ITFSO ITPM Assistant

Insider threat program · Cleared contractors

Insider threat program tools

Four aids for the ITPSO and FSO of a cleared contractor under 32 CFR Part 117: write the program plan, decide whether something must be reported, keep training and program tasks on schedule, and self-inspect the program. A maturity assessment workbook scores how well it all works.

Your records stay on your machine. The tools run entirely in your browser. The pages’ security policy blocks any network connection, and they save nothing in the browser. What you type is gone when you close the tab unless you export it. The place to keep it is an Excel workbook on your own computer or company system.

Sources checked. The references were checked against 32 CFR Part 117 and DFARS 252.204-7012 on eCFR (current as of 22 September 2026) and DCSA ISL 2021-02. This is a preparation aid, not a determination and not legal advice.

Maturity assessment

How well does the program work?

The self-inspection asks whether the program meets the rule. The maturity assessment asks how well it works. It is a separate Excel workbook: score 28 capabilities in six domains from 1 to 5 against written descriptions, and the workbook works out domain averages, your maturity level, the critical controls that fall short, and a roadmap for the next level.

  • Ten critical controls are the capabilities 32 CFR Part 117 requires. One scored below 3 is a compliance gap and caps the overall level at 2.
  • Evidence rules keep scores honest: no record, no score above 2; a written procedure nobody follows scores 2 at most; so does a practice that covers less than 80% of the cleared workforce.
  • Run it every 12 months, with the self-inspection, led by the ITPSO with the FSO, HR, IT and legal.
Made in your browser, like the other workbooks.

Individual concern assessment

When one person’s behavior worries you

If anyone is in immediate danger, call 911 first. Then report possible espionage, sabotage or terrorism to the FBI, and adverse information to DCSA, as 32 CFR §117.8 requires. The case workbook starts with these checks.

A case workbook for one concern about one person. The team records facts, not rumor; marks which behaviors are present (violence-pathway, information-risk, stressors and protective factors); decides a level of concern (Low, Moderate, High or Imminent) and writes down why; and keeps a management plan and reviews.

  • Team judgment, not a score. The workbook counts indicators for context but never adds them into a number. Behavior decides the level, weighed against protective factors; stress alone is not evidence.
  • Guardrails built in: facts only, no diagnoses and no protected characteristics, legal counsel involved, no investigating on your own, and a check for retaliation against protected activity.
  • Not a determination. It does not predict, diagnose or decide eligibility (DCSA does), and no employment action should rest on it alone.
  • One file per case, named by case ID, never by name, and stored with insider threat program records.
  • One register for all cases: a row per case (level, owner, next review, reports, closure and destroy-after dates) with a dashboard of what is due. No names or facts go in it, so one file never exposes every case.
Rename each case workbook to its case ID.

How the records work

One workbook on your machine; the tools fill it

  1. Download the blank workbook once. It has a sheet for each tool: Plan, Training Roster, Program Calendar, Reporting Log and Self-Inspection. The due dates and status columns are calculated by Excel formulas. Save it where your program records belong, with access limited to program personnel.
  2. Use a tool, then export. Each tool exports an Excel file whose sheet has exactly the same columns, widths, drop-downs and formulas as the blank workbook.
  3. Copy the rows across. Select the rows in the export, copy them, and paste them into the first empty row of the same sheet in your workbook. The training calendar can also read rows pasted back from your workbook, so you can check due dates without typing everything again.
Made in your browser. Nothing is downloaded from a server.
Keep only what the program needs. Record facts, not rumor or speculation. Use an employee ID instead of a name where you can. Do not put these files in a personal or shared cloud folder, and do not attach them to email. An exported calendar file (.ics) from the training tool leaves names out on purpose, because calendar apps usually sync to the cloud.

Sources: 32 CFR §117.7 (ITPSO, insider threat program, self-inspections); 32 CFR §117.8 (reporting requirements); 32 CFR §117.12 (training); DCSA ISL 2021-02 and the cleared industry reporting guide on fsotools.ai. For companies under DCSA cognizance. Not legal advice.