15 regions along the border. Source: CBSA, Canada-U.S.
IBETS. http://www.cbsa-asfc.gc.ca/security-securite/ibet-eipf-eng.html#mission
126

Congressional Research Service

26

The Department of Homeland Security Intelligence Enterprise

Air and Marine Operations Center (AMOC)
Located in Riverside, California, the AMOC is a 24/7, multi-agency coordination center that
detects, sorts, and monitors air and marine tracks of interest129 across the nation’s borders and
maritime approaches. A subordinate center located in Puerto Rico performs the same mission for
the Caribbean region. The AMOC also serves as host activity for the central operations of CBP’s
long-range unmanned aircraft systems and is the CBP focal point for the coordination of
unmanned aircraft system maritime operations with the USCG. The AMOC is staffed with
intelligence operations specialists who provide connectivity to the OIOC, DHS, and the IC. It also
has liaison officers assigned from the USCG, FAA, DOD National Guard Bureau, and the
Government of Mexico. 130
The AMOC produces a comprehensive air surveillance radar picture through its Air and Marine
Operations Surveillance System (AMOSS). Fusing input from up to 450 sensors, including an
extensive network of military and civilian radars across the United States and Canada, the
AMOSS can process up to 24,000 fused tracks every 12 seconds and input up to 1,000 flight
plans per minute. 131 This allows the AMOC to provide real-time data on suspicious or noncooperative aircraft and marine vessels to A&M, BP, and the USCG to support interdiction
operations as well as to other DHS intelligence and operations centers. In addition to aircraft and
vessel location data, Detection Systems Specialists at the AMOC have access to numerous law
enforcement and other databases that allow them to provide operational units with information
regarding the flight plans, history, ownership, and registration of aircraft and vessels and criminal
background information on pilots and vessel crew.
In addition to its land and maritime border security mission, the AMOC also supports the multiagency effort to provide airspace security for the National Capital Region. As a participating
agency within the National Capital Region Coordination Center, the AMOC provides its
comprehensive radar picture and law enforcement sorting, detection, and investigative
capabilities to assist in identifying and determining the threat posed by aircraft that are not
compliant with the flight rules in effect for the Washington, D.C. Metropolitan Area Air Defense
Identification Zone (DC ADIZ). 132

Intelligence Driven Special Operations (IDSO)
OIOC collaborates with CBP Office of Field Operations to develop IDSO’s based on threat
information. IDSO’s not only address immediate threat concerns, but also serve to counter
predictability in CBP inspection operations. They are enforcement actions that are based upon

129
Among the reasons for an aircraft or vessel to be considered a track of interest is that it is unidentified,
uncooperative (i.e., not responding to air traffic control or law enforcement direction), or otherwise behaving
suspiciously.
130
U.S. Government Accountability Office, Opportunities Exist to Enhance Collaboration at 24/7 Operations Centers
Staffed by Multiple DHS Agencies, 07-89, Oct. 2006, pp. 13-14.
131
Spanky Kirsch, “Multifunction Phased Array Radar’s Contribution to Secure Skies and Borders,” DHS Science and
Technology Directorate, slide presentation, Oct. 11, 2007, slide 24.
132
The DC ADIZ is that area of airspace in which the ready identification, location, and control of aircraft is required
in the interests of national security. Specifically, it is that airspace from the surface to 18,000 feet within a 30-mile
radius of the Reagan Washington National Airport (DCA). See Federal Aviation Administration (FAA) Notice to
Airmen (NOTAM) 7/0206, effective Aug. 30, 2007.

