NISPOM Central-Working with National Industrial Security Program
Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.
NISPOM Central-Working with National Industrial Security Program
Security Clearances, Insider Threat Programs, Training
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
For some, the FSO designation is a career track with potential growth. For others, it’s an undesired appointment, part of doing business and just another additional duty.
However, this responsibility should be taken very seriously as classified contracts depend on success. Regardless of whether desired or appointed, the FSO is key to managing classified contracts.
Why not let Thrive Analysis Group Inc manage your FSO requirements while you focus on your core capabilities. We are uniquely positioned to equip your organization with FSO solutions and services.
While you may be appointed as FSO, you should delegate FSO responsibilities to us. We provide a wide range of managed solutions. Leave FSO tasks to a trusted partner.
FSO Solutionshttps://thriveanalysis.com/nisp/
https://www.redbikepublishing.com/insiderthreatprogram/
Online security clearance webinars and coaching. Providing security training and resources.
Most organizations attack the problem with either an employee tracking or online activity reporting goal.
After asking the above questions, we recommend a different solution. Of course the employee reporting and activity tracking solutions are important and part of the solution, but they should not be the end goal.
This book recommends a different application that can easily be implemented to both resolve insider threat issues and demonstrate compliance.
NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.
Clearance, NISPOM, and FSO Consulting
Thrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
FSO Consulting:
https://thriveanalysis.com
NISPOM Compliance
https://www.nispomcentral.com
https://www.nispom.com
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves:
I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
- Prepared commercial organizations for defense contracting and NISPOM compliance
- Designed ready to implement security programs before, during and after facility clearance award
- Rescued high risk security programs with quick turnaround; usually within 30 days
- Achieved Commendable and Superior DCSA review ratings
- Developed compliant FOCI mitigation programs
And today we'll be talking about the latest industrial security program operating manuals and how to apply them to your clear facility where you work. A lot of what I'm doing is speaking, writing, and developing content for facility security officers. For those of you who don't know, facility security officers and security specialists are responsible for implementing security programs under NISPOM at their facilities. What usually happens in what most of my clients that read my books and buy my training are FSOs by trade. That is their profession that they work in. Having said that, I've developed uh, you know, under Red Bite Publishing, I'm writing books and training and content for FSOs. But under my other company, Thrive Analysis Group, we recognize not every FSO is in there by career choice. In smaller companies and smaller defense contractors, the FSO is an appointed uh duty, so to speak. It is assigned to somebody in the company that is already busy enough. And while um it's not their full-time job, executing FSO responsibilities is a tremendous undertaking. And so, because of that, um, we've developed a capability to help these facility security officers by performing their tasks for them. And so this is a new part of our business that has kicked off, and just wanted to mention that because give you a little context because as I discuss some of the things that defense contractors might be faced with, keep in mind that you may or may not be an FSO. And if you are an FSO, it might be your appointed duty and not your career field. So I just want to give you those two points of view as we proceed further in this um discussion. For those of you don't know, um, I have a newsletter and a podcast, as well as those books that I told you about that discuss NISPOM-related topics. A lot of my podcast is reused information from the training that I put together as well as from um newsletters that I put out. So it might look familiar to you if you have the newsletter. If you don't have the newsletter, just go to redbikepublishing.com and go to the contacts tab, contacts tab, and you can register for our newsletter there. So what we'll be discussing today is the first topic is effective measures for the insider threat programs. Clear defense contractors appoint three key management persons that many of you may be aware of. These key management personnel include the senior management official who's responsible for verifying and certifying security programs, the facility security officer who is responsible for incorporating a security program at the contractor facility under NISPPOM. And then there's the other one, the insider threat program senior official or the ITPSO. They could be the FSO in a small enough company, the FSO, ITPSO, and SMO are the same person. But the insider threat program senior official executes a discipline that goes above and beyond the normal FSO role. True, a lot of FSOs do assume this role, but I like to think of the insider threat responsibilities as NISPOM plus. You've got your NISPOM requirements to report and prevent outsiders from getting into your facility to steal classified information. But there's also this insider threat point of view that we're supposed to be looking at, which is a different discipline. These require