NISPOM Central-Working with National Industrial Security Program
Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.
NISPOM Central-Working with National Industrial Security Program
Classified Government Contracts and Risk Assessment
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Contact/newsletter:redbikepublishing.com/contact
The National Industrial Security Program NISPOM is THE guidance for Cleared Defense Contractors (CDC) performing on classified contracts. However, it doesn’t always answer some questions these FSOs might have about protecting classified information. For example, suppose a defense contractor company has a contract requiring the storage of classified information at the SECRET level. Do they need an alarm?
You might recall in earlier articles that I’ve emphasized the importance of finding out what the threats to classified information are to your particular organization. Be aware of NISPOM vs. Best Practices, vs. Risk Assessment before committing resources that may or may not be required. Industry standards and common practices may almost seem like requirements, but can be expensive endeavors if not necessary to implement. To some, it may be unheard of not to have alarms, cameras or access control systems (door magnets and card readers). However, these are not required in NISPOM (except for intrusion detection systems as identified in certain situations and not in all situations).
Prior to travel, a cleared employee should have a good understanding of their responsibilities to protect national security. A Defensive Security Briefing is for those who travel overseas and may be vulnerable to foreign entity recruiting methods. They should be constructed to make the cleared traveler aware of their responsibilities to protect employees, product, customers and those with which they do business. Topics of the defense security briefing should include threat recognition, how to assess and how to respond when approached for recruitment.
The Facility Security Officer’s successful program depends on developing relationships with employees, managers and executives to facilitate execution of company policies and adherence to NISPOM. This includes security awareness training, participation in continuous evaluation, and tracking changes of status, and proactive action toward expired, existing and future classified contracts. Any of the above mentioned success measures is difficult to obtain in a changing employee and contract environment, but is simplified through employee and executive buy-in.
Facility security officers and industrial security professionals should develop measures to safeguard classified information at the highest level indicated. Employees should be trained to perform on these contracts based on NISPOM Guidance. This training includes:
Non Disclosure Agreement (SF 312)
Security Awareness Initial and Annual Refresher
NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.
Jeff's Website
Jeff is available for speaking and consulting
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
FSO Consulting:
https://thriveanalysis.com
NISPOM Compliance
https://www.nispomcentral.com
https://www.nispom.com
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
- Prepared commercial organizations for defense contracting and NISPOM compliance
- Designed ready to implement security programs before, during and after facility clearance award
- Rescued high risk security programs with quick turnaround; usually within 30 days
- Achieved Commendable and Superior DCSA review ratings
- Developed compliant FOCI mitigation programs
We welcome you to another episode of DOD Secure, and I'm your host, Jeff Fin. Well, thanks again for joining us today. We will be speaking about many topics to include whether or not defense contractors should focus on alarms, how clear defense contractors can develop a risk assessment model to protect classified information, the defensive security briefing, and finally we'll cover the topic of how to implement and direct a security program. Again, this is a podcast for those of you who are defense contractors or want to be defense contractors or working for the government, protecting classified information or desiring to seek classified contracts. And getting the contract is one thing, keeping it is another. And so we're going to go over good security topics on how to protect that classified information, as well as give you the information you need to go out and bid on those contracts and win them. So let's get started. Alright, so the first topic is when should clear defense contractors use alarms? You know, might think it's natural that if you have information, uh sensitive information in your facility, that you would need to use alarms to protect it. But that should be a decision made based on a good risk assessment. And we'll discuss that risk assessment just a little bit later, but right now we'll see how important it is to do that risk assessment in determining whether or not your facility should have an alarm. Now I'm talking about alarms to specifically protect classified information. The reason I'm bringing this up is because in many forums, um, some security practitioners state unequivocally that you must have an alarm to practic to protect secret information. If you do not have alarm, you are not doing your due diligence. And I'm saying no, not necessarily the case. And it's not me speaking, it's just me speaking as I interpret the National Industrial Security Program operating manual, which states if you have information that is secret level or below a NS a D uh GSA approved container, security container, or what we call a safe in many cases, uh GSA approved safe, and something that's approved and recognized by Defense Counterintelligence and Security Agency DCSA, that that is adequate protection if it's locked in there. The room that contains the safe and the secret data does not need to be protected with an alarm. Again, this should be alarm should be implemented if there is additional risk there. So, according to NISPPOM, the guidance for clear defense contractors performing on classified contracts, uh it states there. However, it doesn't always answer some questions that that uh clear defense contractors might have about protecting uh classified information. For example, maybe a defense contractor, their