FSO ITPM Assistant · Insider threat program · Cleared contractors

Run your insider threat program, with the records on your machine.

Tools for the ITPSO and FSO of a cleared contractor under 32 CFR Part 117: write the program plan, decide whether something must be reported, keep training on schedule, self-inspect the program, score how mature it is, and work a concern about one person through a structured case record. Everything runs in your browser and writes Excel workbooks you keep.

Version 0.1.0 · built from fso-itpm-assistant e3483c0 · references checked against eCFR and ISL 2021-02, 24 September 2026.

0network connections: the pages are not allowed to make any
0records kept by the website or the browser
Excelworkbooks you keep in your own records
Offlinethe same tools as one download

The tools

Each opens in your browser. Each exports an Excel sheet with the same columns as the master workbook, so rows paste straight across.

ITP plan builder

Answer questions about your company and program; get a plan draft with the gaps highlighted, to print or export.

Is this reportable?

Pick what happened. See who must be told, through which channel, how fast and under which rule, and keep a reporting log.

Training and compliance calendar

Initial and annual insider threat training, ITP personnel training and recurring program tasks, with due dates worked out.

ITP self-inspection

The insider threat part of the annual self-inspection, with evidence and corrective actions.

The workbooks

Made in your browser from the tools’ overview page. Nothing is downloaded from a server.

Master workbook

Plan, training roster, program calendar, reporting log and self-inspection in one file, with the due dates and statuses as Excel formulas.

Maturity assessment

How well the program works, not just whether it meets the rule: 28 capabilities in six domains scored 1 to 5, with ten critical controls the rule requires and a roadmap.

Individual concern case workbook and register

When one person’s behavior worries you: immediate checks (911, FBI, DCSA), a fact log, behavior-based indicators and a level of concern the team decides and justifies. It is never a computed score. A register lists every case, with no names or facts.

Where your data stays

  • Nothing leaves the page. The tool pages are served with a security policy that forbids every network connection, and they store nothing in the browser. What you type is gone when you close the tab unless you export it.
  • Your records are Excel workbooks. Keep them with your insider threat program records, open only to program personnel: not in email, and not in personal or shared cloud folders.
  • Or use it offline. If your security team would rather not enter this kind of information on any website, download the offline edition and open it from your own computer. It is the same five pages, byte for byte, with the same no-network policy built in.
  • Store only what the program needs. Facts, not rumor; an employee ID instead of a name where you can; never diagnoses or protected characteristics.

Before you rely on it

A preparation aid. The references to 32 CFR Part 117 and DFARS 252.204-7012 were checked against eCFR (current as of 22 September 2026), and those to DCSA guidance against ISL 2021-02; each tool names the paragraph it relies on. The tools do not make determinations, predict behavior or decide eligibility (DCSA does), and they are not legal advice. If anyone is in immediate danger, call 911 first. Have legal counsel review your use of the individual concern case workbook before you use it on a real case.

Sources: 32 CFR Part 117 (§117.7 insider threat program, SPP and self-inspection; §117.8 reporting; §117.12 training); SEAD 4; SEAD 3 and DCSA ISL 2021-02, as summarized in the cleared industry reporting guide. For companies under DCSA cognizance.