Posts

Showing posts with the label security education

4 Steps to Winning the Cogswell Award

So, which companies will win the Cogswell Award this year? FSOs who take the time to develop a world class program designed to protect classified information are very deserving of the award. Here are four proven steps to help you demonstrate that your organization is going “above and beyond” NISPOM requirements: 1. Set security goals that everyone understands. These goals help create the organization-wide security culture that everyone can live with. 2.   Conduct institutional training that support these goals. Ensure the training encourages your employees to report any and all security violations, suspicious contacts, and foreign travel, which will further enhance those efforts. 3. Goals should be tracked and institutional training and expectations should be conducted   in preparation for the annual security inspection. Do this by implementing a daily security management process, which includes physical security, visitor control, and security education throughout the ye...

8 Simple Steps FSOs use to Inspect Classified Deliveries

Image
The FSO should ensure all arriving classified information is inspected and received into accountability. This due diligence is conducted to ensure that classified information has not been compromised, is related to a contract, and is properly marked. Regardless of transmission methods of physical items (mail, courier, overnight, hand carry and etc.) classified material should be double wrapped. Each layer serves to protect the classified material from inadvertent and unauthorized disclosure and should be properly addressed. The classified information should be wrapped and sealed in opaque material or envelopes. The NISPOM does not cover seams of wrapped items, but a good practice is to cover seams with rip-proof opaque tape or other material that prevents and detects tampering. All seams of the outer layer should be sealed with opaque tape in an effort to create a solid layer of covering. The item should be wrapped and sealed wit...

Appointing the Right FSO

The Cleared Contractor appoints a Facility Security Officer (FSO) to protect the work on classified contracts and provide important administrative functions to maintain the security clearanc e of the business and cleared employees. However, the FSO can be much more impacting by applying understanding of four important functions: 1.  How to protect classified information as it relates to the cleared contract, organizational growth, enterprise goals, and NISPOM guidance 2.  How to conduct a risk analysis 3.  Demonstrate cost, benefits and impact of supporting a classified contract under the NISPOM requirements and sustain an environment of cooperation and compliance within the enterprise. 4.  Influence and compel the senior leaders to make good decisions, support compliance and integrate security into the corporate culture. After all, good industrial security practices protect against damage to national security, but cou...

3 Effective Ways to Go Above and Beyond with Category 7 of the NISP Enhancement

Category 7 of the NISP Enhancement is:  Counterintelligence Integration/Cyber Security provides a tool that cleared contractors can use to demonstrate exceeding NISPOM requirements. Injecting this into the security program also enhances security by bringing to light types and frequency of suspicious contacts. 1.       The purposeful execution of Foreign travel pre-briefings-When employees travel to a foreign country, they may be targeted to provide sensitive information. A threat and/or defensive briefing should be provided to all cleared employees per NISPOM Chapter 3 ( NISPOM Training ). The briefings should be documented with signatures, dates and contents of briefings for presentation to Defense Security Services (DSS) industrial security representatives. 2.     Conducting debriefings once the employees return from foreign travel. It is a tool to follow-up with the threat or defensive security briefing presented prior to the foreign tra...

Why the US Government Assigns Classification Levels and the DoD Contractor Responsibilities

The US Government has designed policy to ensure that classified material is protected at the level designated to prevent unauthorized disclosure. Classified information is marked by an original classification authority (OCA) with CONFIDENTIAL, SECRET or TOP SECRET and cleared contractors should protectect it at the appropriate level. TOP SECRET has more restrictions than SECRET and SECRET has more restrictions than CONFIDENTIAL. Each must be protected according to the classification markings. For example, unauthorized disclosure of CONFIDENTIAL information could reasonably be expected cause damage; SECRET could reasonably be expected to cause serious damage; and TOP SECRET could reasonably be expected to cause exceptionally grave damage to national security. The OCA provides classification level information through the DD Form 254, security classification guide and through classification markings. When the classification level is determined, all related classified inf...

10 Ways to Demonstrate Above and Beyond - Category 3 of the NISP Enhancement

Category 3 of the NISP Enhancement covers Security Education: Information/Product Sharing Within the Community.  This focuses on the FSO providing security education peers and other FSOs outside of their organization. This is a security community event where contractors and government managers can learn from each other. Think Society of Industrial Security, American Society of Industrial Security, or other professional organization level event. Or it can be a smaller venue. Either way, involve others outside of your organization. This demonstrates contribution to the community, a pursuit of improving national security, and helps quantify going above and beyond. For example, an FSO uses their facility, creates an agenda and executes a security conference or training event. Or, committees can be formed to share the tasks. Education of this magnitude has tremendous value as the security community learns from experiences and examples of their peers and applies them at their own organ...

