Jeff Bennett of Thrive Analysis Group discusses how FSOs can shift from reactive “scramble mode” to a proactive, audit-ready NISPOM program that consistently passes DCSA security reviews. He explains why many FSOs—especially in small companies where the FSO wears multiple hats—get overwhelmed, and notes that daily tasks can be delegated even though authority and audit responsibility cannot. Bennett outlines what DCSA looks for: alignment between the FSO and the senior management official (who owns the program), the ability to demonstrate NISPOM compliance with artifacts, clear explanations using anecdotes, and employee buy-in demonstrated through awareness of the program. He recommends maintaining an FSO workbook on a secure shared drive to store compliance artifacts, using standardized forms (not email) to collect required employee information for actions like foreign travel and visit requests, and keeping briefings, trainings, and reports updated to remain continuously review-ready.
00:00 Welcome and Overview
00:45 Why FSOs Go Reactive
02:15 Delegate and Ditch Email
03:15 What DCSA Reviews
04:38 Employee Buy In Matters
05:33 Build the FSO Workbook
06:55 Forms for Every Task
08:27 Always Audit Ready
09:03 IG Inspection Story
10:44 Wrap Up and Next Steps
NISPOM Central Providing security clearance books, training, and resources for cleared defense contractors.
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Welcome to DOD Secure, and I'm your host, Jeff. Well thanks so much for joining us today for a very important discussion that we're going to have in this podcast. Hi, I'm Jeff Bennett and I'm with Thrive Analysis Group where I perform FSO and NISPOM consulting. I'm also from dot com where we have FSO books and training. And welcome to today's podcast or YouTube video. Wherever you're listening from, thanks for joining us. We're going to talk about today about going from reactive to proactive as an FSO, building a NISPPOM program that passes audits. And we're going to focus on a few key points today. The first key point, why most FSOs operate reactively. Second point is what DCSA actually looks for during their review. The next topic is how to structure your program for audit success. Many of you are professional FSOs, meaning you are a security professional and you understand it. Some of you are joining us today in a smaller company where you are FSO, but that is one of your many, many hats. And some of you know who I'm talking about. If you have one to five employees, you're probably the owner of the company as well. You are maintaining a good security program to protect classified information, but there's a difference between having a good security program, protecting classified information, but demonstrating that. Also, it's really easy for those of you who wear multi-hats to be overwhelmed by the sheer volume of FSO tasks. So what we want to do here is show you how to be consistently DCSA security review or audit ready while maintaining that good security program. So now we're going to do that audit ready, proactive security program. Let's address that biggest pain. How to perform those FSO tasks efficiently without getting overwhelmed. Now many FSOs operate in a reactive mode. If you're one of those, I want to show you how to become more proactive. As mentioned earlier, many of you were an FSO as one of your many hats you wear. You own the company, you're the chief financial officer, you're the president, you're the CEO, you're HR, and you're also the FSO. And you might not be aware that you can delegate many or all of your FSO tasks. Sure, you can't delegate your authority. You are still the FSO. You still will undergo audits. You are responsible for your security program. But you are able to delegate daily tasks such as security clearance requests and many tasks that are in DISNIS and INVIS, you can delegate those to a capable employee. You also may be handling too many actions using email. If you're doing all of your tasks and you're waiting for an email to come in so that you can do a visit authorization request or foreign travel with your for your cleared employees, if you're doing that by email, you might find yourself doing five to ten email exchanges just to get that foreign visit request for your cleared employee. There's a more effective way to do that. Now let's jump ahead to the bigger picture of why these tasks are important and what DCSA is actually looking for during their DCSA security review. The first thing they're looking for is alignment with the senior management official. The senior management official owns the security program. The FSO executes it. Now for some of you, this is gonna be really easy because you are the SMO and the FSO, and perhaps even the ITPSO. So you you are all together in this. But those FSOs that have a separate senior management official, DCSA wants to know that they are aligned and that the SMO does own the security program and the FSO is execute executing it and they are in sync. They also want to see that you can demonstrate NISPOM compliance with artifacts and confidence. They also look for the ability to explain your security programs with stories or with anecdotes. Stories and anecdotes are pretty important, and you might find me using them in this video and many other videos, because it demonstrates that you understand your security program. And finally, they want to see that buy-in from cleared employees. What does buy-in look like? Well, here's an anecdote. I've seen many times where the FSO is being um or the facility is being re under review with the DCSA, and the DCSA asks the FSO and the SMO about the security program and they get the answers they want. But then they grab a cleared employee and it never fails. You could have been in front of that cleared employee as the FSO giving security awareness briefing two weeks prior. But when DCSA comes to speak with that employee, the employee has no idea who the FSO is or what they were trained on two weeks prior or whether or not they even had that training. So it's very important that the cleared employees are aligned with the SMO and the FSO and performing under and supporting that security program to protect classified information. Now, how do we structure our security program for audit success? Well, it's managing all those tools, managing all those FSO tasks, keeping aligned with the SMO's goal and vision, and ensuring those cleared employees support that. We can talk about it all day long, but we need to be able to demonstrate it. So I was always recommend keeping an