Skip to main content
Category: Personnel Vetting & Clearances

Defense Information System for Security

Also known as: DISS, DISS JVS
Simply put

The Defense Information System for Security (DISS) is a Department of Defense system used to manage security clearance and related records for DoD military personnel, civilian employees, and contractors. It generally serves as the central system where personnel security, suitability, and credentialing information is recorded and tracked. According to the evidence, it is the current system used to track security clearance records for the vast majority of individuals in the eligible population.

Formal definition

DISS, managed within the Defense Counterintelligence and Security Agency (DCSA) environment, functions as the enterprise-wide solution and system of record for personnel security, suitability, fitness, and credentialing management across DoD military, civilian, and contractor populations. It incorporates components such as the Joint Verification System (JVS), within which defined roles, permissions, and functions support subject management and related security administration workflows. This entry addresses DISS as a personnel security records and management system; it does not cover information system authorization, RMF processes, or the specific procedural steps, access provisioning rules, or eligibility determination criteria, which practitioners should verify against current DCSA guidance and training materials.

Why it matters

DISS functions as the Department of Defense system of record for personnel security, suitability, fitness, and credentialing management across military, civilian, and contractor populations. Because it serves as the authoritative repository for clearance eligibility and related determinations, the accuracy and currency of the records it holds directly affect whether individuals can access classified information or occupy sensitive positions. For organizations operating under DoD security requirements, DISS is generally the operational point where clearance status is verified, updated, and administered, making it central to day-to-day personnel security operations.

According to the evidence, DISS is the current system used to track security clearance records for the vast majority of individuals in the eligible population. This scope means that errors, delays, or improperly maintained records in DISS can have significant downstream consequences, including affecting an individual's ability to work on cleared contracts or to be onboarded into a sensitive role. Facility Security Officers and other security personnel rely on DISS records being properly maintained, which places a premium on trained, authorized use of the system.

A common point of confusion worth flagging is that DISS is a personnel security records and management system, not an information system authorization tool. It does not perform Risk Management Framework (RMF) processes, issue Authorities to Operate, or make eligibility determinations by itself. The specific eligibility criteria, access provisioning rules, and procedural steps are governed by DCSA guidance and training materials that practitioners must verify against current authoritative sources rather than infer from the system's function alone.

Who it's relevant to

Facility Security Officers and Security Administrators
Personnel responsible for administering clearance and suitability records generally interact with DISS JVS to manage subjects and maintain records. Their assigned roles and permissions within the system determine which functions they can perform, and they should rely on current DCSA training and guidance for the specific procedural steps rather than assumptions about system behavior.
Government Contractors Operating Under DoD Security Requirements
Contractor organizations whose personnel require security clearances are affected by how their clearance eligibility and related records are recorded and tracked in DISS, since the evidence indicates it tracks records for the vast majority of the eligible population. Contractors should confirm access, record accuracy, and process specifics against current DCSA guidance.
DoD Military and Civilian Personnel
Individuals in the DoD workforce whose personnel security, suitability, fitness, or credentialing status is maintained in DISS have a direct interest in the accuracy of those records, as they can affect access to classified information and sensitive positions. Procedures for reviewing one's own record are governed by DCSA and should be verified against current authoritative sources.
Personnel Security and Compliance Officers
Those overseeing personnel security programs rely on DISS as the DoD system of record for eligibility and related determinations. They should note that DISS supports personnel security records management and does not address information system authorization, RMF processes, or eligibility determination criteria, which are governed separately.

Inside DISS

Personnel Security Clearance Records
DISS is used to record and track personnel security clearance eligibility determinations, access grants, and related adjudicative information for individuals under the purview of DoD and participating organizations. Specific data elements and retention practices should be verified against current DoD guidance.
Subject Management and Visit Requests
The system generally supports management of cleared personnel (subjects) by their servicing security offices, including establishing and maintaining a relationship of custody, and processing visit access requests. Confirm current functionality against official DoD documentation.
Continuous Vetting and Investigation Status
DISS is commonly used to reflect the status of background investigations and, where applicable, enrollment in continuous vetting or continuous evaluation programs. The precise integration with investigative service providers should be confirmed with current authoritative sources.
Role-Based Access for Security Professionals
Access to DISS is generally provisioned to security officers, facility security officers, and other authorized personnel based on assigned roles and need-to-know. Account provisioning, training, and hierarchy requirements are governed by DoD policy that the reader should verify.

Common questions

Answers to the questions practitioners most commonly ask about DISS.

