The holiday season is approaching quickly! While maintaining strong security practices should be a primary focus throughout the year, it is important to understand the increased threats during the holiday season.
The hustle, bustle, and general spirit of celebration that we experience during the holidays can lead to distraction and lower our guard. Unfortunately, criminals and our adversaries don’t slow their nefarious goals simply because we are busy, distracted, or nurturing kindness during the holidays. In fact, this gives them a better opportunity to exploit us.
Holiday OPSEC
OPSEC (Operations Security) is a five-step process used to identify and protect sensitive information from our adversaries:
- Identify What Needs Protection
- Analyze the Threat
- Analyze Vulnerabilities
- Assess Risk
- Apply Countermeasures
These same concepts can, and should, be used to protect ourselves, our families, our homes, and our data during the holiday season.
Safety in Public and Crowded Places
- Situational awareness! No matter where you are, always be mindful of your surroundings.
- Have an exit plan and know how to contact the authorities if something goes sideways.
- If anything feels off, say something.
- Take care when carrying large amounts of cash. Look out for “shoulder surfers” looking to steal your credit card information.
- When out purchasing gifts, consider bringing items back to your vehicle as you shop and placing them in your trunk, out of sight.
Data Security
- Always follow all company and government data security protocols.
- Never use company-issued or government-furnished equipment for online shopping.
- Consider a personal VPN to help secure your data.
- Use strong passwords, change them frequently, and never share them with anyone.
- Whenever possible, use multi-factor authentication.
Online Shopping
- Know that scams and phishing are especially heightened during the holidays.
- Know how to identify safe and secure websites.
- Always follow safe and proper cybersecurity practices.
- Remember: If it sounds too good to be true, it probably is!
Securing Your Home During the Holidays
- Protect and control your house keys, door codes, and garage access codes with extreme caution.
- Keep a light on, even when you are not at home.
- Keep valuables out of sight.
- Consider a home security system and video surveillance system.
- Be wary of canvassers and anyone requesting access to your residence.
- Mind who is “hanging out” in your neighborhood and report any suspicious activity.
- Care what you share publicly and on social media.
Protect Your Home When You’re Gone
More than 80 million Americans travel 50+ miles from home during the holidays, leaving personal space vulnerable. Studies show that 40% of burglaries do not involve forced entry and most burglars are deterred by simple safeguards.
Secure your home:
- Lock every door and window, including your garage door
- Activate your home security system
- Put valuables in a safe or safety deposit box
- Remove “hidden” keys
Don’t make it look like you’re not home:
- Never post travel plans on social media
- Consider putting lights, TVs, or radios on intermittent timers
- Don’t leave trash and trash cans at the curb
Foreign Travel
If you are traveling outside the US, don’t forget to report it to your FSO! For most of us, all personal and professional foreign travel requires reporting. Ideally, foreign travel should be reported 30 days in advance of departure.
Resources and Additional Learning
- DLA Holiday Safety & Security
- CISA Online Shopper Safety
- CISA Cybersecurity Best Practices
- National Safety Council Holiday Safety
As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!
Have you ever received a phishing email? If so, you have experienced an attempted cyber-attack.
Cyber threats are a very real and persistent risk to us all, both personally and professionally. Cyber-attack attempts happen every single day. They are low-risk, potentially high-reward, and advances in technology have made it easier than ever. No one is immune to a cyber-attack and everyone is a target.
Understanding Cyber Threats and Attacks
A cyber-criminal is any individual or group that uses technology to commit illegal acts, such as stealing data, conducting fraud, or disrupting services. They can be petty criminals, hackers, terrorists, foreign intelligence agents, or even a compromised insider.
A cyber-threat is any malicious act with the intent to steal data, disrupt digital systems, damage information, or gain unauthorized access to a computer network or sensitive data.
A cyber-attack is any deliberate attempt to access, damage, or disrupt a computer system, network, or digital device.
