SOW NLZG242008.pdf

PDF 21 MB Posted

Attached to
Bldg 2000 Secure Area Upgrades Federal contract opportunity
Solicitation number
W50S8P25BA001
Issued by
Department of the Army National Guard

About this file

The file is an Adobe PDF portfolio opening screen prompting users to use Acrobat X or Adobe Reader X for optimal viewing. This appears to be a cover page or initial interface for accessing a PDF document related to a federal contract opportunity.

The actual content relates to a Solicitation (W50S8P25BA001) for Bldg 2000 Secure Area Upgrades issued by the 121st Air National Guard. The competitive small business set-aside contract is for modifications and security upgrades to Room 240 in Building 2000 at Rickenbacker ANGB, Ohio. The project is valued between $250,000-$500,000, with a construction duration of 180 calendar days. Key details include a bid opening date of 31-Jul-2025 at 1:00 PM EDT, NAICS code 237310, and mandatory SAM registration for interested contractors. The project requires contractors to limit subcontractor payments to 85% of the government contract amount, excluding material costs.

View the file

Other files for this federal contract opportunity

Other files attached to Bldg 2000 Secure Area Upgrades, newest first.
File Type Posted
Bid Opening Sign In Sheet.pdf PDF
1419 Abstract of Offers W50S8P-25-B-A001.pdf PDF
Pre-Bid Conference Attendance List.pdf PDF
Questions and Answers.pdf PDF
conformed copy - W50S8P25BA0010001.pdf PDF
_Solicitation Amendment W50S8P25BA0010001 SF 30.pdf PDF
Site Visit Minutes.pdf PDF
CUI_2000 Secure Upgrades Plans.pdf PDF
SOW for NLZG242008.pdf PDF
Solicitation - W50S8P25BA001.pdf PDF
SFS Form 3_EAL Request.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For the best experience, open this PDF portfolio in

Acrobat X or Adobe Reader X, or later.

Get Adobe Reader Now!

http://www.adobe.com/go/reader

CUI

Project # NLZG242008 Building 2000 Security Upgrades

STATEMENT OF WORK

Bldg. 2000 Security Upgrades

1.01 SCOPE: Modifications and mitigations required to establish a secure facility in Room 240 in Building

2000, RANGB.

1.02 LOCATION: Rickenbacker ANGB. Building 2000

1.03 COORDINATION: Notify 121st Civil Engineering at 614-492-4121 or contact Mr. Michael Hissom at 614-492-4459 a minimum of two days prior to starting any work. Coordination with the 121st CES is mandatory.

1.04 SECURITY:

A. Construction will take place in a secure area. Contractors are required to be escorted to/from the worksite within the building and always remain under supervision by at least 1 cleared person while in the secure area.

B. No electronic communications equipment will be allowed on the worksite.

1.05 SUBMITTALS:

A. The contractor shall provide a detailed schedule of construction for this project.

B. Contractors shall include with their material submittal what GREEN Procurement (Re-Cycled- Bio Based Content) items which they intend to use on the contract (if applicable).

The following web sites should be reviewed for materials which can be used in the Governments Green Procurement effort.

Information on Recycled content requirements: www.epa.gov/cpg (Check under Products/Construction Material)

Information on Bio based program: www.biobased.oce.usda.gov

D. The following items must be submitted by the Contractor after award at the Pre-Construction Conference:

1. Contractor will provide SDS Sheets for all: concrete, glues, sealants, solvents, additives, cleaners, and fuels to be used. All other substances of a flammable, corrosive and toxic nature shall be submitted as well.

2. The contractor will ensure that each of the SDS items are listed on a Transient Organization Hazardous Material Inventory Sheet and submitted for approval prior to starting work.

3. To be turned in upon completion of work. Contractor will fill out a Solid Waste Disposal Spreadsheet, which tracks construction debris that goes to dump sites or that is recycled. (When applicable). The intent is to capture quantities and costs.

http://www.epa.gov/cpg http://www.biobased.oce.usda.gov/

1.06 WORK TO BE ACCOMPLISHED:

Background: The 121st Air Refueling Wing has operational need for security upgrades to their facility.

Room 240 (including offices in Rooms 241 & 242) has been determined to be suitable for these upgrades and will be modified as shown herein.

A. References:

1. Best Practices for Architectural Radio Frequency Shielding, March 2010.

2. DoD Manual 5105.21, Vol II SCIF Physical Security.

3. IC Technical Specification for Construction and Management of SCIFs, ver. 15

4. IEEE Standard 299, RF Testing.

5. NSA Standard 94-106 RF Shielding.

B. Requirements: The contractor shall perform the specified work IAW ICD 705 Standards.

1. Perimeter Walls. (Reference Sheets A-101 through A-104)

a) The Contractor shall modify the existing CMU perimeter walls to meet ICD 705 Standards and attain a Sound Transmission Class (STC) of 50.

b) All existing gaps in the CMU walls, including all beam pockets and gaps between top/wall and metal roof decking shall be filled and sealed using 5/8” Gypsum Wall Board (GWB), approved patching materials, and acoustical insulation.

c) All other penetrations shall be sealed using approved patching materials. All SCIF penetrations are to be converted to meet new RF Shielding penetrations

d) The partition wall between Rooms 236 and 240 shall be built to STC 50 Standards and of a Type A design as shown in Sheet A-102 and consist of two layers of 5/8-in GWB, with r-Foil, NT Ultra Radiant Foil per Best Practices Guidelines for RF Shielding mounted on 3-5/8-in metal framing (16 ga.) both on the controlled side and unsecure side of the wall [total of four (4) layers]. Installation shall be IAW per Best Practices Guidelines for RF Shielding (see attached)

(1) The Partition wall shall be insulated with approved sound attenuation material. Insulation shall be fastened in wall so that there is no settlement of subsequent gaps.

(2) The Partition wall shall receive a scheduled wall base on both sides.

