ISP Security Policies & Legal Compliance 2 — Questions and Answers
Question 1: Which federal law establishes the baseline requirements for protecting classified national security information in industry?
- Freedom of Information Act (FOIA)
- National Industrial Security Program Operating Manual (NISPOM) (Correct answer)
- Occupational Safety and Health Act (OSHA)
- Sarbanes-Oxley Act (SOX)
Correct answer: National Industrial Security Program Operating Manual (NISPOM)
The NISPOM (32 CFR Part 117) is the primary federal regulation governing the protection of classified information in the defense industrial base.
Question 2: Under NISPOM, what is the term for a company that has been granted authority to access classified information by the U.S. government?
- Authorized Contractor
- Cleared Defense Contractor (CDC) (Correct answer)
- Classified Access Entity (CAE)
- Trusted Industry Partner (TIP)
Correct answer: Cleared Defense Contractor (CDC)
A Cleared Defense Contractor (CDC) is a company that holds a Facility Clearance (FCL) and is authorized to access classified information.
Question 3: Which executive order originally established the current framework for classifying, safeguarding, and declassifying national security information?
- Executive Order 12958
- Executive Order 13526 (Correct answer)
- Executive Order 12829
- Executive Order 13556
Correct answer: Executive Order 13526
Executive Order 13526, signed in 2009, is the current authority governing the classification system for national security information.
Question 4: A security policy states that all classified materials must be stored in GSA-approved containers. What type of policy requirement is this?
- Discretionary control
- Mandatory control (Correct answer)
- Administrative guideline
- Voluntary best practice
Correct answer: Mandatory control
GSA-approved container requirements are mandatory controls derived from federal regulation, not discretionary guidelines.
Question 5: Under the Privacy Act of 1974, what right do U.S. citizens have regarding federal agency records about them?
- The right to have all records about them permanently deleted
- The right to access and request amendments to their records (Correct answer)
- The right to prevent any government agency from collecting personal data
- The right to financial compensation for any data stored about them
Correct answer: The right to access and request amendments to their records
The Privacy Act gives individuals the right to access federal records about themselves and request corrections to inaccurate information.
Question 6: What is the primary purpose of a security awareness training program in an industrial security context?
- To fulfill a contractual billing requirement to the government
- To ensure employees recognize threats and understand their security responsibilities (Correct answer)
- To qualify employees for access to higher classification levels
- To serve as a substitute for background investigations
Correct answer: To ensure employees recognize threats and understand their security responsibilities
Security awareness training ensures all personnel understand threats like insider threats, social engineering, and their duty to protect classified information.
Question 7: Which agency is responsible for adjudicating personnel security clearances for most Department of Defense contractors?
- Federal Bureau of Investigation (FBI)
- Defense Counterintelligence and Security Agency (DCSA) (Correct answer)
- Office of Personnel Management (OPM)
- Department of Homeland Security (DHS)
Correct answer: Defense Counterintelligence and Security Agency (DCSA)
DCSA (formerly DSS) is the primary security oversight agency for the defense industrial base, including adjudicating clearances for DoD contractors.
Which federal law establishes the baseline requirements for protecting classified national security information in industry?