IC-Tech-Specs-for-Const-and-Mgmt-of-SCIFs-v15.pdf
PDF 6 MB Posted
- Attached to
- EMERGENCY NOTIFICATION SYSTEM (ENS) Federal contract opportunity
- Solicitation number
- FA8307-24-Q-B092
About this file
This document is a Technical Specification for the Construction and Management of Sensitive Compartmented Information Facilities (SCIFs). It provides detailed requirements and guidance for the physical security, technical security, and management of SCIFs for the U.S. Intelligence Community.
The specification covers requirements for SCIF construction materials, doors, windows, perimeter penetrations, intrusion detection systems, access controls, acoustic protection, telecommunications systems, portable electronic devices, management, operations, and documentation. It also includes specific requirements for SCIFs located outside the U.S. and under Chief of Mission authority, as well as temporary, airborne, and shipboard SCIFs. The specification is intended to be a living document that is periodically updated to keep up with changing and emerging technologies. This version 1.5 updates the previous version 1.4 based on input from the Intelligence Community and industry partners.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Combo Synopsis Amendment_04.pdf | ||
| Combo Synopsis Amendment_03.pdf | ||
| All PA Control Box location.pdf | ||
| Floor Cable Troughs_25-Jul-2024.pdf | ||
| Combo Synopsis_A0002.pdf | ||
| FA8307-24-Q-B092_Amendment_01.pdf | ||
| 02 PA specifications.pdf | ||
| FA8307-24-Q-B092.pdf | ||
| 03 System Microphone Block Diagram.pdf | ||
| 04 Sound Cover and PA Areas.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Technical Specifications for Construction and Management of Sensitive Compartmented
Information Facilities
VERSION 1.5
IC Tech Spec – for ICD/ICS 705
An Intelligence Community Technical Specification Prepared by the
National Counterintelligence and Security Center
March 13, 2020
This page intentionally left blank.
OFFICE OF THE DIRECT OR OF NATIONAL INTELLIGENCE
DIRECT OR OF THE NATIONAL COUNTERINTELLIGENCE AND SECURITY CENTER
WASHINGTO N, DC 20511
NCSC 19-686
MEMORANDUM FOR:
SUBJECT:
REFERENCES:
Distribution
Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 A. (U) D/NCSC Memo NCSC-19-329, Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.4, 28 Sep 17 (U)
B. (U) Technical Specifications, Version 1.4, 28 Sep 17 (U) C. (U) ICD 705, Sensitive Compartmented Information Facilities, 26 May 10 (U) D. (U) ICS 705-01, Physical and Technical Standards for Sensitive
Compartmented Information Facilities, 27 Sep 10 (U) E. (U) ICS 705-02, Standards for the Accreditation and Reciprocal
Use of Sensitive Compartmented Information Facilities, 22 Dec 16 (U)
This memorandum promulgates Version 1.5 of the Technical Specification for Construction and Management of Sensitive Compartmented Information Facilities to the Intelligence Community, which replaces Version 1.4 (Ref A), effective immediately.
The Technical Specifications was designed to be a living document that enables periodic updates to keep up with changing and emerging technology. Based on input from the Intelligence Community (IC) and as a result of a cooperative effort by physical and technical experts from IC elements and our industrial partners, this Version 1.5 of the Technical Specifications has been updated to meet the needs of the community and enhance the standards identified in ICS 705-01, Physical Security Standards for Sensitive Compartmented Information Facilities (Ref C) and ICS 705-02, Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information Facilities (Ref D).
Questions may be directed to the National Counterintelligence and Security Center's Special Security Directorate NI-NCSC-SSD-CSG-PTSP-Mailbox@cia.ic.gov.
William R. Evanina Date mailto:NI-NCSC-SSD-CSG-PTSP-Mailbox@cia.ic.gov mailto:NI-NCSC-SSD-CSG-PTSP-Mailbox@cia.ic.gov
UNCLASSIFIED
SUBJECT: Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 ii
UNCLASSIFIED
Distribution:
Secretary of State, Department of State Secretary of the Treasury, Department of the Treasury Secretary of Defense, Department of Defense Attorney General, Department of Justice Secretary of the Interior, Department of the Interior Secretary of Agriculture, Department of Agriculture Secretary of Commerce, Department of Commerce Secretary of Labor, Department of Labor Secretary of Health and Human Services, Department of Health and Human Services Secretary of Housing and Urban Development, Department of Housing and Urban Development Secretary of Transportation, Department of Transportation Secretary of Energy, Department of Energy Secretary of Education, Department of Education Secretary of Veterans Affairs, Department of Veterans Affairs Secretary of Homeland Security, Department of Homeland Security Administrator, Executive Office of the President Administrator, Environmental Protection Agency Director, Office of Management and Budget United States Trade Representative Administrator, Small Business Administration Director, National Drug Control Policy Director, Central Intelligence Agency Administrator, Equal Employment Opportunity Commission Chairman, Federal Communications Commission Chairman, Federal Maritime Commission Chairman, Federal Reserve System Chairman, Federal Trade Commission Administrator, General Services Administration Administrator, National Aeronautics and Space Administration Archivist, National Archives and Records Administration Director, National Science Foundation Chairman, Nuclear Regulatory Commission Director, Office of Government Ethics Chairman, Privacy and Civil Liberties Oversight Board Chairman, Security and Exchange Commission Director, Selective Service System Commissioner, Social Security Administration Administrator, United States Agency for International Development United States Postal Service Chairman, United States International Trade Commission Director, United States Peace Corps
UNCLASSIFIED
SUBJECT: Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 iii
UNCLASSIFIED
Distribution, cont.:
Office of the Chief Administrative Officer
Change History iv
Change History Rev. # Date Page Changes Approver
1.2 04/23/12 Cover Banner Graphic, Version, Date PTSEWG
1.2 04/23/12 4 Added note to warn users of classification when associating threat information and facility location.
PTSEWG
1.2 04/23/12 5 Re-worded approval of CAs to designate the AO as the primary approval authority of Compartmented Areas within SCIFs.
PTSEWG
1.2 04/23/12 9-10 Changed “Type X Gypsum” to “wallboard” to remove the standard of fire resistant gypsum and permit use of other wallboard types.
PTSEWG
1.2 04/23/12 9-10 Changed references to wall design drawings to “suggested” wall types to enable variety of wall construction techniques to meet the security standards.
PTSEWG
1.2 04/23/12 10 Added explanation to glue and screw plywood to ceiling and floor to clarify standard. Stud placement changed to 16 on center to match drawing and correct error.