(3) Partition walls shall be supported top & bottom by 16 ga. Continuous track, anchors at 32-inch on center, maximum. Tracks shall be sealed with approved acoustic sealant in a continuous bead application.

(4) All other voids shall be sealed with approved acoustic sealant as well.

2. Windows. (Reference Drawings A-5 & A-19)

a) The two existing windows in Rooms 241 & 242 shall be removed.

b) Infill shall match existing masonry as shown on A-19, Section 3 and meet the standards of ICD 705.

c) The infill shall be finished to match the surrounding wall, including furring and paint. Existing details provided on Drawing A-5.

3. Performance-based contractors shall provide shop drawings to identify sound masking for utility and duct penetrations to meet ICD 705 Requirements for STC 50. Contractors are required to use a 3rd Party to perform ASTM E90 Testing for STC 50 Standards and provide a report for the entire room.

4. Utilities. (Reference D-101 & E-101)

a) Existing Utility (e.g., power, signal, & telephone) distribution that penetrates sound – engineered structures will require sound dampening or shall be eliminated and sealed appropriate to the wall type IAW ICD 705 if dampening cannot be done. (See E-101 General Electrical Note 3)

b) New utilities shall be surface mounted on both the controlled side of the Room and on the unsecured wall of Room 236.and all penetrations into the controlled side shall be properly sealed to STC 50 standards and include dielectric breaks at the point of penetration.

5. HVAC Duct. (Reference Drawings M-101 & M102). Existing duct more than 96 square inches of cross-sectional area will require affixed man-bars/grills and inspection ports.

a) Bars shall be a minimum of ½-inch in diameter, constructed of tool-resistant steel, and be set at 6-inches o/c (both directions), mounted on a steel frame. Bar and frame assembly shall be painted with a rust inhibitive primer.

b) Inspection ports shall be located with direct line of sight on the security man-bars/ grills and shall be located on the secure side of the space and at the bottom of the duct.

c) Ductwork will require sound masking devices as required.

6. New Security Door. The Contractor shall install an STC Level 50 Security Door, Type F, 3’-0 by 7’-0 . Door must meet criteria listed in IC Tech Spec – For ICD/ICS 705, Ver. 1.5, Pg.

13, Ch. 3, para. E: SCIF Door Criteria (attached).(See Sheet A-104 for additional door details)

a) The door shall also meet the following standards:

(1) 1 ¾-in.-thick face steel equal to a minimum 18-gauge steel.

(2) Hinges, 3 each 4 ½ x 4 ½ - inch reinforced to 7 ga. Steel with non-removable pins.

(3) Door closure: 12 ga. Steel

(4) Lock Area pre-drilled and reinforced with 10 ga. Steel.

(5) Door sweeps and an astragal strip shall be installed for proper sound attenuation of STC 50.

b) The door shall accommodate the following hardware:

(1) Automatic Door Closer

(2) Emergency Egress Only Door release button on the controlled side.

(3) Balanced Magnetic Switch

(4) Intrusion Detection System

(5) FF-L-2470A approved combination lock.

7. RF Shielding Attenuation Testing. The contractor shall coordinate and perform Radio Frequency (RF) shielding attenuation testing in accordance with NSA 94-106 on all 6 sides of the secure area perimeter (4x walls, foundation, and roof). Provide test results to the government (Base Engineering) within 10 working days prior to completion of shielding installation. Must be able to attenuate 40db at 100mhz.

8. Finishes. (Reference Drawings A-104, A-5 & A-19) All paint, and trim shall match existing finishes. Contractor shall provide submittals to the government for approval prior to installation.

See Drawings for specific locations of all finishes. Conduct a walk-through of the building with Base Engineering prior to start of interior finishes.

1.07 BID SCHEDULE: Bids shall be submitted with the price in two one contract line number (CLIN).

CLIN 0001: Building 2000 Security Upgrades.

1.08 SAFETY: All precautions necessary to ensure the safety of personnel and the protection of existing equipment and structures will be strictly enforced. All additional electrical safety precautions shall be followed. All OSHA standards shall be met.

1.09 CONSTRUCTION DIRT AND DEBRIS: The contractor shall remove any dirt, debris, construction waste that collects during construction on the traveled roadways or existing pedestrian facilities on the base as directed by the Base Civil Engineer.

1.10 CONSTRUCTION STAGING OF EQUIPMENT: The contractor shall coordinate with the Base Civil Engineer appropriate locations for overnight storage/staging construction equipment.

1.11 HAZARDOUS MATERIALS REQUIREMENTS:

HAZMAT shall not be stored on base unless with written permission from contracting officer and HMP.

When Hazardous Material (HM) is to be stored for use on Rickenbacker ANGB, the contractor shall establish a hazardous material storage and distribution system that complies with all Federal, State, and Local environmental regulations.

The contractor shall register through the Contracting Officer with the base Hazardous Material Pharmacy (HMP) prior to start work.

The contractor shall submit to the Contracting Officer for approval the following for all HM, as defined by Federal Standard 313 Table I and Table II, to be used in the accomplishment of the work / service to be provided to the government: See paragraph 1.04 Submittals.

1.12 SITE CONDITIONS: Submission of a proposal by a contractor shall be considered evidence that the contractor has examined the statement of work and is satisfied as to the nature and location of the work and all matters, which can in any way affect the work or the cost of the work under the proposal. Any failure of the contractor to become acquainted with all available information, including a physical survey of the site for the proposed work, will not relieve the contractor from successfully fulfilling all the work that is required for a complete and acceptable job.