Congressional Research Service

27

The Department of Homeland Security Intelligence Enterprise

specific intelligence or current trends and are vetted through the DHS CINT.133 For example, if an
increase in aliens entering the United States illegally from or through a particular country were
documented, CBP could develop an IDSO to intensify inspection activity on persons and routes
from that country.
An IDSO based on specific intelligence was conducted following the March 2004 Madrid train
bombings. CBP analysis revealed an increase in aliens attempting to enter the U.S. illegally using
freight and passenger railcars along the northern border. In response, CBP assigned officers and
resources to targeted POE’s to intensify inspections of railcars; NTC intensified its screening of
persons and cargo, the BP assisted in capturing and detaining illegal aliens; and CBP intelligence
intensified its checks of foreign nationals through the IC.134

Immigration and Customs Enforcement (ICE)
Intelligence Element
ICE is the largest investigative organization within DHS. It was established in 2003 and
incorporated into DHS by consolidating the investigative elements of the former U.S. Customs
Service and Immigration and Naturalization Service (INS) and by transferring the Federal
Protective Service from the General Services Administration (GSA).
ICE’s mission is to enforce trade and immigration laws through the investigation of activities,
persons and events that may pose a threat to the safety or security of the United States and its
people. OI also investigates illegal trafficking in weapons (including weapons of mass
destruction), the smuggling of narcotics and other contraband, human smuggling and trafficking,
money laundering and other financial crimes, fraudulent trade practices, identity and benefit
fraud, child pornography, child sex tourism, and health and public safety dangers.135 It has four
operational divisions:
•

Office of Investigations (OI). OI is responsible for investigating a range of issues
that may threaten national security. OI uses its legal authority to investigate
issues such as immigration crime, human rights violations, and human
smuggling; narcotics, weapons and other types of smuggling; and financial
crimes, cybercrime, and export enforcement issues. 136 Of note, ICE Special
Agents are the largest non-FBI component of the Joint Terrorism Task Forces
(JTTF).137

133

Written Testimony of CBP Director of the Office of Intelligence, L. Thomas Bortmes, in U.S. Congress, Hearing of
the Intelligence, Information Sharing, and Risk Assessment Subcommittee of the House Committee on Homeland
Security, “DHS Intelligence and Border Security: Delivering Operational Intelligence.” 109th Cong., 2nd sess.,
June 28, 2006, (Washington: U.S. GPO, 2007).
134
CBP briefing to CRS, May 25, 2004.
135
ICE, FY2010 Enacted Budget Fact Sheet, Nov. 5, 2009, http://www.ice.gov/pi/news/factsheets/
136
ICE, ICE Programs, Office of Investigations. http://www.ice.gov/investigations/index.htm
137
Joint Terrorism Task Forces (JTTFs) are investigative units consisting of law enforcement and other specialists from
dozens of U.S. Federal, state, and local law enforcement and intelligence agencies. They are led by DOJ and the FBI.
The National JTTF was established in July 2002. Forty agencies are represented in the NJTTF, which has become a
focal point for information sharing and the management of large-scale projects that involve multiple agencies. See
DOJ, Joint Terrorism Task Force. http://www.usdoj.gov/jttf/

Congressional Research Service

28

The Department of Homeland Security Intelligence Enterprise

•

Detention and Removal Operations (DRO). DRO is the primary enforcement arm
within ICE for the identification, apprehension and removal of illegal aliens from
the United States.138

•

Office of International Affairs (OIA). With 63 offices in 44 countries, OIA
develops partnerships with foreign governments to advance the homeland
security mission. 139

•

Office of Intelligence, discussed below.

