Military reference books and manuals (2009-2023, Volume 2) - page 17

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 2)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     15      16      17      18     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 2) - page 17

 

 

 

            UNCLASSIFIED 

Chapter 5 

                                                                                           SCIFs Outside the U.S and Under COM 

 

 

 

 

42 

UNCLASSIFIED 

I.

 

Secure Storage of Construction Material 

1.

 

Upon arrival, all inspected and securely shipped materials shall be placed in the SSA 

until required for installation.  

2.

 

An SSA shall be established and maintained for the secure storage of all SCIF 

construction material and equipment.  It is characterized by true floor to true ceiling, slab-
to-slab construction of some substantial material and a solid wood-core or steel-clad door 
equipped with a DoS/DS-approved security lock.   

3.

 

Alternative SSA‟s may include a shipping container located within a secure perimeter 

that is locked, alarmed, and monitored, or a room or outside location enclosed by a secure 
perimeter that is under direct observation by a SECRET-cleared  U.S. citizen.  

4.

 

The SSA shall be under the control of CAGs or other U.S. citizens holding at least 

U.S. SECRET clearances.  

5.

 

Supplemental security requirements for SSAs shall be set forth in the CSP and may 

vary depending on the location and/or threat to the construction site.  

J.

 

Technical Security 

1.

 

TEMPEST countermeasures shall be pre-engineered into the building.  

2.

 

A TSCM inspection shall be required in Category I countries for new SCIF 

construction or significant renovations (50% or more of SCIF replacement cost).   

3.

 

A TSCM inspection may be required by the AO in Category II or III countries for 

new SCIF construction or significant renovations (50% or more of SCIF replacement 
cost).   

4.

 

A TSCM inspection, conducted at the completion of construction, shall be required if 

uncontrolled space is converted (maximum demolition) to new SCIF space.  

5.

 

When a TSCM inspection is not conducted, a mitigation strategy based on a physical 

security inspection that identifies preventative and corrective countermeasures shall be 
developed to address any technical security concerns.  

K.

 

Interim Accreditations 

1.

 

Upon completion of a successful inspection, the respective agency‟s AO may issue an 

Interim Accreditation pending receipt of required documentation.  

2.

 

If documentation is complete, AOs may issue an Interim Accreditation pending the 

final inspection.  

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

43 

UNCLASSIFIED 

 

Chapter 6.

 

Temporary, Airborne, and Shipboard SCIFs   

A.

 

Applicability 

1.

 

General Information 

a)

 

This chapter covers all SCIFs designed to be temporary or such as those at sites 

for contingency operations, emergency operations, and tactical military operations.  

b)

 

These standards apply to the following:  

(1)

 

All ground-based temporary SCIFs (T-SCIFs), including those on mobile 

platforms (e.g., trucks and trailers).  

(2)

 

SCIFs aboard aircraft. 

(3)

 

SCIFs aboard surface and sub-surface vessels.  

c)

 

When employing T-SCIFs, a risk management approach shall be used that 

balances the operational mission and the protection of SCI.  

2.

 

Accreditation 

a)

 

Accreditation for the use of T-SCIFs shall not exceed one year without mission 

justification and approval by the AO.  

b)

 

When the T-SCIF owner determines that a T-SCIF is no longer required, the 

withdrawal of accreditation shall be initiated by the SSO/Contractor Special Security 
Officer (CSSO).  

(1)

 

Upon notification, the AO will issue appropriate SCI withdrawal 

correspondence.   

(2)

 

The AO or appointed representative will conduct a close-out inspection of 

the facility to ensure that all SCI material has been removed.  

B.

 

Ground-Based T-SCIFs 

1.

 

T-SCIF Structures and Activation 

a)

 

Ground-based T-SCIFs may be established in hardened structures (e.g., buildings, 

bunkers) or semi-permanent structures (e.g., truck-mounted or towed military 
shelters, prefabricated buildings, tents).   

b)

 

Permanent-type hardened structures shall be used to the greatest extent possible 

for T-SCIFs.  

c)

 

Prior to T-SCIF activation, the AO may require submission of a standard fixed 

facility checklist or a T-SCIF checklist produced before or after a deployment.   

 

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

44 

UNCLASSIFIED 

2.

 

SCI Storage and Destruction 

a)

 

Under field or combat conditions, open storage of SCI media and materials 

requires a continuous presence by SCI-indoctrinated personnel.   

b)

 

Under field or combat conditions every effort shall be made to obtain from any 

available host command necessary support for the storage and protection of SCI (e.g., 
security containers, generators, guards, weapons, etc.).  

c)

 

The quantity of SCI material within a T-SCIF shall be limited, to the extent 

possible, to an amount consistent with operational needs.   

d)

 

All SCI shall be stored in GSA-approved security containers.  

e)

 

The AO may approve exceptions to the storage of SCI material in GSA-approved 

storage containers for a specified period of time.  

f)

 

When no longer needed, SCI material shall be destroyed by means approved by 

the AO.  

3.

 

Security Requirements 

a)

 

T-SCIF security features shall provide acoustical, visual, and surreptitious entry 

protection.  

b)

 

A TSCM inspection shall be requested for any structure proposed for T-SCIF use 

if the space was previously occupied by a non-U.S. element.  It is the AO‟s 
responsibility to evaluate operating the SCIF prior to TSCM inspection and formally 
assume all risk associated with early operation.  

c)

 

When possible, T-SCIFs shall be established within the perimeters of U.S.-

controlled areas or compounds.   

d)

 

If a U.S.-controlled area or compound is not available, the T-SCIF shall be 

located within an area that affords the greatest degree of protection against 
surreptitious or forced entry.  

e)

 

When a T-SCIF is in operation, the perimeter of its immediate area shall be 

observed and protected by U.S. guards with U.S. SECRET clearances.  Guards shall 
be equipped with emergency communication devices and, if necessary, with weapons.   

f)

 

During non-operational hours, the T-SCIF shall be provided security protection in 

accordance with AO guidelines.   

g)

 

The T-SCIF shall have only one entrance which shall be controlled during hours 

of operation by an SCI-indoctrinated person using an access roster.  

h)

 

Unclassified telecommunications equipment shall meet the requirements outlined 

in Chapter 10 to the greatest extent practical.  

i)

 

Telephones obtained in a foreign country shall not be used within a T-SCIF.  

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

45 

UNCLASSIFIED 

j)

 

Cables and wires penetrating the T-SCIF perimeter shall be protected.  The AO 

may require inspections and routing of cables and wiring through protective 
distribution systems or may require other countermeasures.  

k)

 

AO-approved emergency destruction and evacuation plans shall be developed and 

rehearsed periodically by all personnel assigned to the T-SCIF; the results of the 
rehearsal drills shall be documented.  

l)

 

When in transit, ground-based and mobile (e.g., truck-mounted, towed military 

shelters) T-SCIFs containing unsecured and non-encrypted SCI shall be accompanied 
by a U.S. TOP SECRET-cleared individual with SCI access approval(s).  

m)

 

 During movement, T-SCIF structures shall be secured with GSA-approved 

locking devices and equipped with tamper-evident seals.  

n)

 

When in transit, hardened T-SCIFs having no open storage of SCI may be 

monitored by a U.S SECRET-cleared individual.  

o)

 

Hardened T-SCIFs shall be designed with TEMPEST countermeasures as 

identified by the CTTA.  The AO, in collaboration with the CTTA, shall provide 
red/black separation and “protected distribution” guidance for field installation in 
accordance with NSTISSAM TEMPEST 2/95 and 2/95A and CNSSI 7003.  

p)

 

When a T-SCIF is no longer required, the responsible SCI security official shall 

conduct a thorough facility inspection to ensure all SCI material has been removed.  

C.

 

Permanent and Tactical SCIFS Aboard Aircraft  

1.

 

The Aircraft Facility Checklist (see Forms & Plans) will be used for permanent SCIFs 

aboard aircraft. 

2.

