Posts

Showing posts with the label vulnerability

Applying Risk Analysis to Cleared Defense Contractors

Image
DSS has announced new Vulnerability Assessment Rating Matrix 2013 Update. The matrix does provide a good way to gauge the security program. Even though the threat, vulnerability and impact are already identified, an FSO should still use a risk assessment model. The way to get to good evaluations and enhanced measures is to analyze the protection of classified information and demonstrate how the NISPOM is implemented. A risk analysis provides that answer. The NISPOM and other guidance make our jobs easy. For example, if it’s classified lock it up in a GSA approved container and limit access to those with clearance and need to know. The above is simplified for discussion purposes, but it makes the point, there is another piece to protection; analysis. You might be familiar with the terms susceptibility, vulnerability and risk analysis. These are analyses that we in the defense industry should be regularly practicing, but as demonstrated above, NISPOM makes it easy for us to get by w...

Vulnerability Assessment Rating Matrix 2013 Update

Image
In case you haven't seen the release, http://www.dss.mil/isp/fac_clear/security-rating-matrix.html , DSS has announced new Vulnerability Assessment Rating Matrix 2013 Update. This matrix provides DSS with a way to gauge a cleared defense contractor's compliance with NISPOM. But, it also gives the contractor a methodology to evaluate their own performance. Think of it as a way to enhance your own self-inspection. But let’s go back to DSS, what are they looking for in this analysis? During the annual review, DSS will look at a cleared facility and run through a consistent and reliable process to determine whether or not procedures are in place to adequately protect classified information. As mentioned earlier, the threat and impact are already identified. So, vulnerability is simply a reflection of the proscribed protection measures outlined in NISPOM and the inspection and not an analysis conducted by the FSO. Vulnerability per DSS occurs when a contractor is not in compli...