Posts

Showing posts with the label Industrial Security

DoD Security Professionals and Certification

Image
    Happy New Year DoD security and risk management professionals. A new year, a new beginning; a great motto and motivational phrase. As such, this is the time of year to reflect upon your accomplishments and develop goals. Some of these goals impact only you, but may actually impact your organization. If your goals include professional certification and education, then use this article as a roadmap to get you there. You may be aware of the many available certifications and this article addresses two prominent ones; Industrial Security Professional (ISP) ® and the Security Professional Education Development (SPeD) certifications. Both certifications are great ways to demonstrate professional competence that brings credit to the certified professional and the organization they support. The ISP ® certification The ISP ® certification is sponsored by NCMS and is based on the DoD, 5220.22-M, National Industrial Security Program Operating Manual (NIS...

NISPOM Study Questions

Image
Some NISPOM based questions that might augment your study for the ISP Certification exam. 1. In order to protect fragile intelligence resources and methods, SCI has been established as the SAP for: a. NSA b. GCA c. DNI d. CSA e. GSA 2. Interim TOP SECRET FCLs or PCLs are valid for access to COMSEC at the ____ and ____ levels. a. SECRET, TOP SECRET b. TOP SECRET, CONFIDENTIAL c. CONFIDENTIAL, FOUO d. SECRET, FOUO e. CONFIDENTIAL, SECRET 3. The COR establishes the COMSEC account and notifies the _____: a. CSA  b. GCA c. FSO d. NSA e. DIA 4. Contractors maintain TOP SECRET reproduction records for _____ years. a. Two years b. One year c. Five years d. Ten years e. None of the above Scroll Down for Answer ...

How to study for the ISP Certification using the Self-Inspection Handbook for NISP Contractors.

Image
In our security community, I see a lot of questions about studying for the ISP Certification. Some ask for additional ideas to augment good study groups formed in NCMS (Society of Industrial Security Professionals). These questions facilitate great response from ISPs to help the student prepare for their certification exam. Of the many reasons candidate testers might have for requesting additional study is to gain more experience and practice what they already know. It’s true that one of the testing pre-requisites is five years of experience protecting classified information or otherwise working in the national industrial security program (NISP) environment. However the five years of experience doesn’t necessarily mean that the candidate is executing all National Industrial Security Program Operating Manual (NISPOM) tasks. The tester is responsible for answering questions from the entire NISPOM though they may only personally touch small portions of NISPOM in all of those fiv...

How to take a test; any test

Image
There are a few rules of thumb when it comes to taking tests. These rules are almost constant and really have no technical bearing to the tested information. However, where used logically, these tips will increase chances of correctly answering questions you might not fully know the answer to. Here are some recommendations: Tip #1 Stop studying at a reasonable time before the test. You know that time before a test when your  head is spinning and studying does nothing but confuse you. It's that time when looking at reference material is nothing more than white noise; it never makes it to your brain. Instead, take a break. Just as an athlete tapers down her training before a race, give your brain a break. An overloaded brain before an exam is just as detrimental as a tired and aching body before a race. Tip #2  Take a few deep breaths before you get started. This will increase oxygen flow to your brain and help you concentrate. After all, you are going to be readi...

Traditional Security Tools in Unique Ways-Moving from Security to Risk Management Part 2

Image
See More Ideas in DoD Security ClearanceAnd Contracts Guidebook In part two of the series U sing Traditional Security Tools in Unique Ways-Moving from Security to Risk Management we’ll look at a few more ideas. In part one we looked at security training , clean desk policy and posting reminders of work in progress. In this article we’ll look at documenting the use of security containers and end of day checks. Document the opening and closing of security containers-So, here's the question, other than helping determine who opened the security container, who closed it and who checked it, what real use is it? Such a form is an inspectable item in the government, but other than that, how does industry use it to improve enterprise security posture. As a standalone tool, we rely on professionals to actually fill it out correctly. When they do, what information does the form actually provide? If an insider plans a malicious event, they won't fill it out. Out o...

Using Traditional Security Tools in Unique Ways-Moving from Security to Risk Management

When Facility Security Officers and security specialist build security programs, we tend to use tools to remind employees of their responsibilities. We use security training to get the information out, enforce clean desk policies and post reminders of classified information in progress. Each tool notifies the holder of classified information that they are in possession of classified information, to protect that information and properly dispose of it when they are done. They can also be used to protect proprietary data, intellectual property and personnel information. But sometimes even tools become mundane, no longer giving the impact they once did. Sometimes tools are misused, never giving the impact they were  originally  designed to give. Let's look at a few tools from a risk management perspective with some "out of the box suggestions. What unique ways can you employee traditional security methods. Security training- Cleared employees performing on classifi...

