NISPOM Central-Working with National Industrial Security Program

jeffrey W. Bennett, ISP, SAPPC, SFPC, ISOC

Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.

  1. 1d ago ·  Video

    Protecting CUI: Don't Relegate Responsibility to IT or Cyber

    Send us Fan Mail Protecting CUI Beyond CMMC: Security Managers, Program Teams, and Consistent Marking In this NISPOM Central episode, the host argues that protecting Controlled Unclassified Information (CUI) is primarily a security manager/FSO responsibility that requires active involvement from program managers, engineers, and contract staff to identify, mark, document, and protect CUI and all derived products throughout workflows and the supply chain. He warns against relying on CMMC or technical cyber/IT controls alone, comparing it to a bank that stores valuables without accounting for deposits or growth, and notes inconsistent CUI identification and marking as a common failure. He describes how CUI may arrive as marked source documents (designs, drawings, slides, reports, PII used for government purposes) without a marking guide, requiring contract review and requirement analysis. When CUI status is unclear or unmarked, he advises seeking clarification internally, then from primes or the government program office. He announces forthcoming training on his Teachable LMS. 00:00 Welcome to NISPOM Central 00:08 CMMC Fatigue and Focus 01:02 Bank Analogy for CUI 01:51 Ownership Beyond IT 02:31 Supply Chain Consistency 03:47 Why CUI Became Cyber 06:52 Wake Up Call on CUI 07:16 Define Roles and Accountability 07:54 How CUI Shows Up 08:52 Derived Products and Markings 11:04 When CUI Is Unclear 13:06 Wrap Up and Training Offer Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

    Protecting CUI: Don't Relegate Responsibility to IT or Cyber
  2. Jun 5

    Contractors can determine CUI and ITAR

    Send us Fan Mail https://www.thriveanalysis.com. For consulting https://www.nispomcentrial.com for books and training https://www.skool.com/nispomcentral/about for Nispom central community Due Diligence: Contractors’ Responsibility to Identify and Protect CUI and Sensitive Information Jeff Bennett of Thrive Analysis Group and NISPOM Central argues that the common claim “contractors are not authorized to determine CUI” is bad advice that leads people to ignore their responsibility to identify, mark, and protect sensitive information in their work products. He says contractors are authorized to apply derivative markings based on government instructions and must exercise “presumption of care” (duty of care) to prevent applied research, controlled technologies, export-controlled information (EAR/ITAR), proprietary data, PII, and CUI from entering the public domain, which can harm warfighters and technology. Citing examples of ITAR data nearly published and CUI text copied into deliverables, he emphasizes repeatable processes, reasonable standards aligned to NISPOM, DD Form 254, DFARS, CMMC, and NIST SP 800-171, plus marking by default and reviewing materials before release. 00:00 Contractors Can Mark CUI 01:05 Stopping the Big Mouth 02:33 Bad Advice in Defense 03:41 Due Diligence Basics 05:55 When Research Turns Sensitive 06:57 Real World CUI Slipups 09:34 No CUI Police Myth 10:41 Presumption of Care 11:21 Derivative Marking Process 12:12 Protect Warfighters and Wrap Up NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.NISPOM StoreOur StoreNISPOM Central CommunityThe skill building community for FSOs who desire to progress in a measured way. Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

  3. Apr 2

    Untitled From Reactive to Proactive: Building an Audit-Ready FSO Program for DCSA Reviews

    Send us Fan Mail https://nispomcentral.com/ https://www.nispom.com https://www.thriveanalysis.com Jeff Bennett of Thrive Analysis Group discusses how FSOs can shift from reactive “scramble mode” to a proactive, audit-ready NISPOM program that consistently passes DCSA security reviews. He explains why many FSOs—especially in small companies where the FSO wears multiple hats—get overwhelmed, and notes that daily tasks can be delegated even though authority and audit responsibility cannot. Bennett outlines what DCSA looks for: alignment between the FSO and the senior management official (who owns the program), the ability to demonstrate NISPOM compliance with artifacts, clear explanations using anecdotes, and employee buy-in demonstrated through awareness of the program. He recommends maintaining an FSO workbook on a secure shared drive to store compliance artifacts, using standardized forms (not email) to collect required employee information for actions like foreign travel and visit requests, and keeping briefings, trainings, and reports updated to remain continuously review-ready. 00:00 Welcome and Overview 00:45 Why FSOs Go Reactive 02:15 Delegate and Ditch Email 03:15 What DCSA Reviews 04:38 Employee Buy In Matters 05:33 Build the FSO Workbook 06:55 Forms for Every Task 08:27 Always Audit Ready 09:03 IG Inspection Story 10:44 Wrap Up and Next Steps NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