company has a contract requiring the storage of classified information at the secret level. And the question is, do they need alarm? In this scenario, as discussed a few seconds ago, the FSO only has to request a security clearance of employees who are required to perform unclassified work in another facility. So, to date, classified work had not been performed or stored at the cleared facility. So far, the FSO, the facility security officer, has done an excellent job of managing the clearances and has received a commendable on their last DCSA review. Now, the facility security officer has been preparing for an opportunity to bring classified information into their facility based on a new contract. They've recently purchased an approved security container adequate for holding the classified material. However, the facility security officer isn't sure whether or not their company needs to have an intrusion detection system. So, what would you advise that facility security officer or the person in that cleared contractor facility who just won that contract? Would you tell them to get an intrusion detection system or an alarm? Again, we should consult the NISPOM. Does the NISPOM require a cleared contractor storing secret information to have an IDS? And do you think you know the answer? Well, according to the NISPOM, this situation does not require an intrusion detection system. Secret information is only required to be stored in a GSA approved security container. Did you know that the IDS is required for top secret and secret that is not stored in a GSA approved container in a closed area? How many of you thought IDS is always required? Well, that's why we have these conversations. That's why I'm here to have these discussions that that so that maybe when your time comes to be in this situation, you will know exactly where to go and what to do to get your answers. So this is where the risk management comes in. The intrusion detection system may not be necessary, but according to NISPOM, uh but based on risk assessment. For example, if the clear defense contractor is in a high crime area or life safety considerations require it, go ahead and get the IDS. But only do so after assessing the risk. Otherwise, this best practice or this thing that you want to do may bring unnecessary costs to your program. You know, and larger clear defense contractors can afford these, but don't stress your budget if it's not required. Many small companies do not have the vast security budgets of their larger colleagues. Many large companies may have CCTV, magnetic car readers, IDS, and many other state-of-the-art security measures as best practice considerations. But many times the return on investment may not be there if the risks are low or non existent. So an FSO can demonstrate value added by determining whether or not they need an IDS, and when presenting the pros and cons to the management, they will should have a good argument for or against the use. A terrible and costly mistake is to request security measures just because they are industry standards. Know what the NISPPOM says and implement NISPOM requirements, but make an intelligent determination for all other security issues. And so some of my security colleagues who may be considering certification by taking a certification exam, you might want to remember this as well because this is one area covered by the NISPOM, and you may see it on certification questions. So keep that in mind as you practice your trade and as you become a better security practitioner or as you become a more efficient leader in a clear defense contractor organization. I'd like to take a moment to recognize one of our sponsors, and that's Mission Driven Research. And they can be found at www.missiondrivenresearch.com. And Mission Driven Research is a growing company providing technical services to U.S. federal government. The goal of MDR is to continuously improve performance and three core values. This mission focus is the core of MDR and fosters a highly satisfying work environment, motivating employees to excellence. And so if you get a chance, go by there and visit their website at www.missiondrivenresearch.com. Now let's talk about that risk assessment model. Now this risk assessment model is only applying to classified contracts. Specifically, it can be used for your own situation. If you want to know more, some of these things that I do podcasts on are also written in my newsletter. And so I have an example of this risk model. If you're interested, just go to, if you're not on our subscription, just go to redbitepublishing.com slash contact and register for our newsletter, and you'll get a copy of this. Otherwise, you can see our blog at dodsecure.blogspot.com or dodsecurity.blogspot.com. And also on our website at redbitepublishing.com, we post our blogs there as well. So any one of those places, and I'll put them in the show notes, you can get a copy of the risk management plan that I use. So one of the things that I've done with my risk assessment or my risk management plan is provide added security where I thought it was necessary. So in the earlier model, I said you don't need alarms. But in this next model, I determined that even though work was being performed, it was unclassified work in an unclassified facility as and it was part of our cleared defense contractor facility. I determined that we needed to increase the level of security by using technology. And the management was against that idea. But we had some practices that were not, they're more life safety things that happened. We had people walking in, um unauthorized people walking into the facility to ask directions, such as truck drivers or pizza delivery people. We've also had um spouses, significant others, boyfriends, girlfriends of our employees walk in checking on their family members, and so forth. In this case, the facility had six doors in and out of it that were left unattended. And I thought that this might not be the proper work environment that our employees needed. And so I first of all went to the leadership and asked if we could get card readers for our doors, um, you know, magnetic doors so that authorized people could come in and out, as well as put monitoring on it, CCTV cameras, etc. Again, this was mainly for a life safety area and not necessarily to