6 Awesome Ways to Delay a Security Clearances

One thing an FSO just can't control is how long it takes the US Government to completely investigate, adjudicate and award a security clearance. These investigations rely on trained persons to research a persons background and another set of trained persons to make a decision on the findings. These professionals are charged with determining whether or not a person can be relied on to protect classified information from unauthorized disclosure. Returning or seeking clarification on submitted information is costly. As an  FSO, you can control one critical part of the process. Ensure the applicant fills out the SF86 forms accurately and completely. Any mistakes, omissions or embellishments can cause serious time delays. You can help the applicant understand the content and explain how to complete required forms. Here is great tool to help; the top 6 reasons security clearance decisions are delayed: 1.  Missing or illegible fingerprint cards. The cards must be provided to th...

8 Benefits of Studying for ISP Certification

Leaders at all levels can promote a better security environment and professionalism. Whether full time employees devoted to protecting national security or a VP of contracting, leaders set goals for their employees. Part of those goals should help help understand how to create incredible security programs. Focusing on training, interaction with other cleared employees, self-improvement and institutional education should be part of professional development. Those who write security evaluations for direct reports create goals to challenge them to become better at their jobs, more impactful in their careers and hopefully, groomed to become leaders themselves. Challenging employees and team members to achieve personal and professional goals breeds success. The ISP Certificatio n is one goal FSO's could take as a goal as well as encourage other employees to achieve for several reasons. 1. The employee gains from such education and a prestigious career milestone. 2. The defense co...

10 Ways to Demonstrate Above and Beyond - Category 3 of the NISP Enhancement

Category 3 of the NISP Enhancement covers Security Education: Information/Product Sharing Within the Community.  This focuses on the FSO providing security education peers and other FSOs outside of their organization. This is a security community event where contractors and government managers can learn from each other. Think Society of Industrial Security, American Society of Industrial Security, or other professional organization level event. Or it can be a smaller venue. Either way, involve others outside of your organization. This demonstrates contribution to the community, a pursuit of improving national security, and helps quantify going above and beyond. For example, an FSO uses their facility, creates an agenda and executes a security conference or training event. Or, committees can be formed to share the tasks. Education of this magnitude has tremendous value as the security community learns from experiences and examples of their peers and applies them at their own organ...

Who will be the next FSO

For those defense contractors who what to perform on classified contracts, there are a few considerations to address. Under the National Industrial Security Program (NISP), a cleared contractor should appoint an FSO to take on this responsibility of directing a security program to protect our classified information. This FSO is the link between the government contractor and the cognizant security agency (CSA). When considering who to appoint as an FSO, the cleared contractor has a few choices: 1.       The senior officer can assume the role. 2.       The cleared contractor can designate an existing employee 3.       The cleared contractor can hire an new employee Whoever assumes the role of FSO must meet two requirements: 1.       Be a United States citizen. Both the facility and the FSO have to be U.S. Entities and must have a history of integrity and conduct that prevents or limit...

5 Effective Ways to Study For the ISP Certification Exam

Out of the approximately 3500 NCMS members nearly 325 hold the ISP certification.   The test is challenging and candidates are expected to score at least 75% for a passing grade. Why Certify?   The ISP holder demonstrates a high level of knowledge. The certification is based on the NISPOM but also covers electives such as: COMSEC, OPSEC, and other topics. This certified professional communicates to upper management that they are committed to the business, the industry and the protection of national interests. It puts the company in a stronger position while bidding on contracts and lends credibility to relationships with the oversight agency the Defense Security Services (DSS). Most of all, it gives the bearer confidence in their ability to apply their knowledge. As this certification program evolves, more and more employers will require the certification. Preparing Only those working in the National Industrial Security Program for at least 5 years are edible for the I...

Five Ways For an FSO to Increase High Power Team Effectiveness

Maybe you think you are alone, fighting the one person fight that many leaders face. However, you would be wrong to assume that the head of security is the only one responsible for the security program. For cleared defense contractors, the Facility Security Officer is in charge of the security program, but not the only one with a vested interest in protecting classified contracts. So how does the FSO create a teaming environment or create a program where everyone works together?   Through High Power Teams High power teams (HPT) are the most effective types of entities. Where groups form, storm and norm, HPTs go further to create a body more capable than any individual. They do this by agreeing to rules and primarily keeping in mind that throughout any process or problem, it’s not about the individual, it’s about the group. This allows the organization to benefit as a whole as each member sacrifices their individual desires. The members do not lose or give up the individuality th...

How Cleared Contractors Appoint Facility Security Officers

Image
  Excerpt From Our Newest Book  Becoming a cleared defense contractor demands more than just a defense contractor getting a security clearance. It's more to do with, what to do once the clearance is awarded; specifically, protecting classified information. This protection involves physical, classified processing, and information security. It's more than just buying safes, installing access controls and getting employees security clearances. Primarily, the cleared contractor must appoint a Facility Security Officer (FSO) responsible for implementing a program to protect classified information. To better answer frequently asked questions, I've written several times on the topic of selecting the right Facility Security Officer (FSO) qualifications. According to the National Industrial Security Program Operating Manual (NISPOM), the FSO must be a US Citizen and be cleared to the level of the facility (security) clearance (FCL); period. This provides a lot of room ...