Upload
ngokhuong
View
214
Download
0
Embed Size (px)
Citation preview
DoD Initial Training Guide | 1
Congratulations 2
Introduction 3
ReportingRequirements 4
ProceduresandDuties 5
Safeguarding 6
Reproduction 6
Transmission 6
Retention/Disposition 6
ClassificationOverview 8
Counterintelligence 9
Conclusion 10
ObtainingTrainingCredit 10
Glossary 11
LOCKHEEDMARTINPROPRIETARYINFORMATION
TABLE OF CONTENTS
DoD Initial Training Guide | 2
CONGRATULATIONS
YouhavebeengrantedaDepartmentofDefense(DoD)securityclearanceandconsequentlytheU.S.governmenthasprovidedauthorityforyoutoaccesscertainclassifiedinformation.
Asaclearedindividual,therearebasicsecurityconceptsyouwillneedtolearn.Thistrainingguidewillprovidethefoundationalknowledge,expectationsandrequirementsyouwillneedtounderstandpriortobeginningwork.After30days,youwilltakeanonlinecoursethatwillrecapmuchofthisinformation,alongwithscenario-basedexercisesthatwilltestyourunderstandingofthematerial.YouwillalsogettoknowSecurityProfessionalswhocanassistandguideyouinmaintainingastrong,defensivesecurityposture.
Thankyouforyourattentiontothisimportanttopic,andwelcomeaboard!
BobTronoVicePresident&ChiefSecurityOfficerLockheedMartin
DoD Initial Training Guide | 3
INDIVIDUAL SECURITY RESPONSIBILITIESTheU.S.governmenthasestablisheddetailedrequirementswhichareoutlinedintheNationalIndustrialSecurityProgramOperatingManual,orNISPOM,toensuretheprotectionofclassifiedinformation.PartofyourroleasaclearedLockheedMartinemployeeistoprotectournationfromavarietyofthreats.OurNationalSecurityisconstantlyunderattackbyadversariesbothforeignanddomestic;byprotectingclassifiedinformation,youarefulfillingacriticalroleinprotectingournation.
Thistrainingguidewillprovidesecurityproceduresthatarecriticalforclearedemployeestounderstandandcomplywithgovernmentsecurityregulations.Althougheachclearedfacilityadherestosetgovernmentsecuritystandards,implementationproceduresmayvaryfromsitetosite.
For defense contractors such as Lockheed Martin, the Defense Security Service (DSS) is the primary DoD security agency assigned to oversee the protection of classified information.
INTRODUCTION
PENALTIESPenaltiesforunauthorizeddisclosureofclassifiedinformation,whichcanbeassessedagainstbothclearedemployeesandthecorporation,include:
• Finesofupto$10,000
• Imprisonmentofupto10years
DoD Initial Training Guide | 4
Nowthatyouareaclearedemployee,thereareanumberofreportingrequirementsyoumustadheretoinordertomaintainyoursecurityclearance.Thesereportingrequirementsarecenteredoneventsandactivitiesthatcouldpotentiallyimpactyourabilitytoprotectclassifiedinformation.
ADVERSE INFORMATIONYoumustalsoreportinformationthatreflectsunfavorablyontheintegrityorcharacterofyourselforanotherclearedindividualthatmayimpairtheabilitytosafeguardclassifiedmaterials.Thisinformationisdefinedasadverseinformation.
Someexamplesofadverseinformationinclude:
• Knownorsuspectedviolationofsecurityrulesbyyouoranotherindividual
• Knownorsuspectedcompromiseofclassifiedinformationbyyouoranotherindividual
• Anyarrest,criminalactivity,orcivilcourtactions -Trafficfinesover$300(notincludingcourtfees)• Treatmentforpsychological,mental,emotional,
andpersonalitydisordersandcounseling,exceptfamily/marriage,griefandcombat-relatedcounseling(unlessthecounselingwasprecipitatedbyaviolentactionorevent)
• Substanceabuse• Medicalmarijuana(priortouse)• Useofillegalcontrolledsubstances(whichincludes
marijuanaunderfederallaw)• Unexplainedaffluence• Excessiveindebtednessorrecurringfinancial
difficulties(e.g.,foreclosureorbankruptcy)• Knowledgeofanemployeenotwantingtoperform
onclassifiedwork• Closeorcontinuouscontactwithaforeignperson
orentity• MisuseofanycompanyorU.S.government
informationsystems• Behaviorthatcausesanindividualtobevulnerable
tocoercion,exploitation,orduressand/orreflectslackofdiscretionorjudgement(toincludebehaviorofasexualnature)
CHANGE IN PERSONAL STATUS• Name• Citizenshipincludingacquiringdualcitizenship
and/orforeignpassports• Residence• Maritalstatus• Cohabitationinaspouse-likerelationshipwitha
foreignnational• Jobassignmentnolongerrequiringasecurity
clearance
SUSPICIOUS CONTACT• Anycontactwithanindividualthatissuspiciousin
nature,whethertheyareaU.S.orforeignperson• Someonetakinganunusualinterestinyouand
yourjoband/oraskingprobingquestionsaboutwhatyoudoandwhoyouworkfor
Thesecontactscanoccuronline,throughsocialmedia,email,viaphone,writtencorrespondence,orinperson.
Someexamplesofsuspiciouscontactsinclude:
• Requestforprotectedinformationundertheguiseofapricequoteorpurchaserequest,marketsurvey,orotherpretense
• Attemptstoenticeclearedemployeesintosituationsthatcouldleadtoblackmailorextortion
• Attemptsbyforeigncustomerstogainaccesstohardwareandinformationthatexceedsthelimitationsoftheexportlicenseonfile
• Attemptstoplaceclearedpersonnelunderobligationthroughspecialtreatment,favors,gifts,ormoney
ThesereportsshouldbemadetothelocalSecurityOfficeortotheLMPeoplesysteminternally.Ifindoubtastowhethersomethingisreportable,consultwithyourSecurityOffice.
REPORTING REQUIREMENTS
DoD Initial Training Guide | 5
PROCEDURES AND DUTIES
LEVELS OF CLASSIFIED INFORMATIONTheUnitedStatesgovernmenthasthreelevelsofclassifiedinformation.ThelevelofclassificationisdeterminedbythedegreeofnegativeimpacttoNationalSecurityifimproperlydisclosed.Theclassificationlevelsaredefinedas:
• CONFIDENTIAL -ThisclassificationisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocausedamagetoNationalSecurity.
• SECRET-Thisclassificationisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocauseserious damagetoNationalSecurity.
• TOP SECRET-Thisclassificationisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocauseexceptionally grave damagetoNationalSecurity.
Youmaysometimeshearclassifiedinformationreferredtoas“NationalSecurity”informationor“collateral”information.
RELEASE OF INFORMATIONPriortoreleasinginformation,theholdermustensurethattherecipientoftheinformationhasboth:
• Propersecurityclearance–Clearedindividualsmayaccessclassifiedinformationatorbelowtheirclearancelevel
• Need-to-know–Eachindividualshallonlybegrantedaccesstothespecificclassifiedinformationthatisabsolutelyrequiredtoperformtheirjob.
Ifyouhaveaquestionaboutwhethersomeoneshouldhaveaccesstoclassifiedmaterialsandinformation,ALWAYScontactyourlocalSecurityOffice.
“Collateral” refers to classified materials for which special requirements are not formally established.
Rank, level, or position within the company does not equal a clearance or need-to-know.
DoD Initial Training Guide | 6
HANDLING OF CLASSIFIED INFORMATIONSafeguardingSomegeneralsafeguardingguidelinesinclude:
• Neverleaveclassifiedmaterialunattended
• Secureclassifiedmaterialinagovernment-approvedcontainerorarea
• Properlyprotectcombinationsthatcontrolaccesstoclassifiedmaterialsandareas
• Understandhowyourfacilitysecuresclassifiedmaterialsandareasattheendofeachday
• WhentransmittingclassifiedinformationoutsideofaLockheedMartinfacility,complywithallspecialrequirements
• Takeactionstopreventthelossorunauthorizeddisclosureofclassifiedinformation;bemindfulwhenholdingclassifieddiscussions(suchashallways,cubicles,breakrooms,etc.)
• Beawareoflocalpoliciesorrestrictionsregardingcellphones,cameras,MP3players,tablets,andanyotherpersonalelectronicdeviceenteringclassifiedareas
• Understandthevarioustypesofapprovedareasforclassifiedoperationsincludingbutnotlimitedtoclosedandrestrictedareas
• Recognizethatclassifiedmaterialcomesinvariousforms(suchasdocuments,hardwareorassets,electronicmedia,communicationsortransmissions)
Reproduction• Reproductionofclassifiedmaterial:
-Shouldalwaysbekepttoaminimum
-Shouldbeperformedonlybyauthorized personnelfamiliarwiththeprocedure
-Shouldbeperformedonlyonauthorized equipment
TransmissionAllclassifiedmaterialscominginandoutofafacilitybymail,fax,orcouriermustbesentandreceivedbytheSecurityOffice.
Ifyoureceiveaclassifiedpackagedirectly,notifyyourlocalSecurityOfficeIMMEDIATELY!
Retention / DispositionContractorsareauthorizedtoretainclassifiedmaterialreceivedorgeneratedunderacontractfortwoyearsfollowingcompletionofthecontract,unlessotherguidanceisprovidedbytheGovernmentContractingAuthority(GCA).
Classifiedmaterialshouldonlyberetainedforvalidcontractperformancepurposesanddispositionedwhennolongerneeded.
DestructionofclassifiedinformationmustbeaccomplishedbyauthorizedmethodsandpersonnelONLY.Understandthedestructionmethodsatyourfacility.
In case of emergency, follow all practical security measures for safeguarding classified material as the situation allows.
YOUR PERSONAL SAFETY COMES FIRST!
PROCEDURES AND DUTIES (CONT)
DoD Initial Training Guide | 7
SECURITY INCIDENT REPORTINGTheimpropersafeguarding,handling,reproduction,transmission,disposition,ordisclosureofclassifiedmaterialisareportablesecurityincident.
Ifyoucommitordiscoverapotentialsecurityincident,immediatelyreportthecircumstancestoyourlocalSecurityOfficeand,ifpossible,ensurethematerialinvolvedisproperlysafeguarded.Whenreportinganincident,becognizantnottodiscloseclassifiedinformationoverunsecuremeans.
Securitypersonnelwillevaluatethecircumstancesandtakeactionsasappropriate.
Byadheringtosecurityprocedures,youensurethatclassifiedinformationisproperlyprotectedandcontributetothenation’ssecurity.
Byproperlyprotectinginformation,wemeetourcontractualobligations,enhancecustomertrust,helpensureLockheedMartin’scontinuedabilitytocompetefornewbusinessopportunities,andmaintainourreputationasanindustryleader.
UNAUTHORIZED RELEASE OF CLASSIFIED INFORMATIONTherearenegativeimpactsassociatedwiththeunauthorizedreleaseofclassifiedinformation.Theseimpactsincludebutarenotlimitedto:
• DamagetoNationalSecurity
• Weakenedintegrityofclassifiedinformationandtechnicaladvantage
• Damagetocompanyreputationandcustomerrelationships
• Potentialnegativeimpactonawardfees
• Lossofclassifiedcontractsand/orexclusionfrombidding
• Lossofpersonalsecurityclearanceand/oremployment
DATA SPILLSDataSpills,alsoknownasdatacontaminations,areaformofunauthorizedreleaseofclassifiedinformation.Dataspillsoccurwhenclassifiedinformationiseitherintentionallyorunintentionallyintroducedtoanunclassifiedorunaccreditedinformationsystem.Improperhandlingofdataisatthecoreofmostdataspills.
Thebestwaytopreventadataspillistofocusonwhatyoucancontrol:
• Knowwheretofindandhowtousesecurityclassificationguidesforyourprogramorproject
• Properlyhandleandappropriatelymarkclassifiedinformation
• Ifyoureceiveordiscoverclassifiedorpotentiallyclassifiedinformationonanunclassifiedinformationsystem,immediatelycontactyourlocalSecurityOfficeforguidance.Donotforward,print,save,ordeletethesuspectedinformation.
