Introduction To Industrial Security Flashcards
NISP
National Industrial Program Security.
Can a Classified Contract be less restrictive than the NISPOM?
No.
Do Unclassified contracts require rules to safeguard information?
Yes.
NISPOM
National Industrial Security Program Operating Manual
What is the purpose of the NISPOM?
- Defines NISP requirements
- Provides guidance for contractors.
- Ensures uniform security requirements.
CSA
Cognizant Security Agencies
Establish and oversees security requirements
CSO
Cognizant Security Offices
Administer the NISP on behalf of the CSA and provide security guidance, oversight, and policy clarifications
GCA
Government Contracting Activities
* Issues the contract
* Provides contract-specific security classification guidance
* Manage acquisitions
* Oversee security outside of the NISP
Contractor Responsibility According to NISP
Implement NISP requirements
How many CSAs are there?
5
- Department of Defense (DoD) - largest with the most classified contracts
- Office of the Direction of National Intelligence (ODNI)
- Department of Energy (DOE)
- Nuclear Regulatory Commission (NRC)
- Department of Homeland Security (DHS)
Who is the CSO for DOD?
The Defense Counterintelligence and Security Agency DCSA
Where can you find a list of CSOs?
On the CSA website.
Defencse Counterintelligence and Security Agency (DCSA) Responsibilites
- DCSA is the CSO for the DoD
- Provides security guidance, oversight, and policy clarifications
- Conducts security reviews
- Oversees:
Storage of classified information, visit procedures, security awareness and training, Information System (IS) procedures, Personnel Security Clearances (PCLs), Changes in ownership management or foreign involvement, Compliance with reporting requirements
Contractors at their own facility
follow all NISPOM procedures
Contractors at government facilities
follow installation SOPs
The SOPs must be more restrictive than the NISPOM and clearly outlined in the contract
Overseen by installation commander and can ask DCSA to assume cognizance
DCSA is not involved in unclassified work if the contractor is performing on a government installation
SAP (Special Access Program) PMs may retain security cognizance
Classified Information System (IS)
If this IS is at the contractor site and owned by the contractor then they must follow the NISPOM
Governement owned system at contractor site are governed by the NISPOM
Government owned-system has the security requirements provided by the system owner and should be outline in the contract
DSCA - Industrial Security
- Provides oversight
- Conducts security reviews
DCSA Field Office Strcutre
- located around the US
- Led by a Field Office Chief (FOC)
- maintained by Industrial Security Representatives (IS Reps)
DCSA Administration of FCL, PCL, and A&A
Facilities Clearances (FCL)
- Processes companies for FCLs
- Issues FCLs
- Monitors companies that hold FCLs
Personnel Clearances (PCL)
- Processes PCLs
- Monitors personnel security eligibility
and access for contractors
Assessment and Authorization
- determinations for contractor information systems to process classified information