Enhance Your Security Program with TAG

NISPOM Compliance Starts Here

At TAG, we empower Facility Security Officers with the tools and knowledge needed to ensure robust NISPOM compliance. Our expertise helps you build resilient security programs that stand up to any inspection.

Comprehensive FSO Training

Our tailored training programs equip FSOs with the skills necessary to manage security protocols effectively.

Expert Compliance Guidance

Receive step-by-step guidance to navigate the complexities of NISPOM regulations with confidence.

Tailored Security Solutions

We offer customized solutions that align with your organization’s unique security needs and objectives.

Insights on NISPOM Compliance and FSO Duties

Six Months Gone, Was Certification Part of Your New Year’s Resolution?

By: Jeffrey W. Bennett, ISOC, ISP, SAPPC, SFPC

How are those New Year’s resolutions going? I’ve heard a lot of chatter about preparing for ISP Certification, and was wondering if you are one of the few taking steps to stand apart.

ISP Certification can be yours if you follow the recommendations at the NCMS website. Chances are, if you qualify with the minimum requirements, you have 2 years of great experience under your belt. Now all you need is practice.

Definitely join NCMS’s mentorship program and get their study guide. Once you do that, you may want to take some practice tests. Our study guide has 4 complete tests with 110 questions each.

Join the hundreds of others who have enhanced their study with Master Exam Prep For 32CFR Part 117

Here are some sample questions:

Sample Test Questions

Before taking your ISP Certification Exam, why not test drive a few questions. You can find more at NISPOM.com.

  1. Which of the following are eligibility requirements for an FCL?
    a. The company must be an organization of at least 25 people
    b. The company must have potential for classified access
    c. The company must have a reputation for integrity
    d. The company must make its bottom line for three consecutive quarters
    e. The company is the only one who can perform the work
  2. When can a contractor disclose classified information to another contractor?
    a. Furtherance of contract
    b. Furtherance of business development
    c. When directed by FSO
    d. When directed by CSA
    e. Just as long as other contractor is cleared
  3. Unless restricted by GCA, SECRET material may be reproduced as follows EXCEPT:
    a. In performance of a prime contract
    b. In performance of subcontract in furtherance of prime contract
    c. Upon closure of contract
    d. In preparation of patent applications
    e. In preparation of bid to a Federal Agency
  4. The types of international visit requests include all the following EXCEPT:
    a. One-time
    b. Recurring
    c. Initial
    d. Extended
    e. Emergency

Scroll down for the answers

ANSWERS

1. Which of the following are eligibility requirements for an FCL?

c. The company must have a reputation for integrity

2. When can a contractor disclose classified information to another contractor?

a. Furtherance of contract

3. Unless restricted by GCA, SECRET material may be reproduced as follows EXCEPT:

c. Upon closure of contract

4. The types of international visit requests include all the following EXCEPT:

c. Initial

You have your FCL, Now What

By: Jeff Bennett, ISOC, ISP, SAPPC, SFPC

In my book How to Get U.S. Government Contracts and Classified Work, I cover in depth what happens after you get the new facility security clearance (FCL.) In my Trusted Advisor and consulting role, I consult clients on becoming NISPOM compliant and demonstrating success during security reviews. I wanted to share some information with you in hopes of assisting you with your programs, but also learning from you through comments and recommendations.

In an earlier article, I discussed the FCL process, which many of you may not have experienced. While some of you are new to the NISP and have recently undergone the process as a result of your FSO appointment, the majority of FSOs, especially security professionals, may not have ever gone through the process. While that article is valuable for learning what to do while undergoing the FCL process, this article will assist with how to become a world class FSO even if you are not a security professional.

Once the security clearance is awarded, your responsibility is to establish the security program and protect classified information. Soon enough, your industrial security representative from Defense Counterintelligence and Security Agency (DCSA) will be by to verify those security practices. The most effective way to demonstrate NISPOM compliance is by using your own version of the FSO Workbook. While the FSO Workbook is very indepth, policy and training do stand out. It’s important to get these topics correct.

Essential FSO and ITPSO Policies

Preparation begins with understanding your responsibility and demonstrate compliance. This can be done through building policy, practices, training and infrastructure found in the FSO Workbook and Essential FSO and ITPSO Policies. The least expensive but most time consuming preparation is with policy development. Writing procedures, processes and publishing to build security conscious DNA within a cleared facility is required. Three primary polices are Insider Threat Program Policy, SEAD 3 Reporting Policy and Standard Practices and Procedures. DCSA will eventually review this suite of policies during the next security review. However, keep in mind that cleared defense contractors must state verbally that they do have a written Insider Threat Program policy shortly after the FCL award.

