Posts

Showing posts with the label nispom training

Security Training Topics For Cleared Defense Contractors

Image
New cleared contractors should understand that the CDSE provides initial training and special briefings to their appointed Facility Security Officer (FSO). This training is invaluable as the new FSO will have a chance to learn about their responsibilities. Sometimes the new FSO will be learning for the first time exactly what is expected of them. After training, the FSO is then authorized to present the training to the organization’s cleared employees. According to  NISPOM , the FSO is also required to attend the DSS mandated FSO Program Management Course within one year of appointment. This means that cleared contractors should be prepared to send a designated FSO to the DSS Academy for the training, or take the training on line. Either way, the FSO must be certified. CDSE provides new courses designed for FSOs of possessing and non-possessing facilities. FSOs should coordinate with their representative to determine the training that’s right for their situation. The training ...

What Defense Contractors Should Consider Before Appointing FSOs

Image
Becoming a cleared defense contractor (CDC) demands more than just a defense contractor getting a security clearance and performing on  classified contracts . It's more to do with, what to do once the clearance is awarded; specifically, protecting classified information. This protection involves physical, classified processing, and information security. It's more than just buying safes, installing access controls and getting employees security clearances. Primarily, the CDC must appoint a Facility Security Officer (FSO) responsible for implementing a program to protect classified information. To better answer frequently asked questions, I've written several times on the topic of selecting the right Facility Security Officer (FSO) qualifications. According to the N ational Industrial Security Program Operating Manual (NISPOM) , the FSO must be a US Citizen and be cleared to the level of the facility (security) clearance (FCL); period. This provides a lot of room for a cleare...

The fundamentals of protecting classified information and NISPOM

Image
Cleared Defense Contractors use classified information during performance of contracts. The Department of Defense makes the rules and governs how the classified contractors protect classified material. The Federal Government has published a policy appropriately titled: The National Industrial Security Program Operating Manual ( NISPOM ). This page turner is sponsored by the Presidential Executive Order (E0)12829 for the protection of information classified under E.O. 12958, As Amended. Having poured over both publications and the updates, I can conf idently assure you that they take this business very seriously.     When specific work declares performance objectives on classified efforts, provisions of the applicable DD Form 254 and Security Classification Guide (SCG) shall govern. Both the DD 254 and SCG spell out what specific work a contractor can and cannot perform, what exactly is classified and how to protect it. Both of these documents not ...

Training and Goals for Cleared Defense Contractor Employees

Image
Putting first things first. That has been a motto for many after reading books such as Franklin Covey’s 7 Habits of Highly Effective People or Reverend Rick Warren’s The Purpose Driven Life. Those and several similar motivational publications stress that everyone has the same amount of time in a day. What we do during that time helps us either make or goals or fail before we even get started.    As leaders, FSOs can help cleared defense contractor employees understand how to create incredible security programs. Focusing on training, interaction with other cleared employees, self-improvement and institutional education should be part of professional development. FSOs and managers who write evaluations for direct reports have an excellent opportunity to help them establish goals to become better at their jobs, more impactful in their careers and hopefully, groomed to become FSO’s themselves. Challenging employees and team members to achieve personal and professional goals b...

Cleared employees, FSOs and Classified Work

Image
T his article continues the series describing what happens after the government grants you a security clearance. After receiving a job with a company or agency performing classified work, you’ll receive your onboarding training, which may have included the SF 312 Non-Disclosure Agreement, Initial Security Awareness, Derivative Classifier and other required training events and briefings. Even though the Facility Security Officer (FSO) brought you into the system, awarded your security clearance, and performed the required high-level training, there is still much more work to do to ensure you understand how to perform on classified contracts. The high-level training and onboarding is enough to get you “authorized” and prepared for the work. The rest of the preparation will come from other sources to include peers, supervisors and program managers. This training is usually provided on the job as you actually begin performing on the classified contract. ...

Self Inspection Handbook and The FSO-Classified Storage

Image
This section continues our discussion of the DSS’ The Self-Inspection Handbook for NISP Contractors. We are still addressing Section M, classified storage. This update addresses perimeter controls that deter and detect unauthorized removal and introduction of classified information. 5-103 Is a system of perimeter controls maintained to deter or detect unauthorized introduction or removal of classified information from the facility? If so, when, where, and how are these being implemented? According to NISPOM 5-103. Perimeter Controls. Contractors authorized to store classified material shall establish and maintain a system to deter and detect unauthorized introduction or removal of classified material from their facility . Traceability is an important part of protecting classified information. There is plenty of allusion in industry best practices, NISPOM , and training that only TOP SECRET information is to be accountable. There is tremendous direction for application of...

Communicating Your Security Message

Image
NISPOM topics applying to the cleared contractor facility should be addressed as often as possible. Cleared employees may be very familiar with classified performance requirements, but may not always remember countermeasures implemented at the facility to protect classified information. Though they may be excellent at marking documents or using deriviative classification techiques to properly transfer a classification from a security classification guide to a classified report, they may still need to be reminded to attend security training, report suspicious information, or attend threat briefings. Excellence comes from day to day exposure. As their daily performance makes cleared employees experts in their fields, FSOs play a large role in bringing them to that same level of NISPOM compliance. Take the time to understand what training is needed and try to meet that need. Three effective ways to communicate your security message: 1. Group presentations-a popular and fast wa...

NISPOM Change 1-Derivative Classification Decisions

Image
W hat has changed? According to NISPOM Change 1, the cleared defense contractor has the responsibility to provide training for cleared employees who make derivative classification decisions. Where   NISPOM   used to state that training is the FSO’s responsibility, Change 1 omits the FSO as the responsible party and identifies only the contractor entity. Mere oversight or purposeful instruction? This designation represents an important distinction. Now the FSO can strengthen their role in the enterprise and ship from administrator to leader. It is great opportunity for the FSO to shift the training responsibility from performance to oversight. Who should perform the training? At a technical level, the derivative classification training is best provided by the subject matter experts actually performing on   classified contracts , programs and projects. For example, an experienced FSO or designated trainer with a strong security background may be ...

Proscribed Regulations and a Sensible Security Assessment, Cleared Contractor Protection Measures

Cleared contractor facility security officers (FSO) and security specialists have a unique challenge. They protect classified information and have lots of guidance on how to do so. However, they also have to figure out how to best protect sensitive information based on competitive budget requirements. Some of the forces acting on the budget include NISPOM , ITAR and other regulatory requirements as well as actions required by a thorough risk assessment The NISPOM is a proscriptive policy, meaning that FSOs and security specialists have a list of “to do” countermeasures to protect Government identified classified contract information . For example, a secret document should be stored in a GSA approved security container. Other solutions that appear proscribed are standard practices. Some industry standards include access control, alarms and CCTV. One might think they were required based on the general acceptance and wide use. For example, the NISPOM states that SECRET should b...