FSO workbook. Many of you may have such an FSO workbook, either you've created it yourself, or you're using a third-party software to manage all your FSO tasks. But within that FSO workbook are the artifacts that demonstrate all of your work that you're performing. You may spend your daily work in DIS and NBIS working with security clearances, personnel security clearances, submitting reports. But the real truth is DCSA does not come and do their security reviews based on those databases alone. They come to you to demonstrate your compliance. So that FSO workbook is where everything needs to be stored to demonstrate compliance. And I always recommend that you have it in a secure share drive because you are going to have CUI controlled and classified information in there. Especially if you download reports from DIS and NBIS. Now, the FSO tasks. Again, we talked about doing email. Email should be for notifications, not a tool to conduct your tasks. So I always recommend that you have a form for each FSO task that you need to conduct on behalf of your clear employees. Your cleared employees must report foreign travel, for example. However, they're not able to upload those reports into DIS. You've got to have a way to receive information from your cleared employees. Your clear employees need a way to provide you that information. Because if you go to DIS and look at foreign travel or visit authorization requests, you're going to see required fields that need to be completed. Now if you're creative, you can create your own form. And you can you can create a fillable form that they can download or a fillable form that you can email to them. But either way, those forms bring that information to you. You can also create a fillable form on the shared drive where the employee logs in and completes their tasks. So enough about forms. These forms must be filled out and then uploaded into DIS, and that way you're not managing your FSO tasks via email. These forms can get filled out, you can get notification and work on them when you schedule those times. That will allow you to be proactive. So those forms and that FSO workbook are there for your audit success. Now, how do we move from scramble mode to audit med ready mode? Well that's being purposeful as an FSO. Using those FSO forms, tools, and that FSO workbook that you're putting together. If those are updated consistently and you do those administrative tasks efficiently that you're required to do, you'll always be audit ready. Never cram for security review. You should not be ever working late unless the work requires you to work late. The review should not require you to work late. For example, here's another anecdote. When I was in the army in a private, we always had these commanders and they were under review from the inspector general. The inspector general would come in and see if they were performing their tasks as required. Now, most commanders had everybody working late weeks prior to the inspections. They were painting rocks, maybe even painting grass green to make it look good. They were polishing and cleaning things that normally don't get cleaned. And many people were working working late doing tasks that they should have done. And I s and I made a promise to myself, if as ever a commander or a leader, I would never have people working late. In fact, they would have to come to me for authorization to work late because then they had to explain why they were not always inspection ready. So many years later, I became a commander, went through IG reviews and inspections, and stayed true to my word. Nobody was authorized to work late, and they are always inspection ready. And I recommend the same for you as an FSO. Always be ready. Always have that FSO workbook updated. Do your NIS and IMBIS on time and handle your FSO tasks by either delegating and ensuring those employees complete those tasks accurately and preserve those artifacts in the FSO workbook. Maintain that FSO workbook and update regularly. Some things you don't update all the time, like your FCL paperwork, your facility clearance paperwork, or your company structure, but you always need to update briefings and trainings and reports. Thank you for joining us. I hope this helps you maintain your security program. Even though you have that good security program, you need to be able to demonstrate compliance with it. The best way to demonstrate compliance is not leaving through email or conducting your FSO tasks through emails. The best way may be to delegate some of your tasks to relieve your workload and create forms that enable you to capture what you need to do on behalf of your employee. Make those reports, report foreign travel, do visit requests, and etc. We should even have forms for justifying security clearances. And so if you need more ideas for your FSO workbook, you can go to look at our other videos. If you need assistance with this, please contact me at any time. If you go to Thriveanalysis.com, you can go in there and book some time with me, a 15-minute increment to ask some questions and see if I can help you with your problem. I may be able to fix it just like that. Or make a recommendation for you. However, you may need additional help, some lengthy help getting your security program up to date, developing and implementing your FSO workbook, developing and implementing forms that you can use to reduce your workload. I'll be happy to help you out. I'll put the link to ThriveAnalysis.com in the website or in this page where you're accessing this information. Additionally, if you want to do it yourself, we have FSO workbook that you can download and begin implementing immediately. And it's complete with required training for your cleared employees, all the forms you need to execute all your FSO tasks. So once again, I thank you for joining DOD Secure. This is your place to go for all things Mist Palm, all things contract requirements, and all things security clearances. Hope you come back for another episode. And please look at our show notes, and you can find more resources that might answer your questions on how do I perform once I win a classified contract, and what do I do once I get a security clearance? And the other question is how do I get a security clearance? We are here to help you out. And I hope you remember that when you visit our show notes, you will find those resources, as well as access to my other company. We actually perform this contest as well as FSO on this content, in case you have that need. Wish you all the best, and we'll see you next time.