DCSA will review each of the policies, seeking to better understand your security program. The policies should address key issues in NISPOM explained in such a way that the ISR is able to see how you’ve tailored requirements to your organization. These NISPOM application to your organization should be explained will in the policies and the Self-Inspection Program.

Cleared Employee Training

Next, be prepared to provide and track required cleared employee training. The foundational NISPOM required training is initial and refresher Security Awareness and Insider Threat Training. There may be other training requirements depending on contract and whether or not classified work is occurring at your organization, at other locations, and the type of classified work being performed.

DCSA will review not only the training provided,but also will request certificates or lists of personnel trained. The task is to demonstrate that all cleared employees are provided required training and at the right time consistently. The FSO should be able to communicate the training in the policy as well as demonstrate how the training meets compliance and demonstrated in the Self-Inspection program.

Once you establish your best way forward and implement the security policy and training, it’s time to inspect it and ensure that you are able to protect the classified information as required. DCSA has an excellent Self-inspection Handbook for NISP Contractors on their website that can not only prepare you for establishing an award winning security program, but will lead you through a security program validation process in preparation for the security review. Use the handbook, crosswalk with policies and training to get prepared to receive and protect classified information.

For more information about Essential FSO and ITPSO Polices, NISPOM required training and self inspections, contact me or visit the following links:

Jeff’s Guide to Preparing for the DCSA Security Review

Prepare for the DCSA Security Review

By: Jeff Bennett, ISOC, ISP, SAPPC, SFPC

One thing that you can expect to do is either undergo a facility orientation, self-inspection, a DCSA review or both depending on the audit cycle. The DCSA review is a vulnerability assessment that tests security countermeasures and makes determinations of NISPOM Compliance. DCSA will review using their own documentation, however you can prepare by conducting self inspections, employee interviews, reviewing policies and procedures and keeping your FSO Workbook up to date.

Begin with the self-inspection.

The self-inspection program is an excellent way to bot see where you stand on NISPOM compliance and prepare for your security review. Once you are set up with a security program, you what to know the status and help determine whether or not your security posture is where you expect it to be. Begin with a pre-inspection to plan out your actions. According to DCSA, this can be conducted in six steps:

1) Identify all security elements that apply.

Cleared facilities are either possessing or non-possessing. The common denominator is that there are security elements common to ALL cleared companies. These areas are: Facility and Personnel Security Clearance (FCL and FCL), Access Requirement, Security Education, Foreign Ownership Control and Influence (FOCI), and Classification (original and derivative). Possessing facilities will have additional storage, classified processing, NATO and or other considerations covered in the remaining chapters of NISPOM.

Security requirements are found primarily the NISPOM, DD Forms 254, and sometimes in statements of work and other contracts artifacts.

2) Familiarize yourself with how your company’s business is structured and organized. 

This is a task required for registration in SAM.gov as well during the FCL process. This is where DCSA wants to better understand your organizational make up and something, the FSO and SMO should understand.

Is the business a sole proprietor? Then, easy, only one person makes the decisions. How about a corporation such as limited liability corporations, S-Corp, C-Corp, partnership? The business structure determines positions of employment, ownership, or committee that have influence over classified information.

Along with business structure, the Key Management personnel are those identified senior employees who have influence over classified contract performance. In many cases certain FSOs, VP’s, board members, and etc. make decisions that impact policy. Most KMP must be cleared unless exempted. KMP identification helps DSS understand who has such decision making authority.

3) Identify who you will need to talk to and what records you may want to review. This list may also be used to identify potential subjects for the security review interview. Be sure to identify who impacts classified contracts, export compliance, performs on classified contracts and determine what classified documents exist if at all on site and what documents exist that reference classified contracts. These documents include classified information receipting actions, DD Forms 254, export licenses and etc.

4) Prepare a list of questions and topics to ask select employees. Be sure to include questions to test an employee’s knowledge of NISOM training, access to classified information, performance on classified contracts, foreign travel, need to know enforcement and who the facility security officer is. The Self-Inspection Handbook for NISP Contractors provides lots of sample questions to help you out.

Crosswalk the self-inspection and security review precheck with your SPP, ITP and SEAD-3 Reporting policies. Instead of just selecting yes or no for compliance, develop your narrative. That will assist with answering the security review and Gold Standard Criteria questions.

