Also, we've provided real world security discussions and frequently asked questions. These occasions have proven to be good opportunities to clarify understanding of security policies and the reasons we do what we do. We would love to hear your stories as well.
We hope you continue to learn and benefit from our newsletter and products. If you are, please refer us to a friend or forward this newsletter with our appreciation. Stop by our advertisers websites as well. You just might find what you are looking for.
Have you taken the next step to being competitive in the government contracts arena? If not, this article will provide information and tips based on a proven method of studying for and passing the exam.
Why earn a certification?
There are several reasons to achieve certification. One of which allows cleared defense contractor owners and employees to take advantage of opportunities offered in the recent Presidential Executive Order: National Security Professional Development. The Executive order states: "In order to enhance the national security of the United States...it is the policy of the United States to promote the education, training, and experience of current and future professionals in national security positions (security professionals)..."
The National Strategy identified in the Executive Order provides a plan to give security professionals access to education, training to increase their professional experience in efforts to increase their skill level and ability to protect our nation's secrets.
The ISP Certification is sponsored by NCMS (Society for Industrial Security) a professional organization specializing in protecting classified information. The ISP holder demonstrates a high level of knowledge in this area. The certification is based on the National Industrial Security Professional Operating Manual (NISPOM) but also covers electives such as: COMSEC, OPSEC, and other topics.
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Hello, and welcome to another exciting episode of DOD Secure. And once again, I'm your host, Jeff. Okay, so I realize that it's been a few weeks since I've updated our podcast, but I plan to get on it and be a little bit more faithful and try to get this out at least every two weeks. But you know, it's hard getting articles together and coming up with subjects, but I am here committed to putting podcasts about clear defense contractors and the National Industrial Security Program operating manual. I'm also committed to putting out our books, so I've been working on a few books lately. I've actually revised and updated the um our study guide for the Industrial Security Professional and the Industrial Security Oversight Certification, uh, the latter of which is put out by the Department of Defense. So if you're looking at getting certification this year, hey, come check out our book. It'd be a good way to support our show. Uh we don't take donations or anything, we just ask that you purchase our books and our training. So today's topics again are going to be NISPOM topics, and we're going to talk a little bit about the importance of certification in a career or as you get started in your clear defense contractor organization, and as you train your cleared defense contractor employees. We'll also discuss real world security discussions. We'll have those and we'll talk about, we'll answer some frequently asked questions. And you know, we'd love to hear your stories. And if you have anything that you'd like to discuss or have me cover in future podcasts, go ahead and uh email me at editor at redbikepublishing.com. So wrapping up 2020 has been pretty good as far as focusing on updating our books and our services. You know, there've been updates to NISPOM, um, there have been updates to many different regulations, and so as a result, I've updated our ITAR, I've updated our NISPOM manuals. We have the print versions of that, so I spent a lot of time updating those. I've also redesigned cover work and updated contents of our security books. Uh, one new release has been the insider's guide to security clearances, and the other one has been the how to get U.S. government contracts and classified work. You know, those both of these books have been revised, updated, and new covers put on. So if you come visit us at redbikepublishing.com, you can see our updates, and again, it's a great way to support the show. So that's what I've been focused on lately, and that's why I haven't been podcasting very much. I will also be focusing and possibly doing a podcast on the updated NISPOM that has been updated and out for comments. I haven't looked at it yet, but I promise I will do that and maybe have a podcast within a week on that new NISPPOM. So please come and join us. So, in our various roles, you know, you could be a security manager, you could be an owner of a clear defense contractor, but in our various roles, we often get fielded tough security questions. There's always somebody smarter than us out there trying to play whack-a-mole or trying to play smarter than us by asking us security questions that either do or do not pertain to what we do. So I wanted to fill some questions for you guys with some answers that I've been given or have given. So good questions provide the opportunity to address security clearance and awareness concerns that may not rise out up during formal annual training sessions. For example, maybe you handle formal sessions at your workplace where you train a group of employees on required security topics as found in the NISPOM. Well, these aren't great opportunities for fielding questions because a lot of people may have questions, but they won't ask in front of others. But if you get up and walk around and talk to people, they may ask you some questions. So these questions usually come up and you may have experienced them yourselves, and I'd be interested in see how you have fielded these questions. You don't have to be a security expert to field these questions. Sometimes you can just own your clear defense contractor company and your employees may have these for you. So these questions pertain to everybody. So the first one is is everyone who asks guaranteed a security clearance. So what is generally meant by this question is everyone who gets processed for a security clearance guaranteed a security clearance, or at least granted a security clearance. And so emphatically, no, security clearances are not a right. However, um a person who is hired against a security clearance job, meaning that there is a contract, either a subcontract to a prime clear defense contractor, or a prime contract with a government customer, these usually generate security clearance jobs. Remember that security clearances are granted to companies or organizations who desire to perform perform on classified work and they have that classified work, as well as employees who are being hired to fulfill a security clearance position based on a contract. So where contracts are involved, security clearances for organizations and personnel may be requested and granted. But not always, you know, there are suitability issues that companies and their employees may not be able to meet. In some situations, there may be historical precedences that would keep a person or even a company from getting that security clearance. So if a person or a company is not able to overcome past events and show that there is not a risk to national security, they may not be granted a security clearance. However, let me just offer this. Many people have been denied a security clearance, have been able to overcome situations where they were denied the clearance and have been able to appeal and get their clearances granted. So just because someone has been denied a security clearance doesn't mean that it is a forever denial. There are ways to do this, and many ways we recommend is to contact a security clearance lawyer. And you'll hear a commercial later from my buddy, Ron Sixtus. And if you are in that situation, you can call him. But the answer to that question is no. Um not everybody is guaranteed a security clearance. And if you remember, there are background checks conducted that will help an adjudicator, the person granting the clearance, um, determine whether or not a person is able to protect classified information or if they are a risk to national security. If you remember, there are 13 things that they look at: allegiance to the United States, foreign influence, foreign preference, sexual behavior, personal conduct, financial considerations, alcohol consumption, drug involvement, psychological conditions, criminal conduct, handling protected information, outside activities, and use of information technology systems. But these are thirteen areas that the adjudicator will look at based on an investigation. So the second question is Is it true that the government can deny a security clearance for something as simple as filing bankruptcy? Well, we just picked that one. Uh somebody decided to ask that question, so maybe they were going through it. Yes, a security clearance can be denied for many reasons. And remember the 13 uh topics that I mentioned earlier. Any any one of these topics can be a trigger. However, um, as I mentioned earlier, they can be overcome. So if there is anything in an applicant's, um, again, being a person or an entity or organization that would show that there is a risk to national security, it's up to that applicant to show that there is no risk to national security. So if there is a bankruptcy issue, there may be legitimate reasons for having a bankruptcy. If that goes unanswered, of course, the default will be to not grant that clearance in most situations. However, if there's a legitimate reason for that bankruptcy, and there are many, many of them, uh it's up to the applicant to lay that out in a good argument. Uh remember, a clearance determination is based on whether or not an employee is trustworthy. Events or actions that may be sub or that may subject someone to release classified information to unauthorized persons or prevent them from protecting it could lead to a security clearance denial. So, really, what the answer is not because somebody has a bankruptcy, but that somebody can be exploited because of that bankruptcy. So, an example might be if somebody does have bankruptcy, that they admit that they have the bankruptcy and document that bankruptcy and then talk about what led to it, it may be determined that this person cannot be exploited, that they are able to protect classified information without somebody being able to take advantage of that situation and cause them to be risked to national security. So, right now I'm kind of mixing topics. So the next question that came in was why should I earn a certification? And I'm assuming this means a certification. This could mean any certification, really, if you're an engineer or if you're a logistician. But I believe probably this was asked about a some sort of NISPOM certification. Like I mentioned earlier, the Industrial Security Professional or the Industrial Security Oversight Certification. Um, but you can find out that if you know one of our answers like try using your favorite search engine to find a job uh in your skill set, and you'll find that many employers are looking for prospects with education and certification. So yeah, so job security uh progression in your job and also learn to be the best at your job. That's what a lot of these certifications do provide. So next question is what certifications are available? Um and again, I think this went to for NISPOM specific certifications. So um NCMS, it's November Charlie Mike Sierra. There are the Society of Industrial Security Professionals. They have that Industrial Security Professional or ISP certification. Um ASIS International offers um the CPP Certified Protection Professional, and there are all other certifications available, such as the CISSP, OPSEC, and also the DOD offers, the SAPPC, the SFPC, the ISOC, and many other certifications of which I have, I have the ISP and the DOD certifications. And um the next question is why are so many people being arrested for stealing secrets? So I'm assuming is why are so many people stealing secrets, not why are they being arrested? So um in recent news, we we can see that contractors and government employees have been arrested for taking classified material from the workplace and releasing it in an unauthorized manner. Um, you know, we see that with Assange, we see that with Manning, Reality Winner, and many more, you know, they could be as nefarious as conducting espionage to hurt national security or steal secrets for an idealistic or homeland reason. But there also could be social justice warriors who, for whatever reason, believe that U.S. government has no right to do whatever and they release this information so that others can see what's going on. Uh, regardless of the rationale, the impact is usually the same. US United States national security is compromised. So sometimes we look at motivation, but most times we look at impact to national security based on unauthorized release of classified information. But we also see, you know, secrets can be what the government calls secrets confidential, secret, and top secret. But secrets could also include, you know, if you do the air quote secrets, can include proprietary information, intellectual data, export violation topics, and and much more. So um if you go to the Department of Justice website and look at ITAR violations, you can see there are many, many other people being arrested for, you know, not national security issues as far as um NISPOM secrets, but ITAR violations where people are are sending over technical data that may not be classified but is highly sensitive. So in some cases, employees did not have an ill intent but lacked training. So maybe they didn't get arrested, but they committed a security violation or a security infraction. And so that happens with lack of training and can be corrected with appropriate training. Um in the Army we used to say something like, Don't give a barracks thief a chance. You know, don't leave your good shoes under your bed or your valuables out, lock them up in a locker. And so the same thing is you can keep your employees honest by having good security measures and a good security program that will prevent them from being able to easily access classified information and release it. So those few that we have records of that have conducted espionage, it's important that the security managers or whoever's responsible for protecting the classified information, review the security violations, look for patterns, and include the information as part of the security awareness training. Such information is is integral to developing a good security system designed to protect employee, the corporate, and national security information. The next question is um my friend has a secret clearance just like me. However, she won't talk with me about her secret stuff. What's up with that? Well, you may recall in our security awareness training that classified uh conversations are conducted in approved areas. You know, dinner dates, carpools, movie theaters, and the like aren't approved areas. They're an area designated at work. Also, just because you have a security clearance doesn't automatically make you able to access classified material. You also have to have the valid need to know. So not only do you need a security clearance granted, the signed SF312 form, you also have to have that need to know. And it's up to the holder of the classified information to acknowledge that need to know. So the way you'd establish need to know is develop relationships within your security professional network. Look for opportunities to help other professionals as well. Equally important are developing a positive relationship with those with whom you have the security oversight. Be approachable as a security manager so that they will trust you enough to ask these tough questions. Who knows? You may be able to help prevent security violations or even catch a thief. I'd like to take a moment to recognize one of our sponsors, and that's Mission Driven Research. And they can be found at www.missiondrivenresearch.com. And Mission Driven Research is a growing company providing technical services to U.S. federal government. The goal of MDR is to continuously improve performance and three core values. This mission focus is the core of MDR and fosters a highly satisfying work environment, motivating employees to excellence. And so if you get a chance, go buy there. Visit their website at www.missiondrivenresearch.com. So back to the topic of education and certification. You know, as a clear defense contractor, you might want to consider uh improving your knowledge of how to care for and protect classified information. Um one of the ways to do that is through security education and certification. So why earn a certification? We heard that question asked earlier in our frequently asked questions, but here's a longer, more in-depth reason for it that comes from the Department of Defense. So there are several reasons to achieve certification. One allows you clear defense contractors, owners, and employees to take advantage of opportunities offered in recent presidential executive orders. Now, the national security professional development is one of them. The executive order states that in order to enhance the national security of the United States, it is policy of the United States to promote the education, training, and experience of current and future professionals. Now, the national strategy that was identified in the executive order provides a plan to give security professionals or clear defense contractor employees access to education and training to increase their professional experience and efforts, to increase their skill level and ability to protect our nation's secrets. So, one such certification is the ISP certification, and it's sponsored by the NCMS that we mentioned earlier. It's a professional organization specializing in protecting classified information or providing education and training to those who do so. The ISP holder demonstrates a high level of knowledge in the area of industrial security. The certification is based on the National Industrial Security Program Operating Manual, or the NISPPOM, but also covers other elective topics. Another one is sponsored by the Department of Defense, and that's called the Industrial Security Oversight Certification, ISOC. Now both of these certifications are based on NISPOM requirements. And the NISPPOM is the government contractors' guidance from the DOD on how to receive, process, and distribute classified information. It covers topics such as how to mark, receive, store, disseminate, and destroyed classified information, as well as how to set up classified computing. You know, if you've worked with contractors or planned to work with clear defense contractors, you should be familiar with the NISPOM. Chances are that you've already familiar with the processes from some experience within military or the government. But this is a document that you should read and understand and learn how to apply in your clear defense contract or organization. So the certified professional communicates to supervisors, the promotion boards, or even the contracting officer or the contracting officer's recomm representative that they're committed to the business of protecting classified information and they're committed to being able to execute successfully these clear defense contracts. It equips the certification equips those with the knowledge and skills to perform critical tasks as well as relate well with to what civilian counterparts are are doing. Most of all, it gives the bearer confidence in their ability to apply their knowledge. As this certificate as you know, the certification program evolves, more and more employees and or employers may require this certification. But I champion the fact that it assists with um Bidding on classified contracts. To show that the employees have these certifications or the company owners are certified to protect classified information shows that they mean business, and you can list that as you prepare to receive classified contracts. So, what can you do to increase your experience and skills? This professional certification is a good start. Whether or not you will make security a career, you'll find the certification a career enhancer or a business enhancer. With the event of the new executive orders, certifications may become requirements in the civilian sector and perhaps even in government security positions. Again, we see these in job announcements. They're not necessarily mandatory, but those with certifications will stand out. Clear defense contractor organizations and owners with um certification or certified employees will stand out against the competition. So you also might consider joining a professional organization to assist with that. Again, if you um want study materials, uh we have them at redbikepublishing.com. We have um insider's guide to security clearances, how to get US government and contracts and classified work. We also have um certification type training that specifically goes over the NISPOM at Bennett Institute Institute.com. So at redbikepublishing.com and Bennett Institute.com, you'll find copies of the ITAR, copies of NISPPOM, as well as books and training geared towards security certification and better understanding of NISPOM. Sometimes it just happens. In spite of living a life above reproach, you have an event that could put your security clearance in jeopardy. But before you discuss it with anyone at work or your FSO, contact Ron immediately for help to self-report in the best possible way. You can call Ron at 256-713-0221 or visit his website at www.securityclearance defense lawyer.com. So before I forget it, I want to tell you one of the things that kept me busy from podcasting, and that was providing the audio version of how to get US government contracts and classified work. I ended up reading that entire book and providing it on audiobook. It's being processed right now, and I look forward to its release, so I will let you know when that is done. So the last topic today, this is kind of a warning, and um it's it's a warning that you should worry about the small stuff. You can't be successful at great things if you can't take care of the small things as well. And a small thing here is security container combinations. You do not want to compromise a security container combination, and there are many, many simple ways to compromise it. Some people leave their have uh if you if you have many, many security containers spread out throughout your organization, like if you're a big organization with multiple buildings, multiple rooms where you store classified information, you might have a drawer that is dedicated to combination numbers. Remember, the combination number is classified at the level of the contents in that security container. So if you leave a combination door open andor a security container door open and it lists all of your comp all of your safe combinations, you've compromised all of those, and you'll have to go and do an investigation to see if anything has been compromised, and then you'll have to change all of those combinations. It could be 30 or 40 combinations, and so that's a good work week right there. Another way that people compromise security combinations is to write them down and stick them in their wallet or in their telephone so they can pull it up later or write it down on the desk. That is a security violation, pure and simple, that will have to be investigated because if somebody were to access that combination, they could open that security container and have unauthorized access to classified information. So here's an interesting scenario. Imagine you're walking the floor and talking to your employees when you approach a security container and the employee who is controlling its access. So you want to do an inspection, you want to ask the right questions, you want to see what the security environment is like and how classified information is protected. So as part of your walkthrough, you want to verify that all the documents were properly marked and stored in the container. And after asking for the custodian to open the container, you notice that he pulls out his cell phone and begins scrolling. You ask what he had been looking for, and he states, I can't remember the combination, but I'm sure that it's in here somewhere. Whoa, hold the presses. This is a security violation. So you do the right thing. You immediately start changing combinations, you file the necessary report, you conduct an investigation to determine whether or not classified information was compromised. And you know, not necessarily in this order. You know, so once you conduct investigation and determine root cause and determine whether or not information was compromised, the next step would be, the next appropriate step would be look at your policies, procedures, and immediately conduct retraining. It's important that everybody understands how to act from this point onward. So maybe this situation did not happen where you work, or maybe it reminds you of a similar situation. So here's the question: Do your employees really understand how to protect classified information? You know, some beginning clear defense contractor organizations and their employees may require extra and unrelenting training and diligence to make sure situations as mentioned earlier never happen. More successful security programs include security training conducted and supervised as they apply to the employee's specific duties. For example, if I'm a security engineer and I need to access classified information to conduct my engineering tasks, some specific training might be where do I get the classified documents that I'm looking at? Where do I perform my classified work? In other words, can I bring it back to my office, or is there a designated work area? And when do I turn it back in? When do I lock it up? How do I lock it up? Or do I turn it into a security person for them to lock up? Don't take anything for granted when it comes to this training. Everybody needs to understand. I've seen people take documents to lunch and assured us that they were well protected because it never left their person, but that's not an appropriate countermeasure. It must go in a security container when no longer used unless it's in, you know, of course, a closed area with open storage. So who has access to your security containers? That's another question you might want to ask. Do you limit to only the security personnel, or do cleared program employees have that access as well? This access depends on your security program. Regardless of who has access, authorized employees having access to the combination or the keys should be kept to the bare minimum amount as necessary. And of course they need to be documented, and there are rules to how often the combinations need to be changed or how often the keys need to be or the locks need to be changed. Agencies and contractors should maintain administrative records and tight control of a sound security system or key control or combination control that's designed to protect that classified information and to demonstrate that effectiveness during security inspections. So the security specialists also should maintain a log of those with knowledge of the combinations. They should change the combinations, fill out the security container information form, the SF 700. Now combinations are meant to be memorized and not written down or stored in computers, phones, or personal data assistant devices. The combination is, as mentioned earlier, protected at the same level of the contents in the security container. So if those contents are confidential, then so is the combination. So to ease the memorization, many who assign combinations use a six-letter word or the first six letters of a longer word. So instead of memorizing a confusing six-digit number, which I have problems with, I have problems like in the Army, we used to name training areas with a number, training area 364, training area 436. I get this confused. But they also had a name, uh training area alpha, training area integrity. So I could memorize the words better. So this may be a good idea for your employees. Um so you want to sign a corresponding word with the combinations. So many there are many magnetic combination reminders similar to a telephone touchpad. For example, you have the number two corresponds with ABC, three with DEF. So for example, the memorized word is corky, C O R K I E, then the combination would be 26, 75, 43. So when persons have access to multiple safes, they may commit security violations by writing all the combinations down. Using combination word clues that people can memorize and provide an administrative security container where you can assemble all those combinations in helps to redisk reduce risk of such violations. So let's see if you can answer this question. How often should you change the combinations according to NISPOM? Alright, so some answers, the correct answers are change combinations upon initial use, change in the status of authorized users, compromise or suspected compromise of containers, contents, or the combination when the safe is left open, or as required by the FSO or the CSA. So if any of you said annually, that would be a wrong answer unless it fits in with the above. So if you said annually as a requirement, go back and check the NISPOM. So if you are looking for ways to improve your security program and use and help people memorize combinations, we do have these lock combinations for sale at our website, redbikepublishing.com. So that ends our podcast. And as usual, if you have any comments or questions, you can send it to editor at redbikepublishing.com. We also invite you to join our newsletter where you can get installments of security related or NISPOM related articles to assist you at becoming a better clear defense contractor or a cleared employee. So please again, we don't take donations, but we ask you to support our show by visiting our shop at redbike publishing dot com.