ITFSO ITPM Assistant

FSO ITPM Assistant · Plan builder

Draft your insider threat program plan

Answer the questions below. The plan draft under the form updates as you type. Print it or save it as a PDF, or export it as rows for the Plan sheet of your workbook.

Nothing you type leaves this page. It is not saved either: export or print before you close the tab.

A starting point. For your own plan, sized to your company. It does not replace DCSA’s guidance or your legal counsel’s review.

1Scope
2Designations

The SMO appoints the ITPSO in writing. The ITPSO must be a U.S. citizen employee who holds eligibility at the level of the FCL; the ITPSO, FSO and SMO are key management personnel. §117.7(b); §117.9(c)(5), (d)(1)(iv)

Is the ITPSO also the FSO?

3Program personnel

Which offices take part? Small companies often have one person covering several of these. §117.7(d); good practice

4Gathering and integrating information

Where can relevant information come from? The program looks for information that bears on the 13 adjudicative guidelines, and only for that. §117.7(d); SEAD 4

5Reporting and response

Does any contract or DD Form 254 add customer reporting on top of the reports to DCSA and the FBI? §117.8

6Classified information systems

Does the company operate a classified information system that DCSA has authorized? §117.18(b)(4); DCSA DAAPM

7Training

ITP personnel, including the ITPSO, take program training on four required topics. Cleared employees take insider threat awareness training before access and every year after. §117.12(g)

8Records and privacy

Has legal counsel reviewed the program’s procedures for privacy, civil liberties and whistleblower protections?

9Oversight and approval

Answer the questions to build the plan.

Sources: 32 CFR §117.7(b), (d) and (h); §117.8; §117.9; §117.12(g); §117.18(b)(4); SEAD 4. For companies under DCSA cognizance. Not legal advice.