For more information about preparing for the DCSA Security Review, self inspections, or consulting, contact me or visit the following links:

Get U.S. Government Contracts and Classified Work

https://www.thriveanalysis.com/ – Consulting

https://www.nispomcentral.com/ – Books and training

Contact us for CMMC and CUI Protection Resources

Jeff’s Recommendations of What to Expect After Receiving Your Facility Clearance

FSO Consultation

You have your FCL, Now What

By: Jeff Bennett, ISOC, ISP, SAPPC, SFPC

In my book How to Get U.S. Government Contracts and Classified Work, I cover in depth what happens after you get the new facility security clearance (FCL.) In my Trusted Advisor and consulting role, I consult clients on becoming NISPOM compliant and demonstrating success during security reviews. I wanted to share some information with you in hopes of assisting you with your programs, but also learning from you through comments and recommendations.

In an earlier article, I discussed the FCL process, which many of you may not have experienced. While some of you are new to the NISP and have recently undergone the process as a result of your FSO appointment, the majority of FSOs, especially security professionals, may not have ever gone through the process. While that article is valuable for learning what to do while undergoing the FCL process, this article will assist with how to become a world class FSO even if you are not a security professional.

Once the security clearance is awarded, your responsibility is to establish the security program and protect classified information. Soon enough, your industrial security representative from Defense Counterintelligence and Security Agency (DCSA) will be by to verify those security practices. The most effective way to demonstrate NISPOM compliance is by using your own version of the FSO Workbook. While the FSO Workbook is very indepth, policy and training do stand out. It’s important to get these topics correct.

Essential FSO and ITPSO Policies

Preparation begins with understanding your responsibility and demonstrate compliance. This can be done through building policy, practices, training and infrastructure found in the FSO Workbook and Essential FSO and ITPSO Policies. The least expensive but most time consuming preparation is with policy development. Writing procedures, processes and publishing to build security conscious DNA within a cleared facility is required. Three primary polices are Insider Threat Program Policy, SEAD 3 Reporting Policy and Standard Practices and Procedures. DCSA will eventually review this suite of policies during the next security review. However, keep in mind that cleared defense contractors must state verbally that they do have a written Insider Threat Program policy shortly after the FCL award.

DCSA will review each of the policies, seeking to better understand your security program. The policies should address key issues in NISPOM explained in such a way that the ISR is able to see how you’ve tailored requirements to your organization. These NISPOM application to your organization should be explained will in the policies and the Self-Inspection Program.

Cleared Employee Training

Next, be prepared to provide and track required cleared employee training. The foundational NISPOM required training is initial and refresher Security Awareness and Insider Threat Training. There may be other training requirements depending on contract and whether or not classified work is occurring at your organization, at other locations, and the type of classified work being performed.

DCSA will review not only the training provided,but also will request certificates or lists of personnel trained. The task is to demonstrate that all cleared employees are provided required training and at the right time consistently. The FSO should be able to communicate the training in the policy as well as demonstrate how the training meets compliance and demonstrated in the Self-Inspection program.

Once you establish your best way forward and implement the security policy and training, it’s time to inspect it and ensure that you are able to protect the classified information as required. DCSA has an excellent Self-inspection Handbook for NISP Contractors on their website that can not only prepare you for establishing an award winning security program, but will lead you through a security program validation process in preparation for the security review. Use the handbook, crosswalk with policies and training to get prepared to receive and protect classified information.

For more information about Essential FSO and ITPSO Polices, NISPOM required training and self inspections, contact me or visit the following links:

Get U.S. Government Contracts and Classified Work

https://www.thriveanalysis.com/

https://www.nispomcentral.com/

 

Author Bio

Jeffrey W. Bennett, ISOC, ISP, SAPPC, SFPC, has worked in government and contractor security roles involving industrial security, facility security operations, program protection, security classification guidance, and the protection of critical technology. Through Thrive Analysis Group, he helps defense contractors translate NISPOM requirements into practical, documented, and sustainable security programs.

This article provides general educational information. Contractors should follow their contract documents, current DCSA guidance, and the case-specific instructions included with their sponsorship and facility-clearance communications.

Facility Clearance Guide For Defense Contractors

Facility Clearance Guide For Defense Contractors

Facility Clearance Sponsorship: What Small Defense Contractors Need to Do Next

Your customer has a classified requirement. Your team has the technical capability. A government contracting activity or cleared prime contractor is ready to sponsor your company for a facility clearance.

That is a major business opportunity—but sponsorship is not the finish line.

It begins a time-sensitive process involving corporate records, key management personnel, government systems, personnel-clearance actions, security appointments, ownership disclosures, and the development of an operational security program.

For a large contractor with an established security department, those responsibilities may be distributed across several experienced professionals. For a small defense contractor, they often land on the desk of a founder, executive, program manager, engineer, human-resources professional, or newly appointed Facility Security Officer.