5 Easy Ways to Demonstrate NISP Enhancement Category 2

Category 2 of the NISP Enhancement covers Security Education: Internal Educational Brochures/Products. This focuses on the FSO providing security education to the entire employee population. This is in addition to security awareness training provided to cleared employees (employees with security clearances) required by NISPOM. What is the benefit of training cleared and uncleared employees? Uncleared employees can be the eyes and ears that are needed and add an additional layer of protection.   For example, cleared employees can be trained to recognize classified information. If a classified package is unattended, the cleared employee can be trained to recognize the sensitivity and report the incident to the FSO. Otherwise, they may take possession, read it, throw it away or otherwise cause compromise of classified information.   Here are some recommendations on how to provide that training:   CD/DVD-Defense Security Services, Interagency OPSEC Support Staff and ot...

National Industrial Security Program-NISP Enhancement

Category 1 of the NISP enhancement involves company sponsored events. This is an opportunity that the FSO can use to demonstrate above and beyond adherence to NISPOM Chapter 3. Some of the suggested ideas include: ·          Security fairs-Security fairs are great ways to demonstrate the added value security provides to the cleared defense contractors. The FSO can set up designated booths that functions to provide security solution and awareness. For some examples include: ·          Document wrapping booth to demonstrate how to properly mark and wrap classified packages. You can take the opportunity to brief courier and other classified transport opportunities. ·          Fingerprint booth-As FSO I ordered children’s finger print cards. When we had a company picnic, I invited all the parents to come by to get their children fingerprinted. I then turned the completed...
Experience, commitment and practice are the best qualities to prepare the professional for the necessity of good old fashion networking. Networking is especially necessary in high trust and vulnerability industries like security where peers, colleagues and co-workers closely guard information. A career in security is rewarding and challenging. The work is important, cleared contractor employers count on FSO skills to maintain classified contracts and national security depends on proper protection of classified information. The security professional requires a high degree of interaction as paths cross in training, collaboration or through contractual execution. Security professionals are traditionally somewhat guarded discussing business with new or otherwise unknown persons. Security professionals require time to develop trusting working relationships and getting to know important connections in a timely manner is important. So, how do we accelerate this networking curve? 1. Fost...

5 Steps to Hiring the Perfect Security Employee

Image
Your company is growing and you find yourself reassessing your security team needs. Or, you find yourself severely lacking the personnel required to effectively perform security functions . In either case, it is up to you to hire the perfect employee. Find the perfect employee? Though a daunting task, it is important that you hire and build a team of excellent security managers. Never, ever settle for a warm body just to get the job done. Many of you know from experience the issues of hiring the wrong candidate bring about. There are a few good observations about potential candidates that can further them into the hiring process. These are 5 considerations you should employ befire hiring a security team member. 1.  All qualified applicants must reflect the company culture. What kind of employee does the company value? You must know this before you begin the search process. If your company values initiative, make sure your prescreen selects thinkers who can execute securi...

3 Ways FSOs can Have a More Effective Security Program

The Facility Security Officer’s (FSO) successful program depends on developing relationships with employees, managers and executives to facilitate execution of company policies, necessary security awareness training, willful employee self-admittance of security infractions or change of status, and proactive action toward expired, existing and future classified contracts. Any of the above mentioned success measures is difficult to obtain in a changing employee and contract environment, but is simplified through employee and executive buy-in. How to do this: The following 3 points pave the way for a successful security program. 1. Gain executive, manager and work force buy-in. This can be accomplished by first demonstrating a sound understanding of company mission, classified contract requirements and providing sound security policy. Cross cultural buy-in is critical for integrating the security plan into all business units and company operations. 2. Become the “go to” person for...

5 Effective Ways to Study For the ISP Certification Exam

Out of the approximately 3500 NCMS members nearly 325 hold the ISP certification.   The test is challenging and candidates are expected to score at least 75% for a passing grade. Why Certify?   The ISP holder demonstrates a high level of knowledge. The certification is based on the NISPOM but also covers electives such as: COMSEC, OPSEC, and other topics. This certified professional communicates to upper management that they are committed to the business, the industry and the protection of national interests. It puts the company in a stronger position while bidding on contracts and lends credibility to relationships with the oversight agency the Defense Security Services (DSS). Most of all, it gives the bearer confidence in their ability to apply their knowledge. As this certification program evolves, more and more employers will require the certification. Preparing Only those working in the National Industrial Security Program for at least 5 years are edible for the I...

2 Steps to Determining Need to Know

Take a look at the following dramatization. A Facility Security Officer (FSO) is engaged in an inquiry to determine whether or not a security violation led to the loss, compromise or suspected compromise of classified information. A cleared employee had left classified information out on his desk. A cleared employee asked another cleared employee to “keep an eye” on a classified document while she left for lunch. A short time later, the second employee was summoned to his bosses office to answer some questions. He left in a hurry, forgetting about the classified information on the desk. At first glance, the unattended classified information is the most obvious violation. However, once the inquiry concluded another issue became evident. The co-workers did not work on the same contract or share in any kind of project relationship. The first co-worker entrusted the safeguarding of classified information to an employee who held the proper security clearance, but who did not have need to kn...

Five ways to improve annual security refresher training

Give your cleared employees the training they need to be able to focus on how to protect their classified contracts. We all know that to check the block, the annual refresher training should complement the initial security training. But does it have to be the same presentations over and over? Engineers, supervisors, program manager and others are extremely intelligent and want to be challenged. Here aer some great suggested to help you do just that.      1. Build on last year’s training. Many FSOs make the mistake of providing initial security briefing every year with here’s how to mark, lock it up in a security container, and on and on. This insults people’s intelligence and limits your effectiveness.   For example, you might demonstrate the importance of reporting by highlighting how reporting has helped reduce security violations or even streamlined a process.      2. Make training relevant to the cleared employee’s mission. Things to conside...

Comix

Image

Forms You Might Need to Know About

These standard security forms are used in administering the security classification programs in Government. Industry members should contact their contracting agency for information on how to obtain these forms. The majority of these items are available through the General Services Administration's (GSA) Federal Supply System. Some of the forms are available online at the GSA web site or can be obtained by calling 1(800) 525-8027. *     SF-312 Classified Information Nondisclosure Agreement The SF-312 is a contractual agreement between the U.S. Government and a cleared employee that must be executed as a condition of access to classified information. By signing the SF-312, the cleared employee agrees never to disclose classified information to an unauthorized person. *     SF-700 Security Container Information The SF-700 is a form that contains vital information about the security container in which it is located. This information includes locatio...
Security in depth is a concept similar to peeling back the skin of an onion. Each layer you pull back reveals another layer. The more you peel back, the more layers remain. Eventually you wear it away, but it takes a while to get there. According to Defense Security Service DSS security training, "Security-in-depth is a concept that employs security measures in levels or steps."  This concept can be demonstrated in a walk through a virtual walk through a cleared facility. The cleared facility is approved to store secret information. As such, the only requirement is to keep the classified information in a General Services Administration GSA approved container or safe.  Let's begin at the security container. The container provides the deter and detect capability necessary to protect the secret information, documents or hardware. It is difficult, but not impossible to break the container open, but once you do, it will be difficult to hide the damage. Therefore, you'l...

Risk Management and NISPOM

     The risk assessment helps FSOs focus countermeasures to protect classified information from actual identifiable threats by probability. Risk management helps the FSO determine how to protect the classified information above and beyond the NISPO M guidance. The same approach should be used in determining which parts of the NISPOM apply to an FSO’s facility. For example, a non possessing facility that performs classified work at another facility should not focus security efforts on protecting classified processing.                 However, they should focus their efforts on NISPOM chapters 1, 2, 3 and 6 parts of chapter 5 and Appendices A and C; the parts of NISPOM that apply to ALL cleared contractors.       The NISPOM’s first chapter is dedicated to general industrial security concerns. The chapter is divided into three sections which provide the introduction, general and reporting requirements.    ...

From "DoD Security Clearance and Contracts Guidebook" Not to Readers

The defense industry is booming and cleared contractors are benefiting. Those who know how to execute classified contracts are in demand. Additionally, the Departments of Defense, Department of Energy, the Nuclear Regulatory Commission, Central Intelligence Agency and many other Federal and supporting contractors are in great need of experienced and qualified security specialists, managers and Facility Security Officers. As the industry becomes more demanding and positions more competitive, today’s security specialists need to be on top of their game. Go beyond the Presidential Executive Orders and the National Industrial Security Program Operating Manual. Being technically proficient is great, but building an award winning security program gets you noticed. Make the move from being an administrator to becoming the "go to" security manager. Learn everything you can to better understand what it takes to get security clearances and move to the next step of protecting classif...

How Cleared Contractors Appoint Facility Security Officers

Image
  Excerpt From Our Newest Book  Becoming a cleared defense contractor demands more than just a defense contractor getting a security clearance. It's more to do with, what to do once the clearance is awarded; specifically, protecting classified information. This protection involves physical, classified processing, and information security. It's more than just buying safes, installing access controls and getting employees security clearances. Primarily, the cleared contractor must appoint a Facility Security Officer (FSO) responsible for implementing a program to protect classified information. To better answer frequently asked questions, I've written several times on the topic of selecting the right Facility Security Officer (FSO) qualifications. According to the National Industrial Security Program Operating Manual (NISPOM), the FSO must be a US Citizen and be cleared to the level of the facility (security) clearance (FCL); period. This provides a lot of room ...