 

The AO may determine that an Aircraft Facility Checklist may not be required for 

tactical SCIFs aboard aircraft if the following information is provided: 

a)

 

Name of aircraft (tail number)/airborne T-SCIF. 

b)

 

Major command/organization. 

c)

 

ID number of parent SCIF, if applicable. 

d)

 

Location T-SCIF deployed from and date of deployment. 

e)

 

Location T-SCIF deployed to and date of deployment. 

f)

 

SCI compartment(s) involved in T-SCIF operations. 

g)

 

Time period for T-SCIF operations. 

h)

 

Name of exercise or operation. 

i)

 

Points of contact (responsible officers).  

j)

 

Type of aircraft and area to be accredited as a T-SCIF. 

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

46 

UNCLASSIFIED 

k)

 

Description of security measures for entire period of T-SCIF use (standard 

operating procedures).  

l)

 

Additional comments to add clarification. 

3.

 

Security Requirements for Aircraft when Operating in Support of Missions Involving 

SCI Material  

a)

 

SCIF location shall be identified by aircraft tail number.  

b)

 

Access to the aircraft interior shall be controlled at all times by SCI-indoctrinated 

personnel.  

c)

 

 There are no unique physical security construction standards for SCIFs aboard 

aircraft. 

d)

 

Accreditation, such as that from the Defense Courier Service, is not required for 

aircraft used solely to transport SCI material between airfields.  

e)

 

When all personnel on an aircraft are not briefed on every SCI compartment 

aboard, procedural methods or physical barriers shall be employed to isolate 
compartments of the SCI.  

f)

 

When an aircraft T-SCIF is no longer required, the responsible SCI security 

official shall conduct an inspection of the aircraft to ensure all SCI material has been 
removed.   

4.

 

SCI Storage and Destruction  

a)

 

SCI materials shall be encrypted or secured in an AO-approved security container. 

b)

 

When no longer needed, SCI materials shall be destroyed by means approved by 

the AO.  

c)

 

Following an unscheduled landing in U.S.-controlled or non-hostile territory, the 

senior SCI-indoctrinated person shall retain control of the SCI material until approved 
storage arrangements can be effected through a local Special Security Officer or SCI-
indoctrinated official.  

d)

 

 Prior to an unscheduled landing in unfriendly or hostile territory, every 

reasonable effort shall be made to destroy unencrypted SCI material and 
communications security equipment in accordance with the emergency destruction 
plan.  

e)

 

If the aircraft is stationary, in the absence of SCI-indoctrinated personnel, all SCI 

information shall be encrypted or removed and stored in an alternative accredited 
SCIF or location approved by the AO.  

f)

 

Emergency destruction plans for SCI material shall be developed, approved by the 

AO, and rehearsed periodically by all personnel assigned to the aircraft; rehearsal 
results shall be documented.  

 

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

47 

UNCLASSIFIED 

5.

 

Additional Security Requirements for Stationary Aircraft  

a)

 

The aircraft shall be parked within a controlled area that affords the greatest 

protection against surreptitious or forced entry.  

b)

 

In the absence of SCI-indoctrinated personnel, all SCI information shall be 

encrypted or removed and stored in an alternative accredited SCIF or location 
approved by the AO.  

c)

 

If the aircraft cannot be positioned within a U.S.-controlled area, the SCI is not 

encrypted, and removal of the SCI is not possible, then the following measures must 
be taken:  

(1)

 

SCI-indoctrinated personnel shall remain with the aircraft.  

(2)

 

 A guard force that can control the perimeter of the aircraft shall be deployed, 

unless infeasible.  The guards shall possess U.S. SECRET clearances and be 
armed and equipped with emergency communication devices.  

d)

 

If the aircraft is located within a U.S.-controlled area, the SCI is not encrypted, 

and removal of SCI is not possible then, the following measures shall be taken:  

(1)

 

The AO may mitigate the requirement for SCI-indoctrinated personnel 

provided the aircraft is equipped with, or stored within a structure equipped with, 
an intrusion detection system approved by the AO.  

(2)

 

All aircraft hatches and doors shall be secured with AO-approved locks and 

tamper-evident seals.   

(3)

 

A guard force must be available to respond to an alarm within five minutes.  

(4)

 

Guards shall possess U.S. SECRET clearances and be armed and equipped 

with emergency communication devices.  

(5)

 

If a cleared U.S. guard force is not available, the AO may approve other 

mitigation measures.  

D.

 

Permanent and Tactical SCIFs on Surface or Subsurface Vessels 

1.

 

Permanent shipboard SCIFs shall consist of any area aboard a vessel where SCI is 

processed, stored, or discussed.  

2.

 

The Shipboard Checklist (see Forms & Plans) will be used for permanent SCIFs.  The 

AO may determine that this checklist may not be required providing the below 
information is available:  

a)

 

Name of vessel/hull number. 

b)

 

Major command/organization. 

c)

 

ID number of parent SCIF, if applicable. 

d)

 

Location SCIF deployed from and date of deployment. 

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

48 

UNCLASSIFIED 

e)

 

Location SCIF deployed to and date of deployment. 

f)

 

SCI compartment(s) and sub-compartments involved in SCIF operations. 

g)

 

Name of exercise or operation. 

h)

 

Points of contact (responsible officers).  

i)

 

Description of security measures for entire period of SCIF use (standard operating 

procedures).  

j)

 

Additional comments to add clarification. 

3.

 

Security Requirements for Permanent SCIFs 

a)

 

The perimeter (walls, floors, and ceiling) shall be fabricated of structural 

bulkheads comprised of standard shipboard/submarine construction materials.  

b)

 

Elements of the perimeter shall be fully braced and welded or bonded in place.  

c)

 

Doors shall conform to the following requirements:  

(1)

 

Perimeter doors and emergency exit(s) shall be constructed of standard 

shipboard materials and shall be mounted in a frame, braced and welded or 
bonded in place in a manner commensurate with the structural characteristics of 
the bulkhead, deck, or overhead.  

(2)

 

The primary entry door shall be equipped with a GSA-approved combination 

lock and an access control device.  

(3)

 

If the door is in a bulkhead that is part of an airtight perimeter, the airtight 

integrity may be maintained by co-locating the door with the metal joiner door, or 
by adding a vestibule.  

(4)

 

Metal joiner doors shall be equipped with a combination lock that meets 

specification FF-L-2740A and with an access control device approved by the AO.  

(5)

 

Doors shall be constructed in a manner that will preclude unauthorized 

removal of hinge pins and anchor bolts, and obstruct access to lock-in bolts 
between the door and frame.  

(6)

 

Doorways or similar openings that allow visual access to the SCIF shall be 

screened or curtained.  

d)

 

No damage control fittings or cables shall be located within, or pass through, the 

SCIF.  This does not apply to smoke dampers or other life-safety devices that are 
operated by personnel within the space during working hours.  

e)

 

Removable hatches and deck plates less than 10 square feet that are secured by 

exposed nuts and bolts (external to the SCIF) shall be secured with a high security 
padlock (unless their weight makes this unreasonable).  Padlock keys shall be stored 
in a security container located within the SCIF.  

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

49 

UNCLASSIFIED 

f)

 

Vents, ducts, and similar openings with a cross-sectional measurement greater 

than 96 inches shall be protected by a fixed barrier or security grill. (This requirement 
is not applicable to through-ducts that do not open into the SCIF.)  

(1)

 

Grills shall be fabricated of steel or aluminum grating or bars with a 

thickness equal to the perimeter barrier.   

(2)

 

If a grating is used, bridge center-to-center measurements will not exceed 1.5 

inches by 4 inches.   

(3)

 

Bars shall be mounted in a grid pattern, six-inches on center.   

(4)

 

The grating or bars shall be welded into place.    

g)

 

Construction of the SCIF perimeter shall afford adequate sound attenuation.  Air 

handling units and ducts may require baffles if SCIF discussions can be overhead in 
adjacent areas.  

h)

 

The SCIF shall be equipped with an AO-approved intrusion detection system 

(IDS) or other countermeasures if SCI-indoctrinated personnel cannot continuously 
occupy the area.  

i)

 

Passing scuttles and windows should not be installed between the SCIF and any 

other space on the ship.  If installed, they shall be secured on the inside of the SCIF.  

j)

 

All SCI cryptographic and processing equipment shall be located within the SCIF.  

k)

 

Unclassified telecommunications shall meet the requirements outlined in Chapter 

11, to the greatest extent practical.  

l)

 

Sound-powered telephones will not be permitted in the SCIF without additional 

mitigations determined by the AO.  If a deviation is granted, sound-powered 
telephones located within the SCIF and connecting to locations outside the SCIF shall 
comply with the following:  

(1)

 

Telephone cables shall not break out to jack-boxes, switchboards, or 

telephone sets other than at designated stations.  Cables shall not be shared with 
any circuit other than call or signal systems associated with the SCIF circuit.  

(2)

 

Telephone cables shall be equipped with a selector switch located at the 

controlling station and shall be capable of disconnecting all stations, selecting any 
one station, and disconnecting the remaining stations.  

(3)

 

Sound-powered telephones not equipped with a selector switch shall have a 

positive disconnect device attached to the telephone circuit.  

(4)

 

Within any SCIF, sound-powered telephones not used for passing SCI 

information shall have a warning sign prominently affixed indicating the 
restriction.  

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

50 

UNCLASSIFIED 

(5)

 

A call or signal system shall be provided.  Call signal station, type ID/D, 

shall provide an in-line disconnect to prevent a loudspeaker from functioning as a 
microphone.  

m)

 

The approval of the AO is required for unencrypted, internal, communication-

announcing systems that pass through the SCIF perimeter.  

n)

 

Intercommunications-type announcing systems installed within an SCIF shall 

meet the following standards:  

(1)

 

The system shall operate only in the push-to-talk mode.  

(2)

 

Receive elements shall be equipped with a local buffer amplifier to prevent 

loudspeakers or earphones from functioning as microphones.  

(3)

 

Except as specified, radio transmission capability for plain radio-telephone 

(excluding secure voice) will not be connected.  

(4)

 

Cable conductors assigned to the transmission of plain language radio-

telephone will be connected to ground at each end of the cable.  

(5)

 

A warning sign will be posted that indicates the system may not be used to 

pass SCI.  

(6)

 

Unencrypted internal communication systems that pass through the SCIF 

perimeter shall be in grounded ferrous conduit.  

o)

 

Commercial intercommunication equipment shall not be installed within a SCIF 

without prior AO approval.  

p)

 

Loudspeakers used on general announcing systems shall be equipped with a one-

way buffer amplifier to protect against microphonic responses.  

q)

 

Pneumatic tube systems shall not be installed within the SCIF.  The following 

safeguards apply to existing systems on older ships:  

(1)

 

Covers shall be locked at both ends with an AO-approved lock. Keys shall be 

stored within an approved security container within the SCIF. 

(2)

 

The system shall have the capability to maintain the pressure or vacuum and 

the capability to lock in the secure position at the initiating end.  

(3)

 

There shall be a direct voice communications link between both ends to 

confirm the transportation and receipt of passing cartridges.  

(4)

 

Cartridges passing SCI material shall have a distinctive color.  

(5)

 

Pneumatic tubes shall be visually inspectable along their entire length.  

(6)

 

The CTTA shall conduct a TEMPEST countermeasures inspection and shall 

recommend safeguards to limit compromising emanations. TEMPEST safeguards 
should be pre-engineered into platforms to the greatest extent possible. 

 

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

51 

UNCLASSIFIED 

4.

 

General Requirements for T-SCIFs  

a)

 

SCIFs on sub-surface vessels shall be accredited as T-SCIFs.  

b)

 

T-SCIFs aboard a vessel include portable platforms or containers temporarily 

placed within ship space such as embarked Portable Shipboard Collection Vans.  

c)

 

T-SCIFs shall be occupied by an SCI-indoctrinated person at all times unless the 

facility is protected by a GSA-approved lock, an approved intrusion detection system, 
and a response capability or other countermeasures approved by the AO.  

5.

 

Security Requirements for T-SCIFs  

a)

 

Overall T-SCIF construction standards shall be the same as those used for 

permanent shipboard SCIFs.  

b)

 

Vents, ducts, and similar openings shall be constructed to the same standards as 

those used for a shipboard SCIF.  

c)

 

SCI materials shall be destroyed by means approved by the AO when no longer 

needed.  

d)

 

AO-approved emergency destruction plans shall be rehearsed periodically by all 

personnel assigned to the T-SCIF and the rehearsals documented.  

e)

 

Unclassified telecommunications shall meet the requirements for a shipboard 

SCIF, to the greatest extent practical.  

f)

 

When the T-SCIF is no longer required, the responsible SCI security official shall 

conduct a closing inspection of the T-SCIF to ensure all SCI material has been 
removed.  

g)

 

The CTTA shall conduct a TEMPEST countermeasures inspection and shall 

recommend safeguards to limit compromising emanations.  TEMPEST safeguards 
should be pre-engineered into platforms to the greatest extent possible. 

6.

 

Additional Security Standards for Mobile Platforms or Containers  

a)

 

 Construction of the perimeter must be of sufficient strength to reveal evidence of 

physical penetration (except for required antenna cables and power lines). 

b)

 

Doors must fit securely and be equipped with a locking device that can be locked 

from the inside and outside.  

7.

 

SCI Storage and Destruction 

a)

 

SCI material shall be stored in a GSA-approved security container that is welded 

or otherwise permanently secured to the structural deck.  

b)

 

When no longer needed, SCI materials shall be destroyed by means approved by 

the AO.  

 

            UNCLASSIFIED 

Chapter 6 

 

 

Temporary, Airborne, and Shipboard SCIFs 

 

 

 

 

52 

UNCLASSIFIED 

c)

 

AO-approved emergency destruction and evacuation plans shall be developed and 

rehearsed periodically by all personnel assigned to the SCIF and the rehearsals shall 
be documented. 

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

53 

UNCLASSIFIED 

Chapter 7.

 

Intrusion Detection Systems (IDS)  

A.

 

Specifications and Implementation Requirements  

1.

 

General SCIF IDS Requirements 

a)

 

SCIFs shall be protected by IDS when not occupied.  

b)

 

Interior areas of a SCIF through which reasonable access could be gained, 

including walls common to areas not protected at the SCI level, shall be protected by 
IDS.   

c)

 

Doors without access control systems and that are not under constant visual 

observation shall be continuously monitored by the IDS.  

d)

 

If any component of the IDS is disrupted to the extent the system no longer 

provides essential monitoring service (e.g., loss of line security, inoperable IDE, and 
loss of power), SCI-indoctrinated personnel shall physically occupy the SCIF until 
the system is returned to normal operation.  As an alternative, the outside SCIF 
perimeter may be continuously monitored by a response or guard force.  

e)

 

IDS failure shall be addressed in the SCIF emergency plan.  

2.

 

System Requirements  

a)

 

IDS installation related components and monitoring stations shall comply with 

Underwriters Laboratories (UL) Standard for National Industrial Security Systems for 
the Protection of Classified Material, UL 2050.  

b)

 

Installation shall comply with an Extent 3 installation as referenced in UL 2050.   

c)

 

Systems developed and used exclusively by the USG do not require UL 

certification but shall comply with an Extent 3 installation as referenced in UL 2050.  

d)

 

Interior areas of a SCIF through which reasonable access could be gained, 

including walls common to areas not protected at the SCI level, shall be protected by 
IDS consisting of motion sensors and high security switches (HSS) that meet UL 634 
level 1 or 2 requirements, and/or other AO-approved equivalent sensors. HSS Level 2 
is preferred.  

e)

 

IDS-associated cabling that extends beyond the SCIF perimeter shall be installed 

in rigid conduit or shall employ line security.  

f)

 

The IDS shall be independent of systems safeguarding other facilities.  

g)

 

If a monitoring station is responsible for more than one IDS, there shall be an 

audible and visible annunciation for each IDS.  

h)

 

IDS‟s shall be separate from, and independent of, fire, smoke, radon, water, and 

other systems.  

