Posts

Showing posts with the label list of security clearances

Acronyms FSOs and Security Specialists Should be Familiar With

Acronyms BL Bill of Lading CAGE Commercial and Government Entity CIA Central Intelligence Agency CM Configuration Management COMSEC Communications Security CSA Cognizant Security Agency CSO Cognizant Security Office DAA Designated Accrediting/Approving Authority DGR Designated Government Representative DNI Director of National Intelligence DoD Department of Defense DoE Department of Energy DSS Defense Security Service EAA Export Administration Act FBI Federal Bureau of Investigation FCL Facility (Security) Clearance FGI Foreign Government Information FOCI Foreign Ownership, Control or Influence FSO Facility Security Officer GCA Government Contracting Activity GSA General Services Administration IS Information System ISOO Information Security Oversight Office ISSM Information System Security Manager ISSO Information System Security Officer ITAR International Traffic in Arms Regulations LAA Limited Access Authorization MFO Multiple Facility Organization NACLC ...

Copying Classified Documents

Classified information should only be reproduced in response to a contractual requirement such as in the performance of a deliverable. Reproduction should not be made as a matter of convenience as it puts classified information at unnecessary risk and it requires dedicated resources. The FSO can enforce resource discipline with: 1.  Creating processes and procedures identifying reproduction only as necessary and using only approved equipment 2. Ensuring only trained and authorized personnel are able to reproduce classified information. 3. Identifying office equipment, copy machines, scanners and other reproduction equipment for classified information reproduction. All other enterprise equipment should be off limits to classified reproduction. This can be accomplished through signs identifying authorized equipment as “Approved for Classified Production at the _______ level”. Other equipment would be identified as “Not au...

Requirements for obtaining an FCL

The facility clearance is required to be in place prior to the contractor performing on classified work. After the GCA or prime contractor submits the sponsorship letter, the company can begin the process of applying for the clearance. A contractor has to meet five requirements before it can be processed for an FCL. • Be Sponsored • Sign Department of Defense Security Agreement • Complete a Certificate Pertaining to Foreign Interests • Provide Organization Credentials • Identify Key Management Personnel clearances Sponsorship-A company cannot apply for a security clearance for business development purposes or to be more competitive. The security clearanc e process begins with a need which is supported by a legitimate U.S. Government or foreign government requirement and the classified contract will be offered to meet that need. Department of Defense Security Agreement (DD Form 441)-A security agreement is signed between the US Gover...

FSOs Can Use Defense Security Services Annual Review as Metrics

Annual DSS Reviews as Metrics Inspections are typically conducted every 12 months for possessing and 18 months for non possessing facilities, but circumstances can require more or less frequent visits. DSS inspects the facility’s security program for the primary purposes of ensuring their programs provide the proper protection of classified information they are charged with protecting. Additionally, the inspection programs are designed to improve the effectiveness of the contractor’s security program. At the conclusion of the inspections, the contractor is given a rating ranging from unsatisfactory to superior:      • Unsatisfactory-indicates that the contractor has lost or is in the process of losing their ability to protect classified material.      • Marginal-indicates that a contractor is not meeting the requirements of NISPOM and has a substandard security program.      • Satisfactory-the m...

Four Powerful Ways FSOs Can Employ in Creating a Security Conscious Enterprise

1.  Influence at all levels-A key trait an FSO should demonstrate is the ability to work within organizational structures to gain executive, manager and work force cooperation. An FSO can train and write policy but without the enterprise’s full cooperation, will find it difficult to enforce. 2.  Integrate security at all levels-A well integrated security plan ensures that all business units within an enterprise notify the FSO of any change in disposition of cleared employees or classified contracts. This integrated system will trigger the contracts, program manager, business development and other units to coordinate with and keep the FSO informed of expired, current, and future contract opportunities and responsibilities. 3.  Be fiscally responsible-An important task that an FSO faces is the successful implementation of the security program while supporting the company’s primary mission; to make money while successfully performing on classified contracts. Security eff...

3 Ways FSOs can Have a More Effective Security Program

The Facility Security Officer’s (FSO) successful program depends on developing relationships with employees, managers and executives to facilitate execution of company policies, necessary security awareness training, willful employee self-admittance of security infractions or change of status, and proactive action toward expired, existing and future classified contracts. Any of the above mentioned success measures is difficult to obtain in a changing employee and contract environment, but is simplified through employee and executive buy-in. How to do this: The following 3 points pave the way for a successful security program. 1. Gain executive, manager and work force buy-in. This can be accomplished by first demonstrating a sound understanding of company mission, classified contract requirements and providing sound security policy. Cross cultural buy-in is critical for integrating the security plan into all business units and company operations. 2. Become the “go to” person for...

Cleared Contractors and Annual Security Awareness Training

Cleared contractors are required to brief their cleared employees every year. It’s easy when there is a Facility Security Officer (FSO) on site. However, companies consisting of one to a few hundred employees may have FSOs designated in addition to regular duties. COOs, engineers, CFOs, HR and other professionals don’t have time to create and execute training while performing on contract. That’s where Red Bike Publishing can help. An FSO can spend several hours designing training. At $35.00 per manager work hour, that could end up costing at least $150.00, not including the costs associated with brining the FSO off a contract. Our low cost, high value training package allows you to concentrate on your core competencies while we provide your required training. Our  NISPOM Training  contains requirements for the Annual Security Awareness and Initial Security Training. Just download our slides and lead the discussion, the notes are already filled out a...

Risk Management and NISPOM

     The risk assessment helps FSOs focus countermeasures to protect classified information from actual identifiable threats by probability. Risk management helps the FSO determine how to protect the classified information above and beyond the NISPO M guidance. The same approach should be used in determining which parts of the NISPOM apply to an FSO’s facility. For example, a non possessing facility that performs classified work at another facility should not focus security efforts on protecting classified processing.                 However, they should focus their efforts on NISPOM chapters 1, 2, 3 and 6 parts of chapter 5 and Appendices A and C; the parts of NISPOM that apply to ALL cleared contractors.       The NISPOM’s first chapter is dedicated to general industrial security concerns. The chapter is divided into three sections which provide the introduction, general and reporting requirements.    ...

Security Clearances and the Real Deal

Image
     "Jeff, I need to submit a security clearance request . What do I need to do?" one of our employees asked.      "First of all, you need justification . Can you tell me a little why you need a clearance? We can get started that way."      "Sure, I'd like to have a clearance to apply for a new job. Let's just keep that last part to ourselves."      "No problem, I won't tell people you are job hunting, but I won't be able to process a clearance for you," I responded. I tried really hard not to laugh.     “Really?” he asked incredulously.      Security clearances should only be requested for employees who have a valid reason, such as fulfilling actual classified work. Requesting clearances for the sake of having a clearance is no good reason to initiate a security clearance request. Some other bad security clearance ideas include:      To be able to enter a secure area for convenience ...