ISP Security Policies & Legal Compliance 3 — Questions and Answers
Question 1: An employee discovers a coworker has taken classified documents home without authorization. Under NISPOM, what is the employee's FIRST obligation?
- Confront the coworker directly and demand return of the documents
- Report the incident to the Facility Security Officer (FSO) immediately (Correct answer)
- Wait to see if the coworker returns the documents before reporting
- File a report directly with DCSA, bypassing the FSO
Correct answer: Report the incident to the Facility Security Officer (FSO) immediately
Employees have a mandatory duty to report security violations to the FSO, who then determines appropriate escalation steps.
Question 2: What does the term 'need-to-know' mean in the context of classified information access?
- The individual holds a clearance at least one level above the classification
- Access is required to perform an officially assigned duty or task (Correct answer)
- The individual's supervisor has verbally approved access on request
- The individual has completed required security training for that classification level
Correct answer: Access is required to perform an officially assigned duty or task
Need-to-know means a person must require access to specific classified information to perform their official duties, even if they hold the appropriate clearance level.
Question 3: Which law makes it a federal crime to knowingly and willfully misuse or disclose classified information without authorization?
- The Computer Fraud and Abuse Act (CFAA)
- 18 U.S.C. § 1030
- The Espionage Act (18 U.S.C. §§ 793-798) (Correct answer)
- The Trade Secrets Act (18 U.S.C. § 1905)
Correct answer: The Espionage Act (18 U.S.C. §§ 793-798)
The Espionage Act (18 U.S.C. §§ 793-798) is the primary federal statute criminalizing unauthorized disclosure of national defense information.
Question 4: Under the NISPOM, how frequently must a Facility Security Officer (FSO) conduct self-inspections?
- Monthly
- Quarterly
- Annually (Correct answer)
- Every two years
Correct answer: Annually
NISPOM requires cleared contractors to conduct annual self-inspections to evaluate the effectiveness of their security programs.
Question 5: A classified contract is completed and the contractor retains classified materials. What should the FSO do?
- Retain the materials indefinitely in case the contract is reopened
- Destroy the materials immediately without notification
- Return, transfer, or destroy the materials per the government contracting officer's instructions (Correct answer)
- Archive the materials in a commercial off-site storage facility
Correct answer: Return, transfer, or destroy the materials per the government contracting officer's instructions
Upon contract completion, classified materials must be dispositioned (returned, transferred, or destroyed) in accordance with government direction, not retained by the contractor.
Question 6: What is the key distinction between a 'security violation' and a 'security deviation' under NISPOM?
- A violation involves classified information; a deviation involves only unclassified information
- A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information (Correct answer)
- A deviation is more serious and requires DCSA reporting; a violation can be handled internally
- There is no distinction — the terms are interchangeable
Correct answer: A violation is a confirmed unauthorized disclosure; a deviation is a procedural failure that did not necessarily compromise information
A security deviation is a procedural failure (e.g., open vault door), while a security violation involves an actual or suspected unauthorized disclosure of classified information.
Question 7: Which of the following best describes 'two-person integrity' (TPI) as applied in industrial security?
- Requiring two FSOs to sign off on all security policies
- Ensuring no single person has unsupervised access to certain sensitive materials or areas (Correct answer)
- Mandating that all classified documents be reviewed by two government officials before release
- Requiring dual-factor authentication for all classified computer systems
Correct answer: Ensuring no single person has unsupervised access to certain sensitive materials or areas
Two-person integrity requires at least two authorized, cleared individuals to be present when handling certain sensitive materials to prevent insider threats.
An employee discovers a coworker has taken classified documents home without authorization.
Under NISPOM, what is the employee's FIRST obligation?