PTSEWG
1.2 04/23/12 11 Added statement to finish wall and paint from true floor to true ceiling in Walls B and C to clarify and equal Type A Wall.
PTSEWG
1.2 04/23/12 9-10 Replaced drawings to reflect “suggested” wall construction methods and remove references to “Type X gypsum wallboard”.
PTSEWG
1.2 04/23/12 17-19 Replaced drawings to reflect “suggested” wall construction methods and remove references to “Type X gypsum wallboard”.
PTSEWG
1.2 04/23/12 56 Updated Federal Information Processing Standards (FIPS) encryption standards and certification to remove a standard that could not be met by commercial alarm systems.
PTSEWG
1.2 04/23/12 64 Replaced FIPS 140-2 with Advanced Encryption Standard (AES) to remove a standard that could not be met by commercial alarm systems.
PTSEWG
v
Rev. # Date Page Changes Approver
1.2 04/23/12 TEMPEST
Checklist Removed references to “inspectable space” as requested by the TEMPEST Advisory Group (TAG).
PTSEWG
1.2 04/23/12 TEMPEST
Checklist
Removed references to “Red-SCI” information.
PTSEWG
1.2 04/23/12 TEMPEST
Checklist
Removed parenthetical reference to cell phones and Bluetooth.
PTSEWG
1.2 04/23/12 CA
Checklist
Replaced Compartmented Area Checklist to reflect IC standards.
PTSEWG
1.2 04/23/12 SCIF Co-Use Request and MOA Form
Replaced Co-Use and MOA Form to include “joint-use” statements.
PTSEWG
1.3 03/26/15 Cover Banner change, version, date PTSEWG
1.3 03/26/15 B-C Appended “D/NCSC Memorandum” PTSEWG
1.3 03/26/15 D-G “Appended Change History” PTSEWG
1.3 03/26/15 3 Chapter 2.A (2)(a) Added: “NOTE” regarding prefabricated modular SCIFs.
PTSEWG
1.3 03/26/15 9 Chapter 3.C Corrected wording to match wall drawings on p.21.
PTSEWG
1.3 03/26/15 14 Chapter 3.G (7)(c.4) Correction and addition of guidance on vents and ducts perimeter protection.
PTSEWG
1.3 03/26/15 17-19 Reformatted wall types to reflect correct architectural graphics for prescribed materials.
PTSEWG
1.3 03/26/15 53 Chapter 7.A (2)(d) Added requirement for HSS switches.
PTSEWG
1.3 03/26/15 54 Chapter 7.A (2)(k) Changed to reflect restrictions on dissemination of installation plans.
PTSEWG
1.3 03/26/15 54 Chapter 7.A (3)(a.2) Added exception that sensors must be located within SCIF perimeter.
PTSEWG
1.3 03/26/15 55 Chapter 7.A (3)(b.7.e) Replaced “Zones” with “IDE sensor points”.
PTSEWG
1.3 03/26/15 56 Chapter 7.A (3)(c.1) Added language for approval authority.
PTSEWG
1.3 03/26/15 56 Chapter 7.A (3)(c.2) Added language for integrated IDS and Remote Access.
PTSEWG
1.3 03/26/15 56-57 Chapter 7.A (3)(c.2) Added system application software requirements.
PTSEWG
1.3 03/26/15 58-59 Replaced “access/secure” with “arm/disarm” throughout.
vi
Rev. # Date Page Changes Approver
1.3 03/26/15 58 Chapter 7.B (2) Added “A record shall be maintained that identifies the person responsible for disarming the system”.
PTSEWG
1.3 03/26/15 87 Chapter 12.G (2) Changed Section header to read “Inspections/Reviews, added same where the term “inspection” or “review” used. The responsibility to perform as such was changed from “IC element head” to the AO, or designee.
PTSEWG
1.3 03/26/15 SCIF Co-Use Request and MOA Form
Appended Co-Use Request and MOA Form
PTSEWG
1.4 06/27/17 Cover Banner change, version, date PTSEWG
1.4 06/27/17 i-iii Appended “D/NCSC Memorandum” PTSEWG
1.4 06/27/17 iv-vii “Appended Change History” PTSEWG
1.4 06/27/17 1 Chapter 1.B.2
Added SAPF Language
PTSEWG
1.4 06/27/17 12 Chapter 3.E.1.b Added egress device language
PTSEWG
1.4 06/27/17 60 Chapter 7.C.1.c Added, “…IAW UL 2050 requirements (60 minutes)”
PTSEWG
1.4 06/27/17 71-74 Chapter 10 Revised PTSEWG
1.4 06/27/17 75-76 Chapter 11.B.5
Added sub-bullets to address CNSSI
PTSEWG
1.4 06/27/17 90-91 Chapter 12.L1/2/7 Added clarification language
PTSEWG
1.4 06/27/17 91-92 Chapter 12.M.4 Synchronized bullets
PTSEWG
1.5 11/13/19 3-4 Chapter 2.A.3.a Added clarification language
PTSEWG
1.5 11/13/19 5-6 Chapter 2.C.2 Defined CA Types
PTSEWG
1.5 11/13/19 8 Chapter 3. Added Pre-Construction Checklist language
PTSEWG
1.5 11/13/19 13-15 Chapter 3.E Expanded SCIF Door Criteria
PTSEWG
1.5 11/13/19 30 Chapter 4.E.2 Added reference to Inspectable Materials Checklist vii
1.5 11/13/19 35 Chapter 5.A Added language in Applicability
PTSEWG
1.5 11/13/19 46 Chapter 6.A.1.a Added exception language
PTSEWG
1.5 11/13/19 74-77 Chapter 10 Changed “CSA” to “AO” where appropriate
PTSEWG
1.5 11/13/19 90 Chapter 12.G.8 Added TSCM language to Inspections/Reviews
PTSEWG
1.5 11/13/19 95-97 Chapter 12.N/O/P Added CUA instructions
PTSEWG
1.5 11/13/19 98 Chapter 13 Updated FFC and added CUA Guide and Cancellation Forms, Inspectable Materials Checklist, Pre- Construction Checklist viii
Table of Contents ix
Table of Contents Chapter 1. Introduction……………………………………………………………………… 1
A. Purpose………………………………………………………………………………… 1 B. Applicability…………………………………………………………………………… 1
Chapter 2. Risk Management………………………………………………………………... 3 A. Analytical Risk Management Process………………………………………………… 3 B. Security in Depth (SID)………………………………………………………………. 4 C. Compartmented Area (CA) …………………………………………………………... 5
Chapter 3. Fixed Facility SCIF Construction………………………………………………... 8 A. Personnel………………………………………………………………………… B. Construction Security………………………………………………………………….. 9 C. Perimeter Wall Construction Criteria…………………………………………………. 10 D. Floor and Ceiling Construction Criteria……………………………….………….…... 13 E. SCIF Door Criteria………………………………………………………………….… 13 F. SCIF Window Criteria….….....…………………………………………………..…….15 G. SCIF Perimeter Penetrations Criteria…………………………………………………. 15 H. Alarm Response Time Criteria for SCIFs within the U.S. …………………………… 17 I. Secure Working Areas (SWA) ……………………………………………………….. 17 J. Temporary Secure Working Area (TSWA) ………………………………………….. 18