PROCEDURES AND DUTIES (CONT)
DoD Initial Training Guide | 8
InformationbecomesclassifiedbyadesignatedOriginal Classification Authorityafterithasbeendeterminedtheinformationisowned,producedbyorfor,orcontrolledbytheUnitedStates,andthatunauthorizeddisclosurecouldresultindamagetoNationalSecurity.
Whenmarkingclassifiedmaterial(i.e.documents,media,orelectronicfiles),thefollowingmustbeincluded:
• Theoveralllevelofclassification
• Titleofthematerial
• Datecreated
• Nameandaddressoftheoriginatingfacility
• Identityoftheclassifier
• Periodoftimeprotectionisrequired
• Anysourcesusedtoclassifytheinformation
• Anyportionsthatcontainclassifiedinformation
CLASSIFICATION OVERVIEW
Classificationmarkingsmaybeidentifiedfromthefollowingtwoplaces:
• SecurityClassificationGuides(SCGs)orequivalentguidelineauthorizedforyoureffort
• Existingproperlymarkedsourcematerialauthorizedforuseonyoureffort
Classificationmarkingshelpfacilitatepropersafeguardingrequirementsandassistinthepreventionofinadvertentrelease.
Youmayberequiredtoperformderivative classification decisionsinthecourseofyourjobresponsibilities;ifthisisthecase,youwillreceiveadditionaltrainingingreaterdetail.
SECRET
SECRET
(U) Derivatively Classified Document
August 30, 2014
Lockheed Martin Corporation6801 Rockledge DriveBethesda, MD 20817
Classified By: Name & Position OR Personal IdentifierDerived From: Originally Classified Document, dated August 29, 2014, U.S. NavyDowngrade On: 20291105Downgrade To: CONFIDENTIALDeclassify On: 20391105
SECRET
SECRET
(U) Originally Classified Document
August 29, 2014
U.S. Navy Program Executive Office123 Washington Drive
Washington, DC 20004
Classified By: John Smith, Senior Program ManagerReason: 1.4(a)Derived From: XYZ Security Classification Guide, dated 11 Nove 2014, U.S. NavyDowngrade On: 20291105Downgrade To: CONFIDENTIALDeclassify On: 20391105
Carrying forward these markings to newly-generated material is our responsibility as contractors, who make derivative classification decisions when we include existing classified information into new forms.
Classification markings and examples in this guide are for training purposes only.
DoD Initial Training Guide | 9
Counterintelligenceisdefinedasinformationgatheredandactivitiesconductedtoidentify,deceive,exploit,disrupt,orprotectagainstespionageorsabotage;conductedfororonbehalfofforeignpowers,organizations,internationalterroristgroupsorindividuals.
COUNTERINTELLIGENCE
What does that mean to you? CounterintelligenceisidentifyingintelligencethreatstoLockheedMartinandourgovernmentcustomers,anddevelopingstrategiestomitigatethosethreats.
AsanewlyclearedemployeewithLockheedMartin,it’simportantyouunderstandthesethreats.
Intelligencethreatscancomefromforeignintelligenceservices,foreignand/ordomesticindustrycompetitors,criminal,terrorist,and/orextremeactivistorganizations,andtrustedinsiders,alsoknownastheinsiderthreat.
Intelligencecollectioncancomeinavarietyofdifferentforms,including:elicitation,opensourcecollection,electronicsurveillance,cyberintrusions,socialengineering,exploitationofsocialmedia,andformalrecruitment.Recruitmentoccurswhenanemployeecollectsinformationonbehalforatthedirectionofaforeignintelligenceservice.Formalrecruitmentisoftentheprecursortoinsiderthreatactivity.
TheinsiderthreatissomeonewhohaslegitimateaccesstocompanyorclassifiedUSGinformationandusesthataccesstostealinformationfortheir
foreignintelligenceservice,ontheirbehalf.IndicatorsofinsiderthreatactivitymightincludeanapparentdisgruntlementwithemployerorUSG,disregardforsecurityandITprocedures,outwardexpressionofloyaltiestowardscompetitorsorforeignnations,unreportedforeigntravelorforeigncontacts,orasuddenshiftindemeanor.
Theultimategoalofaforeignintelligenceofficerissuccessfulrecruitmentofanemployeewhocanactasaninsiderontheirbehalf.AsaLockheedMartinemployeeandamemberoftheclearedcommunity,youareanelevatedtargetforrecruitmentandintelligencecollectionbythosethatseekaccesstoclassifiedinformationandclassifiedinformationsystems.
