Posts

Showing posts with the label defense security services

Security Responsibilities, Extra Duties and CDCs

Image
Periodically, Defense Security Services conducts reviews of the Cleared Defense Contractors (CDC) under their pervue to ensure classified information is protected according to NISPOM and contractual requirements. Inherently, there are tasks that the CDC must complete to demonstrate requirements, and these tasks are outside of the scope of what the contractor usually charges their customer. If the CDC does not account for costs of maintaining classified information, it could come out of hide. In many cases, small CDCs of just a few employees perform full time on classified work and then spend extra hours on demonstrating compliance that extend beyond the 8 hour day. Documenting evidence of compliance is a challenge that many Cleared Defense Contractors (CDC) face. Compliance is checked through reviews and audits conducted by customers to ensure contractual and government requirements are met. The best practice for CDCs include conducting self-inspections and documenting events to ...

Why Cleared Contractors and FSOs Should Perform Self Inspections

 I could write the same old same old about government and National Industrial Security Operating Manual (NISPOM) requirements. However, such hammering would overshadow a great opportunity. Sure the NISPOM requires that cleared contractors perform self inspections sometime between Cognizant Security Office (CSO) reviews, but that is not the compelling reason or many of the supporting rewards for those who capture results of self inspections. The Defense Security Services (DSS, the CSO for the Department of Defense) will look for self inspection results during regularly scheduled security reviews. If you have a possessing cleared facility, then DSS will review annually. If non-possessing, then this review will occur every 18 Months. The NISPOM requires a self review be performed midway between CSO reviews. Now that we have the regulatory guidance out of the way, we can focus on the real reasons to perform the self reviews. The Facility Security Officer (FSO) tying security into the ...

Some Popular Security Clearance Questions

As a security manager in a National Industrial Security Program organization, you’ll get a lot of interesting questions. You should be prepared to answer them with confidence and ease. Many you’ll have to look up because they will probably come from outer field. However, there are some very popular questions asked many times over. Here are some of those questions: Where does classified information come from? The US Government created a system to classified and protect sensitive information In the National Industrial Security Program, classified information is marked CONFIDENTIAL, SECRET and TOP SECRET. TOP SECRET has more restrictions than SECRET and SECRET has more than CONFIDENTIAL. So, who determines the classification levels? Executive order 12958, As Amended provides instruction for appointment of trained government Original Classification Authorities (OCA). The OCAs evaluate programs and associated information, equipment, services and etc to determine whether or not they are c...

Latest Article in Clearancejobs.com

A security clearance demonstrates that the government has determined that you are trustworthy. As such, you may perform on classified contracts depending on your security clearance level and need to know. To better understand how to protect classified information, it may help to understand how and why  security classification  is assigned. The following provides answers to popular questions:  Classification Levels and Why Certain Information is Classified Jeffrey W. Bennett, ISP is the owner of Red Bike Publishing Red Bike Publishing . Jeff is an accomplished writer of non-fiction books, novels and periodicals. He also owns Red bike Publishing. Published books include: "Get Rich in a Niche-Insider's Guide to Self Publishing in a Specialized Industry" and "Commitment-A Novel". Jeff is an expert in security and has written many security books including: "Insider's Guide to Security Clearances" and "DoD Security Clearances and Contracts Gu...

8 Simple Steps FSOs use to Inspect Classified Deliveries

Image
The FSO should ensure all arriving classified information is inspected and received into accountability. This due diligence is conducted to ensure that classified information has not been compromised, is related to a contract, and is properly marked. Regardless of transmission methods of physical items (mail, courier, overnight, hand carry and etc.) classified material should be double wrapped. Each layer serves to protect the classified material from inadvertent and unauthorized disclosure and should be properly addressed. The classified information should be wrapped and sealed in opaque material or envelopes. The NISPOM does not cover seams of wrapped items, but a good practice is to cover seams with rip-proof opaque tape or other material that prevents and detects tampering. All seams of the outer layer should be sealed with opaque tape in an effort to create a solid layer of covering. The item should be wrapped and sealed wit...

3 Ways FSOs Create an Effective Security Culture

How do effective FSOs and security managers develop a culture of compliance with regulations and security programs? Quoting regulations only exasperates cleared employees and the very act does little to foster a climate of cooperation. However, developing relationships based on a good understanding of business, the company mission and influence goes a long way toward implement the successful security program. 1. FSO influences corporate culture-Security of classified information should be part of the organization's DNA. Instead of stove piping security functions, they should tie into the corporate mission. Though each office has a different product, funding or budget item, each fulfills their obligation in a chain of responsibilities necessary to get the product to market. When a business unit breaks down or fails to fulfill its mission, other business units are affected. 2. FSO performs a vital mission of protecting classified informa...

