Posts

Showing posts with the label security awareness

The fundamentals of protecting classified information and NISPOM

Image
Cleared Defense Contractors use classified information during performance of contracts. The Department of Defense makes the rules and governs how the classified contractors protect classified material. The Federal Government has published a policy appropriately titled: The National Industrial Security Program Operating Manual ( NISPOM ). This page turner is sponsored by the Presidential Executive Order (E0)12829 for the protection of information classified under E.O. 12958, As Amended. Having poured over both publications and the updates, I can conf idently assure you that they take this business very seriously.     When specific work declares performance objectives on classified efforts, provisions of the applicable DD Form 254 and Security Classification Guide (SCG) shall govern. Both the DD 254 and SCG spell out what specific work a contractor can and cannot perform, what exactly is classified and how to protect it. Both of these documents not ...

Conducting Effective Security Training

Image
Check out our podcast Some security training and briefings are very discouraging for the workforce. Many times, the training is the exact same video or presentation used year after year. This podcast and article discusses ways to improve training by making it applicable based on skill level. In other words, someone who has been working on classified contracts for five years or more already understands the three levels of classified information; so why not move on. So, if you go to my website www.redbikepublishing.com , you might find training and tests that do ask those types of questions. That’s because many of my books and training products are specifically for security managers and includes certification study guides. It’s appropriate for me to ask administrative types of questions. It’s unfair to provide that type of training to the workforce.  This topic is specifically about how to make your security training more effective for your work force. There are two types of training...

Insider Threat Program Compliance

Image
This article addresses the NISPOM based Insider Threat Program (ITP) compliance requirements and is inspired by questions from the Self Inspection Handbook for NISP Contractors . The article uses the handbook’s format to through the self-inspection criteria. We begin the topic question, the NISPOM reference, an explanation of requirements, and finally how to inspect compliance. Topic Question(s): Does your ITPSO ensure compliance with insider threat requirements established in the NISPOM and in the implementing guidance provided by DSS? EVIDENCE: Explain who and how and how often oversight reviews are conducted NISPOM Reference(s): 1-207b 1-202 The NISPOM references provided are to measure application of the cleared contractor’s Insider Threat Program (ITP) . However, the compliance is applicable to the broad implementation of NISPOM and security disciplines and not just the ITP.  For example, the NISPOM requires cleared contractors to conduct a secu...

In Depth Insider Threat Training

Image
This article continues the series covering the Self-Inspection Handbook For NISP Contractors and guidance found in the National Industrial Security Program Operating Manual (NISPOM) Incorporating Change 2. This is the second article under the topic of Insider Threat Training . The earlier article addressed the requirement to training, who to train and when. This article addresses what to train. NISPOM 3-103 b states: NISPOM 3-103 b states: All cleared employees must be provided insider threat awareness training before being granted access to classified information, and annually thereafter. Training will address current and potential threats in the work and personal environment and will include at a minimum: (1) The importance of detecting potential insider threats by cleared employees and reporting suspected activity to the insider threat program designee. (2) Methodologies of adversaries to recruit trusted insiders and collect classified information, in particular with...

FSO Training-Get Some

Facility Security Officers (FSOs) wear many hats. Depending on the size of company and mission, they can be completely dedicated to security or serve as FSOs as one of many additional duties. Regardless of where their responsibilities lie, all FSOs should be very aware of NISPOM requirements . When it comes to training, FSOs should be able to effectively train cleared employees of these NISPOM and Contract Security Classification Specification (DD Form 254) requirements. Training requirements vary not only based on mission, but also depend on whether or not the facility is cleared as possessing or non-possessing. A possessing facility is authorized to store and work classified information in the cleared facility. A non-possessing facility cannot. Objectives of the FSO Program Management Course are to prepare the FSO to implement and direct a NISPOM based security program in their cleared contractor facility. DSS offers online courses to both possessing and non-possessing facilit...

