
You have your FCL, Now What
By: Jeff Bennett, ISOC, ISP, SAPPC, SFPC
In my book How to Get U.S. Government Contracts and Classified Work, I cover in depth what happens after you get the new facility security clearance (FCL.) In my Trusted Advisor and consulting role, I consult clients on becoming NISPOM compliant and demonstrating success during security reviews. I wanted to share some information with you in hopes of assisting you with your programs, but also learning from you through comments and recommendations.
In an earlier article, I discussed the FCL process, which many of you may not have experienced. While some of you are new to the NISP and have recently undergone the process as a result of your FSO appointment, the majority of FSOs, especially security professionals, may not have ever gone through the process. While that article is valuable for learning what to do while undergoing the FCL process, this article will assist with how to become a world class FSO even if you are not a security professional.
Once the security clearance is awarded, your responsibility is to establish the security program and protect classified information. Soon enough, your industrial security representative from Defense Counterintelligence and Security Agency (DCSA) will be by to verify those security practices. The most effective way to demonstrate NISPOM compliance is by using your own version of the FSO Workbook. While the FSO Workbook is very indepth, policy and training do stand out. It’s important to get these topics correct.
Essential FSO and ITPSO Policies
Preparation begins with understanding your responsibility and demonstrate compliance. This can be done through building policy, practices, training and infrastructure found in the FSO Workbook and Essential FSO and ITPSO Policies. The least expensive but most time consuming preparation is with policy development. Writing procedures, processes and publishing to build security conscious DNA within a cleared facility is required. Three primary polices are Insider Threat Program Policy, SEAD 3 Reporting Policy and Standard Practices and Procedures. DCSA will eventually review this suite of policies during the next security review. However, keep in mind that cleared defense contractors must state verbally that they do have a written Insider Threat Program policy shortly after the FCL award.
DCSA will review each of the policies, seeking to better understand your security program. The policies should address key issues in NISPOM explained in such a way that the ISR is able to see how you’ve tailored requirements to your organization. These NISPOM application to your organization should be explained will in the policies and the Self-Inspection Program.
Cleared Employee Training
Next, be prepared to provide and track required cleared employee training. The foundational NISPOM required training is initial and refresher Security Awareness and Insider Threat Training. There may be other training requirements depending on contract and whether or not classified work is occurring at your organization, at other locations, and the type of classified work being performed.
DCSA will review not only the training provided,but also will request certificates or lists of personnel trained. The task is to demonstrate that all cleared employees are provided required training and at the right time consistently. The FSO should be able to communicate the training in the policy as well as demonstrate how the training meets compliance and demonstrated in the Self-Inspection program.
Once you establish your best way forward and implement the security policy and training, it’s time to inspect it and ensure that you are able to protect the classified information as required. DCSA has an excellent Self-inspection Handbook for NISP Contractors on their website that can not only prepare you for establishing an award winning security program, but will lead you through a security program validation process in preparation for the security review. Use the handbook, crosswalk with policies and training to get prepared to receive and protect classified information.
For more information about Essential FSO and ITPSO Polices, NISPOM required training and self inspections, contact me or visit the following links:
Get U.S. Government Contracts and Classified Work
https://www.thriveanalysis.com/
https://www.nispomcentral.com/
Author Bio
Jeffrey W. Bennett, ISOC, ISP, SAPPC, SFPC, has worked in government and contractor security roles involving industrial security, facility security operations, program protection, security classification guidance, and the protection of critical technology. Through Thrive Analysis Group, he helps defense contractors translate NISPOM requirements into practical, documented, and sustainable security programs.
This article provides general educational information. Contractors should follow their contract documents, current DCSA guidance, and the case-specific instructions included with their sponsorship and facility-clearance communications.