3 Effective Ways to Go Above and Beyond with Category 7 of the NISP Enhancement

Category 7 of the NISP Enhancement is:  Counterintelligence Integration/Cyber Security provides a tool that cleared contractors can use to demonstrate exceeding NISPOM requirements. Injecting this into the security program also enhances security by bringing to light types and frequency of suspicious contacts. 1.       The purposeful execution of Foreign travel pre-briefings-When employees travel to a foreign country, they may be targeted to provide sensitive information. A threat and/or defensive briefing should be provided to all cleared employees per NISPOM Chapter 3 ( NISPOM Training ). The briefings should be documented with signatures, dates and contents of briefings for presentation to Defense Security Services (DSS) industrial security representatives. 2.     Conducting debriefings once the employees return from foreign travel. It is a tool to follow-up with the threat or defensive security briefing presented prior to the foreign tra...

5 Great Ways to Perform Award Winning Self-Inspections

Category 5 of the NISP Enhancement Program is titled: Self Inspection. Here, a cleared contractor's FSO documents a self inspection as part of a continuous security program evaluation. This is simply a health check of the established security program designed to safeguard classified information. The Defense Security Services (DSS) recommends that the cleared contractor’s Facility Security Officer (FSO) share the inspection results with their industrial security representative to keep communication open as well as address any issues that might be resolved prior to the scheduled DSS annual review. The self inspection should be designed to evaluate all National Industrial Security Program Operating Manual ( NISPOM ) areas the cleared contractor operates under. At a minimum, each facility should inspect its compliance with NISPOM Chapters 1-5 and parts of Chapter 6. These chapters cover general security, personnel and facility clearances, FSO roles and responsibilities, required tra...

What is a National Industrial Security Program Enhancement Category

Defense Security Services are training their agents to apply the new Security Rating Calculation tool. This tool is used to standardize and is based on a numerical scale that allows graded results while accounting for a cleared facility’s involvement in the National Industrial Security Program. However DSS is training their agents to ensure they understand the process before implementing it. This provides a great opportunity for cleared contractors and FSOs to prepare for the changes to come. One of the most prominent features is the addition of a method to grade the ability of a cleared contractor to go above and beyond National Industrial Security Operating Manual ( NISPOM ) requirements. At one time the ability to go above and beyond seemed objective, requiring the FSO to demonstrate how they went above and beyond during the review or other interaction with DSS. Now, DSS has included a proactive measurement called the NISP Enhancement. According to the DSS website, “…directly relat...

3 Important Uses of the DD Form 254

In addition to the NISPOM, there is another critical piece of information for creating a lasting and significant security program and good classification management; the DD Form 254. The Contract Security Classification Specification (DD Form 254) authorizes classified work performance and conveys the security classification specifications and guidelines for classification in the performance of a classified contract. The DD Form 254 is provided to both the contractor and cognizant security offices when work is subcontracted to a supplier/vendor requiring access to or generation of classified material. So why is this important to you?   It provides authorization for a contractor company to hold and or perform on classified contracts. The DD 254 justifies the need to access classified information and how and where the contractor is expected to perform. This justification also addresses the level of clearance at which the facility and employees should be approved.   It al...

Forms You Might Need to Know About

These standard security forms are used in administering the security classification programs in Government. Industry members should contact their contracting agency for information on how to obtain these forms. The majority of these items are available through the General Services Administration's (GSA) Federal Supply System. Some of the forms are available online at the GSA web site or can be obtained by calling 1(800) 525-8027. *     SF-312 Classified Information Nondisclosure Agreement The SF-312 is a contractual agreement between the U.S. Government and a cleared employee that must be executed as a condition of access to classified information. By signing the SF-312, the cleared employee agrees never to disclose classified information to an unauthorized person. *     SF-700 Security Container Information The SF-700 is a form that contains vital information about the security container in which it is located. This information includes locatio...

DoD Security Clearances and Contracts

We know it’s tough to focus on both creating a company to last and performing under strict government guidelines. Getting classified contracts, requesting security clearances and remaining compliant are all vital to a cleared contractor’s success. But… Just one mistake can cost a defense contractor current and future contracts. Until now, there has been no one place to find everything you need to know about security clearances. Many defense contractors and employees don’t understand how to get their clearances and compete for classified work. The DoD Security Clearance and Contracts Guidebook brings together information from Presidential Executive Orders, National Industrial Security Program Operating Manual (NISPOM), International Traffic in Arms Regulation (ITAR) and other regulations to demonstrate how to establish and maintain a successful security program. Whether you are part of a business or an employee, this book will demonstrate both the security clearance process and how...

