1/21
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
EO 12829
Established the NISP to create a uniform system for safeguarding government classified information released to industry
National Industrial Security Program (NISP)
A government wide framework and partnership between federal agencies and industry designed to protect unauthorized disclosure of classified information
National Industrial Security Program Operating Manual (NISPOM)
The rule book that provides detailed security requirements, operating instructions, and standards that industry must follow when handling government classified information
32 CFR Part 117
The codified federal regulation prescribing the uniform security requirements and operating instructions found in the NISPOM that industry is legally bound to follow to protect classified information
32 CFR 2004
The federal regulation issued by ISOO that dictates how government agencies must uniformly implement, administer, and oversee the NISP; outlining the responsibilities of the CSAs, CSOs, and GCAs
Information Security Oversight Office (ISOO)
An administrative office within NARA responsible for government-wide policy development, implementation, and oversight of the NISP. This is the authority that reports to the NSC and wrote 32 CFR 2004
National Industrial Security Program Policy Advisory Committee (NISPPAC)
A 24-member federal advisory committee chaired by the director of the ISOO where 16 government and 8 industry leaders recommend policy updates and to keep things fair between government and industry.
DoDI 5220.31-National Industrial Security Program
The internal DoD instruction that PLACES the USD(I&S) as the lead for managing the DoD NISP and establishes DCSA as the CSO for DoD
DoDM 5220.32 Volume 1-Industrial Security Procedures for Government Activities
The step-by-step manual for DoD components and agencies executing the NISP, providing procedures for managing FCLs, PCLs, security education, and classified contracts
DoDM 5220.32 Volume 2-NISP Procedures for Government Activities Related to FOCI
The government manual used to govern how the DoD identifies, analyzes, and mitigates risks associated with Foreign Ownership, Control, or Influence (FOCI) at cleared contractor facilities
DoDI 5000.02-Operation of the Adaptive Acquisition Framework
The primary DoD instruction that defines the overarching framework and establishes the 6 customizable acquisition pathways. It governs how the DoD purchases, tests, and develops goods and services from industry
DoDI 5000.85-Major Capability Acquisition
The DoD instruction that executed the AAF pathway for large, complex, defense hardware and software programs (aircraft, naval vessels, major defense weapons)
Federal Acquisition Regulation (FAR)
The master procurement rulebook governing how all federal agencies buy goods and services from industry fairly and legally. It is the baseline purchasing rules for the entire federal gov’t
FAR Subpart 4.4-Safeguarding Classified Information Within Industry
The section of the Far that directs contract officers on when and how to insert security rules into classified contracts, such as security clauses, mandating FCLs, and issuing classification guidance.
Defense Federal Acquisition Regulation Supplement (DFARS)
The DoD specific supplement to the FAR that adds stricter security and cybersecurity requirements for military contracts
FAR Clause 52.204-2 Security Requirements Clause
The mandatory contract clause inserted into all classified contracts that legally forces a company to follow the NISPOM, execute a DD Form 441, and follow a DD Form 254
DD Form 441-DoD Security Agreement
A one time legally binding contract executed at the company corporate level and the government, allowing the company to establish a NISP compliant security program and receive an FCL while the government agrees to process the PCLs for the company
DD Form 254- DoD Contract Security Classification Specification
A document issued for a specific classified contract that maps out the exact classification levels, handling restrictions, access requirements, and all other security requirements needs for the project.
Defense Acquisition System (DAS)
The overarching management process used by the DoD to acquire a good or service from industry that conceptualizes, designs, tests, manufactures, develops, and sustains defense technologies, and military equipment
Cognizant Security Agency (CSA)
An executive branch agency (DoD, DOE, ODNI, DHS, NRC) designated by EO 12829 to set and enforce an industrial security program that is compliant with the NISP and follows the NISPOM
Cognizant Security Office (CSO)
The operational enforcement arm that administers the NISP and conducts facility inspections on behalf of the CSA
Government Contracting Agency (GCA)
The specific military component/office that has the buying power to issue contracts and provide project specific security rules. They are the buyer/customer