AFSSI_7702_30Jan08_through_Change_1_17Oct08.pdf

PDF 659 KB Posted

Attached to
Combat Rescue Helicopter (CRH) Federal contract opportunity
Solicitation number
FA8629-12-R-2400
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Wright Patterson Air Force Base

About this file

AFSSI 7702

View the file

Other files for this federal contract opportunity

Other files attached to Combat Rescue Helicopter (CRH), newest first.
File Type Posted
RFP_Amd_0004_Signed.pdf PDF
Sec_M_-Eval_Factors_for_Award_MASTER_17_Dec.pdf PDF
Sec_J _Attachment_3_-_SOW__14_Nov_12_(Master).pdf PDF
Sec_L_Attachment_1_-_TEP_Workbook_(14_Nov)_w_Adjustment.xlsx XLSX spreadsheet
Amd_0002_SIGNED.pdf PDF
Sec_L_-_Instructions_to_Offerors_MASTER_14_Nov.pdf PDF
CRH_Final_RFP_Industry_Q A_Matrix_-_16_Nov_12_Unsecure.pdf PDF
CRH_Final_RFP_Industry_Q A_Matrix_30_Oct_12.pdf PDF
Sec_J _Attachment_7_-_VIQ_Matrix_19_Jun.pdf PDF
Sec_J _Attachment_20_-_CRH_IMP_02_Oct_12.pdf PDF
Sec_J _Attachment_25_-_2794-Contract_Prime_LRIP_19_Jul.pdf PDF
Sec_J _Attachment_13_-_Base_Support_Agreement_20_Jul.pdf PDF
Sec_M_-Eval_Factors_for_Award_MASTER_21_Sep_Credit.pdf PDF
Sec_J _Attachment_21_-_Training_System_SE_Listing-_24_Aug.pdf PDF
Sec_J _Attachment_28_-_2794-Contract_Prime_FRP_19_Jul.pdf PDF
Sec_J _Attachment_8_-_Restrictions_on_Technical_Data_and_Computer_Software_21_Jun.pdf PDF
Sec_A_through_K_-_19_Oct.pdf PDF
Sec_L _Attachment_9_-_PAST_PERFORMANCE_QUESTIONNAIRE_TRACKING_RECORD.pdf PDF
Sec_L_-_Instructions_to_Offerors_MASTER_1_Oct_TEP_Credit.pdf PDF
Sec_J _Attachment_23_-_2794-Contract_Sub_19_Jul.pdf PDF
Sec_J _Attachment_14_-_Aircraft_Spares_Listing_-_19_Jun.pdf PDF
Sec_L _Attachment_4_-_CEO_Certification_Ltr_24_Sep.pdf PDF
Sec_J _Attachment_30_-_2794-Contract_RDT_FRP_19_Jul.pdf PDF
Sec_J _Attachment_32_-_Listing_of_Licenses_for_CLIN_0006.pdf PDF
Sec_L _Attachment_10_-_PAST_PERFORMANCE_SAMPLE_CONSENT_LETTER.pdf PDF
Sec_L _Attachment_14_-_DCMA_14_Point_SHA_Macro.pdf PDF
Sec_J _Attachment_10_-_SE_Mobility_Package_Kit_Listing_-_19_Jun.pdf PDF
CRH_Offeror_RFP_Question_Format.xlsx XLSX spreadsheet
Sec_L _Attachment_11_-_PAST_PERFORMANCE_SAMPLE_QUESTIONNAIRE_CORP_COVER_LTR_19JUL.pdf PDF
Sec_L _Attachment_1_-_TEP_Workbook_(24_Sep)_w_Adjustment.xlsx XLSX spreadsheet
Sec_J _Attachment_6_-__LFTE_Assets_List_19_Jun_12.pdf PDF
Sec_J _Attachment_12_-_CLIN_and_SOW_Matrix_9_Oct.pdf PDF
Sec_J _Attachment_24_-_2794-Contract_RDT_EMD_19_Jul.pdf PDF
Sec_J _Exhibit_B_CDRL_OMIT_07-12-2012rev1010.pdf PDF
Sec_L _Attachment_13_-_Past_Performance_Client_Authorization_Ltr_20_Jul.pdf PDF
Sec_J _Attachment_17_-_RSP_Kit_Listing_-_19_Jun.pdf PDF
Sec_J _Attachment_5_-_AFMC_Form_158.pdf PDF
Sec_J _Attachment_26_-_2794-Contract_Sub_LRIP_19_Jul.pdf PDF
CRH_RFP_Cover_Letter.pdf PDF
Sec_J _Attachment_15_-_Aircraft_SE_Listing-_19_Jun.pdf PDF
Sec_L _Attachment_3_-_Past_Performance_Information_Tools_24_May_12.pdf PDF
AFRL-HE-WP-TR-2007-0064_Human_Perf_in_Simulated_Rotorcraft_Downwash_Environment.pdf PDF
MSO-C129b.pdf PDF
AF_Drawing_9579777A.pdf PDF
MSO-C145a_GPS.pdf PDF
CRH_Bidders_Library_11_Oct_12.xlsx XLSX spreadsheet
Mil-HDBK-516B_Expanded.pdf PDF
AFSSI_8580_Remanence_Security.pdf PDF
AFFTC-TIH-93-01 _Air_Force_Flight_Test_Center_Test_Plan_Preparation_Guide.pdf PDF
MSO-C144_Airborne_GPS_Antenna.pdf PDF
Show all 50

Combat Rescue Helicopter (CRH) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BY ORDER OF THE AIR FORCE SYSTEMS SECURITY INSTRUCTION 7702

SECRETARY OF THE AIR FORCE 30 JANUARY 2008

Incorporating Through Change 1, 17 October 2008

Communications and Information

EMISSION SECURITY COUNTERMEASURES REVIEWS

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSABILITY: Publication is available for downloading or ordering on the Information Assurance (IA) website at: https://private.afca.af.mil/ip/

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: AFCA/EVPI Certified By: SAF/XCPPI Kenneth Brodie Pages: 212