ISP Certification Test Questions

Image
From ISP Certification Exam Manual Sample Test Questions Before taking your ISP Certification Exam, why not test drive a few questions. You can find more at http://www.redbikepublishing.com 1. Which of the following are eligibility requirements for an FCL? a. The company must be an organization of at least 25 people b . The company must have potential for classified access c. The company must have a reputation for integrity d. The company must make its bottom line for three consecutive quarters e. The company is the only one who can perform the work 2. When can a contractor disclose classified information to another contractor? a. Furtherance of contract b. Furtherance of business development c. When directed by FSO d. When directed by CSA e. Just as long as other contractor is cleared 3. Unless restricted by GCA, SECRET material may be reproduced as follows EXCEPT: a. In performance of a prime contract b. In performance of subco...

Review Questions from Chapter 11 "DoD Security Clearances and Contracts Guidebook"

If you are a defence contractor, cleared contractor or cleared employee, try these questions. Want more, see http://www.redbikepublishing.com 1. The vice president of business development has just brought up the wonderful opportunity of selling an all weather capability the company produces for medical evacuation flights to a foreign owned company.  a. Suppose this item needs a license prior to export. Describe the first step an organization would take in consideration of a possible export. b. If the item is to be delivered to a foreign company just down the street, will export requirements still apply? 2. You are travelling as an authorized courier to deliver a package that contains classified information at the CONFIDENTIAL level. Upon arrival, the foreign government customs agent wants to take custody of the package. You present your credentials and attempt to talk her out of the idea. She informs you that as a representative of the foreign government, she is authorized to...

Information Management Systems

Commerically available IMS use information technology to create a detailed database that helps FSOs track classified material through many dispositions from receipt, inventory requirements and final disposition. Some produce receipts, tie to a barcode scanner, report statistical data that can help determine use and much more. For example, if an inventory reveals missing classified information, the database can provide valuable information to help reconstruct the classified information’s history.   Databases can be tied to scanner software. Barcodes can be printed and applied to classified items for scanning. If an item is destroyed, shipped, filed, loaned or returned, it can be scanned and the status updated. These databases provide reports identifying when and where the barcode on the classified document was scanned and the last disposition. The FSO can use the technology to research dates, methods of receipt, contract number, assigned document number, assigned barcode, title, c...

How Cleared Contractors Appoint Facility Security Officers

Image
  Excerpt From Our Newest Book  Becoming a cleared defense contractor demands more than just a defense contractor getting a security clearance. It's more to do with, what to do once the clearance is awarded; specifically, protecting classified information. This protection involves physical, classified processing, and information security. It's more than just buying safes, installing access controls and getting employees security clearances. Primarily, the cleared contractor must appoint a Facility Security Officer (FSO) responsible for implementing a program to protect classified information. To better answer frequently asked questions, I've written several times on the topic of selecting the right Facility Security Officer (FSO) qualifications. According to the National Industrial Security Program Operating Manual (NISPOM), the FSO must be a US Citizen and be cleared to the level of the facility (security) clearance (FCL); period. This provides a lot of room ...

Security Clearance Opportunities for Defense Contractors and Cleared Employees

Image
The NISPOM  the Cleared Contractor's  Guide to Security Programs Potential for Security Clearance Required Jobs There are more than 12,000 cleared Department of Defense contractor facilities. Considering that organizations can have anywhere from one to thousands of cleared employees, the amount of employees performing classified work is in the hundreds of thousands. Positions requiring security clearances include scientists working on projects to janitorial services and repair providers. Some clearances are based on actually performing classified work or just being cleared to access an area to perform repairs or cleaning services. Even though a job may require a security clearance, an employee does not need a security clearance to apply for the job. The potential employee must only be eligible for the security clearance. Many frequently asked questions in the defense contractor field are from those who want to know how to get a security clearance so that they can app...

Technology Protection and Foreign Travel

Image
Red Bike Publishing's NISPOM Anytime an employee travels abroad, they should expect to be liberated from their computer at the host country's customs. They should also expect to have the hard drive duplicated, files read and etc. These are the contingencies for which astute technology control officers, export compliance officers and security specialists plan. Sensitive, and protected technology should not be contained within computer and related media without proper permissions. Foreign governments want US Technology and aggressively seek it and defense contractors should make the information very difficult to get. However, they may spend too many resources on actions that don't address the real threat. For example physical security efforts may focus on fortifying businesses with barriers, alarms, access control, cameras and etc. Risk assessments indicate that technology is leaked through careless or malicious employee behavior or actions taken due to poorly understoo...