Office of Intelligence
ICE’s intelligence activities are coordinated and managed within the Office of Intelligence. The
office is responsible for collecting, analyzing, and disseminating strategic and tactical intelligence
for use by the operational elements of ICE and DHS. ICE intelligence activities focus on
information related to the movement of people, money and materials into, within and out of the
United States. Its objective is to provide timely, accurate, and useful intelligence to support a
range of investigative activities by identifying patterns, trends, routes, and methods of criminal
activity; predicting emerging and future threats; and identifying potential systemic vulnerabilities
and methods to mitigate those vulnerabilities. 140
Although ICE is not a member of the IC, the Office of Intelligence participates in all aspects of
the intelligence cycle. In support of the agency’s mission, the office collects and analyzes
information from a variety of sources including the IC, other federal agencies, other components
of DHS, state, local, tribal, and foreign agencies. It also analyzes the considerable information
derived from ICE operational activity, such as investigations, document exploitation, and
interviews of detainees. Information sources include classified intelligence reporting, law
enforcement sensitive information, and open source material such as commercial and trade data.
Consumers of ICE intelligence products are ICE investigators; DRO and FPS officials; the ICE
and DHS leadership; DHS partners, particularly CBP; the Department of State; FBI; the Drug
Enforcement Administration; the Bureau of Alcohol, Tobacco, and Firearms, and state and local
law enforcement agencies.
The Office of Intelligence is led by a Director and consists of six divisions and 26 Field
Intelligence Groups.141 The Intelligence Operations Division coordinates and provides
intelligence support to ICE field components, including the ICE Special Agent-in-Charge (SAC)
offices, DRO field offices, and FPS regions. The Intelligence Programs Division analyzes
information obtained from intelligence, law enforcement, and open sources and produces finished
intelligence products to support ICE, DHS, and other intelligence and law enforcement
consumers.

138

ICE, ICE Programs, Detention and Removal Operations. http://www.ice.gov/pi/dro/index.htm
ICE, About the ICE Office of International Affairs. http://www.ice.gov/international-affairs/presence.htm
140
ICE Office of Intelligence, Mission Overview and Guide to Products and Services, June 2008, p. 1.
141
The missions of these divisions are described in detail in Ibid, pp. 2-5.
139

Congressional Research Service

29

The Department of Homeland Security Intelligence Enterprise

Intelligence Programs Division
The Intelligence Programs Division has the following specialized units: Counter Proliferation
Intelligence, Human Smuggling and Public Safety (HSPSU), Contraband, Illicit Finance/Trade
Fraud, and International Intelligence, and the Tactical Intelligence Center located in Bay Saint
Louis, Mississippi, which works with the National Security Agency and other intelligence units to
integrate and analyze signals intelligence, human intelligence, and law enforcement information
to identify new criminal organization targets for ICE investigations, assist NSA in SIGINT
targeting, and support other Office of Intelligence units in performing strategic level intelligence
analysis.
The International and Border Support unit focuses production on two primary areas. The first is
support rendered to the ICE Attachés of the Office of International Affairs through the
International Intelligence Unit. The second is through another cell that provides support to
Southwest Border operations that target criminal organizations operating in that region, especially
those that contribute to escalating violence along the border. Southwest Border is focused on four
operations: the Border Violence Intelligence Cell, Support the Border Enforcement Security
Taskforces, Operation Armas Cruzdas, and Operation Firewall.

Border Violence Intelligence Cell (BVIC)
The BVIC was established in January 2008 in order to provide intelligence support for ICE
weapons smuggling investigations and government-wide efforts to combat violence along the
United States-Mexico border.142 It is located at EPIC within the Crime-Terror Nexus Unit. The
BVIC works closely with I&A’s Homeland Intelligence Support Team, and other partners at
EPIC.
As the level of violence along the U.S.- Mexican border intensified in the past two years, ICE has
partnered with Mexican and other U.S. law enforcement agencies on three initiatives described
below to enhance border security, disrupt transnational criminal organizations, and stop the illegal
flow of firearms from the United States into Mexico. These are the Border Enforcement Security
Task Forces (BEST), Armas Cruzadas, and Operation Firewall. The BVIC supports all three
programs. At the BVIC, all-source intelligence is analyzed and operational leads are provided to
the BEST task forces and ICE attaché offices. The BVIC also analyzes data from arrests and
seizures by the BEST task forces and exchange intelligence with Mexican law enforcement
agencies.
In November 2008, the BVIC, in collaboration with CBP and DHS I&A, produced an Intelligence
Report, United States Southbound Weapons Smuggling Assessment, which examined U.S.
southbound weapon smuggling trends. This report was designed to support the BEST’s and other
operational components in planning and conducting outbound firearms smuggling operations. In
December 2008, the BVIC also co-authored a strategic-level analysis for the ICE and DHS
leadership on the same issue.

142

ICE, BVIC Fact Sheet, June 2008.