That is where a valuable contract opportunity can quickly become an operational burden.

A Facility Clearance Is Tied to Real Classified Work

A facility clearance, commonly called an FCL, is an eligibility determination that allows a company to access classified information at the approved level when required for contract performance.

A company cannot sponsor itself simply because it wants a clearance as a marketing credential. The Defense Counterintelligence and Security Agency requires a legitimate need for classified access, and the company must be sponsored by a government contracting activity or another cleared defense contractor. An FCL is generally required to perform classified contract requirements, although it may also be needed during the solicitation phase when classified access is necessary to prepare a proposal.

The better question for an uncleared business is therefore not:

“How do we get cleared so we can pursue classified work?”

It is:

“How do we become ready so that, when a legitimate classified opportunity and sponsor arrive, we can respond without preventable delay?”

Preparation before sponsorship can make a significant difference.

Once the Welcome Email Arrives, the Clock Is Running

After DCSA accepts the sponsorship request, the company point of contact receives a welcome email containing instructions, responsibilities, and case-specific deadlines.

Current DCSA guidance states that required business-governance documents and facility-clearance forms are due by Day 20. Key management personnel investigation requests and electronic fingerprints are due by Day 45. Those deadlines include weekends and holidays. DCSA also makes clear that incomplete or inaccurate sponsorship and FCL packages may be rejected, while the total time required to issue a clearance depends on variables such as package accuracy, company responsiveness, personnel investigations, and foreign-ownership considerations.

Twenty days may sound manageable—until the company realizes what must be coordinated.

Depending on its legal structure and circumstances, the organization may need to address:

  • CAGE Code and SAM registration information
  • Articles of incorporation or organization
  • Bylaws, operating agreements, or partnership documents
  • Board minutes and corporate resolutions
  • Ownership and foreign-interest information
  • Organizational and governance charts
  • Key management personnel identification
  • FSO and Insider Threat Program Senior Official appointments
  • National Industrial Security System access
  • Personnel-clearance investigation information
  • Electronic fingerprints
  • DD Form 441 and SF 328 documentation
  • Consistency among the sponsorship request, DD Form 254, company records, and requested clearance level

No single item is necessarily overwhelming. The challenge is gathering the correct version of every document, reconciling discrepancies, obtaining system access, coordinating multiple people, and submitting a complete package on time.

Small Errors Can Create Large Delays

DCSA identifies several recurring sponsorship problems, including an unclear justification for classified access, missing government authorization, incomplete DD Form 254 information, and discrepancies between the sponsorship request and supporting contract documents. DCSA also warns that the lack of a CAGE Code, missing governance records, and inaccurate packages can delay or discontinue processing.

Common preventable problems include:

  1. Using different company names or addresses across corporate and government records.
  2. Waiting until sponsorship to locate governing documents.
  3. Submitting a key management personnel list that does not match the company’s actual authority structure.
  4. Failing to prepare necessary personnel for their background-investigation submissions.
  5. Delaying system-access and fingerprint arrangements.
  6. Treating the FCL as a paperwork project instead of the beginning of an ongoing security program.

The facility-clearance process rewards preparation, consistency, and close attention to detail.

Not Storing Classified Information Does Not Eliminate Your Responsibilities

Many small contractors are “access elsewhere” or non-possessing facilities. Their employees access classified information at a government location or another contractor’s facility, but the company does not safeguard classified material at its own office.

That can create a dangerous assumption:

“Because we do not store classified information here, our security program will be simple.”

The program may be less complex than one involving classified storage or information systems, but the company still has responsibilities under the National Industrial Security Program. DCSA specifically recognizes and oversees access-elsewhere companies, and the Senior Management Official’s authority applies even when employees access classified information only at government or other contractor locations.

A non-possessing contractor may still need to manage:

  • Personnel eligibility and access
  • Security briefings and annual training
  • Insider-threat requirements
  • SEAD 3 and other reporting
  • Foreign travel procedures
  • Visit and access coordination
  • Employee onboarding and debriefing
  • Self-inspections
  • Security records
  • Coordination with DCSA, customers, and prime contractors

“Non-possessing” does not mean “noncompliant.”

Security Accountability Begins with Leadership

Facility clearance is not simply an administrative task assigned to an FSO. It is a management responsibility.

Under the NISPOM, the Senior Management Official oversees implementation of the security controls, appoints the FSO and Insider Threat Program Senior Official in writing, and remains informed about the company’s classified operations. DCSA’s current guidance also emphasizes that the SMO retains accountability for the management and operation of the facility.

