sample only order at security awareness training a threat awareness briefing. a defensive security...

23
Sampl e onl y Order at www. r edbikep ublishin g.com Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the security classification system. Employee reporting obligations and requirements. Security procedures and duties applicable to the employee's job.

Upload: colin-nelson

Post on 20-Jan-2016

227 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

omSecurity Awareness Training

• A threat awareness briefing.• A defensive security briefing.• An overview of the security

classification system.• Employee reporting obligations and

requirements.• Security procedures and duties

applicable to the employee's job.

Page 2: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

omReport to DISCO

• Employees who do not want to perform on classified work

• Refusal to sign SF 312

Page 3: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-207 Hotlines

• Hotlines are available. However, recommend that company officers have chance to handle situation

• Not to take place of investigations

• May be used to tip off

Defense HotlineThe PentagonWashington, DC 20301-1900(800) 424-9098

Page 4: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-3 Reporting

• Events that impact:– FCL– PCL– Protection of classified information– Loss or compromise

• Contractors cleared employees on reporting channels with:– Federal agencies– FBI– CSA

Page 5: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-3 Reporting (To FBI)

• Reports to FBI– Espionage– Sabotage– Terrorism– Subversive activities– Submit copy of written report to CSA

Page 6: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

omHow to Report

• Report to the FBI

• Follow up with written report

• Send copy to IS Rep with FBI approval

Page 7: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-3 Reporting (To CSA)

• Reports to CSA– Adverse information– Suspicious contacts– Change in cleared employee status– Naturalization– Not desiring to work on classified contract

Page 8: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

omDISCO

• Adverse Information• Changes in Cleared Employee Status• Citizenship by Naturalization• Employees Desiring Not to Perform on

Classified Work• Standard Form (SF) 312

Page 9: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-3 Reporting (to CSA)

• Reports to CSA– SF 312– Changes affecting FCL– Changes in storage capability– Inability to protect classified– Security equipment vulnerabilities– Unauthorized receipt of classified– Compromise information– Disposition of classified information– Foreign classified contracts

Page 10: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-3 Reporting (to CSA)

• Reports to CSA– Refusal to sign SF 312– Changes affecting FCL– Changes in storage capability– Inability to protect classified– Security equipment vulnerabilities– Unauthorized receipt of classified– Compromise information– Disposition of classified information– Foreign classified contracts

Page 11: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-303 Loss, Compromise or Suspected Compromise

Page 12: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om1-303 Loss, Compromise or Suspected Compromise

Discover circumstances surrounding the reported loss, compromise or suspected compromise.

Page 13: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

www.ispcert.com

Threat Awareness Briefing

Page 14: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Why Our Information

Employee Responsibilities

Threat Awareness and Defensive Information

Methods of Contact

Countermeasures

Test

CONTENTS

Page 15: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

www.ispcert.com

Why go through process of Research and Development

Let someone else pay for R&D

Possible military application

WHY OUR TECHNOLOGY?

Page 16: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Protect Proprietary, For Official Use Only and Sensitive Information

This information includes:Vendor pricespersonnel ratings medical recordscorporate financial investments and resourcestrade secret informationcorporate/government relationscorporate security vulnerabilitiesfinancial forecasts and budget information

EMPLOYEE RESPONSIBILITY

Page 17: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Company Computer Security Safeguards Use computers for authorized business Establish and protect passwords Visit only authorized websites Use caution when downloading attachments Save all work Use classified systems for classified processing

EMPLOYEE RESPONSIBILITY

Page 18: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

The following may indicate that you could be targeted: Your access to active intelligence interest Overseas locations where foreign intelligence operates Located in the U.S. where foreign nationals can gain access to you Ethnic, racial, or religious background that may attract the attention

of a foreign intelligence operative

EMPLOYEE RESPONSIBILITY

Page 19: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Foreign Threat Economic – theft of technology and commerce Classified information-solicitation for unauthorized

disclosure Intelligence-collection efforts

Conduct Risk Analysis Who is targeting What do they want How do they get it

THREAT AWARENESS AND DEFENSE

Page 20: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Collection effortsElicitationEavesdroppingSurveillanceTheft Interception

THREAT AWARENESS AND DEFENSE

Page 21: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Suspicious Activities

Requests for information outside of need to know

Unauthorized reproduction of materials

Unauthorized removal/destruction of materials

Unexplained affluence

Regular, unexplained foreign travel

Maintains long hours in spite of job dissatisfaction

Employees are required to report efforts by any individual to obtain illegal or unauthorized access to classified or sensitive information— This include proprietary information

INSIDER THREAT

                    

              Robert Philip Hanssen

Page 22: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Fax Snail Mail E-mail Telephone Personal Contact

May seem innocent enough, but…. Legitimate business requests will come through appropriate channels

Personal Contact: Asks about project specifics, whether or not classified or proprietary details

Email address originated in a foreign country

METHODS OF CONTACT

Page 23: Sample only Order at  Security Awareness Training A threat awareness briefing. A defensive security briefing. An overview of the

Sample

only

Order

at

www.redbik

epublis

hing.c

om

www.ispcert.com

Remain non-committal if approached Report all suspicious activities to FSO Practice smart information systems security Escort visitors Pay attention to surroundings Secure building at the end of the day

COUNTERMEASURES