Copying Classified Documents

Classified information should only be reproduced in response to a contractual requirement such as in the performance of a deliverable. Reproduction should not be made as a matter of convenience as it puts classified information at unnecessary risk and it requires dedicated resources. The FSO can enforce resource discipline with: 1.  Creating processes and procedures identifying reproduction only as necessary and using only approved equipment 2. Ensuring only trained and authorized personnel are able to reproduce classified information. 3. Identifying office equipment, copy machines, scanners and other reproduction equipment for classified information reproduction. All other enterprise equipment should be off limits to classified reproduction. This can be accomplished through signs identifying authorized equipment as “Approved for Classified Production at the _______ level”. Other equipment would be identified as “Not au...

Three Requirements FSOs Should Include in Cleared Contractor Initial Security Training and Annual Refresher Training

Training is increasingly important as those working in the National Industrial Security Program (NISP) employ security measures at cleared contractor facilities under the National Industrial Security Program Operating Manual ( NISPOM ). Challenges emerge as new technology provides increasing levels of difficulty while protecting classified information. The facility security officer (FSO) should foster an environment where training is encouraged and expected. Developing such relationships with cleared employees create an environment of cooperation. This environment facilitates the recruitment of all employees to protect national security. Those working in the enterprise can be the eyes, ears and muscle, acting as force multipliers, and extending the effectiveness of the security department. FSOs should conduct initial and refresher training and file reports as required by the NISPOM. Instead of conducting NISPOM training with compliance as the end goal, the training can be performed ...

Test your Knowledge with FSO Problems From Chapter 6 DoD Security Clearance and Contracts Guidebook

Test your Knowledge with Problems From Chapter 6 DoD Security Clearance and Contracts Guidebook 1. As a document custodian, your responsibilities include receiving and inspecting documents for proper classification markings. You receive a properly wrapped classified document from a Government agency with the following characteristics:         • Contains UNCLASSIFIED, CONFIDENTIAL and SECRET information      • Created on June 21, 2007      • Reason for Classification is 1.4 (a)      • Contains 400 pages      • Classified by: Jon Wain, RBP, 1022 DDMA      • Classification guidance is found in the Gravy Security Classification Guide 1a. Based on the above description, what are the major areas you would expect to see classification markings? 1b. Write out the “By:” line describing who classified the material, reason for classification and the decla...

3 Ways FSOs Create an Effective Security Culture

How do effective FSOs and security managers develop a culture of compliance with regulations and security programs? Quoting regulations only exasperates cleared employees and the very act does little to foster a climate of cooperation. However, developing relationships based on a good understanding of business, the company mission and influence goes a long way toward implement the successful security program. 1. FSO influences corporate culture-Security of classified information should be part of the organization's DNA. Instead of stove piping security functions, they should tie into the corporate mission. Though each office has a different product, funding or budget item, each fulfills their obligation in a chain of responsibilities necessary to get the product to market. When a business unit breaks down or fails to fulfill its mission, other business units are affected. 2. FSO performs a vital mission of protecting classified informa...
How do effective FSOs and security managers develop a culture of compliance with regulations and security programs? Quoting regulations only exasperates cleared employees and the very act does little to foster a climate of cooperation. However, developing relationships based on a good understanding of business, the company mission and influence goes a long way toward implement the successful security program. 1. FSO influences corporate culture-Security of classified information should be part of the organization's DNA. Instead of stove piping security functions, they should tie into the corporate mission. Though each office has a different product, funding or budget item, each fulfills their obligation in a chain of responsibilities necessary to get the product to market. When a business unit breaks down or fails to fulfill its mission, other business units are affected. 2. FSO performs a vital mission of protecting classified informa...

3 Effective Ways to Go Above and Beyond with Category 7 of the NISP Enhancement

Category 7 of the NISP Enhancement is:  Counterintelligence Integration/Cyber Security provides a tool that cleared contractors can use to demonstrate exceeding NISPOM requirements. Injecting this into the security program also enhances security by bringing to light types and frequency of suspicious contacts. 1.       The purposeful execution of Foreign travel pre-briefings-When employees travel to a foreign country, they may be targeted to provide sensitive information. A threat and/or defensive briefing should be provided to all cleared employees per NISPOM Chapter 3 ( NISPOM Training ). The briefings should be documented with signatures, dates and contents of briefings for presentation to Defense Security Services (DSS) industrial security representatives. 2.     Conducting debriefings once the employees return from foreign travel. It is a tool to follow-up with the threat or defensive security briefing presented prior to the foreign tra...