Common Types of Cyber-Attacks
- Phishing/Spear Phishing/Spoofing: Deceptive emails, messages, or websites designed to trick individuals into revealing sensitive information.
- Malware: Malicious software like viruses, worms, and spyware that can steal data, disrupt systems, or gain unauthorized access.
- Ransomware: A type of malware that encrypts a victim’s files and demands a ransom for the decryption key.
- Man-in-the-Middle (MitM) attacks: An attacker secretly intercepts and possibly alters communications between two parties.
- Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS): Attacks that overwhelm a server or network, making it unavailable to its intended users.
- SQL Injection: A technique where attackers insert malicious code into a server’s database.
- Zero-Day Exploit: An attack that targets a vulnerability in software before the developers are aware of it.
- Password Attacks: Attempts to gain access to accounts by guessing passwords or using brute force methods.
What is the Goal of a Cyber-Attack?
Ultimately, cyber-criminals want to obtain or steal information that can be sold or used to exploit an individual or organization. High value targets include:
- User login IDs and passwords
- Personally Identifiable Information (SSN, date of birth, addresses)
- Financial and Banking information
- Sensitive organizational documents
- Proprietary information
- Information regarding U.S. government funded contracts
- Classified, CUI, Sensitive, and Export-Controlled information and technology
Spotting a Cyber-Attack
Phishing/Spear Phishing indicators:
- Emails or messages that seem to be from a trusted source but are not
- Urgent and suspicious requests asking you to take immediate action
- Significant spelling or grammatical errors
Unusual System and Performance Issues:
- Slow performance, freezing, or frequent crashes
- Disabled security software
- Unknown software or browser toolbars appearing
- Constant pop-ups
Suspicious Network and Internet Activity:
- Abnormal network traffic or unexplained spikes in activity
- Your browser redirects you to unfamiliar websites
- Your contacts report receiving strange emails from your account
- Unauthorized access to systems or unauthorized data transmission
Applying Countermeasures to Protect Against a Cyber-Attack
All Personnel:
- Never use default passwords. Make your passwords complex, change them regularly, and don’t reuse them.
- Never share your passwords with anyone.
- Never open emails, attachments, or click links from unfamiliar sources.
- Report any suspicious or unusual issues with equipment or devices to your IT department immediately.
- Know what to report and who to report it to within your organization.
Management and IT Departments:
- Implement Defense-in-Depth: a layered defense strategy including technical, organizational, and operational controls.
- Update anti-virus software daily and download vendor security patches as soon as they are available.
- Monitor, log, analyze and report attempted and successful intrusions to your systems and networks.
- Train all personnel on proper cybersecurity procedures.
- Conduct frequent computer audits — ideally daily, at minimum weekly.
Why Reporting is Critical & How to Report Concerns
Personnel should report any suspected cyber-attack to the company’s IT department and their FSO immediately. Organizations that do business with the U.S. Government must report any cyber intrusion or attempted intrusion through proper USG channels. Cyber intrusions must be reported within 24 hours of occurrence!
Resources and Additional Learning
- Cyber Awareness Challenge
- CDSE Cybersecurity Shorts
- CISA Cyber Incident Reporting Act
- DoD Cyber Crime Center – Report a Cyber Incident
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!
September is Insider Threat Awareness month! While insider threat is a significant concern that must be considered throughout the year, we would like to take a little time this month to emphasize the importance of deterring, detecting, and mitigating threats posed from trusted insiders, and foster a deeper understanding of indicators and reporting requirements related to insider threat.
What is an Insider? An insider is anyone that has, or has had access to an organization’s resources, facilities and information, network or systems.
What is an Insider Threat? The threat that an insider will use their authorized access, wittingly or unwittingly, to do harm to their organization or the security of the United States.
Understanding Insider Threat
Most insider threats do not start out as a threat; rather, they evolve into a threat over time. The pathway to an insider incident is often complex. Minor frustrations and stressors, both personal and professional, can add up and increase the possibility that an individual may become careless, negligent, or malicious.
