Introduction To Industrial Security Flashcards
NISP
National Industrial Program Security.
Can a Classified Contract be less restrictive than the NISPOM?
No.
Do Unclassified contracts require rules to safeguard information?
Yes.
NISPOM
National Industrial Security Program Operating Manual
What is the purpose of the NISPOM?
- Defines NISP requirements
- Provides guidance for contractors.
- Ensures uniform security requirements.
CSA
Cognizant Security Agencies
Establish and oversees security requirements
CSO
Cognizant Security Offices
Administer the NISP on behalf of the CSA and provide security guidance, oversight, and policy clarifications
GCA
Government Contracting Activities
* Issues the contract
* Provides contract-specific security classification guidance
* Manage acquisitions
* Oversee security outside of the NISP
Contractor Responsibility According to NISP
Implement NISP requirements
How many CSAs are there?
5
- Department of Defense (DoD) - largest with the most classified contracts
- Office of the Direction of National Intelligence (ODNI)
- Department of Energy (DOE)
- Nuclear Regulatory Commission (NRC)
- Department of Homeland Security (DHS)
Who is the CSO for DOD?
The Defense Counterintelligence and Security Agency DCSA
Where can you find a list of CSOs?
On the CSA website.
Defencse Counterintelligence and Security Agency (DCSA) Responsibilites
- DCSA is the CSO for the DoD
- Provides security guidance, oversight, and policy clarifications
- Conducts security reviews
- Oversees:
Storage of classified information, visit procedures, security awareness and training, Information System (IS) procedures, Personnel Security Clearances (PCLs), Changes in ownership management or foreign involvement, Compliance with reporting requirements
Contractors at their own facility
follow all NISPOM procedures
Contractors at government facilities
follow installation SOPs
The SOPs must be more restrictive than the NISPOM and clearly outlined in the contract
Overseen by installation commander and can ask DCSA to assume cognizance
DCSA is not involved in unclassified work if the contractor is performing on a government installation
SAP (Special Access Program) PMs may retain security cognizance
Classified Information System (IS)
If this IS is at the contractor site and owned by the contractor then they must follow the NISPOM
Governement owned system at contractor site are governed by the NISPOM
Government owned-system has the security requirements provided by the system owner and should be outline in the contract
DSCA - Industrial Security
- Provides oversight
- Conducts security reviews
DCSA Field Office Strcutre
- located around the US
- Led by a Field Office Chief (FOC)
- maintained by Industrial Security Representatives (IS Reps)
DCSA Administration of FCL, PCL, and A&A
Facilities Clearances (FCL)
- Processes companies for FCLs
- Issues FCLs
- Monitors companies that hold FCLs
Personnel Clearances (PCL)
- Processes PCLs
- Monitors personnel security eligibility
and access for contractors
Assessment and Authorization
- determinations for contractor information systems to process classified information
IS Rep
- contractor primary POC for security
- Works closely with the FSO to provide advice, assistance, and oversight
- conducts security reviews of the contractors security program
- Receives changed conditions and suspicious contact reports
- Receives security violation reports, conducts inquiries, reports security violations to the GCA
- Coordinate with other entities within DCSA to oversee all aspects of contractor security (international operations, personnel security, counterintelligence’s, authorized information systems, specials programs.
ISSP/SCA
Works with IS Reps and contractor personnel authorization and maintenance of Information Systems
- perform classified Information Systems assessments and make recommendations
- security reviews, evaluate vulnerabilities, identify potential cyber security threats and help develop mitigation strategies
- respond to security violations involving authorized classified Information Systems
- Develop and maintain technical proficiency
CISA
Contractors
- Identify potential threats to US technology
- Develop employee CI awareness/reporting
- assist with foreign travel briefings and debriefings
IS Reps
- provide advice, assistance, and guidance regarding CI best practices
- help conduct security reviews
Installation Commander/Agency Head Responsibilities
- servers as CSO for government-controlled and government-leased facilities
- Oversee installation security
-review and update installation directives to reflect NISPOM guidance for contractors working on the installation
Contractor Facility Roles
FSO: Facility Security Officer
- effectively manages the security program
- oversees day to day security program operation
ISSM: Information Security Manager
- Manages classified IS security if applicable
ITPSO: Insider Threat Program Senior Official
- establish and execute an Insider Threat Program
FSO can serve as all three
All 3 roles must be filled in order to serve on a classified contract