NISPOM Central-Working with National Industrial Security Program

Classified Government Contracts and Risk Assessment

Season 3 Episode 7

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:01

Send us Fan Mail

Contact/newsletter:redbikepublishing.com/contact

The National Industrial Security Program NISPOM is THE guidance for Cleared Defense Contractors (CDC) performing on classified contracts. However, it doesn’t always answer some questions these FSOs might have about protecting classified information. For example, suppose a defense contractor company has a contract requiring the storage of classified information at the SECRET level. Do they need an alarm?
You might recall in earlier articles that I’ve emphasized the importance of finding out what the threats to classified information are to your particular organization. Be aware of NISPOM vs. Best Practices, vs. Risk Assessment before committing resources that may or may not be required. Industry standards and common practices may almost seem like requirements, but can be expensive endeavors if not necessary to implement. To some, it may be unheard of not to have alarms, cameras or access control systems (door magnets and card readers). However, these are not required in NISPOM (except for intrusion detection systems as identified in certain situations and not in all situations).
Prior to travel, a cleared employee should have a good understanding of their responsibilities to protect national security. A Defensive Security Briefing is for those who travel overseas and may be vulnerable to foreign entity recruiting methods. They should be constructed to make the cleared traveler aware of their responsibilities to protect employees, product, customers and those with which they do business. Topics of the defense security briefing should include threat recognition, how to assess and how to respond when approached for recruitment.
The Facility Security Officer’s successful program depends on developing relationships with employees, managers and executives to facilitate execution of company policies and adherence to NISPOM. This includes security awareness training, participation in continuous evaluation, and tracking changes of status, and proactive action toward expired, existing and future classified contracts. Any of the above mentioned success measures is difficult to obtain in a changing employee and contract environment, but is simplified through employee and executive buy-in.
Facility security officers and industrial security professionals should develop measures to safeguard classified information at the highest level indicated. Employees should be trained to perform on these contracts based on NISPOM Guidance. This training includes:

Non Disclosure Agreement (SF 312)

Derivative Classifier

Security Awareness Initial and Annual Refresher

Insider Threat

NISPOM Central
Providing security clearance books, training, and resources for cleared defense contractors.

Jeff's Website
Jeff is available for speaking and consulting

Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.

Support the show

FSO Consulting:
https://thriveanalysis.com

NISPOM Compliance
https://www.nispomcentral.com

https://www.nispom.com

The Trusted Advisor for Technology Protection, FSO and NISPOM consulting. 

After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.

INDUSTRIAL SECURITY TRUSTED ADVISOR

What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements. 

Results you can measure immediately:

  • Prepared commercial organizations for defense contracting and NISPOM compliance
  • Designed ready to implement security programs before, during and after facility clearance award
  • Rescued high risk security programs with quick turnaround; usually within 30 days
  • Achieved Commendable and Superior DCSA review ratings
  • Developed compliant FOCI mitigation programs