AFI33-203V3.pdf

PDF 2 MB Posted

Attached to
ICBM Medium Class Rocket Motor BAA Federal contract opportunity
Solicitation number
FA8219-13-R-7001
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

About this file

AFI 33-203 Vol 3 referenced within the DD 254

View the file

Other files for this federal contract opportunity

Other files attached to ICBM Medium Class Rocket Motor BAA, newest first.
File Type Posted
Questions_and_Answers.docx DOCX document
Medium_Class_Stage_III_SOO.pdf PDF
CDRL_package.pdf PDF
FA821913R7001_Solicitation.pdf PDF
BAAGuide.pdf PDF
PAP_BAA_24_Apr_13.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NOTICE: This publication is available digitally on the AFDPO WWW site at:

http://www.e-publishing.af.mil.

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

BY ORDER OF THE SECRETARY

OF THE AIR FORCE

AIR FORCE INSTRUCTION 33-203, VOLUME 3

2 NOVEMBER 2005

Communications and Information

EMISSION SECURITY COUNTERMEASURES

REVIEWS

OPR: HQ AFCA/EVPI

(Mr. Cyril Prikazsky, GS-13)

Certified by: SAF/XCIA (Mr. David G. Ferguson, GS-15)

Supersedes AFMAN 33-214, Volume 2, 21 September 2001

Pages: 195 Distribution: F

This Air Force instruction (AFI) implements the emission security (EMSEC) portion of Air Force Policy Directive (AFPD) 33-2, Information Protection (will become Information Assurance), and establishes Air Force information assurance (IA) countermeasures and EMSEC requirements for IA. This AFI provides guidance to all Air Force military, civilians, and contractor personnel under contract by the Department of Defense (DOD) that participate in the emission security program. This instruction applies to the Air National Guard (ANG). As part of IA, this AFI implements the National Security Telecommunications and Information Systems Security Memorandum (NSTISSM)/TEMPEST 2-95, (FOUO) RED/BLACK Installation Guidance (U). We encourage the use of extracts from this instruction. Additional security instructions and manuals are listed on the Air Force web site at Uniform Resources Locator (URL): http:/ /www.e-publishing.af.mil under Electronic Publications. Air Force Directory (AFDIR) 33-303, Compen-dium of Communications and Information Terminology, explains other terms. Direct questions or com-ments on the contents of this instruction, through appropriate channels, to Headquarters Air Force Communications Agency (HQ AFCA/EVPI AF-CTTA), 203 W. Losey Street, Room 2000, Scott AFB IL 62225-5222, or the EMSEC organizational e-mail box at afca.ctta.emsec@scott.af.mil. Refer recom-mended changes and conflicts, through appropriate channels, using Air Force (AF) Form 847, Recom-mendation for Change of Publication, to HQ AFCA/EASD, 203 W. Losey Street, Room 1100, Scott AFB IL 62225-5222. Send an information copy to Secretary of the Air Force (SAF/XCIA), 1800 Air Force Pentagon, Washington DC 20330-1800. Ensure that all records created as a result of processes pre-scribed in this publication are maintained in accordance with Air Force Manual (AFMAN) 37-123, Man-agement of Records (will become AFMAN 33-363), and disposed of in accordance with Air Force Records Information Management System (AFRIMS) Records Disposition Schedule (RDS) located at https://afrims.amc.af.mil/rds/index.cfm. See Attachment 1 for a glossary of references and supporting information.

mailto:afca.ctta.emsec@scott.af.mil https://afrims.amc.af.mil/rds/index.cfm http://www.e-publishing.af.mil

2 AFI33-203V3 2 NOVEMBER 2005

SUMMARY OF REVISIONS

This revision incorporates Interim Change IC 2005-1. Upon incorporation of IC 2005-1, the number of this publication changes from AFMAN 33-214, Volume 2, to AFI 33-203, Volume 3, to comply with Air Staff’s direction to incorporate all emission security (EMSEC) publications under the AFI 33-203 umbrella. It updates office symbols and publications throughout the entire document. A bar ( | ) indicates a revision from the previous edition.

Publication number throughout changes from AFMAN 33-214, Volume 2, to AFI 33-203, Volume 3.

