Showing posts with label NISP. Show all posts
Showing posts with label NISP. Show all posts

Wednesday, July 26, 2023

DOD Sends NISPOM Amendment to OMB

Monday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from DOD on “National Industrial Security Program Operating Manual (NISPOM); Second Amendment”. According to the Spring 2023 Unified Agenda entry for this rulemaking:

“Based on public comments, DoD is proposing additional amendments to a rule last published on December 21, 2020. This amendment addresses comments received on requests for guidance and the cost to implement Security Executive Agent Directive (SEAD) 3, as well as to provide clarification on safeguarding procedures for the protection and reproduction of classified information. It also includes DoD’s response to public comments received regarding controlled unclassified information, National Interest Determination requirements for cleared contractors operating under a Special Security Agreement for Foreign Ownership, Control or Influence, and eligibility determinations for personnel security clearance processes and requirements, among others.”

Saturday, August 29, 2020

DOD Sends NISP Operating Manual to OMB for Review


Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had received from DOD the “National Industrial Security Program Operating Manual (NISPOM)” for review.

According to the abstract for this action in the Spring 2020 Unified Agenda:

“This rule will codify the National Industrial Security Program Operating Manual (NISPOM) which prescribes specific requirements, restrictions, and other safeguards that are necessary to preclude unauthorized disclosure and control authorized disclosure of Federal Government classified information to contractors, licensees, or grantees. The NISPOM applies to the release of classified information during all phases of the contracting process, including bidding, negotiation, award, performance, and termination of contractors, the licensing process or the grant process, with or under the control of departments or agencies.”

Commentary


No, I am not going to start digging into the ins and outs of NISP. The publication, however, of this manual will probably serve as a good, informational guide to any organization that is considering trying to get routine access to classified cyber-threat intelligence information from the government.

Monday, September 12, 2016

NARA Sends Industrial Security Program NPRM to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the National Archives and Records Administration (NARA) for revisions of the National Industrial Security Program (NISP, 32 CFR 2004). NISP was established by Executive Order 12829.

According to the Spring 2016 Unified Agenda abstract:

“The Information Security Oversight Office (ISOO), a component of NARA, is proposing this rule pursuant to Executive Order 12829, relating to the National Industrial Security Program (NISP). The proposed changes are primarily administrative, bringing together the original 2006 regulation, the 2010 change, and some updated requirements. However, a small portion of the new provisions deal with requirements from Executive Order 13587 [link added] to implement the insider threat program, and could have a potentially significant effect on agencies implementing that program's requirements.”


NISP is a DOD defense industrial base information security program addressing classified information security and thus will have little direct effect on most manufacturing facilities. It could be instructive, however, for possible future regulations on other classified information sharing programs.

Tuesday, April 29, 2014

NARA Announces Meeting of NISPPAC

Today the National Archives and Records Administration (NARA) published a meeting notice in the Federal Register (79 FR 24019-24020) for a June 19th meeting of the National Industrial Security Program Policy Advisory Committee (NISPPAC). According to the notice the agenda includes a discussion of “National Industrial Security Program policy matters”.

The meeting is going to be held at the Gaylord National Resort in Prince George's Exhibition Hall B and due to “due to space limitations and access procedures” advanced registration is required? That might make some sense if sensitive matters were going to be discussed, but the notice clearly states that this meeting is ‘open to the public’.

And really: “The purpose of this meeting is to discuss National Industrial Security Program policy matters.” Does this fulfill the requirements of 41 CFR 02-3.150 to provide a “summary of the agenda, and/or topics to be discussed”? Of course NISPPAC is going to discuss NISP policy matters, but which ones?

Now NARA is to be commended for giving a month and a half notice instead of just the required 15 days, but is that just an effort to bury this meeting notice? I’m sorry but something smells here.


BTW: 41 CFR 102-3 addresses the management of Federal Advisory Committees not the long outdated 41 CFR 101-6.10 referenced in the notice. More obfuscation?
 
/* Use this with templates/template-twocol.html */