Insider threat program · Cleared contractors
Insider threat program tools
Four aids for the ITPSO and FSO of a cleared contractor under 32 CFR Part 117: write the program plan, decide whether something must be reported, keep training and program tasks on schedule, and self-inspect the program. A maturity assessment workbook scores how well it all works.
Sources checked. The references were checked against 32 CFR Part 117 and DFARS 252.204-7012 on eCFR (current as of 22 September 2026) and DCSA ISL 2021-02. This is a preparation aid, not a determination and not legal advice.
The tools
Pick a task
ITP Plan Builder
Answer questions about your company and program; get a plan draft to print and the same content as rows for your workbook.
Build the plan →Is this reportable?
Pick what happened. See who gets the report, through which channel, how fast, and under which rule, then add it to your reporting log.
Check an event →Training & compliance calendar
Track initial and annual insider threat training, ITP personnel training and recurring program tasks, with due dates worked out for you.
Open the calendar →ITP self-inspection
Go through the insider threat part of the annual self-inspection, record evidence and corrective actions, and export the results.
Start the checklist →Maturity assessment
How well does the program work?
The self-inspection asks whether the program meets the rule. The maturity assessment asks how well it works. It is a separate Excel workbook: score 28 capabilities in six domains from 1 to 5 against written descriptions, and the workbook works out domain averages, your maturity level, the critical controls that fall short, and a roadmap for the next level.
- Ten critical controls are the capabilities 32 CFR Part 117 requires. One scored below 3 is a compliance gap and caps the overall level at 2.
- Evidence rules keep scores honest: no record, no score above 2; a written procedure nobody follows scores 2 at most; so does a practice that covers less than 80% of the cleared workforce.
- Run it every 12 months, with the self-inspection, led by the ITPSO with the FSO, HR, IT and legal.
Individual concern assessment
When one person’s behavior worries you
A case workbook for one concern about one person. The team records facts, not rumor; marks which behaviors are present (violence-pathway, information-risk, stressors and protective factors); decides a level of concern (Low, Moderate, High or Imminent) and writes down why; and keeps a management plan and reviews.
- Team judgment, not a score. The workbook counts indicators for context but never adds them into a number. Behavior decides the level, weighed against protective factors; stress alone is not evidence.
- Guardrails built in: facts only, no diagnoses and no protected characteristics, legal counsel involved, no investigating on your own, and a check for retaliation against protected activity.
- Not a determination. It does not predict, diagnose or decide eligibility (DCSA does), and no employment action should rest on it alone.
- One file per case, named by case ID, never by name, and stored with insider threat program records.
- One register for all cases: a row per case (level, owner, next review, reports, closure and destroy-after dates) with a dashboard of what is due. No names or facts go in it, so one file never exposes every case.
How the records work
One workbook on your machine; the tools fill it
- Download the blank workbook once. It has a sheet for each tool: Plan, Training Roster, Program Calendar, Reporting Log and Self-Inspection. The due dates and status columns are calculated by Excel formulas. Save it where your program records belong, with access limited to program personnel.
- Use a tool, then export. Each tool exports an Excel file whose sheet has exactly the same columns, widths, drop-downs and formulas as the blank workbook.
- Copy the rows across. Select the rows in the export, copy them, and paste them into the first empty row of the same sheet in your workbook. The training calendar can also read rows pasted back from your workbook, so you can check due dates without typing everything again.
Sources: 32 CFR §117.7 (ITPSO, insider threat program, self-inspections); 32 CFR §117.8 (reporting requirements); 32 CFR §117.12 (training); DCSA ISL 2021-02 and the cleared industry reporting guide on fsotools.ai. For companies under DCSA cognizance. Not legal advice.