FSO PROS Snippet Category: Security Policies & Reporting Requirements
Monthly Newsletter
Understanding security incidents and staying vigilant in our daily work are essential to protecting national security, our organization, our customers, and our data. This month, we’re focusing on how to recognize a security incident, understand the difference between an infraction and a violation, and ensure proper and timely reporting.
Defining Security Incidents: Infractions vs. Violations
A security incident is any occurrence that involves, or could reasonably lead to, the loss, compromise, or suspected compromise of classified information or controlled unclassified information (CUI).
While 32 CFR Part 117 (NISPOM) governs classified information requirements, most government contractor organizations operate under multiple federal frameworks (FAR, DFARS, NARA etc.), and incidents involving CUI must also be reported.
Security incidents typically arise when a required security procedure was not followed or was improperly applied. Examples include unsecured classified or CUI documents, improper receipt or handling of information or access credentials, or spillage involving classified information on an unclassified network or CUI on networks not authorized to handle CUI.
Incidents are categorized as either a security infraction or a security violation. It’s easy to confuse these terms, but the distinction is important for determining required responses and reporting.
Security Infraction
A Security Infraction is a security incident that does not result in the loss, compromise, or suspected compromise
of classified information. Infractions require an initial inquiry to facilitate immediate actions, identify root causes, and take corrective action to strengthen the security program. Although an infraction is not a security violation, uncorrected or repeated infractions can increase risk and may eventually contribute to a compromise.
Security Violation
A Security Violation is a security incident that did or reasonably could result in the loss or compromise of classified information. Violations require a formal investigation, documented analysis, and a final determination.
In either case, Security Incidents can be intentional, unintentional, or inadvertent and can reveal recent or recurring patterns of questionable judgment, irresponsibility, negligence, or carelessness.
How Compromise is Determined
Security incidents are evaluated to determine whether classified information was lost, compromised, suspected of compromise, or not compromised.
Loss: Loss occurs when classified information cannot be physically located or accounted for (for example, material discovered missing during an audit and not immediately located). If classified information is transmitted through unsecure means, it is treated as a loss at a minimum and may be elevated depending on exposure.
Compromise: Compromise occurs when there is an unauthorized disclosure of classified information to an individual who does not possess the appropriate clearance, access authorization, or need‑to‑know.
Suspected Compromise: Suspected compromise occurs when identifiable classified information was made available to unauthorized individuals who may have gained access. Although proving direct access may be difficult, the facts would lead a reasonable person to conclude unauthorized access more than likely occurred. Examples include physical or electronic storage of classified information in unsecured areas for extended periods where unauthorized personnel had unrestricted or unmonitored access.
No compromise: A no‑compromise determination is made when the facts show that no classified information was lost, compromised, or suspected of compromise. Contractors must still produce a final report documenting the incident and determination.
Although compromise determinations under 32 CFR Part 117 (NISPOM) apply primarily to classified information, organizations must make similar assessments related to potential exposure of CUI in accordance with applicable federal requirements.
These determinations guide the required reporting steps and ensure the incident is handled in accordance with 32 CFR Part 117 (NISPOM) requirements.
Reporting Security Incidents
What to Report
Any event, large or small, that could involve the loss, compromise, or suspected compromise of classified information, or could otherwise affect the confidentiality, integrity, or availability of organizational systems or data, is a security incident and must be reported.
Security incidents may also involve CUI, which must be safeguarded and reported in accordance with federal handling requirements.
Report any occurrence involving:
- Improper handling, storage, or transmission of classified information or CUI
- Classified material found in an unapproved or unsecured location
- Possible loss, compromise, or suspected compromise
- Unsecure communication channels used for classified discussions or data
- Spillage of classified onto an unclassified network, system, device, or platform
- Spillage of CUI onto an unauthorized system, device, network, or platform
- Improper receipt or handling of classified information or CUI
- Questionable access situations (e.g., personnel without a verified need‑to‑know near classified material)
- Passwords, access badges, authentication tokens left out in plain sight
- Lost or stolen access cards, badges, authentication tokens, materials, etc.
- Unlocked workstations or devices left unattended
- Security containers left unlocked in a secured area
- Anything unusual, unsafe, or out of place involving classified information or security procedures
If you discover anything that may indicate a security procedure was not followed, or may not have been in place, report it immediately. If you’re ever unsure, err on the side of reporting.