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

54 

UNCLASSIFIED 

i)

 

 If the IDS incorporates an access control system (ACS), notifications from the 

ACS shall be subordinate in priority to IDS alarms.  

j)

 

System key variables and passwords shall be protected and restricted to U.S. SCI-

indoctrinated personnel.   

k)

 

IDS installation plans shall be controlled as determined by the AO.  

l)

 

Systems shall not include audio or video monitoring without the application of 

appropriate countermeasures and AO approval.  Systems containing auto-reset 
features shall have this feature disabled.  

m)

 

The AO shall approve all system plans.  Final system acceptance testing shall be 

included as part of the SCIF accreditation package.   

n)

 

False alarms shall not exceed one alarm per 30-day period per zone.  False alarms 

are any alarm signal transmitted in the absence of a confirmed intrusion that is caused 
by changes in the environment, equipment malfunction, or electrical disturbances.  If 
false alarms exceed this requirement, a technical evaluation of the system shall be 
conducted to determine the cause, repaired or resolved, and documented.  

3.

 

System Components  

a)

 

Sensors   

(1)

 

All system sensors shall be located within the SCIF.  

(2)

 

With AO approval, sensors external to the SCIF perimeter and any perimeter 

equipment used may be connected to the IDS provided the lines are installed on a 
separate zone and routed within grounded conduit.  

(3)

 

Failed sensors shall cause immediate and continuous alarm activation until 

the failure is investigated and corrected.   

(4)

 

Dual technology sensors are authorized when each technology transmits 

alarm conditions independent of the other technology.  

(5)

 

A sufficient number of motion detection sensors shall be installed to meet the 

requirements of paragraph A.2.d, shall be UL 639 listed, or shall be approved by 
the AO.  However, the following special circumstances apply to motion detection 
sensors:  

 

Motion detection sensors are not required above false ceilings or below  

false floors. 

 

For facilities outside the U.S. and in Category I and II countries, motion 
detections sensors above false ceilings or below false floors may be 
required by the AO.   

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

55 

UNCLASSIFIED 

(6)

 

When the primary entrance door employs a delay to allow for changing the 

system mode of access, the delay shall not exceed 30 seconds.  

(7)

 

SCIF perimeter doors shall be protected by an HSS and a motion detection 

sensor.  

(8)

 

Emergency exit doors shall be alarmed and monitored 24 hours per day.  

b)

 

Premise Control Units (PCUs)  

(1)

 

PCUs shall be located within a SCIF and only SCIF personnel may initiate 

changes in access modes.   

(2)

 

Operation of the access/secure switch shall be restricted by using a device or 

procedure that validates authorized use.  

(3)

 

Cabling between all sensors and the PCU shall be dedicated to the system, 

contained within the SCIF, and shall comply with national and local electric codes 
and Committee for National Security Systems (CNSS) standards. If the wiring 
cannot be contained within the SCIF, such cabling shall meet the requirements for 
External Transmission Line Security 3.b.(10) below.  

(4)

 

Alarm status shall be continuously displayed with an alphanumeric display at 

the PCU and/or monitoring station.   

(5)

 

Every effort shall be made to design and install the alarm-monitoring panel in 

a location that prevents observation by unauthorized persons.  

(6)

 

The monitoring station or PCU shall identify and display activated sensors.  

(7)

 

Immediate and continuous alarm annunciations shall occur for the following 

conditions.  

 

Intrusion Detection 

 

Failed Sensor 

 

Tamper Detection 

 

Maintenance Mode (a maintenance message may display in place of an 
alarm)  

 

Zones that are shunted or masked during maintenance mode 

(8)

 

Failed/changed power status shall be indicated at the PCU and/or monitoring 

station.  

(9)

 

An IDS with an auto-alarm reset feature shall have it disabled.  All system 

events shall be reset by authorized SCI-indoctrinated personnel after an inspection 
of the SCIF and a determination for the cause of the alarm has been made.  

(10)

 

IDS transmission lines leaving the SCIF to the monitoring station, must meet 

National Institute of Standards and Technology, Federal Information Processing 
Standards (FIPS) certified encrypted lines. The FIPS standard employed must be 
noted on the UL 2050/CRZH Certificate or other certificate employed.   For 

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

56 

UNCLASSIFIED 

Premise Control Units certified under UL 1610 either a FIPS 197 or FIPS 140-2 is 
acceptable encryption certification and method.  For Premise Control Units 
certified under UL1076 only FIPS 140-2 is the acceptable encryption certification 
and method.  Alternative methods shall be approved by the AO and noted on the 
IDS Certificate  

c)

 

Integrated IDS.   

(1)

 

The IC element‟s Chief Information Officer (CIO) shall be consulted before 

connecting an IDS to a government LAN or WAN under their cognizance.  

(2)

 

In cases where the IDS has been integrated into a networked system (local 

area network (LAN) or wide area network (WAN)), the requirements below shall 
be met. 

 

 If any component of the IDS is remotely programmable, a Network 
Intrusion Detection Systems (NIDS) is required.  

 

System application software shall be installed on a host computer 
dedicated to security systems.  The host computer shall be located in an 
alarmed area controlled at the SECRET or higher level.  

 

All system components and equipment shall be isolated with dedicated 
firewalls, or similar enhancements, that are configured to allow data 
transfers only between the PCU and monitoring station.  

 

A secondary communication path may be utilized to augment an existing 
data communication link to reduce investigations of data communication 
failures of less than five minute duration. The supervision provided by the 
secondary communication path shall be equivalent to that of the primary 
communication path.  

 

A unique user ID and password is required for each individual granted 
access to the system host computer.  Passwords shall be a minimum of 
twelve characters consisting of alpha, numeric, and special characters, and 
shall be changed every six months.  

 

Firewalls shall be monitored for unauthorized access attempts, and all 
access attempts and changes to the system network shall be logged.  

 

Network administrators shall immediately notify the AO or designee of 
any unauthorized modifications.  

 

The IDS network system administrator shall be a U.S. citizen and SCI-
indoctrinated.  

 

All transmissions of system information over the LAN/WAN shall be 
encrypted using National Institute of Standards and Technology FIPSAES 
certified encrypted lines.  

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

57 

UNCLASSIFIED 

 

Remote networked system terminals shall:  

o

 

Ensure that non SCI-indoctrinated personnel with access to the remote 
terminal cannot modify the IDS or ACS. 

o

 

Require an independent user ID and password in addition to the host 
login requirements.  

o

 

Have system auditing software that shall log and monitor failed logins 
and IDS/ACS application program modifications.  

B.

 

IDS Modes of Operation  

1.

 

General Information 

a)

 

The system shall operate in either access or secure mode.  

b)

 

There shall be no remote capability for changing the mode of operation or 

accessing the status of the system unless SCIF personnel conduct a daily audit of all 
openings and closings.  

c)

 

Changing access/secure status of the system shall be limited to SCI-indoctrinated 

personnel.  

2.

 

Requirements for Access Mode 

a)

 

When in access mode, normal authorized entry into the SCIF, in accordance with 

prescribed security procedures, shall not cause an alarm.  

b)

 

 Tamper circuits and emergency exit door circuits shall remain in the secure mode 

of operation.  

c)

 

The PCU shall have the ability to allow alarm points to remain in secure status 

while other points are in access status.  

3.

 

Requirements for Secure Mode   

a)

 

The system shall be placed into secure mode when the last person departs the 

SCIF.    

b)

 

A record shall be maintained identifying the person responsible for activating and 

deactivating the system.   

c)

 

Each failure to activate or deactivate the system shall be reported to the 

responsible SCIF Security Manager.  Records of these events shall be maintained for 
two years.  

d)

 

When in the secure mode, any unauthorized entry into the SCIF shall cause an 

alarm to be immediately transmitted to the monitoring station.  

4.

 

Requirements for Maintenance and Zone Shunting/Masking Modes  

a)

 

When maintenance is performed on a system, a signal for this condition shall be 

automatically sent to the monitoring station.   

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

58 

UNCLASSIFIED 

b)

 

When a zone or sensor is shunted for reasons other than maintenance, the shunted 

or masked zone sensor shall be displayed as such at the monitoring station or PCU 
throughout the period the condition exists.  

c)

 

Any sensor that has been shunted shall be reactivated upon the next change in 

status from access to secure.   

d)

 

All maintenance periods shall be archived in the system.   

e)

 

The AO may require that a Personal Identification Number (PIN), for 

maintenance purposes, be established and controlled by SCI-indoctrinated personnel.   

f)

 

A shunted or masked zone or sensor shall be displayed as such at the monitoring 

station or PCU throughout the period the condition exists unless it occurs during a 
maintenance period.  

g)

 

Computing devices are allowed attachment to system equipment either 

temporarily or permanently for the purposes of system maintenance or repair.  

(1)

 

Such devices shall be kept under control of SCI-indoctrinated personnel at all 

times.  

(2)

 

When not in use, the computing devices shall be secured within the SCIF.  

(3)

 

Mass storage devices containing SCIF alarm equipment details, 

configurations, or event data will be protected at an appropriate level approved by 
the AO.  

h)

 

After the initial installation, the capability for remote diagnostics, maintenance, or 

programming of IDE shall not exist unless accomplished only by appropriately SCI-
indoctrinated personnel and shall be appropriately logged or recorded in the Remote 
Service Mode Archive.  A self-test feature shall be limited to one second per 
occurrence.  

5.

 

Requirements for Electrical Power  

a)

 

In the event of primary power failure, the system shall automatically transfer to an 

emergency electrical power source without causing alarm activation.  

b)

 

Twenty-four hours of uninterruptible backup power is required and shall be 

provided by an uninterruptible power supply (UPS), batteries, or generators, or any 
combination. 

c)

 

An audible or visual indicator at the PCU shall provide an indication of the 

primary or backup electrical power source in use.  

d)

 

Equipment at the monitoring station shall visibly and audibly indicate a failure in 

a power source or a change in power source.  The individual system that failed or 
changed shall be indicated at the PCU or monitoring station as directed by the AO.  

6.

 

Monitoring Stations 

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

59 

UNCLASSIFIED 

a)

 

Monitoring stations shall be government-managed or one of the following in 

accordance with UL 2050: 

(1)

 

CSA-operated monitoring station.  

(2)

 

Government contractor monitoring station (formerly called a proprietary 

central station). 

(3)

 

National industrial monitoring station. 

(4)

 

Cleared commercial central station (see NISPOM). 

b)

 

Monitoring station employees shall be eligible to hold a U.S. SECRET clearance.  

c)

 

Monitoring station operators shall be trained in system theory and operation to 

effectively interpret system incidents and take appropriate response action.  

d)

 

Records shall be maintained for two years and indicate the following:  

 

Time of receipt of alarm.  

 

 Name(s) of security or response force personnel.  

 

 Dispatch time.  

 

Arrival time of responding personnel.  

 

 Nature of the alarm.  

 

Follow-up actions that were taken.  

C.

 

Operations and Maintenance of IDS 

1.

 

Alarm Response  

a)

 

Alarm activations shall be considered an unauthorized entry until resolved.  

b)

 

 The response force shall take appropriate steps to safeguard the SCIF, as 

permitted by a written support agreement, until an SCI-indoctrinated individual 
arrives to take control of the situation.  

2.

 

System Maintenance  

a)

 

Maintenance and repair personnel shall be escorted if they are not TOP SECRET-

cleared and indoctrinated for SCIF access.  

b)

 

 Repairs shall be initiated within four hours of receipt of an alarm.  

c)

 

The SCIF shall be continuously manned by SCI-indoctrinated personnel on a 24-

hour basis until repairs are completed.   

d)

 

The following apply to emergency-power battery maintenance:  

(1)

 

The battery manufacturer‟s periodic maintenance schedule and procedures 

shall be followed and documented in the system‟s maintenance logs and retained 
for two years.  

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

60 

UNCLASSIFIED 

(2)

 

If the communications path is via a network, the local uninterruptible power 

source for the network shall also be tested.   

(3)

 

Batteries shall be tested, under load, until 50% of their capacity has been 

expended.  

(4)

 

If a generator is used to provide emergency power, the manufacturers 

recommended maintenance and testing procedures shall be followed.  

e)

 

Network Maintenance 

(1)

 

NIDS system administrators shall maintain configuration control, ensure the 

latest operating system security patches have been applied, and configure the 
operating system to provide a high level of security.   

(2)

 

Inside the U.S., network maintenance personnel within a SCIF shall be a U.S. 

person and be escorted by cleared SCIF individuals.  

(3)

 

Outside the U.S., network maintenance personnel shall be U.S. TOP 

SECRET-cleared or U.S. SECRET-cleared and escorted by SCIF personnel.  

D.

 

Installation and Testing of IDS  

1.

 

Personnel Requirements 

a)

 

Installation and testing within the U.S. shall be performed by U.S. companies 

using U.S. citizens.  

b)

 

 Installation and testing outside of the U.S. shall be performed by personnel who 

are U.S. TOP SECRET-cleared or U.S. SECRET-cleared and escorted by SCIF 
personnel.  

2.

 

Installation Requirements  

All system components and elements shall be installed in accordance with 
requirements of this document, UL 2050, and manufacturer‟s instructions and 
standards.   

3.

 

Testing 

a)

 

Acceptance testing shall be conducted on systems prior to operational use to 

provide assurance that they meet all requirements of this section prior to SCIF 
accreditation.   

b)

 

Semi-annual IDS testing shall be conducted to ensure continued performance.  

c)

 

Records of testing and test performance shall be maintained in accordance with 

documentation requirements.   

d)

 

Motion Detection Sensor Testing  

All motion detection sensors shall be tested to ensure activation of the sensor at a 
minimum of four consecutive steps at a rate of one step per second; that is, 30 

 

            UNCLASSIFIED 

Chapter 7 

 

 

Intrusion Detection Systems 

 

 

 

 

61 

UNCLASSIFIED 

inches ± 3 inches or 760 mm ± 80 mm per second.  The four-step movement shall 
constitute a “trial.”  

(1)

 

 The test shall be conducted by taking a four-step trial, stopping for three to 

five seconds, and taking another four-step trial.  

(2)

 

 Trials shall be repeated throughout the SCIF and from different directions.  

(3)

 

 An alarm shall activate at least three out of every four consecutive trials made 

by moving progressively through the SCIF. 

e)

 

HSS Testing   

All HSS devices shall be tested to ensure that an alarm signal activates before the 
non-hinged side of the door opens beyond the thickness of the door from the 
closed position, e.g., the sensor initiates before the door opens 1¾ inch for a 1¾ 
inch door.  

f)

 

Tamper Testing   

Each IDS equipment cover shall be individually removed or opened to ensure 
there is alarm activation at the PCU or monitoring station in both the secure and 
access modes.  

(1)

 

Tamper detection devices need only be tested when installed.  

(2)

 

The AO may require more frequent testing of tamper circuits. 

 

           UNCLASSIFIED 

Chapter 8 

 

 

Access Control Systems 

 

 

 

 

62 

UNCLASSIFIED 

Chapter 8.

 

Access Control Systems (ACS) 

 

A.

 

SCIF Access Control 

1.

 

Guidelines 

a)

 

SCIFs shall be controlled by SCI-indoctrinated personnel or by an AO- approved 

ACS to ensure access is restricted to authorized personnel.  

b)

 

Personnel access control shall be utilized at all SCIFs.  

c)

 

Visual recognition of persons entering the SCIF by an SCI-indoctrinated person at 

the entrance to a SCIF is the ideal access control.  

d)

 

Entrances where visitor control is conducted shall be under continuous visual 

observation unless the SCIF is properly secured.  

e)

 

When the SCIF is an entire building, access control shall occur at the building 

perimeter.   

2.

 

ACS Requirements if Continuous Visual Observation is Not Possible 

a)

 

An automated personnel ACS that verifies an individual‟s identity before the 

individual is permitted unescorted access shall be utilized when personal recognition 
and verification is not used.  Automated verification shall employ 

two

 of the 

following three technologies:  

(1)

 

Identification (ID) badge or card used in conjunction with the access control 

device that validates the identity of the person to whom the card is issued. 
Compromised or lost access cards shall be reported immediately and updated in 
the system to reflect “no access.”  

(2)

 

A personal identification number (PIN) that is entered into the keypad by 

each individual.  The PIN shall consist of four or more random digits, with no 
known or logical association to the individual or which can be derived from the 
person or system generated.  Compromised PINs shall be reported immediately to 
the facility Security Officer (SO) or SCIF SO and updated in the system to reflect 
“no access.”  

(3)

 

Biometric personal identity verification using unique personal characteristics 

such as fingerprint, iris scan, palm print, etc.  

b)

 

The automated personnel ACS shall ensure that the probability of an unauthorized 

individual gaining access is no more than one in ten thousand while the probability of 
an authorized individual being rejected access is no more than one in one thousand. 
Manufacturers must certify in writing that their system meets these criteria.  

 

           UNCLASSIFIED 

Chapter 8 

 

 

Access Control Systems 

 

 

 

 

63 

UNCLASSIFIED 

B.

 

ACS Administration 

1.

 

ACS administrators shall be SCI-indoctrinated.  

2.

 

Remote release buttons that by-pass the ACS shall be inside the SCIF and in a 

location that provides continuous visual observation of personnel entering the SCIF.   

3.

 

ACSs shall not be used to secure an unoccupied SCIF.  

4.

 

When not occupied, SCIFs shall be alarmed and in secure mode in accordance with 

Chapter 7 and secured with an approved GSA FF-L-2740A combination lock. 

5.

 

Authorized personnel who permit another individual to enter the SCIF shall verify the 

individual‟s authorized access.  

6.

 

SCIF access authorization shall be removed when the individual is transferred, 

terminated, or the access approval is suspended or revoked.  

C.

 

ACS Physical Protection 

1.

 

Card readers, keypads, communication interface devices, and other access control 

equipment located outside the SCIF shall be tamper-protected and be securely fastened to 
a wall or other fixed structure.  

2.

 

Electrical components, associated wiring, or mechanical links shall be accessible only 

from inside the SCIF.  

3.

 

System data that is carried on transmission lines (e.g., access authorizations, personal 

identification, or verification data) to and from equipment located outside the SCIF shall 
be protected using FIPS AES certified encrypted lines.  If this communication technology 
is not feasible, transmission lines shall be installed as approved by the AO.  

4.

 

Equipment containing access-control software programs shall be located in the SCIF 

or a SECRET controlled area.  

5.

 

Electric door strikes installed in conjunction with a personnel ACS shall have a 

positive engagement and be approved under UL 1034 for burglar resistance.   

D.

 

ACS Recordkeeping 

1.

 

Records shall reflect the active assignment of ID badge/card, PIN, level of access, 

entries, and similar system-related information.  

2.

 

Records and information concerning encoded ID data, PINs, Authentication data, 

operating system software, or any other data associated with the personnel ACS shall be 
secured in an open-storage facility or, when unattended, secured in a GSA-approved 
container in a closed-storage facility.  Access to such data shall be restricted to only SCI-
indoctrinated personnel responsible for the access control system.  

3.

 

Records of personnel removed from the system shall be retained for two years from 

the date of removal.  

 

           UNCLASSIFIED 

Chapter 8 

 

 

Access Control Systems 

 

 

 

 

64 

UNCLASSIFIED 

4.

 

Records of security incidents (violations/infractions) regarding ACS shall be retained 

by the SO for five years from the date of an incident or until investigations of system 
violations and incidents have been resolved.  

E.

 

Using Closed Circuit Television (CCTV) to Supplement ACS 

1.

 

CCTV may be used to supplement the monitoring of a SCIF entrance for remote 

control of the door from within the SCIF.   The system shall present no technical security 
hazard.  

2.

 

The remote control device shall be within the interior of the SCIF.  

3.

 

The system shall provide a clear view of the SCIF entrance and shall be 

monitored/operated by SCI-indoctrinated personnel within the SCIF.   

4.

 

CCTV communication lines should be located within the SCIF.  Communication lines 

that must run external to the SCIF shall be installed to prevent tampering as approved by 
the AO.  

F.

 

Non-Automated Access Control  

1.

 

Non-automated access control devices (mechanical, electric, or electromechanical) 

may be approved by the AO to control access to SCIFs where the number of personnel 
that require access is low and there is only one entrance.  

2.

 

Combinations shall consist of four (4) or more random digits.  

3.

 

The use of pass keys to bypass such devices should be avoided except when local 

fire/safety codes require them.  Any pass keys for such devices must be strictly controlled 
by SCI-indoctrinated personnel.  

4.

 

Mechanical access control devices (e.g., UNICAN, Simplex) shall be installed to 

prevent manipulation or access to coding mechanisms from outside the door.  

5.

 

The following shall apply to electric or electromechanical access control devices:  

a)

 

 The control panel or keypad shall be installed in such a manner to preclude 

unauthorized observation of the combination or the actions of a combination change.  

b)

 

The selection and setting of combinations shall be accomplished by the SO and 

shall be changed when compromised or deemed necessary by the SO.  

c)

 

The control panel in which the combination and all associated cabling and wiring 

is set shall be located inside the SCIF and shall have sufficient physical security to 
deny unauthorized access to its mechanism. 

 

            UNCLASSIFIED 

Chapter 9 

 

 

Acoustic Protection 

 

 

 

 

65 

UNCLASSIFIED 

Chapter 9.

 

Acoustic Protection 

A.

 

Overview 

1.

 

This establishes DNI guidelines to protect classified conversations from being 

inadvertently overheard outside a SCIF.  

2.

 

This is not intended to protect against deliberate technical interception of audio 

emanations.  

B.

 

Sound Group Ratings 

The ability of a SCIF structure to retain sound within the perimeter is rated using a 
descriptive value, the Sound Transmission Class (STC).  To satisfy the normal security 
standards of SCIFs, the following transmission attenuation groups have been established:   

 

Sound Group 3 - STC 45 or better.  Loud speech from within the SCIF can be 
faintly heard but not understood outside of the SCIF. Normal speech is 
unintelligible with the unaided human ear.  

 

Sound Group 4 - STC 50 or better.  Very loud sounds within the SCIF, such as 
loud singing, brass music, or a radio at full volume, can be heard with the 
human ear faintly or not at all outside of the SCIF.  

C.

 

Acoustic Testing 

1.

 

Audio tests shall be conducted to verify standards are met. Tests may be instrumental 

or non-instrumental as approved by the AO. Test method used shall be detailed in the 
CSP. 

2.

 

Instrumental Acoustic Tests 

a)

 

Only those with training on audio testing techniques shall conduct instrumental 

acoustic tests 

b)

 

With all SCIF doors closed, all perimeter walls and openings (e.g., air returns, 

doors, windows, etc.) shall be tested along multiple points to ensure that either Sound 
Group 3 or 4 is met.  

c)

 

Audio test sources shall have a variable sound level output.  

d)

 

The output frequency range shall include normal speech.  

e)

 

Test speakers shall be placed six feet from the test wall and 4 feet off the floor.  

f)

 

Audio gain of the test source shall produce “loud or very loud speech” as defined 

by Sound Group 3 and 4 levels respectively.  

g)

 

As an alternative, instrumented testing may be performed to Noise Isolation Class 

(NIC) standards.  Results shall comply with NIC 40 for Sound Group 3 and NIC 45 
for Sound Group 4. 

 

            UNCLASSIFIED 

Chapter 9 

 

 

Acoustic Protection 

 

 

 

 

66 

UNCLASSIFIED 

3.

 

Non-Instrumental Acoustic Tests 

All non-instrumental tests shall be approved by the AO. 

D.

 

Construction Guidance for Acoustic Protection 

1.

 

The SCIF perimeter shall be designed and constructed to meet Sound Group 3 or 

better standards.   (See construction drawings for Wall A, B, or C.)  

2.

 

Areas that provide for amplified conversations, such as conference centers, video 

teleconference (VTC) rooms, or similar areas, shall be designed and constructed to meet 
Sound Group 4 standards.  (See construction drawings for Wall A, B, or C.) 

3.

 

Utility (e.g., power, signal, telephone) distribution shall be surface mounted to a 

sound-treated wall and shall not completely penetrate the sound-engineered structure.  

E.

 

Sound Transmission Mitigations  

1.

 

Construction of walls as described in Chapter 3 (Wall types A, B and C) or with 

brick, concrete, or other substantive material and acoustically treating penetrations, walls 
and doors should provide the necessary acoustic protection for Sound group 3.  

2.

 

When Sound Group 3 or 4 cannot be met with normal construction, supplemental 

mitigations to protect classified discussions from being overheard by unauthorized 
persons may include but not be limited to the following: 

a)

 

Structural enhancements such as the use of high-density building materials (i.e., 

sound deadening materials) can be used to increase the resistance of the perimeter to 
vibration at audio frequencies.  

b)

 

Facility design can include a perimeter location or stand-off distance which 

prevents non-SCI-indoctrinated person(s) traversing beyond the point where SCI 
discussions become susceptible to interception.  For example, use of a perimeter 
fence or protective zone between the SCIF perimeter walls and the closest "listening 
place" is permitted as an alternative to other sound protection measures.  

c)

 

Sound masking devices, in conjunction with an amplifier and speakers or 

transducers, can be used to generate and distribute vibrations or noise; noise sources 
may be noise generators, tapes, discs, or digital audio players.   

d)

 

Speakers/transducers must produce sound at a higher level than the voice 

conversations within the SCIF.  

e)

 

Speakers/transducers shall be placed close to, or mounted on, any paths that 

would allow audio to leave the area, including doors, windows, common perimeter 
walls, vents/ducts, and any other means by which voice can leave the SCIF.   

f)

 

Wires and transducers shall, to the greatest extent possible, be located within the 

perimeter of the SCIF.  

 

            UNCLASSIFIED 

Chapter 9 

 

 

Acoustic Protection 

 

 

 

 

67 

UNCLASSIFIED 

g)

 

The sound masking system shall be subject to inspection during TSCM 

evaluations.  

h)

 

If the AO determines risk to be low, a speaker may be installed outside the SCIF 

door if the following conditions are met:  

 

The cable exiting the SCIF shall be encased within rigid conduit.  

 

 The sound masking system shall be subject to review during TSCM 
evaluations.  

i)

 

For common walls, the speakers/transducers shall be placed so the sound 

optimizes the acoustical protection.  

j)

 

For doors and windows, the speakers/transducers shall be placed close to the 

aperture of the window or door and the sound projected in a direction facing away 
from conversations.  

k)

 

Once the speakers or transducers are optimally placed, the system volume shall be 

set and fixed.  The volume level for each speaker shall be determined by listening to 
conversations outside the SCIF or area to be protected, and the speaker volume 
adjusted until conversations are unintelligible from outside the SCIF.  

l)

 

Sound-source generators shall be permanently installed and not contain an 

AM/FM receiver and shall be located within the SCIF.   

m)

 

Any sound-source generator within the SCIF that is equipped with a capability to 

record ambient sound shall have that capability disabled.   

n)

 

Examples of government-owned or government-sponsored sound-source 

generators are given below:   

 

Audio amplifier with a standalone computer (no network connection).  

 

Audio amplifier with a cassette tape player, compact disc (CD) player, or 
digital audio player, or with a digital audio tape (DAT) playback unit.  

 

Integrated amplifier and playback unit incorporating any of the above music 
sources.  

 

A noise generator or shift noise source generator using either white or pink 
noise.

 

 

            UNCLASSIFIED 

Chapter 10 

 

 

Portable Electronic Devices 

 

 

 

 

68 

UNCLASSIFIED 

Chapter 10.

 

  Portable Electronic Devices (PEDs)  

A.

 

Approved Use of PEDs in a SCIF 

1.

 

Heads of IC elements may institute and maintain mitigation programs 

(countermeasures) to allow introduction of PEDs into SCIFs under their cognizance. 
Such decisions are not applicable to facilities under the cognizance of other heads of IC 
elements.  

2.

 

The AO, and when appropriate the information systems (ISs) authorizing official(s), 

shall collaborate and approve the introduction and use of PEDs into a SCIF.  

3.

 

Outside the U.S., heads of intelligence elements may approve PED usage by waiver 

and include the following:  

 

Defined mission need for PED usage.  

 

Defined period of time.  

 

Statement of residual risk.  

4.

 

Within the U.S., if the CSA determines the risk from PEDs to SCI under their 

cognizance is acceptable, taking a PED into the SCIF may be allowed with the following 
restrictions:   

a)

 

A complete risk assessment addressing each component of risk must be 

completed.   

b)

 

Only PEDs with low risk may be allowed entry to a SCIF.  

c)

 

Mitigation shall be applied to PEDs evaluated to be high and medium risk to 

reduce the PED risk to low before the device may be allowed entry.   

d)

 

Assessments may result in a CSA determination to prohibit specific PEDs; any 

determination shall be applied to all SCIFs under the CSA‟s cognizance.  

5.

 

Government-owned PEDs, with physically disconnected wireless capability, may be 

approved to process and/or be connected to a government classified or unclassified 
information system (IS) provided the following apply:  

a)

 

Use and storage of the PED is specified in the System Security Plan for the 

government system to which it is connected. 

b)

 

The PED is accredited by the authorizing official for the IS.  

6.

 

Contractor-owned and government-sponsored PEDs, with physically disconnected 

wireless capability, may be approved to process and/or be connected to a government 
classified or unclassified IS provided the following apply:  

a)

 

Use and storage is specified in the System Security Plan for the government 

system to which it is connected.  

b)

 

The PED is accredited by the Authorizing Official for the IS. 

 

            UNCLASSIFIED 

Chapter 10 

 

 

Portable Electronic Devices 

 

 

 

 

69 

UNCLASSIFIED 

c)

 

Use and storage is specified in the appropriate contract(s) to include the 

government‟s right to seize if and when necessary.  

B.

 

Prohibitions 

1.

 

Personally-owned PEDs are prohibited from processing SCI.  Connecting personally-

owned PEDs to an unclassified IS inside SCIFs may only be done when wireless 
capability is physically disconnected and has the approval of the AO for the IS.  

2.

 

Personally-owned PEDs are prohibited in SCIFs outside the U.S.  If the CSA 

determines that mission requirements dictate a need, government- or contractor-owned 
PEDs may be permitted in a SCIF by specific exception or if the CSA determines the risk 
is low.  

3.

 

If a PED is transported outside the U.S. and left unattended or physical control is lost, 

that device shall not be reintroduced into a SCIF.  

C.

 

PED Risk Levels 

1.

 

General Information 

a)

 

Levels of risk are based on the functionality of PEDs.  

b)

 

The CSA and appropriate authorizing official for the IS (when a portable IS is 

involved) will determine risk level and mitigation requirements for devices not 
addressed.  

2.

 

Low-, Medium-, and High-risk PEDs 

a)

 

Low-risk PEDs are devices without recording or transmission capabilities and 

may be allowed into a SCIF by CSAs without mitigation.  Low-risk PEDs include, 
but are not limited to, the following:  

 

Electronic calculators, spell checkers, language translators, etc.  

 

Receive-only pagers.  

 

Audio and video playback devices with volatile storage capability.  

 

Radios (receive-only).  

 

Infrared (IR) devices that convey no intelligence data (e.g., text, audio, video, 
etc.), such as an IR mouse or remote control.  

b)

 

Medium-risk PEDs are devices with built-in features that enable recording or 

transmitting digital text, digital images/video, or audio data; however, these features 
can be physically disabled.  Medium-risk PEDs may be allowed in a SCIF by the 
CSA with appropriate mitigations.  Examples of medium-risk PEDs include, but are 
not limited to, the following:  

 

Voice-only cellular telephones.  

 

Portable ISs, such as personal digital assistants (PDAs), tablet personal 
computers, etc.  

 

            UNCLASSIFIED 

Chapter 10 

 

 

Portable Electronic Devices 

 

 

 

 

70 

UNCLASSIFIED 

 

Devices that may contain or be connected to communications modems  

 

Devices that have microphones or recording capabilities  

 

Optical technologies such as infrared (IR) other than those identified in 
paragraph 10.C.2. above  

c)

 

High-risk PEDs are those devices with recording and/or transmitting capabilities 

that require more extensive or technically complex mitigation measures to reduce the 
inherent risk or those that cannot be sufficiently mitigated with current technology. 
The CSA may approve entry and use of government- and contractor-owned PEDs for 
official business provided mitigation measures are in place that reduces the risk to 
low.  Examples include, but are not limited to, the following:  

 

Electronic devices with RF transmitting capabilities including wireless 
devices (WiFi/IEEE 802.11, Bluetooth, etc.).  

 

Photographic, video, and audio recording devices. 

 

Multi-function cellular telephones. 

D.

 

Risk Mitigation 

1.

 

Heads of IC elements shall establish risk mitigation programs if high- or medium-risk 

PEDs are allowed into SCIFs.  

2.

 

Risk mitigation programs shall contain the following elements:  

a)

 

Formal approval process for PEDs. 

b)

 

Initial and annual refresher training for those individuals with approval to bring 

PEDs into a SCIF. 

c)

 

Device mitigation compliance documents listing the specific PEDs, their 

permitted use, required mitigations, and residual risk after mitigation.  

d)

 

A user agreement that specifies the following:  

(1)

 

The USG or a designated representative may seize the PED for physical and 

forensic examination at the government‟s discretion.  

(2)

 

The USG and the designated representative are not responsible for any 

damage or loss to a device or information stored on personally-owned PEDs 
resulting from physical or forensic examination.  

3.

 

 Risk mitigation programs may include the following elements:  

a)

 

Registration of PED serial numbers.  

b)

 

PED security training program. 

c)

 

Reporting procedures for loss or suspected tampering.  

d)

 

Labeling approved PEDs for easy identification.  

 

            UNCLASSIFIED 

Chapter 10 

 

 

Portable Electronic Devices 

 

 

 

 

71 

UNCLASSIFIED 

e)

 

Electronic detection equipment to detect transmitters/cell phones. 

4.

 

The following sample table may be used to identify PED capabilities that could be 

allowed or prohibited, and capabilities that require mitigation and mitigation methods.  

 

 

 

            UNCLASSIFIED 

Chapter 10 

 

 

Portable Electronic Devices 

 

 

 

 

72 

UNCLASSIFIED 

PED 

Sample

 Table 

PED Functionalities 

Introduction 

Permitted 

Approval &/or 

Registration 

Required 

Mitigation 

Required Prior 

to Use 

PED Use 

Permitted 

Single-function RF receiver (Pager, 
AM/FM Radio, etc.)

1

 

Yes 

No 

None 

Yes 

CD Player

2

 

Yes 

No 

None 

Yes 

Medical devices

3

 

Yes 

Yes 

None 

Yes 

Infrared (IR) capability 

Yes 

Yes 

Metal Tape

4

 

Yes

 

PEDs with microphone ports  

Yes 

Yes 

Disable wiring or 

use adapter/erase 

plug

Yes

 

MP3 players (without record or RF 
capability) 

Yes 

Yes 

Yes 

Yes 

Cell phone

6

 

Yes 

No 

Battery removed

No 

RF transmitter

8

 

Prohibited 

 

 

Prohibited 

Wireless transmitting capabilities 

Prohibited 

 

 

Prohibited 

Personally owned laptops 

Prohibited 

 

 

Prohibited 

Any device capable of recording 
images (photographic, video) or audio 
including devices connected to 
memory sticks, thumb drives or flash 
memory. 

Prohibited 

 

 

Prohibited 

Personally owned PEDs capable of 
connecting to systems within the SCIF 
without interface cables or cradles.

9

 

Prohibited 

 

 

Prohibited 

                                                 

1

 

RF Receiver may not have external cabling or contain any internal or external connectivity capabilities.

 

2

 

CD players capable of playing CD, CD-R, CD-RW, and MP3 formats are permitted.  Only commercially produced media is allowed.  No 

personally produced CDs are allowed in SCIFs.

 

3

 

Medical devices are exceptions to these requirements.

 

4

 

Metal tape must be a minimum of 3 mils (.003 inch) thick and completely cover the IR port while within SCIF.

 

5

 

Microphone wires must be cut/disabled on non-laptop PEDs. An adapter/erase plug must be inserted into laptop external microphone ports.  

Any adaptor that is designed for the external microphone port may be used provided that the adapter does not provide any functionality other than 
disabling the internal microphone.

 

6

 

Single-function cell phone is defined as a cellular phone with no additional capabilities (can only be used for voice communications over a 

cellular network, storage of speed dial and caller ID information is permitted).

 

7

 

Cell phones must be turned off and the battery removed while in the SCIF. In addition, multi-function cell phones must be approved and meet 

all other mitigation requirements.

 

8

 

RF transmitter is defined as any radio frequency transmitter, except single-function cell phones that are addressed separately.

 

9

 Excludes mitigated IR function.  Cables and cradles for personally owned PEDs are prohibited. 

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

73 

UNCLASSIFIED 

Chapter 11.

 

Telecommunications Systems  

A.

 

Applicability 

1.

 

This guidance is compatible with, but may not satisfy, security requirements of other 

disciplines such as Information Systems Security, Communications Security (COMSEC), 
Operational Security (OPSEC), or TEMPEST.   

2.

 

This section outlines the security requirements that shall be met to ensure the 

following:  

 

Protection of information.  

 

Configuration of unclassified telecommunications systems, devices, features, and 
software.  

 

Access control.  

 

Control of the cable infrastructure.  

B.

 

Unclassified Telephone Systems  

1.

 

A baseline configuration of all unclassified telephone systems, devices, features, and 

software shall be established, documented, and included in the SCIF FFC.  

2.

 

The AO shall review the telephone system baseline configuration and supporting 

information to determine if the risk of information loss or exploitation has been suitably 
mitigated.   

3.

 

When security requirements cannot be met, unclassified telephone equipment shall be 

installed and maintained in non-discussion areas only.  

4.

 

When not in use, unclassified telephone systems shall not transmit audio and shall be 

configured to prevent external control or activation, technical exploitation, or penetration.   

5.

 

Unclassified telephone systems shall incorporate physical and software access 

controls to prevent disclosure or manipulation of system programming and data. The 
following specific requirements shall be met:  

a)

 

On-hook and off-hook audio protection shall be provided by equipment identified 

by the National Telephone Security Working Group within CNSSI 5006, National 
Instruction for Approved Telephone Equipment, or an equivalent TSG 2 system 
configuration within an AO-approved controlled space.  

b)

 

If a Computerized Telephone System (CTS) is selected for isolation, it shall be 

installed and configured as detailed in TSG 2 with software and hardware 
configuration control and audit reporting (such as station message detail reporting, 
call detail reporting, etc.).  

c)

 

System programming shall not include the ability to place, or keep, a handset off-

hook.   

 

 

 

 

 

 

 

Content      ..     15      16      17      18     ..