Insider threats occur for a wide variety of reasons and can be deliberate or unintentional. Insiders do not need to hold a high rank or position to inflict grave damage. Technology can empower individuals at all levels.
Regardless of intent, an insider threat can cause grave and irrevocable damage, including: resource degradation, harm to national security, reduced military strength; loss of organizational reputation, innovation, and industry advantage; financial instability; and even potential injury to persons or loss of life.
Every organization should have an Insider Threat Program designed to deter, detect, and mitigate actions by insiders who may pose a threat. The organization’s Insider Threat Program Senior Official (ITPSO) implements insider threat program activities. The Facility Security Officer (FSO) is in charge of managing security in the organization’s facilities.
Recognizing Reportable Insider Threat Indicators
Your responsibility is simple: report concerning behavior to the appropriate individuals within your organization. Common categories of concerning behaviors include:
- Professional Lifecycle and Performance Indicators
- Security/Compliance Incidents
- Technical Activities and Technology Related Indicators
- Questionable Allegiance to the United States
- Foreign Considerations, Influence, and Preference
- Financial Considerations
- Criminal, Violent, and Abusive Conduct
- Substance and Alcohol Abuse or Misuse
- Judgment, Character, and Psychological Conditions
- Violent Behavior and Violent Extremist Mobilization Indicators
- Suspicious Contact and Unauthorized Disclosure
Whistleblower Protection
It is important to note that making a protected disclosure does not indicate an insider threat. Whistleblowing is the reporting of waste, fraud, abuse, corruption, or dangers to public health and safety to someone who is in the position to rectify the wrongdoing. Employees are protected from employer retaliation via the Whistleblower Protection Act and Security Executive Agent Directive (SEAD) 9.
The DoD National Hot Line is always available to all individuals to report fraud, waste, abuse, corruption, or dangers to public health and safety.
Email: dodighotline@dodig.mil | Phone: 1-800-424-9098 | Website: https://www.dodig.mil/Hotline
Why Reporting is Critical
An organization’s workforce is the first line of defense against insider threats. Any concerning behavior must be reported to your organization’s FSO and ITPSO immediately upon discovery.
NEVER assume someone else has or will report a concern! Failure to report can result in fines, prison, or both.
Resources and Additional Learning
- CDSE Insider Threat Awareness
- DITMAC – DOD Insider Threat Management and Analysis Center
- Insider Threat Toolkit
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions, ask your FSO!
Every federal contractor facility has access to U.S. government information, in some form or fashion. As such, every person that works for or with a federal contractor facility has a direct impact on the security of our country and the safety of our people and technology.
We must all be aware of the ways that our adversaries will attempt to exploit us to obtain information. We must know what suspicious contact looks like and how to report it.
What is Suspicious Contact?
Suspicious contact is any effort by any individual, regardless of nationality, to obtain illegal or unauthorized access to information or to compromise an individual, as well as all contacts with known or suspected intelligence officers from any country, or any contact which suggests the individual concerned may be the target of an attempted exploitation.
Suspicious Contact Tactics
Not all suspicious contact is obvious. Elicitation is the strategic use of conversation to extract information from people, without giving them the sense that they are being interrogated, to facilitate future targeting attempts.
Information collectors for foreign intelligence entities (FIE) commonly use elicitation to collect sensitive and/or classified information through what appears to be normal social or professional contact.