  4. Feb 16

    FSOs Stop Using Email to Execute FSO Tasks

    Send us Fan Mail https://www.nispomcentral.com https://www.nispom.com Stop Managing FSO Tasks by Email: Use Fillable Forms and an FSO Workbook for DISS and NISPOM Compliance Jeff Bennett, an FSO expert with NISPOM Central, explains why using email to execute FSO tasks creates excessive administrative burden and potential security vulnerabilities, especially when emails are not encrypted. He uses visit authorization requests (VARs) as an example, noting that repeated email back-and-forth often happens because employees don’t provide all required information needed to enter data into DISS. While some organizations use dashboards to capture required fields, many FSOs serve as additional-duty personnel without resources or experience, making email-driven workflows inefficient and time-consuming. He recommends replacing task execution via email with standardized fillable forms that capture DISS-required fields once, storing and archiving them in an “FSO workbook” that can also support NISPOM compliance and self-inspections. Email should be used only for notifications and reminders (e.g., training reminders), not for collecting VAR, training, foreign travel, or other reporting information through multiple messages. He offers sample forms, consultations, and access to the FSO workbook and downloadable files via NISPOM Central’s websites. 00:00 Welcome & Why FSOs Struggle With Task Management 00:58 The Email Trap: VAR Requests Turning Into 10+ Messages 02:19 Why VARs Need So Much Data (and Why Employees Miss It) 02:47 Big-Budget Dashboards vs. Additional-Duty FSOs 04:22 A Better System: The FSO Workbook & Fillable Forms 05:01 Security Risk: Unencrypted Email and Sensitive Data 05:17 How to Build Your Own Forms + Shared Drive Workflow 05:54 Use Email for Notifications—Not for Doing the Work 07:06 Get a Sample Form, Consultation, and Download Resources 07:46 Final Takeaway: Stop Running FSO Tasks Through Email NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

  5. 11/03/2025

    FSO and SMO Relationship Part 2

    Send us Fan Mail FSO professional development https://www.nispomcentral.com/fso-pro... Get NISPOM  https://www.nispomcentral.com/nispom-... Contact us: jeff.bennett@nispomcentral.com Brian Robinson Coaching https://www.brianrobinsoncoaching.com/ Cultivating Excellence: Strengthening the FSO and SMO Relationship In this episode of DOD Secure, host Jeff Bennett is joined by Brian Robinson of Brian Robinson Coaching to discuss the pivotal relationship between Facility Security Officers (FSOs) and Senior Management Officials (SMOs).  They dive into the importance of leadership, communication, and trust in creating a compliant and effective security program. Highlighting strategies such as building trust with team members and communicating effectively with higher management, Brian shares his insights on fostering successful relationships within the organization. This episode is a must-listen for anyone looking to enhance their security program and develop strong leadership qualities. NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Jeff's WebsiteJeff is available for speaking and consultingClearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

    FSO and SMO Relationship Part 2
  6. 10/17/2025

    FSO and SMO Relationship Part 1

    Send us Fan Mail Join our community https://www.skool.com/nispomcentral FSO professional development https://www.nispomcentral.com/fso-pro... Get NISPOM  https://jeffbennettsteamwor48021.mycl... Building Strong FSO and SMO Relationships for Optimal Security Compliance In this episode, Jeff Bennett from Thrive Analysis Group and Red Bike Publishing discusses the critical relationship between the Senior Management Official (SMO) and the Facility Security Officer (FSO) within an organization. It explores how a strained or non-existent relationship can negatively impact NISPOM compliance and the overall security posture of a facility. The episode covers the roles and responsibilities of both positions, the importance of SMO engagement, and provides recommendations on improving communication and collaboration between FSOs and SMOs. Future episodes will feature expert guests offering additional insights and strategies to strengthen these crucial relationships. 00:00 Introduction and Overview 00:47 Understanding the FSO Role 01:38 Bridging the Communication Gap 02:31 Importance of SMO Engagement 04:23 Training and Responsibilities 11:36 Self-Inspection and Compliance 14:06 Organizational Structures and Challenges 16:49 Conclusion and Next StepsJoin our community https://www.skool.com/nispomcentral FSO professional development https://www.nispomcentral.com/fso-pro... Get NISPOM  https://jeffbennettsteamwor48021.mycl... NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

