The Six Step Risk Assessment Process for Cleared Defense Contractors and FSOs
The facility security officer should conduct an assessment of classified holdings to determine vulnerabilities, threats, and risk to classified information. This risk assessment is above and beyond what has been determined by the original classification authority (OCA) and as applies to the National Industrial Security Program Operating Manual (NISPOM). Where the OCA has determined classification level, the NISPOM provides guidance on how to protect the classified information. The mission piece is the defense contractor and how they protect the classified information by format and location. It's not always good enough to rely on NISPOM requirements as the environment may dictate additional countermeasures. For example, SECRET and CONFIDENTIAL information can be approved for storage in a GSA approved container. However, if the defense contractor is in a high crime area, additional physical security measures may be necessary. That's where the 6 step risk management pro...