Posts

Showing posts with the label violations

Forms You Might Need to Know About

These standard security forms are used in administering the security classification programs in Government. Industry members should contact their contracting agency for information on how to obtain these forms. The majority of these items are available through the General Services Administration's (GSA) Federal Supply System. Some of the forms are available online at the GSA web site or can be obtained by calling 1(800) 525-8027. *     SF-312 Classified Information Nondisclosure Agreement The SF-312 is a contractual agreement between the U.S. Government and a cleared employee that must be executed as a condition of access to classified information. By signing the SF-312, the cleared employee agrees never to disclose classified information to an unauthorized person. *     SF-700 Security Container Information The SF-700 is a form that contains vital information about the security container in which it is located. This information includes locatio...

Security through walking around

Perhaps you have already used this term or have at least heard others refer to it on occasion. I have read several articles concerning the subject and am, quite frankly, a fan of the idea. For those new to the term, it means turn off the computer and show your smiling face. If you spend your day processing information at your computer, you don’t get the full security picture. If you only get out to play “gotcha” or to conduct preliminary inquiries into violations, then those you serve only get a partial picture of you. Security through walking around requires a plan. Without the plan you are just milling about engaging in conversation and basically, wasting everyone’s time. A plan will keep you focused as well as prevent the temptations to have conversations and activities that can cause you to lose credibility. The plan doesn’t have to be complicated or lengthy. It just helps direct your purpose, attention and answers questions about your security program’s health. T...

An idea about violations

I was just thinking about the myriad security violations that could have been prevented by using good operations security, communication between cleared co-workers and practicing lessons learned during security training. Once of the biggest culprits of a well rounded security program is the lack of available security violation statistics. There are resources for discovering spy stories or data on espionage, but as far as information about the most common types of violations, mistakes, oversights, etc. the data does not seem to be there. We can’t learn from mistakes if we don’t know what the mistakes are. Good security managers have data of security breaches, violations, reports of compromise or suspected compromise. However, this data rarely leaves their office. Because of the sensitive nature, it is held closely either for fear of retribution or fear of embarrassment. In truth, there is no retribution for security violation reports and information contained could be very valuabl...