According to the DCSA and DNI reports, the top collection methods and contacts are:
Top Methods of Operation:
- Resume Submission *Number 1 method*
- RFI/Solicitation
- Exploitation of Business Activities
- Exploitation of Supply Chain
- Exploitation of Experts
- Exploitation of Cyber Operations
Top Methods of Contact:
- Resumes – Academic & Professional
- Web Form Submissions
- Social Networking Services
- Foreign Visits
Recognizing Suspicious Contact
Likely indicators of elicitation and suspicious contact include:
- Business contact requesting information outside the contract scope
- Hidden/obscured end use/end user data
- Offer of paid attendance at an overseas conference
- A casual acquaintance appears to know more about your work than expected
- A casual contact shows an unusual interest in your work, facility, personnel, or family details
Things you can do to reduce the risk of exploitation:
- Know what information you cannot share and be suspicious of those who seek such information
- Do not share anything the elicitor is not authorized to know, including personal information about yourself, your family, or your coworkers
- Be aware that outreach may occur via social media
- Plan tactful ways to deflect probing or intrusive questions
- Never feel compelled to answer any question that makes you feel uncomfortable
At the heart of it all: No matter where you are, no matter who you are communicating with…Care what you share and report suspicious interactions!
Why Reporting is Critical
It is NOT your job to determine if suspicious communications present a legitimate concern or threat. It IS your responsibility to simply report any suspicious interactions to your FSO. A good rule of thumb: If you have to say “No,” let your Facility Security Officer know.
You must report the following to your FSO immediately:
- Any suspicious emails, phone calls, or social interactions
- Any resumes received from foreign nationals applying to positions requiring U.S. citizenship or security clearance
- Any suspected elicitation attempts at conferences, conventions, seminars, or tradeshows
- If any person asks you questions that seem strange, probing, or obviously inappropriate
Resources and Additional Learning
- DNI 2025 Threat Assessment Report
- Identifying Suspicious Contact
- Suspicious Emails
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions, ask your FSO! FSO PROS® is here to help you navigate things to ensure you fulfill all requirements.
We may think it only happens in movies, but espionage is a very real threat. Spies are out there, they are targeting our nation’s most valuable information and technology, and they are more active than ever before.
The truth is that U.S. information and technologies are targeted every day. Advancements in technology have only made the modern day spy’s job easier. Every one of us plays a role in protecting our country and we must be vigilant.
What is Counterintelligence?
Counterintelligence is information gathered, and activities conducted to identify, deceive, exploit, disrupt, or protect against espionage, other intelligence activities, sabotage, or assassinations conducted for or on behalf of foreign powers, organizations, or persons, or their agents, or international terrorist organizations or activities.
The goal of counterintelligence is to:
- Protect U.S. sensitive, controlled unclassified, and classified information and technology
- Protect our nation’s critical assets: our people, advanced technologies, and protected information
- Counter the activities of foreign spies
- Keep weapons of mass destruction from falling into the wrong hands
Are You a Potential Target?
In short, anyone that has, or could have, access to targeted information, knowledge of information systems, or security procedures, is a potential target to foreign intelligence services. This includes:
- Developers that research and develop leading technologies
- Information Systems Personnel with access to cleared facility networks
- Business Development Personnel supporting marketing and sales
- Human Resources and Recruiting Personnel
- Senior Managers and company owners
- Subject Matter Experts involved with targeted technology
- Administrative Staff with access to leadership calendars and proprietary information
- Anyone that has access to national defense information
MCMO (Methods of Contact and Methods of Operation)
Common collection methods include:
Requests for Information (RFI) and Solicitations: Attempts to collect protected information by asking, petitioning, requesting, or eliciting protected information, technology, or persons.
Exploitation of Business Activities: Attempts to establish or leverage relationships to obtain access to protected information. Most commonly through joint ventures, partnerships, mergers and acquisitions.
Exploitation of Cyber Operations: Attempts to compromise or risk confidentiality, integrity, or availability of targeted networks, applications, credentials, or data.
Exploitation of Experts: Requests for peer or scientific review, invites to participate in foreign conferences, requests to collaborate with foreign academic institutions.
Exploitation of Insider Access: Attempts by trusted insiders to exploit their authorized placement or access.
Resume Submission: Applications by foreign individuals seeking academic or professional placement that could facilitate access to protected information.
Surveillance: Observation of equipment, facilities, sites, or personnel associated with classified contracts.
