NISPOM Central-Working with National Industrial Security Program
Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.
NISPOM Central-Working with National Industrial Security Program
Determining security costs, protecting CUI, FSO training and more
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
A cleared contractor can help reduce expenses with by preparing ahead of time. This is where an experience FSO can anticipate expenses, perform risk assessment while implementing NISPOM and advise on ways to reduce costs while being compliant. The more money saved on overhead expenses, the greater the overall company profit. The earlier into the process the assessment is conducted the better the company performs overall.
It's a common practice to allow employees to use enterprise computers outside of the enterprise. This has become more common where employees are increasingly working at home. Though a common practice, these occurrences are not always best practices. Anytime an employee leaves work with a company computer, the expectation is that all information is vulnerable.
Protecting classified material – The proper receipt, accountability, storage, dissemination and destruction of classified material. Link to CDSE training https://www.cdse.edu/
Required training – This instruction helps the FSO establish an ongoing training program designed to create an environment of security conscious cleared employees.
Personnel security clearances – The FSO gains an understanding of the personnel security clearance request procedure, briefing techniques and maintenance of personnel clearances.
You can find study recommendations, practice questions and NISPOM links at https://www.redbikepublishing.com/ispcertification/ and https://bennettinstitute.com/course/ispisoctipis/
If you need assistance with FSO or security training please contact me or visit my consulting site www.jeffreywbennett.com. Additionally, we have NISPOM fundamentals training perfect for studying and applying to your CDC facility. https://bennettinstitute.com/course/nispomfundamentals/
Jeff is available for speaking and consulting
NISPOM Central
Providing security clearance books, training, and resources for cleared defense contractors.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
FSO Consulting:
https://thriveanalysis.com
NISPOM Compliance
https://www.nispomcentral.com
https://www.nispom.com
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
- Prepared commercial organizations for defense contracting and NISPOM compliance
- Designed ready to implement security programs before, during and after facility clearance award
- Rescued high risk security programs with quick turnaround; usually within 30 days
- Achieved Commendable and Superior DCSA review ratings
- Developed compliant FOCI mitigation programs
Welcome to DOD Secure and I'm your host Jeff Bennett. With the latest and information that you need to navigate the world of clear defense contracting, we'll cover a few articles as well as introduce you to our proud sponsors who provide goods and services that assist other clear defense contractors with their day-to-day activities, just making their lives so much easier. So stay tuned to information as well as our sponsors' advertisements that might just help you. So today we'll be talking about why the FSO and the DD Form 254 and the budget are important to be incorporated together. So let's get started as this may take a while. Alright, so what do the facility security officer, the DD Form 254, and the budget have in common? Right, good answer. They all need to work together to provide an efficient security program to protect classified information. So there are all kinds of opportunities for the cleared defense contractor to ask questions and determine the security needs even prior to signing the contract. So this is where an experienced facility security officer can come in. They can anticipate the expenses, perform a risk assessment, all the while supporting and implementing the National Industrial Security Program operating manual. The manual that advises and discusses security measures and gives security guidance to clear defense contractors. And so the FSO can interpret the NISPPOM as well as anticipate costs of supporting the NISPPOM that they the defense contractor organization can prepare for ahead of time. The more money saved on overhead expenses, which is normally where the facility security officer charges to, the greater the overall company profit. The earlier into the process the assessment is conducted, the better the company performs overall. So for example, maybe a clear defense contract requires the storage of classified documents. If the storage of classified documents includes maybe 25 or 30, that's easy. One security container can handle that. So for a $3,000 investment, that um that may not be too much to prepare for and it might be handled very well under the contract. But suppose the contract involves three or four hundred contracts, closed areas, and supporting equipment. Well, that may need to be put into the budget as well as put into the bid so that the declared contractor can be prepared to conduct the work. Timing is key as some of these security requirements depend on the approval of the cognizant security agency. So as a reminder, the Defense Counterintelligence and Security Agency, or the DCSA, is a cognizant security agency for the Department of Defense. So conducting the assessment or coordinating with DCSA after committing to the contract may place the contractor in a tough position. So reviewing the contract requirements, recording with CD with DCSA early will put you in a good position. Coordinating late or after the contract is awarded and then determining what your contractual needs are to protect classified information may put you at a disadvantage. For example, if you find out that you need to commit resources and time to dedicating a room to as a closed area and doing the construction necessary will be an expensive endeavor if you're not prepared to do so. Planning too late could prove costly. So a facility security officer should facilitate a team of organized leaders from all disciplines of the organization and create a successful security plan and budget. So this team could consist of a program manager, engineers, security personnel, contracts personnel, or other managers responsible for developing business with the prime contractor or the government contracting activity. So this team, regardless of individual duty description or organizational structure, should be able to speak for the company and commit the company to perform as the contract specifies. So as part of this group, the FSO provides information and guidance on the best way to protect classified information in the process. So this could, this positive activity or proactive activity, could translate into significant cost reduction. So understanding how to advise and assist in the development of the DD Form 254 is very fundamental. The DD Form 254 talks specifically about how the contract should be executed and how classified information should be protected. So the budgeting should be determined by the DD Form 254. It provides a groundwork for ensuring the GCA requirements are clear, applicable, and understood. So since the government provides the protection requirements, getting in on the ground level and costing out these requirements can only benefit the contractor. If you'd like more information about this, feel free to contact me at editor at redbikepublishing.com. And now a special message for our listeners from our proud sponsor, Sims Software. As clear defense contractors, you represent the backbone of innovation, the front line of our national security, and protectors of all that we hold dear. SimS Software is proud to be your ally in these endeavors. As the most trusted name in industrial security information management for over 38 years, SimSoftware equips you with tools to protect the lifeblood of your organization. Our flagship Sims Suite provides all the features and functionality you need to run an automated, paperless industrial security program. Gain a 360-degree view of every physical, virtual, and human asset inside of your security domain. From classified documents and materials to cleared personnel, facilities, visitor control, information systems, and more. SIMS supports requirements within all security communities. To learn more or schedule a demo, visit www.sims software. SIMSSOFTWARE.com or call 858-481-9292. Let's discuss protecting controlled unclassified information on work computers. Now this is an interesting topic and one that I'm very familiar with because of the type of work that I do and the vising that I do. Now I'm not talking about sitting on the enterprise network and responding to emails and making sure I don't open something up that may contain malware or ensure that as I work on my daily activities in the office on the network that I'm doing the right things to protect CUI. I'm talking about removing the work computer from its protected environment and taking it on the road. Some examples of this happening are maybe you're going to a presentation where you need to bring your work computer. Maybe you're allowing your employees to bring a laptop home and to attend training or college or other events. There are many reasons, legitimate reasons, why somebody should be able to remove their computer from the work environment and take it with them for personal or professional reasons. I like to talk about this situation because again, it removes this computer from a protected environment and leaves protecting that computer solely to the individual using it. So it's a common practice to allow employees to use enterprise computers outside of the enterprise, especially during this time of COVID where people are teleworking. This has become more common where employees are increasingly working at home. This is a common practice, and these occurrences are not always under the best of situations. A thorough risk assessment should be made and a thorough plan should be made to ensure that the employee is protecting the information. Also should, which another thing that should be considered is what information are they allowed to use, are they authorized to use at home, and how is that information protected from being vulnerable? Anytime an employee leaves work with a company computer, the expectation is that that information will be vulnerable. Ransomware, malware, supply chain attacks, hacking, and other threats are prevalent. Now, my thought is if an employee takes home information and it's minor information and does not involve high-risk information, then if an attack occurs, nothing's being removed from the computer. But again, this should be part of a risk scenario. What information is the employee taking home? How should it be protected? In many cases, this can be controlled through applying NIST standards and strong cybersecurity measures. So we'll focus on limiting the use of loan laptops to what is completely necessary and not on technical cybersecurity application. For example, I'm not going to tell you which software to run, you know, which firewalls to use. I'm going to discuss what actually needs to be on that computer and how to determine that. So clear defense contractor or a contracting organization should assign a strong risk assessment based on use prior to assigning a company computer for home use. This risk assessment should limit the information to be provided and for specific purposes only. For example, if a user works on a specific project, the laptop might only contain that information that they need for that specific use. The laptop removed for home use should not contain all information available unless that information is absolutely necessary. For example, if somebody is working on a project on a classified contract or any contract, they should limit that computer to that information necessary for that one project and not the entire program. This goes along with the need to know, as well as identifying what information should be protected and what should be removed on this classified computer or this unclassified, but this work computer. Even though there may be a strong policy and cybersecurity requirements required by the organization, the CUI on the computer is still vulnerable to the whims of whether or not the employee will follow that technical guidance. So limiting the information on that computer may be the best practice. A specific example of a common but not best practice is to provide an employee a computer to take home. In this example, maybe they're using it for college. In this case, employee would take the provide laptop to college, to their home, to the restaurant, to the cafe, any places along the way. They may contact connect to a Wi-Fi and choose not to use a VPN. This would leave any information stored in the laptop vulnerable to exploitation. The organization should also expect to have any number of hacking, thieving, or destroying attacks put on that computer. This is a high-risk activity of the laptop that contains CUI. However, a low risk of the laptop does not contain any information. For example, yeah, so using this example, the laptop that contains CUI is a higher risk laptop than any that does not contain CUI. So the point is to control the data, not the laptop. If assigning laptops for non-business or even professional use, it should be provided with only the information absolutely needed and with the right protections. Performing work with CUI should be limited to the CUI necessary to accomplish a task and with the controls in place required to protect it. So the policy should not only be protect all CUI, but the policy should include which CUI should be on that computer that leaves the premises and the protective measures to ensure that is not at risk, or at least at a major risk reduction. If assigned for non-CUI tasks such as college or professional development, no CUI should be on that computer. Now think about it. This would mean that instead of the employee bringing home a laptop that is assigned to them for day-to-day use at the office, you might consider loaning or assigning a computer that is completely wiped of their daily tasks and provided with only the adequate information they need. Again, this um the recommendation is to limit the information and not the use of technology outside of it of the organization. Laptop issuing risk management should identify contingencies for which astute technology control officers, export compliance officers, and security specialists should plan. Sensitive and protected technology should not be contained within the computer and related media without the proper permissions. The example is includes the fact that exports violations, you know, violations or export issues that are under the International Traffic and Arms Regulation should still be protected on that computer because now an export violation can occur within the United States as long as an adversary exfiltrates that information, sees that information on the computer screen or otherwise, that constitutes an export violation. Consider the following export controls and applying these to the best practices in your risk assessment of determining what information should be removed on that computer that you are signing to your employee to take home. Foreign governments want U.S. technology and aggressively seek it. And defense contractors should make the information very difficult to get. Cyber hacking, supply chain attacks are increasing, most definitely calling for stronger controls. So we we see issues of ransomware, we see issues where information is removed from computers, and so we need to figure out a way to allow this work to be done offsite and at low risk. So relying on these technical controls is definitely not enough. Often appointing too many resources for actions that don't address the real threat. For example, physical security efforts may focus on forifying laptops with firewalls, barriers, alarms, access to control, and etc. These are important, but the employee may make information vulnerable the first time they use a public Wi-Fi without first logging into a VPN, for example. Risk assessments include technical controls and limiting data to be used in the laptop. CUI is leaked through careless or malicious employee behavior or actions taken due to poorly understood responsibilities and security disciplines. So export compliance officers, facility security officers, and other leaders should develop a culture within their organizations to prevent unauthorized disclosure of economic, classified, and sensitive information. Such practices include destroying sensitive waste properly, locking all desk and cabinet drawers after work, and using access control to keep employees, vendors, and non-US persons from accessing the unauthorized areas. And these unauthorized areas do include computers that are removed for outside use. So one of the important tasks would be to identify what the control unclassified information is. Be specific in your technology. You know, any information that provides intimate details about a program is considered CUI. And so we did a podcast a couple of years ago with a company called Management Analysis Network, and they talk about exactly how to identify sensitive information, whether it be employee PII, um, social security numbers, contracts information, HR information, or even um intimate details about a program. These should be identified by item and so that the employee can understand how to protect it as well as determine what actually needs to be provided in that take-home computer. So prov prior to providing or removing any devices with controlled and classified information, these employees should understand the risk. Don't take it lightly, give them a thorough briefing on how to protect it and then also an understanding of you know how to limit what they are removing. A defensive security briefing is for cleared employees who travel overseas, who may become vulnerable in foreign countries or recruiting methods. These are similar types of training could be tailored, you know, to give you a tool and given to all the employees who remove this information from the enterprise. The risks are still the same. We're just trying to protect CUI within our borders. Now, if technical data and laptop computers will be removed from the organization, the CUI and other sensitive information, export controlled information, not under license or TAAs, should be limited to the need to know to perform the necessary network or the necessary work. Also consider a communication strategy. What information is going to be allowed to put into the public domain or be allowed to put into press releases and announcements. Anything that is not allowed should be scrutinized prior to removing it. And also make sure you have a process in place to approve the removal of information on that laptop. So if you have any more questions, you can contact me at editor at redbikepublishing.com, and I'll have some links to my websites and how to contact me or even um Ron Sixtus, which is who is a security clearance lawyer, and you'll hear his commercial a little bit later. I'd like to take a moment to recognize one of our sponsors, and that's Mission Driven Research. And they can be found at www.missiondrivenresearch.com. And Mission Driven Research is a growing company providing technical services to U.S. federal government. The goal of MDR is to continuously improve performance in three core values. This mission focus is the core of MDR and fosters a highly satisfying work environment, motivating employees to excellence. And so if you get a chance, go buy there. Visit their website at www.mdr.com. So, this next topic will discuss required training for the cleared defense contractor. Now, there is required training for cleared contractor employees who perform on classified contracts. Well, this training I'm going to talk about today is training that is available from the U.S. government to the person who or the people in charge of protecting classified material within the cleared contractor organization. So the U.S. government's Center for Development of Security Excellence, or the CDSE, offers training that can help the security manager better protect classified information. And this training has several different topics. And this is something that each of the facility security officers and their staff, if the company is large enough, should undertake. The training is valuable as FSOs will have an opportunity to learn about their responsibilities. Sometimes a new clear defense contractor and their new FSO will be learning for the first time exactly what is expected of them after they win the contract. But I'm going to give you some clues into what is available at the CDSE and so that you can have your one-stop shopping for the training so you can better understand what will be required of you. Or if you're an existing cleared defense contractor or existing FSO, you may not know these resources, and so I'm just relaying them to you. So after this training, the FSO is then authorized to present the rest of the training to the organization's cleared employees. So according to the NISPOM, the FSO is also required to attend mandated FSO program management courses within one year of their appointment. So this means that the cleared contractor should be prepared to send a designated employee to the academy for training or take that training online. So the CDSE provides new courses that are designed for the FSOs of possessing and non-possessing facilities. Simply means FSOs of facilities that have clearances, but either do or do not perform unclassified work at those facilities. FSOs should coordinate with their representative to determine the training that's right for their situation. And this training is designed to prepare the FSO once again to implement and direct a NISPPOM-based security program in their cleared contractor facilities, and including to, but not limited to the following topics. So first topic is protecting classified material. And this teaches the proper receipt, accountability, and storage and dissemination and destruction of classified material. Now there's another topic called required training, and this instruction helps the FSO establish an ongoing training program. And again, this training program is not designed for security experts, but designed to allow the other cleared employees, such as engineers, program managers, and others, to create an environment of security conscious cleared employees. In other words, how do you work on this classified contract and protect the classified information under your charge? Personnel security clearances is another topic, and the FSO will gain an understanding of the personnel security clearance request process, the learn briefing techniques, and the maintenance of personnel clearances. Another training topic is called facility clearance, and this teaches the FSO how facility clearances are established and which records and activities and documentation are required to maintain the security clearance level. Another topic is foreign ownership control and influence, or FOCI. Now the organizations analyze their foreign investments, sales, and ownership on a regular basis using the certificate pertaining to foreign interests. And this is the SF 328. So here the FSO will learn to interact with management and provide guidance and direction in preventing a foreign entity from unauthorized access to or controlling work that involves classified information. So the FSO will learn their points of contact and how to assess whether or not or to what level their organization is under FOCI. Export compliance and international operations is another topic. Here FSOs receive instruction on how to prevent unauthorized disclosure of critical technology, classified and export controlled information. Also teaches about the licenses and restrictions of that intimate data. Restricted areas. This teaches FSOs how to establish a restricted area. And a restricted area is primarily established to control temporary access or temporary work to classified material. Now closed areas is a dedicated space to approve and store and work with classified material. It involves approved construction and limiting access controls to prevent unauthorized disclosure during and after work hours. Another course is teaching the specifics of the DD Form 254, which is the contract security classification specification. We've talked about this form many times and it lists what classified work is to be performed, where it is to be deformed, and many, many details. The cleared contractor is allowed to access classified contracts based on this DD Form 254. And so the FSO would learn here how the DD Form 254 is constructed and how to provide input to better meet security requirements. So another course is security classification guides. You know, the DD Form 254 provides authorizations to execute the classified contract. The security class guide or SCG provides the how-to. It tells you what is classified in which situation it's classified in, how long the classification should endure, and much more. Another course is security administration and records keeping. This teaches the maintenance of facility and personnel security clearance information as well as all other documents for accountability. The FSO is expected to provide information on personnel clearances, original documentation and their facility clearance, and demonstrate classified information accountability during the annual security inspections. Another course is subcontracting. When approved to subcontract classified work, the prime contractor will provide a DD Form 254 to the subcontractor, and this course teaches the specifics of that relationship. So the CDSC, we'll just call it the Academy, issues a certificate which could be filed for presentation during security audits. The FSO training should not end with this course. There's also career-enhancing training available to various security and management courses. More in-depth online and residence training is available in each of the above-mentioned topics. You can take these online at the CDSE website, and I'll post those, that information on our podcast page. Other agencies may offer more training certification in special access programs, Comsec, Intelligence, and etc. Other training is available in colleges, professional organizations, vendor websites, through books like many that I've written and with the security community. So you can find study recommendations and practice questions and certain types of NISPPOM training at the CDSE website. Again, I'll post that, or at redbikepublishing.com or Bennett Institute.com. We're so glad to have Access Commander by Mathcraft. At Access Commander by Mathcraft, we believe security risks and lack of compliance are threats to a business and its people. We strive to provide our clients with the tools they need to stay compliant and prepare for the next generation of threats. Through comprehensive training, support, and customer resources, we transform our clients into security professionals with the know-how to defend their organizations and maintain comprehensive security programs. We support the mission of the FSOs, CSOs, and other security professionals who stand at the front door of our nation's battle against foreign domestic threats. With software designed to the latest federal standards, we help them to strategize, speed up self-auditing processes, create new workflows, generate reports, and retrieve tactical information at a moment's notice. For more information on ways we can help, visit www.mathcraft.com or call us at seven zero three seven two two two two two two two two two two nine nine zero two two. And it's under the chapel chapter that talks about international operations. So this these questions are to put you in a scenario or a position and situation that will be described to see how you would handle it. So it might be a good exercise if you're driving down the road or or in a location where you can actually think about these. And so let's give it a shot. Situation number one. Now suppose this item needs a license prior to export. What steps would you take in consideration of a possible export? And the other question is if the item is to be delivered to a foreign company just down the street, will export requirements still apply? And why and why or why not? Situation number two. You are traveling as an authorized courier to deliver a package that contains classified information at the confidential level. Upon arrival, the federal government customs agents or the foreign government customs agent wants to take custody of this package. You present your credentials and attempt to walk out of the area or talk them out of the idea of looking at it. She informs you that as a representative of a foreign government, she is authorized to accept the delivery. Is she correct? Why or why not? Situation number three. As a facility security officer, you have many responsibilities, including approving classified visits. So a program manager enters your office and informs you that his foreign government customer wants to send an employee to perform at your location on a classified contract. The program manager requests that you draw up a sample visit request form that the foreign company can use to submit a visit request. Is this the proper request for procedure? Why or why not? Number four, in the same situation as the previous one, the visit has been authorized through appropriate channels. Since your clear facility handles many classified contracts, you want to ensure that the visitor does not gain access to classified and unclassified items not authorized for export. What will you produce to ensure that the visitor and company employees remain in compliance with export laws? Part A of question four is which agency has jurisdiction over commercial and dual use items? b which regulation covers commercial and dual use items? And C which regulation governs the export of defense articles. And finally, question five or situation five. Your organization has an opportunity to perform a modification of a foreign government weapon platform. You will not be selling the item but modifying the platform for a radio mount. If awarded the contract, your company will send a team to the foreign company to perform the services over the next few years. What type of request will you submit? And who is the approving agency? Anyway, these are tough questions, and I would invite you and encourage you to buy the book because many answers are in there, as well as look at the ITAR and the NISPPOM where you can find these answers. You're filling up the SF 86 and suddenly you realize you have red flags. You need good advice before submitting it. Get Ron involved as early in the process as possible, and it is always best to have him review your problem questions and answers before you submit that SF 86. You can call Ron Sixtus at 256 713 0221 or email him at R Sixtus. That's R-S-Y-K-S-U-S at Bonds or at Bond B O N D, the letter N B O T E S dot com, or visit his website at www.securityclearance defense lawyer.com. And thanks again for joining us for DoD Secure. Remember, I'm your host, Jeff Bennett, and we'd love to hear from you. If you have comments about the show, please contact us at editor at redbikepublishing.com. And we'd love to hear your review of this from whoever provides your podcast. Please find links to our sponsors as well as information about the topics that we've provided today at our links, at our article, or at our um podcast page. There you'll be able to find out more information about these topics and do your own research. Thanks for attending, and we'll talk to you next time.