Posts

Showing posts with the label Security

Managing Export Violations

Image
Let’s test your knowledge of international operations. The following situation is pure fiction, but is based on issues facing businesses everyday. This situation is tricky enough with unclassified contracts, but the addition of possible classified work may complicate the issue. Try to answer the following question: As the security manager of a classified facility, you have many responsibilities including approving classified visits. Not a problems since most visit requests are handled through agency approved data bases . Besides, you have a very large staff and the process is pretty much routine until…. A program manager enters your office and informs you that her foreign customer wants to send an employee to work onsite on a classified program for six months. The program manager wants you to give her a visit request form that the foreign company can use to submit a visit request. You think about this for a moment and realize that though the situation is unusual, it should be a worka...

NISPOM, ISP and ISOC Study Questions

Image
Get your copy @ www.redbikepublishing.com These NISPOM based questions could be helpful in passing the NCMS ISP Certification and the DoD's SPeD Certification exams including the most recent Industrial Security Oversight Certification ( ISOC) . Taking practice tests is a great way to prepare for an exam. Successful students in grade school and college study using guides and exam preparation questions based on the test subject material. This same successful methodology can also help prepare for professional exams like ISP Certification and SPeD Certification.  Practice tests augment certification exam preparation.  Red Bike Publishing's Unofficial Study Guide  features four complete test length practice exams based on  NISPOM .  We've updated our manual for NISPOM Change 2.  1. TOP SECRET information can be transmitted by which of the following methods within the U.S. and its t...

Facility and Personnel Security Clearances

Image
Facility Security Clearances A defense contractor is a business entity that has registered to contract with the US Government and has registered with the Central Contractor Registration. A Cleared Defense Contractor (CDC) is the designation of a U.S. Government Contractor facility that has been granted a Facility Clearance, authorizing them to perform on classified contracts. An uncleared defense contractor may bid on a classified contract without possessing an FCL. However, they must be cleared before getting access to the classified contract. Many defense contractors may find it difficult to find and compete for classified contracts. They may have a unique skill that is hard to identify contracts requiring those skills. But this should not be a showstopper as uncleared defense contractor may partner with or team with an existing CDC for sponsorship. For example, suppose a major defense contractor is performing on a classified contract for engineering support. Their core compe...

The Security Clearance in 30 Seconds

Image
Add caption How are security clearances granted? Why does the Government grant them? How does the Government assign classification levels? Who is eligible? First of all, classified information must be protected. Part of the protection is to ensure only properly investigated and vetted cleared employees with need to know get access granted. According to the latest Executive Order, employees should not be granted access to classified information unless they possess a security clearance, have a need to know to get it, received an initial security briefing and have signed a nondisclosure agreement.  Some clarifications should be made concerning who actually gets them. Those granted include the businesses and their employees. Defense contractor are business entities and employees are the people who work there. When a defense contractor gets granted access to classified information, they are then called Cleared Defense Contractors (CDC). Once they have their clearance, then the e...

How Security Clearances Work

Image
People often ask the question: "How do I get a security clearance? Or how can my business get a security clearance?" My first response is market yourself. There's nothing you can do about getting a security clearance until somebody sees value in your product or your service and sponsors the business for a security clearance.  Value is simply someone who has a tangible need for a particular product or service and they want to put you on contract already classified contract to be able to use your products or services.  There are many jobs that require security clearance or services and some of those jobs include janitorial services, engineering services, secretarial, you name it. There are many opportunities out there to get a security clearance. However, one cannot just get a security clearance in preparation for the work. The work offer comes first.  The first step is to be sponsored by a federal government entity, a government contracting agency  (GCA) or ...

An Interview with a Cold War Counter-Spy

Image
We spoke with former Counter-Spy and Author John W. David about his experiences with cold war espionage and applying it to counter the insider threat . John has written two books, Rainy Street Stories and Around the Corner . Both are essays of his experiences with the cold war, terrorism, and espionage. John offers several anecdotes and shares past experience of how he has recognized spies and those who would recruit insiders. He weaves relevant stories in the podcasts that are still applicable to a successful insider threat program. Listen to the podcast to hear two of many major points on running Insider Threat Programs. Here are two points to get started: 1. Develop a culture of security by walking around. Security managers should get away from their desks and meet the employees that can work as risk management and security force multipliers. The employees should be comfortable with the office staff and understand what expectations are. One of the primary results o...

The Fine and Time Honored Art of Piggy Backing

Image
After years of fighting what he had assumed as bad practice, a Facility Security Officer (FSO) confidently confided that he now welcomes “piggy backing” as acceptable. Entering a protected facility while using the credentials of another employee also known as “piggy backing” is now being proven an efficient means of enterprise ingress. “With each employing needlessly scanning their badges, when someone else had already triggered the authorization at first seemed redundant.” said the FSO. “Now we know that there is so much more benefit. Now we see a realized cost savings involved as they now only trigger the device once, saving destructive wear and tear on locking and opening hardware. Also, holding the door open for multiple employees to enter simultaneously reduces the number of times the door is opened and closed, thus also creating cost savings for heating and air conditioning expenses”, he continued. The progressive cleared defense contractor began a month long pilot ...

Insider Threat Program Compliance

Image
This article addresses the NISPOM based Insider Threat Program (ITP) compliance requirements and is inspired by questions from the Self Inspection Handbook for NISP Contractors . The article uses the handbook’s format to through the self-inspection criteria. We begin the topic question, the NISPOM reference, an explanation of requirements, and finally how to inspect compliance. Topic Question(s): Does your ITPSO ensure compliance with insider threat requirements established in the NISPOM and in the implementing guidance provided by DSS? EVIDENCE: Explain who and how and how often oversight reviews are conducted NISPOM Reference(s): 1-207b 1-202 The NISPOM references provided are to measure application of the cleared contractor’s Insider Threat Program (ITP) . However, the compliance is applicable to the broad implementation of NISPOM and security disciplines and not just the ITP.  For example, the NISPOM requires cleared contractors to conduct a secu...

FSO's, OPSEC, and Protecting Sensitive Information

Image
In our latest DoD Secure Pod Cast we continued our discussion the owners of The Management Analysis Network. This discussion is about apply Operations Security in the form of a Communication Strategy or Comms Strategy.  The need to communicate They explain that a comms strategy is vital to being able to communicate information about the work a cleared defense contractor is executing without giving away too much information. When developing a significant capability others may be able to observe the work and become inquisitive.  Whether they are neighbors, businesses, news media or others,  what people are naturally going to do is inquire about it. Additionally, it may be necessary to present information at conferences, award ceremonies, promotions, advertisements and etc.  So the question is, how do we talk about the program to meet the requirements, to convey information to Congress, to oversight to others and to tell the good news story to the American peo...

Risk Management without Threat Reports

Image
The insider threat by the very concept is a difficult threat to face. As professionals operating in a National Industrial Security Program Operating Manual environment, we pay homage to these deviant but trusted employees without really addressing the issue. Of course we conduct the required insider threat program training , document it, and report the existence of our insider threat programs as required. In other words, it is easy to recognize the existence of the potential of an insider threat. We can even assign an impact level should we have an insider that goes to the dark side, but few can go beyond the recognition to implementing preventative measures. What if you can’t identify a threat, do you still have a risk? Insider threat programs and training requirements spend much effort on convincing that the insider threat is “real” and that if activated, they can cause a level of “damage” to national security, depending on the level of classified information exploited....

Security Responsibilities, Extra Duties and CDCs

Image
Periodically, Defense Security Services conducts reviews of the Cleared Defense Contractors (CDC) under their pervue to ensure classified information is protected according to NISPOM and contractual requirements. Inherently, there are tasks that the CDC must complete to demonstrate requirements, and these tasks are outside of the scope of what the contractor usually charges their customer. If the CDC does not account for costs of maintaining classified information, it could come out of hide. In many cases, small CDCs of just a few employees perform full time on classified work and then spend extra hours on demonstrating compliance that extend beyond the 8 hour day. Documenting evidence of compliance is a challenge that many Cleared Defense Contractors (CDC) face. Compliance is checked through reviews and audits conducted by customers to ensure contractual and government requirements are met. The best practice for CDCs include conducting self-inspections and documenting events to ...