Posts

Showing posts with the label information systems

Operational Controls and Classified Information Systems

Image
Operational Controls and Classified Information Systems By: Jeffrey W. Bennett, SFPC, SAPPC, ISOC, ISP This article addresses the protection of Information Systems and the information that resides on them and is modeled after questions from the Self Inspection Handbook for NISP Contractors . We feel this is a great format to walk through the self-inspection criteria. We begin with the topic question, the NISPOM reference, an explanation of requirements, and finally how to inspect compliance. Topic Question(s): How is the IS physically protected? (Check all that apply) NISPOM Reference(s): 8-302b Operational Controls Discussion: Each of the countermeasures above are already covered in sections of NISPOM chapter 5. Neither NISPOM nor the Self-Inspection Handbook desire to define these countermeasures. The intent is to determine which countermeasures are applied to demonstrate their application. These countermeasures should reflect the three controls identified in NISPOM f...

4 Situations FSOs Could Find Themselves Addressing

Facility Security Officers (FSO) may find themselves addressing many types of security incidents. How would you handle the following? 1.  You are an FSO of a growing defense contractor. One of the executives approaches you about the need for more space to conduct classified work. He is agreeable to implementing your recommendation to use a restricted area and would like you to prepare a security briefing for his team. Prior to your briefing, you conduct the necessary research. Describe the reason for a restricted area and when cleared employees would use a restricted area. Keep in mind access control and storage requirements. 2. You have just sat down to eat lunch and receive a phone call from a cleared employee. She tells you that the security container’s drawers are closed, but the dial on the combination lock has not been engaged. She explains further that according to the SF 702, the container had been locked and checked...

5 Steps to Protecting Technical Data on International Travel

Prior to travel, a cleared employee should have a good understanding of their responsibilities to protect sensitive information. This can include classified or unclassified information and military or dual use information. For defense contractors, protection of classified information is addressed in the National Industrial Security Program Operating Manual ( NISPOM ), military technical data is covered by the International Traffic in Arms Regulation ( ITAR) and dual use technical data is protected under the Export Administration Regulation (EAR). Facility Security Officers (FSOs) and Exports Compliance Officers can train their travelling employees to protect technical and help them accept the responsibly to protect themselves, classified information, and technical information. Preparation for travel can be covered in 5 steps: 1. Ensure cleared employees notify their security office of all foreign business well in advance of a proposed travel date. This will prepare the employee ...

Security COmix

Image

DoD Security Clearance and Contracts Guidebook — Red Bike Publishing

Image
DoD Security Clearance and Contracts Guidebook — Red Bike Publishing Our Newest Book DoD Security Clearance and Contracts Guidebook - What DoD Contractors Need to Know about Their Need to Know Coming April-Pre-Order your copy now This new book will demystify the security clearance process and help cleared contractors develop security programs to win and keep classified contracts. It is a good companion for all seasoned and novice defense contractors, Facility Security Officers (FSO) and the college student. Defense contractors can confidently pursue classified contracts with: •Step by step guide demonstrating how to meet requirements for security clearances •Senior leader responsibilities in security cleared facilities •Classified contracts administrative responsibilities •Method for reducing costs associated with protecting classified information and NISPOM requirements •Description of exceptional (FSO) qualities Cleared contractors can protect program information th...

Secure IT

Image
Information systems allow businesses to increase work productivity at blinding speeds. Documents, images, and media can be duplicated, printed, emailed and faxed much quicker than technology allowed just a few years ago. The lightening fast capabilities enable enterprise to perform on contracts more efficiently and in less time. However, because of fast distribution and processing speeds, measures must be in place to prevent unauthorized disclosure, spillage and compromise of classified information. Once a spillage occurs, the errant person cannot take the action back. Information systems identified to process classified information is marked according to the highest classification. As with protecting physical classified properties, information systems and their products must also be safeguarded at the appropriate level. Computers used for uploading, storing, processing, disseminating, printing and other functions are protected at the level of the information being worked...