The roles work together:

The Senior Management Official provides authority and resources.
The SMO ensures that security is supported as a company requirement rather than treated as an isolated administrative function.

The Facility Security Officer executes the program.
The FSO translates requirements into procedures, training, records, reporting processes, personnel actions, and evidence of compliance.

The Insider Threat Program Senior Official oversees the insider-threat program.
The ITPSO ensures that the organization has an operational process for identifying, reporting, assessing, and responding to relevant indicators.

In a small company, a limited number of people may carry several of these responsibilities. That may be workable, but it does not reduce the underlying requirements.

It can also create a business problem. When the FSO is simultaneously an engineer, vice president, human-resources manager, or program manager, every hour devoted to interpreting requirements and chasing documents is an hour taken away from contract delivery, workforce development, and business growth.

Is Your Company a Strong Candidate for Outside FSO Support?

External assistance is especially valuable when any of the following situations sound familiar:

  • A customer or prime contractor expects to sponsor your company soon, but preparation has not begun.
  • Your company received its welcome email, and no one has built a deadline-driven action plan.
  • Leadership is uncertain about who qualifies as key management personnel.
  • Your FSO role was assigned as an additional duty to an already overloaded employee.
  • You are an access-elsewhere facility and are unclear about which NISPOM requirements apply.
  • Policies, appointment letters, training records, and security evidence are stored in different locations.
  • Your company has an upcoming DCSA interaction or self-inspection but is not confident that it can demonstrate implementation.
  • Your security program depends heavily on the knowledge of one person.
  • Your organization is growing, but its security processes have not scaled with it.

The best time to address these issues is before they affect contract performance or attract scrutiny during a security review.

How Thrive Analysis Group Supports Cleared and Soon-to-Be-Cleared Contractors

Thrive Analysis Group provides specialized support for organizations entering or operating within the National Industrial Security Program.

Its services include facility-clearance and entity-eligibility processing, personnel-clearance support, NISS and DISS activities, key management personnel guidance, DCSA liaison support, appointment documentation, security procedures, employee training, insider-threat programs, self-inspections, CUI governance, and FOCI mitigation. Thrive describes itself as a boutique, veteran-owned solution for the defense industry, with services designed around the unique needs of each organization.

Support can begin at several points.

Before Sponsorship

Thrive can help a company assess its readiness, organize governance records, evaluate likely key management personnel, identify missing documentation, and prepare a practical action plan.

This gives leadership time to resolve discrepancies before the welcome email starts the formal timeline.

During the Facility-Clearance Process

Thrive can help coordinate package activities, track deadlines, support government-system submissions, prepare appointment documentation, organize personnel-clearance actions, and communicate with the appropriate stakeholders.

The objective is not merely to submit documents. It is to submit a complete, internally consistent, defensible package.

After the FCL Is Issued

Receiving the FCL begins the company’s continuing obligations.

Thrive can help build the policies, procedures, training, reporting workflows, records, insider-threat processes, and self-inspection practices required to operate a sustainable security program.

When an Existing Program Needs Structure

Some companies already possess an FCL but have accumulated inconsistent files, outdated procedures, undocumented practices, or an overloaded collateral-duty FSO.

Thrive’s FSO Workbook, Gold Standard Criteria, and inspection-focused methodology are designed to translate NISPOM requirements into assigned tasks, documented evidence, and repeatable workflows. The company also offers Self-Inspection as a Service to identify weaknesses and provide prioritized remediation guidance.

Delegate the Work—Not the Accountability

Outside support should not remove company leadership from the security program.

The appointed company officials retain their required authority and accountability. A qualified consultant supports them by performing and organizing much of the detailed work, providing expert interpretation, establishing repeatable processes, and giving leadership better visibility into program status.

That distinction matters.

The goal is not to create a security program that depends permanently on a consultant. The goal is to give the company an effective program today while strengthening its ability to manage future requirements, contracts, employees, and reviews.

Facility-Clearance Readiness Is a Business Issue

An incomplete package does more than generate administrative frustration.

DCSA has stated that package rework adds time to case reviews, delays government access to needed goods and services, affects contractor profitability, and can increase national-security risk. Its updated procedures place greater emphasis on complete submissions and correction of identified deficiencies.

For a small contractor, delays may affect:

  • Contract start dates
  • Employee onboarding
  • Access to customer facilities
  • Program staffing
  • Revenue recognition
  • Customer confidence
  • Future classified opportunities

Facility-clearance preparation is therefore not merely a compliance activity. It is part of contract execution and business-risk management.

Do Not Wait for Day One

A classified contract can be transformative for a small defense contractor. It can also reveal weaknesses in documentation, governance, staffing, and security operations.

Those weaknesses are easier to correct before deadlines begin.

Whether your company expects sponsorship, has already received its welcome email, or needs to stabilize an existing security program, Thrive Analysis Group can help you organize the work, meet immediate requirements, and build an operational program that supports continued growth.

 

Author Bio

Jeffrey W. Bennett, ISOC, ISP, SAPPC, SFPC, has worked in government and contractor security roles involving industrial security, facility security operations, program protection, security classification guidance, and the protection of critical technology. Through Thrive Analysis Group, he helps defense contractors translate NISPOM requirements into practical, documented, and sustainable security programs.

This article provides general educational information. Contractors should follow their contract documents, current DCSA guidance, and the case-specific instructions included with their sponsorship and facility-clearance communications.

Beyond CMMC. Why You Should Develop an Information Control Plan

The Opportunity

Defense contractors fulfilling CMMC requirements should also consider developing an information control plan. While the CMMC certification evaluates systems, the plan will address information residing on the systems and networks.

Where NIST provides technical guidance and NISPOM might address the protection of classified information, there is still a need to address adequate protection of other information such as TAR, CUI, FGI and proprietary.

The Problem

Take a look at this paraphrase from Allen Dulles’ book The Craft of Intelligence:

In the 1950’s the US Congress was concerned that there was just too much technical information available on government programs. From that concern, they commissioned researchers to assemble as much information from the public domain about a particular program as they could. The group scoured libraries, newsstands, TV, radio and other media common to the decade and provided a report. As a result, the government determined the information to be classified, safeguarded the information and disbanded the group. The lesson; intimate program details were not properly identified, marked and protected.

Here are a few examples of where this happens today.

  1. CMMC ratings evaluate a contractors ability to protect data that resides on networks, devices and computers. However, the data residing on protected networks and devices is not marked. CMMC measures technical countermeasures to protect the data. However, the additional requirement is to “Develop a CUI program or information control plan complete with methods, policies and training. This is usually an area that falls under the IT manager, an expert at countermeasures, but not intimately knowledgeable of the information being protected.
  2. An employee is required to provide white papers, pamphlets, or technical drawings for public events such as a conference or publication. While the employee is an expert on their information, they may not understand which products (drawings, technical references, research results, etc.) are CUI, ITAR or proprietary. This is usually an area controlled by a compliance officer, FSO, or other employee, who may not be familiar with the technical information. When the employee uses technical drawings to provide required products, and reviews are not in place, there is a potential CUI or ITAR violation.
  3. Employees create work products, deliverables, purchase orders, etc and are distributed through shared drives, emails or other public facing methods. This becomes an issue where reference documents such as technical manuals, statement of work, or other source documents and products are marked CUI, export controlled, or proprietary information, but not identified in derived products.

 

There are so many situations, too many to put into one article, on how vulnerable technical information can be. The above three situations can lead to information and data release violations if the correct measures are not taken.

Don’t believe the hype

Let’s use CUI as an example of what should be part of an information protection plan and how to apply it. There is bad advice going around that says: “contractors are not authorized to determine CUI”. or “contractors are not authorized to mark CUI on documents”. Don’t fall for this, it’s your responsibility to identify, document and control information.

How to implement your own program

For example, while it is true that the government determines what information is CUI, contractors can derive CUI in products created from CUI source documents. Further, if a contractor is creating blueprints or providing a product using a source document marked CUI or export controlled, then anything produced from that source should carry over the new creation.

Unfortunately, sensitive information derived by contractors is not always carried over into work instructions, purchase orders, technical drawings, or other products. The solution can’t be only technical controls found in NIST, rather is should include the other requirements for applying an information control plan with the following objectives:

  1. Identify or recognize source products
  2. Train employees to identify protected source documents
  3. Label and catalog decisions
  4. Develop public release review process to ensure protected information is not released
  5. Publish policies and training to ensure it is complete
  6. Implement self-inspection

 

The work effort is huge, but rewarding. It involves working groups, records and accountability.

However, you might consider getting assistance. Where third party services ensure NIST compliance and perform CMMC reviews, they do not create CUI programs or information control plans as described above. If you need assistance with developing your program, please reach out to us.

Contact us for CMMC and CUI Protection Resources

The FSO should be plugged into on boarding and off boarding of cleared employees

Human Capital or Human Resources on board employees into the organization. This has been a practice for years and works very well. Part of onboarding should include verification of eligibility to work as well as execution of a background check.

With cleared defense contractors, FSOs should be incorporated into the onboarding process. The FSO role is to either grant access to already cleared personnel, initiate background investigations for those not already cleared, and prepare employees to execute on classified contracts.

In many organizations, HR and FSOs might be the same person or share the same office. In this case, the onboarding process for cleared employees may not be an issue as the employees are either the same or shared.

In larger organizations, the FSO and HR may be separated by distance, offices or other circumstances. However, they should be working together from onboarding to termination of cleared employees. Here are some important things to consider:

  • If HR only uses I9 for employment eligibility, which does not determine citizenship, just eligibility to work.
  • FSOs must ensure U.S. citizenship, which requires passport, birth certificate and or citizenship documents such as naturalization forms, therefore should be part of the on boarding process. Where I9 requires driver’s license or SSN, be sure to check citizenship
  • FSOs must ensure cleared employees remain eligible. This may require involving HR in policymaking and documentation of employee non-compliance
  • FSOs must debrief employees when access is no longer required, therefore should be part of the off boarding process

As your company grows, consider ensuring your FSO is part of the growth and has the opportunity to execute their requirements to demonstrate NISPOM compliance.

Security Through Email; Not a Best Practice

How many emails does it take to for an FSO to get a Visit Authorization Request (VAR) approved

 

a. 4

b. 10

c. 1

Hopefully your answer is none of the above. However, it’s more likely that the answer for some of you is unfortunately, four or more. Some have commented that they have exchanged email correspondence up to 10 times with a subject before finally getting the information needed to complete the VAR request in the Defense Information System for Security (DISS). 10 or more emails per VAR; multiply that by the number of employees and that’s a lot of attention. Now, let’s add foreign travel and other required reports. Using email as the primary information gathering resource can significantly increase administrative workloads.

Why use email for FSO tasks at all.

For those of you who work in cleared facilities with large budgets, you might ask the same question and it’s a good question. In your case, you might be enjoying the benefits of a dashboard and all of the benefits of being a well trained security professional and perhaps even a security team in support. As such, you might rarely get emails for security tasks as each employee might have their own portal.

However, there are a large number of FSOs who are not security professionals and have been appointed to the position and may not be aware of a better way. Many of the FSOs I serve are managing tasks through email and it does involve a lot of time devoted to answering email, requesting additional information and so much more. These email tasks are tedious and if they already receive abundant emails with their full time job, they could get buried, lost or misfiled.

A better way

While these FSOs may not have the resources such as security dashboards for employee and FSO tasks, email can be incorporated into their procedures, but should not be the primary way of gathering information.

The danger with email is that it’s email and not a very good system for tasking. Additionally, the information that is required to complete reports and requests in DISS is sensitive and unsecure email may create a vulnerability. There is a better way

Here are a few recommendations for making your FSO tasks more efficient and secure.

  • Create a fillable form or eform for each type of request or report. Duplicate required DISS fields to create the forms.
  • Upload form on shared drive for employees to access, populate and send to FSO
  • Create an FSO Workbook to file forms, archive documents and demonstrate NISPOM Compliance

Email is a great communication tool, but not a good tasking mechanism. For example, an email can be used to notify and FSO that a form has been filled and ready to process. It may be a great way to remind employees to take their training. However, conducting operations and tasks via email may lead to a breakdown in efficiency and compliance.

If you would like to see some sample forms, contact me and I’ll be happy to provide.

If you are ready for consultation, program building or creating your own FSO Workbook and system contact me.

Alternatively, you can download files, folders and templates in our FSO Workbook product. I’ll also be happy to set that up.

How to Gain an Absolutely Unfair Advantage at Security Reviews

 

By: Jeffrey W. Bennett, SAPPC, SFPC, ISOC, ISP

Demonstrating NISPOM compliance requires both an in-depth knowledge of NISPOM requirements and the ability to grasp administrative tasks.

For example, the cleared company’s Senior Management Official (SMO) and Facility Security Officer (FSO) implement the NISPOM within their organization to address risk to classified information. While these leaders oversee and execute NISPOM requirements, there may be issues with demonstrating how they are meeting compliance. With a bit of organization, compliance can be easily demonstrated with the correct artifacts and documentation.

In my newsletter, I tackle NISPOM compliance and lead with three pillars. One of which is a continuous study of NISPOM and application of FSO and NISPOM professional development; both critical to technical proficiency. The other resource is the Self-Inspection Handbook for NISP Contractors, which covers all NISPOM topics.

Using the handbook as a professional development and assessment strategy, let’s tackle how to demonstrate compliance under the “Procedures” topics.

One task is the identification of a Senior Management Official (SMO) who is responsible for overseeing the security and Insider Threat programs, reporting requirements and security operations.

Compliance is measured by the SMO’s execution of their role and delegation of tasks. When the Defense Counterintelligence and Security Agency (DCSA) conducts the security review, they will determine how SMO is exercising their role, approving procedures and resourcing programs.

The SMO appoints the FSO and the Insider Threat Program Senior Official (ITPSO) in writing. Additionally, the SMO should sign, endorse and require the implementation of the following NISPOM required procedures:

  • Insider Threat Program
  • SEAD-3 Reporting
  • Standards, Practices and Procedures (SPP)

These procedures should be tailored for the organization. Once they are signed and implemented, they can be incorporated into training, presentations and available to employees. Appointment memos and policies can be signed and available to DCSA for review. However, let’s level up.

For example, one question asks, “Has the company developed and implemented an Insider Threat Program endorsed by the SMO”. The answers are: YES, NO or NA. You can select an option and move to the next question.

However, I always recommend populating the narrative space with how the practices are implemented. That way the FSO can rehearse answers, provide written documentation and verbally demonstrate how requirements are met. Let’s proceed to the narrative.

How Implemented/Notes: _________________________________

This provides a white space for answers. Take the opportunity to write explanations as completely as possible. Most answers may translate to address DCSA’s Gold Standard Criteria, allowing the facility to possibly meet Commendable and Superior rating criteria.

For example:

How Implemented/Notes: “Our ITPSO developed a robust program policy and briefed it to the SMO who approved and signed it. The policy is available to each employee and referenced in Insider Threat Program training and Insider Threat Program Working Group training. Our organization also analyzes insider threat information with IXN Solutions or other third party vendor software”

Again, this narrative assists with the future DCSA review. However, it takes a well educated FSO to be up to the task. FSOs should incorporate professional development that provides increasing and measurable technical proficiency. This NISPOM foundation also provides understanding of the application of The Self-Inspection Handbook for NISP Contractors. Attend professional development opportunities and use the handbook to verify education and compliance.

Your NISPOM Compliance Questions Answered

u

What is the role of a Facility Security Officer?

A Facility Security Officer (FSO) is responsible for overseeing and implementing a security program that complies with NISPOM requirements, ensuring the protection of classified information.

u

How can I ensure my facility is NISPOM compliant?

To ensure NISPOM compliance, conduct regular audits, provide ongoing FSO training, and stay updated with regulatory changes. TAG offers comprehensive support to help you maintain compliance.

u

What are the key responsibilities of an FSO?

Key responsibilities include managing security clearances, conducting security training, and ensuring adherence to NISPOM guidelines.

u

How often should security training be conducted?

Security training should be conducted at least annually, with additional sessions as needed to address specific updates or changes in regulations.

u

What is NISPOM?

The National Industrial Security Program Operating Manual (NISPOM) outlines the requirements for safeguarding classified information within cleared contractor facilities.

u

How does TAG assist with FSO tasks?

TAG provides expert consulting services to help FSOs manage their duties effectively, offering training, compliance audits, and tailored security solutions.

u

What are the consequences of non-compliance with NISPOM?

Non-compliance can lead to penalties, loss of security clearances, and damage to your organization’s reputation. Ensuring compliance is essential for maintaining operational integrity.

u

How can I stay updated on NISPOM changes?

Stay informed by subscribing to industry newsletters, attending relevant workshops, and consulting with experts like TAG who monitor regulatory updates.

u

What resources are available for new FSOs?

New FSOs can benefit from TAG’s comprehensive training programs, mentorship opportunities, and access to a wealth of industry resources to build their expertise.

Key Features of Our FSO Programs

Comprehensive Compliance Audits

Our audits ensure your security program aligns with all NISPOM requirements, identifying gaps and providing actionable insights.

Tailored Training Solutions

We offer customized training programs that empower your team with the knowledge and skills needed to maintain compliance.

Proactive Risk Management

Our strategies focus on identifying potential threats and implementing measures to mitigate risks before they impact your operations.

Our Consulting Services

NISPOM Compliance Consulting

We provide expert guidance to ensure your organization meets all NISPOM standards efficiently.

FSO Capability Building

Develop your internal FSO capabilities with our hands-on training and support services.

Security Program Development

We assist in designing and implementing robust security programs tailored to your specific needs.

Inspection Preparation

Our team prepares you for successful inspections, minimizing disruptions and ensuring compliance.

Enhance Your Security Program Today

Contact TAG for expert guidance in developing compliant and resilient security strategies tailored to your needs.

13 + 11 =