Chapter 4. SCIFs Outside the U.S. and NOT Under Chief of Mission (COM) Authority….. 23 A. General………………………………………………………………………………… 23 B. Establishing Construction Criteria Using Threat Ratings…………………………….. 23 C. Personnel………………………………………………………………………………. 26 D. Construction Security Requirements…………………………………………………. 27 E. Procurement of Construction Materials……………………………………………….. 30 F. Secure Transportation for Construction Material……………………………………… 31 G. Secure Storage of Construction Material……………………………………………… 32 H. Technical Security……………………………………………………………………. 33 I. Interim Accreditations………………………………………………………………… 33
Chapter 5. SCIFs Outside the U.S. and Under Chief of Mission Authority………………… 35 A. Applicability…………………………………………………………………………… 35 B. General Guidelines…………………………………………………………………….. 35 C. Threat Categories……………………………………………………………………… 36 D. Construction Requirements…………………………………………………………… 36 E. Personnel………………………………………………………………………………. 38 F. Construction Security Requirements…………………………………………………. 39 G. Procurement of Construction Materials……………………………………………….. 42 H. Secure Transportation for Construction Material……………………………………… 43 I. Secure Storage of Construction Material……………………………………………… 44 x
J. Technical Security…………..………………………………………………………… K. Interim Accreditations………………………………………………………………… 45
Chapter 6. Temporary, Airborne, and Shipboard SCIFs……………………………………. 46 A. Applicability………………………………………………………………………….. 46 B. Ground-Based T-SCIFs………………………………………………………………. 46 C. Permanent and Tactical SCIFS Aboard Aircraft……………………………………... 48 D. Permanent and Tactical SCIFs on Surface or Subsurface Vessels…………………… 50
Chapter 7. Intrusion Detection Systems (IDS) ……………………………………………… 56 A. Specifications and Implementation Requirements…………………………………….. 56 B. IDS Modes of Operation………………………………………………………………. 61 C. Operations and Maintenance of IDS…………………………………………………… 63 D. Installation and Testing of IDS………………………………………………………… 64
Chapter 8. Access Control Systems (ACS) ………………………………………………… 66 A. SCIF Access Control…………………………………………………………………. 66 B. ACS Administration…………………………………………………………………… 67 C. ACS Physical Protection………………………………………………………………. 67 D. ACS Recordkeeping…………………………………………………………………… 67
. E. Using Closed Circuit Television (CCTV) to Supplement ACS……………………….. 68 F. Non-Automated Access Control………………………………………………………. 68
Chapter 9. Acoustic Protection……………………………………………………………… 70 A. Overview………………………………………………………………………………. 70 B. Sound Group Ratings………………………………………………………………….. 70 C. Acoustic Testing……………………………………………………………………… 70 D. Construction Guidance for Acoustic Protection……….……………………………… 71 E. Sound Transmission Mitigations………………………………………………………. 71
Chapter 10. Portable Electronic Devices with Recording Capabilities and Embedded Technologies (PEDs/RCET)………………………………….…………….………………… 74
A. Approved Use of PEDs/RECET in a SCIF…………………………………………… 74 B. Prohibitions……………………………………………………………………………. 75 C. PED/RCET Risk Levels………………………………………………………………. 75 D. Risk Mitigation………………………………………………………………………… 76
Chapter 11. Telecommunications Systems………………………………………………….. 78 A. Applicability…………………………………………………………………………… 78 B. Unclassified Telephone Systems………………………………………………………. 78 C. Unclassified Information Systems…………………………………………………….. 80 D. Using Closed Circuit Television (CCTV) to Monitor the SCIF Entry Point(s) ……… 80 E. Unclassified Wireless Network Technology…………………………………………. 80 F. Environmental Infrastructure Systems………………………………………………… 81 G. Emergency Notification Systems……………………………………………………… 81 xi
H. System Access………………………………………………………………………… 82 I. Unclassified Cable Control……………………………………………………………. 82 J. Protected Distribution Systems………………………………………………………… 83 K. References……………………………………………………………………………
Chapter 12. Management and Operations…………………………………………………… 86 A. Purpose………………………………………………………………………………… 86 B. SCIF Repository………………………………………………………………………. 86 C. SCIF Management…………………………………………………………….......…... 87 D. SOPs………………………………………….………………………………….....… 88 E. Changes in Security and Accreditation……………………………………………..…. 89 F. General………………………………………………...……………………………… 89 G. Inspections/Reviews…………………………………………………………………… 90 H. Control of Combinations………………………………………………………………. 90 I. De-Accreditation Guidelines…………………………..……………………….……… 91 J. Visitor Access………………………………………………………………………….. 91 K. Maintenance……..………………………………………………….………………… 93 L. IDS and ACS Documentation Requirements……………………………….………….. 93 M. Emergency Plan……………………………………………………………………….. 94 N. SCIF Co-Use and Joint Use……..…………………………………………………….. 95 O. CUA Form and Instructions…..……………………………………………………….. 96 P. CUA Cancellation..…………………………………………………………………….. 97
Chapter 13. Forms and Plans………………………………………………………………… 98 Fixed Facility Checklist TEMPEST Checklist Compartmented Area Checklist Shipboard Checklist Submarine Checklist Aircraft/UAV Checklist SCIF Co-Use/Joint-Use Request SCIF Co-Use/Joint-Use Request Users Guide Cancellation of SCIF Co-Use/Joint-Use Pre-Construction Checklist Construction Security Plan (CSP) Inspectable Materials Checklist xii
Chapter 11 Telecommunications Systems
Chapter 11. Telecommunications Systems
A. Applicability
1. This guidance is compatible with, but may not satisfy, security requirements of other disciplines such as Information Systems Security, Communications Security (COMSEC), Operational Security (OPSEC), or TEMPEST.
