Military reference books and manuals (2009-2023, Volume 2) - page 18

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 2)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     16      17      18      19     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 2) - page 18

 

 

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

74 

UNCLASSIFIED 

d)

 

Configuration of the system shall ensure that all on-hook and off-hook 

vulnerabilities are mitigated.  

e)

 

Equipment used for administration of telephone systems shall be installed inside 

the SCIF or a controlled area where access is limited to authorized personnel.   

f)

 

When local or remote CTS administration terminals are not contained within a 

controlled area and safeguarded against unauthorized manipulation, the use of CNSSI 
5006 approved telephone instruments shall be required, regardless of the CTS 
configuration.  

g)

 

Speakerphones and audio conferencing systems shall not be used on unclassified 

telephone systems in SCIFs.  Exceptions to this requirement may be approved by the 
AO when these systems have sufficient audio isolation from other classified 
discussion areas in the SCIF and procedures are established to prevent inadvertent 
transmission outside the SCIF.  

h)

 

Features used for voice mail or unified messaging services shall be configured to 

prevent access to remote diagnostic ports, internal dial tone, and dial plans.  

i)

 

 Telephone answering devices and facsimile machines shall not contain features 

that introduce security vulnerabilities, e.g., remote room monitoring, remote 
programming, or other similar features that may permit off-premise access to room 
audio.  

j)

 

All unclassified telephone systems and associated infrastructure shall be 

physically isolated from classified information and telecommunications systems in 
accordance with DNI and CNSS TEMPEST guidance.  

k)

 

The security requirements and installation guidelines contained in the National 

Telecommunications Security Working Group (NTSWG) publication CNSSI 5000 
shall be followed for Voice over Internet Protocol (VoIP) systems installed in a SCIF.  

C.

 

Unclassified Information Systems  

1.

 

Unclassified information systems shall be safeguarded to prevent hardware or 

software manipulation that could result in the compromise of data.  

2.

 

Information systems equipment with telephonic or audio features shall be protected 

against remote activation and/or removal of audio (analog or digitized) information.  

3.

 

Video cameras used for unclassified video teleconferencing and video recording 

equipment shall be deactivated and disconnected when not in use.  

4.

 

 Video devices shall feature a clearly visible indicator to alert SCIF personnel when 

recording or transmitting.  

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

75 

UNCLASSIFIED 

D.

 

Using Closed Circuit Television (CCTV) to Monitor the SCIF Entry 

Point(s) 

1.

 

CCTV may be used to supplement the monitoring of a SCIF entrance and to record 

events for investigation.  

2.

 

The system shall present no technical security hazard to the SCIF.  

3.

 

The system and all components, including communications and control lines, shall be 

exterior to the SCIF perimeter.  

4.

 

The system may provide a clear view of the SCIF entrance but not enable the viewer 

to observe classified information when the door is open nor external control pads or 
access control components that would enable them to identify PINs.  

E.

 

Unclassified Wireless Network Technology   

1.

 

The use of devices or systems utilizing wireless technologies pose a high risk and 

require approval from the AO, CTTA, and IT systems approving authority prior to 
introduction into the SCIF.   

2.

 

Wireless systems shall meet all TEMPEST and TSCM requirements and shall be 

weighed against the facilities overall security posture (i.e., facility location, threat, as well 
as any compensatory countermeasures that create SID) when evaluating these systems.  

3.

 

All separation and isolation standards provided in TEMPEST standards are applicable 

to unclassified wireless systems installed or used in SCIFs.   

F.

 

Environmental Infrastructure Systems    

1.

 

The FFC shall include information on whether or not environmental infrastructure 

systems (also referred to as building maintenance systems) are located in the SCIF.  
Examples include the following:  

 

Premise management systems 

 

Environmental control systems 

 

 Lighting and power control units 

 

Uninterrupted power sources     

2.

 

The FFC shall identify all external connections for infrastructure systems that service 

the SCIF.  Examples of the purpose of external connections include the following: 

 

Remote monitoring  

 

Access and external control of features and services 

 

Protection measures taken to prevent malicious activity, intrusion, and 
exploitation  

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

76 

UNCLASSIFIED 

G.

 

Emergency Notification Systems  

1.

 

The introduction of electronic systems that have components outside the SCIF 

perimeter is prohibited, with the following exceptions:  

a)

 

The system is approved by the AO.  

b)

 

The system is required for security purposes.  

c)

 

The system is required under life safety regulations.  

2.

 

If required, and speakers or other transducers are part of a system that is not wholly 

contained in the SCIF but are installed in the SCIF for life safety or fire regulations, the 
system must be protected as follows:  

a)

 

All incoming wiring shall breach the SCIF perimeter at one point.  TEMPEST or 

TSCM concerns may require electronic isolation and shall require review and 
approval by the CTTA.  

b)

 

One-way (audio into the SCIF) communication systems shall have a high gain 

amplifier.  

c)

 

Two-way communication systems shall only be approved when absolutely 

necessary to meet safety/security requirements.  They shall be protected so that audio 
cannot leave the SCIF without the SCIF occupants being alerted when the system is 
activated.   

d)

 

All electronic isolation components shall be installed within the SCIF and as close 

to the point of SCIF penetration as possible.  

H.

 

Systems Access    

1.

 

Installation and maintenance of unclassified systems and devices supporting SCIF 

operations may require physical or remote access.  The requirements outlined in this 
section shall apply to telecommunications devices located within the SCIF or in a 
controlled area outside the SCIF.  

2.

 

Installation and maintenance personnel requiring physical access shall possess the 

appropriate clearance and access, or will be escorted and monitored at all times within the 
SCIF by technically knowledgeable, U.S. SCI-indoctrinated personnel.  

3.

 

Remote maintenance shall be protected against manipulation or activation.  

4.

 

All capabilities for remote maintenance and diagnostic services shall be specified in 

the FFC.  

5.

 

The FFC shall identify all procedures and countermeasures to prevent unauthorized 

system access, unauthorized system modification, or introduction of unauthorized 
software.  

6.

 

Remote maintenance and diagnosis may be performed from a SCIF or an adjacent 

controlled area over a protected link in accordance with FIPS AES standards.  

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

77 

UNCLASSIFIED 

7.

 

 Telephone systems only may be accessed over an unclassified telephone line as 

specified in TSG 2 Standard, Section 4.c.  

I.

 

Unclassified Cable Control  

1.

 

To the extent possible, all telecommunications cabling shall enter the SCIF through a 

single opening and allow for visual inspection.  

2.

 

Cable, either fiber or metallic, shall be accounted for from the point of entry into the 

SCIF.   

a)

 

The accountability shall identify the precise use of every cable through labeling.   

b)

 

Log entries may also be used.   

c)

 

Designated spare conductors shall be identified, labeled, and bundled together.  

3.

 

Unused conductors shall be removed.  If removal is not feasible, the metallic 

conductors shall be stripped, bound together, and grounded at the point of ingress/egress.  

4.

 

Unused fiber shall be uncoupled from the interface within the SCIF, capped, and 

labeled as unused fiber.   

J.

 

References 

1.

 

Overview 

a)

 

The NTSWG publishes guidance for the protection of sensitive information and 

unclassified telecommunications information processing systems and equipment.  

b)

 

NTSWG documents are currently in transition from TSG/NTSWG documents to 

Committee on National Security Systems (CNSS) publications.  

c)

 

The List of References is provided for use by personnel concerned with 

telecommunications security.  

2.

 

List of References 

a)

 

TSG Standard 1 (Introduction to Telephone Security).  Provides telephone 

security background and approved options for telephone installations in USG 
sensitive discussion areas.  

b)

 

TSG Standard 2 (TSG Guidelines for Computerized Telephone Systems) and 

Annexes.  Establishes requirements for planning, installing, maintaining, and 
managing CTS, and provides guidance for personnel involved in writing contracts, 
inspecting, and providing system administration of CTS.  

c)

 

TSG Standards 3, 4, 5, and CNSSI 5001.  Contains design specifications for 

telecommunication manufacturers and are not necessarily applicable to facility 
security personnel.  

d)

 

CNSSI 5000.  Establishes requirements for planning, installing, maintaining, and 

managing VoIP systems.  

 

            UNCLASSIFIED 

Chapter 11 

 

 

Telecommunications Systems 

 

 

 

 

78 

UNCLASSIFIED 

e)

 

CNSSI 5006. Lists approved equipment which inherently provide on-hook 

security. 

f)

 

NTSWG Information Series (Computerized Telephone Systems).  A Review of 

Deficiencies, Threats, and Risks, December 1994). Describes deficiencies, threats, 
and risks associated with using computerized telephone systems.  

g)

 

NTSWG Information Series (Executive Overview, October 1996).  Provides the 

salient points of the TSG standards and presents them in a non-technical format.  

h)

 

NTSWG Information Series (Central Office (CO) Interfaces, November 1997).  

Provides an understanding of the types of services delivered by the local central 
office and describes how they are connected to administrative telecommunications 
systems and devices.  

i)

 

NTSWG/NRO Information Series (Everything You Always Wanted to Know 

about Telephone Security…but were afraid to ask, 2nd Edition, December 1998). 
Distills the essence of the TSG standards (which contain sound telecommunications 
practices) and presents them in a readable, non-technical manner.  

j)

 

NTSWG/NRO Information Series (Infrastructure Surety Program…securing the 

last mile, April 1999).  Provides an understanding of office automation and 
infrastructure system protection that contributes to SCIF operation.  

k)

 

NTSWG Information Series (Computerized Telephone Systems Security Plan 

Manual, May 1999).  Assists to implement and maintain the “secure” operation of 
CTSs as used to support SCIF operations.  (The term “secure” relates to the safe and 
risk-free operation, not the use of encryption or a transmission security device.)  

l)

 

Director of National Intelligence, Intelligence Community Directive 702, 

Technical Surveillance Countermeasures.  

m)

 

Director of National Intelligence, Intelligence Community Directive 503, 

Intelligence Community Information Technology Systems Security Risk 
Management, Certification and Accreditation.  

n)

 

SPB Issuance 00-2 (18 January 2000).  Infrastructure Surety Program and the 

Management Assessment Tool. 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

79 

UNCLASSIFIED 

Chapter 12.

 

  Management and Operations 

A.

 

Purpose 

To establish safeguards and procedures necessary to prevent the unauthorized disclosure 
of SCI and other classified national security information in SCIFs.  To define 
administrative processes that shall provide a secure operating environment and enable 
adequate security oversight, management, and operations of SCIFs  

B.

 

SCIF Repository 

1.

 

As required by ICD 705, the DNI shall manage an inventory of information on all 

SCIFs which shall be reported to the DNI via the SCIF repository not later than 180 days 
after the effective date of ICD 705 and updated no later than 30 days after changes occur 
thereafter.  

2.

 

Reportable SCIF Administrative Information: 

 

SCIF ID 

 

AO ID 

 

Location of SCIF 

o

 

In U.S. 

o

 

Outside U.S.  

o

 

Under COM 

 

SCIF Type 

o

 

Closed Storage 

o

 

Open Storage 

o

 

SWA 

o

 

TSWA 

o

 

T-SCIF 

 

SID 

 

Initial Accredited Date 

 

Re-Accreditation Date 

 

Review date 

 

Waivers 

 

Date waiver approved 

 

Waiver approval authority/ID 

 

Exceeded standards 

 

Does not meet standards 

 

Date waiver expires 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

80 

UNCLASSIFIED 

C.

 

SCIF Management 

1.

 

SO Responsibilities: 

a)

 

The SCIF SO shall be responsible for all aspects of SCIF management and 

operations to include security policy implementation and oversight.  

b)

 

The SO shall prepare a comprehensive Standard Operating Procedure (SOP) that 

documents management and operations of the SCIF.  

c)

 

The SO shall review the SOP at least annually and revise it when any aspect of 

SCIF security changes.  

d)

 

The SO shall issue and control all SCIF keys.  Locks shall be changed when a key 

is lost or is believed to be compromised.  

e)

 

The SO shall conduct annual self-inspections to ensure the continued security of 

SCIF operations, identify deficiencies, and document corrective actions taken. 
Inspection results shall be forwarded to the AO and copies retained by the SO until 
the next inspection.  

f)

 

 The SO shall create an emergency plan to be approved by the AO.  Plans shall be 

reviewed and updated annually and all SCIF occupants shall be familiar with the 
plans.  Drills shall be conducted as circumstances warrant, but at least annually. The 
emergency plan may be an extension of an overall department, agency, or installation 
plan.  

(1)

 

For SCIFs within the U.S., emergency plans shall address the following:  

 

Fire 

 

Natural disaster 

 

Civil unrest 

 

Intrusion detection system failures 

 

Admittance of emergency personnel 

 

The protection of SCIF occupants and classified information 

 

Evacuation requirements and emergency destruction 

(2)

 

For SCIFs outside the U.S., emergency plans shall address all of the above 

and shall include instructions for the emergency destruction or removal of SCI 
where political instability, terrorism, host country attitudes, or criminal activity 
suggest the possibility that a SCIF may be overrun.  

g)

 

The SO shall control passwords to access the maintenance mode of copiers and 

other office equipment.  

h)

 

The SO shall develop an SOP that addresses actions to be taken when IDS 

maintenance access is required. 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

81 

UNCLASSIFIED 

2.

 

Required SCIF Documentation 

a)

 

Copies of all documents relating to SCIF accreditation shall be maintained by the 

SCIF SO and include, but not limited to, the following:  

 

SCIF accreditation 

 

Fixed facility checklist 

 

Construction security plan  

 

CTTA evaluation 

 

IS accreditation 

 

SOPs 

 

The results of the final acceptance test of the original system installation and 
any tests to system modifications made thereafter 

 

Emergency plan 

b)

 

As applicable, the following documents shall be maintained by the SCIF SO:   

 

TSCM reports 

 

Co-utilization agreements 

 

Memoranda of agreement  

 

Self-inspection reports 

 

Compartmented area checklist 

 

Shipboard SCIF checklist  

 

Aircraft/UAV checklist 

 

A copy of the CRZH certificate (UL 2050)  

D.

 

SOPs 

1.

 

A comprehensive SOP that documents management and operations of the SCIF shall 

be prepared by the SO.  

2.

 

The SOP shall be included in the accreditation package and approved by the AO.  

3.

 

All individuals assigned to, or having unescorted access to, the SCIF shall be familiar 

with and adhere to the SOP.  

4.

 

All SOP revisions shall be provided to the AO for approval.  

5.

 

SOPs shall be tailored to a specific SCIF. 

6.

 

SOPs shall include specific areas of security concern as defined by program or 

mission requirements.  

7.

 

The following are examples of subjects that should be addressed in an SOP:  

 

Self-inspections 

 

Security incidents and violations 

 

Alarm systems and response requirements 

 

Opening and closing procedures 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

82 

UNCLASSIFIED 

 

Access controls 

 

Visitor access 

 

Escort procedures 

 

Equipment maintenance procedures 

 

Handling, processing, and destruction of classified material 

 

Badge procedures 

 

End-of-day security procedures 

 

Personnel and package inspection procedures 

 

Secure communications device instructions 

E.

 

Changes in Security and Accreditation 

1.

 

Changes affecting the security posture of the SCIF shall be immediately reported by 

the SO to the AO to include any corrective or mitigating actions taken.  

2.

 

If an AO determines that SCIF security conditions are unsatisfactory, SCIF 

accreditation may be suspended or revoked.  

a)

 

All appropriate authorities and SCIF occupants shall be immediately notified and 

the SCIF closed until deficient conditions are corrected.  

b)

 

All SCI material shall be relocated to another SCIF.  

F.

 

General 

1.

 

Except for law enforcement officials or other personnel required to be armed in the 

performance of their duties, firearms and other weapons are prohibited in SCIFs.  

2.

 

Photography, video, and audio recording equipment are restricted but may be 

authorized for official purposes as documented in the SOP.  

3.

 

Procedures shall be established to control IT storage media upon entering or exiting a 

SCIF in accordance with ICD 503 (Intelligence Community Information Technology 
Systems Security Risk Management, Certification and Accreditation).  

4.

 

SCIF perimeter doors shall remain closed and controlled at all times.  When a door 

needs to be open, it shall be continually monitored by an SCI-indoctrinated individual.  

5.

 

All SCIF occupants shall be familiar with emergency plans and drills shall be 

conducted as circumstances warrant, but at least annually.  

6.

 

Where the risk of hostile action is significant, SCI materials shall be maintained at an 

absolute minimum. 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

83 

UNCLASSIFIED 

G.

 

Inspections 

1.

 

SCIF inspections shall be performed by the AO, or designee, prior to accreditation.   

2.

 

Heads of IC elements shall conduct periodic security reviews to ensure the efficiency 

of SCIF operations, identify deficiencies, and document corrective actions taken.  All 
relevant documentation associated with SCIF accreditation, inspections, and security 
administration may be subject to review.   

3.

 

Periodic inspections shall be conducted based on threat, facility modifications, 

sensitivity of programs, past security performance, or at least every five years. 

4.

 

SOs shall conduct annual self-inspections to ensure the continued security of SCIF 

operations, identification of deficiencies, and to document corrective actions taken. 
Inspection results shall be forwarded to the AO and copies retained by the SO until the 
next inspection. 

5.

 

Authorized inspectors shall be admitted to a SCIF without delay or hindrance when 

inspection personnel are properly certified to have the appropriate level of security 
clearance and SCI indoctrination for the security level of the SCIF. 

6.

 

Short-notice or emergency conditions may warrant entry without regard to the normal 

SCIF duty hours. 

7.

 

Government-owned equipment needed to conduct SCIF inspections will be admitted 

into the SCIF without delay. Specifically, equipment for TEMPEST or Technical 
Surveillance Countermeasures (TSCM) testing shall be admitted to a SCIF as long as the 
personnel operating the equipment are certified to have the appropriate level of security 
clearance and SCI indoctrination. 

H.

 

Control of Combinations 

1.

 

Combinations to locks installed on security containers/safes, perimeter doors, 

windows, and any other opening should be changed in the following circumstances:  

a)

 

When a combination lock is first installed or used.  

b)

 

When a combination has been subjected, or believed to have been subjected, to 

compromise. 

c)

 

Whenever a person knowing the combination no longer requires access to it 

unless other sufficient controls exist to prevent access to the lock.  

d)

 

At other times when considered necessary by the SO.  

2.

 

When the lock is taken out of service, it will be reset to 50-25-50.  

3.

 

All combinations to the SCIF entrance doors should be stored in a different SCIF. 

When this is not feasible, alternative arrangements shall be made in coordination with the 
AO.  

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

84 

UNCLASSIFIED 

I.

 

De-Accreditation Guidelines 

SCIF closeouts and de-accreditations shall comply with the following procedures:  

1.

 

Inspect all areas, storage containers, and furniture for the presence of classified, 

sensitive, or proprietary information. 

2.

 

Reset safe combinations to 50-25-50 and lock the containers.  

3.

 

Affix written certification to all storage containers that the container does not contain 

classified, sensitive, or proprietary information.  The certification shall include the date of 
inspection and the name and signature of the inspector. 

4.

 

Ensure that reproduction and printing equipment is decertified or disposed of in 

accordance with AO guidance.  

5.

 

Dispose of, or relocate, SCI computer equipment, media, hard drives, and portable 

storage media as approved by the AO.  

6.

 

Request revocation of Automated Information Systems (AIS) accreditation. 

7.

 

Request revocation of SCIF accreditation. 

8.

 

If the SCIF will be used for another mission or project that requires alarms, transfer 

alarm service to the new activity. 

9.

 

If the SCIF will not be used for another mission or project and all classified 

information has been removed, the following shall occur:  

a)

 

Alarm service shall be discontinued.  

b)

 

Combinations on the entrance door and any GSA containers shall be changed to 

50-25-50.  

c)

 

All keys shall be accounted for.  

J.

 

Visitor Access 

1.

 

General Requirements 

a)

 

Visitor logs shall be used to record all SCIF visitors and include the following 

information:  

 

Visitor‟s full name 

 

Organization 

 

Citizenship 

 

Purpose of the visit 

 

Point of contact 

 

Date/time of the visit 

b)

 

Government-issued identification shall be required as a means of positive 

identification.  

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

85 

UNCLASSIFIED 

c)

 

Visitor logs shall be retained for two years after the date of the last entry.  

d)

 

Visitor clearance verification shall be accomplished using the DNI Scattered 

Castles database to the greatest extent possible.   

e)

 

Visitors whose clearances have not been verified may be permitted, under escort, 

entry into the SCIF; however, access to and/or discussion of classified information 
shall be denied pending clearance verification.  

f)

 

Visitors, SCIF occupants, and their possessions may be subject to screening and 

inspections to deter the unauthorized removal of classified material or the 
introduction of prohibited items or contraband.  

g)

 

Screening and inspection procedures shall be documented and approved by the 

AO.  

2.

 

SCIF Access by Uncleared and Emergency Personnel 

a)

 

Uncleared personnel shall be escorted at all times by cleared personnel.  

b)

 

The ratio of cleared escorts to uncleared personnel shall be determined on a case-

by-case basis by the SO.  

c)

 

Prior to assuming escort duties, all escorts shall receive a briefing by the SO or 

designee outlining their responsibilities.  

d)

 

Uncleared personnel shall be kept under observation at all times while in the 

SCIF.  Escorts shall ensure precautions are taken to preclude inadvertent access to 
classified information.   

e)

 

Lights, signs, or other alerting mechanisms or procedures shall be used to alert 

SCIF occupants of the presence of uncleared personnel. 

f)

 

Emergency personnel and equipment shall be allowed access to SCIFs and be 

escorted to the degree practical.  If exposed to classified information, they shall sign 
an inadvertent disclosure statement when feasible.  

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

86 

UNCLASSIFIED 

K.

 

Maintenance 

1.

 

SCI-indoctrinated maintenance personnel shall be used to the extent possible.  

2.

 

Procedures for performing maintenance on office equipment, including the use of 

diagnostic equipment, shall be documented in the SCIF SOP.  

3.

 

Computerized diagnostic equipment, to include associated hardware and software, 

shall be kept under control within a SCIF and shall be managed to prohibit the migration 
of classified data when connected to classified systems.  Procedures shall be documented 
in the SOP.  

4.

 

Passwords to access the maintenance mode of copiers and other office equipment 

shall be controlled by the SO. 

5.

 

Office equipment that is no longer serviceable, such as copiers and classified fax 

machines, shall be sanitized by having volatile memory erased and non-volatile memory 
and disk storage removed for terminal destruction.  

L.

 

IDS and ACS Documentation Requirements  

The following documents and records shall be maintained within the SCIF: 

1.

 

System Plans such as system design, equipment, and installation documentation.  

2.

 

MOAs established for external monitoring, response, or both, and which shall include 

the following information:  

 

Response time for response forces and SCIF personnel.  

 

Responsibilities of the response force upon arrival.  

 

 Maintenance of SCIF points of contact.  

 

Length of time response personnel are required to remain on-site.  

3.

 

Monitoring Station SOP and/or a copy of the monitoring station UL certificate. 

4.

 

Maintenance access SOP.  

5.

 

Records, logs, and archives.  

6.

 

Records of system testing (for two years) shall include the following information:  

 

Testing dates  

 

Names of individuals performing the test 

 

Specific equipment tested 

 

Malfunctions detected 

 

Corrective actions taken 

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

87 

UNCLASSIFIED 

7.

 

Records of guard or response force personnel testing. 

8.

 

The PCU shall contain a secured, non-volatile event (alarm) log capable of storing at 

least six months of events, or a printer shall be installed that provides real-time recording 
of openings, closings, alarms, trouble alarms, and loss of communications.  

a)

 

If the system has no provision for automatic entry into archive, the AO may 

authorize a manual logging system. 

b)

 

 Monitoring personnel shall record the time, source, type of alarm, and action 

taken. 

c)

 

The SCIF SO shall routinely review the historical records. 

d)

 

Results of investigations and observations by the response force shall also be 

maintained at the monitoring station. 

e)

 

Records of alarm annunciations shall be retained for two years. 

f)

 

Shunting or masking of any zone or sensor shall be logged in the system archives.  

g)

 

All maintenance periods shall be archived into the system.  

h)

 

An archive shall be maintained for all remote service mode activities.   

9.

 

Access Control Systems Records which include: 

a)

 

The active assignment of ID badge/card, PIN, level of access, entries, and similar 

system-related information  

b)

 

Records of personnel removed from the system which shall be retained for two 

years from the date of removal.  

10.

 

Records of security incidents (violations/infractions) regarding automated systems 

shall be retained by the SO for five years from the date of an incident or until 
investigations of system violations and incidents have been resolved.  

M.

 

Emergency Plan 

1.

 

The SO shall create an emergency plan.  

2.

 

The emergency plan shall be approved by the AO and maintained on-site for each 

accredited SCIF.  

3.

 

The emergency plan may be an extension of an overall department, agency, or 

installation plan.  

4.

 

The emergency plan shall address the following:  

 

Fire  

 

Natural disaster  

 

Civil unrest 

 

Admittance of emergency personnel into a SCIF 

 

The protection of SCIF occupants and classified information  

 

            UNCLASSIFIED 

Chapter 12 

 

 

Management and Operations 

 

 

 

 

88 

UNCLASSIFIED 

 

Evacuation requirements 

 

Emergency destruction 

5.

 

Plans shall be reviewed at least annually and updated as necessary.  

6.

 

All SCIF occupants shall be familiar with the plans and drills shall be conducted as 

circumstances warrant, but at least annually.  

7.

 

Where political instability, terrorism, host country attitudes, or criminal activity 

suggests the possibility that a SCIF may be overrun, emergency plans shall include 
instructions for the secure destruction or removal of SCI under adverse circumstances and 
include contingencies for loss of electrical power and non-availability of open spaces for 
burning or chemical decomposition of material.  

8.

 

Where the risk of hostile actions are significant, SCI holdings and reference materials 

shall be maintained at an absolute minimum required for current working purposes. If 
reference or other material is needed, it shall be obtained from other activities and 
returned or destroyed when no longer needed. 

 

            UNCLASSIFIED 

 

 

 

 

 

89 

 

Chapter 13.

 

  Forms and Plans 

 

 
 
 
 
 
 
 
 
 
 
 
 
 

This page intentionally left blank. 

 

 

 

            UNCLASSIFIED 

 

 

 

 

 

90 

 

 
 
 

 

CLASSIFY ACCORDING TO FACILITY SPONSOR 

CLASSIFICATION GUIDANCE 

 

 

            

Fixed Facility Checklist

 

 

 [Insert Org Name]

 

 
 
 

 
 

 
 

[Date] 

 
 

[Address] 

 

 

 

            UNCLASSIFIED 

 

 

 

 

 

91 

 

SCIF Fixed Facility Checklist 

 

CLASSIFY ACCORDING TO FACILITY SPONSOR CLASSIFICATION 

GUIDANCE 

CHECK Applicable blocks

 

 Domestic

 

  Overseas Not 

COM

 

[ ] 

Overseas COM

 

 

  Pre-construction, 

Complete Sections 
as Required by A/O

 

  Final FFC 

Accreditation

 

  Update/Page 

Change

 

 

Checklist Contents 

 
Section A:  General information 
 
Section B: 

Security-in-Depth 

 

 
Section C:  SCIF Security 
 
Section D:  Doors 
 
Section E:      Intrusion Detection Systems (IDS) 
 
Section F: 

Telecommunication Systems and Equipment Baseline 

 
Section G:  Acoustical Protection 
 
Section H:  Classified Destruction Methods 
 
Section I: 

Information Systems/TEMPEST/Technical Security 

 
 

 

 

            UNCLASSIFIED 

 

 

 

 

 

92 

 

List of Attachments 

 
 

--  TEMPEST Checklist           
--  Other Attachments as Required 

(Diagrams must be submitted ) 

 

Section A:  General Information

 

1.

 

SCIF Data

 

 

Organization/Company Name

 

 

 

SCIF Identification Number (

if applicable)

 

 

 

Organization subordinate to 

(if applicable)

 

 

 

Contract Number & Expiration Date 

(if 

applicable)

 

 

 

Concept approval Date/by 

(if applicable)

 

 

 

Cognizant Security Authority (CSA)

 

 

 

Defense Special Security Communication System Information 

(if applicable)

 

 

DSSCS Message Address

 

 

 

DSSCS INFO Address

 

 

 

If no DSSCS Message Address, please provide 
passing instructions

 

 

2.

 

SCIF Location

 

 

Street Address

 

 

 

Building Name/#

 

 

Floor(s)

 

 

 

Suite(s)

 

 

Room(s) #

 

 

 

City

 

 

Base/Post

 

 

 

State/Country

 

 

Zip Code

 

 

3.

 

Mailing Address (if different from SCIF location)

 

 

Street or Post Office Box

   

 

City

   

State

   

Zip Code

   

 

 

            UNCLASSIFIED 

 

 

 

 

 

93 

 

 

4.

 

Responsible Security Personnel

 

 

 

PRIMARY

 

ALTERNATE

 

 

Name

 

 

 

 

Commercial Phone 

 

 

 

 

DSN Phone

 

 

 

 

Secure Phone

 

 

 

 

STE Other Phone

 

 

 

 

Home

 

 

 

 

Secure Fax

 

 

 

 

Command or Regional Special Security Office/Name (SSO) 

(if applicable)

 

 

Commercial Phone

 

 

 

 

Other Phone

 

 

 

5.

 

E-Mail Address of Responsible Security Personnel

 

 

Classified

 

 

(Network/System Name & Level)

 

 

Unclassified

 

 

(Network/System Name)

 

 

Other

 

 

(Network/System Name)

 

6.

 

Accreditation Data  (Ref Chapter: 12E)

 

 

a.  Category/Compartments of SCI Requested: 
1)  Indicate storage requirement:

 

 

  Open

 

  Closed

 

  Continuous Operation

 

  None

 

 

2)  Indicate the facility type

 

 

  Permanent

 

  Temporary

 

  Secure Working Area

 

  TSWA

 

 

3)  Co-Use Agreements

 

  Yes

 

  No

 

If yes, provide sponsor:

 

 

b.  SAP(s) co-located  
      within SCIF

 

  Yes

 

  No

 

If yes, identify SAP Classification level 
(check all that apply)

 

 

  SCI

 

  Top Secret

 

  Secret

 

  Confidential

 

 
 

 

            UNCLASSIFIED 

 

 

 

 

 

94 

 

 
 

c.  SCIF Duty Hours

 

Hours to Hours:

 

Days Per Week:

 

 

d.  Total square footage that the SCIF occupies:

   

 

e.  Has or will CSA 
requested any 
waivers?

 

  Yes

 

  No

 

  N/A

 

If yes, attach a copy of 
approved waiver

 

 
 

 

Construction/Modification  (Ref: Chapter 3B)

 

 

Is construction or 
modification 
complete?

 

  Yes

 

  No

 

  N/A

 

If no, enter the expected date of 
completion

 

 
 
 

 

Was all 
construction 
completed in 
accordance with 
the CSP?

 

  Yes

 

  No

 

  N/A

 

If not, explain changes.

 

7.

 

Inspections  (Ref: Chapter 12G)

 

 

Has a TSCM Inspection been performed

 

  Yes

 

  No

 

 

If yes, provide the following

 

 

 

 

a.  TSCM Service completed by

   

On ________________

 

(Attach a copy of report)

 

 

Were deficiencies 
corrected?

 

  Yes

 

  No

 

  N/A

 

If no, explain

 

 

 

b.  Last physical security 
inspection by

 

 

On ________________

 

(Attach a copy of report)

 

 

Were deficiencies 
corrected?

 

  Yes

 

  No

 

  N/A

 

If no, explain

 

 

 

c.  Last Staff Assistance Visit by:

 

On ________________

 

(Attach a copy of report)

 

8.

 

REMARKS:

 

 

            UNCLASSIFIED 

 

 

 

 

 

95 

 

Section B:  Security-in-Depth

 

1.

 

Describe building exterior Security  (Ref: Chapter 2B)

 

 

a.  Is the SCIF located on a military installation, embassy 
     compound, USG compound or contractor compound with  
     a dedicated U.S. person response force?

 

  Yes

 

  No

 

 

b.  Is the SCIF located in an entire Building

 

  Yes

 

  No

 

 

c.  Is the SCIF located on a single floor of Building

 

  Yes

 

  No

 

 

d.  Is the SCIF located in a secluded area of Building 

 

  Yes

 

  No

 

 

e.  Is the SCIF located on a fenced compound with access  
     controlled vehicle gate and/or pedestrian gate?

 

  Yes

 

  No

 

 

Fence Type

 

 

Height

 

Does it surround 
the compound? 
How is it 
controlled?

 

How many gates?

 

Hours of usage?

 

How are they 
controlled when 
not in use?

 

 

1)

 

  Is the Fence  
     Alarmed?

 

If so, describe alarm systems (i.e. – Microwave)

 

 

2)  Fence Lighting

 

 

 

3)  Building Lighting

   

 

f.  Is there external CCTV 

 

     coverage?  If so, describe  

 

     the CCTV system.

 

      (include monitor locations on map)

 

 

 

g.  Guards

 

□  Yes

 

□  No

 

□  Static

 

□  Roving

 

 

 

Clearance level of guards 

(if applicable)

 

 

 

 

During what hours/days?

 

 

 

Any SCIF duties?

 

□  Yes

 

□  No

 

If yes, describe duties

 

 
 

 

            UNCLASSIFIED 

 

 

 

 

 

96 

 

2.

 

Describe Building Security 

(Please provide legible general floor plan of the SCIF perimeter)

 

 

Is the SCIF located in a 
controlled building 
with separate access 
controls, alarms, 
elevator controls, 
stairwell control, etc. 
required to gain access 
to building or elevator?

 

□  Yes

 

□  No

 

If yes, is SCIF 
controlled by bldg 
owners?

 

 

If controlled by 
SCIF owners, is 
alarm activation 
reported to SCIF 
owners by 
agreement?

 

□  Yes

 

□  No

 

□  Yes

 

□  No

 

 

b.  Construction Type

 

 

 

c.  Windows

 

 

 

d.  Doors

 

 

 

e.  Describe Bldg

 

     Access Controls

 

□  Continuous

 

□  Yes

 

  No

 

If no, during what hours?

 

 

 

Clearance level of guards 

(if 

applicable) 

Any SCIF duties?  If 
yes, describe duties?

 

 
 
 

During what 
hours/days?

 

□  Yes

 

  No

 

3.

 

Describe Building Interior Security

 

 

Are office areas 
adjacent to the SCIF 
controlled and 
alarmed?  If yes, 
describe adjacent areas 
and types of alarm 
systems.

 

 
 
 
 

□  Yes

 

□  No

 

Controlled by 
SCIF Owner?

 

 

If controlled by 
Bldg owner, alarm 
activation reported 
to SCIF owner by 
agreement?

 

□  Yes

 

□  No

 

□  Yes

 

□  No

 

 

            UNCLASSIFIED 

 

 

 

 

 

97 

 

 

4.

 

Security In-Depth

 

 

What external security attributes and/or features should the AO consider before 
determining whether or not this facility has Security In-Depth?  Please 
identify/explain all factors:

 

 
 
 

Section C:  SCIF Security

 

1.

 

How is access to the SCIF controlled  (Ref: Chapter 8)

 

 

a.  By Guard Force

 

□  Yes

 

  No

 

If yes, what is their minimum security 
clearance level?

 

 

b.  Is Guard Force Armed?

 

□  Yes

 

  No

 

  N/A

 

 

c.  By assigned personnel?

 

□  Yes

 

  No

 

If yes, do personnel have visual control 
of SCIF entrance door?

 

 

d.  By access control 
device?

 

□  Yes

 

  No

 

If yes, what kind?

 

 

□  Automated access control system

 

  Non-Automated

 

 

If Non-Automated

 

 

1.  Is there a by-pass key?

 

□  Yes

 

  No

 

  N/A

 

 

 

If yes, how is the by-pass key protected? 

 

 

2.  Manufacturer:

 

 

Model:

 

 

 

(Attach sheet if additional space is required for this information)

 

 

If Automated

 

 

1.  Is there a by-pass key?

 

□  Yes

 

  No

 

  N/A

 

 

 

If yes, how is the by-pass key protected? 

 

 

2.  Manufacturer:

 

 

Model:

 

 

 

(Attach sheet if additional space is required for this information)

 

 

3.  Are access control  

□  Yes

 

  No

 

If no, explain the physical protection 

 

            UNCLASSIFIED 

 

 

 

 

 

98 

 

      transmission lines 
      protected by 128-bit 
      encryption/FIBS 140?

 

provided.

 

 
 

 

4.  Is automated access control system located within a SCIF or an  
      alarmed area controlled at the 

SECRET

 level?

 

□  Yes

 

  No

 

 

5.  Is the access control system encoded and is ID data and PINs  
      restricted to SCI-indoctrinated personnel?

 

□  Yes

 

  No

 

 

6.  Does external access control outside SCIF have tamper  
      protection?

 

□  Yes

 

  No

 

 

7.  Is the access control device integrated with IDS

 

□  Yes

 

  No

 

  N/A

 

 

8.  Is the access control device integrated with a  
      LAN/WAN System?

 

□  Yes

 

  No

 

  N/A

 

2.

 

Does the SCIF have windows?  (Ref: Chapter 3F)

 

 

a.  Are they acoustically 
      protected?

 

  Yes

 

  No

 

  N/A

 

If yes, how?  Please explain

 

 

 

b.  Are they secured 
      against forced entry?

 

  Yes

 

  No

 

  N/A

 

If yes, how?  Please explain

 

 

 

c.  Are they protected 
      against visual 
      surveillance?

 

  Yes

 

  No

 

  N/A

 

If yes, how?  Please explain

 

 

3.

 

Do ventilation ducts penetrate the SCIF perimeter? (Ref: 
Chapter 3G)

 

□  Yes

 

  No

 

 

(Indicate all duct penetrations and their size on a separate floor plan as an attachment)

 

 

a.  Any ducts over 96 square inches that penetrate perimeter walls?

 

□  Yes

 

  No

 

 

 

If yes, how are they protected?

 

 

  IDS (Describe in  

     Section E)

 

  Bars/Grills/Metal  

     Baffles

 

  Other, please explain

 

 

 

Describe Protection:

 

 

b.  Inspection ports?

 

□  Yes

 

  No

 

 

 

If yes, are they within the 
SCIF?

 

□  Yes

 

  No

 

 

 

If no, are they secured?

 

□  Yes

 

  No

 

Please explain

 

 

            UNCLASSIFIED 

 

 

 

 

 

99 

 

 

 

c.  Do all ventilation ducts  
     penetrating the perimeter 
     meet acoustical requirements?

 

□  Yes

 

  No

 

 

(

NOTE:  

All ducts and vents, regardless of size may require acoustical protection)

 

 

 

If yes, how are they protected?

 

 

□  Metal Baffles

 

  Noise Generator

 

□  Z-Duct

 

  Other (Describe)

 

 

Describe the method of ventilation and duct work protection 

(if applicable)

 

4.

 

Construction  (Ref: Chapter 3B)

 

 

a.  Describe Perimeter Wall Construction:

 

 
 
 
 

 

b.  True ceiling (material and thickness)?

 

□  Yes

 

  No

 

 

c.  False ceiling?

 

□  Yes

 

  No

 

 

 

If yes, what is the type of ceiling material?

 

 

 

 

What is the distance between false and true 
ceiling?

 

 

 

d.  True floor (material and thickness)?

 

□  Yes

 

  No

 

 

e.  False floor?

 

□  Yes

 

  No

 

 

 

If yes, what is the type of false flooring?

 

 

 

 

What is the distance between false and true 
floor?

 

 

5.

 

REMARKS:

 

Section D:  Doors

 

1.

 

Describe SCIF primary entrance door construction (indicate on floor plan)  (Ref: 
Chapter 3E)

 

 

a.  Does the door and doorframe meet sound attenuation  
     requirements?

 

□  Yes

 

  No

 

 

 

If no, have acoustical countermeasures been employed?

 

□  Yes

 

  No

 

 

            UNCLASSIFIED 

 

 

 

 

 

100 

 

 

b.  Describe SCIF perimeter doors to include thickness and type of door. 

 

 

c.  Is an automatic door closer 
      installed?

 

□  Yes

 

  No

 

If no, please explain

 

 

 

d.  Is a door sweep/thresholds  
      installed?

 

□  Yes

 

  No

 

If no, please explain

 

 

 

e.  Is an acoustical/astragal strip 
      installed?

 

□  Yes

 

  No

 

If no, please explain

 

 

 

 

 

 

 

2.

 

Describe number and type of doors used for SCIF emergency exits and other 
perimeter doors including day access (show on floor plan) 
 

 

 

a.  Do the doors and doorframes meet sound attenuation  
      requirements?

 

□  Yes

 

  No

 

 

 

If no, have acoustical countermeasures been employed?

 

□  Yes

 

  No

 

 

b.  Has exterior hardware been removed?

 

□  Yes

 

  No

 

 

c.  Has local enunciator been installed?

 

□  Yes

 

  No

 

 

 

Describe how the door hinges exterior to the SCIF are secured against 
removal (if in an uncontrolled area).

 

 

  

 

3.

 

Locking Devices

 

 

a.  Is the primary entrance door equipped with a GSA-approved  
      pedestrian door deadbolt meeting Federal Specification  
      FF-L-2890 including lock meeting FF-L-2740A

 

□  Yes

 

  No

 

 

b.  List combination lock manufacturer, model number and group rating

 

 

Manufacturer:

 

 

Model Number:

 

 

c.  Does the entrance door stand open into an uncontrolled area?

 

□  Yes

 

  No

 

 

If yes, please describe tamper protection.

 

 

 

            UNCLASSIFIED 

 

 

 

 

 

101 

 

 

 

d.  Emergency exits and other perimeter doors:  Describe (locks, metal strip/bar,  
      deadbolts, local annunciation, and panic hardware). 
 

 

 

e.  Where is the lock combination(s) filed?  (Please identify the SCIF AO and SCIF  
      ID#)

 

4.

 

REMARKS:

 

 

 

 

 

 

 

Section E:  Intrusion Detection Systems

 

1.

 

General IDS Description  (Ref: Chapter 7A)

 

 

a.  Has the IDS configuration been approved by the AO?

 

□  Yes

 

  No

 

 

b.  Identity of IDS installer:

 

 

Identity of IDS monitoring firm:

 

 

c.  Premise Control Unit (PCU)

 

 

Manufacturer

 

Model Number

 

Tamper Protection

 

 

□  Yes

 

  No

 

 

d.  Is the PCU located inside the  
      SCIF perimeter (indicated on 
      floor plan)?

 

□  Yes

 

  No

 

If no, please explain

 

 

 

e.  Location of interior motion detection  
      protection

 

 

 

 

Accessible points of entry/perimeter?

 

□  Yes

 

  No

 

 

 

Any others?  Specify

 

□  Yes

 

  No

 

 

f.  Has the IDS alarm monitor station been installed to Underwriters  
     Laboratories certified standards?

 

□  Yes

 

  No

 

 

Contractor facility submit copy of Certificate

 

 

g.  Has the IDS passed AO or UL 2050 installation and acceptance  
      tests?

 

□  Yes

 

  No

 

 

 

If yes, attach a copy of certificate (Non-commercial proprietary system must 

 

            UNCLASSIFIED 

 

 

 

 

 

102 

 

answer all questions)

 

 

h.  High Security Switches Type I

 

□  Yes

 

  No

 

 

i.  High Security Switches Type II

 

□  Yes

 

  No

 

 

j.  Motion sensor (indicate sensor placement on a legible floor plan;  8 ½ x 11” or  
     11” x 17” paper)

 

 

k.  Are any other intrusion detection equipment sensors/detectors in 
      use?

 

□  Yes

 

  No

 

 

 

Please identify make, model and manufacturer and function (indicate on floor 
plan)

 

 

Make

 

Model

 

Manufacturer

 

Function

 

 

 

l.    Does the IDS extend beyond the SCIF perimeter?

 

□  Yes

 

  No

 

 

m.  Can the status of PCU be changed from outside IDS protection?

 

□  Yes

 

  No

 

 

 

If yes, is an audit conducted daily?

 

□  Yes

 

  No

 

 

n.  Do any intrusion detection equipment components have audio or 
      video capabilities?

 

□  Yes

 

  No

 

 

 

If yes, please explain.

 

 

o.  PCU Administrator SCI indoctrinated?

 

□  Yes

 

  No

 

 

p.  External Transmission Line Security:

 

 

q.  What is the method of line security?  National Institute of 
      Standards and Technology (NIST) FIBS AES encryption?

 

□  Yes

 

  No

 

 

1)  If yes, has the encryption been certified by NIST or another  
      independent testing laboratory?

 

□  Yes

 

  No

 

 

2)  If not NIST standard, is there an alternate?

 

□  Yes

 

  No

 

 

3)  If yes, please explain

 

 

 

4)  Does the alternate line utilize any cellular or other Radio  
      Frequency (RF) capability?

 

□  Yes

 

  No

 

 

Manufacturer

 

Model Number

 

 

 

r.  Does any part of the IDS use local or wide area network 
     (LAN/WAN)?

 

□  Yes

 

  No

 

  N/A

 

 

1)  Is the host computer dedicated solely for security  

□  Yes

 

  No

 

  N/A

 

 

            UNCLASSIFIED 

 

 

 

 

 

103 

 

      purposes?

 

 

2)  Is the host computer secured within an alarmed area  
      controlled at the 

SECRET

 or higher level?

 

□  Yes

 

  No

 

  N/A

 

 

3)  Is the host computer protected through firewalls or  
      similar devices?

 

□  Yes

 

  No

 

  N/A

 

 

4)  Is the password for the host computer unique for each  
      user and at least 8-characters long consisting of alpha, 
      numeric, and special characters?

 

□  Yes

 

  No

 

  N/A

 

 

5)  Is the password changed semi-annually?

 

□  Yes

 

  No

 

  N/A

 

 

6)  Are remote security terminals protected the same as the 
      host computer?

 

□  Yes

 

  No

 

  N/A

 

 

 

If no, please explain:

 

2.

 

Is emergency power available for the IDS?

 

□  Yes

 

  No

 

  N/A

 

 

Generator?

 

□  Yes

 

  No

 

 

 

If yes, how many hours?

 

 

Battery?

 

□  Yes

 

  No

 

 

 

If yes, how many hours?

 

3.

 

Where is the IDS alarm monitor station located?

 

4.

 

Does the monitor station have any remote capabilities 
(i.e., resetting alarms, issuing PINs, accessing/securing 
alarms, etc.?

 

□  Yes

 

  No

 

  N/A

 

 

 

If yes, please explain:

 

5.

 

Does the IDS have any automatic features (i.e., timed 
auto-secure, auto-access capabilities?

 

□  Yes

 

  No

 

  N/A

 

6.

 

Does the PCU/keypad have dial out capabilities?

 

□  Yes

 

  No

 

  N/A

 

7.

 

IDS response personnel

 

□  Yes

 

  No

 

  N/A

 

 

a.  Who provides initial alarm response?

 

 

b.  Does the response force have a security clearance?

 

□  Yes

 

  No

 

 

 

If yes, what is the clearance level?

 

 

c.  Do you have a written agreement with external response force?

 

□  Yes

 

  No

 

 

d.  Emergency procedures documented?

 

□  Yes

 

  No

 

 

e.  Response to alarm condition:  

 

______ Minutes

 

 

            UNCLASSIFIED 

 

 

 

 

 

104 

 

 

f.  Are response procedures tested and records maintained?

 

□  Yes

 

  No

 

 

 

If no, please explain:

 

 

g.  Has a catastrophic failure plan been approved by the CSA?

 

□  Yes

 

  No

 

8.

 

Does the IDS undergo semiannual testing?

 

□  Yes

 

  No

 

9.

 

Have IDS records been maintained?

 

□  Yes

 

  No

 

 

 

If no, please explain:

 

10.

 

REMARKS:

 

Section F:  Telecommunication Systems and Equipment Baseline

 

1.

 

Is the facility declared a “No Classified Discussion Area”?  (Ref: 
Chapter 11A)

 

□  Yes

 

  No

 

 

 

If yes, then the audio protection questions within this section may be 
identified as N/A

 

 

 

If the facility is declared a “No Classified 
Discussion Area”, are warning notices posted 
prominently within the facility?

 

□  Yes

 

  No

 

  N/A

 

2.

 

Does the facility have any unclassified telephones that are 
connected to the commercial public switch telephone network 
(PSTN)?

 

□  Yes

 

  No

 

 

 

What is the method of on-hook protection?

 

 

1)  CNSSI 5006 (TSG-6) approved telephone or instrument

 

□  Yes

 

  No

 

  N/A

 

 

(Please identify all telephone equipment/stations and/or instruments being used either below 

or as an attachment)

 

 

Manufacturer

 

 

Model Number

 

TSG Number 

(if applicable)

 

 

2)  CNSSI 5006 (TSG-6) approved disconnect device?

 

□  Yes

 

  No

 

  N/A

 

 

a.  Line disconnect?

 

□  Yes

 

  No

 

  N/A

 

 

b.  Ringer protection?

 

□  Yes

 

  No

 

  N/A

 

 

Manufacturer

 

 

Model Number

 

TSG Number 

(if applicable)

 

 

3)  CNSSI 5002 (TSG-2) configured computerized  
      telephone system (CTS)?

 

□  Yes

 

  No

 

  N/A

 

 

a.   If yes, please provide the following information about the CTS  

 

 

            UNCLASSIFIED 

 

 

 

 

 

105 

 

 

Manufacturer

 

 

Model

 

 

b.   If yes, please provide specific location of the CTS  

 

 

c.   How is the facility protecting the CTS physically controlled?  

 

 

d.   If yes, what is the clearance level (if any) of facility or area where the switch is  
       located and how is area controlled?  

 

 

e.   How are all cables, signal lines and intermediate writing frames between the SCIF 
      telephones and the CTS physically protected within a physically controlled space?

 

 

f.   Are all program media, such as tapes and/or disks, from the CTS 
      afforded physical protection from unauthorized alterations?

 

□  Yes

 

  No

 

 

g.   Is an up-to-date master copy of the CTS software program  
       maintained for confirmation and/or reloading of the operating 
       system?

 

□  Yes

 

  No

 

 

h.   Does the CTS have the capability to force or hold a telephone  
       station off-hook?

 

□  Yes

 

  No

 

 

i.   Does the CTS use remote maintenance and diagnostic procedures  
      or other remote access features?

 

□  Yes

 

  No

 

 

 

If yes, explain maintenance procedures

 

 

j.   Do the CTS installers and programmers have security clearances?

 

□  Yes

 

  No

 

 

 

If yes, at what access level (minimum established by AO)

 

 

 

If no, are escorts provided?

 

□  Yes

 

  No

 

 

4)  Is it a Voice over Internet Protocol (VOIP) phone  
      system (IPS) (Ref CNSSI 5000)?

 

□  Yes

 

  No

 

  N/A

 

 

a.  If yes, please provide the following information about the IPS

 

 

Manufacturer

 

 

Model Number

 

IPS Location

 

 

b.  Do all unclassified telephones within the facility have a  
      hold, mute and/or push-to-talk [handset] capability, 
      (for off-hook audio protection)?

 

□  Yes

 

  No

 

  N/A

 

 

 

If no, please explain?

 

 

c.  Is access to the facility housing the IPS physically controlled?

 

□  Yes

 

  No

 

 

d.  If yes, what is the clearance level (if any) of facility or area where the switch is  
      located and how is the area controlled?

 

 

 

 

 

 

 

 

Content      ..     16      17      18      19     ..