BSE 206: Advanced OSINT for CI Assessment
How to read this course. BSE 206 (Advanced OSINT for CI Assessment) is written for the assessor team at the moment the work changes character. BSE 106 (Community Critical Infrastructure Research) taught you to walk a community with open eyes — to observe and report, at familiarization depth, behind a hard consent line. This course opens the methodology floor that BSE 106 deliberately left closed: the structured open-source research disciplines that turn observation into a defensible assessment input. You will learn to design a research question before you collect, to plan collection to the minimum the assessment requires, and to attach provenance and a confidence characterization to every finding you produce. You will run deep research on the Hardened Facility Framework’s families, primary -source analysis of the food system’s three legs, and lawful public-record research on Foreign Adversary Personnel (FAP). One rule governs every page: findings, not facts. An open-source research product states its findings with provenance and confidence attached; it never represents an open-source finding as verified ground truth. Its corollary governs every collection decision: minimum necessary collection — you gather what the assessment needs and nothing beyond it. And one boundary is load-bearing above all others: this course teaches research method and never targeting tradecraft. It names no site-access technique, builds no persona or pretext, teaches no counter-detection craft, and it holds the no-trespass line without exception — open-source means open sources, and the method never crosses from research into approach, contact, or entry. The capstone seats you with the assessor team for one working week compressed into an evening — scoping a research engagement, holding the bright lines under pressure, and assembling findings into a product the assessment can actually use.
Deep open-source research methods for hardened-facility and critical infrastructure assessment (Assessor Methodology band; hard prerequisites: the 099 -> 100 -> 101 -> 102 foundation chain, the Common Paid Core of BSE 104 and GOV 106/107/108, BSE 106 (Community Critical Infrastructure Research), and BSE 201 (FIR Resilience Framework) — per the Presidential ratification, both BSE 106 and BSE 201 are hard: this course presumes the familiarization base and the consent/no-trespass doctrine that BSE 106 established, and the assessment discipline BSE 201 certifies, because the research product this course teaches feeds that assessment). Written for the assessor team, the course opens the methodology floor that BSE 106 deliberately left closed: the structured open-source research disciplines that turn observation into a defensible assessment input — question design and collection planning, provenance and confidence characterization, deep research on the Hardened Facility Framework, primary-source analysis of the food system’s three legs, and Foreign Adversary Personnel (FAP) workforce research at lawful public-record depth. The governing doctrine is findings, not facts: an open-source research product states its findings with provenance and confidence attached and never represents an open-source finding as verified ground truth; its taught corollary is minimum necessary collection — the engagement collects what the assessment requires and nothing beyond it. The load-bearing boundary is ethics, operations security (OPSEC), and legal: the course teaches research method and never targeting tradecraft at any level — no site-access technique, no persona or pretext creation, no counter-detection craft — and it holds the no-trespass line absolutely (no physical access without written owner authorization, ever; open-source means open sources). It provides no legal advice; every legal question belongs to the counsel retained by the parties.
Before representing any research finding, facility profile, or workforce analysis to a third party, or releasing any research product that names facilities, personnel, or vulnerabilities — consult your own counsel. Open-source research on critical infrastructure sits adjacent to domains of law this course deliberately does not enter: computer-fraud and access statutes, privacy and data-protection law, and the access-restriction laws for critical infrastructure that vary by state. This course teaches open-source research as curriculum — what the method is, how a finding is sourced and characterized, what a research product asserts and what it cannot — and it teaches the discipline of staying on the lawful, remote, consent-bound side of every line. It provides no legal advice; it authorizes no physical access to any site; it teaches no technique whose function is defeating a facility’s security; and no passage in it substitutes for the judgment of the counsel retained by the parties in a real engagement. The no-trespass doctrine is absolute: no physical access without written owner authorization, ever.