different methods, different countermeasures, and additional reporting requirements. When I wrote the book Establishing the Insider Threat Program Under NISPOM, I asked that question, you know, if we have the NISPPOM, why do we need an insider threat program? That's a very good question. Um, but what what is the NISPPOM guidance lacking? And what what do we need to add as a break? What is the NISPPOM guidance lacking that we need to add this additional emphasis? Well, after a lot of study, a lot of interviewing with FSOs, going to a lot of training under the insider threat program topic, the answer became pretty quickly that the NISPOM application prevents unauthorized persons from accessing classified information with those established controls that the FSO puts in place and that the SMO senior management official approves and certifies. Unauthorized persons will have difficulty entering these protective environments. However, we soon realize that sense of information is actually walking out of our organizations with our cleared employees. I like to think of the FSOs and other compliance officers, such as quality assurance or safety or um export control officials as being the guardians. And they're doing a good job with it. We have alarms, we have gates, we have guards, all those things to keep everybody out, and they're standing there. But then I see them standing there diligently, life-size giants, keeping unauthorized people out. But then I visualize employees with access, those cleared employees coming out of the facilities, fist bumping those giants as they walk out with sensitive information that is not controlled as it should be. So we realize that sensitive information is walking out, and we see that as some of our technologies are copied, or some of our technologies end up in the public domain, as we've seen in the news. We see it in the news where sense of information resides in unauthorized locations without removal being detected. A robust insider threat program is needed to focus on those gaps, you know, where the NISPOM is keeping unauthorized persons out. The additional emphasis on the insider threat program will focus on the information and prevent uh that puts in protective measures that detect access to sensitive information, whether they're unauthorized or authorized. I like to focus on information. This is key. The reason I focus on information is so that I do not have to focus on the employees. Um many FSOs build their security programs. Well, I don't know how many do, I say many, but I would tell you that training that is being put out right now focuses on employees and trying to detect which employee will commit espionage. That's a hard measure. That is a hard um uh metric to see. So, how do you measure if a person has committed espionage if they haven't done it before? And how do you measure if a person's committing espionage if you if you don't have anything in place to measure? A lot of times what happens is um somebody might call an insider threat event when an employee gets arrested, for example, or an employee um goes bankrupt or doesn't pay their bills. Well, these are reports that are required under NISPPOM anyway, under um um constant surveillance. We always have to report adverse information. It's already covered. That's not an insider threat event, that's an adverse information. If somebody gets arrested does not mean that they're going to commit espionage. So I like to focus on the information, determine what needs protected, set up countermeasures in place, set up an um public review process so that you can determine before something's released that to a measure of assurance that there is no um sense of information in that product that's going to be released, such as um speaking at seminars, writing white papers, writing patents. So many insider threat programs and working groups describe the problem, but they lack focus on solutions, on identifying which critical technology or controlled technical information should be protected. A lot of times information is not even identified as needing to be controlled, and that is something that we should fix. Training should not just describe the training requirements, but how to interpret and implement requirements specific to the information residing at your organization. So, like a successful insider threat program that will evaluate and identify the existence of controlled technical information. This could be controlled unclassified information, critical information, classified, ITAR controlled, export controlled, etc. Without taking that step, the insider threat program will not have a good understanding of what to protect. It's important that the organization identify that sense of information and how it resides within that organization. Unfortunately, insider threat program working groups focus only on employee behavior, and that is a mistake. It doesn't matter who's trying to steal your stuff, you should put triggers in place to identify when those activities take place. That way you're not focusing on a culprit that you don't know who it is, but you're focusing on their actions that can be detected. So when only focusing on employee behavior, the trend is to evaluate using those 13 adjudicative criteria, which you know it talks about allegiance to other countries, um, sexual behavior, um alcohol and drug abuse, or violating um information system uh plans or trying trying to go around security plans. Now, going around security plans and violating information system plans, those might be indicators of insider threats. But the other parts of that 13 of GDK criteria, if you're not familiar with what those are, go to our archives and