A. References:

1. Best Practices for Architectural Radio Frequency Shielding, March 2010.

2. DoD Manual 5105.21, Vol II SCIF Physical Security.

3. IC Technical Specification for Construction and Management of SCIFs, ver. 15

4. IEEE Standard 299, RF Testing.

5. NSA Standard 94-106 RF Shielding.

B. Requirements: The contractor shall perform the specified work IAW ICD 705 Standards.

1. Perimeter Walls. (Reference Sheets A-101 through A-104)

a) The Contractor shall modify the existing CMU perimeter walls to meet ICD 705 Standards and attain a Sound Transmission Class (STC) of 50.

b) All existing gaps in the CMU walls, including all beam pockets and gaps between top/wall and metal roof decking shall be filled and sealed using 5/8” Gypsum Wall Board (GWB), approved patching materials, and acoustical insulation.

c) All other penetrations shall be sealed using approved patching materials. All SCIF penetrations are to be converted to meet new RF Shielding penetrations

d) The partition wall between Rooms 236 and 240 shall be built to STC 50 Standards and of a Type A design as shown in Sheet A-102 and consist of two layers of 5/8-in GWB, with r-Foil, NT Ultra Radiant Foil per Best Practices Guidelines for RF Shieldi...

(1) The Partition wall shall be insulated with approved sound attenuation material. Insulation shall be fastened in wall so that there is no settlement of subsequent gaps.

(2) The Partition wall shall receive a scheduled wall base on both sides.

(3) Partition walls shall be supported top & bottom by 16 ga. Continuous track, anchors at 32-inch on center, maximum. Tracks shall be sealed with approved acoustic sealant in a continuous bead application.

(4) All other voids shall be sealed with approved acoustic sealant as well.

2. Windows. (Reference Drawings A-5 & A-19)

a) The two existing windows in Rooms 241 & 242 shall be removed.

b) Infill shall match existing masonry as shown on A-19, Section 3 and meet the standards of ICD 705.

c) The infill shall be finished to match the surrounding wall, including furring and paint. Existing details provided on Drawing A-5.

3. Performance-based contractors shall provide shop drawings to identify sound masking for utility and duct penetrations to meet ICD 705 Requirements for STC 50. Contractors are required to use a 3rd Party to perform ASTM E90 Testing for STC 50 Stan...

4. Utilities. (Reference D-101 & E-101)

a) Existing Utility (e.g., power, signal, & telephone) distribution that penetrates sound – engineered structures will require sound dampening or shall be eliminated and sealed appropriate to the wall type IAW ICD 705 if dampening cannot be done. (See...

b) New utilities shall be surface mounted on both the controlled side of the Room and on the unsecured wall of Room 236.and all penetrations into the controlled side shall be properly sealed to STC 50 standards and include dielectric breaks at the poi...

5. HVAC Duct. (Reference Drawings M-101 & M102). Existing duct more than 96 square inches of cross-sectional area will require affixed man-bars/grills and inspection ports.

a) Bars shall be a minimum of ½-inch in diameter, constructed of tool-resistant steel, and be set at 6-inches o/c (both directions), mounted on a steel frame. Bar and frame assembly shall be painted with a rust inhibitive primer.

b) Inspection ports shall be located with direct line of sight on the security man-bars/grills and shall be located on the secure side of the space and at the bottom of the duct.

c) Ductwork will require sound masking devices as required. (See Note 3)

6. New Security Door. The Contractor shall install an STC Level 50 Security Door, Type F, 3’-0 by 7’-0 . Door must meet criteria listed in IC Tech Spec – For ICD/ICS 705, Ver. 1.5, Pg. 13, Ch. 3, para. E: SCIF Door Criteria (attached).(See Sheet A-104...

a) The door shall also meet the following standards:

(1) 1 ¾-in.-thick face steel equal to a minimum 18-gauge steel.

(2) Hinges, 3 each 4 ½ x 4 ½ - inch reinforced to 7 ga. Steel with non- removable pins.

(3) Door closure: 12 ga. Steel

(4) Lock Area pre-drilled and reinforced with 10 ga. Steel.

(5) Door sweeps and an astragal strip shall be installed for proper sound attenuation of STC 50.

b) The door shall accommodate the following hardware:

(1) Automatic Door Closer

(2) Emergency Egress Only Door release button on the controlled side.

(3) Balanced Magnetic Switch

(4) Intrusion Detection System

(5) FF-L-2470A approved combination lock.

7. RF Shielding Attenuation Testing. The contractor shall coordinate and perform Radio Frequency (RF) shielding attenuation testing in accordance with NSA 94-106 on all 6 sides of the secure area perimeter (4x walls, foundation, and roof). Provide tes...

8. Finishes. (Reference Drawings A-104, A-5 & A-19) All paint, and trim shall match existing finishes. Contractor shall provide submittals to the government for approval prior to installation. See Drawings for specific locations of all finishes. Cond...

Department of Defense

MANUAL

NUMBER 5105.21, Volume 2 October 19, 2012

Incorporating Change 2, Effective November 2, 2020

USD(I&S)

SUBJECT: Sensitive Compartmented Information (SCI) Administrative Security Manual:

Administration of Physical Security, Visitor Control, and Technical Security

References: See Enclosure 1

1. PURPOSE

a. Manual. This Manual is composed of several volumes, each serving a specific purpose, and reissues DoD Manual (DoDM) 5105.21-M-1 (Reference (a)). The purpose of the overall Manual, in accordance with the authority in DoD Directive (DoDD) 5143.01 (Reference (b)), is to implement policy established in DoD Instruction (DoDI) 5200.01 (Reference(c)), and Director of Central Intelligence (DCI) Directive (DCID) 6/1 (Reference (d)) for the execution and administration of DoD Sensitive Compartmented Information (SCI) program. It assigns responsibilities and prescribes procedures for the implementation of DCI and Director of National Intelligence (DNI) policies for SCI.

b. Volume. This Volume addresses the administration of physical security, visitor control, and technical security for SCI facilities (SCIFs).

2. APPLICABILITY. This Volume:

a. Applies to OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense, the Defense Agencies, except as noted in paragraph 2.c., the DoD Field Activities, and all other organizational entities within the DoD (hereinafter referred to collectively as the “DoD Components”).

b. Applies to contractors in SCIFs accredited by the Defense Intelligence Agency (DIA) and to DoD SCI contract efforts conducted within facilities accredited by other agencies and approved for joint usage by a co-utilization agreement.

