SAPPC CERTIFICATION EXAM STUDY GUIDE
QUESTIONS AND ANSWERS COMPLETE AND
VERIFIED.
List five responsibilities of the Government SAP Security Officer/Contractor
Program Security Officer (GSSO/CPSO)?
• Possess a personnel clearance and Program access at least equal to the highest
level of
• Program classified information involved.
• Provide security administration and management for his/her organization.
• Ensure personnel processed for access to a SAP meet the prerequisite personnel
clearance and/or investigative requirements specified.
• Ensure adequate secure storage and work spaces.
• Ensure strict adherence to the provisions of the NISPOM, its supplement, and the
Overprint.
• When required, establish and oversee a classified material control program for
each SAP.
• When required, conduct an annual inventory of accountable classified material.
• When required, establish a SAPF.
• Establish and oversee a visitor control program.
• Monitor reproduction and/or duplication and destruction capability of SAP
information
• Ensure adherence to special communications capabilities within the SAPF.
• Provide for initial Program indoctrination of employees after their access is
approved;
rebrief and debrief personnel as required.
• Establish and oversee specialized procedures for the transmission of SAP material
to and
from Program elements.
• When required, ensure contractual specific security requirements such as TEMPEST
Automated Information System (AIS), and Operations Security (OPSEC) are
accomplished.
• Establish security training and briefings specifically tailored to the unique
requirements
of the SAP.
What is the definition of Critical Program Information in DoD?
,Elements or components of a Research, Development, and
Acquisition (RDA) program that, if compromised, could
cause significant degradation in mission effectiveness;
shorten the expected combat-effective life of the system;
reduce technological advantage; significantly alter program direction; or enable an
adversary to defeat, counter, copy, or reverse engineer the technology or
capability. Includes information about applications, capabilities, processes and end-
items. Includes elements or components critical to a military system or network
mission effectiveness. Includes technology that would reduce the U.S. technological
advantage if it came under foreign control.
How does lack of attention to the concept of compilation introduce risks to DoD
assets? (It can cause)
• Unauthorized disclosure
• Misclassification
• Security violation
• Improper safeguarding
• Improper dissemination
• Improper handling
• Improper destruction
List three transmission and transportation requirements that help manage risks
to DoD assets?
• Safeguarding
• Briefings
• Documentation
• Personal control
• Utilizing proper methods of transmission/transportation based on classification
level
• Intended recipient(s) have proper clearance/eligibility and need to know (or
access)
• Capability to properly store classified
information
List three types of security briefings that help manage risks to DoD assets?
• Initial Orientation
• Annual Refresher
• Threat Awareness
• Foreign Travel
, • Special Training Requirements
• Derivative Classification
• Original Classification Authority (OCA)
• Declassification Authority
• Debriefings
• Termination briefing
List three disposal and destruction methods used to effectively manage risks to
DoD classified information?
• Cross-cut shredding
• Burning/ Incinerating
• Pulverizing
• Disintegrating
• Mutilating
• Degaussing
• Chemical decomposition
• Special burn
• Wet pulping
• Overwriting
• Sanding
• Physical destruction
List three types of safeguarding procedures for classified information?
• Proper storage
• Proper handling
• Approved disposition
• Proper transmission/transportation methods
• Receipt use, when required
• Forced entry protection
• Dissemination
• Physical security measures
• Technical, administrative, and personnel control measures (deleted access control
as these measures constitute access control)
• Develop emergency plan
Describe the security professional's role in handling a security incident?
• Secure
• Safeguard
• Report
QUESTIONS AND ANSWERS COMPLETE AND
VERIFIED.
List five responsibilities of the Government SAP Security Officer/Contractor
Program Security Officer (GSSO/CPSO)?
• Possess a personnel clearance and Program access at least equal to the highest
level of
• Program classified information involved.
• Provide security administration and management for his/her organization.
• Ensure personnel processed for access to a SAP meet the prerequisite personnel
clearance and/or investigative requirements specified.
• Ensure adequate secure storage and work spaces.
• Ensure strict adherence to the provisions of the NISPOM, its supplement, and the
Overprint.
• When required, establish and oversee a classified material control program for
each SAP.
• When required, conduct an annual inventory of accountable classified material.
• When required, establish a SAPF.
• Establish and oversee a visitor control program.
• Monitor reproduction and/or duplication and destruction capability of SAP
information
• Ensure adherence to special communications capabilities within the SAPF.
• Provide for initial Program indoctrination of employees after their access is
approved;
rebrief and debrief personnel as required.
• Establish and oversee specialized procedures for the transmission of SAP material
to and
from Program elements.
• When required, ensure contractual specific security requirements such as TEMPEST
Automated Information System (AIS), and Operations Security (OPSEC) are
accomplished.
• Establish security training and briefings specifically tailored to the unique
requirements
of the SAP.
What is the definition of Critical Program Information in DoD?
,Elements or components of a Research, Development, and
Acquisition (RDA) program that, if compromised, could
cause significant degradation in mission effectiveness;
shorten the expected combat-effective life of the system;
reduce technological advantage; significantly alter program direction; or enable an
adversary to defeat, counter, copy, or reverse engineer the technology or
capability. Includes information about applications, capabilities, processes and end-
items. Includes elements or components critical to a military system or network
mission effectiveness. Includes technology that would reduce the U.S. technological
advantage if it came under foreign control.
How does lack of attention to the concept of compilation introduce risks to DoD
assets? (It can cause)
• Unauthorized disclosure
• Misclassification
• Security violation
• Improper safeguarding
• Improper dissemination
• Improper handling
• Improper destruction
List three transmission and transportation requirements that help manage risks
to DoD assets?
• Safeguarding
• Briefings
• Documentation
• Personal control
• Utilizing proper methods of transmission/transportation based on classification
level
• Intended recipient(s) have proper clearance/eligibility and need to know (or
access)
• Capability to properly store classified
information
List three types of security briefings that help manage risks to DoD assets?
• Initial Orientation
• Annual Refresher
• Threat Awareness
• Foreign Travel
, • Special Training Requirements
• Derivative Classification
• Original Classification Authority (OCA)
• Declassification Authority
• Debriefings
• Termination briefing
List three disposal and destruction methods used to effectively manage risks to
DoD classified information?
• Cross-cut shredding
• Burning/ Incinerating
• Pulverizing
• Disintegrating
• Mutilating
• Degaussing
• Chemical decomposition
• Special burn
• Wet pulping
• Overwriting
• Sanding
• Physical destruction
List three types of safeguarding procedures for classified information?
• Proper storage
• Proper handling
• Approved disposition
• Proper transmission/transportation methods
• Receipt use, when required
• Forced entry protection
• Dissemination
• Physical security measures
• Technical, administrative, and personnel control measures (deleted access control
as these measures constitute access control)
• Develop emergency plan
Describe the security professional's role in handling a security incident?
• Secure
• Safeguard
• Report