Preparing For the Industrial Security Professional (ISP) Certification Exam

Reading the National Industrial Security Programnot the organization is capable of providing
Operating Manual (NISPOM) will certainly have onecontinuous protection of classified information
learning new jargon and acronyms necessary towhile following the guidance of the Department of
becoming fluent in Industrial Security ProfessionalDefense. This would work in similar circumstances
language. Throughout the exam there arewithin each federal agency. The CSA is primarily
questions referring to roles of governmentconcerned with administering clearances and
agencies. Such questions concern whichoversight. They support the stipulations of the
organization has oversight, which organizationGCA.
would a security manager report a particularThe GCA is appointed by a federal agency to
incident to, or which organization inspects a certainhandle all acquisition functions. They provide
security program. The answer could be anycontract support between the government
possibility such as government contracting agencyagency and contractor. In our DoD example, the
(GCA), general services administration (GSA),GSA provides contractual support to the defense
Cognizant Security Agency (CSA), or any othercontractor from the DoD. The GCA also provides
acronym of a critical federal organization listed inthe stipulations of the contract include the
the NISPOM.statement of work, DD Form 254, and other
Consider the letters CSA which stand forguidance on how to perform the classified work.
Cognizant Security Agency. This acronym appearsThe GCA is also an approval authority for any
250 times throughout the NISPOM betweenclassified performance taking place between
chapters one and eleven. The multiple listingsagencies and governments. The GCA is
pretty much conclude that the CSA plays anconcerned with supporting and administering
important role in managing the National Industrialspecifics of a contract. The GCA provides the
Security Program. This is also one of thoseguidance that the CSA will monitor.
acronyms that a potential Industrial SecurityThe GSA approves equipment used in support of
Professional must know to successfully pass thethe security and mission. Locks, security
Industrial Security Professional Certification exam.containers, overnight delivery services and etc are
Primary questions a security manager should beapproved for use by the general services
able to describe are: What is a Cognizant Securityadministration.
Agency (CSA)? How does the Cognizant SecurityLet's check your knowledge:
Office (CSO) fit in? To answer those questions,1. Which organization would provide direction as to
we can go to the source. However, I will answerhow classified information is disseminated (USPS,
them here. The CSAs are four primary federalOvernight delivery, courier):a. GCAb. NSAc. GSAd.
agencies. They have cognizance or oversightCSA
authority over their own federal organizations.Remember that all classified work is stipulated by
The CSAs are the Department of Defense,the contract. The GCA is the organization
Department of Energy, Nuclear Regulatoryresponsible for providing the specifics of how to
Commission and the Central Intelligence Agency.perform on the contract. The answers can be
Each of the federal organizations has authorityfound in the statement of work, DD Form 254,
and oversight over their own organizations. Eachor the security classification guide. Questions
agency can delegate oversight to any officeconcerning performance and specifics of a
within their federal organization or to anothercontract will point to the GCA.
CSA. The CSAs have Cognizant Security Offices2. Which organization would an FSO report loss,
(CSO) that take care of administrative functions.compromise or suspected compromise?a. CSAb.
The CSAs are identified with their CSOs asGSAc. CIAd. GCA
follows:The answer is CSA. The Cognizant Security
CSA: Department of DefenseAgency provides oversight of the contractor
CSO: Defense Security Services (DSS)protecting the federal agency's classified
CSA: Department of Energyinformation. All questions concerning oversight
CSO: Department of Energy Field Officesbelong to the CSA.
Safeguards and Security Divisions3. Which organization provides a list of authorized
CSA: Central Intelligence Agencyovernight delivery services?a. CSAb. GCAc. NSAd.
CSO: Contract Officer's Security RepresentativeGSA
(COSR)Many questions concerning approved products or
CSA: Nuclear Regulatory Commissionservices belong to GSA.
CSO: Offices within the Nuclear RegulatoryAcronyms and jargon are part of any
Commissionprofessional organization. The FSO, security
For example, the Facility Security Officer in amanager, security specialist and ISP certified
contractor organization under the Department ofindividuals not only understand the jargon, but
Defense (DoD) follows guidance of their CSA, thehow it applies to protecting classified information
Department of Defense. Oversight andand implementing classified programs. The ISP
administrative functions are assigned to the DSS.candidate would do well to understand the broad
The DSS provides support to the contractor asand general roles of the GCA, CSA, GSA and
well as conducts analysis to determine whether orother agencies identified in NISPOM.