FSO PROS Archives: Security Snippet

Monthly Newsletter

Controlled Unclassified Information (CUI)

Bits of information can act like puzzle pieces that an adversary may collect, aggregate, analyze, and exploit to do harm to or gain an advantage over the U.S. Sensitive information can be especially vulnerable to compromise due to its potential for aggregation. As such, it is crucial to have robust safeguards in place to protect this type of information.

What is CUI?

Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended.

The CUI program, established by Executive Order 13556 and implemented by 32 CFR part 2002, defines the need for protection of this type of information and establishes requirements for protecting it.

Identifying CUI

Unclassified information associated with a law, regulation, or government-wide policy and identified as needing safeguarding is considered CUI. It requires access control, handling, marking, dissemination controls, and other protective measures for safeguarding.

CUI is clustered into organizational indexes (e.g., defense, privacy, proprietary) with associated categories, and is categorized by the DoD according to the specific law, regulation, or government-wide policy requiring control.

The authorized holder of a document or material is responsible for determining, at the time of creation, whether information falls into a CUI category and for applying CUI markings and dissemination instructions accordingly.

The National Archives and Records Administration (NARA) maintains the CUI Registry, which lists the authorities that require or permit safeguarding or dissemination controls for specific types of information.

CUI Responsibilities and Training Requirements

Every individual at every level, including DoD civilian, military personnel, and contractors providing support to the DoD, are required to comply with the requirements in DoDI 5200.48.

The Department of Defense (DoD) has implemented a mandatory CUI training program to educate personnel on the proper handling, protection, and dissemination of CUI. All individuals, both cleared and uncleared, that perform U.S. Government related work could be exposed to CUI information and should complete CUI training.

Reporting Requirements

  • If you receive CUI and have not yet completed CUI training, contact your Facility Security Officer (FSO) immediately.
  • When you receive CUI information, documents, or materials, notify your company’s FSO for awareness.
  • If you find CUI that is not properly controlled or stored, you must report this to your company’s FSO.

Resources and Additional Learning

As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!

Reporting Requirements for U.S. Government Contractor Facilities and Personnel

Organizations that perform work on U.S. Government classified contracts are required to report certain incidents, events, information, and behaviors. Reporting is required under a variety of U.S. Government policies. Today we will focus on the most common types of reporting required under 32 CFR Part 117, Security Executive Agent Directive 3 (SEAD 3), and many U.S. Government contractual stipulations.

Do You Have an Obligation to Report?

All cleared facilities and all covered individuals are required to follow the reporting requirements outlined in 32 CFR Part 117, SEAD 3 and ISL2021-02, and all other U.S. Government policies and contractual requirements.

A Covered Individual is any person that:

  • Has been granted eligibility for access to classified information; and/or
  • Occupies a “Sensitive Position”; and/or
  • Is in the process of eligibility determination for access to classified or sensitive information; and/or
  • Occupies a position wherein contractual guidance for reporting requirements has been applied by any U.S. government agency or customer

If you perform work for a cleared facility, you have reporting requirements. If you have any question as to whether reporting requirements pertain to you, contact your organization’s FSO immediately.

What Are You Required to Report?

Security Incidents/Violations/Vulnerabilities: Any known or suspected security incident, violation, infraction, or vulnerability. NOTE: Security violations must be reported within 24 hours of discovery!

Espionage, Sabotage, Terrorism, or Subversive Activities: Any situation related to actual, probable, or possible espionage, sabotage, terrorism, or subversive activities directed at the United States.

Adverse Information: Any information (about yourself or any other covered individual) that could adversely reflect on the integrity, trustworthiness, reliability, or character of an individual, or suggests their ability to safeguard classified or sensitive information may be impaired.

Insider Threat Concerns and Indicators: Any information or behavior that suggests an individual may be, or may become, an insider threat, including indicators of recruitment by a foreign intelligence service, suspicious behavior, or questionable national loyalty.

Suspicious Contact: Any contact by any individual, regardless of nationality, that is of a suspicious nature, including efforts to obtain illegal or unauthorized access to classified information.

Foreign Travel: Travel to any foreign country (including Canada and Mexico). NOTE: Cleared individuals must report ALL foreign travel, both personal and professional.

