# 32 CFR § 2004.12: ISOO review of agency NISP implementation

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12

## Section

- **Citation:** 32 CFR § 2004.12
- **Heading:** ISOO review of agency NISP implementation
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** September 22, 2026
- **Source:** Publisher's official text
- **Location:** Title 32—National Defense > Subtitle B—Other Regulations Relating to National Defense > CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION > PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) > Subpart A—Implementation and Oversight

## Text

(a) ISOO fulfills its oversight role based, in part, on information received from NISP Policy Advisory Committee (NISPPAC) members, from on-site reviews that ISOO conducts under the authority of E.O. 12829, and from any submitted complaints and suggestions. ISOO reports findings to the responsible CSA or agency.
(b) ISOO reviews agency policies and guidelines to ensure consistency with NISP policies and procedures. ISOO may conduct reviews during routine oversight visits, when a problem or potential problem comes to ISOO's attention, or after a change in national policy that impacts agency policies and guidelines. ISOO provides the responsible agency with findings from these reviews.

## Nearby sections

- [32 CFR § 2004.1 § 2004.1 Purpose and scope.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.1.md)
- [32 CFR § 2004.4 § 2004.4 Definitions that apply to this part.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.4.md)
- [32 CFR § 2004.10 § 2004.10 Responsibilities of the Director, Information Security Oversight Office (ISOO).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10.md)
- [32 CFR § 2004.11 § 2004.11 CSA and agency implementing regulations, internal rules, or guidelines.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.11.md)
- [32 CFR § 2004.12 § 2004.12 ISOO review of agency NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12.md)
- [32 CFR § 2004.20 § 2004.20 National Industrial Security Program Executive Agent and Operating Manual.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.20.md)
- [32 CFR § 2004.22 § 2004.22 Agency responsibilities.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.22.md)
- [32 CFR § 2004.24 § 2004.24 Insider threat program.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24.md)
- [32 CFR § 2004.26 § 2004.26 Reviews of entity NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.26.md)
- [32 CFR § 2004.28 § 2004.28 Cost reports.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28.md)
- [32 CFR § 2004.30 § 2004.30 Security classification requirements and guidance.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.30.md)
- [32 CFR § 2004.32 § 2004.32 Determining entity eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.32.md)
- [32 CFR § 2004.34 § 2004.34 Foreign ownership, control, or influence (FOCI).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.34.md)
- [32 CFR § 2004.36 § 2004.36 Determining entity employee eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.36.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12. Check the current official text before relying on it. Not legal advice.