Youarealsointhebestpositiontoobservebehaviorssuggestingconcernsofaninsiderthreatintheworkplace.EmployeeshouldcontacttheirlocalSecurityOfficeimmediatelyiftheyhaveconcernsthey’vebeeninvolvedinarecruitmentattemptorotherintelligencecollectionattempts,oriftheyhaveanyconcernsofpotentialinsiderthreatactivityintheworkplace.
Foreign Intelligence Services
Foreign and/or Domestic Industry
Competitors
Criminal, Terrorist, and/or Extreme
Activist Organizations
Trusted Insiders
DoD Initial Training Guide | 10
This guide provided you with information on:• Yourreportingrequirements
• Thesecuritydutiesandproceduresapplicabletoyourjob
• TheSecurityClassificationSystem
• Counterintelligence,theinsiderthreat,anddefensivesecuritypracticestomitigatethesethreats
Rememberthateachfacilitysupportsuniquecontractsandmayimplementrequirementsinslightlydifferentways.TobesuccessfulinyournewroleasaclearedLockheedMartinemployee,itisimperativethatyouworkcloselywithyourlocalSecurityOfficeregardingthecontentreviewedinthisguideandanyadditionalfacilityspecificrequirements.
Nowthatyouhavereceivedyoursecurityclearance,youplayanintegralpartinensuringthesuccessoftheLockheedMartinSecurityProgramandourNationalSecurity.Thenatureofyournewresponsibilitiesrelatesdirectlytoourcustomers.
Pleasecontinuetotheinstructionsonreceivingcreditforthiscourse.
Completing the Training Acknowledgement form
Now that you have completed this training, please click here to retrieve and complete the Training Acknowledgement form. The following options are available to you for submitting this form:
• Fax without a cover sheet to LMSecurity at (720) 479-2750
• Email a digital copy of the requested document to:
• Mail the requested document overnight to:
Lockheed Martin Corporation Attn: LMSecurity 100 Global Innovation Circle, MP801 Orlando, FL 32825
Once LMSecurity receives your form, training credit will be given via our internal training system.
CONCLUSION
DoD Initial Training Guide | 11
Collateral–AllNationalSecurityinformationclassifiedConfidential,TopSecretorSecretundertheprovisionsofanexecutiveorderforwhichspecialcommunitysystemsofcompartmentation(e.g.,non-SpecialCompartmentedInformation(non-SCI))arenotformallyestablished
Confidential–AlevelofclassificationthatisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocausedamagetoNationalSecurity
Courier–Anindividualwhohasbeenbriefedandmeetstherequirementstotransportclassifiedmaterials
Derivative classification decisions–Theincorporating,paraphrasing,restating,orgeneratinginnewforminformationthatisalreadyclassified,andmarkingthenewlydevelopedmaterialconsistentwiththeclassificationmarkingsthatappliestothesourceinformation.Derivativeclassificationincludestheclassificationofinformationbasedonclassificationguidance.Theduplicationorreproductionofexistingclassifiedinformationisnotderivativeclassification.
DoD–DepartmentofDefense
DSS–DefenseSecurityService
GCA–GovernmentContractingAuthority,whichprovidesguidancetocontractors
GLOSSARY
Need-to-know–mustbeinplacealongwithasecurityclearancetobegrantedaccesstospecificclassifiedinformationrequiredtoperformajob
NISPOM–NationalIndustrialSecurityProgramOperatingManual
Secret–AlevelofclassificationthatisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocauseseriousdamagetoNationalSecurity
Security clearance-AnadministrativeauthorizationforaccesstoNationalSecurityinformationuptoastatedclassificationlevel(TopSecret,Secret,Confidential).NOTE: A security clearance does not, by itself, allow access to controlled access programs
Top Secret –AlevelofclassificationthatisassignedwhentheunauthorizeddisclosureofinformationormaterialcouldreasonablybeexpectedtocauseexceptionallygravedamagetoNationalSecurity
USG –UnitedStatesgovernment
An extensive list of security terms can be found at the Defense Security Service website.