  • Are coversheets required for CUI? If not, can I use a coversheet if I would like to? If CUI is derived from different source documents e. While the CUI Program has no requirement to cite derivative source documents, in some instances, it may be...

  • For more information on NISP resources, click here. For assistance with policy interpretations, frequently asked questions or other policy related concerns, please send email to DCSA. Contractors will identify their plans in the remarks section of the IS Tracking Form. It is understood the number of workstations may vary during fulfillment of the contract and the contractor may elect to add workstations to an existing system when there is a RAL or contractual requirement to do so; however, when additional growth in the program occurs e.
  • Since there is no real vendor, how do we determine when it is no longer supported? Are we going to have a list of "legacy" operating systems to share with industry? Each instance will be considered on a case by case basis and no "list" will be maintained by DCSA. Is the contractor required to establish a POAM for their current systems or as a part of their reaccreditation package?
  • Also, will a POAM be required if the systems are contractually required? Are contractors in states that have enacted laws authorizing the medical use of marijuana, or in states that have enacted laws authorizing the use, possession, production, processing and distribution of marijuana, required to report use, possession, production, processing, or distribution of marijuana by cleared contractor personnel? The NISPOM defines a document as "Any recorded information, regardless of the nature of the medium or the method or circumstances of recording.
  • If multiple documents are stored on the electronic media, are NISP contractors required to maintain accountability of each TS digital document stored on a system's hard drive or account for the TS hard drive only? When documents are in electronic form and stored on another medium e. When electronic media e. Any such report of loss must identify each individual document and item when a loss occurs. When multiple items are placed on the same medium, each having their own control number, they must be accounted for separately. Is the contractor required to re-mark classified material received from any source that is improperly marked? The contractor is required to ensure that documents they prepare, and the documents prepared by their subcontractor, to meet the performance requirements of a contract are properly marked. Where can I find information on marking and derivative classification? This course has a separate exam the cleared contractor must pass in order to receive credit for this course.
  • The simple answer is by marking item It is understood that AIS are a primary means for receiving and generating information; therefore, when No other annotations are required on the form. The DD Form is one part of the documents included in a classified contract. Its purpose is to convey security classification guidance and to advise contractors on the handling procedures for classified material.
  • The GCA may use the DD Form to provide guidance regarding unclassified information associated with the classified contract. Block If Block The GCA is responsible for oversight of unclassified information provided to contractors. The fact that the DD Form provides guidance on unclassified information does not change the oversight responsibilities.
  • How is removable media marked and labeled? If each document on a removable device contains all of the required information for that document, only the overall classification and associated caveats markings must be marked on the exterior of the device. What items are considered to be removable media? Removable media is any type of storage device that can be removed from a computer while the system is running. This includes removable media which is inserted into readers and drives integrated into the system e. Note: Examples are not all inclusive. If you are unsure if your equipment falls into this category, contact your local DCSA Representative i. Information System Security Professional for assistance. Are easily removed hard drives e. No, these devices do not fit the definition of removable media since they generally cannot be removed while the system is running. Users should take care not to confuse these devices with external hard drives, which are removable media.
  • Although not considered removable media, these items have similar marking requirement a to bear a conspicuous label stating the highest classification and most restrictive caveats. What types of removable media needs to be marked? All types of removable media, regardless of their impact to the operation of a system. Additionally, unclassified media and systems located in areas approved by the CSA for classified processing must also be marked and labeled so that the overall classification and associated caveats are apparent to the user.
  • What is meant by weekly? Does that mean once a calendar week or every seven days? There are many variables that could impact the completion of audit trail analysis on a routine basis, which is why a weekly requirement is called for in the NISPOM rather than a strict seven days. Are contractors required to submit adverse information reports for an employee with clearance eligibility in JPAS, even if the employee currently does not require access to classified information? Also refer to ISL If all of the drawers or doors of a GSA-approved container lock with a single mechanism and if none can be left unlocked or open when the mechanism is set, a single contact mounted on the control drawer or door on which the mechanism is installed is acceptable. Alternatively, surface protection may consist of linings that comply with the Standard for Linings and Screens applied to a safe or safe cabinet that completely surround the safe. The protection shall be arranged so that an alarm will be initiated if an opening 4 inches mm in diameter or larger is made in the safe or safe door by any method of attack.
  • To ensure compliance with the extent of protection of "complete" the UL Certified Alarm Services Companies recommends to the user the appropriate sensor type to be installed to meet UL certification requirements. What can a company do to facilitate the final eligibility determination for an employee who is currently assigned overseas but has an interim clearance? What happens when the requests for periodic reinvestigations PRs are not submitted within required timeframes? Contractor personnel with access granted at the Top Secret, Secret, and Confidential levels must be reinvestigated at 5-, and year intervals, respectively, from the closing date of the previous investigation. To facilitate compliance with submission timeframes, contractors may submit an employee's e-QIP for a PR up to 30 days in advance of the due date.
  • Contractors are reminded to access JPAS accounts within timeframes that do not exceed 30 days. Is it necessary for the contractor to maintain the hard copy original "signature pages" releases and certification of the SF while the investigation is on-going? Contractors may maintain the entire SF electronically, including signature pages with scanned signatures, as long as it is retrievable if needed and the confidentiality of the document is protected in accordance with NISPOM paragraph JPAS may not be used to verify citizenship; however, the fact that an individual has a current active clearance in JPAS can be the basis for assuming that US citizenship was verified as part of the initial investigative process.
  • Individuals who have had a break in access should be asked if there has been any change in their citizenship status since they last worked in a cleared position. Initial Briefing Certificate: The contractor should retain the initial briefing certificate for an employee who has been given access to NATO classified information until the employee no longer requires access and has been debriefed. Annual Refresher Briefing: The contractor should retain the current annual refresher briefing record on file until the next annual refresher briefing is completed or the employee is debriefed, whichever occurs first.