you can see what those 13 of GDK criteria are. But it doesn't identify what an insider threat behavior is. So by explanation, NISPOM requires clear defense contractors to protect classified information and establish reporting requirements for security incidents and violations. And there's guidance out there under SEAD3 and other guidance and reports, adverse information reports that are required under NISPPOM. NISPPOM spells out the protection, the training, and reporting requirements that must occur. Additionally, the NISPOM provides requirements that go above and beyond traditional NISP guidance. And these are specific to the insider threat program. So if there are reporting requirements under the insider threat program, they should be above and beyond those 13 adjudicative requirements. Since those are already required, the insider threat program, in my opinion, should focus on additional reporting requirements not covered under those 13 adjudicative criteria. So the designation of an insider threat program senior official, in addition to the required FSO, should cover this. While they could be the same person, their focus is different. You could have a successful insider threat program with the ITPSO and the FSO as the same person. My point is under the insider threat program, there's a different skill set that any FSO could learn and could apply. I'm not saying they should be different. I'm just saying different skill sets. So the mistake would be to perform traditional NISPOM requirements and record those as insider threat compliance. For example, if an FSO reports that a person who has been arrested for DUI or otherwise triggers an adverse information report, the mistake would be calling that an insider threat event when no insider threat event actually occurred. Adverse information is different than insider threat information. Just keep that in mind. So adverse information and security violation reports are already required and they serve a purpose in the continuing evaluation process. They may be used during an insider threat report. It can be leveraged and can be used as part of the investigative process. Just committing that risky behavior that might put classified information at risk. Doesn't mean that it is at risk, but it could be put at risk. However, filtering and triaging reports or reporting behavior may lead to indicating insider threat activities, such as introducing unauthorized devices in a secure area, bypassing security controls, consistently trying to access information outside of that need to know. So the insider threat under NISPPOM, what are those requirements? Requires detecting, reporting, and responding to insider threat events while applying specific and focus activities by an insider threat working group. So successful application of insider threat programs may require focus on information to be protected, determining what needs to be protected, applying countermeasures and enforcing need to know, monitoring those measures, that will lead to better insider situational awareness. It will also lead to detecting insider threat activities and direct threats to protected information and environments. So here are four proven ways to do this. Establish a working group to identify that controlled technical information. Remember, it's CUI, could be classified, could be critical items, ITAR, export controlled, etc. Include in there your program managers, your engineers, your software designers, those technical experts. Document that controlled technical information. Establish protective measures found in policy and guidance, such as in the NISPOM and in the ITAR, and anything specific to that sense of information as it resides. And then train employees to identify those threats to protect the information and report them appropriately through those insider threat programs. Remember, there's already an FSO reporting program in process. Now you need an insider threat program reporting process. So many protective measures are in place that prevent unauthorized access. We got gates, guards, alarms, locks. Efforts such as following these are geared toward protecting sense of information from walking out with trusted employees, not just stopping outsiders from coming in. So label and identify that sense of information and establish a public release review process before you release anything into the public domain. So it has a chance to go through that process. So consider forming working groups with enterprise members such as folks outside of the security discipline, maybe contracts, maybe safety, maybe HR, as well as those program managers and software developers. So we've provided some solutions here for you. Hope you find them useful. We are definitely experts in this area in identifying sensitive information. Now, if you derive sensitive information from other classified contracts information, run tests or otherwise create products under a contract, you should be controlling that derived information the same way. So make sure you get your derivative classification training as well as your insider threat program training and your security awareness training. If you need help with any of that, you can contact me. My information is here for you. Hi everybody, I want to introduce you to a brand new sponsor. We're so glad to have Access Commander by MathCraft. At Access Commander by Mathcraft, we believe security risks and lack of compliance are threats to a business and its people. We strive to provide our clients with the tools they need to stay compliant and prepare for the next generation of threats. Through comprehensive training, support, and customer resources, we transform our clients into security professionals with the know-how to defend their organizations and maintain comprehensive security programs. We support the mission of the FSOs, CSOs, and other security professionals who stand at the front door of our nation's battle against foreign domestic threats. With software designed to the latest federal standards, we help them to strategize, speed up self-auditing processes, create new workflows, generate reports, and retrieve tactical information at a moment's notice. For more information on ways we can help, visit www.mathcraft.com or call us at 703-729-9022. Alright, so our next topic today is going to be about that security awareness training. This is something that every cleared employee should be going through. Now the National Industrial Security Program operating manual, or that NISPOM, lists required training for each cleared employee. New employees are required to have that initial security training, and this ensures that they understand what the threat awareness is, a defensive security briefing, overview of the security classification system, employee reporting requirements, and security procedures and duties applicable to their jobs. So if they're an engineer, what should they do to protect classified information? If they're a software designer or if they work off-site at another location, what are their responsibilities? These topics are important because they give that cleared contractor employee a good idea of what is classified, why it's classified, and how to protect it from unauthorized disclosure. Well-trained and enabled employees drive the enterprise security program headed by the FSO and approved by that senior management official. So the threat awareness briefing is the next part. And it helps cleared employees uh understand what they that there are people who want that information. These people have techniques and have modus operandi to get access to classified information. Employees should understand some of the these threats and how they act to recruit them. This can be also part of that insider threat program that we talked about earlier. Now there's a defensive security briefing. That's the next step. This is training that goes into detail about how an adversary may approach an intended victim to get their sensitive information. The overview of the security classification system provides cleared employees with answers to how information is classified, the criteria that is used, and how this decisions are disseminated by the government. Now, the important employee reporting obligations and requirements are follow the continuous vetting and should provide resources for reporting certain types of information. Again, those 13 adjudicated criteria, security programs and procedures and duties applicable to that employee's jobs. This is the real meat. This goes beyond the national classification system. It's how do I do my job? How do I perform my classified projects and still maintain my security requirements? Great tools for this training, including reviewing the DD Form 254, looking at security classification guides, the statement of work, and requirements documents. The key to ensure a properly trained employee and document that training. Let them know they're being trained, tell them they're being trained, and remind them that they received training, as well as get their signature and document that occurrence. That way, when you get your audit, you can demonstrate to your representative that. That training has been completed. Now, training cleared employees to perform unclassified contracts is the first step to great industrial security program. And NISPOM outlines these required topics, but enterprise FSOs can make that training more applicable. So if you're hurting for um training ideas or you need assistance with your training, we do that as well. Um I'm currently writing training for two organizations right now, specific to what they do. And we also have um training available to be downloaded. And I'll put the link in our um notes so you'll be able to see that. But it's at Thriveanalysisgroup.com. And now if you'd like assistance with these training tasks, just contact us or assistance with FSO services. We'll be happy to help there. All right, I would like to tell you now, uh give you a special message from SIMS Software. S-I-M as a Mike S software. As clear defense contractors, you represent the backbone of innovation, the front line of our national security and protectors of all that we hold dear. SimS Software is proud to be your ally in these endeavors. As most trusted name in industrial security information management for over 38 years, SimSoftware equips you with the tools to protect the lifeblood of your organization. Our flagship Sims Suite provides all the features and functionality you need to run an automated, paperless industrial security program. Gain a 360-degree view of every physical, virtual, and human asset inside your security domain. From classified documents and materials to cleared personnel, facilities, visitor control, information systems, and more. Visit Sims at simsoftware.com or call eight five eight four eight one nine two nine two or see our show notes for more information. The last thing we wanted to talk about today is security clearance, an overview of adjudication. Adjudication means is the last step that an adjudicator takes to uh determine whether or not somebody can be granted a security clearance. The security clearance uh request process is finalized during this adjudication process. It begins with um notifying the employee that they the the employee is the key part, and uh they have to be an employee of the company and associated with a classified contract. Then the FSO puts them in for their security clearances. They they begin with filling out that SF 86. Now, here the decisions are made under the adjudication process whether or not to grant a person a security clearance. The adjudicator evaluates the results of the investigation to determine whether or not an applicant is suited to protect classified information. So there are 13 categories, and we'll go over those in a little bit, that could prevent a person from getting a clearance or prevent the continuance of a current clearance. Simply put, the adjudicator evaluates an investigation results and makes that decision. Now, if there are indications that is not in the best interest of national security, then a clearance will not be granted. It will be denied or revoked. Now, sometimes the mistakes happen, you know, with a cleared employee in their past, and investigations don't provide that complete whole person profile. So when that happens and a clearance is denied, or the investigator may have more clip more questions, the applicant can put in mitigating factors. There are ways to overcome some of these red flags that might come up during the investigation. Now, this provides the process that allows an employee the opportunity to appeal or turn around unfavorable security clearance adjudication. Now, one of our sponsors I'd like you to visit is um is is Ron Sixtus. Now he helps people with this adjudicated process. So if you have any questions, give him a call. His contact information will be in the notes as well. Now so what can a person do when they have been denied or a security clearance or has their security clearance revoked? Now the NIST provides that process. Where there was no earlier process or consistency in policy, the NISPOM provides standards for addressing the security clearance denials or revocations. So going back to decision-making stage, the adjudicator reviews the investigation and focuses on those 13 criteria. The goal is to determine whether or not an applicant can be trustworthy to adequately protect that classified information. Again, the adjudicator will lean towards national security. So here are the topics: allegiance to the United States, foreign influence, foreign preference, sexual behavior, personal conduct, financial considerations, alcohol consumption, drug involvement, emotional, mental, and personality disorders, criminal conduct, security violations, outside activities, and misuse of technical information systems or information technology systems. Now the adjudicator will consider that whole person concept that I spoke about earlier. If the subject has violated one or more of these criteria, they could still be given their clearance. The adjudicator will consider all mitigating circumstances before making a final decision. So the circumstances including that, the following are compared to each of the 13 topics. So for example, um the adjudicator will consider the nature, extent, and seriousness of the conduct, the circumstances surrounding the conduct. You know, maybe you're coerced, maybe you are impaired, and which includes knowledgeable participation or ignorant participation. The frequency and the time elapsed since the conduct. So something happened 40 years ago, 10 years ago, it may be overcome by events, it may not be a factor anymore. Then the individual's age and maturity at the time of the conduct and the willingness to participate. So what happens then when the adjudicator considers all available information that denies or revokes that clearance? Well, the applicant can appeal. Um, perhaps in the information, all the information wasn't provided or the investigator missed something. The applicant did not provide enough information at first, so the applicant has another chance to submit mitigating factors. So this process allows the applicant to go to court or have an administrative judge make a decision. In both cases, the adjudicator and applicant can present their cases for a judge's decision. And the judge will make that determined again, determination again based on national security. So for those currently holding clearances, undergoing investigations, or considering working in an industry where background information or investigations are conducted, act accordingly, right? You don't want to put that clearance in jeopardy. If it is necessary to explain or mitigate questionable past or current behavior, gather the necessary information, get some witnesses, get some evidence that will support decisions to grant your clearance. The final decision will be made in the interest of national security, and the applicant influences that decision. So this concludes um our podcast. And if you need any more information, contact us. You can get me at jb at thriveanalysis.com or editor at redbikepublishing.com. I'll have contact information in the show notes. And I've mentioned a lot of books that I've written and training programs that I've created, as well as the services that we conduct. I also invite you to visit our sponsors as well. Again, you can find everything in our show notes. Have a great day. If you have any questions, send them our way. In spite of living a life. Once again, I thank you for joining DOD Secure. This is your place to go for all things in this contract for help requirements and all things security clearance. We hope you're coming back for another episode. And please look at our show notes and you can find more resources that might answer your questions. How do I perform once I win a classified contract? And what do I do once I get a security clearance? And the other question is how do I get a security clearance? We are here to help you.