The rational for initial and refresher is because new employees are introduced to sensitive and classified government information and they should learn the fundamentals.
Here are some great topics; just so happens to be addressed in NISPOM: The nature of classified material and how to protect it. Notice of their responsibilities to protect classified information and the consequences of unauthorized disclosure Recognizing and protecting U.S. and foreign government classified material Criteria for authorizing access to classified information Responding to classified information released to the public Security chain of command and support structure for addressing security incidents and violations Cleared employees on foreign travel
For example, the newly cleared employee may not understand how to dial a combination or determine who to allow access to classified material. Without proper training, the newly cleared employees may make honest mistakes leading to security violations.
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Welcome to DOD Secure. And I'm your host, Jess Vincent. But today we are starting a new change. DOD Secure is now going to be referred to as NISPPOM Central. All of our books, information, and training can be found at NISPOM Central. And we'll begin phasing this new title in as we go through the next podcast. At any rate, we are glad you are here and we hope to teach you more about NISPPOM. And today's topic is on cleared employee training under the NISPOM. So if you're a cleared defense contractor or you work for a cleared defense contractor, you might recognize the need that comes out of NISPPOM or that requirement to conduct cleared employee training. And this cleared employee training is how people with security clearances learn to protect classified information and reduce risk to that classified information. If you have any questions about this topic, please contact us. You can contact us per our contact that can be found in the show notes or visit our website for more information. This next section is called Security Training and Briefings. Keep in mind that though we have posted insider threat training and security awareness training and derivative classifier training, that training meets NISPPOM requirements for cleared employee training. This section just briefs what those requirements are and they come out of the NISPOM rule. Contractors are expected to train and brief their cleared employees. While this is particularly done by the facility security officer, the cognizant security activity, or maybe the DCSA representative, will provide training to the contractors. And then the FSOs provide that to the cleared employee. This training includes security topics and security briefings. The training material is also available from the Cognizant Security Activities or DCSA's website, which includes the DCSA website called CDSE. There you will find many security topics such as security, threat awareness, insider threat, and other materials that clear defense contractors and employees can access to increase their understanding of NISPPOM. Now, contractors ensure that the FSOs complete required training as considered appropriate by the DCSA. So, for example, for um clear defense contractors that do not have possessing capability, in other words, they do not store or work on classified information on location, that facility security officer can complete the FSO orientation course within six months of being appointed. The FSO program management course is reserved for those clear defense contractors who do have storage capability at their facility as well as performing on classified information at their facility. And this is required for the FSO within six months of the storage approval. Additional training topics under NISPOM include CUI training. Outside of the NISPPOM requirements, this just basically means that this the training for cleared employees on the handling of controlled unclassified information is not covered under NISPPOM. However, it is applicable when a classified contract requires CUI training. At that point, DCSA may review this CUI training. However, we personally believe that it is important to understand, is important for clear defense contractors to understand what their level of involvement with controlled unclassified information is. Primarily, they should understand that they are handling controlled unclassified information. Therefore, it should be marked appropriately and controlled appropriately so that it is not disclosed in an unauthorized manner to those without access or need to know. Other training requirements found in NISPOM are as follows. Now the ones in red include insider threat training. So a threat awareness briefing is required, but it also includes information on insider threat awareness. Now this training is required prior to cleared employees having access to classified information. Counterintelligence awareness briefings, overview of security classification system, employees' reporting obligations are required, including that insider threat. Initial and annual refresher cybersecurity awareness training for all authorized IS users or information system users. Now, this is classified information systems. And usually this refresher cybersecurity awareness training is primarily required for clear defense contractors who access government information systems. And also security procedures and duties applicable to the employees' jobs. We recommend in this last category that the training be provided for cleared employees that reflects the statement of work requirements, the SF, the DD Form 254, SF328, and others, standard forms or government forms and signature items that are required for performing on classified contract. These should be incorporated into the training to give it a little bit more flavor. For example, employees that have five or more years of security awareness training or five or more years of working on classified contracts should get more information in their training than is usually required for personnel getting access to classified information the first time. Now, in addition, insider threat training requirements. These are for employees with insider threat program responsibilities. In addition to what was briefed earlier, as far as NISPPOM training requirements, these employees should be understanding counterintelligence and security fundamentals, procedures for conducting insider threat response actions, applicable laws and regulations regarding gathering, integrating, retention, safeguarding, use of records and data, including the consequences of misuse and such information. And then the applicable legal, civil liberties, and privacy policies. So it's our opinion that the insider threat program is a program that is in addition to other NISPOM requirements. The insider threat program is added to additional NISPPOM requirements, where NISPPOM demonstrates how to protect classified information using alarms, access controls, et cetera, that prevent outsiders from getting in. We believe NISPOM is written lately to ensure that authorized cleared employees are prevented from accessing classified information in an unauthorized manner. For example, in the procedures for conducting insider threat response actions, how will your cleared defense contractors report insider threat incidents? Who do they report to? And what are the actions of the insider threat program team? And we usually refer to them as the insider threat program working group. Now, the applicable laws and regulations regarding gathering, integrating, and safeguarding information, this should be applied to those on the working group who will be handling the insider threat reports. For example, not everybody in that working group should have information, uh, all information regarding an insider threat incident. Not everybody needs to know all the parties involved, just those people gathering, integrating, and retaining that information. It is also required that you safeguard reported information and understand how to record and use data in an authorized manner. There are consequences involved that the insider threat program team should consider as they collect, communicate, and safeguard this data about insider threat incidents. Also, understand privacy issues and responsibilities for gathering information on cleared employees. Insider threat requirements for cleared employees. Now, they address the current and potential threats in the work and personal environment. This protects classified information from unauthorized access as well as protects employees from threatening actions. Now, the insider threat program is required to detect potential insider threats, report suspected activity to the insider threat program designee, recruit and collection methodology used by an adversary, indicators of insider threat behavior, reporting procedures, counterintelligence and security reporting requirements as applicable. So cleared employees should understand what their role is in the insider threat environment. Now, this will require some actions. One is understanding what should be protected, setting up countermeasures that protect valuable information from authorized employees and putting those countermeasures in place so that these employees will be detected. While many clear defense contractors, FSOs, and ITPSOs use the 13 adjudicative criteria to develop reporting requirements for the insider threat. We recognize that insider threat reporting is an addition to those 13 adjudicative criteria. Those 13 adjudicative criteria are applied to that continuous vetting. We recommend more robust reporting requirements be put in place that go above and beyond those 13 adjudicative criteria, but leveraging those 13 adjudicative criteria during the investigation process. For example, if a clear defense contractor were to identify information to be protected, put in countermeasures to protect that information by its format. Is it hardware? Is it software? Is it a document or an item? And location, is it behind a locked door? Does it have access control? And then a sign need to know. Then we believe that triggers will be put in place that where an insider threat tries to gain unauthorized access, the clear defense contractor will have something to report. So focusing on protecting information and not focusing on the actual insider threat behavior may prove to have a more effective insider threat program. Security training and briefings that are required under the NISPPOM. Another topic is the derivative classifier initial training. This refresher training is required every two years, so keep that in mind. This training is provided for the proper application of derivative classification and in accordance with whatever DCSA requires or directs. Employees are not authorized to conduct derivative classification until they receive such training. And in the derivative classifier section, we will discuss what is um what derivative classification means. So who is best to provide this derivative classifier training? Is it the FSO? Is it the um or is it the subject matter expert or subject matter expert manager who can provide that information? Because we believe that this is technical information, and the right people should be teaching this course, unless, of course, the FSO understands what the technical data is and what is already identified as controlled and classified information. Not everybody is required to do derivative classification, but where it applies, the training is necessary. Derivative classifier training or refresher training is required every two years. If the cleared employees do not receive this training, their authority is revoked. Address classified classification levels, durations, identification and marking, prohibitions and limitations, sanctions and challenges, security classification guidance and information sharing. Now, these classification items that we should be addressing is the national classification system. Many are applied during the cognizant, not um during the original classification authorities review of information to be classified. Those same processes can be applied during the um derivative classifier training. The clear defense contracts do not classify information. However, there should be an actionable effort to evaluate information that the clear defense contractor is working with or producing to ensure its proper classification and control. While the clear defense contractor does not classify information, their responsibility is to identify instances where classified information is derived from other classified information or is compiled into a classified item or information. Now, the clear defense contractor should then, or the derivative classifier should then be able to date the training, the most recent training, you know, record the date and the type of training provided. So usually these are conducted with a role of who attended the training, the name of the training and the date, or a training certificate that can be displayed for DCSA review. Information system security training is required when a clear defense contractor processes classified information on information systems such as networks, computers, and other devices. The training requirement is to identify risks associated with user activities and what those user responsibilities are as they're processing classified information. Now, it's necessary to determine the content of the training, and this content should consider the roles and responsibilities of the user, the security requirements when working on classified information on the information systems, and what personnel are authorized to access access while using those information systems. Now, refresher training. Now, this is refresher training as far as security awareness training. That is done initially when a or conducted initially when a new employee or newly cleared person gets onboarded. Then it is required annually. Many defense contractors provide individual initial security awareness training or provide it to a group when they're being onboarded into the company. Whether or not they've received the clearance or have had a clearance before, it is important to give that initial security awareness training to help the new employee understand how the new organization or their new employer applies NISPPOM at their location. Now, refresher training is provided every year. This reinforces what was provided at the initial training, provides updates to NISPPOM or policy if there's any, and addresses any self-review issues or concerns, such as maybe lack of performance of security functions or security issues that have been discovered during the past year. Many clear defense contractors provide the annual security awareness training every 12 months, regardless of when the initial training was conducted, to get all the employees at one time. And again, it's necessary to record the training, record the title, the training, the date, and who attended that training. One of the FSO's toughest jobs is to make sure everybody attends training and gets credit for it. So there are many different ways to do refresher training. Doesn't always have to be an FSO-led or using PowerPoint like I'm using now. Group briefings, interactive videos, dissemination of instruction material, other media methods. I like to use newsletters as well as videos to do our training. We download videos that we've created at NISPOMcentral. And there are videos there that you can download and present to your cleared employees. Now debriefings are very important. Whether or not a debriefing is signed, it is important that when an employee no longer needs access to classified information or their employment is terminated, that they understand that they no longer have access to classified information, but they still have a responsibility to protect that classified information that's in their heads. They're not allowed to take it home with them. They can't email it to themselves. It stays with the organization. And again, remind them that once classified, as far as they're concerned, they cannot discuss it in a public area or with people who do not have need to know. Access should be terminated, suspended, or revoked. These debriefings will be required. If you have any more questions about training, be sure to visit Miss PalmCentral.com. We'd also like to thank our sponsors. Please visit them and their websites can be found in our show notes.