By: Jeff Bennett, ISOC, ISP, SAPPC, SFPC
One thing that you can expect to do is either undergo a facility orientation, self-inspection, a DCSA review or both depending on the audit cycle. The DCSA review is a vulnerability assessment that tests security countermeasures and makes determinations of NISPOM Compliance. DCSA will review using their own documentation, however you can prepare by conducting self inspections, employee interviews, reviewing policies and procedures and keeping your FSO Workbook up to date.
Begin with the self-inspection.
The self-inspection program is an excellent way to bot see where you stand on NISPOM compliance and prepare for your security review. Once you are set up with a security program, you what to know the status and help determine whether or not your security posture is where you expect it to be. Begin with a pre-inspection to plan out your actions. According to DCSA, this can be conducted in six steps:
1) Identify all security elements that apply.
Cleared facilities are either possessing or non-possessing. The common denominator is that there are security elements common to ALL cleared companies. These areas are: Facility and Personnel Security Clearance (FCL and FCL), Access Requirement, Security Education, Foreign Ownership Control and Influence (FOCI), and Classification (original and derivative). Possessing facilities will have additional storage, classified processing, NATO and or other considerations covered in the remaining chapters of NISPOM.
Security requirements are found primarily the NISPOM, DD Forms 254, and sometimes in statements of work and other contracts artifacts.
2) Familiarize yourself with how your company's business is structured and organized.Â
This is a task required for registration in SAM.gov as well during the FCL process. This is where DCSA wants to better understand your organizational make up and something, the FSO and SMO should understand.
Is the business a sole proprietor? Then, easy, only one person makes the decisions. How about a corporation such as limited liability corporations, S-Corp, C-Corp, partnership? The business structure determines positions of employment, ownership, or committee that have influence over classified information.
Along with business structure, the Key Management personnel are those identified senior employees who have influence over classified contract performance. In many cases certain FSOs, VP's, board members, and etc. make decisions that impact policy. Most KMP must be cleared unless exempted. KMP identification helps DSS understand who has such decision making authority.
3) Identify who you will need to talk to and what records you may want to review. This list may also be used to identify potential subjects for the security review interview. Be sure to identify who impacts classified contracts, export compliance, performs on classified contracts and determine what classified documents exist if at all on site and what documents exist that reference classified contracts. These documents include classified information receipting actions, DD Forms 254, export licenses and etc.
4) Prepare a list of questions and topics to ask select employees. Be sure to include questions to test an employee's knowledge of NISOM training, access to classified information, performance on classified contracts, foreign travel, need to know enforcement and who the facility security officer is. The Self-Inspection Handbook for NISP Contractors provides lots of sample questions to help you out.
Crosswalk the self-inspection and security review precheck with your SPP, ITP and SEAD-3 Reporting policies. Instead of just selecting yes or no for compliance, develop your narrative. That will assist with answering the security review and Gold Standard Criteria questions.
For more information about preparing for the DCSA Security Review, self inspections, or consulting, contact me or visit the following links:
Get U.S. Government Contracts and Classified Work
https://www.thriveanalysis.com/Â - Consulting
https://www.nispomcentral.com/Â - Books and training
