Attachment_0003_Secret_Internet_Protocol_Routing_Network_Memo.pdf

PDF 283 KB Posted

Attached to
Construction- Richmond, VA Federal contract opportunity
Solicitation number
W15QKN19Q1141
Issued by
Department of the Army Materiel Command Contracting Command Picatinny Arsenal

About this file

Attachment 0003 SIPRNet

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF THE ARMY

UNITED STATES ARMY RESERVE COMMAND

BUILDING 8-1808, 4710 KNOX STREET

FORT BRAGG, NC 28310

REPLY TO

ATTENTION OF

REPLY TO

ATTENTION OF

AFRC-INS 21 July 2017

MEMORANDUM FOR RECORD

SUBJECT: Secret Internet Protocol Routing Network (SIPRNET) Secret Controlled Access Area (S-CAA) and Secure Conference Room Certification Policy and Procedures.

1. References.

a. AR 380-5 Department of the Army Information Security Program, 29 September 2000.

b. AR 380-27, Control of Compromising Emanations, 19 May 2010.

c. AR 380-40, Safeguarding and Controlling Communications Security Material, 9 July 2012.

d. United States Army Information System Engineering Command (USAISEC) SIPRNet Technical Implementation Criteria (STIC) version 7.

e. National Security Instruction (NSTISSI) No. 7003, Protective Distribution Systems (PDS), September 2015.

f. CNSSAM TEMPEST/1-13, RED/BLACK Installation Guidance, 17 January 2014

2. Scope. This memorandum establishes security controls and certification procedures required to connect classified information systems up to the SECRET level in United States Army Reserve Command (USARC) managed S-CAA and extend Secure Video Teleconference (S-VTC) connectivity to USAR managed Secure Conference Rooms.

This document does not apply to COMSEC controls and certification procedures.

3. Responsibilities.

a. The Security Specialist / Managers for the Operational, Functional, Training, and Support (OFTS) Commands responsible for the facility within which a USARC-managed S-CAA or secure conference room is located will certify the room(s) for use. Security Specialists shall conduct an initial site survey as directed by USARC G-2.

b. USARC G2 will provide Security Specialists / Managers guidance regarding Information Security and Access controls. USARC G-2 will be the final certification co-

MEMORANDUM FOR RECORD 21 July 2017

SUBJECT: Secret Internet Protocol Routing Network (SIPRNET) Secret Controlled Access

Area (S-CAA) and Secure Conference Room Certification Policy and Procedures.

approving authority for all physical security control requirements for S-CAA and secure conference rooms. USARC G2 will maintain all inspections and certification records.

c. USARC G34 will provide Security Specialists / Managers guidance regarding Physical Security controls. USARC G34 will be the final certification co-approving authority for all physical security control requirements for S-CAA and secure conference rooms.

d. USARC G6 will provide USARC G2 and G34 guidance regarding Cybersecurity controls.

4. Procedure.

a. Security Specialists / Managers will use this memorandum and cited reference material to conduct surveys, inspections and certification of S-CAAs and Secure Conference Rooms located in Army Reserve facilities.

b. After verifying an S-CAA and, if applicable, a Secure Conference Room located in an Army Reserve facility conforms to the security controls established by this memorandum, the Security Specialist / Manager will complete and digitally sign a S- CAA request Memorandum requesting the room(s) for certification (see Enclosure). This request must be digitally sign by the Facility Manager and Commander.

5. Protection of National Security Information (NSI). Protecting unencrypted NSI is based on threat and risk analysis, requiring evaluation of each facility, considering all factors such as threat, location, physical security, environment, access controls, personnel security, etc. The emphasis is on “detection” not “prevention”. Evaluating the risks and vulnerabilities, when measured against the threat, can result in reduced requirements and cost savings while still affording adequate unencrypted NSI protection, demonstrated in reference 1.e., Table B-1. For example, in a LOW Threat environment, if an organization has a certified S-CAA, a hardened carrier Protective Distribution System (PDS) installation within the CAA is not required for classified networks up to SECRET level. Not only does this eliminate PDS installation cost within the CAA, but eliminates the costs associated with daily PDS inspection requirements.

Several solutions are available for protecting unencrypted NSI. The Army Reserve uses a multi-layered protection methodology consisting of using NSA-certified encryption devices within CAA located in facilities meeting the definition of a Limited Controlled Area (LCA) and Uncontrolled Access Area (UAA).

a. References 1.d. and e. identify the basic characteristics of an LCA and UAA. This policy establishes access controls for facilities considered LCA by the Army Reserve.

(1) An LCA is a building controlled by the government or military. The controlling authority may be a civil government, federal government, or military agency.

(2) Access to the LCA is controlled by key, combination, cipher lock, badge access, guard, or similar method.

(3) Access to the LCA is generally restricted to personnel with a legitimate reason to conduct business within the facility.

(4) Visitors, once granted access, may roam unescorted within the LCA.

(5) A UAA is an area over which no personnel access controls are exercised.

This area is open to the public and have no physical access controls implemented to restrict personnel with an illegitimate reason to gain access to the area.

(6) A UAA requires hardened carrier PDS at any threat level for transmission of unencrypted classified information.

b. Per Reference 1.d and e, USARC Reserve Centers will use two types of PDS;

Hardened Carrier and Simple Carrier. Random and daily inspections are required on all PDS. SIPRNet lines located within a S-CAA only require a Simple Carrier System (SCS), not a PDS. An SCS has the same physical characteristic of a Simple Carrier PDS, but is not considered a PDS. An SCS only has an initial inspection requirement.

Subsequent SCS inspections are only required in association with maintenance activities.

c. Reference 1.a defines construction standards for a S-CAA beyond a requirement for direct physical control within which unauthorized persons are denied unrestricted access and are escorted by authorized persons or are under continuous physical or electronic surveillance. This policy memorandum establishes S-CAA construction requirements within Army Reserve Centers.

(1) Top Secret and Confidential CAA is not applicable and falls outside the scope of this policy.

(2) The S-CAA will be located within an LCA.

d. References 1.d. and e. identify a hardened carrier and simple carrier PDS installation criteria required for the transmission of unencrypted data up to SECRET level.

(1) A hardened carrier PDS traverses through an LCA or through the UAA.

(a) The hardened carrier PDS has periodic inspection requirements to ensure the hardened PDS has not been subject to tampering.

(2) SIPRnet local area network (LAN) cabling located within a Secret CAA only require a simple carrier PDS. A simple carrier PDS has the same material characteristics of a simple PDS for unencrypted SIPRnet cabling in a Confidential CAA.

Per reference 1.e., minimum separation criteria still applies for SIPRnet and NIPRnet simple carrier PDSs that run parallel in close proximity within the CAA. A simple carrier PDS only has an initial inspection requirement upon completion of installation.

Subsequent SCS inspections are only required in association with maintenance activities. Simple carrier PDS within a CAA will be inspected prior to the designation of an area as a CAA. Additional inspections may occur after the system or facility maintenance, depending on the nature of maintenance and network configuration.

6. S-CAA Certification Criteria. United States Army Reserve (USAR) S-CAAs must conform to one of two S-CAA design types established by USARC. The two types are:

a. S-CAA without Intrusion Detection System (IDS). This design type consists of a S- CAA that meets the physical security criteria established in Reference 1.a. An IDS alarm is not required for this design type. Information classified up to the SECRET level may be processed in an S-CAA without IDS with the following controls applied:

(1) The encryption device, network gear (e.g. KG-175D, router, and switch), and Mission Command and Intelligence Systems will be secured within a GSA approved Information Processing Station (IPS) container at all times.

(2) Client devices and classified media such as SIPRNet Laptop Computers and SIPRNet Computer Hard Drives will be secured in a GSA approved security container when not in use. SIPRNet client devices may be stored in the IPS Container if connected to the SIPRNet LAN for the purpose of receiving patches and updates.

(3) Local Area Network (LAN) cabling will be distributed to workstations within the S-CAA by a Hardened Carrier PDS and lockable User Drop Boxes (UDB) as described in references 1.d and 1.e. The hardened carrier will be made of ferrous metallic conduit or duct as described in USAISEC STIC v7 and NSTISSI 7003. The UDB will be secured with high security combination locks (e.g. Sargent & Greenleaf model 8077AD). The Security Specialist / Manager responsible for the facility within which the Secure Conference Room is located will coordinate certification of the PDS by the 902nd Military Intelligence Battalion per reference 1.b. The Security Specialist / Manager will also establish and monitor a plan to periodically inspect the PDS at least once every 24 hours (at random intervals) without exception. The SIPRNet S-CAA Manager, or other assigned personnel with clearance level equal to or greater than the information transiting the PDS, will conduct the periodic inspections.

(4) For S-CAA that only have a GSA approved IPS container and Simple Carrier PDS and lockable UDB’s are not installed. The LAN cabling will be connected directly to the SIPRNet switch and ran to a SIPRNet laptop computer stored within the IPS container. The SIPRNet laptop computer will be stored on an extending shelf installed in the container. The entire length of LAN cabling must be physically visible to the operator from the SIPRNet switch to the SIPRNet laptop computer when the computer is in use.

When the SIPRNet laptop computer is not in use, it will remain connected to the SIPRNet switch to receive patches and updates. The entirety of the LAN cabling must be secured within the IPS container when the system is not in use.The Security Specialist / Manager or the S/G-6 will establish an access roster of personnel that are authorize access to the GSA approved IPS container for local users. The authorize person must remain with the safe while it is open.

b. S-CAA with Intrusion Detection System (IDS). This design type consists of a S- CAA that meets the physical security criteria for CAA established in Paragraph 5.c.(2) of this policy memorandum. An IDS alarm is required for this design type. Information classified up to the SECRET level may be processed in an S-CAA with IDS with the following controls applied:

(1) The S-CAA will be protected by IDS alarm as described in AR 380-5 para 7- 14.

(2) The encryption device and network gear (e.g. KG-175D, router, and switch) will be secured within a wall or floor-mounted lockable server cabinet at all times.

(3) Client devices and classified media such as SIPRNet Laptop Computers and SIPRNet Computer Hard Drives will be secured in a GSA approved security container when not in use.

(4) LAN cabling will be distributed to workstations within the S-CAA by a Simple Carrier PDS as described in Paragraph 5.b.

(5) Except as authorized in Paragraph 6 of this memorandum, the SIPRNet LAN will not be extended outside the S-CAA by any means.

7. Secure Conference Room Certification Criteria. Secure Conference Rooms must be located in the same building as the S-CAA providing SIPRNet connectivity. Doors, walls, floors, and ceilings of Secure Conference Rooms must be made of permanent construction material. Attenuation of sound from Secure Conference Rooms must conform or exceed ST-35 standards. Doors must be closed, locked or guarded, and windows obscured during S-VTC sessions. Extension of the SIPRNet Local Area Network (LAN) to the Secure Conference Rooms must conform to one of these three methods in accordance with reference 1.a. The three methods are:

a. Extension with Encryption Device: Connection of S-VTC equipment in the Secure Conference Room to the classified LAN in the S-CAA will be made by cross-connect existing unclassified LAN cabling installed in the building. Classified information transmitted across the unclassified LAN cabling will be protected by Type 1 Encryption.

An inline-encryption (INE) device such as a KG-175D will be placed at both termination points of the connection (one in the Secure Conference Room and one in the S-CAA).

The INE device located in the S-CAA will be stored in the IPS container or in the case of an S-CAA with IDS, in a wall or floor-mounted, lockable server cabinet. The INE device located in the Secure Conference Room will be stored in an IPS container. If an IPS container is not available or practicable for use in the Secure Conference Room, the INE device will be disconnected from the S-VTC equipment and stored in a GSA approved security container when not in use.

b. Extension with Continuously Viewed Carrier PDS: Connection of the S-VTC equipment in the Secure Conference Room to the classified LAN in the S-CAA will be made with temporary LAN cabling. As required, the local organization will run LAN cabling from the S-CAA to the Secure Conference and connect the S-VTC equipment to the SIPRNet LAN. Individuals with clearance equal to or exceeding the information transiting the temporary LAN cabling will visually monitor the entire length of the cabling while it is connected to the SIPRNet LAN. When the S-VTC session has concluded and the temporary LAN cabling is no longer required, it will be disconnected, rolled up, and stored in a secure cabinet. While connected to the SIPRNet LAN, the temporary LAN cabling will not be left unattended for any length of time.

c. Extension with Certified Hardened Carrier PDS: Connection of the S-VTC equipment in the Secure Conference Room to the SIPRNet LAN in the S-CAA will be made with LAN cabling protected by a Hardened Carrier PDS. The hardened carrier will be made of ferrous metallic conduit or duct as described in USAISEC STIC v7 and NSTISSI 7003. The Security Manager responsible for the facility within which the Secure Conference Room is located will coordinate certification of the PDS by the 902nd Military Intelligence Battalion per AR 380-27 paragraph 3-2.c. The Security Manager will also establish and monitor a plan to periodically inspect the PDS at least once every 24 hours (at random intervals) without exception. The SIPRNet Terminal Manager, or other assigned personnel with clearance equal to or greater than the information transiting the PDS, will conduct the periodic inspections.

(1) In an S-CAA without IDS, the end of the carrier system in the S-CAA will be connected directly to the IPS Container. The end of the carrier system in the Secure Conference Room will be protected by hardened user drop box (UDB) secured with a GSA approved high security combination lock (e.g. Sargent & Greenleaf model 8077AD). As required, the S-VTC equipment will be connected with LAN cabling to the access port in the UDB. When the S-VTC equipment is not in use, the LAN cabling will be disconnected, rolled up and secured, and the UDB will be locked.

(2) In an S-CAA with IDS, the end of the carrier system in the S-CAA will be connected directly to the wall or floor-mounted, lockable server cabinet. The end of the carrier system in the Secure Conference Room will be protected by hardened user drop box secured with a GSA approved high security combination lock (e.g. Sargent &

Greenleaf model 8077AD). As required, the S-VTC equipment will be connected with LAN cabling to the access port in the UDB. When the S-VTC equipment is not in use, the LAN cabling will be disconnected, rolled up and secured, and the UDB will be locked.

(3) In a C-CAA with Continuously Viewed PDS, the ends of the carrier system in both the S-CAA and Secure Conference Room will be protected by hardened UDB secured with a GSA approved high security combination lock (e.g. Sargent & Greenleaf model 8077AD). As required, the S-VTC equipment will be connected with LAN cabling to the access ports in the UDBs. When the S-VTC equipment is not in use, the LAN cabling connecting the S-VTC system to the access port in the UDB will be disconnected, rolled up and secured, and the UDBs will be locked.

(4) In a C-CAA with Hardened Carrier PDS the end of the carrier system in the S-CAA will be connected directly to the IPS Container. The end of the carrier system in the Secure Conference Room will be protected by hardened UDB secured with a GSA approved high security combination lock (e.g. Sargent & Greenleaf model 8077AD). As required, the S-VTC equipment will be connected with LAN cabling to the access port in the UDB. When the S-VTC equipment is not in use, the LAN cabling will be disconnected, rolled up and secured, and the UDB will be locked.

8. Points of Contact. Action Officer for this policy memorandum is Ms. Denise Sanders, USARC G2 Security Officer, 910-570-8491 or denise.m.sanders.civ@mail.mil and Ms Jessica Taylor, Physical Security, USARC, G-34, 910 570-9109 or jessical.l.taylor177.civ@mail.mil

7/27/2017

X Jason J. Schrank

Signed by: SCHRANK.JASON.JAMES.1100877585 Encl JASON SCHRANK Certification Memo COL, MI USARC S-CAA Inspections Checklist USAR, G-2 mailto:denise.m.sanders.civ@mail.mil mailto:jessical.l.taylor177.civ@mail.mil

File details come from the government source that posted it.