Mastering the FSO Workbook: Your Essential Tool for Security Compliance
The script provides a comprehensive guide on maintaining the FSO workbook, an essential tool for Facility Security Officers (FSOs) to ensure compliance with security protocols. It emphasizes the importance of keeping the workbook updated and secure, outlines key documents and folders that should be included, and provides practical tips for organizing information. The script also recommends printing the workbook before DCSA audits and discusses the importance of consistency in self-inspections and training records. This video serves as an invaluable resource for FSOs, whether they are managing security in-house or through outsourced services.
The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.
After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics.
INDUSTRIAL SECURITY TRUSTED ADVISOR
What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.
Results you can measure immediately:
Prepared commercial organizations for defense contracting and NISPOM compliance
Designed ready to implement security programs before, during and after facility clearance award
Rescued high risk security programs with quick turnaround; usually within 30 days
Achieved Commendable and Superior DCSA review ratings
Developed compliant FOCI mitigation programs
SPEAKER_00
Welcome to DOD Stick Hure and I'm your host Jaspin. Thanks so much for joining us.
SPEAKER_01
Hi, I want to share with you three keys to a successful DCSA review. Now these keys are going to help you build confidence and better prepare for that review. Whether you want to just maintain a satisfactory rating or you want to elevate to commendable or superior, these three keys are going to help you. The first is the FSO notebook, that's your survival tool. The second is the self-inspection program or your health check. The third is the gold standard criteria, which are your war stories. So let's talk about these three and how they are important. First, let's talk about your survival tool, that FSO notebook, the bare minimum that you need to have on hand to measure or demonstrate that you are NISPOM compliance. Why is this important? Because it has all of your facility and personnel clearance artifacts in one place. What I mean by one place, you should have it in two. One is in a printed workbook form in a binder. The other one I recommend is on a network. Why on a network? Because then you can move pieces in and out. Why printed? So you can easily display them to DCSA when they come to do your review. Either way, it must be maintained regularly. This is an important document that provides artifacts that demonstrate you are in compliance. Again, you're going to have artifacts for your facility clearance, such as your nondisclosure agreement and your SF328, as well as your articles of incorporations, things that bring your organization into account. You'll also want to maintain training documents, standard practices and procedures inside of threat program plans, and many other things that DCSA is going to want to look at. The other part is your health check or the self-inspection program. Now you can use the self-inspection handbook for NISP contractors. That's provided by DCSA. It's a wonderful tool. The only thing I don't recommend is doing it all at once. Spread that out over a year. This is a requirement to be uploaded and turned in over a year. However, you want to meet that compliance, but use it as a health check. Go back and forth throughout the year, checking and double checking, again, cross-walking with DIS, NIS, and INBIS, just like you did with that FSO notebook, and maintain this regularly. The third is a gold standard criteria, which I call your war stories. DCSA has a gold standard criteria under the new rating scheme that allows defense contractors opportunities to excel. One, you can use the FSO notebook and get standardized as far as, or use the FSO notebook as a kind of standardization. If you have this completed, you're going to definitely get a satisfactory rating. However, the gold standards allows you to demonstrate commendable and superior capabilities. This is your opportunity to story board your security program. Many people use the term story branding or avatars. Basically, you're making a story about your security program. You're sharing your experiences, having discussions and demonstrations of your ability to implement the NISPOM. What does your management support look like? Are you involved with the community? And what does security education look like? This also must be maintained regularly. You don't want to be cramming for this right before the DCSA review. So in summary, these three cool the notebook, the FSO workbook, the self-inspection program, and the gold standard criteria will give you the confidence to do well during a DCSA review. The FSO workbook is your tool. It's your survival tool as an FSO to get the job done. Now, whether or not you're a do it-it-yourself FSO or you have outsourced FSO or fractal FSO support, maintain your FSO workbook in a place that is secure and where you know where everything is. Why is the FSO workbook so important? It's because this is where you're going to draw your information from when your DCSA rep is doing an audit or a review. This is where you're going to maintain all of your information and be able to do your checks on knowledge checks on tasks. For example, your training records will be in here. Your clear employees' training records will be in here, as well as any facility documents that are updated, or if you do a change condition package in this, or you need to update information in this, it should come from this FSO workbook. This should be in one location where it's maintained. But then prior to the DCS review, I recommend that you print it off. The reason we need it printed is so that you are not showing your files during the DCSA review that are online. Or if your