Congressional Research Service

30

The Department of Homeland Security Intelligence Enterprise

Border Enforcement Security Task Forces (BEST)
The BEST initiative143 consists of a series of multi-agency investigative task forces, of which ICE
is the lead agency. They seek to identify, disrupt, and dismantle criminal organizations posing
significant threats to border security. Other agency participants include CBP, the Drug
Enforcement Administration (DEA), Bureau of Alcohol, Tobacco, and Firearms (ATF), FBI,
USCG, and the U.S. Attorney’s offices, and state and local law enforcement. The Mexican law
enforcement agency Secretaria de Seguridad Publica is a partner along the southern border. The
Royal Canadian Mounted Police and Canadian Border Services Agency are partners on the
northern border.
There are currently BEST task forces on both the northern and southwestern borders with ten on
the southwest border. Each BEST concentrates on the prevalent threat in their area. On the
southern border, this entails cross-border violence; weapons smuggling and trafficking; illegal
drug and other contraband smuggling; money laundering and bulk cash smuggling; and human
smuggling and trafficking. The Office of Intelligence maintains 28 analysts within the Southwest
Border BESTs to ensure responsive intelligence support and appropriate information sharing with
other federal, Government of Mexico, state, tribal and local law enforcement partners.144

Armas Cruzadas
Armas Cruzadas is a partnership between U.S. and Mexican law enforcement agencies. 145 Its
objective is to synchronize bilateral law enforcement and intelligence sharing operations in order
to identify, disrupt, and dismantle trans-border weapons smuggling networks. Among the
activities under Armas Cruzadas, ICE Border Liaisons are deployed to the border to strengthen
bilateral communication. There is also a Weapons Virtual Task Force, a virtual online community
where U.S. and Mexican investigators can share intelligence and communicate in a secure
environment.146
For the United States, ICE is a major participant agency in Armas Cruzadas because of its
authority as the Federal agency responsible for investigating cases involving weapons being
smuggled out of the United States. ATF participates as a result of its authority over weapons
being illegally sold and transported within the United States. CBP is also a participating agency
due to its border security responsibilities.

Operation Firewall
Operation Firewall is an initiative to combat bulk cash smuggling, one of the methods that
transnational criminal organizations use to move the proceeds from their criminal activities to
fund future operations. ICE has found that as successful enforcement has made the transfer of
illicit funds between banks and other financial institutions more difficult, criminal organizations
143

ICE, BEST Fact Sheet, Dec. 3, 2008.
ICE Briefing for CRS, Jan. 21, 2010.
145
ICE, Armas Cruzadas Fact Sheet, Nov. 12, 2008.
144

146

U.S. Congress, Senate Committee on Judiciary, Subcommittee on Crime and Drugs, Law Enforcement Responses to
Mexican Drug Cartels, Statement of Kumar C. Kibble, Deputy Director, ICE Office of Investigations, 111th Cong.,
Mar. 17, 2009.

Congressional Research Service

31

The Department of Homeland Security Intelligence Enterprise

are increasing their use of bulk cash smuggling. 147 Operation Firewall is a joint effort with CBP to
target the full array of methods used to smuggle bulk cash, including commercial and private
passenger vehicles, commercial airline shipments and passengers, and pedestrians crossing U.S.
borders with Mexico and Canada. 148

Collection Management and Requirements Division
The Collection Management and Requirements Division coordinates the intelligence collection
and reports efforts within ICE. In this regard, it works closely with other DHS and IC elements to
articulate ICE intelligence requirements to collection elements within the IC to ensure the flow of
needed information to ICE. This division also manages the ICE Joint Intelligence Operations
Center.
The Office of Intelligence also has two divisions which provide support activities, the Business
Management Division and the Executive Information and Technology Division. Business
Management provides support to daily operations throughout the homeland and overseas through
executing procurement, budget, logistics, and training functions.
The Executive Information and Technology Division provides information technology services
that support day to day operations, processing large quantities of information, and managing
secure communications s

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/crs%3AR40602. Public record. Not legal advice.