protect classified information. Of course, um they wanted more information before they directed a budget to that. So I did this similar risk assessment that I'm going to show you. And in that risk assessment, I I showed them what the risks were, but then I did a study. Um we instituted this over time. We um started with secure keys and limited access to the doors, and then this required um management personnel to walk to the doors and make sure they were closed all the time. And so I considered all of these and I did a um risk management, which included the cost of leaders checking doors as well as the um difference in the HVAC um heating and air conditioning costs once we made sure that the doors were closed. And to make a long story short, that study and risk assessment uh allowed uh the management to see the benefit of restricting access uh to the employees. And uh it was a cost-reducing effort because having the doors permanently closed and practicing that discipline pretty much um in the first year paid for the security system that we put in place just by HVAC expenses alone. And so that was a success story, and I want to share you with you some of the methodology I used, you know, to achieve that. So, speaking of the risk assessments, um, you know, I've spoken about a couple times, posted a few articles on our blogs. And so you might recall in earlier times that I've emphasized the importance of finding out what the threats are to the classified information in the particular organization. In fact, the first topic we just talked about discussed that. What is the risk to the classified information? No, this risk assessment is of that risk to classified information in and of itself and does not consider other risks. So be aware of NISPPOM requirements versus best practices versus what you find out on a risk assessment. You know, before you commit resources that may or may not be required. Also, once you perform this risk assessment, document it so that you can show or demonstrate to DCSA or any oversight organization of why you made decisions to include or exclude um any security technologies above and beyond what the NISPPOM requires. It's always a good idea. So industry standards and common practices may almost seem like a requirement because they're discussed so much, and you'll hear it in briefings, and you'll hear it in campaigns, and you'll hear it in seminars. But understand that they are best practices and not necessarily a requirement. They can be expensive endeavors if not necessary to implement, or they're implemented incorrectly. To some in this security industry or any clear contractor industry, it may be unheard of or laughable not to have alarms, cameras, or access control systems. However, they're not required except for intrusion detection systems as identified in certain situations, such as a closed area or a location where classified information will not be s um stored in a security container but on an open shelf. So what's needed? Well, this risk assessment that we are discussing. So if you determine that cameras and alarms and etc. are necessary, then provide the evidence to your company officers and get it in the budget. If not, if you don't have this information, provide the findings to your manager to demonstrate your value at reducing unnecessary costs. They will appreciate your assessments and ability to provide realistic and useful input. Risk assessments can be scientific or as scientific or technical and involved as you need them to be. However, my process is simplicity, and I'm willing to accept the small risk of error that this simple assessment tool may provide because I'm actually keeping it simple so I'll actually get it done. If it's too complicated, many times risk assessments do not get done. As simple as a tool I've developed, is its value has always been tremendous and recognized by DCSA. Again, a risk assessment is to be used to complement requirements in NISPOM, not replace them. For example, classified information is always required to be stored in according to NISPPOM, regardless of the risk level you might identify. So if you if you identify no risk, you still have to put that secret information in a security container, for example. You don't get to make that decision. So I've had an example of of what I've designed. We'll discuss it, but if you want to see a visual, you can see it later when you go to any of the sources that I mentioned. So you begin with a list of what you would like to protect. Classified information. You might want to protect the employees that work with the classified information. You might want to protect export controlled items and controlled unclassified information. So you need to know what they are and where they reside in your facility in what format. For example, if they're paper documents and they are stored in a security container, identify the room that the security container is in. Or if they're in classified computers or in a hard drive, you want to identify that as well. If they're in whatever format they're in, it's important as part of that so you can correctly apply this risk assessment. Now these will go under a column called assets. You can name that column anything you want, classified information, whatever, but I just name them assets to keep it simple. These are what you want to protect. Now the list can be as long or as short as you want it to be, but should indicate the most important items your or your organization want to protect. And it might be a good idea to select the most vulnerable items so that your risk assessment can be based on what might be your highest risk. You want to, you know, you want to protect the weakest link, as a saying goes, you're only as strong as your weakest link. So make sure at least that most vulnerable item gets highlighted. If you don't know what the most vulnerable item is, well, this risk assessment can help you get there. Now this um now you want to consider what the threats are. So you may not have a threat per se. You may not be able to say person X or Country X or identify a specific person or specific entity that's trying to steal your secrets. So I like to ch exchange that threat. And the reason I'm calling it threat is because that's what other people do. But to keep it simple, we'll just call it threat. But I like to exchange that threat for a vulnerability or an event. So do you live in an area subject to theft, break-ins, violence, or severe weather? Each one of those in and itself is a threat to your classified information, but you're not identifying it by name or person. So is your company next to a transportation terminal that has explosives or dangerous chemicals? Is the organization in a high area for potential security violations? Does your company have poorly trained cleared employees? This information will go into the threat column. Again, you can call it threat or you can call it vulnerability. What you want to have is as a result of this, is what could happen in your facility and how bad could it be? Again, using the most vulnerable and most impactful of situations. Now, the reason I mention the explosive or dangerous chemicals or severe weather is simple. You might be asking, you said we want to protect classified information. Well, theft is not the only danger to classified information. For example, if there's a hurricane or a tornado or a fire that happens while classified information is not properly secured, what are you going to do about it? What happens if it's blown around? Or if the firefighters need to come and put a fire out in an area where classified information is being worked on. So you will need to identify that as part of your risk. That's why I mentioned those. The next column you might have is probability of occurrence. I like to use a scale one to five for all of these. One being the lowest level of probability, and five being the highest. You can use any scale you want. You can go to a hundred, you can use one as high and a hundred as low, whatever. That's this is just what I use. This column is for predicting the chance. Of threat occurring. Now the next column is the level of impact. Again, using a scale of one through five, you will predict the severity of the damage and the impact to the assessment. So you have asset, you have threat, probability, and impact. You may want to include another one, and one of my favorites is visibility or identification. If this event happened, would somebody recognize it either before, during, or after the occurrence? And that can help you further um bring fidelity to your risk assessment. I don't discuss that much here, but I might do it in another podcast. So for this example, I looked at or considered three threats to classified information stored at a fictional cleared facility. The first threat is the insider threat. I gave a score of three, meaning that the probability of classified information getting out by way of an insider was high. The impact is a five, meaning that the insider would know exactly what to take and may be able to do so without detection. The next threat situation is a break-in. I've determined that based on threat data, crime reports, that spies have not been breaking into the company and gaining access to classified information. The impact of a break-in will be relatively low as an outsider will be hard-pressed to determine what to steal and where it is stored. Outside help, you know, from an insider or an employee. The next threat is severe weather. The probability of wind damage is pretty solid where we live, and tornadoes form often. The probability of a tornado or high winds destroying a facility does exist. Now the impact of the facility's destruction is high, and scattering of classified information cannot be negated or predicted. So based on my assessment, the number one threat is insider espionage with a score of 15. So I will ensure that my countermeasures primarily address this threat. Now my budget may be constructed to include employee training on how to identify the cider threat. I also may develop procedures to limit access to classified processing, copying, or other interaction with classified material. So the next priority to reduce risk on is severe weather. With a total of eight, now I'll focus my efforts on developing and rehearsing how to protect classified information when disaster strikes. I should also spend some time identifying and training cleared employees on how to search for and recover classified information after the disaster. I would not spend much of my budget or effort addressing break-ins for classified information in and of itself in the theft of that classified material. Committing tens of thousands of dollars for alarms, cameras, and access control to counter a threat of breaking in, blowing a safe, and stealing classified information is not justified. However, if part of your assessment includes life and health and safety, you know, things outside of storing classified information, violence, theft of products, workplace violence, then yes, consider these measures. Now this exercise was developed only to demonstrate how to meet risks to classified information, you know, in a semi-intelligent manner. Again, I kept it simple and less technical. Again, this was just a snapshot of a risk in a certain time. A real conclusion for the way ahead cannot be made until all assets and threats have been identified. So once you finish, you'll have a list of priorities on which to focus your security efforts. From there, you can develop your countermeasures and mitigate the impact of a threat and keep assessments as you get new contracts and requirements and be sure to keep your management informed. Again, document this, maybe have a senior vice president or your next level vice president or your director, depends on what level you're working at. Sign this and accept this and keep it on file to demonstrate to DCSA that your clear defense contractor facility has instituted risk assessment in its decision to protect classified information. Now, this is what's called above and beyond NISPOM, and this may get you rewarded during your evaluations. And now a special message for our listeners from our proud sponsor, SimS Software. As clear defense contractors, you represent the backbone of innovation, the front line of our national security, and protectors of all that we hold dear. SimS Software is proud to be your ally in these endeavors. As the most trusted name in Industrial Security Information Management for over 38 years, SIM Software equips you with tools to protect the lifeblood of your organization. Our flagship SIMS Suite provides all the features and functionality you need to run an automated, paperless industrial security program. Gain a 360-degree view of every physical, virtual, and human asset inside of your security domain. From classified documents and materials to cleared personnel, facilities, visitor control, information systems, and more. SIMSSOFTWARE.com or call eight five eight four eight one nine two nine two. Now this is a required briefing that's imposed on cleared defense contractor employees that will be traveling abroad. So prior to travel, a cleared employee should have a good understanding of their responsibilities to protect national security. Now if you recall, I had a little discussion earlier in an earlier podcast episode where the new NISPOM requirements are coming in. Even though there's not really a new NISPPOM, some updated requirements will be evident, and that is to present to Defense Counterintelligence and Security Agency the travel plans of cleared employees, whether they're going for business or pleasure. Now prior to travel, a cleared employee should have that good understanding, you know, of what they need to do to protect the classified information that resides in your head, or even, you know, maybe um sense of information that might even reside on their computers. Now these briefings should be constructed to make the clear traveler aware of how to protect the the themselves, their product, their customers, and those with which they do business. Topics under the defense security briefing should include threat recognition, how to assess the situation, how to respond when approached for recruitment. Now the employees should notify their security office of all travel plans. Again, I mentioned this could be business or pleasure. This includes plans for Canada, Mexico, the Caribbean countries, you know, typical places you might even visit on a cruise. Now the Security Department uh or whoever is responsible for implementing NISPPOM at the clear defense contractor facility should um develop a plan for the specific area after research into that area to be traveled. So again, just like the risk assessment, it should be specific to the situation. Now the State Department has a great website and and the um traveler can go to it to get briefed on necessary travel documentation and what to expect while traveling. Now these employees that will be on vacation or business travel uh should familiarize themselves with the State Department site and use it to become informed. And this is state.gov, www.state.gov. Now technical data now going beyond the classified information into the area for technical data can be transferred by by uh non-US person reading a note, viewing the computer screen, conducting seminars, and etc. So for example, an employee is traveling for business and they're going to go to a seminar where they will present information or maybe even meet a potential customer or business client, they should only have information with them that is under an export license. Other than that, all technical data should be removed from that computer or the employee should be provided with a clean computer, and they should not be traveling with a notebook, pamphlet, or anything that shows information that is protected by export controls. So making sure that they are authorized for license and/or have some kind of agreement before discussing technical data that falls under this export compliance. The employees should be briefed well enough to understand the boundaries in advance and practice scenarios prior to sharing any technical information with the foreign host. Because if the traveling employee does not understand their role and what can be shared, they will not be able to respond properly when, or could not be able to be respond properly when pressed to share more data. And there's all kinds of techniques that somebody can use to elicit information from somebody unaware. Employees should know the boundaries. Okay, so also a sanitized computer, as I mentioned earlier, of no export information in it, company secrets, proprietary data, or anything should not be on that unless it's approved for release, and employee knows how to release it properly. So make sure that this everything is erased from this computer, notebook, or whatever this employee will be bringing. Also, keep all documentations that could lead to export violation or to release the proprietary data close at hand. So there is risk involved just staying in hotels, going out to restaurants where or traveling where the employee could be removed from their information that they have. Employees should also practice good physical safety and security. Now, good practices for them to conduct themselves as professionals at all times. Stick with the host and ensure the employee uh is safe and hopefully refer to them. You know, the the host will hopefully refer uh reputable establishments to your traveling employee. Now, some threats an employee can face while traveling abroad are economic and intelligence types of threats. The economic threat is the theft of technology and commerce. Now the agent may be after formulas, financial gain, etc. Could be many different scenarios. Foreign entities may target classified or company-sensitive information to can you know to gain that competitive edge. Again, it doesn't always have to be classified. It could be intimate details about budgets, names of employees, um business practices, some things that you might want to protect from being shared in an unauthorized manner. Now, this uh economic estimate costs millions of dollars to damage in the US business, so it could happen at your facility while you're while your employee is traveling. Intelligence threats are similar, but they make uh collection efforts against the US to increase their government power or competitive edge. So again, uh a cleared employee that is traveling must report that travel and they must receive a defensive security briefing prior to travel, with the knowledge that if they are approached, they may need to report that to the cleared defense contractor security office once they return from travel. We're so glad to have Access Commander by MathCraft. At Access Commander by MathCraft, we believe security risks and lack of compliance are threats to a business and its people. We strive to provide our clients with the tools they need to stay compliant and prepare for the next generation of threats. Through comprehensive training, support, and customer resources, we transform our clients into security professionals with the know-how to defend their organizations and maintain comprehensive security programs. We support the mission of the FSOs, CSOs, and other security professionals who stand at the front door of our nation's battle against foreign domestic threats. With software designed to the latest federal standards, we help them to strategize, speed up, self-auditing processes, create new workflows, generate reports, and retrieve tactical information at a moment's notice. For more information on ways we can help, visit www.mathcraft.com or call us at 703-729-9022. All that in an effort to facilitate execution of company policies and the facility's adherence to NISPOM guidance. So this includes security awareness training, participation in continuous evaluation, and tracking changes of status and proactive actions toward expired, existing, and future classified contracts. So again, this is all about maintaining employee security clearances as well as facility security clearances. And the successful maintenance of these clearances have everything to do with success of protecting classified information. So any of the above-mentioned success measures is difficult to obtain in changing employee and contract environments, but is simplified through employee and executive buy-in. So one of the most important traits a security manager should possess, aside from being technical or technical competence, is the ability to gain executive, manager, and workforce buy-in. So this buy-in is critical for integrating the security plan into all business units and company operations. For example, one major cause of security violations is the introduction or removal of classified material into or away from a company without the proper accountability of those items. So this is in contradiction to, of course, DOD regulations requiring that classified information in any form should be entered into an information management system and stored properly according to the classification level. A facility security officer can train and write policy, but without the enterprise's full cooperation, will find it difficult to enforce. We've often seen breakdowns in processes, procedures, or in business when managed from the top, where the top has policies and procedures, and everybody at the top is in agreement with those, but they are difficult to implement at the workforce level. So this requires all levels being in agreement. So as well as an integrated security plan or a well-integrated security plan ensures that all business units within an enterprise interact and notify the FSO of any changes in position of classified uh material or storage or change in that disposition, as well as anything that might impact the employee security clearance or the facility security clearance. So a change in disposition of classified material storage, for example, would be where any required security measures are failing or aren't protecting as they should. This should be reported to the FSO and further reported to the Defense, Counterintelligence and Security Agency. So this integrated system will trigger the contracts, program manager, business, development, and other units to coordinate with the security manager and keep them informed of expired current and future contract opportunities and responsibilities. The coordination will allow the security manager to be proactive and better support the company's classified mission. Or maybe the mission is not classified, but help them support the execution of classified contracts. In other words, so having a security program integrated into all aspects of the company produces award-winning situations and dramatically reduces security violations. Sometimes it just happens. In spite of living a life above reproach, you have an event that could put your security clearance in jeopardy. But before you discuss it with anyone at work or your FSO, contact Ron immediately for help to self-report in the best possible way. You can call Ron at 256-713-0221 or visit his website at www.securityclearance defense lawyer.com. To thank you so much for joining our podcast. Please, I encourage you, if you want to learn more, to visit our other podcast episodes as well as our sponsors of the show. Now in our in our podcast notes, I'll have links to some very important information that you can use that supports our mission at Red Bite Publishing. Our mission is the same as with this podcast. We want to help clear defense contractors better establish programs to get classified contracts and protect the classified information under the contracts. So to do so, we have a newsletter that you can subscribe to, and the link is found at redbikepublishing.com slash contact. You can join our newsletter and get a free ebook on security clearances. And also we have training specifically designed to help clear defense contractor employees better protect classified information. And this training is called Fundamentals of NISPPOM, and it is available at Bennett Institute.com, B-E-N-N-E-T-Tinstitute.com. We're also pleased to announce the training that we have that includes the defensive security briefing that you just download and present to your employees, or if your group is small, you can download and just pass it around via email. Now this is tailored training, and it's all the elements of NISPPOM required training. That includes initial security training, insider threat awareness training, defensive security training, derivative classifier training, and many, many more. Again, you shouldn't have to spend your time developing this training when you can just go to redbikepublishing.com, download the already developed training, and provide it to your employees. Also at RedbikePublishing.com, we have security books, risk assessment books, the NISPPOM, the ITAR, and many other books that discuss how clear defense contractors can get more business and protect classified information. Finally, one more thing if you need assistance with facility security officer or security training, please contact me at jeffreyw.bennet.com. Thanks for joining us at DOD Secure, and we look forward to seeing you at our next episode.