Skip to main content

Security Operations

DISS Administration: A Practical Guide for FSOs and Security Administrators

DISS is the system of record for personnel security and the daily lifeline of cleared contracting. If an employee's status is wrong in DISS, they cannot access classified, enter a government facility, or bill the contract. Mastering DISS is a core FSO competency, not a clerical task.

DISS Architecture and Access

JVS (Joint Verification System) is where FSOs work — view eligibility, grant access, submit VARs, manage the cleared population.

CATS (Case Adjudication Tracking System) is for government adjudicators; JVS pulls from it.

FSO access requires a PKI cert (ECA token or CAC), a DCSA-provisioned account, and login at least every 30 days to prevent deactivation.

Crossover: Establishing an Owning Relationship

Search by SSN. Verify active eligibility and current investigation. Establish "Owning" relationship for direct W2 employees. Grant access at or below eligibility level. Ensure SF-312 NdA is recorded.

Common pitfall: failing to terminate the owning relationship when someone leaves. A terminated employee committing a violation while still "owned" by your SMO creates direct liability.

Initiating a New Investigation

Establish Owning relationship. Initiate Investigation at appropriate tier (T3 for Secret, T5 for Top Secret).

Employee gets an eApp invite to complete SF-86. FSO must review for completeness before releasing to DCSA — incomplete forms reset the timeline.

Capture fingerprints via SWFT within 14 days of release.

Visit Authorization Requests

Enter the host SMO code, dates (VARs valid up to one year), purpose, and subjects.

Pitfall: last-minute submission. The receiving SMO must manually acknowledge — submit the morning of and your employee is denied entry at the gate.

Reporting Adverse Information

Arrests, financial distress (bankruptcy, garnishment), unreported foreign travel or contacts, substance abuse, security violations.

Create Incident Report, document facts objectively (no opinion), submit to DCSA VROC.

Failing to report to "protect" an employee is a severe NISPOM violation. The FSO's loyalty is to national security, not the individual.

Continuous Evaluation

DoD has largely retired the 5/10-year periodic reinvestigation. The cleared workforce is enrolled in CE — automated monitoring of credit, criminal, and travel databases.

When CE flags an issue, VROC sends an RFI or CE Alert through DISS. The FSO responds promptly, often interviewing the employee for context.

Foreign National Visitors and Self-Inspection

Foreign National Visit Requests submitted via DISS, approved by the government customer before the visit, with designated US Person escort accountable for the visit duration.

Annual self-inspection audits DISS records: active clearances vs. actual employment, investigation currency, pending action backlog, incident-report closure.

Outage Contingency

DISS is a government system and it goes down. Develop written contingency procedures for alternate clearance verification, visit access, and post-outage data entry.

Many experienced FSOs maintain a secure offline log of clearance level, investigation date, and access grants for routine verification when DISS is unavailable.

Want help putting this into practice?

Desra Secure provides experienced FSOs and security administrators who run DISS as a discipline, not a clerical task.

This guide is provided for general informational purposes only and does not constitute legal, accounting, or compliance advice. Specific obligations depend on your contracts and your environment.