DoDM 5105.21-V2, October 19, 2012

Change 2, 11/02/2020 2

c. Does not apply to the National Security Agency/Central Security Service (NSA/CSS), National Geospatial-Intelligence Agency (NGA), and the National Reconnaissance Office (NRO), to which separate statutory and other Executive Branch authorities for control of SCI apply.

3. DEFINITIONS. See Glossary.

4. RESPONSIBILITIES. See Enclosure 2 of Volume 1 of this Manual.

5. PROCEDURES. General procedures for SCI administrative security are found in Enclosure 2, Volume 1 of this Manual. Procedures for physical security, visitor control, and technical security for SCI facilities are detailed in Enclosures 2, 3, and 4 respectively of this Volume.

6. RELEASABILITY. Cleared for public release. This volume is available on the Directives Division Website at https://www.esd.whs.mil/DD/.

7. SUMMARY OF CHANGE 2. This administrative change:

a. Updates the title of the Under Secretary of Defense for Intelligence to the Under Secretary of Defense for Intelligence and Security in accordance with Public Law 116-92 (Reference (e)).

b. Updates references.

8. EFFECTIVE DATE. This Volume is effective October 19, 2012.

Michael G. Vickers Under Secretary of Defense for Intelligence

Enclosures

1. References

2. Physical Security

3. Visitor Control

4. Technical Security Glossary

Change 2, 11/02/2020 CONTENTS 3

TABLE OF CONTENTS

ENCLOSURE 1: REFERENCES

ENCLOSURE 2: PHYSICAL SECURITY

GENERAL

SCIF DESIGN AND PLANNING

SCIF TYPES

CONSTRUCTION SECURITY

SCIF ACCREDITATION

SCIF OPERATIONS

APPENDIXES

1. SCIF CLOSEOUT GUIDELINES

2. SCIF END OF DAY SECURITY CHECK

3. EAPs FOR SCIFs WITHIN THE UNITED STATES

ENCLOSURE 3: VISITOR CONTROL

GENERAL

BADGE RECIPROCITY IN THE METROPOLITAN WASHINGTON, D.C., AREA

(MWA)

CERTIFICATION OF CLEARANCES AND SCI ACCESSES

VISITS BY FOREIGN NATIONALS

FOREIGN LIASION AND INTEGRATED PERSONNEL

CERTIFICATION FOR PART-TIME EMPLOYMENT

NON-INDOCTRINATED PERSONS

CONTRACTORS AND CONSULTANTS

ESCORTS

ACCESS CONTROL

ENCLOSURE 4: TECHNICAL SECURITY

GENERAL

TSCM SURVEYS AND EVALUATIONS

CONTROL OF COMPROMISING EMANATIONS (TEMPEST)

CLASSIFYING TEMPEST RELATED INFORMATION

GLOSSARY

PART I. ABBREVIATIONS AND ACRONYMS

PART II. DEFINITIONS

Change 2, 11/02/2020 CONTENTS 4

FIGURE

Sample EAP Format

Change 2, 11/02/2020 ENCLOSURE 1 5

ENCLOSURE 1

REFERENCES

(a) DoD 5105.21-M-1, “Department of Defense Sensitive Compartmented Information

Administrative Security Manual,” August 1998 (cancelled by Volume 1 of this Manual)

(b) DoD Directive 5143.01, “Under Secretary of Defense for Intelligence and Security (USD(I&S)),” October 24, 2014, as amended

(c) DoD Instruction 5200.01, “DoD Information Security Program and Protection of Sensitive

Compartmented Information (SCI),” April 21, 2016, as amended

(d) Director of Central Intelligence Directive 6/1, “Security Policy for Sensitive

Compartmented Information and Security Policy Manual,” March 1, 19951

(e) Public Law 116-92, “National Defense Authorization Act for Fiscal Year 2020,”

December 20, 2019

(f) Intelligence Community Directive 705, “Sensitive Compartmented Information Facilities,”

May 26, 2010

(g) Intelligence Community Standard 705-1, “Physical and Technical Security Standards for

Sensitive Compartmented Information Facilities,” September 17, 2010

(h) Intelligence Community Standard 705-2, “Standards for the Accreditation and Reciprocal

Use of Sensitive Compartmented Information,” September 17, 2010

(i) DoD Instruction 5200.08, “Security of DoD Installations and Resources and the DoD

Physical Security Review Board (PSRB),” December 10, 2005, as amended

(j) DoD Directive 5205.02E, “DoD Operations Security (OPSEC) Program,” June 20, 2012, as amended

(k) Unified Facilities Criteria 4-010-1, “DoD Minimum Antiterrorism Standards for

Buildings,” 2002

(l) DoD Manual 5200.01, “DoD Information Security Program,” February 24, 2012, as amended

(m) Volume 6 of U.S. Department of State Foreign Affairs Handbook 12, “OSPB Security

Standards and Policy Handbook,” July 20062.

(n) Intelligence Community Directive 503, “Intelligence Community Information Technology

Systems Security Risk Management, Certification and Accreditation,” September 15, 2008

(o) DoD Directive 5205.07, “Special Access Program (SAP) Policy,” July 1, 2010, as amended

(p) DoD Instruction 5205.11, “Management, Administration, and Oversight of DoD Special

Access Programs (SAPs),” February 6, 2013, as amended

(q) Director of Central Intelligence Directive 6/7, “Intelligence Disclosure Policy,” June 30, 1998

(r) DoD Directive 5230.20, “Visits and Assignments of Foreign Nationals,” June 22, 2005

(s) DoD Instruction 5530.03, “International Agreements,” December 4, 2019

(t) Intelligence Community Directive 701, “Security Policy Directive for Unauthorized

Disclosures of Classified Information,” March 14, 2007

(u) Army Regulation 380-27, “Control of Compromising Emanations,” May 19, 2010

1Available via http://www.intelink.ic.gov/sites/cps/policystrategy/policy/pages/dcids.aspx [JWICS] 2 Available via http://source.ds.state.sgov.gov/products/library_FAMsFAHs/FFhome.asp [SIPRNET] http://source.ds.state.sgov.gov/products/library_FAMsFAHs/FFhome.asp

Change 2, 11/02/2020 ENCLOSURE 1 6

(v) Air Force Instruction 71-101, Volume 3 “Air Force Technical Surveillance Countermeasures Program,” June 1, 2000

(w) Secretary of the Navy Instruction 3850.4, “Technical Surveillance Countermeasures,” December 8, 2000

(x) Joint Staff Manual 5220.01A, “Temporary Restricted Area Access Request,” October 1, 1997

(y) Administrative Instruction 30, “Force Protection of the Pentagon Reservation,”

June 26, 2009, as amended

(z) DoD Instruction 5240.05, “Technical Surveillance Countermeasures (TSCM) Program,”

April 3, 2014, as amended

(aa) Intelligence Community Directive 702, “Technical Surveillance Countermeasures,”

February 18, 2008

(ab) National Security Telecommunications Information System Security Advisory Manual 2-95 & 2-95A, “RED/BLACK Installation Guidance” February 3, 2000

(ac) National Security Telecommunications and Information Systems Security Instruction 7003, “Protected Distribution Systems (PDS),” December 3, 1996

(ad) National Security Telecommunications and Information Systems Security Instruction

7002,”TEMPEST Glossary,” March 17, 1995

(ae) National Security Telecommunications and Information Systems Security Instruction 4002, “Classification Guide for COMSEC Information,” June 5, 1986

Change 2, 11/02/2020 ENCLOSURE 2 7

ENCLOSURE 2

PHYSICAL SECURITY

1. GENERAL

a. Physical security standards for the construction and protection of SCIFs are prescribed in Intelligence Community Directive (ICD) 705 (Reference (f)), Intelligence Community Standard (ICS) 705-1 (Reference (g)), and ICS 705-2 (Reference (h)). DoD SCIFs will be established in accordance with those references and this Volume.

(1) Wherever practical, SCIFs will be designated as a restricted area in accordance with DoD Instruction 5200.08 (Reference (i)). The special security officer (SSO) will coordinate to list the SCIF within the post or installation directive that defines and designates all local restricted areas and will post outside the SCIF the proper English and, when appropriate (overseas areas only), foreign language “Restricted Area” signs. If a SCIF is physically located within a restricted area, it does not also need to be designated as a controlled area.

(2) Personnel who work in or have routine or unescorted access to a SCIF must be indoctrinated for the compartments of SCI that is discussed, processed, or stored within the facility.

(a) If a SCIF has multiple SCI control systems that are physically separated by an internal access control device or other similar control system, only SCI-indoctrinated personnel with the appropriate level of access for the facility will escort uncleared personnel. SCIF door combinations and bypass keys, if applicable, must be protected at the same level for which the facility is accredited.

(b) Main entry point combinations and bypass keys, if applicable, will be stored in a different SCIF of the same or higher accreditation.

(c) Access codes to an intrusion detection system and access control device will be limited to personnel who are SCI-indoctrinated and have a need to know. Administrator privileges to intrusion detection systems should be limited to the SSO.

(3) Operations security (OPSEC) principles are critical for protecting the operational activities and security of SCIFs. OPSEC principles should be considered and implemented based on the local security environment.

(a) The facility’s location (complete address) and identity as a SCIF shall be protected at a minimum of FOR OFFICIAL USE ONLY (FOUO). Drawings or diagrams identified as a SCIF may not be posted on an UNCLASSIFIED website or transmitted over the Internet without some type of encryption.

Change 2, 11/02/2020 ENCLOSURE 2 8

(b) SCIFs should be referred to as a controlled space or another terminology so as not to designate it as a SCIF on releasable documents (e.g., bid requests, permit requests, sub-contractor plans).

(c) Refer to DoDD 5205.2 (Reference (j)) for further OPSEC guidance.

(4) All new facilities shall be constructed as directed in References (g) and (h), and in compliance with Unified Facilities Criteria 4-010-1 (Reference (k)). SCIF construction overseas shall also comply with applicable local anti-terrorism and force protection regulations. SCIFs built under Chief of Mission (COM) control will follow Department of State guidelines.

b. Approvals. Reference (f) provides detailed physical security recommendations that should be applied. These recommendations are generally phrased with words such as “should,” “may,” and “can.” In some instances, such as speakerphones, answering machines, and secondary doors, these recommendations are contingent upon accrediting official (AO) (DIA Counterintelligence and Security Office (DAC)) approval. Requests must include adequate details that enable DAC to render an informed decision. DAC may delegate to senior intelligence officials (SIOs) of the Combatant Commands the authority to approve Temporary Secure Working Areas (TSWAs), Temporary SCIFs (T-SCIFs), and concept statements for creation of new SCIFs.

c. Mitigations. Methods identified in the Intelligence Community (IC) Technical Specifications contained in Reference (g) are an accepted way to meet the performance standard, but there may be several ways to achieve the same standard other than what is listed. A different method may be used if it achieves the same performance standard as identified in Reference (f).

This mitigation must be identified in the Fixed Facility Checklist (Attachment A to Reference (g)) and requires approval from the AO before implementation.

d. Waivers

(1) Reference (f) provides detailed physical security requirements. These requirements are generally phrased with definitive words such as “will,” “shall,” and “must.” Requirements of this nature require a waiver whenever they cannot be followed and mitigations cannot be applied (i.e., a waiver down). A waiver is also required when these standards are exceeded (i.e., a waiver up).

(2) All waiver requests will be submitted through the cognizant security authority (CSA), their designee, or the DoD Component SIO to DAC for review. If DAC determines that a waiver is warranted, it will process the waiver request for approval.

(3) Waivers down will be guided by the principles of risk management. The request must be signed by the reviewing official (the CSA, their designee, or the DoD Component SIO) and at a minimum must include the following information:

(a) The physical security requirement(s) that cannot be met.

Change 2, 11/02/2020 ENCLOSURE 2 9

(b) Explanation of why the security requirement cannot be implemented and the mitigations that were considered.

(c) Mission impact if the waiver is disapproved.

(d) Identification of compensatory countermeasures that can be implemented in lieu of the established physical security requirements that can reduce the residual risk.

(e) The time expectation on when the standard can be met and a waiver is no longer required.

(4) Elements requesting waivers up must forward a written request through the CSA, their designee, or the DoD Component SIO to DAC. The request at a minimum must include the following information:

(a) The physical security requirement that will be exceeded.

(b) A statement of documented risk that justifies the need to exceed standards.

(c) Mission impact if the waiver is disapproved.

(d) Identification of the additional security measures being put into place.

(e) The time expectation on when the waiver will no longer be required.

(5) Limitations on Waivers. Waivers are normally granted for a period of up to 1 year or until such time as the waiver is no longer needed. All waivers shall be reported to the Office of the Director of National Intelligence (ODNI) and maintained in the ODNI database. All SCIFs with permanent waivers will be reviewed annually using the current standards to determine if a waiver is still needed or if mitigations can be used instead. Elements requesting co-use of any SCIF with a waiver will be informed of it.

(6) Classification Guidance. Guidance on classification of information related to the accreditation of DoD SCIFs is maintained on the DAC JWICS website (http://www.dia.ic.gov/homepage/da/security/field/index.html). All SCIF documentation classified under DIA classification authority shall be marked and transmitted per DoDM 5200.01 (Reference (l)).

2. SCIF DESIGN AND PLANNING

a. Site Planning

(1) SCIF security begins with the decision to build a SCIF. Adequate planning and design will prevent many of the security risks to SCI and reduce the costs of construction. Site planning should include looking at the standoff distances for AT/FP as well as TEMPEST.

Change 2, 11/02/2020 ENCLOSURE 2 10

(2) The Service CSA or DoD Component SIO or their designees shall conduct one-time construction project reviews before site acquisition (purchase or lease of a building) for the purpose of making transparent, accountable, and prudent risk management decisions involving security requirements and long-term security risks.

b. Concept Approval

(1) The concept approval is the first critical element in the establishment of a SCIF.

Concept approval certifies that a clear operational requirement exists for the SCIF and there is no existing SCIF to support the requirement.

(2) Once a need for SCI has been identified, the organization’s commander will submit a request for SCI to the Service CSAs, their designees, or DoD Component SIOs. This request will identify the levels and types of SCI desired and certify that the organization is able to support the SCIF (i.e., manning and budget) throughout its lifecycle.

(3) Upon receipt of the request to build a SCIF, the Service CSAs, their designees, or

DoD Component SIOs will validate the need for a SCIF and the requirement for the requested level of SCI. The Service CSAs, their designees, or DoD Component SIOs are required to grant concept approval to establish a SCIF, to include contractor SCIFs. They may delegate this approval as deemed necessary. If delegated, the Service CSAs, their designees, or DoD Component SIOs must notify DAC to preclude potential confusion.

(4) The Service CSAs, their designees, or DoD Component SIOs will provide the concept approval and, if applicable, the DD Form 254, “Contract Security Classification Specification,” for contractor facilities to DAC with an information copy to the supporting SSO.

c. Diplomatic Facilities

(1) DoD SCIFs established within diplomatic facilities fall under the security responsibility of the COM and must also obtain permission through Department of State channels to build a SCIF. These SCIFs will comply with all requirements of Reference (f) and meet the Overseas Security Policy Board (OSPB) standards in accordance with Volume 6 of U.S.

Department of State Foreign Affairs Handbook 12 (Reference (m)).

(2) Where OSPB standards and DoD standards conflict, the more stringent will be applied unless resolved by DAC and the Department of State Bureau of Diplomatic Security.

3. SCIF TYPES

a. Temporary SCIFs

(1) TSWA

Change 2, 11/02/2020 ENCLOSURE 2 11

(a) A TSWA must not be used more than 40 hours per month and no longer than 12 months in the same location. The 40-hour rule is based on an average use of the TSWA over a 12-month period. The purpose for this requirement is that a TSWA’s physical security standards are less than that of a permanently accredited SCIF. If the facility will be used on a more frequent basis, the user of a facility must pursue permanent accreditation. On a case-by-case basis and with sufficient justification, DAC may approve SCI storage (not to exceed 6 months).

(b) The Service CSAs, their designees, or DoD Component SIOs may approve TSWAs for all compartments of SCI. Approval for processing SCI in TSWAs may only be granted by DIA or heads of the intelligence and counterintelligence elements of the Military Services, Combatant Commands, and Defense Agencies according to their respective information system (IS) accreditation authority.

(c) Active TSWA status will be annotated on the DIA JWICs share point site by the applicable Service CSAs, their designees, or DoD Component SIOs.

(2) T-SCIF

(a) T-SCIFs are used in support of tactical, contingency, and field-training operations for a limited time where physical security construction standards associated with permanent facilities are not possible. They may include hardened structures (buildings, bunkers, etc.), truck-mounted or towed military shelters, tents, prefabricated modular trailers or buildings, and areas used on aircraft and surface and subsurface vessels.

(b) The Service CSAs, their designees, or DoD Component SIOs may establish and grant temporary accreditation to operate a T-SCIF. These officials may further delegate this approval, in writing, to a lower level of command providing continued oversight is maintained.

No further delegation is authorized. T-SCIF approvals will be valid for up to 1 year.

Consideration must be given to establishing a permanent SCIF whenever it is known that the T- SCIF will be required for a period greater than 1 year. Extension beyond the 1-year period must be justified in writing to DAC, which retains approval authority.

(c) Active T-SCIF status will be annotated on the DIA JWICs sharepoint site by the applicable Service CSAs, their designees, or DoD Component SIOs.

(d) Elements establishing or operating a T-SCIF within a deployed theater will notify the respective Combatant Command SSO within 48 hours. Such elements will also provide updates relating to the current location and status of T-SCIF under their control as directed by the Combatant Command SSO.

(e) Refer to Chapter 5, “IC Technical Specifications,” of Reference (f) for detailed physical security requirements for T-SCIFs. DAC is the approving authority whenever the application of a specific physical security requirement cannot be achieved in response to an unprecedented or unique operating environment.

Change 2, 11/02/2020 ENCLOSURE 2 12

(f) The information assurance manager (IAM) must obtain Automated Information System (AIS) accreditations in accordance with Reference (f). The designated approval authority (DAA) shall decide whether to grant accreditation approval to operate a system based on all available documentation and mitigating factors. The DAA may grant approval to operate a system as certified or grant interim approval to operate identifying the steps and any additional controls to be completed prior to full accreditation.

(g) The T-SCIF accrediting authority is responsible for ensuring that the TEMPEST requirements for the T-SCIF are followed. These requirements are outlined in Enclosure 4 of this Volume of this Manual. If these requirements cannot be met, DIA’s Certified TEMPEST Technical Authority (CTTA) must be consulted.

b. Permanent SCIF. DAC is the sole accrediting authority for physical and technical (TEMPEST) security for permanent SCI facilities.

(1) Secure Working Areas (SWAs). SWAs are accredited and used for handling, discussing, and processing but SCI is not stored in them. Since there is no time limit on their accreditation, SWAs require a higher level of security than TSWAs and T-SCIFs. The SWA shall be controlled at all times by SCI indoctrinated individuals or secured with a General Services Administration (GSA)-approved pedestrian deadbolt meeting Federal specification FF- L-2890. All SCI used in a SWA shall be moved to an accredited SCIF at the end of each business day or destroyed using CSA approved methods. There shall be a plan to relocate or destroy SCI material in the event of an emergency or natural disaster. This plan shall be tested semi-annually.

(2) Continuous Operations SCIFs. This SCIF is staffed and operated 24 hours a day, 7 days a week. Staffed refers to personnel who possess the appropriate security clearance and are permanently assigned to the SCIF as opposed to the guard force. There should be enough personnel continuously present to observe all areas that provide access to the SCIF to include primary, secondary, and emergency exit doors.

(3) Open Storage SCIFs. Open storage SCIFs allow SCI to be openly stored within the SCIF without using GSA-approved storage containers. Open storage construction requirements shall be met.

(4) Closed Storage SCIFs. All SCI material must be stored in a GSA-approved security container in an accredited facility.

4. CONSTRUCTION SECURITY

a. The renovation of existing SCIFs and the construction of new SCIFs shall meet the security requirements outlined in Reference (f). Any variances of these requirements must be approved by DAC prior to their implementation.

Change 2, 11/02/2020 ENCLOSURE 2 13

b. An SCI-indoctrinated site security manager (SSM) shall be designated by the component SSO for each new construction or renovation project. The SSM may be a U.S. Government (USG) employee, military member, or contractor, but will not be employed by the construction firm completing the project. The SSM represents the organization constructing or renovating the SCIF for all security matters to both the construction firm and the AO.

(1) The SSM shall develop a construction security plan (CSP) for each project. The plan shall include a risk assessment of the threats against the project to include human intelligence (HUMINT), counterintelligence (CI), technical, and AT/FP. The threat sources identified in Reference (f) must be used, but additional threat assessments from local sources should be utilized to define the total threat.

(2) The complexity and scope of the CSP will depend on the project. Simple modifications may only be a few pages, while the construction of a new building may be several hundred pages. Project work schedule and related documents shall be provided to the SSM in order to adequately consider and implement prudent or required security measures.

(3) The SSM, during the course of the project, shall establish appropriate security files.

These files may include work schedules, picture ID cards and access records, local guard incident and other reports, inspection reports, copies of security violations, and similar substantive project documentation as deemed appropriate by the SSM.

(4) SSMs shall have 24-hour unrestricted access to on-site construction offices and areas to conduct security inspections. This does not mean that the SSM has to be on site at all times.

During construction or renovations, the SSM shall conduct unannounced security surveys at random intervals to meet appropriate security procedures.

(5) The SSM shall be responsible for access control of the site and verify that the construction site is clear of all uncleared workers during non-duty hours.

c. During the design phase and prior to the start of construction, a CSP shall be developed by the SSM. A CSP template is available on the DIA SCIF JWICS accreditation site (http://www.dia.ic.gov/homepage/da/security/field/index.html).

(1) Security officials overseeing SCIF construction projects shall submit the CSP to DAC at the 30 percent design point along with the completed risk assessment. Based on these two documents, DAC will issue CSP guidance. The SSM will continue to update the CSP as appropriate and develop SOPs for use on the project. Component SSOs will monitor the development and implementation of the CSP. TEMPEST requirements will also be identified during this time in accordance with Enclosure 4 of this Volume.

(2) A facility under the COM, the CSP must be confirmed or certified in accordance with the OSPB in accordance with Reference (m). Assistance in developing a CSP can be obtained through DAC or the local Department of State representative.

Change 2, 11/02/2020 ENCLOSURE 2 14

d. SCI-indoctrinated escorts are required when uncleared workers have access to SCIF areas.

The ratio of escorts will be determined on a case-by-case basis by the SSM. Prior to assuming escort duties, escorts shall receive a briefing outlining their individual responsibilities.

e. Security checks will be performed on construction personnel to the greatest extent practical. Security checks shall, at a minimum, consist of local records checks conducted by military installation visitor and pass and identification offices, local military police, or local CI offices.

(1) Access to the construction site shall be denied or withdrawn by the SSM if any security checks reveal a felony criminal record, or the risk is otherwise too great to permit access to the site. SSM shall notify the installation or corporate access control department to ensure the individual cannot gain further access.

(2) A list of authorized workers should be established and maintained by the SSM.

(3) Prior to obtaining access to the site, construction workers shall be given an unclassified security orientation by a security representative. A security POC shall be provided for construction personnel to report information of a security nature.

f. A unique project site picture ID card and temporary pass system shall be implemented for access control.

(1) Construction site access control must include effective entry and exit screening and search procedures. To the greatest extent possible, a single entry point should be established to aid in this process.

(2) A prominent sign, printed in English and, if applicable, any other language deemed appropriate, shall list all prohibited and restricted items, and shall be posted at all construction area entry points. Personal bags, parcels, or packages shall not be allowed on the construction site by uncleared workers unless procedures are established for searching and safekeeping of such items.

(3) Physical security barriers shall be erected to deny unauthorized access to the controlled areas.

5. SCIF ACCREDITATION

a. The DAC is the accrediting official for DoD SCI facilities, excluding those under NGA, NRO, and NSA cognizance.

b. Refer to Enclosure 4 of this Volume for TEMPEST accreditation and ICD 503 (Reference (n)) for AIS accreditation.

Change 2, 11/02/2020 ENCLOSURE 2 15

c. The physical accreditation process begins when the DAC AO receives a validated concept approval from a Service CSA or DoD Component SIO or their designee.

d. Upon receipt of the concept approval, DAC will assign a SCIF ID in order to track future correspondence and forward this to the requestor through their chain. The requestor shall appoint an SSM, complete the CSP (see section 4 of this enclosure) and TEMPEST Countermeasures Review worksheet (see Enclosure 4 of this Volume) and begin the fixed facility checklist (FFC). The FFC format is in the technical specifications published under Reference (f).

e. Preconstruction Approval

(1) The SCIF design will consider threats and vulnerabilities against appropriate security measures to reach an acceptable level of risk. Proper security planning for a SCIF is intended to deny foreign intelligence services and other unauthorized personnel the opportunity for undetected entry into these facilities and exploitation of sensitive activities.

(2) Upon receipt of the concept approval and checklists, DAC will conduct a comprehensive risk management review and provide preconstruction advice and assistance. To avoid costly construction pitfalls, no construction should begin until DAC has reviewed the packet.

(3) The FFC included in technical specifications published in accordance with Reference

(g) and the Aircraft/UAV Accreditation Checklist and Shipboard (Surface/Subsurface) Accreditation Checklist are the primary documents in the decision-making process for granting a final accreditation. These checklists must provide sufficient detail to enable DAC to determine if the facilities satisfy physical standards detailed in Reference (g). Shipboard and aircraft accreditation checklists are available through the JWICS website at http://www.dia.ic.gov/homepage/da/security/field/index.html.

(4) These documents, along with their enclosures, should be completed and submitted initially around the end of the design phase when sufficient information has been gathered to complete the majority of the FFC. They should be updated periodically during the construction phase. The fully complete FFC and TEMPEST Addendum, along with attachments, should be submitted prior to the completion of the SCIF for the final accreditation.

f. Accreditation. Acceptance of the accreditation package is the last step in obtaining the accreditation of a new SCIF or the reaccreditation of an existing SCIF. The SCI security official will submit one copy each of the accreditation package to DAC through the appropriate CSA, their designee, or the DoD Component SIO.

(1) The accreditation package must include:

(a) The final FFC.

(b) Specification sheets for IDS component parts.

Change 2, 11/02/2020 ENCLOSURE 2 16

(c) UL 2050 certification for IDS (this requirement does not apply to SCIFs on military installations).

(d) NIST 128 bit certificate for IDS.

(e) IDS test results.

(f) SAP co-utilization agreement (if applicable).

(g) Technical surveillance countermeasure (TSCM) reports (if applicable).

(h) Catastrophic failure plan.

(2) All entries on the changed or “to be determined” items list must be completed and an asterisk placed to the left of each paragraph that changed from the initial FFC.

(3) DAC will review the accreditation package for compliance with SCI physical security standards and will issue a formal written accreditation for the SCIF and notify the requesting SSO and the appropriate CSA, their designee, or the DoD Component SIO once the SCIF satisfactorily meets the standards. In some instances, a pre-accreditation inspection by DIA SCIF accreditors may be required. The SCIF identification number initially assigned by DAC in the preconstruction phase must be used on all future communications with DIA/DAC-2.

SCI will not be discussed or introduced into the proposed SCIF until the facility is accredited.

The SCI compartments will not be included in the DAC formal written accreditation document.

(4) Accreditation documents transmitted to DAC, to the greatest extent practical, should be in a digital format.

g. Transfer of Security Cognizance. SCIFs transferred from one CSA to another are not required to be reaccredited provided that all the physical security standards remain in place, all accreditation records will be furnished to the new CSA, and all appropriate organizations will be notified. Whenever DIA assumes CSA responsibility, DAC will issue a temporary accreditation with a new SCIF identification number and request that all accreditation documents be updated and submitted to DAC within 90 days. A permanent accreditation will then be issued.

h. Reaccreditation. An existing SCIF must be reaccredited when a change occurs in any of the following areas: SCIF perimeter (i.e., expansion or downsizing), storage requirements (i.e., closed storage to open storage), change from continuous (24 hours) operations to open or closed storage. Furthermore, a reaccreditation may be issued based upon results from a DIA inspection.

Reaccreditation is not required whenever a compartment of SCI is moved from one room to another within the SCIF.

i. Modifications

Change 2, 11/02/2020 ENCLOSURE 2 17

(1) All modifications involving construction work on the perimeter walls or major modifications must have a CSP (see section 4 of this enclosure).

(2) Major modifications to existing SCIFs require prior approval by DAC. These modifications include, but are not limited to, acquisition and installation of new alarm, telephone and intercom systems, changes in exterior doors, windows and locking devices, vent and duct work, and changes in security posture (e.g., closed vice open storage, continuous operations vice closed).

(3) Minor modifications to existing SCIFs require DAC notification. These modifications include, but are not limited to permanent securing of doors, installation of approved phones, changes in occupant or office symbol, room numbers, and interior changes.

(4) For either modification, submit an updated page change of the FFC with applicable drawings.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .