NISPOM Central-Working with National Industrial Security Program
Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.
NISPOM Central-Working with National Industrial Security Program
Training, inspections and other cleared contractor requirements
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Free security clearance seminare
https://www.redbikepublishing.com/securityclearanceseminar/
NISPOM Fundamentals https://www.bennettinstitute.com
Stay tuned for more information about our upcoming book. In the meantime, if you need to provide Insider Threat Training, you can download and present your very own to your employees
NISPOM requires Derivative Classification Training and Record keeping Guidance. This guidance states that the cleared contractor provide cleared personnel with initial Derivative Classification Training and follow up and at least once every 2 years.
No time to write training?You can find training here https://www.redbikepublishing.com/derivative/
See more in our books "Insider's Guide to Security Clearances" and "How to get U.S. Government Contracts and Classified Work
visit https://www.redbikepublishing.com/fso-consulting/
Providing security clearance books, training, and resources for cleared defense contractors.
Clearance, NISPOM, and FSO Consulting
Thrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
FSO Consulting:
https://thriveanalysis.com
NISPOM Compliance
https://www.nispomcentral.com
https://www.nispom.com
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
- Prepared commercial organizations for defense contracting and NISPOM compliance
- Designed ready to implement security programs before, during and after facility clearance award
- Rescued high risk security programs with quick turnaround; usually within 30 days
- Achieved Commendable and Superior DCSA review ratings
- Developed compliant FOCI mitigation programs
Welcome to DOD Secure, and I'm your host, Jeff Bennett. Well, thanks so much for joining us. I decided to put the applause track back in because it was so much fun, and I hope you don't find it annoying. I hope it pumps you up for a very important discussion that we're going to have in this podcast. Alright, today's training or today's podcast is uh about NISPPOM training. Again, NISPPOM is a National Industrial Security Program operating manual. And um, what we'll be discussing today is a topic is called to how to prepare for the Defense Counterintelligence and Security Agency Review. And we'll also talk about NISPPOM mandated security training. So what kind of training would you have to undertake if you are a clear defense contractor company or person? This training is coming out of and in reference to some other training that we've or this podcast, I'm sorry, is is reference to some training that we are putting together. Um you might already know that we have a course called NISPPOM Fundamentals or Fundamentals of NISPPOM. And this course is this course that's currently up is with the NISPPOM, the 2016 version with change to. That was the latest version before the NISPPOM got changed over to something called the 32 Code of Federal Regulations Part 117. You might remember from an earlier podcast that I described it as having the government or DOD having two NISPPOMs in their hand, and they looked at both of them and said, Huh, they're both redundant. Let's pick one. So they settled on the 32 CFR, even though the whole world was using the other version of NISPPOM called the Department of Defense Manual 5250. Don't know why they chose one or the other, or why they chose the one nobody was using, but as a result, um things are being rewritten, and in our in our case, our customers have asked us to redo the training to reflect the 32 CFR. Even though CDSE or Defense Counter Intelligence and Security Agency, their training site still refers to the old NISPOM and still refers to DCSA as the DC DSS. So other folks have not updated their training just yet. We are on the cutting edge and we are updating your training just for you. But as a bonus for those who already have the training, we're gonna add the 32 CFR to the DODM training. That way you get 16 hours of training that you can potentially request to have. So even though other people have not updated their training, we are doing that now just for you. So we should be done within the next 30, 40 days. The training has been developed, and now I am recording it. And I'll let you know when it is done. In the meantime, I will have a link to that training in our show notes, and you can go there and start accessing it immediately. Again, not much is changing out of the requirements. Alright, so on to our podcast discussion. So for you defense contractors or those of you who do not know it, when you become a clear defense contractor, that means that you have been entrusted to handle U.S. government information that is classified at the confidential, secret, or top secret level. There are other levels or other variations of classifications and security clearances. When you get a security clearance, that paired with a need-to-know, such as a contract need or a specific work need, you can have access to that classified information. The government provides that classified information to contractors so that the contractor can produce goods and services, as we've discussed before. The NISP is a national industrial security program. That is instructions from the U.S. government on how to protect classified information. So where the government program office may have required contractors to provide goods and services on a contract, the government contracting activity oversees that work. However, the oversight of the classified work is under a cognizant security agency or office. And for the DOD and several other agencies, that is the Defense County Intelligence and Security Agency. So what this means is instead of the government contracting activity going to contractors to see how well they are protecting classified information, this third-party government organization called DCSA does that. And so the DCSA does reviews of cleared contractors to determine how they are protecting classified information. And they do that using the NISPPOM as guidance. Or rather, they grade the contractor's ability to protect classified information according to NISPOM guidance. I'm sorry, there is something called that gets inspected called derivative classification training and record keeping guidance. So this guidance states that the cleared contractor should provide their employees, their cleared employees, with initial derivative classification training and follow that training at least every two years. Now the training topics are vital to the cleared contractor performing on their classified contracts. No training, they should not be able to perform on it. So these properly trained employees reduce the risk of unauthorized disclosure of classified information. Well, how do they do that? Well, you might remember that only the government can classify can provide a classification level or classification guidance for U.S. government work that is provided for the US government or by the U.S. government. So they assign the classification level. Defense contractors cannot provide original classification. The only thing they can do is receive this classify information or classification guidance from the government who provides that original classification. And then they, the contractor, can provide derivative classification. In other words, if I give, if I'm the government and I provide a document that's at the secret level, the contractor can use that secret level document to do research and write other documents. And whatever comes out of that research is at the classification level of so they will classify that derivative document, that document deriving from the riv original, at the level of that original document. In this case, that would be secret. So the contractor should go through training on how to do that. And that training will enable them to understand what the classification levels are, how to properly mark that derived document, and ensure that it is protected where it is or how whenever it's transported or transmitted. Okay, currently the training can be put in place at a at the contractor's initiative. Anywhere that they are having or anywhere that they're organized, they can provide that training. The sooner the training is given, the better. Now remember, if the cleared employees are not trained, they're not authorized to perform unclassified work. So right now that would mean that a cleared defense contractor would not only need to provide that classified information, but document it because it will be an inspectable item. Prove to me, I'm DCSA, prove to me that you are providing derivative classification training. So failure to protect classified information is in itself a security violation. So many security violations are often caused by mismarked materials arising from poor derivative classification practices. So for example, you might be reviewing the requirements, the security requirements from a DD Form 254 or a statement of work, and then the DCSA representative discovers that derivative classification work has been occurring since the award of the contract a year prior. However, they might come through and look at training records and see that those training records indicate that derivative classification markings have only been conducted in the last two weeks. Guess what happened? The clear defense contractor forgot to do the training, and then now they're preparing last minute for the inspection. So it wouldn't be impossible to deduce that there may be a possible security violation because these employees had not been trained and they may have been conducting derivative classification and not knowing how to properly do so. So, how can you prepare to meet the challenge of derivative classified training? Well, the cleared contractors can refer to NISPOM and develop their own training based on the directed subject matter. So document that training and schedule follow-up training in two years. A good practice is to provide a copy of the training with training signatures or certificates and a date of that so that DCSA can go through and say, okay, this person was trained on this day. This was within the two-year window, so they are good to go. That way they can determine who has trained and whether or not the derivative classification training conformed to that NISPOM. So, no time to write the training. I'll put a link here where you can download that derivative classification training and complete with a certificate that you can provide to DCSA on their next audit. So, those of you who may not be familiar with what the declassific derivative classification is, it simply means the incorporation or the paraphrasing or restating or regenerating in new form information that was already classified and marking the newly developed material consistent with the original classification marking. I tried to give an example earlier, but this time I just wanted to give you an example. So an example of what derivative classification is not, simply duplicating or reproducing an existing classification an existing classified document is not derivative classification. You've got to make a new product for it to do so. So in derivative classifier training, you would want to train how to mark these classified documents, you know, where to put the markings, and this includes overall marking, the top and bottom of each page, each paragraph, each picture, each graph. So all these need to be in that training. And there's so much more as described in the NISP bomb. At MathCraft, we believe security risks and lack of compliance are threats to a business and its people. We strive to provide our clients with the tools they need to stay compliant and prepare for the next generation of threats. With comprehensive training, support, and customer resources, we transform our clients into security professions with them to know how to defend their organizations and maintain comprehensive security programs. For more information or ways we can help you, visit mathcraft.com or call 703-729-9022. At MathCraft, we support the mission of FSOs, CSOs, and other security professions to stand at the front line of our nation's battle against foreign and domestic threats. And again, if you're interested in some of the MathCraft's products and services, check our show notes for a link to Math. Okay, now let's talk about training. Ms. Palm required training, and we'll talk about what that looks like. So I used to run a lot until I got tired of it. Now like three years later, I'm trying to get back into it. I want to be able to run like I used to, but it's not just it's just not there. And it's taken me a lot of time to get back to where I was. In fact, I used to have another podcast called Run in Mud, and uh it was about obstacle race training. I might get back to it one day, but it's not happening just yet. So as I go, my thoughts sometimes wonder as I start trying to get back to running. I used to do 40-50 miles a week. Now I'm doing two miles every once in a while. So as I go, my thoughts sometimes wander to adding more distance. However, to increase my stamina and speed, I have to add that distance. So I begin to add more cul-de-sacs and side roots to make my runs just a little bit longer. So at first my body responded to the request with, oh gosh, not another requirement. This run is perfectly just fine as it is. Let's not break stride, let's not do anything out of the ordinary. Well, anyway, my mind started rationalizing: if you ever want to get better, stronger, and faster, you'll have to accept more challenges. Now, sometimes the same thought is also the way we confront our day-to-day work. Now, this is something that may sound familiar where you are. In fact, it reminds me of some conversations I've had as an FSO with some of the people in our company. So you may have heard it before, where everyone declares not another security requirement. You're putting enough on us already. Well, as an FSO, you want to make the training effective, efficient, and relevant. So the annual security awareness training that should be considered part of doing business, a core competency. After all, the organization or the clear defense contractor enterprising is performing on a classified contract, and training is the expectation and not the exception. There are four or five, I can't remember off the top of my head, requirements in NISPOM for training. So there are ways to incorporate this training as a standard that makes it transparent to the cleared contractor facility or those in the organization. You know, train them without them being known that they're being without them knowing that they're being trained. So this makes the FSO's job easier as they will hear fewer sighs of exasperation. So the following suggestions incorporate training with the contract review requirements. So all you need to do is document the training with signatures. So as an example of exasperating training is when you get an employee that's been there 30 years and never left the company, and every year you're teaching them that there's three levels of classification: confidential secret and top secret. Well, they've heard that over the years, so why not step it up? I think the most relevant type of training you can do is work with that work with individual program managers or task managers in the organization. Find out what their jobs are, how they handle classified information, and develop training specific to their needs. For example, there's no need in telling people how to protect top secret information if they don't have a top secret contract. There's no need in training people how to process classified information on computers if they don't have a classified have a contractual requirement to do so, and perhaps they don't even have classified computing capabilities at all in their organization. So make the training relevant and practical. So all you need to do to do this is document the training with signatures, and first step is to gather the information that you need for this training. So for the training task, you'll need the contract documentation. So you want to look for the DD Form 254 that specifies the type of classified work that's going on in your organization. Again, that 254 tells you at what classification level you're working with and the protection requirements on that classified information, as well as where the classified work is to be performed. You also want the contract or the statement of work that says, hey, we want you guys to develop 50 classified widgets. We want you to conduct research on this classified topic. And so it gets into the specifics, and this will help you determine what kind of training as well as how do you enforce and need to know. The other one you can get good information from is the security classification guide. And this is produced by the government. That's the one that tells you what's classified and what situation it's classified in, and which situation it may not be classified in. That should be included as you build this training up. So you also want to get some government documentation. One is get a copy of the NISPPOM and find out appropriate to the organization what kind of security practices that you need. How to do a risk assessment, how to inspect your security program. You also want to get some industrial security letters that are put out by DCSA if they are put out. Another documentation you want to gather is enterprise documentation, the clear defense contractors, security policies and procedures, as well as policies and procedures from supporting and operational business units. So some other things you might want to look at as far as incorporating ideas for training is audit documents, certification documents, things that tell how work is being performed in that organization. Use the FSO, unless you perform on a classified contract, are probably just overseeing protection of classified information, but not well integrated into the program manager work. So why not recruit program managers or program personnel to assist with developing this training? So you can also form an interim protection team. This is where you are the FSO and you lead this team and you get everybody together, you know, cleared and poorly, employees on a given contract. Now these team members can provide input and their subject matter experts on that work that you may not be familiar with, and they can lead you through the technical details of how they are performing on this classified contract to produce the products and the services. And there may be some nuances that you are not aware of that can be incorporated into the training so they understand better what to do and how to protect it. They provide the situation and you provide the protection measures working together. So with the resources and subject matter experts available, create and lead this security training. This is a highly desired technique as it all contributes to understanding the requirements. Everyone, including the FSO, receives a training, but you also get to document the results such as the protection measures. And you can use these to develop that winning training session and as a refresher every year. So this classification training, you know, um security awareness is Required when the employee gets there, and every year after that. So, some things you want to do while you are creating this training, build in information that they need to know. For example, this is really important information. Hey everybody, I'm training you on your security requirements. These are the security requirements I'm going to train you on. And when you get done, hey everybody, I trained you on these security requirements. Please sign in date here. In addition, you want to tell them we are going to be inspected by DCSA. Please let them understand that this security training that I gave you was given to you on this date. Again, I want you to be aware that you are currently being trained according to the NISPPOM. Somebody will ask about this later. I don't mean to be totally obvious, but sometimes you do need to tell the cleared employees this information because I don't know how many times DCSA came out to audit and employees weren't aware that they had training, even though I saw them sitting there and they signed the paperwork themselves. So be obvious about the training and let them know why you're giving that training to them. Okay, so some other things that you can do is review the 254 with a cleared employees supporting that classified contract. Again, the 254 provides valuable information on how that classified contract is to be executed and how the classified materials that you're using or producing are to be protected. Ask questions and expect answers from the participants. Seek to clarify these requirements and offer some good security solutions. Alright, review the contract as well. This provides how work will be performed and to what standard. Now the employees get to discuss their plan of action in support of the contract, and you get to provide those protection measures to apply as they perform their work. That way there's no classify or any spillage or security violations. Okay. So you can also go to the security class guide and discuss impact to the program and the enterprise. So using these methods, you can they can be applied with input from the government and enterprise oversight requirements as well, and you will have a well-rounded security program or training to protect classified information. Instead of just seeing NISPOM training as another requirement, it will be part of the contract expectation. So the end result is the ability to remain in compliance while documenting training requirements, improved security posture, and value to cost performance and schedule. Such in-depth classified contract review clarifies roles and are viewed by cleared employees as value added. So I mentioned that I do have training and I'm putting this training together at Bennett Institute, but I also have at redbike publishing.com derivative classifier training as well as security awareness training and more as called out in NISPOM that you can download, modify if you need to, and present to your employees. If you want more ideas, you can get our book called How to Get U.S. Government Contracts and Classified Work. Again, these are posted on our show notes. Alright, I would like to tell you now, give you a special message from SEMS Software, S-I-M as a Mike S software. As Clear Defense contractors, you represent the backbone of innovation, the front line of our national security and protectors of all that belongs to you. SIMS Software is proud to be your ally in these endeavors. As most trusted name in industrial security information management for the last 38 years, SIM Software equips you with the tools to protect the lifeblood of your organization. Our flagship SIMS Suite provides all the features and functionality you need to run an automated, paperless industrial security program. Gain a 360-degree view of every physical, virtual, and human asset inside your security domain. From classified documents and materials to cleared personnel, facilities, visitor control, information systems, and more.com or call 858-481-9292 or see our show notes for more information. So one thing that's required also in training is the Insider Threat Program. You guys might be