Homeland Security Intelligence: Perceptions, Statutory Definitions, and Approaches

Since the 9/11 terrorist attacks, Congress has focused considerable attention on how intelligence
is collected, analyzed, and disseminated in order to protect the homeland against terrorist threats.
Prior to 9/11, it was possible to make a distinction between “domestic intelligence”—primarily
law enforcement information collected within the United States—and “foreign intelligence”—
primarily military, political, and economic intelligence collected outside the country. Today,
threats to the homeland posed by terrorist groups are now national security threats. Intelligence
collected outside the United States is often very relevant to the threat environment inside the
United States and vice versa.
Although the activities involved in homeland security intelligence (HSINT) itself are not new, the
relative importance of state, local, and private sector stakeholders; the awareness of how law
enforcement information might protect national security; and the importance attached to
homeland security intelligence have all increased substantially since the events of 9/11.
There are numerous intelligence collection disciplines through which the U.S. Intelligence
Community (IC) collects intelligence to support informed national security decision-making at
the national level and the allocation of tactical military and law enforcement resources at the local
level. The collection disciplines are generally referred to as those which fall within national
technical means or non-technical means. Technical means include signals intelligence (SIGINT),
measurement and signatures intelligence (MASINT), and imagery intelligence (IMINT). Non-
technical means include human intelligence (HUMINT) and open source intelligence (OSINT).
Each of these collection disciplines is source-specific—that is, a technical platform or human
source, generally managed by an agency or mission manager, collects intelligence that is used for
national intelligence purposes.
HSINT, however, is generally not source specific, as it includes both national technical and non-
technical means of collection. For example, HSINT includes human intelligence collected by
federal border security personnel or state and local law enforcement officials, as well as SIGINT
collected by the National Security Agency. Reasonable individuals can differ, therefore, with
respect to the question of whether HSINT is another collection discipline, or whether homeland
security is simply another purpose for which the current set of collection disciplines is being
harnessed. Homeland security information, as statutorily defined, pertains directly to (1) terrorist
intentions and capabilities to attack people and infrastructure within the United States, and (2)
U.S. abilities to deter, prevent, and respond to potential terrorist attacks.
This report provides a potential conceptual model of how to frame HSINT, including geographic,
structural/statutory, and holistic approaches. Given that state, local, tribal, and private sector
officials play such an important role in HSINT, the holistic model, one not constrained by
geography or levels of government, strikes many as the most compelling. The report argues that
there is, in effect, a Homeland Security Intelligence Community (HSIC). Although the HSIC’s
members are diffused across the nation, they share a common counterterrorism interest. The
proliferation of intelligence and information fusion centers across the country indicate that state
and local leaders believe there is value to centralizing intelligence gathering and analysis in a
manner that assists them in preventing and responding to local manifestations of terrorist threats
to their people, infrastructure, and other assets. At the policy and operational levels, the
communication and integration of federal HSINT efforts with these state and local fusion centers
will likely remain an important priority and future challenge. This report will not be updated.

Since the 9/11 terrorist attacks, Congress has not only focused considerable attention on how
intelligence is collected, analyzed, and disseminated in order to protect the homeland against
terrorism, but also what should such intelligence encompass. A discussion of what constitutes
“homeland security intelligence” and how it nests within the broader intelligence discipline may
be useful background as Congress continues to examine a broad range of homeland security
Prior to 9/11, it was possible to make a distinction between “domestic intelligence”—primarily
law enforcement information collected within the United States—and “foreign intelligence”—
primarily military, political, and economic intelligence collected outside the country. Today, this
distinction is blurred. Threats to the homeland posed by terrorist groups are national security
threats, and intelligence collected outside the United States is often very relevant to the threat
environment inside the United States and vice versa.
The National Commission on Terrorist Attacks Upon the United States (hereafter the 9/11
Commission) stated that one of the challenges in preventing terrorist attacks is bridging the 2
“foreign-domestic divide.” The 9/11 Commission used this term for the divide that it found not
only within the Intelligence Community (IC), but also between the agencies of the IC dedicated to
the traditional foreign intelligence mission, and those agencies responsible for the homeland
security intelligence (HSINT) and law enforcement missions. Some might categorize security 3
intelligence and law enforcement (criminal) intelligence as “non-traditional” intelligence. Yet,
the scope and composition of this non-traditional or homeland security intelligence remains
somewhat nebulous.