computer does a restart or a hard boot or something goes down in your network, you will be able to access these files. Printing it out in the old school waiting, putting it in a 3D binder, good enough. But whatever works for you, the key point is to maintain this workbook as a living document where information gets updated regularly. So now that we have that established, let me tell you what should be in this FSM workbook. One of the first things you need is a place to put your DD Forms 254. Now, as I go down this list, I have my own workbook that I'm looking at. I'm giving you the topics by alphabetical order. So they don't have to be any particular order. I'm just going down the list. The first should be your DD Forms 254. These are your authorizations to work on classified contracts, and it tells you what classification level is, where the work is to be farmed, and many, many other things. You where you put your current DD Forms 254. If you're a prime contractor, what you get from the government. If you're a subcontractor, you need to put those 254s in that you got from your prime contractor. If you're subbing, you need to put those 254s in that you deliver to your subcontractors. The reason that this is important is because DCSA will review your 254s and crosswalk them against the work that you're doing and the clear employees that you have. These 254s are also important to be in here because prior to your inspection, your rep will want you to upload these 254s into the MIS system and do a facility update. So now you have one place where they all are, it's in a protected environment on your network, and then when necessary, you can upload them into this. The next set of documents is a folder that I have entitled Facility Clearance Documents or FCL documents. And in there, you're gonna have your DD form 441, and it is the non-disclosure agreement between the organization and the U.S. government. The U.S. government says it will provide classified information to the organization and that they will provide oversight. And then the organization will sign in the form saying yes, we will receive classified information and we will protect it during the time that we have that. This form needs to be updated. It's usually good for one time, unless, and these are the times that this needs to be updated. One, you get a change in the company name, you get a change in the company location. But one thing that is important is that you make sure DCSA signs it. There are many times when they do not, so you might just have to contact your rep that they had not signed this document and ask them to sign it for you. And whatever form they sign needs to be the latest update. Now, the next form is the 328. The 328 is the foreign ownership, control, and influence form that you should complete with your leadership and other KMP. This is something the FSO may not know offhand, unless, of course, the FSO is leadership for the company or owns the company. You may need help filling this one out because it determines level if you are and at what level you are under foreign ownership, control, and influence. Again, this form needs to be filled out once and then updated as necessary. This is one of those forms as well that you will upload during your facility update that DCSA will want you to do before they're audited. The next set of folders is maybe personnel files. You might already have that maintained in a database, but sometimes DCSA wants to see a subject report. And then so you can dump your subject report in there and have it ready to present. Some people actually might include all of their employee files in there with employees training, any information that you might need on your employees individually. Some you may already have this maintained on a database, such as if you use PeopleSoft or if you use Mathcraft or SIN software or something else. You may not need a personnel security or a personnel files folder. But if you don't have any other way keeping it up, you can put your clear employees information in this personnel files folder. Again, this should be RNA protected network. So policies and procedures. You may have a lot of policies and procedures concerning security. We recommend that you put it in a policies and procedures folder for presentation to DCSA, as well as make them available to your employees so they can be part of your security culture. One of the things that is hard to demonstrate is that security culture that you're trying to establish. Employees should have access not only to clear employee training, but to the policies that you put out. And in this folder, you may have subfolders. One called this feed three reporting policy. You should have a policy in your organization that demonstrates the reportable information your employees are required to provide to you. This policy should be in that policy and procedures folder. The next policy and procedures that should be in there are the standard practices and procedures. Basically, your security program operations manual. This should be provided to your employees as well. Both of these documents so far should be signed by the senior management official and the FSO. That shows that your leadership is directing this security program and they support it. And they continue to do so with the resources and backup to the FSO. And the final document that we recommend is the insider threat program policy. You may put that in there for your employees to read. Additional documents might be whatever you have that may be appropriate, maybe your security system procedures or your SSP and maybe your insider threat program working group policy. These are just some minimums and some examples you might have in there. DCSA is going to want to look at these policies and procedures, make sure they're available and in hand, and also be able to answer that question. Do your employees have access to this? You can put the policy on your server for the employees to be able to read. You can email them to them or print them out for them. The next one is the security vulnerability assessment. Any past assessments in there, DCSA is going to want to review past assessments, at least your latest one, and see what you put in place. If they had any administrative findings or vulnerabilities that you've mitigated, you want to keep those in those files. DCSA probably has records of, but they will want to see them when they come and look at your organization. And if you've mitigated them, you want to make sure they're continuously mitigated. Maybe it once and they find these vulnerabilities again, you might have a systematic issue. So it's good to have these security vulnerability assessments or VARs in a folder that you can refer to regularly. You might even want to check them against your self-inspections or against any security by walking around that you do, just to make sure there are no systematic errors in place that keep you or your organization repeating these old offenses. The other important part is the self-inspection program. Again, if you find any vulnerabilities or administrative findings or observations in these, go ahead and document them. This self-inspection program should be conducted using the self-inspection handbook for NISP contractors. We at NISPPOM Central provide print copies of NISPPOM and ITAR, as well as books that I've written. But one thing I do want to point out, we do have a hard copy of the self-inspection handbook for NISP contractors that you can purchase and do it by hand. However, we do recommend that you use the online version as well, provided by DCSA, because it populates in certain areas. So you can take the book, the hard book, and walk around and fill it out, but then go ahead and go back and transcribe it onto the downloadable handbook provided by DCSA. And then you want to go and inspect your program. You want to inspect it, it gives all those folders that you've already created. So this workbook, the self-inspection handbook, will crosswalk to the folders. Because in the folders, you'll have all those artifacts that either demonstrate compliance or demonstrate you have areas that need improvement. Now the self-inspection handbook is required to be used to self-inspection is required once a year. It should be once a year at the same time. So if you did last year in August, make sure you do it again this year in August. It's very important. DCS State wants to see consistency. Without that consistency, you could have vulnerabilities or administrative findings. Even though it's due in August, don't do it in August. Do it throughout the year. Make sure that it is another living document that you continue to complete and fill out. Another folder you might want to have are reports or notifications. You want to keep records of notification or reports that your employees provide to you and any reports that you have to submit up to DCSA. Common reports that you might want to keep track of that this is keeping track of is foreign travel. So when an employee requests foreign travel, have a form for them to fill it out, keep that form on file, as well as when they return, they get their foreign travel debriefing. And finally, you want to have folders for training and briefings. In that folder, you want to have all the NISPOM required training that your cleared employees are to undertake. Again, this training should be at a specific time of year. So some FSOs do security awareness training in the first quarter. And then it might be, if they don't combine security awareness training with any other training, they might have the insider threat training in the second quarter. But there's other retraining that is required for some employees, and that is derivative classifier training. And you may have NATO training, SynWIT training, or other specialties training. This folder is for you to keep the training in. So you want to keep if you have online training or some other training that you deliver to your employees, you'll want to have some kind of artifact of what is in that training. So DCSA can review it and make sure all of the criteria are met for that training. And then you want to have another folder for briefings and debriefings. And in this folder, you want to have records of the employees that completed the required trade. Additionally, in these records, you want to keep records that they received their debriefings. Debriefings are very important. DCSA will want to know that even though you went in and did debriefings in this and removed access, you should have some artifact that demonstrates that your employees did have a debriefing and what date that debriefing was accomplished. That's the FSO workbook, your toolkit, your survival tool to ensure that you are running a security program and collecting artifacts of that demonstrate compliance to those security programs, as well as demonstrate what you are doing well and some areas that you may need to be make improvements on. Again, this workbook, FSO workbook, should crosswalk with a self-inspection program and the other leg of the stool that I was telling you about that is called the gold standard criteria. Any questions? Contact me on this platform, send me an email, go to my website, or make comments. We'd love to hear from you and thank you for your support. I hope that this video has helped you. I'm Jeff Bennett, and I'm with Thrive Analysis Group, and I provide fractional FSO support to many different companies. Thank you for the opportunity to share what I've learned. If you have any questions on any of the topics that I just discussed here, contact me in the comments through this platform via email. But by all means, stay tuned. I'll be discussing each of these points in further podcasts, webinars, and via my YouTube channel and this platform as well. I hope you will stay in touch and stay tuned for more information.