aware of. And it's specifically two clear defense contractors, and it's specifically requirements stated in the NISPOM. So this is going to be specifically to FSOs and insider threat program senior officials. So I'm putting this book together after many years of meeting with program offices or setting up security programs that meet requirements and advising government and cleared contractor clients. And I've decided to write what I've learned, and also from all you wonderful professionals who have contributed with emails and provided guidance, my mentors and everything else. I put it all together in this book. It states that clear defense contractor facilities are required to establish that insider threat program. And I call that the ITP. It's a requirement and guidance is provided in NISPPOM as well as on the DCSA's website. And this book will highlight those NISPOM requirements and discuss valuable methods that you can use to execute these requirements. Now the value is that you'll be able to apply our recommendations and you may have the tools necessary to demonstrate compliance during these defense counterintelligence and security agency reviews. And so what this means is this book will have appointment letters that you need, establishing an insider threat working group memo, as well as other paperwork that you're going to need to demonstrate that you are in compliance, such as training certificates and risk assessments and much, much more. What I've done also is neck down all these requirements that you may see at the DCSA. So if you go to a DCA website and start viewing their videos on insider threat program, or you start getting instruction on what should be in your insider threat program, you're going to find a lot of information, which includes having counterintelligence briefings, intelligence briefings, things that aren't normally accessible to a clear defense contractor. So when you go and look for insider threat program guidance, you're probably going to find guidance that's specific to government agencies and not necessarily tailored for the defense contractor. For example, again, those briefings that agencies are required to get, you may not be able to go to. Additionally, some of the recommendations are to get behavior therapists and to help you know review your employees and see what kind of behavior they may be exhibiting that could be associated with an insider threat. I don't recommend that. That is something that you probably can't afford, and it may bring about some ethics violations or some type of lawsuits. So I always recommend if you ever go forward for an insider threat program that you bring it with your compliance folks so that you can get the correct guidance. And so what I've done is kind of filtered out information that is required from a government agency and so that you, as a clear defense contractor, can worry about what your specific requirements are. So the DCSA has this oversight responsibility, right? They also provide resources to help clear contractors initiate and maintain their insider threat program. There are many components to the insider threat program that you need to address. And I hope that the book will lead you to successfully implementing your very own insider threat program. And so the book can should be able to augment your current program by providing suggestions that you can use to develop tools, templates, and processes. I've got those in the book that help you protect sensitive information under your control and ensure that your cleared employees understand their requirements. So in the back of the book, you'll have valuable appendices that get you started with setting that program or some things that you can adopt to your existing program. So before we get too deep into this, I'm going to give more information about this book as we go along. I just want to give you a little bit of progress. So here's a little bit about the expectations of the ITP from a NISPOM point of view. Keep in mind that your working plan should be able to demonstrate compliance. Not only are you looking to protect classified information, but you need to demonstrate that ability to do that. So we're going to focus on some things in this book that will help you do that. So for the compliance part, again, you'll have documentation and certificates that you can use to show and demonstrate to DCSA that you are in compliance. We're also going to give you effective methods to actually reduce the occurrence of an insider stealing your classified information. A lot of countermeasures recommended it right now, do not do that. All they do is an important task, which I recommend you do as well, is report behavior. And let me rephrase. One is a strong reporting culture, and the other one is a strong culture of auditing employee activity online. These two alone aren't the entire answer. So I've got insight into how you can protect classified information. Because I want you to ask the question what does the NISPOM ask you to do to protect classified information? And why is that not good enough to stop an insider? I've asked those questions, I've done the research, and I think I've got viable solutions for you that you can implement through this book. So for the Department of Defense contractors, compliance can be measured doing a couple things. There's a methodology that we can use in the self-inspection handbook for NISP contractors. That's published through the DCSA. And there's a lot of questions in there that you can ask in your own insider threat program that will help you demonstrate whether or not you're successful. Using that self-inspection program and questions from it, we're leveraging that in this book as well, and it will help you ascertain how successful and whether or not you're in compliance with the insider threat program that is required of you. And so we'll have lots of examples. We've got real life examples of people who have stolen classified information, how they've done it, and how they've been caught. And maybe they've been caught too late. So we invite you to continue following this podcast. Again, this book should be published in about a month. We're talking about April 2023, in case you're reading an older version of this, and we'll have links to how you can get your own copy as well. Now I'd like to tell you about our other sponsored, Mission Driven Research. They're there to glorify God by empowering employees to fulfill their mission. Their vision statement is that every employee finding fulfillment and joy by actively engaging in the mission. Their core values are to go the extra mile for their customers, grow our employees personally and professionally, and give generously to our community. And their website, they describe themselves as a growing company providing technical services to the U.S. federal government. If you'd like to know more about mission-driven research, find them at missiondrivenresearch.com. And also in our show notes, I'll include a link to their website and how to contact them. Alright, let's talk about security clearances for a minute. Many of you may find yourself in need of a security clearance and wondering how to get it. Well, if you're an employee with a facility security officer on site, they're the ones that are required to initiate that security clearance, and they do it based on the justification. If you're a new FSO, you might be wondering, well, how do I justify a security clearance? Well, holding a security clearance again is a privilege. It's a determination by an adjudicator after an investigation has been completed that a person can be trusted to protect classified information in their possession. And the security clearance and a valid need to know are what is required. So holding that security clearance is a privilege. Now the wardee is able to perform on classified contracts where they would not otherwise be able to do so. However, some defense contractors mistakenly assume that they can request a facility security clearance for business development purpose or to better position themselves for future classified opportunities. But I'm here to tell you that that facility security clearance is tied with a contract. And if you don't have a security clearance yet, you have to provide a justification. Not you, but your sponsor. Again, you might remember that to be able to have a facility security clearance, you have to be sponsored by a U.S. government customer that you have a contractual um obligation with, or a prime contractor that is subcontracting you because you have a special skill. Though that is not how you know FCLs or facility clearances are not awarded so that you can get a contract in the future. It's awarded when you get a contract. So there's a methodology in place. So the FCL or facility clearance justification is a trigger point for DCSA or a cognizant security agency to begin security clearance processes. A well-documented justification indicates that the contractor is or will be required to work on that classified contract. So the justification should include information regarding the nature of the classified work performance that requires the company to access that classified information. So, you know, some examples are you can look at a DD Form 254, and this lists exactly what a cleared company is expected to do with classified information and how they are to perform in that classified contract. It provides the name of the company, the DCSA covering organization, the clearance level, the storage level, the place of performance, and so much more. Now that sponsored company should review the 254 with a sponsor for accuracy and completeness. So another way to do it is a contract statement of work. Now this provides great justification that the sponsor can use, and it states how the contractor is to perform on that contract. And it provides the why. Why do I need contractor XYZ to have a clearance? Because I need contractor XYZ to make 50 classified widgets. Now the administrative details may not be as great as they are in the 254, however, the statement of work does list those technical security-related tasks. So a request for proposal might be another way. It's before the statement of work, right? So when or during the statement of work, when you can finally read what is required of the contractor. So when a government agency or prime contractor has a need, they send that request for proposal listing the need and the performance standards. So the intent is to find a competent contractor or vendor to compete and win that contract. So if the work requires access to classified information, this can be used to strengthen that justification. So there are just a few things considered that would cause DCSA to re reject a sponsorship. So this includes a lack of justification, incomplete or inaccurate information, and the requester and sponsor should review packets for accuracy and make those corrections as needed. So you can find more information in that webinar that I put together called Security Clearance Webinar. It's at redbikepublishing.com, and you can find on the top tab. But I'll also put it in the show notes. Once again, I thank you for joining DOD Secure. This is your place to go for all things NISP Palm, all things contract requirement, and all things security clearances. Please look at our show notes and you can find more resources that might answer your questions on how do I perform once I win a classified contract? And what do I do once I get a security clearance? And the other question is how do I get a security clearance? We are here to help you out. And hopefully remember that when you visit our show notes, you will find those resources, as well as access to the company. Wish you all the best, and I'll see you next time.