Foreign Contact and Influence: Close and continuing contact with a foreign national in any capacity, contact with anyone associated with a foreign government or foreign-owned organization, or financial obligations to any foreign national or entity.

Personal Finance & Business Interests: Ownership of foreign state-backed, hosted, or managed cryptocurrency and ownership of cryptocurrency wallets hosted by foreign exchanges.

Change in Personal Status: Name changes, changes in marital or cohabitation status, changes in citizenship, changes in employment status or need for access to classified information.

Cyber Intrusions and Cyber Incidents: Any actual, possible, or potential penetration of information systems, suspicious network activity, unauthorized use of DOD account credentials, or spillage.

DoD Hotline

Your organization’s FSO should always be your first point of contact for all matters. That said, certain types of reports may be made to the Department of Defense Hotline if going to your FSO is not an option.

Examples of matters to report to the DoD Hotline include: fraud, waste, abuse, whistleblower reprisal, bribery, contract and procurement fraud, health care fraud, and COVID-19/CARES Act Fraud.

DoD National Hot Line: Email: dodighotline@dodig.mil | Phone: 1-800-424-9098 | Website: https://www.dodig.mil/Hotline

Resources and Additional Learning

As always, if you have any questions about whether or not a situation requires reporting, ask your FSO!

Security Policies and Procedures for Contractor Facilities

All cleared contractor facilities are required to have written procedures in place that dictate how their facility will implement and maintain a system of security controls within the organization in alignment with the requirements of 32 CFR Part 117 (NISPOM rule) and other U.S. Government laws and policies.

Two written policies that every cleared facility should have are:

  1. A Security Standard Practice Procedures (SPP)
  2. An Insider Threat Program Plan (ITP)

The Security Standard Practice Procedures (SPP)

The Security Standard Practice Procedures (SPP) is a written document that implements requirements for the contractor’s operations and involvement with classified information. Key aspects of a SPP include:

  • Opening Statement: Outlines the purpose of the document and includes a statement of support for the National Industrial Security Program (NISP).
  • Facility Information: States the company’s facility clearance level, classified storage requirements, and outlines security roles within the organization.
  • Personnel Security Clearances: Outlines how personnel clearances for employees and consultants are handled.
  • Reporting Requirements: Outlines reporting requirements for both personnel and the facility, and establishes the necessary processes and procedures all company personnel are required to follow.
  • Security Education: Outlines the training requirements for the organization per U.S. Government and contractual requirements.
  • Self-Inspections: Outlines how the organization will meet self-inspection requirements and the intervals at which the company will perform these inspections.
  • Classified Visits and Meetings: Outlines how classified visits and meetings will be handled.
  • Safeguarding Classified Information: Establishes the organization’s procedures for protecting classified information.

The Insider Threat Program Plan (ITP)

The Insider Threat Program Plan (ITP) is a comprehensive strategy designed to deter, detect, and mitigate potential threats posed by individuals within an organization who have authorized access to sensitive information or systems. Key aspects include:

  • Risk assessment: Identifying critical assets and evaluating the likelihood of an insider threat occurring.
  • Employee screening: Conducting thorough background checks and reference verifications during the hiring process.
  • Access controls: Implementing strong user access management practices, including the least privilege principle.
  • User activity monitoring: Continuously monitoring employee actions on company systems to detect suspicious behavior.
  • Security awareness training: Regularly educating employees about insider threat risks and reporting procedures.
  • Incident response plan: Defining clear steps for investigating and responding to potential insider threats.

Insider Threat Program Plans must also consider balancing privacy concerns, establishing clear reporting mechanisms without fear of retaliation, and promoting a culture of security awareness.

How and Why Is This Relevant to You?

All cleared contractor personnel, both employees and consultants, are required to follow all policies and procedures set forth in company and U.S. Government policies. Your organization is required to make security policy documents available to you and all personnel. If you do not know where to find them, please contact your company’s security team immediately.

If you have any questions or concerns about the security policies within your organization, your FSO and Insider Threat Program Senior Official can certainly assist. You should never hesitate to reach out to your FSO and ITPSO for guidance.

Resources and Additional Learning

As always, if you have any questions about security or reporting requirements, ask your FSO! FSO PROS® is here to help you navigate things to ensure you fulfill all requirements.

Learn how FSO PROS® can help
support your security program

Let’s discuss how we can help support your security and compliance needs.
Secret Link