  7. 10/07/2025

    Gain an Absolutely Unfair Advantage of FSO Skills With Your Copy of NISPOM

    Send us Fan Mail Achieving Unfair Advantage: Professional Development as an FSO Click link below to get your NISPOM and professional library. Link to NISPOM In this video, Jeff Bennett, founder of Red Bike Publishing, discusses how to build credibility and gain an advantage in professional development as a Facility Security Officer (FSO). Jeff shares his journey from an entry-level security position to becoming an FSO, author, speaker, and consultant. He stresses the importance of understanding and utilizing NISPOM for a career in security within the defense industry. Jeff highlights the necessity of having a printed, durable copy of NISPOM and offers high-quality versions through his company. The video also covers various resources for professional growth, including books authored by Jeff, training programs, and certification opportunities to enhance skills and credibility in the field. Jeff underscores the value of continuous learning, mentorship, and how these efforts can lead to career advancement and mastery in the field of security. 00:00 Introduction to Gaining an Unfair Advantage as an FSO 01:12 Understanding the Importance of NIST Palm 02:41 Jeff's Journey and the Birth of Red Bike Publishing 04:37 The Role of Mentorship and Continuous Learning 08:22 Developing a Comprehensive Insider Threat Program 09:21 Staying Sharp and Investing in Your FSO Future 12:29 Conclusion: Take Action Now https://jeffbennettsteamwor48021.myclickfunnels.com/sales-page--40fb2?new_run=true NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Jeff's WebsiteJeff is available for speaking and consultingDisclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

  8. 10/07/2025

    Gain an Absolutely Unfair Advantage of FSO Skills with Professional Development

    Send us Fan Mail How to Achieve Unmatched Credibility as a Facility Security Officer (FSO) Click link below to get FSO and NISPOM professional development opportunities Link to professional development In this video, Jeff Bennett, founder of Red Bike Publishing and NS Palm Central, shares his extensive experience and insights into professional development for security specialists and FSOs. Jeff explains the importance of understanding and applying the National Industrial Security Program Operating Manual (NISPOM) to build credibility within the FSO field. He discusses his journey from military service to becoming an influential FSO, author, and consultant. Jeff outlines key topics critical for professional growth, including the basics of NISPOM, certification and training opportunities, and practical ways to create influence and credibility. He emphasizes the need for continuous learning and professional engagement to stay ahead in the security field. Jeff also introduces his comprehensive 20-hour FSO training course, designed to equip aspiring FSOs with the skills and knowledge needed to succeed. 00:00 Introduction to Gaining an Unfair Advantage as an FSO 01:22 Understanding NIST POM and Its Importance 03:10 Jeff Bennett's Journey and Insights 04:44 The Importance of Continuous Learning and Development 09:25 Making Strategic Decisions as an FSO 13:22 Investing in Your FSO Future Sales Page NISPOM CentralProviding security clearance books, training, and resources for cleared defense contractors.Clearance, NISPOM, and FSO ConsultingThrive Analysis Group Inc is your resource for security clearance, NISPOM, and FSO consulting.Jeff's WebsiteJeff is available for speaking and consultingDisclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.Support the show FSO Consulting: https://thriveanalysis.com NISPOM Compliance https://www.nispomcentral.com https://www.nispom.com The Trusted Advisor for Technology Protection, FSO and NISPOM consulting.  After dialing in my craft and many years of honing program protection experiences, I became a trusted advisor. I am currently supporting customers with technology protection and NISPOM compliance topics. INDUSTRIAL SECURITY TRUSTED ADVISOR What Trusted Advisor Involves: I partner with executive leadership to design and operate security programs that meet and exceed NISPOM requirements.  Results you can measure immediately: Prepared commercial organizations for defense contracting and NISPOM complianceDesigned ready to implement security programs before, during and after facility clearance awardRescued high risk security programs with quick turnaround; usually within 30 daysAchieved Commendable and Superior DCSA review ratingsDeveloped compliant FOCI mitigation programs

4.6
out of 5
7 Ratings

About

Interviews and topics centering on security clearances and National Industrial Security Clearance Operating Manual (NISPOM) compliance.