Clearance Advertising is Prohibited
Organizations that have been granted facility clearance under the National Industrial Security Program (NISP) are bound by 32 CFR Part 117 (NISPOM), which states that a cleared contractor may not use its favorable entity eligibility determination for advertising or promotional purposes.
“Advertising” that a company has a facility clearance is strictly prohibited. You may never state that your organization is a cleared facility, nor include any facility clearance information in any public facing space.
Countermeasures
A strong countermeasures plan utilizes defensive, offensive, and investigative measures to both detect and deter threats. Countermeasures may include:
- Security Education and Counterintelligence Briefings
- Physical Security measures
- Cybersecurity measures
- Personnel Security measures and training
- Insider Threat Programs
- Supply Chain Security
- Technology Control Plans (TCPs)
- OPSEC Plans
Resources and Additional Learning
- DCSA CI MCMO Countermeasures Matrix
- Counterintelligence Awareness and Reporting Course for DOD
- Counterintelligence Tool Kit
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions, ask your FSO! FSO PROS is here to help you navigate things to ensure you fulfill all requirements.
The United States is the dominant political, economic, and military force in the world. We have power, information, and technology that other countries want, and they will not hesitate to harm or exploit U.S. persons to obtain it.
Every U.S. person is a potential target for exploitation. Our work in the government space means that we are of particular interest to foreign actors. For this reason, we must take extra precautions when interacting with any foreign person(s), foreign entity, foreign business, or foreign organization.
Foreign Travel
U.S. Citizens are often targeted while traveling outside the U.S. Even in “safe” countries, there are risks and precautions we must take to ensure safety and awareness when traveling.
Federal contractor facilities and their personnel are subject to foreign travel briefing and reporting requirements as outlined in 32 CFR Part 117, SEAD 3, and certain program specific reporting guidelines. FSOs are required to provide travel safety briefings, country specific briefings, and post-travel debriefing.
For this reason, we recommend that all contractor personnel (employees and consultants) report any travel outside of the United States, both personal and professional, to their company’s FSO at least 30 days prior to departure (whenever possible).
Pre-Travel: Ideally any travel outside the US should be reported to your FSO at least 30 days prior to your departure. When 30 days’ notice is not possible, the travel should be reported immediately upon booking. For those that live in border areas, unexpected day trips to Mexico and Canada must be reported within 5 days of return.
Post-Travel: Foreign travel debriefing is required. Covered individuals should contact their company’s FSO immediately upon return to complete post travel debriefing requirements.
Foreign Considerations (Contact, Influence, Interests, Activities, Conflicts of Interest)
Covered individuals are required to self-report any contact with foreign nationals, potential foreign influence, foreign activities or interests, suspicious contact, and any other information pertinent to connections with a foreign country or foreign persons.
Conditions that must be reported include, but may not be limited to:
- Any contact (through any method including social media) with a foreign family member, business or professional associate, friend, acquaintance, or any other person who is a citizen or resident of a foreign country
- Any business, financial, or property interests in a foreign country, or in any foreign-owned or foreign-operated business
- Any unauthorized association with a suspected or known agent, associate, or employee of a foreign intelligence entity
- Any connection to any foreign person, group, government, or country that could potentially create a perceived conflict of interest
Foreign Preference
When an individual gives preference to a foreign country over the U.S., they are far more vulnerable to exploitation. Conditions that could raise concern, and must be reported, include but are not limited to:
- Applying for and/or acquiring citizenship in any other country
- Failure to use a U.S. passport when entering or exiting the U.S.
- Assuming employment, position, or political office in a foreign government or military organization
- Any act of expatriation from the U.S.
Suspicious Contact
Suspicious contact is any effort by any individual, regardless of nationality, to obtain illegal or unauthorized access to information or to compromise an individual.
Examples of suspicious contact that must be reported include:
- Any individual’s efforts, regardless of nationality, to obtain illegal or unauthorized access to sensitive or classified information
- All contact with known or suspected foreign intelligence operatives
- Any contact requesting a person to participate in a foreign conference, seminar, tradeshow, etc.