2. This section outlines the security requirements that shall be met to ensure the following:
• Protection of information.
• Configuration of unclassified telecommunications systems, devices, features, and software.
• Access control.
• Control of the cable infrastructure.
B. Unclassified Telephone Systems
1. A baseline configuration of all unclassified telephone systems, devices, features, and software shall be established, documented, and included in the SCIF FFC.
2. The AO shall review the telephone system baseline configuration and supporting information to determine if the risk of information loss or exploitation has been suitably mitigated.
3. When security requirements cannot be met, unclassified telephone equipment shall be installed and maintained in non-discussion areas only.
4. When not in use, unclassified telephone systems shall not transmit audio and shall be configured to prevent external control or activation, technical exploitation, or penetration.
5. Unclassified telephone systems shall incorporate physical and software access controls to prevent disclosure or manipulation of system programming and data. The following specific requirements shall be met:
a) On-hook and off-hook audio protection shall be provided by equipment identified by the National Telephone Security Working Group within TSG-6/CNSSI 5006, National Instruction for Approved Telephone Equipment, or an equivalent TSG 2/
CNSSI 5002:
(1) The purpose of a TSG-2 or CNSS 5002 Computerized Telephone Switch (CTS) installation is to prevent manipulation of telephone instruments to obtain audio from within the SCIF while the instrument is in an "on-hook" condition.
(2) When isolation is provided by a CTS installed IAW TSG-2 or CNSS 5002, the AO accepts the risk on-hook audio from the SCIF may be present on all instrument wiring until it reaches the CTS due to instrument configuration, design, or breakdown. (TSG-2/CNSS 5002 does not address procedures to determine security of the station itself.)
(3) To provide the necessary level of security, the Physically Protected Space (PPS) where the CTS is installed must meet equivalent security and access control standards as the SCIF it supports to provide positive physical protection for the CTS and all of its parts. (CNSSI 5002 para 7.A.(1) ). This includes all instruments, cables, lines, intermediate wiring frames, and distributed CTS modules necessary for the functioning of the instruments.
(4) The AO may require all instrument wiring exiting between the SCIF and PPS which is not at the SCIF level be contained in a closed and sealed metal conveyance as defined in Chapter 7.A.2 to ensure physical security of the instrument wiring.
(5) Telephones or instruments not type-accepted will be presumed to have on-hook audio available at the mounting cord until determined otherwise.
Determining telephone stations do not have on-hook audio hazards requires a technical investigation and specific equipment. These investigations and determinations may only be conducted by a TSCM team or National Telephone Security Working Group (NTSWG) authorized telephone laboratory.
b) If a Computerized Telephone System (CTS) is selected for isolation, it shall be installed and configured as detailed in TSG 2 with software and hardware configuration control and audit reporting (such as station message detail reporting, call detail reporting, etc.).
c) System programming shall not include the ability to place, or keep, a handset off-hook.
d) Configuration of the system shall ensure that all on-hook and off-hook vulnerabilities are mitigated.
e) When local or remote CTS administration terminals are not contained within a controlled area and safeguarded against unauthorized manipulation, the use of CNSSI 5006 approved telephone instruments shall be required, regardless of the CTS configuration.
f) Speakerphones and audio conferencing systems shall not be used on unclassified telephone systems in SCIFs. Exceptions to this requirement may be approved by the AO when these systems have sufficient audio isolation from other classified discussion areas in the SCIF and procedures are established to prevent inadvertent transmission outside the SCIF.
g) Features used for voice mail or unified messaging services shall be configured to prevent access to remote diagnostic ports, internal dial tone, and dial plans.
h) Telephone answering devices and facsimile machines shall not contain features that introduce security vulnerabilities, e.g., remote room monitoring, remote programming, or other similar features that may permit off-premise access to room audio.
i) All unclassified telephone systems and associated infrastructure shall be physically isolated from classified information and telecommunications systems in accordance with DNI and CNSS TEMPEST guidance.
j) TSG6/CNSSI 5006 approved instruments or compliance with CNSSI 5000 is required for installation in SCIFs for Voice over Internet Protocol (VoIP) systems installed in a SCIF. TSG6/CNSSI 5006 approved instruments must be installed following the manufacturer’s requirements. For non-TSG6/CNSSI 5006 approved instruments, the security requirements and installation guidelines contained in the National Telecommunications Security Working Group (NTSWG) publication CNSSI 5000 shall be followed for Voice over Internet Protocol (VoIP) systems installed in a SCIF.
C. Unclassified Information Systems
1. Unclassified information systems shall be safeguarded to prevent hardware or software manipulation that could result in the compromise of data.
2. Information systems equipment with telephonic or audio features shall be protected against remote activation and/or removal of audio (analog or digitized) information.
3. Video cameras used for unclassified video teleconferencing and video recording equipment shall be deactivated and disconnected when not in use.
4. Video devices shall feature a clearly visible indicator to alert SCIF personnel when recording or transmitting.
D. Using Closed Circuit Television (CCTV) to Monitor the SCIF Entry Point(s)
1. CCTV may be used to supplement the monitoring of a SCIF entrance and to record events for investigation.
2. The system shall present no technical security hazard to the SCIF.
3. The system and all components, including communications and control lines, shall be exterior to the SCIF perimeter.
4. The system may provide a clear view of the SCIF entrance but not enable the viewer to observe classified information when the door is open nor external control pads or access control components that would enable them to identify PINs.
E. Unclassified Wireless Network Technology
1. The use of devices or systems utilizing wireless technologies pose a high risk and require approval from the AO, CTTA, and IT systems approving authority prior to introduction into the SCIF.
2. Wireless systems shall meet all TEMPEST and TSCM requirements and shall be weighed against the facilities overall security posture (i.e., facility location, threat, as well as any compensatory countermeasures that create SID) when evaluating these systems.
3. All separation and isolation standards provided in TEMPEST standards are applicable to unclassified wireless systems installed or used in SCIFs.
F. Environmental Infrastructure Systems
1. The FFC shall include information on whether or not environmental infrastructure systems (also referred to as building maintenance systems) are located in the SCIF.
Examples include the following:
• Premise management systems
• Environmental control systems
• Lighting and power control units
• Uninterrupted power sources
2. The FFC shall identify all external connections for infrastructure systems that service the SCIF. Examples of the purpose of external connections include the following:
• Remote monitoring
• Access and external control of features and services
• Protection measures taken to prevent malicious activity, intrusion, and exploitation.
G. Emergency Notification Systems
1. The introduction of electronic systems that have components outside the SCIF perimeter is prohibited, with the following exceptions:
a) The system is approved by the AO.
b) The system is required for security purposes.
c) The system is required under life safety regulations.
2. If required, and speakers or other transducers are part of a system that is not wholly contained in the SCIF but are installed in the SCIF for life safety or fire regulations, the system must be protected as follows:
a) All incoming wiring shall breach the SCIF perimeter at one point. TEMPEST or TSCM concerns may require electronic isolation and shall require review and approval by the CTTA.
b) One-way (audio into the SCIF) communication systems shall have a high gain amplifier.
c) Two-way communication systems shall only be approved when absolutely necessary to meet safety/security requirements. They shall be protected so that audio cannot leave the SCIF without the SCIF occupants being alerted when the system is activated.
d) All electronic isolation components shall be installed within the SCIF and as close to the point of SCIF penetration as possible.
H. Systems Access
1. Installation and maintenance of unclassified systems and devices supporting SCIF operations may require physical or remote access. The requirements outlined in this section shall apply to telecommunications devices located within the SCIF or in a controlled area outside the SCIF.
2. Installation and maintenance personnel requiring physical access shall possess the appropriate clearance and access, or will be escorted and monitored at all times within the SCIF by technically knowledgeable, U.S. SCI-indoctrinated personnel.
3. Remote maintenance shall be protected against manipulation or activation.
4. All capabilities for remote maintenance and diagnostic services shall be specified in the FFC.
5. The FFC shall identify all procedures and countermeasures to prevent unauthorized system access, unauthorized system modification, or introduction of unauthorized software.
6. Remote maintenance and diagnosis may be performed from a SCIF or an adjacent controlled area over a protected link in accordance with FIPS AES standards.
7. Telephone systems only may be accessed over an unclassified telephone line as specified in TSG 2 Standard, Section 4.c.
I. Unclassified Cable Control
1. To the extent possible, all telecommunications cabling shall enter the SCIF through a single opening and allow for visual inspection.
2. Cable, either fiber or metallic, shall be accounted for from the point of entry into the
SCIF.
a) The accountability shall identify the precise use of every cable through labeling.
b) Log entries may also be used.
c) Designated spare conductors shall be identified, labeled, and bundled together.
3. Unused conductors shall be removed. If removal is not feasible, the metallic conductors shall be stripped, bound together, and grounded at the point of ingress/egress.
4. Unused fiber shall be uncoupled from the interface within the SCIF, capped, and labeled as unused fiber.
J. Protected Distribution Systems
1. Unencrypted communication cables transmitting SCI between accredited SCIFs shall be installed in a Protective Distribution System that complies with standards established in CNSSI 7003, Protected Distribution System.
2. PDS used to protect SCI shall be approved by the CSA AO.
K. References
1. Overview
a) The NTSWG publishes guidance for the protection of sensitive information and unclassified telecommunications information processing systems and equipment.
b) NTSWG documents are currently in transition from TSG/NTSWG documents to Committee on National Security Systems (CNSS) publications.
c) The List of References is provided for use by personnel concerned with telecommunications security.
2. List of References
a) TSG Standard 1 (Introduction to Telephone Security). Provides telephone security background and approved options for telephone installations in USG sensitive discussion areas.
b) TSG Standard 2 (TSG Guidelines for Computerized Telephone Systems) and Annexes. Establishes requirements for planning, installing, maintaining, and managing CTS, and provides guidance for personnel involved in writing contracts, inspecting, and providing system administration of CTS.
c) TSG Standards 3, 4, 5, and CNSSI 5001. Contains design specifications for telecommunication manufacturers and are not necessarily applicable to facility security personnel.
d) CNSSI 5000. Establishes requirements for planning, installing, maintaining, and managing VoIP systems.
e) CNSSI 5006. Lists approved equipment which inherently provide on-hook security.
f) NTSWG Information Series (Computerized Telephone Systems). A Review of Deficiencies, Threats, and Risks, December 1994). Describes deficiencies, threats, and risks associated with using computerized telephone systems.
g) NTSWG Information Series (Executive Overview, October 1996). Provides the salient points of the TSG standards and presents them in a non-technical format.
h) NTSWG Information Series (Central Office (CO) Interfaces, November 1997).
Provides an understanding of the types of services delivered by the local central office and describes how they are connected to administrative telecommunications systems and devices.
i) NTSWG/NRO Information Series (Everything You Always Wanted to Know about Telephone Security…but were afraid to ask, 2nd Edition, December 1998).
Distills the essence of the TSG standards (which contain sound telecommunications practices) and presents them in a readable, non-technical manner.
j) NTSWG/NRO Information Series (Infrastructure Surety Program…securing the last mile, April 1999). Provides an understanding of office automation and infrastructure system protection that contributes to SCIF operation.
k) NTSWG Information Series (Computerized Telephone Systems Security Plan Manual, May 1999). Assists to implement and maintain the “secure” operation of CTSs as used to support SCIF operations. (The term “secure” relates to the safe and risk-free operation, not the use of encryption or a transmission security device.)
l) Director of National Intelligence, Intelligence Community Directive 702, Technical Surveillance Countermeasures.
m) Director of National Intelligence, Intelligence Community Directive 503, Intelligence Community Information Technology Systems Security Risk Management, Certification and Accreditation.
n) SPB Issuance 00-2 (18 January 2000). Infrastructure Surety Program and the Management Assessment Tool.
