STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Periodic Reinvestigations - Submitted in a Timely Manner based Upon Position Sensitivity and Type of Investigation Required

DISA Rule

SV-42745r3_rule

Vulnerability Number

V-32408

Group Title

Periodic Reinvestigations

Rule Version

PE-06.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Ensure there are local procedures for requesting reinvestigations AND that PRs have been submitted on all expiring investigations within required timeframes.

NOTE 1: Generally PRs should be requested about 6-months prior to the 5-year (SSBI/ T5R – Tier 5 Reinvestigation) and 5-year (Secret Periodic Review /T3R - Tier 3 Reinvestigation) anniversary of the previous investigation.

NOTE 2: Periodic reviews for secret security clearances and/or ADP/IT-2 positions of trust have been reduced from 10-year to 5-year cycles in the new DoD Personnel Security Manual.

NOTE 3: Other temporary changes (usually a slight increase to the PR timeframe) based on investigation backlogs may occur and adjustments in the submission timeframe will need to be made. Organizations should maintain documentation from OPM or other authoritative source to support any deviations from the regulatory standards for periodic reviews.

Check Contents

Check procedures for requesting reinvestigations and obtain documentation (proof) that PRs have been submitted on expiring investigations. Any PRs discovered that are not submitted prior to the respective expiration date will result in a finding.

NOTE 1: Generally PRs should be requested about 6-months prior to the 5-year (for SSBI/ T5R – Tier 5 Reinvestigation) and 5-year (for Secret PR/ T3R - Tier 3 Reinvestigation) anniversary of the previous investigation.

NOTE 2: Periodic reviews for secret security clearances and/or ADP/IT-2 positions of trust have been reduced from 10-year to 5-year cycles in the new DoD Personnel Security Manual.

NOTE 3: Other temporary changes (usually a slight increase to the PR timeframe) based on investigation backlogs may occur. Reviewers should base evaluations of compliance on DoD or CC/S/A requirements existing at the time of a site review.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments and is also applicable to a field/mobile environment.

Vulnerability Number

V-32408

Documentable

False

Rule Version

PE-06.03.01

Severity Override Guidance

Check procedures for requesting reinvestigations and obtain documentation (proof) that PRs have been submitted on expiring investigations. Any PRs discovered that are not submitted prior to the respective expiration date will result in a finding.

NOTE 1: Generally PRs should be requested about 6-months prior to the 5-year (for SSBI/ T5R – Tier 5 Reinvestigation) and 5-year (for Secret PR/ T3R - Tier 3 Reinvestigation) anniversary of the previous investigation.

NOTE 2: Periodic reviews for secret security clearances and/or ADP/IT-2 positions of trust have been reduced from 10-year to 5-year cycles in the new DoD Personnel Security Manual.

NOTE 3: Other temporary changes (usually a slight increase to the PR timeframe) based on investigation backlogs may occur. Reviewers should base evaluations of compliance on DoD or CC/S/A requirements existing at the time of a site review.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments and is also applicable to a field/mobile environment.

Check Content Reference

M

Potential Impact

Related STIG rules:
PE-02-02-01 - Position Sensitivity - Based on Security Clearance and/or Information Technology (IT) Systems Access Level or Responsibility for Security Oversight on Assigned Information Systems (IS)
PE-03.02.01 - Validation Procedures for Security Clearance Issuance (Classified Systems and/or Physical Access Granted)
PE-04.02.01 - Information Assurance (IA) Positions of Trust - Identification of Positions or Duties with Privileged Access to Information Systems or Responsibility for Security Oversight of Information Systems
PE-05.02.01 - Background Investigations

Target Key

2506

Comments