- Any contact seeking information about your work, job duties, coworkers, etc.
Outside Activities
Involvement in certain types of outside employment or activities could be a security concern if it poses a conflict of interest or if it could increase the risk of unauthorized disclosure of classified or sensitive information.
Some conditions that could raise concern, and must be reported, include:
- Any employment or service with the government of a foreign country or any foreign nation, organization, or other entity
- Any foreign, domestic, or international organization engaged in analysis, discussion, or publication of material on intelligence, defense, foreign affairs, or protected technology
Why Reporting is Critical
Full transparency and self-reporting about any foreign considerations is vital. Failure to report will always be viewed by Adjudicators as “what is this person trying to hide and why?” If investigators find information on their own before you self-report, the consequences are significantly greater.
All covered individuals must report any foreign travel, foreign considerations, suspicious contact, and outside activities to their company’s FSO.
Resources and Additional Learning
- CDSE Foreign Travel Defensive Briefing
- DCSA Self-Reporting
- SEAD 3 – Reporting
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions, ask your FSO!
May is Mental Health Awareness Month! Mental health is a critical part of a person’s overall wellness. According to the CDC, mental illnesses are among the most common health conditions in the United States. Approximately 50% of the population will experience a mental health condition in their lifetime and 1 in 5 Americans are affected by mental illness each year.
During this month of awareness, we would like to spotlight this topic as it pertains to government contractor workforce members and, hopefully, alleviate common concerns about seeking care for your mental wellbeing as a federal contractor.
Destigmatizing Mental Health Care
Mental health care is a positive course of action that often mitigates security concerns. Avoiding care can increase risk and create deeper concern.
In recent years, significant strides have been made within the federal government to destigmatize seeking support. DCSA is working diligently to raise awareness that seeking mental health care and services, on its own, does not affect one’s ability to obtain or hold clearance eligibility and will not impact your national security eligibility.
The Benefits of Mental Health Care and Stress Management Strategies
Some techniques that many find beneficial include:
- Meditation and Mindfulness techniques
- Physical exercise
- Deep breathing exercises
- Yoga
- Journaling
- Positive self-talk
- Healthy eating and prioritizing sleep
- Engaging in creative activities like painting, music, writing, etc.
- Setting healthy boundaries both personally and professionally
- Seeking professional assistance
Many companies offer Employee Assistance Programs (EAP) or other similar programs to assist their personnel when trouble arises. Don’t be afraid to tap into these resources if you need them.
When Are Mental Health Concerns Reportable
Security Executive Agent Directive 3 (SEAD 3) states you must report any apparent or suspected mental health issues where there is reason to believe it may impact a cleared individual’s ability to protect classified or other information specifically prohibited by law from disclosure.
Examples of reportable conditions include:
- Declarations of mental incompetence by a court or administrative agency
- Court-ordered mental health care or evaluation (inpatient or outpatient)
- Hospitalizations for mental health conditions (voluntary or involuntary)
- Diagnoses of psychotic disorders, bipolar mood disorders, or certain personality disorders
- Developing a mental health condition that substantially affects judgment, reliability, or trustworthiness
Will Reporting a Mental Health Concern Affect an Individual’s Clearance?
History dictates that, in most cases, the answer is No. DCSA Adjudications looked at 5.4 million adjudicative actions taken from 2012 to 2020 and found that of 97,000 cases that dealt with psychological-related issues, only 62 were denied or revoked for psychological concerns. This equates to only 0.00115% of total adjudicative actions.
Mitigating circumstances that may ease security concerns include:
- The person’s condition is controllable with treatment and the person has demonstrated ongoing compliance with a treatment plan
- The person voluntarily enters a counseling or treatment program
- The issue was temporary and has since been resolved
- There is no indication of a current problem
Why Reporting is Critical
Looking back on some of the most devastating security incidents in our Nation’s history, mental health and psychological considerations were prevalent pre-incident indicators. In almost all cases there were indicators but, unfortunately, other people around the individual were simply afraid to report for fear the person would lose their clearance.