Is DISS the same system as JPAS, or does it work the same way?
No. DISS replaced the Joint Personnel Adjudication System (JPAS) as the system of record for personnel security, and the two should not be treated as interchangeable. JPAS has been retired, and legacy processes, screens, and terminology from JPAS do not necessarily map one-to-one onto DISS. Users familiar with JPAS should confirm current DISS functionality and procedures against official Defense Counterintelligence and Security Agency (DCSA) guidance rather than assuming continuity of behavior.
Does having a record in DISS mean an individual holds a current, active security clearance?
Not by itself. DISS is a system of record that reflects eligibility determinations, access, and related personnel security information, but a record's presence does not on its own establish that access is currently active or that eligibility remains valid. Eligibility, access, and continuous vetting status are distinct concepts within personnel security, and each must be confirmed against the applicable record and current adjudicative status. Users should verify the specific status reflected in DISS rather than inferring an active clearance from the existence of a record.
Who is authorized to access DISS and how is that access typically established?
Access to DISS is generally limited to authorized personnel security roles, such as designated security officers acting on behalf of a cleared entity, subject to account provisioning and role-based permissions. Provisioning typically involves a formal request and account management process governed by DCSA. Because specific eligibility for an account, required training, and role definitions can change, organizations should confirm current onboarding requirements and role assignments against official DCSA instructions before requesting or granting access.
How does DISS relate to the broader personnel vetting and continuous vetting process?
DISS functions as a system of record that supports personnel security operations, and it interacts with vetting and continuous vetting activities within the federal personnel security enterprise. It is not the whole of the vetting process; adjudication, investigation, and continuous vetting involve additional authorities and systems. Users should treat DISS as one component of the personnel security ecosystem and confirm how it interfaces with current vetting workflows through authoritative DCSA sources.
What responsibilities do security officers have when maintaining records in DISS?
Security officers using DISS are generally responsible for maintaining accurate personnel security records, reflecting access relationships appropriately, and taking required actions consistent with their assigned roles. The precise obligations, timelines, and reporting responsibilities depend on applicable policy and the organization's role. Because these responsibilities are governed by current DCSA and DoD personnel security guidance and can be updated, officers should verify specific duties and timeframes against the current authoritative instructions rather than relying on prior practice.
Should DISS be relied upon as the sole source for confirming a person's eligibility before granting access to information?
DISS is a system of record for personnel security information, but reliance on it for an access decision should follow current policy and role-appropriate procedures, including confirming the specific eligibility and access status reflected. Access decisions may also involve additional requirements beyond what a single record indicates. Users should confirm the applicable verification procedures and any supplementary requirements against current DCSA and DoD guidance rather than assuming DISS alone satisfies all preconditions for granting access.

Common misconceptions

DISS is a cybersecurity compliance or authorization system like the RMF-related tools (for example, eMASS).
DISS is oriented toward personnel security clearance and vetting management, not information system authorization under the Risk Management Framework. It should not be conflated with tools used to document control implementation, assessment, or an Authority to Operate (ATO); those are distinct functions maintained under different authorities.
A clearance eligibility record in DISS is equivalent to active access to classified information or to a system.
Clearance eligibility and actual access are distinct. Eligibility recorded in DISS does not by itself grant access; access generally also requires a need-to-know, an appropriate access grant, and, for information systems, separate authorization. Practitioners should not treat an eligibility determination as a standing access authorization.
Records in DISS are static once entered.
Clearance eligibility and vetting status are subject to change, including through continuous vetting, reinvestigation, or adverse information. Records should be treated as time-sensitive and dependent on ongoing monitoring rather than as permanent determinations. Verify current continuous vetting requirements against official DoD sources.

Best practices

Verify current DISS functionality, data elements, and procedural requirements against official DoD guidance rather than relying on legacy assumptions, as personnel security systems and their features evolve across revisions.
Maintain accurate subject relationships (custody) so that servicing security offices reflect current organizational responsibility, and promptly update when personnel change assignments or affiliations.
Enforce role-based access and need-to-know for DISS accounts, ensuring security personnel receive required training and that access is deprovisioned when roles change or end.
Treat clearance eligibility and actual access as separate determinations; confirm need-to-know and appropriate access grants before assuming an individual may access classified information or systems.
Track investigation and continuous vetting status as time-sensitive information, and act on adverse or changed information consistent with applicable DoD policy.
Confirm any interpretation involving classified system authorization or CUI handling against the governing authorities, since DISS addresses personnel security and does not substitute for RMF authorization or contractual cybersecurity obligations.