# 32 CFR § 2004.10: Responsibilities of the Director, Information Security Oversight Office (ISOO)

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10

## Section

- **Citation:** 32 CFR § 2004.10
- **Heading:** Responsibilities of the Director, Information Security Oversight Office (ISOO)
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** September 22, 2026
- **Source:** Publisher's official text
- **Location:** Title 32—National Defense > Subtitle B—Other Regulations Relating to National Defense > CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION > PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) > Subpart A—Implementation and Oversight

## Text

The Director, ISOO:
(a) Implements E.O. 12829, including ensuring that:
(1) The NISP operates as a single, integrated program across the executive branch of the Federal Government (i.e., such that agencies that release classified information to entities adhere to NISP principles);
(2) A responsible CSA oversees each entity's NISP implementation in accordance with § 2004.22;
(3) All agencies that contract for classified work include the Security Requirements clause, 48 CFR 52.204-2, from the Federal Acquisition Regulation (FAR), or an equivalent clause, in contracts that require access to classified information;
(4) Those agencies for which the Department of Defense (DoD) serves as the CSA or provides industrial security services have agreements with DoD defining the Secretary of Defense's responsibilities on behalf of their agency;
(5) Each CSA issues directions to entities under their cognizance that are consistent with the NISPOM insider threat guidance;
(6) CSAs share with each other, as lawful and appropriate, relevant information about entity employees that indicates an insider threat; and
(7) CSAs conduct ongoing analysis and adjudication of adverse or relevant information about entity employees that indicates an insider threat.
(b) Raises an issue to the National Security Council (NSC) for resolution if the EA's NISPOM coordination process cannot reach a consensus on NISPOM security standards (see § 2004.20(d)).

## Nearby sections

- [32 CFR § 2004.1 § 2004.1 Purpose and scope.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.1.md)
- [32 CFR § 2004.4 § 2004.4 Definitions that apply to this part.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.4.md)
- [32 CFR § 2004.10 § 2004.10 Responsibilities of the Director, Information Security Oversight Office (ISOO).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10.md)
- [32 CFR § 2004.11 § 2004.11 CSA and agency implementing regulations, internal rules, or guidelines.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.11.md)
- [32 CFR § 2004.12 § 2004.12 ISOO review of agency NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12.md)
- [32 CFR § 2004.20 § 2004.20 National Industrial Security Program Executive Agent and Operating Manual.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.20.md)
- [32 CFR § 2004.22 § 2004.22 Agency responsibilities.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.22.md)
- [32 CFR § 2004.24 § 2004.24 Insider threat program.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24.md)
- [32 CFR § 2004.26 § 2004.26 Reviews of entity NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.26.md)
- [32 CFR § 2004.28 § 2004.28 Cost reports.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28.md)
- [32 CFR § 2004.30 § 2004.30 Security classification requirements and guidance.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.30.md)
- [32 CFR § 2004.32 § 2004.32 Determining entity eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.32.md)
- [32 CFR § 2004.34 § 2004.34 Foreign ownership, control, or influence (FOCI).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.34.md)
- [32 CFR § 2004.36 § 2004.36 Determining entity employee eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.36.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10. Check the current official text before relying on it. Not legal advice.
