NISPOM Central-Working with National Industrial Security Program
Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.
NISPOM Central-Working with National Industrial Security Program
Don't waste valuable training time
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Some security training and briefings are very discouraging for the work force. Many times, the training is the exact same video or presentation used year after year.
So, if you go to my website www.redbikepublishing.com, you might find training and tests that do ask those types of questions.
This topic is specifically about how to make your security training more effective for your work force. There are two types of training: for security professionals and for the workforce.
So here are three problems I see with the current security training trend:
1. Lack of training resources
What is concrete is that there are various training topics required for cleared defense contractor employees, they include:
· SF 312 Non-Disclosure Agreement briefing
· Initial Security Awareness training
· Annual Security Awareness Training
· Derivative Classifier training
· other required training events and briefings
2. One Size Fits all
There are many resources that busy security managers can draw upon to solve the problem of training the workforce. There are downloadable training topics available from vendors and government websites. The problem is, the training never grows up or ever requires growth from members of the cleared workforce.
3. Making a nation of Security Professionals
The very resources we use to present to our cleared force comes from security professional targeted websites. Defense Counterintelligence and Security Agency trains security professionals and their courses are designed for that purposes. Because of problem statements 1 and 2, we are forced to use these canned presentations. In here the workforce is tested on their knowledge of security forms, how to conduct security investigations, and how to challenge classification. In fact they need to understand better that a cover sheet exists, how to recognize and report a violation, and what to do if something is over or under classified.
The solution
1. Begin with the Contract Security Classification Specification or DD Form 254.
2. Incorporate workforce peers, supervisors and program managers.
Links mentioned.
Youtube Video
https://youtu.be/eF1JHRa2U8M
Free Book plus shipping
https://www.redbikepublishing.com/insiders-guide-to-security-clearances-free-plus-shipping/
Free book to first five people
https://www.redbikepublishing.com/contact/
Cleared employee training
https://www.redbikepublishing.com/fsocertification/
https://www.BennettInstitute.com
Providing security clearance books, training, and resources for cleared defense contractors.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
FSO Consulting:
https://thriveanalysis.com
NISPOM Compliance
https://www.nispomcentral.com
https://www.nispom.com
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
- Prepared commercial organizations for defense contracting and NISPOM compliance
- Designed ready to implement security programs before, during and after facility clearance award
- Rescued high risk security programs with quick turnaround; usually within 30 days
- Achieved Commendable and Superior DCSA review ratings
- Developed compliant FOCI mitigation programs
Hi, and welcome to another episode of The LD Here, and I'm your host, Jeff Finn. Thank you so much for being here and joining me today. I know there are a lot of other places where you can go and learn about security clearances, the National Industrial Security Program, and defense contractor security, but I'm glad you chose to come here. And I know there's a lot of places to go to for your podcast enjoyment. Thanks for being here. While you're here, you're going to learn how to get a security clearance, how to prepare to receive classified information to work on them, and we'll talk about training requirements and everything else. Today's topic specifically is about training and how not to drive your audience crazy. Security training is very important. We've got to learn the fundamentals of protecting classified information that we are working on to build our customer systems. The classified information is there based on an agreement that you would receive them, that the government would provide that information, and you would protect it accurately. And so there is a lot of training that needs to be done. But not all training is equal. We've got to train in such a way to that our audience continues to learn and grow. For example, your audience may not need to be overwhelmed with details, administrative type of details, um, that you may be tempted to provide to them. Like, which form do you fill out at the end of the day? And the choices are form numbers. Your audience may not need to know those form numbers. However, I want to clarify by saying if your audience needs to know those form numbers, then that's fine. We'll get into a little bit more of that later. But I just wanted to clarify also one more thing. If you go to my website and download my training, my training is geared towards people who have their full-time job of protecting classified information or are owners of companies that protect classified information, and that is one of your jobs because your company is not a large company. Basically, you will get that kind of training because you need to know those form numbers. Also, I train security professionals on how to get certification. In this case, security professionals need to know form numbers. But my question to you is do the engineers that come to you for security resources need to know form numbers? If they do, teach it. If not, don't. Anyway, that's what this training is going to be about. We're going to hear what is appropriate for your audience. Now I base this on I do work full-time and I do this as a part-time job, and I am required to take training annually, semi-annually, every two years on protecting classified information. In my capacity, I am not a security manager. I've done this job many times. I know it. I study it. It's my hobby, but I don't perform a full-time job as a security manager. So I get frustrated as I take these required training courses. And I've been doing this 22 years in the army working with a clearance, and then many, many years after I get out, I'm continuing to take this training, and it's always the same level. It never progresses. I'm taking the same training that I did when I just first got a security clearance. And it's frustrating. And I know many of you are probably frustrated too. Unfortunately, we have to design that training ourselves. A lot of it doesn't exist. The training that does exist that we're able to use is one size fits all training. Whether you've been a security professional for 20, 30, or even five years, you know this stuff, but they keep throwing at you the same language, the same basic training, and it never advances based on your knowledge. So I'm appealing to you as security managers or owners of companies, make the training worth it. And so today we'll discover some ways, three or four ways that you can make your training appropriate to your audience. Now, let's get started. Let's talk about the different types of training there are. Now, the first time you ever get a clearance, you're going to possibly get a briefing. You should be getting a briefing about the non-disclosure agreement. It is called the SF312. And again, I'm using the term SF312 non-disclosure agreement because you, as a security manager, should know that form. But if I'm talking to an engineer who just needs to get their security clearance, I'm going to call them in the office and talk about a non-disclosure agreement that we're going to have with the United States government. I don't need to at the end ask him which form they are going to sign as part of a test so that they understand. Now, there's three things you need to do before you can access classified information. One is sign the non-disclosure agreement. Two is be granted a security clearance. So you sign that agreement based on the government's granting of a security clearance. And then number three is you have a need to know. Right? You are actually working on that project, and there is a reason for you working on it. So you're able to access classified information there. So that's the first part of training. That first indoctrinization is the is the basic, most fundamental level of um the classified information briefing. There you learn what security clearance levels are, how information gets classified, your responsibilities as a cleared employee. This information is very important. As a matter of fact, I've developed some training. If you want to uh download it and present it to your brand new employees, it walks them right through it. This should not be a check-to-block, but it should be a heart-to-heart talk talking about the importance of recognizing and protecting classified information. So you give this briefing once, maybe twice the next year. But once somebody has learned this, it's time to expand the um security awareness briefing from the initial. Now you have to give this every year. Do you want to give that initial level briefing every year? If somebody's been working with you for five years, don't you think they already know there's three types of clearances? And you're still asking them what are the levels of clearances? Secret, confidential, and top secret, they already know this. Don't insult their intelligence. So let's talk about the next level of training. Additional training is uh is required by those working on classified information, it's called the initial security awareness training. Now, the um non-disclosure agreement briefing can also be used for this initial security awareness training. In fact, if that briefing has the same um elements as described in the NISPOM of what should be provided in the um uh initial security awareness training, then use that same briefing by all means. Transition from sign the non-disclosure agreement to initial briefing and you're done with them. The next level of training is called the annual security awareness refresher training. It should look different. And we'll get into those elements a little bit later, but it should build upon that foundation that you've already made. Um and it may be that you do the initial security awareness training in different groups based on people's experience, or you may be that you do the um I'm sorry, the annual refresher training based on contract or based on project. So there you can delve into the intricacities of the security program or the uh engineering program or project or services that they are providing specifically based on their work that they're doing. And a lot of this training can incorporate supervisors into that training to provide specific information that they may need to know. And again, we're we're gonna break this down a little bit more. And then the the next level training is derivative classifier training that is provide needed every two years by people who are in the contracting activity, basically subcontractors, prime contractors, people who are working on projects that require them to um paraphrase, rewrite, or um work on classified products to make a new product based on existing classified information. That's derivative classifier training that's required every two years. Again, this training is a little bit different and it gets into more specific and it should grow from a basic training to a more intrinsic and a more complicated training based on their skill level. All right, so I've talked about the the training that is required by um cleared contractors. Again, this is not training to make somebody a security practitioner. This is training to help people that work with classified information be able to do their job better and provide ultimate um security to the classified information they are working with. Together you work as a team. You're not trying to build an extension of the security department, you're trying to incorporate them into the security program. Um, and so one ingredient that should be applied to all training is the the uh DD Form 254, contract security classification specification. And this is issued from either the government program office that provides the classified work or the prime contractor that provides the classified work to the subcontractor. They will issue to the DD Form 254. And again, you guys are familiar with that form, but if there's anybody out here that's not a security practitioner or is interested in getting to this career field as a clear defense contractor, this basically tells the contractor that has won a classified contract, the level of the contract, the classification level of the contract, the type of work that is to be done, whether or not that information is going to be stored or worked at that facility or at another location. And then it gets into other classified uh requirements. This form can be an actual uh blueprint for your training that you build. I'd like to take a moment to recognize one of our sponsors, and that's mission driven research. And they can be found at www.missiondrivenresearch.com. And Mission Driven Research is a growing company providing technical services to U.S. federal government. The goal of MDR is to continuously improve performance and three core values. This mission focus is the core of MDR and fosters a highly satisfying work environment, motivating employees to excellence. And so if you get a chance, go by there. Visit their website at www.mdr.com. Sensitive compartmented information. You would provide training on how to do that at that facility. If it requires handling um 3,000 classified documents, then you can train them on the security policy and how to handle those 3,000 documents, how to protect them from the time that they access it to the time that they are finished with it. I want to say one thing about the level of training and how you validate that training. A lot of people do tests at the end. And again, I'm frustrated because the tests that I am taking are asking me form numbers. I'm not in my capacity, in my full-time job, a security manager, and there is no need for me to know what a form number is. For example, at the end of the day, I need to sign an end-of-the-day checklist. So it's appropriate for me, if I'm a security manager, to tell my engineers that if they lock something in the safe and at the end of the day they are doing the last-minute checklist, they need to sign the phone that's hanging on the door. It's called the end-of-the-day checklist. Or activity activity security checklist. It has a few different names. Do I need to put on the form? Hey, at the end of the day, when you when every you are locking up, do you you need to find sign the SF 701, the 702, 703, or 704? I don't know. I'm gonna get frustrated and you're gonna make me fail a test because I didn't know your form number. Um, this happens many times. However, again, I want to say if you're a trained security specialist, they need to know that form. However, um, and again, do I need to know that if I hand carry top secret information from one area of the building to the other, that I need to be familiar with a form. So if you are to check out top secret information from the security office and carry it to another location of the building for a meeting, you need to have SF 703, 704, 705. I don't know what that engineer needs to know. They probably need to know that they need the orange top secret cover sheet. That's about what they need to know. And again, what's gonna happen if somebody comes up to you and says, Hey, could I have a SF 705? Are you actually going to know what they mean, or are you gonna look that up yourself? So, no need putting things like that in a test to validate training, or no need to even train, uh, in my opinion, no need to for them to even know the form number. What they need to know, if they're not acquiring this form, purchasing this form, bringing this form as far as um security, um, supplies, maintenance, or responsible for it, just let them know they need the top secret cover sheet or they need the secret cover sheet or confidential cover sheet if they're carrying a confidential document. Um, so that's my opinion on the subject matter. So, why frustrate your audience by going over form numbers when you can just tell them the easy rule? Now, having said that, some um contractor activities have everything centralized in a um one security office. It's called document control. They may have another office that does security clearances, they may have another office that does physical security in these individual organizations. So then the engineer, if they want to work on a document, they have to go to that office to get it. If they want to know the status of their security clearance, they need to go to the security office to the personnel security office and get that information. That's one example. The other example is that the employees have their own security containers for their own projects and they maintain that security at their location. So they may need a little bit more information. So again, it may be appropriate for them to know the form numbers in case they have to order, need to order those form numbers. But if it's not necessary for the training, why not give them a break and give them the training that they do need and not just try to make up training that frustrates them? I know it's tough, but it will pay off in the end to do that tailored training based on the work that's going to be accomplished. Sometimes it just happens. In spite of living a life above reproach, you have an event that could put your security clearance in jeopardy. But before you discuss it with anyone at work or your FSO, contact Ron immediately for help to self-report in the best possible way. You can call Ron at 256-713-0221 or visit his website at www.securityclearance defense lawyer.com. So right now um I've given you some ideas about using um the SF, I mean the DD Form 254, on kind of make an architect of your training, and that form is very important. And if you go line by line on that form, you'll get some great training opportunities. Now, training doesn't have to be very long either. Um, I'm just taking a lot of training that lasted an hour that um didn't need to last an hour because it gave me more information that I needed to use as a security practitioner. Most of the stuff can be given in less time, um, especially if it's given annually. And again, the point is to build on training that they already know. If they are working with classified documents every day and they have a supervisor there and they're interacting constantly with the security office to get their classified documents, chances are they are trained very well. Another example is what does a cleared employee need to do to transfer, hand carry a secret document from one location to the other? Or how does a cleared employee ensure items get mailed from their facility to a facility where they are going to go and give a presentation? This is a good question because in one organization, the security department takes care of everything. In another organization, that engineer may perform these functions themselves because the company is too small to have that big security organization. So, again, if you're working in a facility where you, as a security office, is handling all the preparation of classified document for mailing or for hand carry, and that employee does nothing except maybe hand carry it, then their security training should be how do I safeguard this information while it is in my custody? Do they need a detailed instruction on how to wrap a classified document and how to put or whether or not to put the person's name on the inside of the envelope or how to properly mark and stamp the envelope? These are these are bad examples, but I'm holding up envelopes for those of you on the podcast and not on the YouTube channel. I'm holding up envelopes that I've made and they're kind of falling apart. I need better material. But you know, um, there's a lot of training, about 20 about okay, I'll be more realistic, about five minutes to 10 minutes of an hour's worth of training on how to properly mark and wrap classified information. And I'm not authorized to do that as part of my job. Why do I need that part of the training? I can reduce it to a few minutes to show the importance of doing it, but I they don't need to know the task of wrapping a classified document. Security practitioners do. Users of classified material, most cases do not. And if they don't need to do that in that job as part of their duties, then why expand on it? Help them understand how better to mark classified information that they're doing, that they're creating derivatively, how to recognize a security violation, how to report that security violation. For example, if they need to challenge a classification, do you need to tell them that they need to go to the ISO and challenge that classification? No, they really need to go to their program manager or their facility security officer. If they find out that there is a security violation, do they go to straight to DSS? No, they need to go to the FSO. Why teach them how a security violation occurs? They need to know what happens during a security violation, what could happen to them, the importance of protecting classified information correctly. They don't need all this other data that they will never use. If they don't, if they do need this data, again, there are certain circumstances where they do I'm asking you to do as the trainer as the FSO as the person responsible for this is to make sure it makes sense to the user because we can overwhelm them with telling them how to do our job we want to help them do their job better. Now some things that you may need to teach the workforce to do is you know how to um receive classified information, how to transport it, how to safeguard it while they are working on it, how to determine what need to know is, how to um mark classified material and to include if they create a new document, a derivatively classified document, what goes in those markings, how do you determine what it's derived from? You know that's what they might need to learn. Additionally they should learn how to recognize a properly marked document whether something comes in through email through the SIPR net or through classified email or a hand carried package you should have them inspect that so that they can say hey this is not marked properly. If it's not marked properly it needs to be brought to the security office so they can handle that because what happens is this security office or somebody ends up with a collaboration of improperly marked documents and you want to stop it before it happens. If a document is not marked properly it needs to go back to the person sending it for corrections. And so they need to learn how to correctly mark assemble store and protect classified information and work products. So we talked about bringing in um supervisors so if employees are working and they've been there between three and five years they need a little bit more training and this training could be on the job and this training could be conducted by the supervisor. You don't need to come into an auditorium but you can have uh delegate some training to supervisors with a checklist of the skills that they need to demonstrate and the supervisor can declare that their employees have done these skill levels send them back to the security office to be recorded as security training that's some way of doing it. The FSO may not always be the best trainer again I'll repeat that the FSO may not always be the best trainer. They are the best trainer when it comes to talking about security policy and protecting classified information according to the NISPOM but they may not know the ins and outs and the struggles that the program office is with working with classified information. So they may leave this training to the supervisor who knows the intimate details of the project and can complement that foundational training. So in summary we've talked about training and the importance of training now there's two types of training one is where you want to train your security employees to be better at their jobs so they need to know intimate details such as how to enter security information into the database how to initiate a security clearance request how to grant access to classified information that is for the security team that is not for the general workforce a lot of times security departments re put this in annual security awareness training when all they need to know that is that there is a process that exists. Another example is or another thing is you you train your security team then you train the workforce the workforce needs to know how to implement security while they are working on their classified projects they don't need to know administrative details such as form names and form numbers they need to know what the classification level is where the work should be conducted how to conduct the work and protect the classified information according to NISP and there are some skill sets and some processes that that you can use to train them and one important tool is to use the DD Form 254 and go line by line and train each program based on what the 254 says and the intent is not to give the initial security awareness training or the non-disclosure agreement briefing every year so that people who have vast knowledge and experience are still learning the three levels of classification. The intent is to build upon that and build develop a training program specific to the work that they are doing. And again the DD Form 254 provides a great starting place a great roadmap towards that training and the second point is incorporate more experienced professionals who are engineers who actually do the work and protect the classified information incorporate them into the training because while the FSO and the security team may be great points of or great trainers for the initial security awareness training in the SF312 or the um non disclosure agreement briefing they may not have the skills or the intimate detail to describe how to protect classified information based on the program that is working with it. And there are many reasons that I'm saying this I don't mean to insult anybody but um this information may be needed so this training more in-depth training may be better suited for fellow engineers or more senior engineers or supervisors who can provide that training to their growing workforce. Another great tool that I didn't mention early is how to read the security classification guide. That would be something that could be incorporated into the training toolkit again by a supervisor. And one more thing is the FSO can provide the minimum requirements to the supervisor and have the supervisor build upon those minimum requirements through the year and provide a checklist or provide validation that they have taught those skills to their cleared employees based on those contracts that they are working on. And in my opinion this will be a more robust security plan than bringing everybody together and providing a briefing or having everybody watch a the same video year after year. All right so hopefully that helps you and encourages you to build upon your great security training that you have right now and maybe give you ideas to think how to present security in other in other ways to make it resonate with your workforce so that they can understand how to prevent unauthorized disclosure by marking information properly, by safeguarding classified information as they should, and maybe discovering areas that people aren't familiar with where classified information may be vulnerable. So I wish you luck. I wish you the best of success as you implement uh training programs within your organization to help you win and keep classified contracts. So until next time this is Jeff Bennett signing out of DOD Secure the podcast. Now if you want any more information about training or about security topics or how to win classified contracts visit my website at redbikepublishing.com and I also have a training website for security managers and it is called or for managers or even owners of clear defense contractor companies it's called Bennett Institute and I have um free training there that discusses um how to protect classified information and for security managers how to get security certification and their study guides there as well as in depth security training so that you can better protect classified information. And we hope to see you next week