How to Report
All security incidents, whether categorized as infractions or violations, must be reported immediately upon discovery. Prompt reporting allows the security team to:
- Contain risks before they escalate
- Investigate root causes, determine the incident category, and determine if classified has been compromised
- Protect systems, data, and personnel
- Provide required notifications to the Cognizant Security Agency (CSA) when applicable
A “wait and see” approach creates avoidable gaps that threat actors and environmental factors can easily exploit.
Report all security incidents to the appropriate security POCs immediately upon discovery:
- Company FSO (always)
- Host U.S. Government (USG) security staff, if located at a government location
- Host contractor security staff, if located at another contractor location
Share what you know at the time; additional details can be added as they develop.
You should never be penalized for reporting a concern in good faith. Underreporting introduces far more risk than reporting something that ultimately proves harmless.
Any occurrence that may involve classified information or controlled unclassified information being lost, improperly handled, exposed, accessed by unauthorized individuals, or placed at risk must be reported immediately. If you see something unusual, unsafe, or out of place, report it.
Why Reporting Matters
Timely reporting is essential to maintaining a secure operating environment. When incidents are reported quickly, security personnel can take immediate action to contain risks, determine whether classified information was exposed, and ensure all requirements under 32 CFR Part 117 are met. Early notification also helps prevent small issues from becoming major vulnerabilities and ensures the organization consistently protects classified information, personnel, and mission objectives. Ultimately, reporting strengthens our overall security posture and supports full compliance with Government standards.
Resources and Additional Learning
CDSE Job Aid Special Circumstances for Reporting Security Incidents
CDSE Security Incidents Reporting Requirements
32 CFR Part 147 (Adjudicative Guidelines)
As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.
Unauthorized disclosures rarely begin with bad intentions. More often, they happen during quick conversations, fast moving emails, working in the wrong system, or assuming everyone in the room already has the appropriate need to know.
For those of us supporting the National Industrial Security Program (NISP), protecting classified information and Controlled Unclassified Information (CUI) is part of our daily responsibilities. While cyber and physical security tend to get most of the attention, routine interactions can create risks if we aren’t careful.
Understanding Unauthorized Disclosure
An unauthorized disclosure occurs any time classified information or CUI ends up somewhere it shouldn’t—whether shared with someone without proper access, stored on the wrong system, discussed in an uncontrolled environment, or otherwise mishandled.
Authorization requires more than simply holding a clearance. The recipient must have:
- The appropriate level of clearance (if classified)
- A valid need to know
- Authorization to access the specific information
If any one of these elements is missing, the disclosure is NOT authorized. Let’s clear up a common misconception.
Myth: “If someone has a clearance, I can discuss classified information with them.”
Fact: A clearance alone is not enough. Access requires a demonstrated need to know and any program specific authorizations.
CUI: A Frequently Overlooked Risk
Many personnel are comfortable spotting risks involving classified information but overlook CUI—material protected by law, regulation, or government wide policy even though it isn’t classified.
A few examples include, but are not limited to:
- Procurement sensitive information
- Export controlled data
- For Official Use Only (FOUO) or Sensitive but Unclassified (SBU) material
- Controlled technical information
- Privacy information (PII)
CUI does not require a clearance, but it does require authorized access, approved systems, and proper safeguarding. We should treat CUI with the same level of care we apply to preventing classified spills.
Everyday Risks: Classified & CUI
Unauthorized disclosures often come from ordinary activities and habits:
- Forgetting to check if an email thread contains CUI before hitting “Reply All”
- Pulling up sensitive documents during virtual meetings without verifying participants
- Mixing classified and CUI discussions without confirming what can be shared
- Copying/pasting project details into public facing documents
- Uploading CUI to unapproved collaboration tools or storage locations
Small oversights can create big vulnerabilities.
How Unauthorized Disclosures Happens
Here are a few real world situations we may encounter:
- Mentioning a milestone schedule in front of visitors, not realizing it is CUI
- Receiving a draft with embedded CUI that wasn’t marked
- Getting a “quick context” question from someone whose access level is unclear
- Moving between networks and saving sensitive files in the wrong location
None of these feel reckless, but they still count as unauthorized disclosures.
Unauthorized disclosures can also occur in everyday environments:
- Discussing sensitive work in public places such as airports, restaurants, or elevators
- Forwarding emails without confirming all recipients are authorized
- Using the wrong collaboration platform or distribution list
- Leaving sensitive material visible during virtual meetings or screen sharing
- Assuming a coworker “already knows” without verifying need to know
Most of these situations are preventable with a brief pause to verify before sharing.
Good Habits for Preventing Unauthorized Disclosure
Before sharing sensitive information, ask yourself:
- Who is receiving this information?
- Do they have the appropriate authorization and need to know?
- Is this the correct communication method?
- Am I sharing only what is necessary for the task?
A few simple behaviors go a long way:
- Check classification and CUI markings when opening, editing, or sharing documents
- Verify access and need to know—even when you think someone is read in
- Keep sensitive conversations in controlled spaces and on approved systems
- Slow down before sending emails, especially cross organization
- Properly mark CUI according to DoD or agency specific guidance
- When uncertain, pause and ask—your security team is here to support you
These habits take only seconds and help prevent reportable security incidents.
Reporting Mistakes
Mistakes happen—and fast reporting is critical.
If you believe protected information may have been disclosed to an unauthorized person:
- Stop any additional sharing
- Preserve any relevant information
- Notify your Facility Security Officer (FSO) immediately
- Avoid trying to resolve the issue on your own
Prompt reporting allows your security team to assess the situation, limit potential damage, and meet mandatory reporting requirements.
Final Thought
Protecting information isn’t about making work harder—it’s about ensuring sensitive information reaches only those who are authorized to receive it. A quick verification today can prevent a security incident tomorrow.
This Month’s Challenge: Before sending your next sensitive email or discussing a protected project, take five seconds to verify the recipient, the need-to-know, and the communication method. Small habits make a big difference.
Want to Learn More?
Resources and Additional Learning
CDSE Unauthorized Disclosure of Classified and CUI
CDSE Unauthorized Disclosure Student Guide
CDSE Unauthorized Disclosure Toolkit
National Archives Unauthorized Disclosure Prevention and Reporting
32 CFR Part 147 (Adjudicative Guidelines)
As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.
Tax season is a great time to discuss financial considerations, and life changes that federal contractors and federal contractor personnel must report.
Every individual that works in and around the U.S. Government is a potential target for exploitation by malicious actors intending to do harm to the United States and its people. Certain situations make us more susceptible to compromise and we must be aware of those that must be reported to our company’s Facility Security Officer (FSO).
Financial Difficulties and Distress
One of the easiest pathways for our adversaries to elicit information is through offers of gifts and money or threats of exposing our difficulties.
Financial distress can happen to anyone and may be caused by a variety of circumstances. Regardless of the reason, when a person is overextended or having difficulty satisfying debts, there is a greater risk that they might engage in illegal or questionable activity to generate additional funds. Financial pressure makes us a prime target for exploitation.
Unexplained Affluence
Unexplained affluence refers to a lifestyle, standard of living, or accumulation of wealth that cannot be reasonably attributed to a person’s known income or legal sources. It can be a red flag, suggesting that a person may have access to illegal or undisclosed sources of income, and raises concerns about the person’s trustworthiness or vulnerability to bribery or coercion.
Financial Awareness and Reporting Financial Considerations
Keeping a close eye on your financial data and credit information can help you identify if you are running into financial difficulty and if there is any questionable activity happening in your name. All 3 credit bureaus will allow you to run your own credit report for free each year. We recommend you run all 3 annually.
If you suspect your Social Security number is being used fraudulently, contact the Social Security Administration at www.ssa.gov or call toll-free at 1-800-772-1213.
Reporting Financial Considerations — The following circumstances must be reported to your company’s FSO:
- Excessive indebtedness or inability to satisfy debts
- History of not meeting financial obligations
- Unpaid obligations over 120 days, liens, judgements, collections
- Bankruptcies, foreclosures, or wage garnishments
- Deceptive or illegal financial practices (embezzlement, fraud, etc.)
- Failure to file, pay, or fraudulently filing Federal, state, or local income tax returns
- Any indicator of unexplained affluence inconsistent with known income sources
- Borrowing money or engaging in significant financial transactions to fund gambling
- Receipt of a large sum of money, property, or wealth not readily identifiable by typical income (e.g., inheritance, lottery winnings, proceeds from sale of a home)
- Concern that your identity or credentials have been compromised
Changes in Personal Status / Life Changes
If you have been granted security clearance or suitability for access to sensitive information, the following life events and changes must be reported to your company’s FSO:
- A name change, for any reason
- Marriage, separation, or divorce
- Changes in cohabitation status
- Cohabitation with any Non-U.S. citizen
- New relatives and additions to your family (new children by birth or adoption)
- Adoption of Non-U.S. citizen children
- Any change in U.S. citizenship status
- Change in employment status
- Change in need for access to classified information
Why Reporting is Critical
Despite the cause, both financial difficulties and unexplained affluence can raise concerns about an individual’s reliability, trustworthiness, and ability to protect classified or sensitive information.
Financial considerations must be reported immediately upon occurrence. Changes in personal status must be reported to your company’s FSO as soon as you become aware that the change will occur.
Resources and Additional Learning
- CDSE Financial Considerations
- DCSA Reporting Changes, Concerns, or Threats
- Experian Credit Bureau
- Equifax Credit Bureau
- Transunion Credit Bureau
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!
All cleared contractor facilities are required to have written procedures in place that dictate how their facility will implement and maintain a system of security controls within the organization in alignment with the requirements of 32 CFR Part 117 (NISPOM rule) and other U.S. Government laws and policies.
Two written policies that every cleared facility should have are:
- A Security Standard Practice Procedures (SPP)
- An Insider Threat Program Plan (ITP)
The Security Standard Practice Procedures (SPP)
The Security Standard Practice Procedures (SPP) is a written document that implements requirements for the contractor’s operations and involvement with classified information. Key aspects of a SPP include:
- Opening Statement: Outlines the purpose of the document and includes a statement of support for the National Industrial Security Program (NISP).
- Facility Information: States the company’s facility clearance level, classified storage requirements, and outlines security roles within the organization.
- Personnel Security Clearances: Outlines how personnel clearances for employees and consultants are handled.
- Reporting Requirements: Outlines reporting requirements for both personnel and the facility, and establishes the necessary processes and procedures all company personnel are required to follow.
- Security Education: Outlines the training requirements for the organization per U.S. Government and contractual requirements.
- Self-Inspections: Outlines how the organization will meet self-inspection requirements and the intervals at which the company will perform these inspections.
- Classified Visits and Meetings: Outlines how classified visits and meetings will be handled.
- Safeguarding Classified Information: Establishes the organization’s procedures for protecting classified information.
The Insider Threat Program Plan (ITP)
The Insider Threat Program Plan (ITP) is a comprehensive strategy designed to deter, detect, and mitigate potential threats posed by individuals within an organization who have authorized access to sensitive information or systems. Key aspects include:
- Risk assessment: Identifying critical assets and evaluating the likelihood of an insider threat occurring.
- Employee screening: Conducting thorough background checks and reference verifications during the hiring process.
- Access controls: Implementing strong user access management practices, including the least privilege principle.
- User activity monitoring: Continuously monitoring employee actions on company systems to detect suspicious behavior.
- Security awareness training: Regularly educating employees about insider threat risks and reporting procedures.
- Incident response plan: Defining clear steps for investigating and responding to potential insider threats.
Insider Threat Program Plans must also consider balancing privacy concerns, establishing clear reporting mechanisms without fear of retaliation, and promoting a culture of security awareness.
How and Why Is This Relevant to You?
All cleared contractor personnel, both employees and consultants, are required to follow all policies and procedures set forth in company and U.S. Government policies. Your organization is required to make security policy documents available to you and all personnel. If you do not know where to find them, please contact your company’s security team immediately.
If you have any questions or concerns about the security policies within your organization, your FSO and Insider Threat Program Senior Official can certainly assist. You should never hesitate to reach out to your FSO and ITPSO for guidance.
Resources and Additional Learning
- CDSE Resources for Standard Practice Procedures
- Written Standard Practice Procedures for Industry Video
- DCSA Information about Insider Threat
- Deliver Uncompromised Toolkit
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions about security or reporting requirements, ask your FSO! FSO PROS® is here to help you navigate things to ensure you fulfill all requirements.