This instruction implements the Emission Security Countermeasures Reviews portion of Air Force Instruction (AFI) 33-202, Volume 1, Network and Computer Security (will become AFI 33-200, Information Assurance (IA) Management), and establishes Emission Security Countermeasures Reviews requirements for Information Assurance (IA) in compliance with the Committee on National Security Systems (CNSS) Policy No 300, National Policy on Control of Compromising Emanations. It gives the implementation requirements for the Emission Security Countermeasures Reviews component of IA as outlined in AFI 33-202, Volume 1 (will become AFI 33-200). It applies to Air Force military, civilian, and contractor personnel under contract by Department of Defense (DoD) who develop, acquire, deliver, administer, or manage Emission Security (EMSEC) for Air Force information systems. This instruction applies to the Air National Guard (ANG) and Air Force Reserve Command (AFRC). The term major command (MAJCOM), when used in this publication, includes field operating agencies and direct reporting units. This Air Force Systems Security Instruction (AFSSI) is authorized by AFI 33-102, Communications and Information Specialized Publications. Direct questions or comments on the contents of this instruction, through appropriate command channels, to Headquarters Air Force Communications Agency (HQ AFCA/EVP), 203 W. Losey Street, Room 2100, Scott AFB IL 62225-5222. Refer recommended changes and conflicts between this and other publications, through appropriate command channels, to HQ AFCA/EASD, 203 W. Losey Street, Room 1100, Scott AFB IL 62225-5222, using Air Force (AF) Form 847, Recommendation for Change of Publication. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN) 33-363, Management of https://private.afca.af.mil/ip/

Records, and disposed of in accordance with Air Force Records Information Management System (AFRIMS) Records Disposition Schedule (RDS) located at https://afrims.amc.af.mil/rds_series.cfm. See Attachment 1 for a glossary of references and supporting information. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force.

SUMMARY OF CHANGES

This interim change (IC-1) updates the applies statement in the purpose paragraph. The Table of Contents was updated to reflect the correct page numbers for all paragraphs. Paragraphs 5.4.1, 5.4.2, and 5.4.5 were changed to provide clarity. In paragraph 6.4.1.6 the second “6” was changed to “4” to correct paragraph numbering. This IC updated the information in paragraphs

6.5.1 through 6.5.8 to provide clarity. Paragraph 10.49.5.5 was changed for clarity. It corrected a publication reference and several acronyms and abbreviations in Attachment 1. This change replaced the current version of the “Sample of a Completed AF Form 4170” (highlighted by various colors), located in Attachment 15, with a clear version. Attachment 16 was added to update A16.1., A16.2., and the summary paragraph in Figure A16.1 to provide clear instructions for handling the completed AF Form 4170.

This instruction replaces substantial portions of AFI 33-203, Volume 3, Emission Security Countermeasures Reviews.

Table of Contents

Chapter 1 - GENERAL INFORMATION 9

1.1. Introduction 9

1.2. Applicability. 9

1.3. Objectives. 10

Chapter 2 - ORGANIZATIONAL ROLES AND RESPONSIBILITIES 11

2.1. Secretary of the Air Force, Policy and Resources Directorate, Policy and Compliance Division (SAF/XCPP). 11

2.2. Headquarters Air Force Communications Agency (HQ AFCA). 11

2.3. Certified TEMPEST Technical Authority (CTTA): 11

Chapter 3 - EMISSION SECURITY (EMSEC) POLICY 12

3.1. Emission Security (EMSEC) Process. 12

3.2. Emission Security (EMSEC) Countermeasures Reviews. 13

3.3. Completing the Countermeasures Reviews. 13

3.4. Maintaining Emission Security (EMSEC). 13

3.5. Emission Security (EMSEC) Testing. 13

3.6. Emission Security (EMSEC) Countermeasures. 13

3.7. Waivers, Deviations and Exceptions. 13

https://afrims.amc.af.mil/rds_series.cfm

Chapter 4 - THE INFORMATION SYSTEMS COUNTERMEASURES REVIEW 14

4.1. Introduction. 14

4.2. Systematic Approach. 14

4.3. Application Requirement. 15

4.4. Determine the Inspectable Space. 15

4.5. Identify Equipment TEMPEST Characteristics. 16

4.6. Selecting Countermeasures. 17

Table 4.1. Countermeasures Requirements. 18

4.7. Estimating Cost. 19

4.8. Analyzing the Results. 19

4.9. Documenting the Results. 19

4.10. Completing the Information Systems Countermeasures Review. 19

Chapter 5 - THE COMMUNICATIONS SYSTEMS COUNTERMEASURES

REVIEW 20

5.1. Introduction. 20

5.2. Installation Requirement. 20

5.3. Transmitting Equipment. 20

Table 5.1. Separation Requirements for Transmitters. 20

Table 5.2. Separation Requirements for Signal and Control Wire Lines. 21

5.4. Special Items. 22

5.5. Estimating Cost. 24

5.6. Analyzing the Results. 24

5.7. Documenting the Results. 24

5.8. Completing the Information Systems Countermeasures Review. 24

Chapter 6 - THE CRYPTOGRAPHIC EQUIPMENT COUNTERMEASURES

REVIEW 25

6.1. Introduction. 25

6.2. Installation Requirement. 25

6.3. Secure Telephone Unit-III (STU-III), Secure Terminal Equipment (STE), and Like Items. 25

6.4. Cryptographic System KIV-7. 25

6.5. Cryptographic System (KG-75, KG-175). 26

6.6. FORTEZZA For Classified (FFC). 27

6.7. Electronic Key Management System (EKMS). 27

6.8. All Other Cryptographic Equipment. 28

6.9. Changing From Unclassified to Classified Processing. 28

6.10. Analyzing the Results. 29

6.11. Documenting the Results. 29

6.12. Completing the Cryptographic Equipment Countermeasures Review. 29

Chapter 7 - COMPLETING THE COUNTERMEASURES REVIEWS 30

7.1. Introduction. 30

7.2. Classification Marking. 30

7.3. Authentication Documentation. 30

7.4. Tracking and Address Information. 30

7.5. Validating the Countermeasures Reviews. 30

7.6. Inform the User. 31

7.7. Date. 32

7.8. Apply the Countermeasures. 32

7.9. Emission Security (EMSEC) Inspection. 32

7.10. Waivers. 32

7.11. Emission Security (EMSEC) Certification. 32

7.12. File Copy. 32

7.13. Reassessments and Recertifications. 32

Chapter 8 - EMISSION SECURITY MAINTENANCE 34

8.1. Maintaining Equipment and Countermeasures. 34

8.2. Maintenance Requirements. 34

8.3. Ensuring the Integrity of TEMPEST-Certified Equipment. 34

8.4. When Not to Maintain the TEMPEST Integrity. 35

8.5. Transportation of Equipment for Maintenance. 36

8.6. Repair Facilities. 36

8.7. Emission Security (EMSEC) Documentation-of-Maintenance Requirements. 36

8.8. Disposing of TEMPEST-Certified Equipment. 36

Chapter 9 - EMISSION SECURITY (EMSEC) TESTING 37

9.1. Purpose of Testing. 37

9.2. Kinds of Emission Security (EMSEC) Tests. 37

9.3. When to Test. 37

9.4. Requesting a Test. 38

9.5. Emission Security (EMSEC) Test Results. 38

Chapter 10 - EMISSION SECURITY (EMSEC) COUNTERMEASURES 39

10.1. Introduction. 39

10.2. Fundamentals of Compromising Emanations. 39

10.3. Requirement—Contain Comprimising Emanations 41

10.4. Containing Radiated Compromising Emanations 41

10.5. Containing Conducted Compromising Emanations. 42

10.6. RED and BLACK Concept. 42

10.7. RED and BLACK Equipment. 42

10.8. Countermeasure -- RED Equipment and BLACK Equipment Separation. 43

10.9. Countermeasure -- RED Equipment and BLACK Wire Line Separation. 44

10.10. Countermeasure -- RED Equipment and BLACK Power Line Separation. 45

10.11. Countermeasure -- RED Equipment and BLACK Signal Ground Wire Separation. 46

10.12. Countermeasure -- RED Equipment and Fortuitous Conductor Separation. 47

10.13. Countermeasure -- Low-Level Signaling. 48

10.14. Signal Lines. 48

10.15. RED and BLACK Wire Lines. 49

10.16. Countermeasure -- RED Wire Line and BLACK Equipment Separation. 49

10.17. Countermeasure -- RED Wire Line and BLACK Wire Line Separation. 50

10.18. Countermeasure -- RED Wire Line and BLACK Power Line Separation. 51

10.19. Countermeasure -- RED Wire Line and BLACK Signal Ground Wire Separation. 52

10.20. Countermeasure -- RED Wire Line and Fortuitous Conductor Separation. 53

10.21. Shielded Signal Wire Lines. 54

10.22. Fiber Optic Signal Lines. 54

10.23. Countermeasure -- Shielded RED Wire Lines. 55

10.24. Countermeasure -- Shielded BLACK Wire Lines. 56

10.25. Countermeasure -- BLACK Wire Line Isolation. 57

10.26. RED and BLACK Power. 59

10.27. Countermeasure -- RED Power. 60

10.28. Countermeasure -- Filtered RED Power. 61

10.29. Countermeasure -- RED Power Line and BLACK Equipment Separation. 63

10.30. Countermeasure -- RED Power Line and BLACK Wire Line Separation. 65

10.31. Countermeasure -- RED Power Line and BLACK Power Line Separation. 66

10.32. Countermeasure -- RED Power Line and BLACK Signal Ground Wire Separation. 67

10.33. Countermeasure -- RED Power Line and Fortuitous Conductor Separation. 68

10.34. Introduction to Grounds. 69

10.35. RED and BLACK Signal Grounds. 71

10.36. Countermeasure -- RED Signal Ground Wire and BLACK Equipment Separation. 72

10.37. Countermeasure -- RED Signal Ground Wire and BLACK Wire Line Separation. 74

10.38. Countermeasure -- RED Signal Ground Wire and BLACK Power Line Separation. 74

10.39. Countermeasure -- RED Signal Ground Wire and BLACK Signal Ground Wire Separation. 75

10.40. Countermeasure -- RED Signal Ground Wire and Fortuitous Conductor Separation. 76

10.41. Countermeasure -- BLACK Signal Ground Wire and BLACK Equipment Separation. 77

10.42. Countermeasure -- BLACK Signal Ground Wire and BLACK Wire Line Separation. 78

10.43. Countermeasure -- BLACK Signal Ground Wire and BLACK Power Line Separation. 79

10.44. Countermeasure -- BLACK Signal Ground Wire and Fortuitous Conductor Separation. 79

10.45. Ground Checks. 80

10.46. Fortuitous Conductors. 81

10.47. Countermeasure -- Fortuitous Conductor Isolation. 81

10.48. Distribution Facilities. 82

10.49. Countermeasure -- Distribution Facility Installation. 83

10.50. Countermeasure -- TEMPEST-Certified Equipment. 88

10.51. Countermeasure -- Shielding. 89

10.52. Countermeasure -- BLACK Telephone Systems. 91

10.53. Countermeasure -- BLACK Intercom and Public Address Systems. 92

10.54. Countermeasure -- BLACK Local Area Networks (LAN). 93

10.55. Countermeasure -- Comfort Music Systems. 94

10.56. Countermeasure -- BLACK Cable Television Systems. 95

10.57. Countermeasure -- BLACK Television-Video Cassette Recorder (VCR) Systems. 95

10.58. Secure Telephones. 96

10.59. Countermeasure -- Timing and Control Lines Installation Guidance. 96

10.60. Countermeasure -- Utility Control Cables. 97

10.61. Operating and Maintenance Practices. 97

10.62. Control of RED Equipment. 97

10.63. Adopted and Prescribed Forms. 98

Attachment 1 - GLOSSARY OF TERMS AND SUPPORTING INFORMATION 99

Attachment 2 - TRANSPORTABLE SYSTEMS IN A TACTICAL ENVIRONMENT 104

Attachment 3 - AIRCRAFT 106

Attachment 4 - DOCUMENTING THE COUNTERMEASURES REVIEWS 108

Attachment 5 - GENERIC ZONE ASSIGNMENTS (GZA) 114

Attachment 6 - FACILITY ZONE A, EQUIPMENT ZONE A 116

Attachment 7 - FACILITY ZONE B, EQUIPMENT ZONE A 121

Attachment 8 - FACILITY ZONE C, EQUIPMENT ZONE A 125

Attachment 9 - FACILITY ZONE A, EQUIPMENT ZONE B 129

Attachment 10 - FACILITY ZONE B, EQUIPMENT ZONE B 138

Attachment 11 - FACILITY ZONE C, EQUIPMENT ZONE B 147

Attachment 12 - FACILITY ZONE A, EQUIPMENT ZONE C 155

Attachment 13 - FACILITY ZONE B, EQUIPMENT ZONE C 165

Attachment 14 - FACILITY ZONE C, EQUIPMENT ZONE C 174

Attachment 15 - EMISSION SECURITY (EMSEC) ASSESSMENTS 183

Attachment 16 - EXAMPLE OF EMISSION SECURITY (EMSEC)

REQUIREMENTS MEMORANDUM 191

Attachment 17 - EXAMPLE OF EMISSION SECURITY (EMSEC)

CERTIFICATION MEMORANDUM 192

Attachment 18 - EMISSION SECURITY (EMSEC) TESTING 193

Attachment 19 - SHIELDED CABLES 198

Attachment 20 - FILTERS AND ISOLATORS 199

Attachment 21 - MAINTENANCE OF SHIELDED ENCLOSURES 205

Attachment 22 - APPLYING ADMINISTRATIVE COMMUNICATIONS

COUNTERMEASURES 207

Chapter 1

GENERAL INFORMATION

1.1. Introduction. A major goal of IA is to assure the availability, integrity, and confidentiality of information and information systems. To this end, the IA disciplines of communications security (COMSEC), computer security (COMPUSEC), and emission security (EMSEC) have, of necessity, become interdependent. EMSEC mostly supports the “confidentiality” requirement, to deny access to classified and, in some instances, unclassified information and contain compromising emanations within an inspectable space. Instances of when you must consider unclassified information are addressed in AFMAN 33-214, Volume 1 (S), Emission Security Assessments (U) (will become AFSSI 7701 [S]). The term “classified information,” as used in this instruction, includes those instances. This is accomplished by identifying requirements from the broader view of IA and providing the appropriate protection at the least possible cost. Key to this is a partnership between the IA office and the user.

1.1.1. The objective of EMSEC is to contain compromising emanations within an inspectable space.

1.1.1.1. The wing IA office assesses the need for EMSEC as part of IA; it determines the required countermeasures; advises commanders of vulnerabilities, threats, and risks; and recommends a practical course of action.

1.1.1.2. The user identifies the systems that will process classified and, in some instances, unclassified information; the volume, relative sensitivity, and perishability of the information; the physical control measures in effect around the area that will process classified information; and applies identified countermeasures.

1.1.2. An understanding of the EMSEC problem is essential to meeting EMSEC goals. The EMSEC problem is explained in AFMAN 33-214, Volume 1 (S) (will become AFSSI 7701 [S]).

1.1.3. The national managers used risk management principles to develop the minimum requirements identified in this instruction. Since the risk is accepted at the national-level, no further risk for EMSEC can be accepted.

1.2. Applicability.

1.2.1. Applies to all information systems, including information system components of weapon systems, information systems that provide the management infrastructure and connections among other information systems, and networks that are used to process, store, display, transmit or protect DoD information, regardless of classification or sensitivity. This document is also binding on all users that operate, connect, or interact with information systems owned, maintained, and controlled by the DoD.

1.2.2. More restrictive DoD and Director of Central Intelligence Agency directive requirements governing Special Access Program information take precedence over this instruction.

1.2.3. This instruction is not applicable to Sensitive Compartmented Information (SCI) information systems. For SCI systems, refer to the Joint Department of Defense Intelligence Information Systems/Cryptologic SCI Information Systems Security Standards.

1.3. Objectives. The objective of EMSEC is to deny access to classified and, in some instances, unclassified information and contain compromising emanations within an inspectable space.

Instances of when you must consider unclassified information are addressed in AFMAN 33-214, Volume 1 (S) (will become AFSSI 7701 [S]). The term “classified information,” as used in this instruction, includes those instances. This is accomplished by identifying requirements from the broader view of IA and providing the appropriate protection at the least possible cost. Key to this is a partnership between the IA office and the user. These objectives are met by provision of safeguard and their associated control collectively known as countermeasure.

1.3.1. Safeguards are actions or activities taken to protect information and are an integral part of security disciplines including COMPUSEC, EMSEC, COMSEC, etc.

1.3.2. The wing IA office identifies required IA countermeasures; assesses the need for EMSEC as part of IA; determines the required EMSEC countermeasures; advises commanders of vulnerabilities, threats, and risks; and recommends a practical course of action.

1.3.3. The CNSS used risk management principles to develop the minimum EMSEC requirements identified in this instruction. Since the risk is accepted at the national-level, no further risk for EMSEC can be accepted.

Chapter 2

ORGANIZATIONAL ROLES AND RESPONSIBILITIES

2.1. Secretary of the Air Force, Policy and Resources Directorate, Policy and Compliance Division (SAF/XCPP).

2.1.1. Develops policies and procedures for daily communication enterprise operations and maintenance.

2.1.2. SAF/XCPP. Responsible for EMSEC policy according to Air Force Policy Directive (AFPD) 33-2, Information Assurance (IA) Program. Establishes Air Force EMSEC policy and doctrine, and coordinates with the other military departments and government agencies to eliminate duplication and to exchange technical data. Appoints Air Force Certified TEMPEST Technical Authorities (AF-CTTA) according toAFSSI 7700, Emission Security

(EMSEC).

2.2. Headquarters Air Force Communications Agency (HQ AFCA). On behalf of

SAF/XCP:

2.2.1. Advises Headquarters Air Education and Training Command on EMSEC curriculum.

2.2.2. Reviews, approves, or disapproves the installation plans that have EMSEC requirements when the installation is contracted.

2.2.3. Provides Air Force organizations disposition instructions for TEMPEST-certified and formerly TEMPEST-certified equipment.

2.2.4. Maintains files of EMSEC countermeasures reviews and waivers.

2.2.5. Reviews national TEMPEST publications and identifies those required for issuance to Air Force activities. Publications with special applications at bases outside the continental U. S. (OCONUS) are identified. Posts a list of required EMSEC program publications on the AFCA IA home page.

2.2.6. Is assigned AF-CTTA responsibility (see paragraph 2.3).

2.3. Certified TEMPEST Technical Authority (CTTA):

2.3.1. Validates all EMSEC countermeasures reviews.

2.3.2. Issues Emission Security Information Messages.

2.3.3. Distributes guidance on the domestic and foreign technical threat environment as provided by the CNSS.

2.3.4. Tasks all Air Force EMSEC testing.

2.3.5. Provides Air Force EMSEC requirements and guidance for Air Force information systems.

2.3.6. Provides Air Force EMSEC requirements and guidance for all Air Force aircraft.

2.3.7. Represents the Air Force at DoD and national-level TEMPEST forums.

2.3.8. Serves as the Air Force technical consultant for emerging EMSEC issues.

Chapter 3

EMISSION SECURITY (EMSEC) POLICY

3.1. Emission Security (EMSEC) Process. An important part of IA is the certification and accreditation (C&A) process under the DoD Information Assurance Certification and Accreditation Process (DIACAP). The C&A process addresses vulnerabilities and threats with the goal of reducing the risk to an acceptable level. EMSEC is part of the C&A process. The EMSEC process determines protective measures that deny unauthorized persons information collected from the intercept and analysis of emanations from information systems processing classified information. The EMSEC assessment determines if the threat is sufficient to require an EMSEC countermeasures review for information systems, communications systems, and cryptographic equipment. Paragraphs 3.1.1.1. through 3.1.1.7. describe the major steps and where they fit into the C&A process.

3.1.1. Basic EMSEC Process:

3.1.1.1. The user contacts the wing IA office whenever classified information will be processed. The user must do this before processing any such information.

3.1.1.2. The wing IA office makes the information systems, communications systems, and cryptographic equipment assessments to determine the need for EMSEC countermeasures and required IA countermeasures. This is the first half of determining the EMSEC portion of the security policy for the C&A of the information system.

3.1.1.3. When needed, the wing IA office makes the information systems, communications systems, or cryptographic equipment countermeasures reviews to determine specific EMSEC countermeasures based on the threat for that location. This is the second half of determining the EMSEC portion of the security policy for the C&A of the information system.

3.1.1.4. The selection of EMSEC countermeasures is validated by the AF-CTTA at HQ

AFCA.

3.1.1.5. The required countermeasures are given to the user for application or implementation.

3.1.1.6. The wing IA office inspects the application of countermeasures for correctness and effectiveness. The inspection is made during the validation of IA Controls in Activity 2 of DIACAP.

3.1.1.7. The wing IA office certifies the information system, communications system, or cryptographic equipment meets EMSEC requirements as part of the certification phase of the C&A.

3.1.2. The Different EMSEC Problems. The means for escape of compromising emanations are different for information systems, communications systems, and cryptographic systems;

therefore, the EMSEC process is established to treat each of these separately to address their individual hazards. The countermeasures review for each of theses systems determines the required countermeasures.

3.2. Emission Security (EMSEC) Countermeasures Reviews. Like the EMSEC assessments, there are three EMSEC countermeasures reviews: information systems, communications systems, and cryptographic equipment. Complete each review separate from the others and without regard to the outcome of the others. These reviews produce the EMSEC requirements for the information system under review. Document the requirements on AF Form 4170, Emission Security Assessments/Emission Security Countermeasures Reviews. The AF Form 4170 documents EMSEC requirements and is the basis for making the EMSEC inspection; it is not the result of an EMSEC inspection.

3.2.1. Information Systems. Follow the guidance in Chapter 4 to make the information systems countermeasures review.

3.2.2. Communications Systems. Follow the guidance in Chapter 5 for the communications systems countermeasures review.

3.2.3. Cryptographic Equipment. Follow the guidance in Chapter 6 for the cryptographic equipment countermeasures review.

3.3. Completing the Countermeasures Reviews. After selecting and documenting the needed countermeasures, complete documenting the countermeasures reviews. Classification marking, authentication, tracking, validation, informing the user, inspection, certification, and filing procedures are in Chapter 7.

3.4. Maintaining Emission Security (EMSEC). The user must properly maintain the EMSEC countermeasures and equipment used to process classified information. Follow the guidance in Chapter 8.

3.5. Emission Security (EMSEC) Testing. When EMSEC testing is needed to meet EMSEC requirements, follow the guidance in Chapter 9 to request EMSEC testing.

3.6. Emission Security (EMSEC) Countermeasures. The numerous countermeasures used in EMSEC are discussed in Chapter 10. For each countermeasure there is a discussion of the problem requiring a countermeasure, what the countermeasure is, what the countermeasure does, what conditions negate the need for the countermeasure, how to apply the countermeasure when required, and alternatives

3.7. Waivers, Deviations and Exceptions. Requests for exceptions to any of the provisions of this instruction must be submitted through IA channels for approval prior to implementation. All waiver requests for exceptions must be accompanied by complete operational justification. The AF-CTTA reviews these waivers and sends recommendations to the DAA.

Chapter 4

THE INFORMATION SYSTEMS COUNTERMEASURES REVIEW

4.1. Introduction. When the need to control compromising emanations is indicated by the information systems assessment, make an information systems countermeasures review to determine the required control of compromising emanations countermeasures. This review is based on the use of non-TEMPEST-certified equipment. TEMPEST-certified equipment is a countermeasure. The AF-CTTA must validate all requirements for TEMPEST-certified equipment. The possibility of the intercept of compromising emanations is a function of many variables. Chief among these are the:

4.1.1. Amount of inspectable space surrounding the systems processing classified information.

4.1.2. Radiation characteristics of the systems processing classified information.

4.1.3. Radio frequency attenuation offered by the facility containing the systems processing classified information.

4.1.4. Fortuitous conductors near the systems processing classified information.

4.2. Systematic Approach. The Air Force uses a systematic approach to determine the required countermeasures and the degree to which they are applied.

4.2.1. Location. This is the geographic location where the information is processed, the proximity to establishments of countries listed in Annex C of the Committee on National Security Systems Instruction (CNSSI) 7000, (C) TEMPEST Countermeasures for Facilities (U), and other countries that could pose a technical threat to the information.

4.2.2. Volume of Information Processed. This is the total volume and the percentage or volume of processed information at the UNCLASSIFIED, SENSITIVE, CONFIDENTIAL, SECRET, and TOP SECRET-level.

4.2.3. Sensitivity of Information Processed. This is the sensitivity of the processed information (e.g., Department of Energy - Restricted Data; Director of Central Intelligence - SCI; Joint Staff - Single Integrated Operational Plan). This is useful in determining the likelihood that an adversary may target the facility.

4.2.4. Perishability of Information Processed. The processed information has either long-term value (e.g., strategic) or short-term value (e.g., tactical). Long-term information requires a more conservative approach to selecting countermeasures than short-term information.

4.2.5. Physical Control. This is the physical and access control for the facility and area containing the system under review. This includes guards (number, hours of posting, patrols, etc.), badging, control of access to the facility, alarms, procedures to monitor or control uncleared or unauthorized personnel including custodial and janitorial personnel, vending personnel, and telephone and power maintainers and installers. Determine the level of authority that exists for the inspection or removal of personnel who could potentially exploit compromising emanations. Examine the posting of warning signs and the implementation of procedures in effect to exercise control over parking and other areas adjacent to or in close proximity to the facility containing the system under review.

4.2.6. TEMPEST Profile of Equipment. This is the generic or actual TEMPEST profile information for each equipment or system used to process classified information in the facility. Consider existing on-site EMSEC test results for the facility.

4.2.7. Different categories of RED Local Area Networks (LAN), (SECRET Internet Protocol Router Network, North Atlantic Treaty Organization, Coalition, etc.) must adhere to the same separation requirements for components and wiring as RED/BLACK LANs.

4.3. Application Requirement. Apply control of compromising emanations countermeasures according to the instructions in this chapter. The requirements are separate from other EMSEC requirements (communications systems and cryptographic equipment). Apply them even when there are no other EMSEC requirements. Tactical equipment and aircraft are excluded from this universal requirement. See Attachment 2 and Attachment 3 for transportable systems in a tactical environment and aircraft-unique requirements.

4.4. Determine the Inspectable Space. When it is required to control compromising emanations, contain them within the inspectable space. In the planning stages for large projects, the user contacts the IA office as soon as possible. When classified information is to be processed, the IA office contacts the installation’s information security program manager or reviews DoD Regulation (DoDR) 5200.1-R, Information Security Program, for secure room construction standards, and others responsible for constructing or modifying a building. Even for projects as small as the acquisition of a personal computer (PC), the user consults with the IA office early to identify physical security requirements. Adopt measures to meet the security requirements that are effective, practical, and compatible with local policies and provisions.

4.4.1. The IA Office. The IA office identifies the inspectable space by using the guidance in paragraph 4.4.3 and indicates it on a map (see Attachment 4). Attach the map to the AF Form 4170, documenting the information systems, communications systems, and cryptographic equipment countermeasures reviews. The map of the inspectable space is usually unclassified.

4.4.2. The CTTA. The CTTA reviews the map and validates the identified inspectable space as complying with national guidance. This determines the inspectable space. The Defense Intelligence Agency (DIA/DAC-2A) determines inspectable space for DIA-accredited SCI facilities.

4.4.3. Identifying the inspectable space. The inspectable space is not intended to prevent an adversary from making a technical attack but rather to identify the area where the chance of discovery is too risky thereby deterring an adversary. Therefore, the inspectable space takes advantage of existing physical security.

4.4.3.1. Inspectable space is defined as “the three-dimensional space surrounding systems that process classified or sensitive information within which TEMPEST exploitation is not considered practical or where legal authority to identify or remove a potential TEMPEST exploitation exists.” This definition is explained as follows:

4.4.3.1.1. Three-Dimensional Space. This term means up and down as well as around.

4.4.3.1.2. Not Practical. An adversary conducting a TEMPEST-exploitation operation on a military installation would require extensive equipment in a vehicle, in close proximity to the target. Such activity could easily be detected and reported to Security Forces. An attack conducted from outside a military installation would risk detection, identification, and potential prosecution.

4.4.3.1.3. Legal Authority to Identify or Remove a Potential TEMPEST Exploitation.

The United States (U.S.) Government has the authority on every base in the U.S., its territories and possessions, and on some bases under foreign control, to identify or remove, in concert with the host nation’s security personnel, any potential adversary.

In some countries the U.S. Government has legal authority, but the host country has areas where U.S. personnel are either not authorized to enter or require prior notice.

If prior notice of less than one hour is required, then the U.S. Government has access.

If prior notice of more than one hour is required, then the U.S. Government does not have access and that area is not considered as inspectable space.

4.4.3.2. Take advantage of circumstances that keep adversaries away or increase either the physical distance or the zone rating.

4.4.3.2.1. For radiated compromising emanations, 6 inches of reinforced concrete provides a nominal 8 decibels (dB) of attenuation. When the inspectable space is defined in distance, a steel pan, poured concrete floor, or ceiling provides about 20 dB of attenuation adding one zone level to the inspectable space in that direction.

That is, when the inspectable space is 1 meter but less than 20 meters (Zone A) the inspectable space becomes Zone B or when the inspectable space is 20 meters but less than 100 meters (Zone B) the inspectable space becomes Zone C, etc. This is because the zones are 16 dB apart. An 8-inch thick reinforced concrete wall offers about 12 dB of attenuation or about 3/4 of a zone. Cinder block and brick walls offer about 4 dB of attenuation or about 1/4 of a zone.

4.4.3.2.2. For conducted compromising emanations, look for things that prevent access to conductors (like the building is totally within the inspectable space so heating and air conditioning ducts and water pipes are not accessible) or would reduce the magnitude of any compromising emanations on a conductor.

4.4.3.3. Identify the inspectable space boundary and indicate it on the map. Base the decision on how willing an adversary is to risk an asset and U.S. Government access to areas considered as inspectable space.

4.4.4. Multiple use of the inspectable space map. Once the inspectable space is determined and the map made, it can be used for all other countermeasures reviews of systems within that inspectable space.

4.4.5. When Changes Occur. Reaccomplish all information systems countermeasures reviews when the inspectable space shrinks or expands.

4.5. Identify Equipment TEMPEST Characteristics. Paragraphs 4.5.1 through 4.5.4 list the preferred sequence and methods for identifying the equipment TEMPEST characteristics. Ask your MAJCOM IA office for assistance if you do not have the information you need.

4.5.1. Equipment TEMPEST Zone Rating. Use the TEMPEST zone assignment for information processing equipment to find the equipment TEMPEST zone ratings.

4.5.2. TEMPEST-Level Rating. Use the level assignment (I, II, or III) for the system based on EMSEC test results. The Equipment Radiation TEMPEST Zone (ERTZ) may be used if known.

4.5.3. Generic Zone Assignment. HQ AFCA/EVPI AF-CTTA developed the generic zone assignment and is an average of like equipment. Use Attachment 5 for the zone assignment for the kind of equipment used.

4.5.4. Other Guidance. If the equipment under review is not identified in any of the above sources, use the category “All Other RED Equipment.”

4.6. Selecting Countermeasures.

4.6.1. Radiated Compromising Emanations. Using the equipment TEMPEST characteristics, identify the amount of inspectable space required to contain radiated compromising emanations within the inspectable space.

4.6.2. Conducted Compromising Emanations. Use Table 4.1 to identify which attachment (Attachment 6, 7, 8, 9, 10, 11, 12, 13, or 14) has the basic selection of countermeasures to contain conducted compromising emanations within the inspectable space. To do this, find the column across the top of Table 4.1 that includes the facility zone rating or the minimum amount of inspectable space identified in paragraph 4.4. Then find the row along the left side of Table 4.1 that includes the worst case equipment TEMPEST characteristics identified in paragraph 4.5. Follow the column down and the row in until they intersect. Follow the directions in the applicable attachment to select required countermeasures.

Table 4.1. Countermeasures Requirements.

FACILITY ZONE

OR

INSPECTABLE SPACE (IS)

Facility Zone A

OR

IS less than 20 meters

Facility Zone B

OR

IS more than 20 meters, less than 100 meters

Facility Zone C

OR

IS more than 100 meters

Equipment

Zone A, or ERTZ = 1 meter, or Meets National Security Telecommunications and Information Systems Security Advisory Memorandum

(NSTISSAM)/TEMPEST 1-92,

(C) Compromising Emanations Laboratory Test Requirements, Electromagnetics (U), Level I

Go to Attachment 6

Go to Attachment 7

Go to Attachment 8

Zone B, or ERTZ = 1 meter to 20 meters, or Meets NSTISSAM/TEMPEST 1-92, Level II

Go to Attachment 9 (See Note)

Go to Attachment 10

Go to Attachment 11

Zone C, or ERTZ = 20 meters to 100 meters, or Meets NSTISSAM/TEMPEST 1-92, Level III, or All Other RED Equipment

Go to Attachment 12 (See Note)

Go to Attachment 13 (See Note)

Go to Attachment 14

Note: This installation may create serious TEMPEST hazards. Contact your CTTA to evaluate the actual TEMPEST zone test results for the equipment and the facility to determine if you can use the equipment in the facility.

Facility Zone C is the best shielded or has the most Inspectable Space

Equipment Zone A meets 1-92, Level I; “TEMPEST certified” equipment

4.6.2.1. Select those countermeasures identified as required unless there is a reason not

to. Look for a reason not to select a countermeasure. Keep in mind the factors identified in paragraph 4.2. Balance those factors against such things as: the cost to the adversary, the adversary’s access to the system, the risk of discovery, the objectives of the adversary, and the impact on the user’s mission. Do not select it if it is not needed.

Explain why each deselected required countermeasure was not selected. A waiver is not needed for any deselected required countermeasure since the requirement for protection has been met.

4.6.2.2. Consider other listed countermeasures within the attachment using the environment and the TEMPEST characteristics of the equipment. Do not select one unless there is a reason to apply it. Base the selection of any additional countermeasures on the situation (sensitivity, perishability, threat level, inspectable space, equipment TEMPEST profile, construction, and layout). You must explain why each selected nonrequired countermeasure was selected (i.e., identify a threat).

4.6.2.3. To aid the EMSEC person making a countermeasures review, a brief discussion of each countermeasure is contained in Chapter 10. The discussion identifies the basic compromising emanation problem the countermeasure is designed to control and contains an explanation of how the countermeasure works. When there are options, optional ways to treat the hazard are identified.

4.7. Estimating Cost. Estimate the cost of each selected countermeasure and enter that cost after the countermeasure on the AF Form 4170.

4.8. Analyzing the Results. Analyze the results and determine if they are acceptable (i.e., reasonable, practical, and cost effective). If the results are not acceptable, request assistance from your MAJCOM IA office. If the results are acceptable, continue.

4.9. Documenting the Results. Document the results by identifying the required inspectable space and countermeasures on AF Form 4170, Part II, following the instructions in Attachment 4 for information systems. Remember that the form establishes EMSEC requirements. It must clearly state to the user what is required. It is not an inspection report.

4.10. Completing the Information Systems Countermeasures Review. If the communications systems or cryptographic equipment assessment indicated the need for either a communications systems or cryptographic equipment countermeasures review, make the review before completing the countermeasures review according to Chapter 7.

Chapter 5

THE COMMUNICATIONS SYSTEMS COUNTERMEASURES REVIEW

5.1. Introduction. When the need for communications systems countermeasures is indicated by the communications systems assessment, the communications systems countermeasures review determines the required countermeasures. Selection is a function of many variables. Chief among these are the:

5.1.1. Separation distance between RED equipment and radio equipment.

5.1.2. Radiation characteristics of the systems processing classified information.

5.1.3. Radio frequency attenuation offered by the facility containing the systems processing classified information.

5.2. Installation Requirement. Install equipment that processes classified information according to the instructions in this chapter. The communications systems installation requirements are separate from other EMSEC requirements. Meet them even when there are no other EMSEC requirements.

5.3. Transmitting Equipment. Use the guidance in this paragraph except when the equipment is addressed in paragraph 5.4.

5.3.1. Equipment Separation Requirements. This countermeasure is required. Separation guidance for fixed transmitters and transceivers (transmitters and receivers contained in one unit) is based on the TEMPEST characteristics of the RED equipment. Separate RED equipment from transmitters according to Table 5.1.

5.3.2. Power Requirements. This countermeasure is required. Do not power RED equipment from the same electrical circuit as radio frequency transmitters and any ancillary equipment, such as control heads, connected to radio frequency transmitters. Install a separate power circuit for either the RED equipment or the radio frequency transmitter and any ancillary equipment. The separate power circuit is established at the circuit-breaker panel. It is permissible to power both from the same electrical circuit if either the RED equipment or the radio frequency transmitter and any ancillary equipment are equipped with power line filters.

Table 5.1. Separation Requirements for Transmitters.

EQUIPMENT RADIATION TEMPEST ZONE SEPARATION DISTANCE

Zone A, or less than 3 meters 2 meters

Zone B, or 3 meters to 20 meters 3 meters

Zone C, or 20 meters to 100 meters 5 meters

Zone D, or over 100 meters 10 meters

5.3.3. Signal and Control Lines Separation Requirements. This countermeasure is required.

These are BLACK lines. If they are wire lines:

5.3.3.1. Separate transmitter signal and control wire lines from RED equipment by the distance specified in Table 5.2 or shield them. The separation requirement for shielded signal and control wire lines from RED equipment is reduced to 15 centimeters.

5.3.3.2. Separate transmitter signal and control wire lines from RED wire lines, RED power lines, and RED signal ground wire lines by 0.5 meter or shield them. The separation requirement for shielded signal and control wire lines from RED wire lines, RED power lines, and RED signal ground wire lines is reduced to 5 centimeters.

5.3.3.3. There are no separation requirements for fiber optic signal and control lines.

5.3.3.4. If the separation distances for signal and control wire lines cannot be achieved, shield the wire lines, filter the wire lines, use opto-isolators, or use fiber optic lines instead of wire lines.

Table 5.2. Separation Requirements for Signal and Control Wire Lines.

EQUIPMENT RADIATION TEMPEST ZONE SEPARATION DISTANCE

Zone A, or less than 3 meters 0.5 meter

Zone B, or 3 meters to 20 meters 1 meter

Zone C, or 20 meters to 100 meters 2 meters

Zone D, or over 100 meters 3 meters

5.3.4. Remote Control Head Separation Requirements. This countermeasure is required.

Determine if the control head is passive or active. Passive control heads have no electronic circuits with active devices in them (e.g., computer chips, junctions, registers, etc.);

mechanical switches or mechanical relays do all the switching. Active control heads have electronic circuits activated by front-panel buttons or switches or use a computer to control operator selections.

5.3.4.1. Separate active control heads by the distance specified in Table 5.2.

5.3.4.2. Separate passive control heads from RED equipment, RED wire lines, RED power lines, and RED signal ground lines by the same distance as determined in paragraph 5.3.3.2.

5.3.4.3. If the separation distance cannot be achieved, use opto-isolators on the signal and control wire lines to the transmitter or use fiber optic signal and control lines instead of wire lines.

5.3.5. Shielding Alternative. An alternative to the separation requirement in paragraph 5.3.1 is shielding either the RED equipment or the transmitter. If the transmitter is shielded, a part of the shielding must include the antenna lead. Circumferentially bond the antenna lead shield to the shielded enclosure. Extend the shield to a distance 20 times the diameter of the shield. You must use filters to penetrate the shielding for power, signal, and control lines. If signal or control lines are fiber optic, a waveguide beyond cutoff penetration may be used.

Keep the diameter as small as possible not exceeding one-half inch. Make the length of the waveguide 10 times the diameter.

5.4. Special Items. Use the guidance in this paragraph for the items addressed in this paragraph instead of the guidance in paragraph 5.3. People may innocently introduce other radio devices, such as pagers, hand-held portable transceiver radios, cellular telephones, cordless telephones, and cordless microphones into the area processing classified information with disastrous results.

Also, alarm systems may use radio transmitters to alert remotely located security or fire-fighting teams. Personal AM/FM receive-only radios do not pose an EMSEC hazard.

5.4.1. Wireless. No Bluetooth devices, cordless phones or microphones, wireless keyboards or mice, wireless LANs, or Infrared LANs are allowed in areas where classified information is discussed, briefed, or processed. “Area” refers to a room and/or space the size of a 3-meter radius sphere, centering on the classified source. In areas where classified information is discussed, briefed, or processed, wireless pointer/mice devices are allowed for presentations only. This is an acceptable EMSEC risk.

5.4.2. Hand-Held Radios. These countermeasures are required. Hand-held radio transceivers used with intrabase radios and land mobile radios (LMR) deserve special consideration because of their unique operational applications. A person may carry these portable radios in the standby mode, into an area where classified information is processed.

Move away from classified processors prior to transmitting, 2 meters minimum.

5.4.3. Beepers and Pagers. These countermeasures are required. Beepers and pagers deserve special consideration because of their unique operational applications. A person may carry these devices into an area where classified information is processed. If the person carrying such a device works in the facility, keep the device 2 meters from classified processors. Beepers/pagers are wireless devices that present a low EMSEC risk since they transmit with very short bursts of data.

5.4.4. Alarm Systems. These countermeasures are required. The mode of operation of alarm systems radio frequency transmitters determines their treatment. Any such transmitter with a continuous transmit mode or a high duty cycle (transmits most of the time) must meet the same separation requirements as all other fixed transmitters; follow the applicable guidance in paragraph 5.3. If they do not meet these requirements, exclude them from operating in the classified information processing area. Low duty cycle (transmits short bursts infrequently) systems are not considered hazards and require no special treatment.

5.4.5. Cellular Telephones. These countermeasures are required. In classified areas, when a cellular telephone is used as an operational necessity, separate it 3 meters from RED equipment. When the cellular telephone is a personal asset, disable the unit from receiving calls. This especially applies to cellular telephone use in facilities outside the U.S. Local requirements may be more restrictive.

5.4.5.1. Cell phone users that are moving/traveling and breach the 3-meter area boundary present a low EMSEC risk as long as they clear the area expeditiously.

5.4.5.2. Cell phones with integral digital camera capability are prohibited in classified processing areas. Local requirements may be more restrictive.

5.4.6. Cordless Telephones. These countermeasures are required. When a radio frequency cordless telephone is used as an operational necessity, separate it 3 meters from RED equipment. When the cordless telephone is a personal asset, its use is prohibited. Disable the personal cordless telephone from receiving calls or separate it 3 meters from RED processors. There are no separation requirements for infrared cordless telephones. This applies to cordless telephone use in facilities outside the U.S.

5.4.7. Cordless Microphones.

5.4.7.1. Radio Frequency Cordless Microphones. These countermeasures are required.

When a radio frequency cordless microphone, encrypted or unencrypted, is used for briefing either classified information or unclassified information, separate it 3 meters from RED equipment. Using unencrypted radio frequency cordless microphones for classified briefings is prohibited.

5.4.7.2. Infrared Cordless Microphones. These countermeasures are required. Using an infrared cordless microphone for briefing classified information requires blocking the line of sight to a possible place where an adversary could detect the infrared emanations.

Do not forget that smooth or shiny surfaces cause infrared signals to be reflected. The best solution is to use a closed room, keeping the doors closed and covering the windows with drapes.

5.4.8. Cordless Accessories. These countermeasures are required. When using a radio frequency cordless accessory such as a keyboard or a mouse, separate it 3 meters from RED equipment. Radio frequency cordless accessories cannot be used to process classified information unless encrypted.

5.4.9. Wireless Local Area Networks (LAN). These countermeasures are required. When using a radio frequency wireless LAN, separate the transmitter and receiver units, normally known as access points and mobile units, 3 meters from RED equipment.

5.4.10. Infrared Local Area Networks (LAN). These countermeasures are required. An infrared LAN processing classified information requires blocking the line of sight to a possible place where an adversary could detect the infrared emanations. Do not forget that smooth or shiny surfaces cause infrared signals to be reflected. The best solution is to use a closed room, keeping the doors closed and covering the windows with drapes.

5.4.11. Infrared Devices. These countermeasures are required. Infrared devices not covered by any subparagraph of paragraph 5.4 require blocking the line of sight to a possible place where an adversary could detect the infrared emanations. Do not forget that smooth or shiny surfaces cause infrared signals to be reflected. The best solution is to use a closed room, keeping the doors closed and covering the windows with drapes.

5.4.12. All other Portable/Personal Electronic Devices (PED). All other wireless PEDs not specifically addressed above, that are…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .