Posts

Showing posts with the label spp

Legacy of the Facility Security Officer (FSO)

You might already know how to write policy that reflects the NISPOM and export compliance or ITAR regulations. That might very well be an easy task for you. Just like ISP certification mentioned in an earlier post, the policy itself should not be the catch all solution. Just as the certification compliments the bearer’s capabilities, the policy should complement the processes and procedures you have in place. Policy tells what should happen and is in itself easier to write and have approved than the how to do it found in processes and procedures. Even if you do not know how to write policy, you can always download a boilerplate standard practice procedures, technology control plan, or sample security policies downloaded from Defense Security Services (DSS), or shared by fellow security professional organization contacts. What won’t be so easy to find is policy tailored to your specific needs and how to incorporate them into company business. That will require teamwork with othe...