REPORTING CAN SAVE LIVES.
If you have any concerns about the mental health of yourself or anyone else, please seek guidance from your company’s Facility Security Officer (FSO). Report all concerns to your company’s FSO.
Resources and Additional Learning
- The Facts About Mental Health and Security Clearances
- DCSA: Mental Health Treatment Not an Automatic Disqualifier
- SAMHSA National Helpline
- SAMHSA 988 Suicide & Crisis Lifeline
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions, ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements.
Tax season is a great time to discuss financial considerations, and life changes that federal contractors and federal contractor personnel must report.
Every individual that works in and around the U.S. Government is a potential target for exploitation by malicious actors intending to do harm to the United States and its people. Certain situations make us more susceptible to compromise and we must be aware of those that must be reported to our company’s Facility Security Officer (FSO).
Financial Difficulties and Distress
One of the easiest pathways for our adversaries to elicit information is through offers of gifts and money or threats of exposing our difficulties.
Financial distress can happen to anyone and may be caused by a variety of circumstances. Regardless of the reason, when a person is overextended or having difficulty satisfying debts, there is a greater risk that they might engage in illegal or questionable activity to generate additional funds. Financial pressure makes us a prime target for exploitation.
Unexplained Affluence
Unexplained affluence refers to a lifestyle, standard of living, or accumulation of wealth that cannot be reasonably attributed to a person’s known income or legal sources. It can be a red flag, suggesting that a person may have access to illegal or undisclosed sources of income, and raises concerns about the person’s trustworthiness or vulnerability to bribery or coercion.
Financial Awareness and Reporting Financial Considerations
Keeping a close eye on your financial data and credit information can help you identify if you are running into financial difficulty and if there is any questionable activity happening in your name. All 3 credit bureaus will allow you to run your own credit report for free each year. We recommend you run all 3 annually.
If you suspect your Social Security number is being used fraudulently, contact the Social Security Administration at www.ssa.gov or call toll-free at 1-800-772-1213.
Reporting Financial Considerations — The following circumstances must be reported to your company’s FSO:
- Excessive indebtedness or inability to satisfy debts
- History of not meeting financial obligations
- Unpaid obligations over 120 days, liens, judgements, collections
- Bankruptcies, foreclosures, or wage garnishments
- Deceptive or illegal financial practices (embezzlement, fraud, etc.)
- Failure to file, pay, or fraudulently filing Federal, state, or local income tax returns
- Any indicator of unexplained affluence inconsistent with known income sources
- Borrowing money or engaging in significant financial transactions to fund gambling
- Receipt of a large sum of money, property, or wealth not readily identifiable by typical income (e.g., inheritance, lottery winnings, proceeds from sale of a home)
- Concern that your identity or credentials have been compromised
Changes in Personal Status / Life Changes
If you have been granted security clearance or suitability for access to sensitive information, the following life events and changes must be reported to your company’s FSO:
- A name change, for any reason
- Marriage, separation, or divorce
- Changes in cohabitation status
- Cohabitation with any Non-U.S. citizen
- New relatives and additions to your family (new children by birth or adoption)
- Adoption of Non-U.S. citizen children
- Any change in U.S. citizenship status
- Change in employment status
- Change in need for access to classified information
Why Reporting is Critical
Despite the cause, both financial difficulties and unexplained affluence can raise concerns about an individual’s reliability, trustworthiness, and ability to protect classified or sensitive information.
Financial considerations must be reported immediately upon occurrence. Changes in personal status must be reported to your company’s FSO as soon as you become aware that the change will occur.
Resources and Additional Learning
- CDSE Financial Considerations
- DCSA Reporting Changes, Concerns, or Threats
- Experian Credit Bureau
- Equifax Credit Bureau
- Transunion Credit Bureau
- 32 CFR Part 117 (NISPOM Rule)
As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!