At the broadest level, there is a plethora of definitions for intelligence.4 Most explain the various
types of clandestine intelligence, the methods of intelligence collection (the “-Ints”), intelligence 5
consumers, the purposes for which intelligence is collected, and the intelligence cycle. 67
Traditional intelligence collection done clandestinely and overtly, largely at the federal level, to
inform national-level policymakers is often differentiated from criminal intelligence gathered by a
broader set of federal, state, and local actors generally for law enforcement purposes. Some argue
that given that the end result in a criminal case is successful prosecution, that criminal
intelligence gathering is largely reactive—a crime takes place, and “intelligence” or evidence is
collected to support a prosecution. However, intelligence gathering can also be used to advance
the causes of national security, as state and local law enforcement agencies can be viewed as the 8
nation’s counterterrorism “eyes and ears.” Arguably, not all criminal intelligence gathering is
reactive, as some law enforcement organizations and intelligence fusion centers use proactive
intelligence gathering techniques, such as the recruitment of human assets, to prevent terrorist
The terms domestic intelligence and homeland security intelligence are often used colloquially
and interchangeably by some observers. Depending on how one defines “homeland security,” this
may be understandable. If, however, one bounds the activities associated with intelligence
geographically, a systemic malady which was at least a proximate cause of the intelligence failure
resulting in the terrorist attacks of September 11, 2001, the two terms are inherently distinct. That
is, domestic intelligence could be defined as that which is collected, analyzed, and disseminated
within the United States; yet, homeland security intelligence may be much more broadly defined

without regard to the geographic origin of the intelligence collected. The rationale for the
integration of what is traditionally defined as foreign intelligence with that which is thought of as
domestic intelligence is concisely stated by former Director of National Intelligence (DNI) 9
Ambassador John Negroponte: “What happens abroad can kill us at home.”
One of the broadest definitions of intelligence is that “intelligence is knowledge, organization, 10
and activity.” Arguably, one of the most meaningful purposes of intelligence is “to establish 11
where the danger lies.” Some would argue based on this definition that “intelligence is
intelligence”—that is, differentiating traditional from non-traditional intelligence is a theoretical
matter which may have little relation to the end result—protecting national security. This
argument might continue that threats to U.S. national security by and large originate overseas and,
since its formal and statutory inception in 1947, the U.S. Intelligence Community has always
been the first line of defense in identifying and understanding these threats. Although compelling,
this argument could lead some observers to conclude that the state, local, and private sector
intelligence players are simply “bolt on” modules to the existing federal community. Such a status
quo plus model could be interpreted by some to mean that state, local, and private sector entities
are new and passive consumers of federally gathered and analyzed intelligence products, yet not
necessarily full intelligence cycle partners. This may not necessarily be the case, as state, local,
and private sector organizations have taken on a more activist and proactive role in protecting
their populations and infrastructure, a role that includes collecting their own intelligence while
working with federal law enforcement and IC partners stationed in Washington, DC, and within 12
their respective districts.
The “intelligence is intelligence” position might beg the question of what is the most appropriate
strategy for homeland security intelligence—a “top-down” federally driven model where the
traditional “Ints” are dominant, a “bottom-up” state, local, and private sector model where the
thousands of state and local law enforcement intelligence collectors are dominant, or some unique
partnership that strikes a balance between these two extreme models? To some extent, HSINT
may be perceived by some as a federally led “top-down” model through which the federal
government’s intelligence entities provide raw intelligence and/or finished terrorism threat
assessments to state, local, and tribal law enforcement entities which may make independent
determinations of whether the intelligence is actionable. Another alternative is a “bottom up”

model through which criminal intelligence,13 of the type collected long before the events of
September 11, 2001, provides an assessment of the local environments in which a national
security and/or a criminal threat might become a reality. A third model, among others, might
envision a less hierarchical or a more decentralized structure in which roles and responsibilities of
federal, state, and local players are more clearly delineated, information shared more widely, and
coordination between law enforcement and traditional intelligence actors closer. These models
will be highlighted below.
Some perceptions of HSINT among leaders in the IC and observers of the intelligence process are

Leaders within the Intelligence and Homeland Security communities often speak openly about the
responsibilities, priorities, accomplishments, and challenges their agencies face. The nation’s first
DNI, Ambassador John Negroponte, stated that the Intelligence Community has tasked itself with 14
“bolstering intelligence support for homeland security as enterprise objective number one.” He
spoke of this priority within the context of the DNI’s mandate resulting from the Intelligence
Reform and Terrorism Prevention Act of 2004 (IRTPA) to “integrate the foreign, military and
domestic dimensions of the United States intelligence into a unified enterprise” and “connecting 15
the dots across the foreign-domestic divide.” At the aggregate level, even if it is assumed that
there is one unified intelligence discipline, according to Ambassador Negroponte, there are three 16
different dimensions of intelligence—foreign, military, and domestic. Under this school of
thought, HSINT could become another dimension of intelligence that is distinct in some manners,
yet overlaps with the aforementioned dimensions. At a relatively simplistic level, the relationships
among the dimensions of intelligence could be depicted according to Figure 1 below.

Figure 1. Dimensions of Intelligence
Although each of the dimensions of intelligence (referred to above) could be further subdivided,
the domestic intelligence dimension, under a broad understanding of the term, would include the
role state, local, tribal, and private sector entities play in collecting, analyzing, and disseminating
information and intelligence within their respective areas of jurisdiction or industries. DNI
Negroponte has defined the domestic agenda as “institution building and information sharing 17
without damaging the fabric and values of our political culture.” With respect to institution
building, the approach remains federal-centric. Ambassador Negroponte referred specifically to
the refinement of the FBI’s National Security Branch, the further development of the National
Counterterrorism Center (NCTC), as well as the development of the DHS Office of Intelligence
and Analysis. State governments, local law enforcement, the private sector, and tribal entities
were mentioned at a procedural level—that is, in the sense of “facilitating these multidirectional 18
flow of information.”
Former Secretary of Homeland Security Michael Chertoff provided his insights into and thoughts st
about defining the scope of HSINT. Using the metaphor of intelligence as the “radar of the 21
century” to provide early warning of terrorist attacks, he stated,
Intelligence, as you know, is not only about spies and satellites. Intelligence is about the
thousands and thousands of routine, everyday observations and activities. Surveillance,
interactionseach of which may be taken in isolation as not a particularly meaningful piece
of information, but when fused together, gives us a sense of the patterns and the flow that
really is at the core of what intelligence analysis is all about ... . We (DHS) actually generate
a lot of intelligence ... we have many interactions every day, every hour at the border, on 19
airplanes, and with the Coast Guard.

Some observers have characterized domestic intelligence in the following manner:
Domestic intelligence entails the range of activities focused on protecting the United States
from threats mostly of foreign origin. Focused narrowly, it includes the FBIs
counterterrorism work with local law enforcement. On a much broader scale, however, it
also involves a broader set of intelligence activities overseen by the Director of National
Intelligence, the secretary of defense, the attorney general, and the secretary of homeland
security. The goal is to integrate federal, state and local governments, and, when appropriate,
the private sector on a secure collaborative network to stop our enemies before they act.
Those enemies include individuals and groups attempting to transport weapons of mass
destruction, international terrorists, organized criminals, narcotics traffickers, and countries 20
that are working alone or in combination against U.S. interests.
Another observer has defined “domestic national security intelligence” as
intelligence concerning the threat of major, politically motivated violence, or equal grievous
harm to national security or the economy, inflicted within the nations territorial limits by
international terrorists, homegrown terrorists, or spies of saboteurs employed or financed by 21
foreign nations.
According to Dr. Sherman Kent, security intelligence is defined as
the intelligence behind the police function. Its job is to protect the nation and its members
from malefactors who are working to our national and individual hurt. In one of its most
dramatic forms it is the intelligence which continuously is trying to put the finger on
clandestine agents sent here by foreign powers. In another, it is the activity which protects
our frontiers against other undesirable gatecrashers: illegal entrants, smugglers, dope runners,
and so on... By and large, security intelligence is the knowledge and the activity which our
defensive police forces must have before they take specific action against the individual ill-22
wisher or ill-doer.
Some of the similarities between these perceptions include (1) a fundamental belief that 23
intelligence is the first line of defense for the nation, (2) threats to U.S. national security are
largely, although not solely, of foreign origin, and (3) there is a national intelligence role for non-
traditional players (largely state, local, tribal law enforcement, as well as the private sector), a role
in which they make contributions to preventing terrorist attacks or other inimical acts directed
against U.S. citizens within the United States. Others, however, may account for the difference in
these perceptions as being associated with the explicit roles and responsibilities that these non-
traditional entities play. Are these entities solely recipients of federally collected raw and finished
intelligence products? At a policy and, importantly, local level, are non-traditional players viewed
by federal personnel as equal partners, and/or “force multipliers?” At the federal level, what

policies and mechanisms are in place to provide those non-traditional entities with feedback on
the intelligence they collect and provide to the federal government?
Although the breadth of these questions is beyond the scope of this report, it may be illustrative to
view HSINT through the eyes of national strategy.

According to the DNI’s National Intelligence Strategy of the United States of America:
Transformation Through Integration and Innovation, one of the basic objectives is to “build an
integrated intelligence capability to address threats to the homeland, consistent with U.S. laws 24
and the protection of privacy and civil liberties.”
The strategy stipulates that the nature of the transnational threats to the United States “force us to
rethink the way we conduct intelligence collection at home and its relationship with traditional
intelligence methods abroad.” Moreover, the strategy states that
U.S. intelligence elements must focus their capabilities to ensure that (1) Intelligence
elements in the Departments of Justice and Homeland Security are properly resourced and
closely integrated within the larger Intelligence Community, (2) all Intelligence Community
components assist in facilitating the integration of collection and analysis against terrorists,
weapons of mass destruction, and other threats to the homeland, and (3) state, local, and
tribal entities and the private sector are connected to our homeland security and intelligence 25
Any national strategy, one could argue, by definition focuses on and provides direction to only
those agencies that the federal government controls. A broader reach and/or direction to entities
beyond this purview might run the risk of presupposing that the affected community(ies) agree
with the national strategy and/or have the resources to implement such direction. Therefore, it
may be appropriate that the National Intelligence Strategy, while recognizing a homeland security
intelligence role for state, local, and tribal entities, as well as the private sector, does so only in a
general manner that does not stipulate the activities these communities will implement as part of
the broader community of entities working to protect U.S. national security.
It could also be argued, that while the National Intelligence Strategy calls for state, local, and
tribal entities to be “connected to our homeland security and intelligence efforts,” it nevertheless
envisions homeland security intelligence as being driven, in large part, by the federal entities
most associated with the domestic intelligence mission—that is, the activities undertaken by the
intelligence elements of the Departments of Justice and Homeland Security. How the term
“connected” is defined becomes of critical importance, as it implies communication and the
sharing of information among federal, state, and local intelligence officials.

The National Strategy for Homeland Security published in October 2007, is more explicit about
the role of state, local, tribal, and even private sector elements. It stresses that homeland security 26
is a shared responsibility. Consistent with this theme, the strategy highlights the importance of
collaboration in the realm of homeland security intelligence. It characterizes the process of
identifying, locating, and uncovering terrorist activity—the core objective of homeland security
intelligence—as multifaceted. The strategy specifies the ways government at all levels and the
private sector need to contribute to the homeland security effort. It also notes the importance of
an “integrated Information Sharing Environment that supports the vertical and horizontal 27
distribution of terrorism-related information.... ”
The sharing of homeland security intelligence has been a particular priority for the Congress,
which directed the establishment of the Information Sharing Environment in the IRTPA. Later, in
the Implementing Recommendations of the 9/11 Commission Act of 2007 (9/11 Act), Congress 28
directed DHS to undertake additional initiatives, including the following:
• Establish department-wide procedures for review and analysis of information
provided by state, local, tribal, and private sector elements; integrate that
information into DHS intelligence products, and disseminate to federal partners
within the IC.
• Evaluate how DHS components are utilizing homeland security information and
participating in the Information Sharing Environment.
• Establish a DHS State, Local, and Regional Fusion Center Initiative to establish
partnerships with state, local, and regional fusion centers.
• Coordinate and oversee the creation of an Interagency Threat Assessment and
Coordination Group (ITACG) that will bring state, local, and tribal law
enforcement and intelligence analysts to work in the National Counterterrorism

The DHS intelligence strategy has four main elements: (1) vision, (2) mission, (3) definitions, and 29
(4) goals and objectives. While the strategy does not specifically define HSINT, it provides a
vision for the DHS intelligence enterprise as being “an integrated ... enterprise that provides a 30
decisive information advantage to the guardians of our homeland security.” According to the
strategy, the mission of the DHS intelligence enterprise is to
provide valuable, actionable intelligence and intelligence-related information for and among
the National leadership, all components of DHS, our federal partners, state, local, territorial,
tribal, and private sector customers. We ensure that information is gathered from all relevant
DHS field operations and is fused with information from other members of the Intelligence

Community to produce accurate, timely, and actionable intelligence products and services.
We independently collate, analyze, coordinate, disseminate, and manage threat information 31
affecting the homeland.
Implicit in this strategy is the DHS adoption of the definition of homeland security information
outlined in the Homeland Security Act of 2002.

Homeland security intelligence is not a term that is as yet defined or codified in law.32 The term
and activities associated with it include—and go beyond—the definitions of the two traditional
types of intelligence commonly defined in law and executive orders: foreign intelligence and
counterintelligence. And, more recently, definitions of these two types of intelligence have been
supplemented by the terms “national intelligence” and “intelligence related to national security.”
As with most intelligence-related terms, individuals attach their own interpretations and
perceptions to HSINT. While there may be some commonly held perceptions about how HSINT
is defined, it is also possible that individuals use the terms freely, but without a true common
understanding of the scope and breadth of activities that may be consistent with homeland
security intelligence. The primary statutory definition that applies is that which appears in the
Homeland Security Act of 2002, which defines homeland security information as
any information possessed by a federal, state, or local agency that (a) related to the threat of
terrorist activity, (b) relates to the ability to prevent, interdict or disrupt terrorist activity, (c)
would improve the identification or investigation of a suspected terrorist or terrorist 33
organization; or (d) would improve the response to a terrorist act.

The DHS Office of Intelligence and Analysis has adopted this definition of homeland security 34
information. It is worthwhile to note that although DHS remains an organization designed to
protect against “all hazards,” the focus of homeland security information, at least as defined in
law, is counterterrorism. As illustrated below, HSINT can be more broadly interpreted to involve
intelligence designed to protect against the inimical activities of narcotics traffickers, organized
criminals, and others having international support networks and seeking to engage in activities
that could undermine U.S. national security.
Another type of intelligence defined in statute is traditional or foreign intelligence, which means
[i]nformation relating to the capabilities, intentions, and activities of foreign governments or 35
elements thereof, foreign organizations, or foreign persons, or international terrorism activities.
The methods of traditional foreign intelligence collection fall into the following five areas:
imagery intelligence (IMINT), signals intelligence (SIGINT), human intelligence (HUMINT), 36
measurement and signatures intelligence (MASINT), and open source intelligence (OSINT).
While the meanings of these disciplines are relatively well known and commonly understood
among intelligence professionals, HSINT is more nebulous. Because HSINT is not necessarily
source-specific, some would question whether it should be referred to as a collection “discipline.”
Although it is true that numerous unique entities are within DHS and at the state and local
government levels, as well as within the private sector, that are aggressively collecting homeland
security information, it is also true that many of the traditional aforementioned “INTs” collect
homeland security intelligence insofar as they provide information on terrorism threats that may
originate globally, yet are potentially manifested within U.S. borders. Within DHS Intelligence 373839
itself, the OSINT and HUMINT collection methods are likely to be most prevalent.
The other type of intelligence codified in law is counterintelligence, which is defined as
Information gathered and activities conducted to protect against espionage, other intelligence
activities, sabotage, or assassinations conducted for by or on behalf of foreign governments

or elements thereof, foreign organizations, or foreign persons, or international terrorist 40
With respect to counterintelligence, DHS Intelligence has as one of its objectives to “consistent
with legal authorities, establish measures to protect the Department against hostile intelligence
and operational activities conducted by or on behalf of foreign powers or international terrorist 41
activities.” To some extent, however, at least for semantics if not necessarily for jurisdictional
purposes, the differences between foreign intelligence and counterintelligence were attenuated
with the passage of the Intelligence Reform and Terrorism Prevention Act of 2004 (P.L. 108-458).
The IRTPA sought to remedy numerous problems uncovered by the 9/11 Commission, one of
which was the aforementioned gap between foreign and domestic intelligence. The IRTPA
amended the National Security Act of 1947 (50 U.S.C. §401a) to read,
The terms national intelligence’ andintelligence related to national security refer to all
intelligence, regardless of source from which derived and including information gathered
within or outside the United States that (a) pertains, as determined consistent with any
guidance issued by the President, to more than one United States Government agency; and
(b) that involves - (I) threats to the United States, its people, property, or interests; (ii) the
development, proliferation, or use of weapons of mass destruction; or (iii) any other matter 42
bearing on U.S. national or homeland security.
As such, HSINT could be interpreted as synonymous with intelligence related to national security,
or some subset thereof.
A framework for outlining the scope of HSINT, or at least the criteria by which it might be
framed could prove helpful. While there are numerous approaches to framing homeland security
intelligence, three possible approaches are discussed below.

There are at least three different constructs that could be used to frame HSINT: (1) geographic (2)
structural, and (3) holistic. Table 1 summarizes some of the limits and boundaries of these three
possible approaches to framing HSINT. Beyond geographic bounds, another set of differentiating
factors between these approaches is the extent to which, if at all, one believes homeland security
intelligence is the sole purview of the federal government, or a more inclusive and cooperative
federal, state, local, tribal, and private sector model.

Table 1. Approaches to Defining Homeland Security
Approach Geographic Bounds Government Level Bounds
Geographic Yes No
Structural/Statutory No Yes
Holistic No No
Homeland security intelligence can be viewed, some might argue rather simplistically, in
geographic and federal/state/local government terms. That is, if the intelligence collection activity
takes place within the United States—whether it be by a federal agency or a state, local, tribal, or
private sector actor, it would be considered HSINT. Under this approach, while HSINT’s
activities are constrained by borders, the yield from homeland security’s collection and analysis
could be combined with foreign intelligence to develop a more complete picture of homeland
security threats. Others might counter that the problem with this type of approach is that, as the
events of September 11, 2001, demonstrated clearly, national borders increasingly have little
meaning in determining threats to U.S. national and homeland security. As has been well 43
documented by numerous studies, the planning for the events of 9/11 took place largely
overseas, but the acts were executed within U.S. borders. An intelligence approach that
considered only activities associated with homegrown threats, without a more integrated, global
perspective on the threat, would miss one of the central lessons learned from 9/11—the
importance of integrating intelligence related to threats to national security regardless of the
geographic location of the source.
Homeland security intelligence could be viewed as primarily a federal activity. Geography is not
as important under this approach, as the federal entities that engage in homeland security
intelligence may, directly or indirectly, collect information outside the United States. For
example, the FBI, through its Legal Attaché (LEGAT) program, has 75 LEGAT offices and sub-44
offices providing coverage for over 200 countries, islands, and territories. Through these offices,
it collects principally criminal information through open liaison with international law
enforcement counterparts. More specifically, under this approach, HSINT is a federal activity that
is engaged in by certain statutory members of the Intelligence Community. Thus, of the 16
agencies that are statutory members of the IC, under this approach perhaps only four would 45
engage in domestic intelligence activities—the intelligence elements of the FBI; DHS I&A and

the modus operandi of individuals or groups that threaten U.S. national security. As defined by the 9/11 Commission,
the role of strategic (counterterrorism) analysis is to “look across individual operations and cases to identify trends in
terrorist activity and develop broad assessments of the terrorist threat to U.S. interests.” See “Law Enforcement,
Counterterrorism, and Intelligence Collection in the United States Prior to 9/11,” Staff Statement No. 9, p. 8. Although
strategic analysis can be highly useful to operational personnel, its intended consumer set includes, but is not limited to,
national-level policy and decision makers. Tactical analysis, on the other hand, is generally thought of as analysis
which provides direct support to an ongoing intelligence operation or investigation. Tactical and strategic intelligence
analyses are mutually supportive.
47 Pursuant to Homeland Security Presidential Directive (HSPD) 5, Management of Domestic Incidents, the Secretary
of Homeland Security is theprincipal federal official for domestic incident management.” The Secretary of Homeland
Securityshall coordinate the federal government’s resources utilized in response to or recovery from terrorist attacks,
major disasters, or other emergencies.” Part of such coordination is the management of information or intelligence
sharing both within the federal government and between level of governments, as well as the private sector. The
management of information in the aftermath of Hurricane Katrina was criticized. The 9/11 Public Discourse Project
assigned a grade of “C” for the government’s effort to establish a unified incident command system. The report
concluded that, “although there is awareness of and some training in the Incident Command System (ICS), Hurricane
Katrina demonstrated the absence of full compliance during a multi-jurisdictional/statewide catastropheand its
resulting costs.” See Final Report of 9/11 Commission Recommendations, Dec. 5, 2005, p. 1.

Although information sharing between levels of government is widely held to be an undisputable 4849
public “good,” achieving effective levels of information exchange is a challenging goal. As
former Vice Chair of the 9/11 Commission, Lee H. Hamilton, stated: “You can change the law,
you can change the technology, but you still need to change the culture; you need to motivate 50
institutions and individuals to share information.” Administration officials have recognized
these challenges. Ambassador Thomas E. McNamara, the Program Manager for the Information 51
Sharing Environment (ISE), testified that “the breadth and complexity of the information
sharing challenge should not be underestimated. Information silos, cultural issues, and other 52
barriers that inhibit sharing still exist today.”
Under the holistic approach, the HSINT community might include the 16 statutory members of
the IC (as each collects national intelligence, or intelligence related to national security which
could have a profound impact on homeland security); the National Counterterrorism Center,
National Counterintelligence Center, National Counter Proliferation Center, and the Open Source
Intelligence Center; the 14 existing private sector Information Sharing and Analysis Centers 53
(ISACS), scores of state and local law enforcement entities charged with gathering criminal 54
intelligence, numerous state and regional “intelligence fusion” centers, and federal entities with
law enforcement responsibilities which may collect intelligence related to national security. This
holistic approach implies an interdependency between the diverse players of the statutory IC and
the broader HSINT Community. As Ambassador Henry A. Crumpton, a former CIA case officer

and former Special Coordinator for Counterterrorism at the State Department states, although
there are differences between intelligence and law enforcement,
the primary customer for domestic foreign intelligence on near-term threats is law
enforcement. And law enforcement can provide valuable leads for intelligence officers. The
intelligence collector and the law enforcement consumer, therefore, must strive for more than 55
information sharing; they must seek interdependence.
Calls for interdependence between foreign intelligence and security or criminal intelligence today
mirror those made nearly thirty years ago by Dr. Kent, who wrote
The real picture of the diversity in kinds of intelligence... lies in this truth: a very great many
of the arbitrarily defined branches of intelligence are interdependent. Each may have its well-
defined primary target which it makes its primary concern, but both the pursuit of this target
and the byproducts of pursuing it bring most of the independent branches into some sort of
relationship with the others. Intelligence as an activity is at its best when this fact is realized 56
and acted upon in good faith.
The challenge, then as now, is to implement such a vision where all players in the de facto HSINT
Community would be treated as partners with value to add. What has changed substantially since
Dr. Kent’s seminal work is the addition of state, local, and private sector actors as both producers
and consumers of intelligence. It is here—in the interaction with these relatively new players—
that the DHS Intelligence Enterprise has a great role to play. The clear elucidation of HSINT role
and responsibilities and implementation, particularly between the FBI and DHS Intelligence,
remains an evolving process. A broader understanding of the members and functions of the
HSINT Community and the DHS members of the community may be helpful in assessment of
these matters.

The Intelligence Community (IC) is defined in law, yet the homeland security intelligence
community (HSIC) remains a somewhat nebulous entity. As defined by the DHS Intelligence
Enterprise Strategic Plan, the HSIC “includes the organizations of the stakeholder community 57
that have intelligence elements.” The Homeland Security Stakeholder Community is defined
broadly as

all levels of government, the Intelligence, Defense, and Law Enforcement Communities,
private sector critical infrastructure operators, and those responsible for securing the borders, 58
protecting transportation, and maritime systems, and guarding the security of the homeland.
Notwithstanding the fact that a HSIC is not statutorily defined, and may not necessarily be a
useful construct from a managerial perspective, such a community, as traditionally defined, exists.
The members and collective responsibilities of this community depend, to some extent, on how
one bounds the function of HSINT. As mentioned above, the broader the definition of HSINT, the
wider the range of players in the community. If one adopts the holistic model of HSINT, the HSIC
would include a broad range of agencies, many of which are hybrid agencies undertaking
homeland security, law enforcement, defense, and/or traditional foreign intelligence functions.
These entities include, among others, the intelligence elements of the Department of Defense 59
(DOD) U.S. Northern Command (USNORTHCOM), and Counterintelligence Field Activity; the
Department of Justice’s Federal Bureau of Investigation; Bureau of Alcohol, Tobacco, Firearms,
and Explosives; and Drug Enforcement Administration; the Department of Treasury’s Office of
Terrorism and Financial Intelligence, and the Department of Energy’s (DOE) Office of 60
Intelligence and Counterintelligence. Numerous state and local law enforcement entities, and
the state and regional intelligence fusion centers, would fall under a broad interpretation of
homeland security intelligence. Finally, the private sector, particularly those sectors outlined as
being part of U.S. critical infrastructure (as defined under HSPD-7) would also fall into a broadly
defined concept of a homeland intelligence community.
An interesting comparison can be drawn between the HSIC and the statutory IC, as defined in the
National Security Act of 1947, as amended, and in subsequent Executive Orders. One general
definition of the IC is a “federation of Executive Branch agencies and organizations that conduct
intelligence activities necessary for the conduct of foreign relations and protection of national 61
security.” A federation differs from a community insofar as the constituent elements of a
federation, by definition, give up some degree of authority to a more central body. A community,
by contrast, implies a group of persons or entities merely having common interests, but not
necessarily bound together by any formal power sharing arrangements or agreements. While the
IC has arguably moved more in the direction of a federation with the establishment of a Director 62
of National Intelligence (DNI), one could argue the HSIC, broadly defined, remains very much
a community spread across federal, state, local government sectors, as well as the private sector.
The diffuse nature of a broadly defined HSIC may be dictated by the very nature of the function
itself. That is, if state, local, tribal and private sector members are valued and contributing

members of the HSIC, an attempt at centralization may undermine the community’s effectiveness
and efficiency. Planned decentralization, with a clear understanding of the roles played by each
level of organization, and the parameters of how information is shared bi-directionally, is one 63
model of organization for the HSIC.