Chapter 13 Forms and Plans
Chapter 13. Forms and Plans
Fixed Facility Checklist TEMPEST Checklist Compartmented Area Checklist Shipboard Checklist Submarine Checklist Aircraft/UAV Checklist SCIF Co-Use Request and MOA SCIF Co-Use Request Users Guide Cancellation of SCIF Co-Utilization or Joint-Utilization Pre-Construction Checklist Construction Security Plan (CSP) Inspectable Materials Checklist
SCIF Fixed Facility Checklist V1.5
CLASSIFY ACCORDING TO CLASSIFICATION AUTHORITY
CHECK Applicable blocks
□ Domestic □ Overseas Not COM □ Overseas COM
□ Pre-construction, Complete
Sections as Required by A/O
□ Final FFC Accreditation □ Update/Page Change
Checklist Contents
Section A: General Information
Section B: Security-in-Depth
Section C: SCIF Security
Section D: Doors
Section E: Intrusion Detection Systems (IDS)
Section F: Telecommunication Systems and Equipment Baseline
Section G: Acoustical Protection
Section H: Classified Destruction Methods
Section I: Information Systems/TEMPEST/Technical Security
List of Attachments
FFC Date:
Section A: General Information
1. SCIF Data
Organization/Company Name
SCIF Identification Number (if applicable)
Organization subordinate to (if applicable)
Contract Number & Expiration Date (if applicable)
Concept approval Date/by (if applicable)
Accrediting Office/Accrediting Individual's Name
Defense Special Security Communication System (DSSCS) Information (if applicable)
DSSCS Message Address
DSSCS INFO Address
If no DSSCS Message Address, please provide passing instructions
2. SCIF Location
Street Address
Building Name
Floor(s) Suite(s) Room(s) #
City Base/Post
State/Country Zip Code
3. Mailing Address (if different from SCIF location)
Street or Post Office Box
City State Zip Code
4. Responsible Security Personnel
PRIMARY ALTERNATE
Name
Commercial Phone
DSN Phone
Secure Phone
Cell Secure Fax
Command or Regional Special Security Office/Name (SSO) (if applicable)
Commercial Phone
Other Phone
Accrediting Agency
Type
Class Email
Unclass Email
Other Email
Name
Lat/Long (If No Street) /
5. Accreditation Data (Ref ICS 705-01, Para F.2 & ICS 705-02, Para D.1.a)
a. Indicate storage requirement: □ Closed □ Continuous Operation □ None
b. Indicate the facility type: □ Secure Working Area □ TSWA
□ Yes □ Nod. Co-Use Agreements
e. SAP(s) co-located within SCIF □ Yes □ No
If yes, identify SAP Classification level (check all that apply)
□ SCI □ Top Secret □ Secret □ Confidential
f. SCIF Duty Hours Hours to Hours: Days Per Week:
g. Total square footage that the SCIF occupies:
h. Does the facility have any approved waivers? □ Yes □ No
Provide attachment if required by AO
6. Construction/Modification (Ref: Chapter 3B)
a. Is construction or modification complete? □ Yes □ No □ N/A
If no, enter the expected date of completion:
b. Was all construction completed in accordance with the CSP? □ Yes □ No □ N/A
If NO, explain:
7. Inspections (Ref: Chapter 12 G) (Provide attachment if required by AO)
□ Yes □ No
If yes, provide the following:
1) TSCM Service completed by: On
2) Were deficiencies corrected? □ Yes □ No □ N/A
3) If NO, explain:
c. Compartments of SCI Requested:
□ Open
□ Permanent □ Temporary
a. Has a TSCM Inspection been performed?
b. Last AO compliance periodic inspection/review: On
Were deficiencies corrected? □ Yes □ No □ N/A
If NO, explain:
c. Last self Inspection completed by: On
AO Office Name AO Individual's Name
8. REMARKS:
Section B: Security-in-Depth
1. Answer the questions in this section to describe your Security In Depth (Ref: Chapter 2B)
a. Is the SCIF located on a military installation, embassy compound, USG compound or contractor compound with a dedicated U.S. person response force?
□ Yes □ No
b. Does the SCIF occupy an entire building □ Yes □ No
c. Does the SCIF occupy a single floor of the building □ Yes □ No
d. Does the SCIF occupy a secluded area of the building □ Yes □ No
e. Is the SCIF located on a fenced compound with access controlled vehicle gate and/or pedestrian gate?
□ Yes □ No
f. Fence Type
1) Height:
2) Does it surround the compound? □ Yes □ No
3) How is it controlled?
4) How many gates (vehicle & pedestrian)?
5) Hours of usage?
6) How are they controlled when not in use?
7) Is the Fence Alarmed? □ Yes □ No
If so, describe alarm systems (i.e. - Microwave)
g. Exterior Lighting Type:
1) Fence Lighting
2) Building Lighting
h. Is there external CCTV coverage? □ Yes □ No
If so, describe the CCTV system. (include monitor/coverage locations on map)
i. Exterior Guards
1) What kind of patrols are they? □ Static □ Roving
Clearance level of guards (if applicable)
During what hours/days?
If yes, describe duties:
Any SCIF duties?
2)
3) 4)
□ SCI □ Top Secret □ Secret
□ No□ Yes
□ Yes □ No
□ None
2. Describe Building Security (Please provide legible general floor plan of the SCIF perimeter)
Is the SCIF located in a controlled building with separate access controls, alarms, elevator controls, stairwell control, etc. required to gain access to building or elevator?
□ Yes □ No
If yes, is SCIF controlled by bldg owners? □ Yes □ No
If controlled by SCIF owners, is alarm activation reported to SCIF owners by agreement? □ Yes □ No
b. Construction Type
c. Windows
d. Doors
e. Describe Building Access Control: Continuous? □ Yes □ No
If no, during what hours?
f. Clearance level of guards (if applicable) □ SCI □ Top Secret □ Secret
1) Any SCIF duties? □ Yes □ No
If yes, describe duties?
During what hours/days?
3. Describe Building Interior Security
Are office areas adjacent to the SCIF controlled and alarmed? □ Yes □ No
If yes, describe adjacent areas and types of alarm systems.
Controlled by SCIF Owner? □ Yes □ No
If controlled by Bldg owner, alarm activation reported to SCIF owner by agreement? □ Yes □ No
4. Remarks (Describe any additional security measures not addressed in this section) What external security attributes and/or features should the AO consider before determining whether or not this facility has Security In-Depth? Please identify/explain all factors:
a.
b.
a.
Section C: SCIF Security
1. How is access to the SCIF controlled (Ref: Chapter 8)
a. By Guard Force □ Yes □ No
If yes, what is their minimum security clearance level? □ SCI □ Top Secret □ Secret
b. Is Guard Force Armed? □ Yes □ No □ N/A
c. By assigned personnel? □ Yes □ No
If yes, do personnel have visual control of SCIF entrance door? □ Yes □ No
d. By access control device? □ Yes □ No
If yes, what kind? □ Automated access control system □ Non-Automated
If Non-Automated
1. Is there a by-pass key? □ Yes □ No □ N/A
If yes, how is the by-pass key protected?
2. Manufacturer: Model:
(Explain in Remarks if more space is required) If Automated
1. Is there a by-pass key? □ Yes □ No □ N/A
If yes, how is the by-pass key protected?
2. Manufacturer: Model:
(Explain in Remarks if more space is required)
3. Are access control transmission lines protected by 128-bit encryption/FIPS 140? □ Yes □ No
If no, explain the physical protection provided
4. Is automated access control system located within a SCIF or an alarmed area controlled at the SECRET level?
□ Yes □ No
5. Is the access control system encoded and is ID data and PINs restricted to SCI-indoctrinated personnel?
□ Yes □ No
6. Does external access control outside SCIF have tamper protection? □ Yes □ No
7. Is the access control device integrated with IDS □ Yes □ No □ N/A
8. Is the access control device integrated with a LAN/WAN System? □ Yes □ No □ N/A
2. Does the SCIF have windows? (Ref: Chapter 3F)
a. Are they acoustically protected? □ Yes □ No □ N/A
If Yes, how:
If No, explain:
b. Are they secured against forced entry? □ Yes □ No □ N/A
If Yes, how:
If No, explain:
□ Yes □ No □ N/A
c. Do they have RF protection? □ Yes □ No □ N/A
If Yes, describe:
3. Do ventilation ducts penetrate the SCIF perimeter? (Ref: Chapter 3G) □ Yes □ No
(Indicate all duct penetrations and their size on a separate floor plan as an attachment)
a. Any ducts over 96 square inches that penetrate perimeter walls? □ Yes □ No
If yes, how are they protected? □ Other as Approved by AO□ Bars/Grills/Metal /Baffles
If Other, Describe Protection:
b. Inspection ports? □ Yes □ No
If yes, are they within the SCIF? □ Yes □ No
If no, are they secured with AO approved High Security Lock? □ Yes □ No
If No, explain:
c. Do all ventilation ducts penetrating the perimeter meet acoustical requirements? □ Yes □ No (NOTE: All ducts and vents, regardless of size may require acoustical protection)
If yes, how are they protected? □ Metal Baffles □ Noise Generator□ Z-Duct
If Other, Describe Protection:
4. Construction (Ref: Chapter 3)
b. Describe Perimeter Wall Construction:
c. True ceiling
Describe material and thickness:
d. False ceiling? □ Yes □ No
1) If yes, what is the type of ceiling material?
2) What is the distance between false and true ceiling?
d. Are they protected against visual surveillance? □ Yes □ No □ N/A
If Yes, how:
If No, explain:
2. SCIF windows (continued) (Ref: Chapter 3F)
e. True floor
Describe material and thickness:
f. Raised floor? □ Yes □ No
1) If yes, what is the type of false flooring?
2) What is the distance between raised and true floor?
a. Is the entire wall assembly finished from true floor to true ceiling? □ Yes □ No
□ Other
4. REMARKS:
Section D: SCIF Doors
a. A GSA-approved pedestrian door deadbolt meeting the most current version of Federal Specification FF-L-2890. NOTE: Previously AO approved FF-L-2740 integrated locking hardware may be used. Additional standalone and flush-mounted dead bolts are prohibited.
□ Yes □ No
b. A combination lock meeting the most current version of Federal Specification FF-L-2740? NOTE: Previously AO approved combination lock or deadbolt lock type may be used.
□ Yes □ No
If NO, explain:
If NO, explain:
c. Is an approved access control device installed? □ Yes □ No
If NO, explain:
2. Secondary Door Criteria Secondary doors may be established with AO approval and as required by building code, safety and accessibility requirements.
□ Yes □ Noa. Does the SCIF have any approved Secondary doors?
□ Yes □ No
The following door type definitions are referenced in this section: (Reference 3E)
a. Primary door: A SCIF perimeter door recognized as the main entrance.
b. Secondary door: A SCIF perimeter door employed as both an entry and egress door that is not the Primary door.
1. Is the Primary door equipped with the following
c. Emergency egress-only door: A SCIF perimeter door employed as an emergency egress door with no entry capability.
d. Is there a by-pass keyway for use in the event of an access control system failure? □ Yes □ No
If NO, explain:
If Yes, are all approved Secondary doors equipped with the following:
1) A GSA-approved pedestrian door egress device with deadbolt meeting the most current version of Federal Specification FF-L-2890 for secondary door use If NO, explain:
2) Approved access control hardware which n D: Doors must be deactivated when the SCIF is not occupied, or as determined by the AO. □ Yes □ No
If NO, explain:
□ Yes □ Nob. Does the SCIF have any Emergency Egress-only doors?
□ Yes □ No
If Yes, do all approved Emergency Egress-only doors meet the following:
1) Are they installed as required by building code, safety and accessibility requirements?
If NO, explain:
3. Criteria for ALL SCIF Doors (Ref: Chapter 3E)
□ Yes □ Noa. Do all SCIF perimeter doors comply with applicable building code, safety, and accessibility requirements as determined by the authority having jurisdiction?
If NO, explain:
□ Yes □ Nob. Does the SCIF SOP includes procedures to ensure all doors are secured at end of day?
If NO, explain:
□ Yes □ No
c. Are all SCIF perimeter pedestrian doors equipped with an automatic, non-hold door-closer which shall be installed internal to the SCIF?
If NO, explain:
□ Yes □ No
d. Are door hinge pins that are accessible from outside of the SCIF modified to prevent removal of the door, e.g., welded, set screws, dog bolts, etc?
If NO, explain:
2) Are they equipped with GSA-approved pedestrian door emergency egress device with deadbolt configuration meeting the most current version of Federal Specification FFL-2890 for exit only door use or an AO approved alternate device with similar functionality ?
□ Yes □ No
If NO, explain:
3) Are they alarmed 24/7 and have a local audible annunciator that must be activated if the door is opened? □ Yes □ No
If NO, explain:
4. Describe SCIF door fabrication and unique criteria
a. Wooden SCIF doors are at least 1 ¾ inch-thick solid wood core (i.e. wood stave, structural composite lumber).
□ Yes □ No □ N/A
□ Yes □ No
e. Do SCIF perimeter doors and frame assemblies meet acoustic requirements unless declared a non-discussion area?
If NO, explain:
□ Yes □ No
If NO, explain:
□ Yes □ Nog. Do all SCIF Perimeter doors meet TEMPEST requirements per CTTA guidance?
If NO, explain:
f. Are all SCIF perimeter doors alarmed in accordance with Chapter 7 of the Technical Specifications?
Section D: SCIF Doors
5. REMARKS:
Section D: Doors
b. Steel doors have the following specifications:
1) 1 ¾ inch-thick face steel equal to minimum 18-gauge steel.
2) Hinges reinforced to 7-gauge steel and preferably a lift hinge.
3) Door closure installation reinforced to 12-gauge steel.
4) Lock area pre-drilled and/or reinforced to 10-gauge steel.
□ Yes □ No □ N/A
c. Vault door are GSA-approved Class 5 and not used to control day access. □ Yes □ No □ N/A
d. Roll-up Doors are a minimum 18-gauge steel, secured inside the SCIF using dead-bolts on both sides of the door and alarmed in accordance with Chapter 7 □ Yes □ No □ N/A
e. SCIF perimeter Double Doors have the following specifications:
1) The fixed leaf shall be secured at the top and bottom with deadbolts.
2) An astragal shall be attached to one door.
3) Each leaf of the door shall have an independent security alarm contact.
□ Yes □ No □ N/A
f. Adjacent SCIF adjoining doors specifications
1) Be dead bolted on both sides
2) Be alarmed on both sides according to chapter 7.
3) Meet acoustic requirements as required.
4) Be covered by AO standard operating procedures.
5) Other door types shall be addressed on an individual basis as approved by the AO.
□ Yes □ No □ N/A
Section E: Intrusion Detection Systems
1. General IDS Description (Ref: Chapter 7A)
a. Has the IDS configuration been approved by the AO? □ Yes □ No
IDS installed by:
c. Premise Control Unit (PCU)
Manufacturer Model Number
Tamper Protection □ Yes □ No Is the PCU located inside the SCIF perimeter (indicated on floor plan)? □ Yes □ No
If no, explain b.
d.
e. Accessible points of entry/perimeter? □ Yes □ No
Any others? Explain;
f. Has the IDS passed AO or UL 2050 installation and acceptance tests? □ Yes □ No
If yes, attach a copy of certificate (Non-commercial proprietary system must answer all questions)
g. High Security Switches Type I □ Yes □ No
h. High Security Switches Type II □ Yes □ No
i. Motion sensor
j. Are any other intrusion detection equipment sensors/detectors in use?
□ Yes □ No
k. Does the IDS extend beyond the SCIF perimeter? □ Yes □ No
l. Can the status of PCU be changed from outside IDS protection? □ Yes □ No
If yes, is an audit conducted daily? □ Yes □ No
m. Do any intrusion detection equipment components have audio or video capabilities?
□ Yes □ No
If yes, explain.
n. PCU administrator SCI indoctrinated? □ Yes □ No
o. Is external Transmission Line Security used? □ Yes □ No
If yes, explain.
If yes, explain.
p. What is the method of line security? National Institute of Standards and Technology
(NIST) FIPS AES encryption?
□ Yes □ No
Make Model Manufacturer Function
Please identify make, model and manufacturer and function and the location of interior motion detection protection(indicate on floor plan)
1) If yes, has the encryption been certified by NIST or another independent testing laboratory?
□ Yes □ No
2) If not NIST standard, is there an alternate? □ Yes □ No
If yes, explain.
3) Does the alternate line utilize any cellular or other Radio Frequency (RF) capability? □ Yes □ No
Manufacturer Model Number
q. Does any part of the IDS use local or wide area network (LAN/WAN)? □ Yes □ No □ N/A
1) Is the host computer dedicated solely for security purposes? □ Yes □ No □ N/A
2) Is the host computer secured within an alarmed area at the physically or higher level protected spaces or higher level? □ Yes □ No □ N/A
3) Is the host computer protected through firewalls or similar devices? □ Yes □ No □ N/A
4) Is the password for the host computer unique for each user and at least 8-characters long consisting of alpha, numeric, and special characters?
□ Yes □ No □ N/A
5) Is the password changed semi-annually? □ Yes □ No □ N/A
6) Are remote security terminals protected the same as the host computer? □ Yes □ No □ N/A
2. Is emergency power available for the IDS? □ Yes □ No □ N/A
Generator? □ Yes □ No If yes, how many hours?
Battery? □ Yes □ No If yes, how many hours?
3. Who monitors is the IDS alarm monitor station and where is it located?
4. Does the monitor station have any remote capabilities (i.e., resetting alarms, issuing PINs, accessing/securing alarms, etc.?
□ Yes □ No □ N/A
If yes, explain:
If no, explain:
5. Does the IDS have any automatic features (i.e., timed auto-secure, auto-access capabilities?
□ Yes □ No □ N/A
6. Does the PCU/keypad have dial out capabilities? □ Yes □ No □ N/A
7. IDS response personnel □ Yes □ No □ N/A
a. Who provides initial alarm response?
b. Does the response force have a security clearance? □ Yes □ No If yes, what is the clearance level? □ SCI □ Top Secret □ Secret
c. Do you have a written agreement with external response force? □ Yes □ No
d. Emergency procedures documented? □ Yes □ No
e. Response to alarm condition: Minutes
f. Are response procedures tested and records maintained? □ Yes □ No
If no, explain:
a. Has the IDS alarm monitor station been installed to Underwriters Laboratories certified standards?
□ Yes □ No
Contractor facility submit copy of Certificate
g. Has a catastrophic failure plan been approved by the AO? □ Yes □ No
If no, explain:
10. REMARKS:
Section F: Telecommunication Systems and Equipment Baseline
1. Does the facility have any unclassified telephones that are connected to the commercial public switch telephone network (PSTN)? □ Yes
Identify the method of on-hook protection by completing items below
NOTE: TSG 6 approved phones can be found at the following link:
https://www.dni.gov/files/NCSC/documents/products/TSG-Approved-Equipment-List-May-2017.pdf
□ Yes
Manufacturer Model Number TSG Number (if applicable)
b. CNSSI 5006 (TSG-6) approved d isconnect device? □ Yes
1) Line disconnect? □ Yes
2) Ringer protection? □ Yes
Manufacturer Model Number
c. CNSSI 5002 (TSG-2) configured computerized telephone system (CTS)? □ Yes
1) If yes, please provide the following information about the CTS Manufacturer Model
3) Does the Physically Protected Space (PPS) meet equivalent security and access control standards as the supported SCIF?"
4) How are all cables, signal lines and intermediate writing frames between the SCIF telephones and the CTS physically protected within a physically controlled space?
5) Are all program media, such as tapes and/ or disks, from the CTS afforded physical protection from unauthorized alterations? □ Yes
□ No □ N/A
□ No □ N/A
□ No □ N/A
□ No □ N/A
□ No □ N/A
□ No
a. CNSSI 5006 (TSG-6) approved telephone or instrument
(Please identify all telephone equipment/stations and/or instruments…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .