Contractors should comply with DOD security training rules

Contractors who are serious about getting Defense Department contracts should make sure now that their employees who have information assurance roles meet the standards set by DOD Directive 8570.1, according to panelists who spoke this morning at an Information Technology Association of America event.

"There's not a downside to contractors being certified," said Phyllis Scott, president of training firm TTSC. Contracts will require it, and contractors who are already certified will have an immediate advantage, she said.

DOD approved the directive’s proposal to train and certify at least 80,000 department employees in four years in December 2005. The directive applies to every aspect of DOD -- military, agencies and contractors. It divides positions into technical or management, and applies different standards to each group, further subdivided by tiers.

Like DOD, contractors have to assess their organizations to identify the individuals and positions that should be working to meet the directive, Scott said. Assessing the positions is an important aspect, she added. Some positions are primarily concerned with information assurance and are obvious targets for training and certification.

Others are more peripherally connected to information assurance. In some cases, companies might need to give those jobs to employees with the necessary certifications. But in other cases, managers may be able to redefine a position to remove the information assurance component so they can fill it without worrying about whether the job candidates are properly certified, Scott said.

"Maybe we need to rethink how we're doing those positions," she said. "That's where we can really manage our workforce."

Shelley Morris, a vice president at training firm New Horizons, told managers to look for what's already there. Some employees may already have certifications -- or be working toward them -- that fulfill the directive. When managers find a need for training, much of it is available commercially and need not be custom-designed.

The required certifications include common ones such as the Computing Technology Industry Association's Network+ and the International Information Systems Security Certification Consortium's Certified Information Systems Security Professional. The directive includes a matrix showing which certifications apply to each position. DOD components can choose one of the approved certifications to serve as their standard for each category and level.

In many cases, employees may have some but not all of the training they need to earn the certifications. "If your folks have pieces and parts of the knowledge needed for certification, you can put together something custom" to fill in the gaps, she said.

Featured

  • Telecommunications
    Stock photo ID: 658810513 By asharkyu

    GSA extends EIS deadline to 2023

    Agencies are getting up to three more years on existing telecom contracts before having to shift to the $50 billion Enterprise Infrastructure Solutions vehicle.

  • Workforce
    Shutterstock image ID: 569172169 By Zenzen

    OMB looks to retrain feds to fill cyber needs

    The federal government is taking steps to fill high-demand, skills-gap positions in tech by retraining employees already working within agencies without a cyber or IT background.

  • Acquisition
    GSA Headquarters (Photo by Rena Schild/Shutterstock)

    GSA to consolidate multiple award schedules

    The General Services Administration plans to consolidate dozens of its buying schedules across product areas including IT and services to reduce duplication.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.