STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Position of Trust - Knowledge of Responsibility to Self Report Derogatory Information

DISA Rule

SV-42673r3_rule

Vulnerability Number

V-32336

Group Title

Position of Trust - Knowledge of Responsibility to Report Derogatory Information

Rule Version

PE-01.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Ensure that Individuals are familiar with pertinent personnel security regulations, such as DoD 5200.2-R and are aware of standards of conduct required of persons holding positions of trust, including (and especially) the requirement to report derogatory information to their local security manager.

Compliance can be validated by:

1. Ensuring that organizational personnel security initial and annual refresher training records include the topic of standards of conduct for individuals holding a security clearance in addition to covering each individual’s responsibility to self-report derogatory information to their security manager.

2. Conducting a general survey of multiple employees to ascertain their familiarity with personal responsibilities while holding a security clearance.

Check Contents

Check to ensure that Individuals are familiar with pertinent personnel security regulations, such as DoD 5200.2-R and are aware of standards of conduct required of persons holding positions of trust, including (and especially) the requirement to report derogatory information to their local security manager.

This check can be validated by:

1. Checking organizational personnel security initial and annual refresher training records to ensure that the topic of standards of conduct for individuals holding a security clearance and each individual’s responsibility to self- report derogatory information to their security manager are covered.

2. Conducting a general survey of multiple employees to determine if they understand the standards of conduct and their responsibility to self-report.

The results should be based on a compilation of survey results rather than a single instance of an employee who is not familiar with personal responsibilities (standards and self-reporting).

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments AND is applicable to a field/mobile environment.

Vulnerability Number

V-32336

Documentable

False

Rule Version

PE-01.03.01

Severity Override Guidance

Check to ensure that Individuals are familiar with pertinent personnel security regulations, such as DoD 5200.2-R and are aware of standards of conduct required of persons holding positions of trust, including (and especially) the requirement to report derogatory information to their local security manager.

This check can be validated by:

1. Checking organizational personnel security initial and annual refresher training records to ensure that the topic of standards of conduct for individuals holding a security clearance and each individual’s responsibility to self- report derogatory information to their security manager are covered.

2. Conducting a general survey of multiple employees to determine if they understand the standards of conduct and their responsibility to self-report.

The results should be based on a compilation of survey results rather than a single instance of an employee who is not familiar with personal responsibilities (standards and self-reporting).

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments AND is applicable to a field/mobile environment.

Check Content Reference

M

Target Key

2506

Comments