Chapter 1— INTRODUCTION 8

1.1. General

1.2. Emission Security Process

1.3. Emission Security Countermeasures Reviews

1.4. Completing the Countermeasures Reviews

1.5. Maintaining Emission Security

1.6. Emission Security Testing

1.7. Emission Security Countermeasures

Chapter 2— THE INFORMATION SYSTEMS COUNTERMEASURES REVIEW 11

2.1. Introduction

2.2. Systematic Approach

2.3. Application Requirement

2.4. Determine the Inspectable Space

2.5. Identify Equipment TEMPEST Characteristics

2.6. Selecting Countermeasures

Table 2.1. Countermeasures Requirements

2.7. Estimating Cost

2.8. Analyzing the Results

2.9. Documenting the Results

2.10. Completing the Information Systems Countermeasures Review

Chapter 3— THE COMMUNICATIONS SYSTEMS COUNTERMEASURES REVIEW 17

3.1. Introduction

3.2. Installation Requirement

3.3. Transmitting Equipment

AFI33-203V3 2 NOVEMBER 2005 3

Table 3.1. Separation Requirements for Transmitters

Table 3.2. Separation Requirements for Signal and Control Wire Lines

3.4. Special Items

3.5. Estimating Cost

3.6. Analyzing the Results

3.7. Documenting the Results

3.8. Completing the Information Systems Countermeasures Review

Chapter 4— THE CRYPTOGRAPHIC EQUIPMENT COUNTERMEASURES REVIEW 21

4.1. Introduction

4.2. Installation Requirement

4.3. Secure Telephone Unit-III (STU-III), Secure Terminal Equipment (STE), and Like Items

4.4. Cryptographic System KIV-7

4.5. FORTEZZA For Classified (FFC)

4.6. Electronic Key Management System (EKMS)

4.7. All Other Cryptographic Equipment

4.8. Changing From Unclassified to Classified Processing

4.9. Analyzing the Results

4.10. Documenting the Results

4.11. Completing the Cryptographic Equipment Countermeasures Review

Chapter 5— COMPLETING THE COUNTERMEASURES REVIEWS 25

5.1. Introduction

5.2. Classification Marking

5.3. Authentication Documentation

5.4. Tracking and Address Information

5.5. Validating the Countermeasures Reviews

5.6. Inform the User

5.7. Date

5.8. Apply the Countermeasures

5.9. Emission Security Inspection

5.10. Waivers

5.11. Emission Security Certification

4 AFI33-203V3 2 NOVEMBER 2005

5.12. File Copy

5.13. Reassessments and Recertifications

Chapter 6— EMISSION SECURITY MAINTENANCE 29

6.1. Maintaining Equipment and Countermeasures

6.2. Maintenance Requirements

6.3. Ensuring the Integrity of TEMPEST-Certified Equipment

6.4. When Not to Maintain the TEMPEST Integrity

6.5. Transportation of Equipment for Maintenance

6.6. Repair Facilities

6.7. Emission Security Documentation-of-Maintenance Requirements

6.8. Disposing of TEMPEST-Certified Equipment

Chapter 7— EMISSION SECURITY TESTING 32

7.1. Purpose of Testing

7.2. Kinds of Emission Security Tests

7.3. When to Test

7.4. Requesting a Test

7.5. Emission Security Test Results

Chapter 8— EMISSION SECURITY COUNTERMEASURES 34

8.1. Introduction

8.2. Fundamentals of Compromising Emanations

8.3. Requirement -- Contain Compromising Emanations

8.4. Containing Radiated Compromising Emanations

8.5. Containing Conducted Compromising Emanations

8.6. RED and BLACK Concept

8.7. RED and BLACK Equipment

8.8. Countermeasure -- RED Equipment and BLACK Equipment Separation

8.9. Countermeasure -- RED Equipment and BLACK Wire Line Separation

8.10. Countermeasure -- RED Equipment and BLACK Power Line Separation

8.11. Countermeasure -- RED Equipment and BLACK Signal Ground Wire Separation. 40

8.12. Countermeasure -- RED Equipment and Fortuitous Conductor Separation

8.13. Countermeasure -- Low-Level Signaling

AFI33-203V3 2 NOVEMBER 2005 5

8.14. Signal Lines

8.15. RED and BLACK Wire Lines

8.16. Countermeasure -- RED Wire Line and BLACK Equipment Separation

8.17. Countermeasure -- RED Wire Line and BLACK Wire Line Separation

8.18. Countermeasure -- RED Wire Line and BLACK Power Line Separation

8.19. Countermeasure -- RED Wire Line and BLACK Signal Ground Wire Separation

8.20. Countermeasure -- RED Wire Line and Fortuitous Conductor Separation

8.21. Shielded Signal Wire Lines

8.22. Fiber Optic Signal Lines

8.23. Countermeasure -- Shielded RED Wire Lines

8.24. Countermeasure -- Shielded BLACK Wire Lines

8.25. Countermeasure -- BLACK Wire Line Isolation

8.26. RED and BLACK Power

8.27. Countermeasure -- RED Power

8.28. Countermeasure -- Filtered RED Power

8.29. Countermeasure -- RED Power Line and BLACK Equipment Separation

8.30. Countermeasure -- RED Power Line and BLACK Wire Line Separation

8.31. Countermeasure -- RED Power Line and BLACK Power Line Separation

8.32. Countermeasure -- RED Power Line and BLACK Signal Ground Wire Separation. 60

8.33. Countermeasure -- RED Power Line and Fortuitous Conductor Separation

8.34. Introduction to Grounds

8.35. RED and BLACK Signal Grounds

8.36. Countermeasure -- RED Signal Ground Wire and BLACK Equipment Separation. .. 65

8.37. Countermeasure -- RED Signal Ground Wire and BLACK Wire Line Separation

8.38. Countermeasure -- RED Signal Ground Wire and BLACK Power Line Separation. 67

8.39. Countermeasure -- RED Signal Ground Wire and BLACK Signal Ground Wire Separation

8.40. Countermeasure -- RED Signal Ground Wire and Fortuitous Conductor Separation

8.41. Countermeasure -- BLACK Signal Ground Wire and BLACK

Equipment Separation

8.42. Countermeasure -- BLACK Signal Ground Wire and BLACK

Wire Line Separation

6 AFI33-203V3 2 NOVEMBER 2005

8.43. Countermeasure -- BLACK Signal Ground Wire and BLACK

Power Line Separation

8.44. Countermeasure -- BLACK Signal Ground Wire and Fortuitous Conductor Separation

8.45. Ground Checks

8.46. Fortuitous Conductors

8.47. Countermeasure -- Fortuitous Conductor Isolation

8.48. Distribution Facilities

8.49. Countermeasure -- Distribution Facility Installation

8.50. Countermeasure -- TEMPEST-Certified Equipment

8.51. Countermeasure -- Shielding

8.52. Countermeasure -- BLACK Telephone Systems

8.53. Countermeasure -- BLACK Intercom and Public Address Systems

8.54. Countermeasure -- BLACK Local Area Networks

8.55. Countermeasure -- Comfort Music Systems

8.56. Countermeasure -- BLACK Cable Television Systems

8.57. Countermeasure -- BLACK Television-Video Cassette Recorder (VCR) Systems. . 86

8.58. Secure Telephones

8.59. Countermeasure -- Timing and Control Lines Installation Guidance

8.60. Countermeasure -- Utility Control Cables

8.61. Operating and Maintenance Practices

8.62. Control of RED Equipment

8.63. Information Collections, Records, and Forms

Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 89

Attachment 2— TRANSPORTABLE SYSTEMS IN A TACTICAL ENVIRONMENT 94

Attachment 3— AIRCRAFT 96

Attachment 4— DOCUMENTING THE COUNTERMEASURES REVIEWS 98

Attachment 5— GENERIC ZONE ASSIGNMENTS (GZA) 104

Attachment 6— FACILITY ZONE A, EQUIPMENT ZONE A 105

Attachment 7— FACILITY ZONE B, EQUIPMENT ZONE A 109

AFI33-203V3 2 NOVEMBER 2005 7

Attachment 8— FACILITY ZONE C, EQUIPMENT ZONE A 113

Attachment 9— FACILITY ZONE A, EQUIPMENT ZONE B 116

Attachment 10— FACILITY ZONE B, EQUIPMENT ZONE B 125

Attachment 11— FACILITY ZONE C, EQUIPMENT ZONE B 133

Attachment 12— FACILITY ZONE A, EQUIPMENT ZONE C 140

Attachment 13— FACILITY ZONE B, EQUIPMENT ZONE C 149

Attachment 14— FACILITY ZONE C, EQUIPMENT ZONE C 157

Attachment 15— EXAMPLE OF EMISSION SECURITY REQUIREMENTS

MEMORANDUM 165

Attachment 16— EXAMPLE OF EMISSION SECURITY CERTIFICATION

MEMORANDUM 168

Attachment 17— EMISSION SECURITY TESTING 169

Attachment 18— SHIELDED CABLES 173

Attachment 19— FILTERS AND ISOLATORS 174

Attachment 20— MAINTENANCE OF SHIELDED ENCLOSURES 179

Attachment 21— APPLYING ADMINISTRATIVE COMMUNICATIONS

COUNTERMEASURES 181

Attachment 22— AIR FORCE FORM 4170, EMISSION SECURITY ASSESSMENTS 185

Attachment 23— INTERIM CHANGE (IC) 2005-1 TO AFMAN 33-214, VOLUME 2, EMISSION SECURITY COUNTERMEASURES REVIEWS 189

8 AFI33-203V3 2 NOVEMBER 2005

Chapter 1

INTRODUCTION

1.1. General. A major goal of IA is to assure the availability, integrity, and confidentiality of information and information systems. To this end, the IA disciplines of communications security (COMSEC), com-puter security, and emission security (EMSEC) have, of necessity, become interdependent. EMSEC mostly supports the “confidentiality” requirement, to deny access to classified and, in some instances, unclassified information and contain compromising emanations within an inspectable space. Instances of when you must consider unclassified information are addressed in AFMAN 33-214, Volume 1, (S) Emis-sion Security Assessments (U) (will become AFI 33-203, Volume 2 (S). The term “classified informa-tion,” as used in this AFI, includes those instances. This is accomplished by identifying requirements from the broader view of IA and providing the appropriate protection at the least possible cost. Key to this is a partnership between the IA office and the user.

1.1.1. The objective of EMSEC is to contain compromising emanations within an inspectable space (IS). This is accomplished by identifying requirements from the broader view of IA and providing the appropriate protection at the least possible cost. Key to this is a partnership between the IA office and the user.

1.1.1.1. The wing IA office assesses the need for EMSEC as part of IA; it determines the required countermeasures; advises commanders of vulnerabilities, threats, and risks; and recommends a practical course of action.

1.1.1.2. The user identifies the systems that will process classified and, in some instances, unclas-sified information; the volume, relative sensitivity, and perishability of the information; the phys-ical control measures in effect around the area that will process classified information; and applies identified countermeasures.

1.1.2. An understanding of the EMSEC problem is essential to meeting EMSEC goals. The EMSEC problem is explained in AFMAN 33-214, Volume 1 (S) (will become AFI 33-203 Volume 2 [S]).

1.1.3. The national managers used risk management principles to develop the minimum requirements identified in this AFMAN. Since the risk has been accepted at the national level, no further risk for EMSEC can be accepted.

1.2. Emission Security Process. An important part of IA is the certification and accreditation (C&A) process. The C&A process addresses vulnerabilities and threats with the goal of reducing the risk to an acceptable level. EMSEC is part of the C&A process. The EMSEC process determines protective mea-sures that will deny unauthorized persons information collected from the intercept and analysis of emana-tions from information systems processing classified information. The EMSEC assessment determines if the threat is sufficient to require an EMSEC countermeasures review for information systems, communi-cations systems, and cryptographic equipment. Following are the major steps and where they fit into the C&A process.

1.2.1. Basic EMSEC Process:

1.2.1.1. The user contacts the wing IA office whenever classified information will be processed.

The user must do this before processing any such information.

AFI33-203V3 2 NOVEMBER 2005 9

1.2.1.2. The wing IA office makes the information systems, communications systems, and cryp-tographic equipment assessments to determine the need for EMSEC countermeasures and required IA countermeasures. This is the first half of determining the EMSEC portion of the secu-rity policy for the C&A of the information system.

1.2.1.3. When needed, the wing IA office makes the information systems, communications sys-tems, or cryptographic equipment countermeasures reviews to determine specific EMSEC coun-termeasures based on the threat for that location. This is the second half of determining the EMSEC portion of the security policy for the C&A of the information system.

1.2.1.4. The selection of EMSEC countermeasures is validated by the Air Force Certified TEM- PEST Technical Authority (CTTA) at HQ AFCA.

1.2.1.5. The required countermeasures are given to the user for application or implementation.

1.2.1.6. The wing IA office inspects the application of countermeasures for correctness and effec-tiveness. The inspection is made during the security test and evaluation task of the C&A.

1.2.1.7. The wing IA office certifies the information system, communications system, or crypto-graphic equipment meets EMSEC requirements as part of the certification phase of the C&A.

1.2.2. The Different EMSEC Problems. The means for escape of compromising emanations are dif-ferent for information systems, communications systems, and cryptographic systems; therefore, the EMSEC process is established to treat each of these separately to address their individual hazards.

1.2.2.1. The information systems countermeasures review determines the control of compromis-ing emanations required for information systems that process classified information.

1.2.2.2. The communications systems countermeasures review determines the countermeasures required for information systems that process classified information close to communications sys-tems.

1.2.2.3. The cryptographic equipment countermeasures review determines the countermeasures required for cryptographic equipment.

1.3. Emission Security Countermeasures Reviews. Like the EMSEC assessments, there are three EMSEC countermeasures reviews: information systems, communications systems, and cryptographic equipment. Complete each review separate from the others and without regard to the outcome of the oth-ers. These reviews produce the EMSEC requirements for the information system under review. Document the requirements on AF Form 4170, Emission Security Assessments/Emission Security Countermea-sures Reviews. The AF Form 4170 documents EMSEC requirements and is the basis for making the EMSEC inspection; it is not the result of an EMSEC inspection.

1.3.1. Information Systems. Follow the guidance in Chapter 2 to make the information systems countermeasures review.

1.3.2. Communications Systems. Follow the guidance in Chapter 3 for the communications systems countermeasures review.

1.3.3. Cryptographic Equipment. Follow the guidance in Chapter 4 for the cryptographic equipment countermeasures review.

10 AFI33-203V3 2 NOVEMBER 2005

1.4. Completing the Countermeasures Reviews. After selecting and documenting the needed counter-measures, complete documenting the countermeasures reviews. Classification marking, authentication, tracking, validation, informing the user, inspection, certification, and filing procedures are in Chapter 5.

1.5. Maintaining Emission Security. The user must properly maintain the EMSEC countermeasures and equipment used to process classified information. Follow the guidance in Chapter 6.

1.6. Emission Security Testing. When EMSEC testing is needed to meet EMSEC requirements, follow the guidance in Chapter 7 to request EMSEC testing.

1.7. Emission Security Countermeasures. The numerous countermeasures used in EMSEC are dis-cussed in Chapter 8. For each countermeasure there is a discussion of the problem requiring a counter-measure, what the countermeasure is, what the countermeasure does, what conditions negate the need for the countermeasure, how to apply the countermeasure when required, and alternatives.

AFI33-203V3 2 NOVEMBER 2005 11

Chapter 2

THE INFORMATION SYSTEMS COUNTERMEASURES REVIEW

2.1. Introduction. When the need to control compromising emanations is indicated by the information systems assessment, make an information systems countermeasures review to determine the required con-trol of compromising emanations countermeasures. This review is based on the use of non-TEM- PEST-certified equipment. TEMPEST-certified equipment is a countermeasure. The Air Force CTTA must validate all requirements for TEMPEST-certified equipment. The possibility of the intercept of com-promising emanations is a function of many variables. Chief among these are the:

2.1.1. Amount of inspectable space surrounding the systems processing classified information.

2.1.2. Radiation characteristics of the systems processing classified information.

2.1.3. Radio frequency attenuation offered by the facility containing the systems processing classified information.

2.1.4. Fortuitous conductors near the systems processing classified information.

2.2. Systematic Approach. The Air Force uses a systematic approach to determine the required coun-termeasures and the degree to which they are applied. Consider the following:

2.2.1. Location. This is the geographic location where the information is processed, the proximity to establishments of countries listed in Annex C of National Security Telecommunications and Informa-tion Systems Security Instruction (NSTISSI) 7000, (C) TEMPEST Countermeasures for Facilities (U), and other countries that could pose a technical threat to the information.

2.2.2. Volume of Information Processed. This is the total volume and the percentage or volume of processed information at the UNCLASSIFIED, SENSITIVE, CONFIDENTIAL, SECRET, and TOP SECRET level.

2.2.3. Sensitivity of Information Processed. This is the sensitivity of the processed information (e.g., Department of Energy - Restricted Data; Director of Central Intelligence - Sensitive Compartmented Information [SCI]; Joint Staff - Single Integrated Operational Plan). This is useful in determining the likelihood that an adversary may target the facility.

2.2.4. Perishability of Information Processed. The processed information has either long-term value (e.g., strategic) or short-term value (e.g., tactical). Long-term information requires a more conserva-tive approach to selecting countermeasures than short-term information.

2.2.5. Physical Control. This is the physical and access control for the facility and area containing the system under review. This includes guards (number, hours of posting, patrols, etc.), badging, control of access to the facility, alarms, procedures to monitor or control uncleared or unauthorized personnel including custodial and janitorial personnel, vending personnel, and telephone and power maintainers and installers. Determine the level of authority that exists for the inspection or removal of personnel who could potentially exploit compromising emanations. Examine the posting of warning signs and the implementation of procedures in effect to exercise control over parking and other areas adjacent to or in close proximity to the facility containing the system under review.

12 AFI33-203V3 2 NOVEMBER 2005

2.2.6. TEMPEST Profile of Equipment. This is the generic or actual TEMPEST profile information for each equipment or system used to process classified information in the facility. Consider existing on-site EMSEC test results for the facility.

2.3. Application Requirement. Apply control of compromising emanations countermeasures according to the instructions in this chapter. The requirements are separate from other EMSEC requirements (com-munications systems and cryptographic equipment). Apply them even when there are no other EMSEC requirements. Tactical equipment and aircraft are excluded from this universal requirement. See Attach-ment 2 and Attachment 3 for transportable systems in a tactical environment and aircraft-unique require-ments.

2.4. Determine the Inspectable Space. When it is required to control compromising emanations, con-tain them within the inspectable space. In the planning stages for large projects, the user contacts the IA office as soon as possible. When classified information is to be processed, the IA office contacts the installation’s information security program manager or reviews Department of Defense (DoD) Regulation 5200.1-R, Information Security Program, January 1977, for secure room construction standards, and oth-ers responsible for constructing or modifying a building. Even for projects as small as the acquisition of a personal computer (PC), the user consults with the IA office early to identify physical security require-ments. Adopt measures to meet the security requirements that are effective, practical, and compatible with local policies and provisions.

2.4.1. The IA Office. The IA office identifies the inspectable space by using the guidance in para-graph 2.4.3. and indicates it on a map (see Attachment 4). Attach the map to the AF Form 4170, doc-umenting the information systems, communications systems, and cryptographic equipment countermeasures reviews. The map of the inspectable space is usually unclassified.

2.4.2. The CTTA. The CTTA reviews the map and validates the identified inspectable space as com-plying with national guidance. This determines the inspectable space. The Defense Intelligence Agency (DIA/DAC-2A) determines inspectable space for DIA-accredited SCI facilities.

2.4.3. Identifying the inspectable space. The inspectable space is not intended to prevent an adversary from making a technical attack but rather to identify the area where the chance of discovery is too risky thereby deterring an adversary. Therefore, the inspectable space takes advantage of existing physical security.

2.4.3.1. inspectable space is defined as “the three-dimensional space surrounding systems that process classified or sensitive information within which TEMPEST exploitation is not considered practical or where legal authority to identify or remove a potential TEMPEST exploitation exists.”

This definition is explained as follows:

2.4.3.1.1. Three-Dimensional Space. This term means up and down as well as around.

2.4.3.1.2. Not Practical. What is considered not practical? Put yourself in the place of a spy manager. You have this person with a high level of technical knowledge, trained in testing and analysis, and 3 to 5 years of experience. You equip this person with some equipment (not spe-cially built but it is expensive in total cost; several receivers, demodulators, oscilloscope, video monitor, a couple of recorders, and accessories). So, how much risk are you going to take with this person? It is extremely unlikely that you will direct this person to set up a TEM- PEST-exploitation operation on a military installation. If the information is vital and this is the

AFI33-203V3 2 NOVEMBER 2005 13

only way to get the information, you might, but it is very risky because the person will have to get very close since they will apply many countermeasures. So, as the IA office, keep this in mind when identifying inspectable space. Also, it may be possible to include exposed places outside a military installation as inspectable space since the adversary does not want to be dis-covered.

2.4.3.1.3. Legal Authority to Identify or Remove a Potential TEMPEST Exploitation. The United States (U.S.) Government certainly has that authority on every base in the United States, its trust territories, and possessions (hereafter called the United States), but, what about bases under foreign control? On some bases under foreign control, the U.S. Government does have the authority to identify or remove, in concert with the host nation’s security people. That counts as inspectable space. What about a base in a country where the U.S. Government has all that but the host country has areas where U.S. personnel are not authorized to visit, either not at all or not without prior notice. The key here is access. If prior notice of less than one hour is required, then the U.S. Government has access. If prior notice of more than one hour is required, then the U.S. Government does not have access and that area is not considered as inspectable space.

2.4.3.2. Take advantage of circumstances that keep adversaries away or increase either the physi-cal distance or the zone rating.

2.4.3.2.1. For radiated compromising emanations, 6 inches of reinforced concrete provides a nominal 20 decibels (dB) of attenuation. When the inspectable space is defined in distance, a steel pan, poured concrete floor, or ceiling will provide about 20 dB of attenuation adding one zone level to the inspectable space in that direction. That is, when the inspectable space is 1 meter but less than 20 meters (Zone A) the inspectable space becomes Zone B or when the inspectable space is 20 meters but less than 100 meters (Zone B) the inspectable space becomes Zone C, etc. This is because the zones are 16 dB apart. An 8-inch thick reinforced concrete wall offers about 12 dB of attenuation or about 3/4 of a zone. Cinder block and brick walls offer about 4 dB of attenuation or about 1/4 of a zone.

2.4.3.2.2. For conducted compromising emanations, look for things that prevent access to conductors (like the building is totally within the inspectable space so heating and air condi-tioning ducts and water pipes are not accessible) or would reduce the magnitude of any com-promising emanations on a conductor.

2.4.3.3. Identify the inspectable space boundary and indicate it on the map. Base the decision on how willing an adversary is to risk an asset and U.S. Government access to areas considered as inspectable space.

2.4.4. Multiple Use of the inspectable space Map. Once the inspectable space is determined and the map made, it can be used for all other countermeasures reviews of systems within that inspectable space.

2.4.5. When Changes Occur. Reaccomplish all information systems countermeasures reviews when the inspectable space shrinks or expands.

2.5. Identify Equipment TEMPEST Characteristics. The methods for identifying the equipment TEMPEST characteristics are listed in preferred sequence. Ask your major command (MAJCOM) IA office for assistance if you do not have the information you need.

14 AFI33-203V3 2 NOVEMBER 2005

2.5.1. Equipment TEMPEST Zone Rating. Use the TEMPEST zone assignment for information pro-cessing equipment to find the equipment TEMPEST zone ratings. Obtain this from the MAJCOM IA office.

2.5.2. TEMPEST Level Rating. Use the level assignment (I, II, or III) for the system based on EMSEC test results. The equipment radiation TEMPEST zone (ERTZ) may be used if known.

2.5.3. Generic Zone Assignment. HQ AFCA/EVPI AF-CTTA developed the generic zone assignment and is an average of like equipment. Use Attachment 5 for the zone assignment for the kind of equip-ment used.

2.5.4. Other Guidance. If the equipment under review is not identified in any of the above sources, use the category "All Other RED Equipment."

2.6. Selecting Countermeasures.

2.6.1. Radiated Compromising Emanations. Using the equipment TEMPEST characteristics, identify the amount of inspectable space required to contain radiated compromising emanations within the inspectable space.

2.6.2. Conducted Compromising Emanations. Use Table 2.1. to identify which attachment (Attach-ment 6, Attachment 7, Attachment 8, Attachment 9, Attachment 10, Attachment 11, Attachment 12, Attachment 13, or Attachment 14) has the basic selection of countermeasures to contain con-ducted compromising emanations within the inspectable space. To do this, find the column across the top of Table 2.1. that includes the facility zone rating or the minimum amount of inspectable space identified in paragraph 2.4. Then find the row along the left side of Table 2.1. that includes the worst case equipment TEMPEST characteristics identified in paragraph 2.5. Follow the column down and the row in until they intersect. Follow the directions in the applicable attachment to select required countermeasures.

Table 2.1. Countermeasures Requirements.

FACILITY ZONE

OR

INSPECTABLE SPACE (IS)

Facility Zone A

OR

IS less than 20 meters

Facility Zone B

OR

IS more than 20 meters, less than 100 meters

Facility Zone C

OR

IS more than 100 meters

Equipment Zone A, or ERTZ = 1 meter, or Meets NSTISSAM/TEMPEST 1 - 9 2 , ( C ) Compromis ing Emanations Laboratory Test Requirements, Electromagnetics (U), Level I

Go to Attachment 6

Go to Attachment 7

Go to Attachment 8

AFI33-203V3 2 NOVEMBER 2005 15

2.6.2.1. Select those countermeasures identified as required unless there is a reason not to. Look for a reason not to select a countermeasure. Keep in mind the factors identified in paragraph 2.2.

Balance those factors against such things as: the cost to the adversary, the adversary’s access to the system, the risk of discovery, the objectives of the adversary, and the impact on the user’s mission.

The bottom line is: select it if it’s needed, do not select it if it is not. Explain why each deselected required countermeasure was not selected. A waiver is not needed for any deselected required countermeasure since the requirement for protection has been met.

2.6.2.2. Consider other listed countermeasures within the attachment using the environment and the TEMPEST characteristics of the equipment. Do not select one unless there is a reason to apply

it. Base the selection of any additional countermeasures on the situation (sensitivity, perishability, threat level, inspectable space, equipment TEMPEST profile, construction, and layout). You must explain why each selected nonrequired countermeasure was selected (i.e., identify a threat).

2.6.2.3. To aid the EMSEC person making a countermeasures review, a brief discussion of each countermeasure is contained in Chapter 8. The discussion identifies the basic compromising ema-nation problem the countermeasure is designed to control and contains an explanation of how the countermeasure works. When there are options, optional ways to treat the hazard are identified.

2.7. Estimating Cost. Estimate the cost of each selected countermeasure and enter that cost after the countermeasure on the AF Form 4170.

2.8. Analyzing the Results. Analyze the results and determine if they are acceptable (i.e., reasonable, practical, and cost effective). If the results are not acceptable, request assistance from your MAJCOM IA office. If the results are acceptable, continue.

Zone B, or ERTZ = 1 meter to 20 meters, or Meets NSTISSAM/TEMPEST 1-92, Level II

Go to Attachment 9 (See Note)

Go to Attachment 10

Go to Attachment 11

Zone C, or ERTZ = 20 meters to 100 meters, or Meets NSTISSAM/TEMPEST 1-92, Level III, or All Other RED Equipment

Go to Attachment 12 (See Note)

Go to Attachment 13 (See Note)

Go to Attachment 14

NOTE: This installation may create serious TEMPEST hazards. Contact your CTTA to evaluate the actual TEMPEST zone test results for the equipment and the facility to determine if you can use the equipment in the facility.

FACILITY ZONE

OR

INSPECTABLE SPACE (IS)

Facility Zone A

OR

IS less than 20 meters

Facility Zone B

OR

IS more than 20 meters, less than 100 meters

Facility Zone C

OR

IS more than 100 meters

Equipment

16 AFI33-203V3 2 NOVEMBER 2005

2.9. Documenting the Results. Document the results by identifying the required inspectable space and countermeasures on AF Form 4170, Part II, following the instructions in Attachment 4 for information systems. Remember that the form establishes EMSEC requirements. It must clearly state to the user what is required. It is not an inspection report.

2.10. Completing the Information Systems Countermeasures Review. If the communications sys-tems or cryptographic equipment assessment indicated the need for either a communications systems or cryptographic equipment countermeasures review, make the review before completing the countermea-sures review according to Chapter 5.

AFI33-203V3 2 NOVEMBER 2005 17

Chapter 3

THE COMMUNICATIONS SYSTEMS COUNTERMEASURES REVIEW

3.1. Introduction. When the need for communications systems countermeasures is indicated by the communications systems assessment, the communications systems countermeasures review determines the required countermeasures. Selection is a function of many variables. Chief among these are the:

3.1.1. Separation distance between RED equipment and radio equipment.

3.1.2. Radiation characteristics of the systems processing classified information.

3.1.3. Radio frequency attenuation offered by the facility containing the systems processing classified information.

3.2. Installation Requirement. Install equipment that processes classified information according to the instructions in this chapter. The communications systems installation requirements are separate from other EMSEC requirements. Meet them even when there are no other EMSEC requirements.

3.3. Transmitting Equipment. Use the guidance in this paragraph except when the equipment is addressed in paragraph 3.4.

3.3.1. Equipment Separation Requirements. This countermeasure is required. Separation guidance for fixed transmitters and transceivers (transmitters and receivers contained in one unit) is based on the TEMPEST characteristics of the RED equipment. Separate RED equipment from transmitters accord-ing to Table 3.1.

3.3.2. Power Requirements. This countermeasure is required. Do not power RED equipment from the same electrical circuit as radio frequency transmitters and any ancillary equipment, such as control heads, connected to radio frequency transmitters. Install a separate power circuit for either the RED equipment or the radio frequency transmitter and any ancillary equipment. The separate power circuit is established at the circuit-breaker panel. It is permissible to power both from the same electrical cir-cuit if either the RED equipment or the radio frequency transmitter and any ancillary equipment are equipped with power line filters.

Table 3.1. Separation Requirements for Transmitters.

3.3.3. Signal and Control Lines Separation Requirements. This countermeasure is required. These are BLACK lines. If they are wire lines:

3.3.3.1. Separate transmitter signal and control wire lines from RED equipment by the distance specified in Table 3.2. or shield them. The separation requirement for shielded signal and control wire lines from RED equipment is reduced to 15 centimeters.

Equipment Radiation TEMPEST Zone SEPARATION DISTANCE Zone A, or less than 3 meters 2 meters Zone B, or 3 meters to 20 meters 3 meters Zone C, or 20 meters to 100 meters 5 meters Zone D, or over 100 meters 10 meters

18 AFI33-203V3 2 NOVEMBER 2005

3.3.3.2. Separate transmitter signal and control wire lines from RED wire lines, RED power lines, and RED signal ground wire lines 0.5m or shield them. The separation requirement for shielded signal and control wire lines from RED wire lines, RED power lines, and RED signal ground wire lines is reduced to 5 centimeters.

3.3.3.3. There are no separation requirements for fiber optic signal and control lines.

3.3.3.4. If the separation distances for signal and control wire lines cannot be achieved, shield the wire lines, filter the wire lines, use opto-isolators, or use fiber optic lines instead of wire lines.

Table 3.2. Separation Requirements for Signal and Control Wire Lines.

3.3.4. Remote Control Head Separation Requirements. This countermeasure is required. Determine if the control head is passive or active. Passive control heads have no electronic circuits with active devices in them (e.g., computer chips, junctions, registers, etc.); mechanical switches or mechanical relays do all the switching. Active control heads have electronic circuits activated by front-panel but-tons or switches or use a computer to control operator selections.

3.3.4.1. Separate active control heads by the distance specified in Table 3.2.

3.3.4.2. Separate passive control heads from RED equipment, RED wire lines, RED power lines, and RED signal ground lines by the same distance as determined in paragraph 3.3.3.2.

3.3.4.3. If the separation distance cannot be achieved, use opto-isolators on the signal and control wire lines to the transmitter or use fiber optic signal and control lines instead of wire lines.

3.3.5. Shielding Alternative. An alternative to the separation requirement in paragraph 3.3.1. is shielding either the RED equipment or the transmitter. If the transmitter is shielded, a part of the shielding must include the antenna lead. Circumferentially bond the antenna lead shield to the shielded enclosure. Extend the shield to a distance 20 times the diameter of the shield. You must use filters to penetrate the shielding for power, signal, and control lines. If signal or control lines are fiber optic, a waveguide beyond cutoff penetration may be used. Keep the diameter as small as possible not exceeding one-half inch. Make the length of the waveguide 10 times the diameter.

3.4. Special Items. Use the guidance in this paragraph for the items addressed in this paragraph instead of the guidance in paragraph 3.3. People may innocently introduce other radio devices, such as pagers, hand-held portable transceiver radios, cellular telephones, cordless telephones, and cordless microphones into the area processing classified information with disastrous results. Also, alarm systems may use radio transmitters to alert remotely located security or fire-fighting teams.

3.4.1. Hand-Held Radios. These countermeasures are required. Hand-held radio transceivers used with intrabase radios and land mobile radios deserve special consideration because of their unique operational applications. A person may carry these devices into an area where classified information

EQUIPMENT RADIATION TEMPEST ZONE SEPARATION DISTANCE

Zone A, or less than 3 meters 0.5 meters Zone B, or 3 meters to 20 meters 1 meter Zone C, or 20 meters to 100 meters 2 meters Zone D, or over 100 meters 3 meters

AFI33-203V3 2 NOVEMBER 2005 19

is processed. If the person carrying such a device works in the facility, either turn off the device and use the telephone or separate it 2 meters from classified processors; no transmissions are allowed. If the person carrying the device is a short-term visitor, it is not necessary to turn off the radio because the visitor usually moves about in the facility. Infrequent transmissions are allowed, but only for short durations.

3.4.2. Beepers and Pagers. These countermeasures are required. Beepers and pagers deserve special consideration because of their unique operational applications. A person may carry these devices into an area where classified information is processed. If the person carrying such a device works in the facility, either turn off the device and use the telephone or keep the device 2 meters from classified processors. If the person carrying the device is a short-term visitor, it is not necessary to turn off the device because the visitor usually moves about in the facility. If the device has a transmit capability, follow the instructions for hand-held radios.

3.4.3. Alarm Systems. These countermeasures are required. The mode of operation of alarm systems radio frequency transmitters will determine their treatment. Any such transmitter with a continuous transmit mode or a high duty cycle (transmits most of the time) must meet the same separation requirements as all other fixed transmitters; follow the applicable guidance in paragraph 3.3. If they do not meet these requirements, exclude them from operating in the classified information processing area. Low duty cycle (transmits short bursts infrequently) systems are not considered hazards and require no special treatment.

3.4.4. Cellular Telephones. These countermeasures are required. When a cellular telephone is used as an operational necessity, separate it 5 meters from RED equipment. When the cellular telephone is a personal asset, disable the unit from receiving calls or separate it 10 meters from RED processors.

Cellular telephones are excluded from operating within 10 meters of the classified information pro-cessing area when the facility is located outside the United States.

3.4.5. Cordless Telephones. These countermeasures are required. When a radio frequency cordless telephone is used as an operational necessity, separate it 5 meters from RED equipment. When the cordless telephone is a personal asset, its use is prohibited. Disable the personal cordless telephone from receiving calls or separate it 10 meters from RED processors. There are no separation require-ments for infrared cordless telephones. Cordless telephones are excluded from operating within 10 meters of the classified information processing area when the facility is located outside the United States.

3.4.6. Cordless Microphones.

3.4.6.1. Radio Frequency Cordless Microphones. These countermeasures are required. When a radio frequency cordless microphone, encrypted or unencrypted, is used for briefing either classi-fied information or unclassified information, separate it 5 meters from RED equipment. Using unencrypted radio frequency cordless microphones for classified briefings is prohibited.

3.4.6.2. Infrared Cordless Microphones. These countermeasures are required. Using an infrared cordless microphone for briefing classified information requires blocking the line of sight to a possible place where an adversary could detect the infrared emanations. Do not forget that smooth or shiny surfaces cause infrared signals to be reflected. The best solution is to use a closed room, keeping the doors closed and covering the windows with drapes.

20 AFI33-203V3 2 NOVEMBER 2005

3.4.7. Cordless Accessories. These countermeasures are required. When a radio frequency cordless accessory such as a keyboard or a mouse is used, separate it 5 meters from RED equipment. Radio fre-quency cordless accessories cannot be used to process classified information unless encrypted.

3.4.8. Wireless Local Area Networks (LAN). These countermeasures are required. When a radio fre-quency wireless LAN is used, separate the transmitter and receiver units 5 meters from RED equip-ment.

3.4.9. Infrared LANs. These countermeasures are required. An infrared LAN processing classified information requires blocking the line of sight to a possible place where an adversary could detect the infrared emanations. Do not forget that smooth or shiny surfaces cause infrared signals to be reflected.

The best solution is to use a closed room, keeping the doors closed and covering the windows with drapes.

3.4.10. Infrared Devices. These countermeasures are required. Infrared devices not covered by any subparagraph of paragraph 3.4. require blocking the line of sight to a possible place where an adver-sary could detect the infrared emanations. Do not forget that smooth or shiny surfaces cause infrared signals to be reflected. The best solution is to use a closed room, keeping the doors closed and cover-ing the windows with drapes.

3.5. Estimating Cost. Estimate the cost of each selected countermeasure and enter that cost after the countermeasure on the AF Form 4170.

3.6. Analyzing the Results. Analyze the results and determine if they are acceptable (i.e., reasonable, practical, and cost effective). If the results are not acceptable, request assistance from your MAJCOM IA office. If the results are acceptable, continue.

3.7. Documenting the Results. Document the results that identify the required countermeasures on AF Form 4170, Part II, following the instructions in Attachment 4 for communications systems. Remember, the form establishes EMSEC requirements. It must clearly state to the user what is required. It is not an inspection report.

3.8. Completing the Information Systems Countermeasures Review. If the cryptographic equipment assessment indicated the need for a cryptographic equipment countermeasures review, make the review before completing the countermeasures reviews according to Chapter 5.

AFI33-203V3 2 NOVEMBER 2005 21

Chapter 4

THE CRYPTOGRAPHIC EQUIPMENT COUNTERMEASURES REVIEW

4.1. Introduction. When the need for cryptographic equipment countermeasures is indicated by the cryptographic equipment assessment, the cryptographic equipment countermeasures review determines the required countermeasures. The possibility of the escape of classified information is a function of many variables. Chief among these are the:

4.1.1. Separation distance between RED equipment and cryptographic equipment.

4.1.2. Radiation characteristics of the systems processing classified information.

4.1.3. Type of information processed.

4.2. Installation Requirement. Install cryptographic equipment according to the instructions in this chapter. The cryptographic equipment installation requirements are separate from other EMSEC require-ments. Meet them even when there are no other EMSEC requirements.

4.3. Secure Telephone Unit-III (STU-III), Secure Terminal Equipment (STE), and Like Items.

These countermeasures are required for STU-III, STE, and secure data devices (SDD). Do the following when connecting ancillary items such as computers and facsimile (FAX) machines to the secure digital data port:

4.3.1. Separate the STU-III, STE, or SDD 1 meter from the RED equipment.

4.3.2. Use the manufacturers’ shielded cable to connect the STU-III, STE, or SDD to the RED equip-ment. If the manufacturers’ shielded cable is not available, use a generic shielded cable.

4.4. Cryptographic System KIV-7. These countermeasures are required for KIV-7 cryptographic sys-tems.

4.4.1. Do the following when the KIV-7 is installed in a computer:

4.4.1.1. Do not use the computer’s internal modem; use an external modem.

4.4.1.2. Separate the external modem 1 meter from the RED equipment.

4.4.1.3. Use the cables (for installing the KIV-7 in a computer) made by the KIV-7 manufacturer.

All cables not made by the manufacturer must meet the same requirements as the manufacturer’s cables.

4.4.1.4. There are no separation requirements between the KIV-7 and RED or BLACK equip-ment.

4.4.2. Do the following when installing the KIV-7 in a rack near a computer:

4.4.2.1. Do not use the computer’s internal modem; use an external modem.

4.4.2.2. Use the cables (for installing the KIV-7 in a rack near a computer) made by the KIV-7 manufacturer. All cables not made by the manufacturer must meet the same requirements as the manufacturer’s cables.

22 AFI33-203V3 2 NOVEMBER 2005

4.4.2.3. A rack is not required if the KIV-7 is not installed in a computer. When installing the KIV-7 in an external rack, use the manufacturer’s supplied rack. If you are not using a rack made by the manufacturer, your rack must meet the same requirements as the manufacturer’s rack.

4.4.2.4. Separate the modem 1 meter from the RED equipment.

4.4.2.5. There are no separation requirements between the KIV-7 and RED or BLACK equip-ment.

4.4.3. Do the following when the KIV-7 is installed in a stand-alone mode (similar to a cryptographic room):

4.4.3.1. Do not use the internal modem of an equipment processing classified information unless the equipment is TEMPEST certified. Use an external modem.

4.4.3.2. Connect the KIV-7 to BLACK power.

4.4.3.3. Shield both the RED and BLACK wire lines. Connect the shields to the appropriate RED and BLACK signal grounds.

4.4.3.4. A rack is not required if the KIV-7 is not installed in a computer. Whenever possible, use the manufacturer’s supplied rack. If you are not using a rack made by the manufacturer, your rack must meet the same requirements as the manufacturer’s rack.

4.4.3.5. There are no separation requirements between the KIV-7 and RED or BLACK equip-ment.

4.5. FORTEZZA For Classified (FFC). These countermeasures are required for FFC cryptographic systems. Do the following when using a FFC card to secure a computer:

4.5.1. Do not use the internal modem if one is installed in the computer; use an external modem.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .