Attachment 2-DHS OCSO Contractor Orientation.pdf

PDF 988 KB Posted

Attached to
Training Support Services Federal contract opportunity
Solicitation number
70LART25RPFB00006
Issued by
Department of Homeland Security Federal Law Enforcement Training Center

About this file

This is a DHS Contractor Security Orientation training guide presented by the DHS Office of the Chief Security Officer's Compliance/Standards and Training Division. The guide provides comprehensive security training for DHS contractors covering personnel, physical, and information security protocols.

The training covers key areas including: the DHS mission and assets protection (using the PIE-FAO framework - Personnel, Information, Equipment, Facilities, Activities, Operations), threat identification (natural and human threats), Operations Security (OPSEC) processes, insider threat awareness, physical security controls (access badges, facility security, suspicious package procedures), and information security protocols (handling Sensitive But Unclassified/FOUO information). The guide emphasizes contractors' responsibilities in safeguarding DHS assets, maintaining proper information security practices, and following "Need-to-Know" principles. The document includes specific procedures for marking and handling FOUO documents, reporting requirements for security incidents, and guidance on preventing unauthorized access through tailgating and piggybacking. The training concludes with an acknowledgment form that contractors must sign confirming their completion of the orientation.

View the file

Other files for this federal contract opportunity

Other files attached to Training Support Services, newest first.
File Type Posted
Clauses and Provisions Training Support R2.docx DOCX document
Site Visit Sign in Sheet.pdf PDF
Clauses and Provisions Training Support R1.docx DOCX document
70LART25RPFB00006 00006.pdf PDF
70LART25RPFB00006 0005.pdf PDF
70LART25RPFB00006 0003.pdf PDF
70LART25RPFB00006 0002.pdf PDF
Attachment 52 - Speakers Cameras.pdf PDF
Attachment 47-RP T A-FTC-SVC-43.pdf PDF
Attachment 46-Staff Uniform Issue Card FTC-SSD-45.pdf PDF
Attachment 41-End of Program ReportFTC-OFT-09.pdf PDF
Attachment 39-OF-347 Order for Supplies or Services.pdf PDF
Attachment 38- Weapon Ammo Ck Out In.pdf PDF
Attachment 37 - Armory Control Procedure.pdf PDF
Attachment 29- Move Order.pdf PDF
Attachment 22-HISTORICAL DATA Training Support.pdf PDF
Attachment 16-FTC-ADM-1A PR.pdf PDF
Attachment 3-Contractor Security Screening Forms Instructions.pdf PDF
Training Support TOC.xlsx XLSX spreadsheet
PRS Summary Training Support (3).xlsx XLSX spreadsheet
70LART25RPFB00006 0001.pdf PDF
Attachment 51-RP Scenarios-Examples.pdf PDF
Attachment 45-Gym Issue Card FTC-SSD-35.pdf PDF
Attachment 34-Lock Key Request Blank (1).pdf PDF
Attachment 30-Work Request.pdf PDF
Attachment 26-Property Acct. Change-FTC-ADM-43.pdf PDF
Attachment 23-Training Support Weapons.pdf PDF
Attachment 13-FD_FM 70-09 Occupational Safety and Health Program - 508.pdf PDF
Attachment 10-FLETC Form 121-00-02 Visitor Vendor Access Request_.pdf PDF
Attachment 9-DHS Form 11000-9 Fair Credit Reporting Act.pdf PDF
Attachment 8-DHS Form 11000-6 Non-Disclosure Form.pdf PDF
Attachment 6-DHS Form 11000-25.pdf PDF
Wage Determination 20110084 Revision 32.txt TXT text file
Attachment 44-Daily Issue Cards FTC-SSD-30A.pdf PDF
Attachment 36-FTC-ADM-67 CDR.pdf PDF
Attachment 33-Lock Key Mgmt..pdf PDF
Attachment 31-Print Request Form - Blank FLETC Form-142-00-01.pdf PDF
Attachment 28-FTC-ALM-44 Survey Report.pdf PDF
Attachment 27-Inventory Control Form-FTC-MRSD-10.pdf PDF
Attachment 24-Facility List.pdf PDF
Attachment 23-340.pdf PDF
Attachment 19-SF-91 - Motor Vehicle Accident Report Form.pdf PDF
Attachment 14a-FLETC-OAO HMWMP.pdf PDF
Attachment 14-FLETC Hazardous Waste Management Plan - 508.pdf PDF
Attachment 5-DHS Form 11055 FN Screening.pdf PDF
Attachment 1-Abbreviations and Definitions.pdf PDF
Section J - Atch 53-Resume Format.pdf PDF
Attachment 32 -SASS Sample Class Schedule.pdf PDF
70LART25RPFB00006.pdf PDF
Section E-QASP Training Support.doc DOC document
Show all 50

Training Support Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

content

Department of Homeland Security Contractor Security Orientation

Presented by:

DHS Office of the Chief Security Officer

Compliance / Standards and Training Division

IMPORTANT:

The contents of this training guide are

UNCLASSIFIED.

All information and instructions contained herein are in accordance with Executive Order 13526, 32 CFR, part 2001, DHS Management Directive (MD) 11042.1, DHS IT policies and MD 11056.1: DHS policy regarding the recognition, identification, and safeguarding of Sensitive But Unclassified Information (SBU). The policies and directives referenced in this guide are applicable to all persons who are permanently or temporarily assigned, attached, detailed to, employed, or under contract with

DHS.

DO NOT duplicate, copy, or redistribute any information contained in this guide without written permission from the DHS Office of Security Compliance, Standards and Training Branch.

securitytraining@hq.dhs.gov

Page | 1 Department of Homeland Security Office of The Chief Security Officer C/S&TD Contractor Security Orientation Guide V 1.3

Introduction

The Office of the Chief Security Officer would like to welcome you to the Department of Homeland Security. This Contractor Security Orientation was developed to provide contractors with general information regarding DHS asset protection policies and safeguarding procedures. In addition to the information contained herein, be sure to review your specific operational policies and procedures, as they may contain additional helpful information and/or details.

Once you have read the information provided in this orientation, you will be able to:

The Department of Homeland Security’s mission Identify what DHS protects and the types threats being protected Identify the basic principles of each major security discipline Discuss how OPSEC applies to you and the DHS mission Explain your roles and responsibilities in accordance with the Department of Homeland Security's mission to protect America's assets, including Sensitive But Unclassified and Classified National Security Information.

Understand the terms "Need-to-Know" and "unauthorized disclosure"

Page | 2

C/S&TD Contractor Security Orientation Guide V 1.3

Protecting America’s Assets Skip to main content The department of Homeland Security employs a comprehensive security program to ensure the operational integrity and protection of our assets. The acronym "PIE-FAO" is an easy way to remember what these assets are.

• Personnel: People are our most important asset. Without the protection of people, some of the other items listed here could also be compromised.

• Information: In all DHS environments, information is something we all work with on a daily basis; both classified and unclassified.

• Equipment: From computer network systems and telecommunications, to facsimiles and COMSEC equipment, we use these things on a daily basis to process and disseminate the information we work with.

• Facilities: We need to protect places we work, process, and store information and equipment. No two facilities are alike.

• Activities: Many activities also need protection. This includes our travel, meetings, working groups, and project teams that we may be involved with.

• Operations: Protecting the continuity of essential security operations, like immigration and terrorism task force operations is crucial.

Page | 3

C/S&TD Contractor Security Orientation Guide V 1.3

Identifying Threats

There are primarily two types of threats we are most concerned with. The first type of threat is known as a natural disaster - an adverse condition or event imposed by nature. without certain security efforts, the after effect of natural disasters could leave our facilities damaged, creating vulnerability to further threats and compromises. Normally, these happenings are not predictable, therefore we have to be emergency prepared and establish and maintain a Continuity Of Government (COG) and Continuity of Operations Plan (COOP).

Page | 4

C/S&TD Contractor Security Orientation Guide V 1.3

The second type of threat we need to be concerned with is the human threat. The human threat ranges from International, domestic, gangs, to the insider threat. International and Domestic Terrorist threats run the gamut; from hate-filled white supremacists…to highly destructive eco-terrorists…to violence-prone anti-government extremists…to radical separatist groups. U.S.

Immigration and Customs Enforcement (ICE) is continually working to rid our streets of violent foreign-born gang members who are in our country illegally and represent a threat to our community and government.

Are there any other kinds of threats you can think of? Maybe you’ve heard of the term “insider threat”? Executive Order (EO) 13587 directs U.S. Government Executive Branch agencies and departments to establish an Insider Threat Task Force to develop a government-wide Insider Threat program, to protect classified national security information. But what exactly is an Insider threat? In the next section, we will briefly discuss the insider threat and what you can do to identify and report suspected insider threats.

Page | 5

C/S&TD Contractor Security Orientation Guide V 1.3

Insider Threat

The National Insider Threat Task Force (NITTF) provides the following definitions to better understand and identify insider threats.

An insider is a person with authorized access to any United States Government resource to include personnel, facilities, information, equipment, networks or systems.

The Insider Threat is identified as someone who uses his/her authorized access, wittingly or unwittingly, to do harm to the security of the United States.

Top, left to right: Edward Joseph Snowden, Nidal Malik Hasan, and Chelsea Manning Bottom, left to right: Aaron Alexis, David Petraeus

Anyone with positioning and/or access could be an insider threat, either through intentional or unintentional efforts. In some cases, simply a lack of training, knowledge of experience can create security vulnerabilities. As a contractor for the Department of Homeland Security, you may also be required to complete Insider threat-specific training and direct your Insider Threat matters/questions to: dhs_insider_threat_program@hq.dhs.gov or (202) 447-4200.

Page | 6

C/S&TD Contractor Security Orientation Guide V 1.3

Operations Security (OPSEC)

Operations Security (OPSEC) is systematic and proven process by which the U.S.

Government and its supporting contractors can deny to potential adversaries’ information about capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence of the planning and execution of sensitive Government activities.

Being able to identify indicators and following your Operational Security (OPSEC) processes are essential in protecting information about missions, activities, and operations.

We can never underestimate the capabilities or strength of conviction of an adversary. Nothing is more dangerous than someone who is willing to die for a cause. Who is the adversary? It is important to remember that the U.S. Government has many adversaries with bad intentions. For example, foreign intelligence services continue to collect information on us that could be used to hurt us in the future. We sometimes only focus on what just happened, but it is a certainty that our adversaries will continually look for and find any weak links.

Their intent may be to:

• Collect Information

• Conduct Espionage

• Disrupt/Impact Service

• Secure Criminal advantage

• Terrorism

• Obtain Publicity/Propaganda

• Gain Competitive Advantage

• Exploit Personnel/Vulnerabilities

• Offensive Cyber Operations

Think about what someone may observe regarding your activities. What do you do when you go to work? What are you revealing by your predictable routines and the way you do business?

These are called "indicators". As a DHS contractor, you are responsible for identifying the indicators and vulnerabilities that may exist in your activities and operations, so that the OPSEC Process can be applied effectively.

Page | 7

C/S&TD Contractor Security Orientation Guide V 1.3

The OPSEC Process is a 5-step evaluation methodology that involves: identifying critical assets, such as information; analyzing the threat; analyzing vulnerabilities; assessing risk;

and applying countermeasures. Do you currently apply OPSEC in your daily activities?

What kinds of routine activities could be measurably observed by others? Look at the example diagram below and determine if your OPSEC is working to help protect critical information.

1. Identify Your Critical Information What do you want to protect and why? Is it governed by a regulatory requirement?

Can it be defined as sensitive but unclassified?

2. Analyze the Threat Who wants the sensitive information? Is there more than one adversary?

What is their objective? What will they do to get to your sensitive information?

What methods will they use to get it?

3. Analyze the Vulnerabilities How is your information vulnerable? How is it protected or not protected?

Is it properly protected?

4. Assess the Risk Is the risk great enough to do something about the threat? How would the loss of sensitive data affect your operations? What would be the cost of losing sensitive information?

5. Develop and Apply Countermeasures What countermeasures will block access to your information?

Page | 8

C/S&TD Contractor Security Orientation Guide V 1.3

Personnel Security

Although there are many tasks associated with Personal Security, some basic tasks include:

Conduct background investigations of federal and contract employees to determine integrity and trustworthiness Verify security clearances for DHS employees and contractors Process incoming and outgoing Perm-Certs Provide continuous evaluation reporting guidance

Does the screen below look familiar? It should. If you’re reading this guide, it was likely one of your first encounters with the Personnel Security information collection process.

Page | 9

C/S&TD Contractor Security Orientation Guide V 1.3

Along with your initial inquiry, you may be required to report additional information, to include, but not limited to:

• unofficial foreign travel / contacts

• criminal conduct / activity

• marital status, legally recognized civil union, domestic partner, cohabitant(s), and immediate family members

• adverse information

What is Adverse Information?

It is any information that may reflect unfavorably on the trustworthiness or reliability of an individual and suggests that their ability to safeguard classified information may be impaired. Policy requires clearance holders to report adverse information immediately.

If you hold a National Security position, then you are required to self-report any derogatory activity on a good-faith basis. However, a person determined to conceal negative behavior may not self-report and therefore conceal the negative behavior until their next Periodic Reinvestigation (PR).

Continuous Evaluation addresses this by conducting the same sorts of automated and unannounced records checks you agreed to as part of your original investigation, on a recurring basis. You will still be required to report certain categories of life events, but the automated records checks will drastically shorten the interval between the occurrence and reporting of an incident.

Continuous Evaluation Continuous Evaluation (CE) is a mandated personnel security process, implemented by DHS Personnel Security offices, to review personnel who have been determined to be eligible for access to classified information or hold a sensitive position. CE is part of the security clearance reform effort to modernize personnel security processes and increase the timeliness of information between the cycles of periodic reinvestigation. Current PR cycles run approximately every five years. CE leverages automated, unannounced record checks on a recurring basis and applies standardized business rules to identify security-relevant information that assists in the assessment of an individual's on-going eligibility for access to classified information or eligibility to hold a sensitive position. The types of records collected through CE are the same as those currently checked for personnel security purposes (to include: credit, criminal activity, commercial, eligibility, foreign travel, suspicious financial activity, and terrorism).

CE shall supplement, not replace, traditional periodic reinvestigations.

NOTE: If you have signed the SF-86, Questionnaire for National Security Positions, dated 2010 or later, you have already given your consent for CE and the process will appear seamless.

Page | 10

C/S&TD Contractor Security Orientation Guide V 1.3

Physical Security

Physical Security encompasses the full range of protective measures designed to safeguard personnel and prevent unauthorized access to, and the loss, theft, destruction, sabotage, or compromise of equipment, facilities, material, and information.

Physical Security controls typically include, but are not limited to:

Security Personnel Supporting infrastructure Contingency and emergency support Access Control (keycards, doors/locks, readers, etc.)

Intrusion Detection/Surveillance Systems Operational Security Procedures

Most importantly, the continued development and engagement of your security mindset is key to the success of our physical security mission. With your help and dedication, we can all provide a safer and more secure environment.

Your role and responsibility start with strict adherence to established security policies. Additionally, you can stop unauthorized access and help maintain a secure workplace by:

Wearing your access badge appropriately Reporting lock or door failures Securing your workspace/terminal Challenging unknown/non-badged individuals Reporting suspicious people, packages, and activities Preventing tailgating and/or piggybacking

Page | 11

C/S&TD Contractor Security Orientation Guide V 1.3

Always wear your badge/PIV properly. Badges/PIVs should be visibly worn between the neck and waist. Protect your badge against theft or duplication and put it away when not in use.

Leaving your badge/PIV in plain view could provide sufficient information to anyone able to use

it. Challenge unknown and/or non-badged persons. Simply ask them if they have their badge/PIV or whether they are being escorted in unauthorized spaces. If you are dissatisfied with the response given, report them immediately to security. Lastly, remember to lock your computer and remove your badge/PIV when leaving your workspace.

Another important part of your responsibilities is to be able to identify the presence of suspicious packages and mail items.

If you believe you may have encountered a suspicious package, here are some things to look for:

Strange/no return address Restrictive markings Excessive postage / tape Leaks, stains, powders, or protruding materials Package does not contain signs of having been screened by the DHS Consolidated Remote Delivery Site (CRDS)

Depending on your region, items mailed to DHS will likely be processed through a Consolidated Remote Delivery Site (CRDS) before arriving at your location. All mail and packages are opened, inspected, and processed for safety prior to delivery. You will know that your mail has been inspected because there will be a visible stamp showing material has been x-rayed or inspected, and it will be resealed with a special DHS security tape. As a reminder, personal mail should never be sent or delivered directly to DHS.

If your region is supported by a local CRDS and you receive a package or envelope that does not have these indicators, do not open it; notify your supervisor, security, or call 911.

In the unfortunate event that you encounter a suspicious package, it is recommended that you follow the emergency checklist provided by your security office.

Some of the guidance that will be provided includes:

Do not move or disturb the package Clear immediate area of other personnel Instruct employees to wash hands and other exposed skin Direct employees to designated area away from package Cordon/block off the immediate area Shut down ventilation system if possible

Remember: Upon discovery of a suspicious package or mail item, try to remain calm, do not attempt to open it, and avoid any additional movement of the package or item. Should you open a mail item and discover a suspicious substance (i.e. powder, gel, etc.), attempt to cover the package and/or contents with a solid item, such as a file folder or piece of paper (if reasonable to do so). Do not attempt to clean up any substance(s) that may have emitted from the package.

Page | 12

C/S&TD Contractor Security Orientation Guide V 1.3

Bomb Threats Bomb threats can be delivered in a variety of ways: a direct call to you, via third party, in writing, or by a recording; of these the telephone is probably still the most common. We suggest that you obtain a copy of the DHS bomb threat checklist and keep it near your telephone. It will aid you in gathering information if you ever receive a bomb threat call.

The most important thing to consider is to remain calm so you can gather information that may be useful for an investigation. Then, notify security as soon as it is safe and reasonable to do so.

Try to complete the bomb threat checklist Note the date and time the call came in and the phone number it came in on.

Listen for background noises, voice accents and anything that may be of assistance to investigators.

Try to keep the caller on the line; the longer they can be kept on the line, the better the possibility of a trace.

If possible, get the attention of a co-worker and have them contact security while you have the caller on the line.

Don't hang up the phone; even if they hang up. Keeping the line open will prevent other calls from coming in on that line which may prove crucial in tracing the call

Tailgating and Piggybacking Another security concern is when one or more persons gain access to secure areas through tailgating or piggybacking activities. Tailgating and piggybacking are common activities that occur in many work environments. However, it is important to consider that either activity could create a vulnerability that may potentially involve giving restricted access to an unauthorized individual.

Tailgating is when a person follows an authorized person into a secure or restricted area without the knowledge/consent of the authorized person. Once common way that people attempt tailgating is through the use of social engineering techniques, essentially “tricking” an individual into granting them unauthorized access.

Piggybacking is when a person follows an authorized person into a secure or restricted area with the knowledge/consent of the authorized person. One example of an accepted practice of piggybacking would be when an employee with access accepts the liability of holding a door open for another employee that has access.

The DHS Office of the Chief Security Officer wants to remind you that you should review and understand the related polices and cultures that govern your work environment.

content

Page | 13

C/S&TD Contractor Security Orientation Guide V 1.3

Information Security content

Next, we will discuss Information Security and how it relates to you. As a DHS contractor, you may encounter classified and unclassified information regarding government operations, activities, capabilities, mission, and privacy information. There are two types of sensitive information processed and stored within DHS.

The first type of information is known as Sensitive But Unclassified Information (SBU). The other type is National Security Information (NSI), also referred to as Classified Information. For the purpose of this training, we will only discuss SBU, because it pertains to everyone, clearance holders and non-clearance holders alike.

Unauthorized disclosure is defined as communication or physical transfer of information such as speaking, paper documents, computer media, and any other means of transferring or communicating information to an unauthorized recipient. Unauthorized disclosures can be intentional or inadvertent, but either way, they can have serious repercussions to the Federal Government. Unauthorized disclosures can damage our national security, compromise government operations and intelligence community sources and methods, have potential loss of life, have financial cost, and undermines the public's confidence and trust. There are four types of unauthorized disclosures: espionage, improper safeguarding, leaks and spills.

The DHS Information Security Office's mission is to provide a secure and trusted computing environment based on risk management principles to enable the Department to effectively share information. Information security is an essential business function, critical to enabling DHS to conduct its operations and deliver service to the public.

Most information security systems are comprised of policies, procedures, and requirements designed to protect Sensitive But Unclassified (SBU) and classified National Security Information (NSI) from unauthorized disclosure. It is important to remember that systems alone are not the answer to maintaining information security. It takes a concerted effort of everyone involved to ensure the safety and security of sensitive information.

As a DHS contractor, your mission is to protect information from unauthorized disclosure by:

1. Reading and following security policies and procedures for the information you have been granted access to DHS Management Directive 11042.1; Safeguarding Sensitive but Unclassified (FOUO) Information DHS Handbook for Safeguarding Sensitive Personally Identifiable Information Instruction 121-01-011; The DHS Administrative Security Program

2. Acknowledging and adhering to the “Need-to-Know” principal

Page | 14

C/S&TD Contractor Security Orientation Guide V 1.3

Sensitive But Unclassified Information As previously mentioned, in addition to National Security information (NSI), DHS uses information that requires protection from unauthorized disclosure. This information falls under the Sensitive But Unclassified (SBU) information umbrella; it is information that does not meet the requirements of the Executive Order for classification but is still sensitive in nature and requires protection against unauthorized disclosure.

Currently within the government there are over 100 different categories of information in this category. A few examples of SBU include: Law Enforcement Sensitive (LES), Official Use Only (OUO), and Controlled Unclassified Information (CUI).

The Department of Homeland Security uses For Official Use Only (FOUO) to identify SBU information not otherwise categorized by statute or regulation. FOUO is the term used within DHS to identify unclassified information of a sensitive nature that is not otherwise categorized by statute or regulation and the unauthorized disclosure of which could adversely impact a person's privacy or welfare, the conduct of Federal programs, or other programs or operations essential to the national interest.

Protected Critical Infrastructure Information (PCII), Sensitive Security Information (SSI), and Chemical-terrorism Vulnerability Information (CVI), are governed by statute and regulation and therefore are not considered or treated as FOUO. PCII, SSI, and CVI are identified, handled, and safeguarded in accordance with separate guidance issued by the responsible program office.

For Official Use Only information retains the FOUO designation until determined otherwise by someone with jurisdiction over the information. Declassification markings are not applicable, because the information is not classified. Any DHS employee can designate or mark information as FOUO if it falls within the (11) categories of Section 6.C.1 of DHS MD 11042.1, and not otherwise governed by other statute or regulation.

The Information Security Oversight Office has issued 32 CFR 2002, Controlled Unclassified Information (CUI). While many details for DHS have yet to be determined, here are a few key things to keep in mind:

1. CUI will have a phased-in approach.

2. Markings such as "FOUO" will eventually disappear.

3. Everything that requires protection will be protected under CUI.

Because some categories of information do not translate cleanly from FOUO to CUI, OCSO is working with the Office of General Counsel to ensure that key areas, particularly those dealing with law enforcement information, continue to receive protection when CUI takes effect.

Page | 15

C/S&TD Contractor Security Orientation Guide V 1.3

Because FOUO is not classified, no clearance is needed for access. However, what is required is the "Need-to-Know." According to DHS MD 11042.1, "Need-to-Know" is a determination made by an authorized holder of the information that a prospective recipient requires access to the information in order to perform or assist in a lawful and authorized governmental function.

Marking FOUO FOUO marking isn't complicated, but it must be done correctly. When marking a document, prominently mark bottom of the front cover, first page, title page, back cover and each page containing FOUO with "For Official Use Only".

The same marking requirements apply to information presented in electronic formats, such as Email. Some documents may require further markings for caveats such as: "Law Enforcement Sensitive" to alert reading of additional restrictions.

Page | 16

C/S&TD Contractor Security Orientation Guide V 1.3

Safeguarding FOUO FOUO information must be secured in a locked file cabinet or desk drawer. A locked office is sufficient only when you can be certain that individuals without the proper "need-to-know" cannot access the office; this includes after-hours cleaning and building management.

Some other safeguarding considerations include:

When discussing FOUO be aware of others who may overhear your conversation. Do not post FOUO information on public websites, blog sites, etc.

Although it is not required, use a secure phone or fax (if available) to safeguard the information. When faxing FOUO, contact the recipient to ensure that they are available to receive the fax when it comes in; confirm the fax number before faxing and once the fax has been sent confirm that the intended recipient did receive the document. When expecting a fax with FOUO information, do not allow it to remain on the fax machine for others to view.

Do not store FOUO information with classified information unless there is a direct correlation between the FOUO and classified information.

Properly destroy FOUO information before disposal (degauss, shred, etc.).

FOUO information that are protected by law cannot be shared with spouses or friends, as well as media outlets and/or the general public.

Lastly, since part of your responsibility includes protecting information from unauthorized disclosure, make sure you read and follow the security policies and procedures for the information you have been granted access to. Familiarizing yourself with the specific polices and guidance that govern how sensitive and classified information is handled in your work environment will greatly improve your ability to identify, avoid and report potential unauthorized disclosures.

Page | 17

C/S&TD Contractor Security Orientation Guide V 1.3

Congratulations! You have successfully completed the Security Orientation Briefing For DHS Contractors. If you have any other questions or concerns about the information in this presentation, consult your security officer.

During this presentation, we discussed the following:

The DHS mission and what/who is protected Types of threats How OPSEC applies to the DHS mission Your role in Personnel Security Your role in Physical Security Your role in Information Security "Need-to-Know" and "unauthorized disclosure" principles How to properly identify, mark and handle Sensitive But Unclassified information.

By completing this Security Orientation Briefing For DHS Contractors, you have met the initial requirements for your DHS security training. Be sure to check with your organization or security office for additional security training and reporting requirements.

For more information contact:

DHS Office of Security Customer Service Center

(202) 447-5010 OfficeofSecurity@dhs.gov

Security Training Branch | Office of the Chief Security Officer

COMPLETION OF DHS SECURITY ORIENTATION TRAINING

Acknowledgement Statement

I hereby acknowledge that I have reviewed the Security Orientation training provided to me (PDF read-through) and will contact the Security Training Branch with any questions.

Printed Name:

(First M. Last)

Last Four of SSN:

Date:

Signtature:

File details come from the government source that posted it. Updated .