ATT0072 DD254 Appendix B- IC Tech Spec-for ICD_ICS 705.pdf

PDF 10 MB Posted

Attached to
TOTAL ENGINEERING and INTEGRATION SERVICES-TEIS IV Federal contract opportunity
Solicitation number
W9128Z-20-R-0001
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This is a solicitation for a multiple award indefinite delivery/indefinite quantity contract to provide information systems engineering and information technology support services to the United States Army Information Systems Engineering Command. Services will include engineering support across all phases of information and communication systems projects, including planning, design, development, engineering, implementation, procurement, logistics, evaluation, testing, sustainment, systems retirement, and ancillary services. Worldwide support is required, with most support occurring at secure sustained locations with adequate infrastructure. However, some support may be necessary in remote or hostile locations with limited resources. Work in highly secure facilities involving high-level clearances may also be required. The period of performance is for one base year and four option years.

View the file

Other files for this federal contract opportunity

Other files attached to TOTAL ENGINEERING and INTEGRATION SERVICES-TEIS IV, newest first.
File Type Posted
W9128Z20R0001-0004.pdf PDF
ATT0065 REVISED Small Business Participation Commitment Document (SBPCD).pdf PDF
ATT0059 REVISED Sample Task-Technologies.pdf PDF
ATT0051 REVISED Sample Task-Satellite Communications.pdf PDF
ATT0011 REVISED CDRL A001.pdf PDF
ATT0060 REVISED ST-3 CDRL TS08 Facility Wiring Design Criteria (FWDC).pdf PDF
ATT0061 REVISED Past Performance Reference List (PART A).docx DOCX document
ATT0021REVISED Sample Task Cybersecurity Pkg.pdf PDF
ATT0032 REVISED ST-1 CDRL SE003 Pre Deployment Meeting.pdf PDF
ATT0062 REVISED Past Performance Information Summary (PART B).docx DOCX document
ATT0036 CDRL SE007 Out-Brief.pdf PDF
ATT0014 CDRL A004.pdf PDF
ATT0012 CDRL A002.pdf PDF
ATT0005 2.5 item d SIPRNET_Tech_Impl_Criteria V7 - Final 12Nov13.pdf PDF
ATT0051 Sample Task-Satellite Communications.pdf PDF
ATT0040 CDRL SE012 Test Data.pdf PDF
ATT0027 1.6.2C_ITV Ports and Protocols List.xls XLS spreadsheet
ATT0015 CDRL A005.pdf PDF
ATT0050 CDRL SE023 SCA-V Rec Memo.pdf PDF
ATT0045 CDRL SE017 Documentation Evaluation Report.pdf PDF
ATT0069 Fairfax VA WD 2015-4281.pdf PDF
ATT0044 CDRL SE016 SE Assessment Report.pdf PDF
ATT0031 CDRL SE001 Weekly Project Report.pdf PDF
ATT0009 2.5 item n DISN-EN ICAN-DI Standards Specifications v1_09f FINAL.pdf PDF
ATT0026 1.6.2B_ITV CONOPS Diagrams.pdf PDF
ATT0021 Sample Task Cybersecurity Pkg.pdf PDF
ATT0066 Joint VentureTeaming Informaiton.xlsx XLSX spreadsheet
ATT0057 CDRL TS29 Trip Report.pdf PDF
ATT0025 1.6.2A_ITV HW-SW List.xlsx XLSX spreadsheet
ATT0060 CDRL TS08 Facility Wiring Design Criteria (FWDC).pdf PDF
ATT0028 1.6.3A_NC HW-SW List.xlsx XLSX spreadsheet
ATT0007 2.5 item i UFC 4-140-03.pdf PDF
ATT0004 2.5 item c 18-033 USAISEC VIS Software Design Criteria - Final 14 Mar 18.pdf PDF
ATT0067 Estimated Work Breakout.pdf PDF
ATT0035 CDRL SE006 Daily Project Report.pdf PDF
ATT0029 1.6.3B_NC Block Diagram Layout.pdf PDF
ATT0010 2.5 item f USAISEC Cyber Security Assessment and Security Engineering Manual V2.1.pdf PDF
ATT0064 CONUS High CONUS OCONUS Labor Rates.xlsx XLSX spreadsheet
ATT0054 CDRL TS26 Project Concurrence Memo.pdf PDF
ATT0042 CDRL SE014 IAVA Compliance Report.pdf PDF
ATT0018 TEIS IV QASP.pdf PDF
ATT0047 CDRL SE019 Executive Summary.pdf PDF
ATT0038 CDRL SE009 DCAFS.pdf PDF
ATT0033 CDRL SE004 Test Readiness Review Questionnaire.pdf PDF
ATT0019 TEIS IV - Draft Labor Category Descriptions.pdf PDF
ATT0043 CDRL SE015 STIG Compliance Report.pdf PDF
ATT0020 TEIS IV - DD254.pdf PDF
ATT0013 CDRL A003.pdf PDF
ATT0063 Past Performance Questionnaire.pdf PDF
ATT0030 1.6.3C_NC Ports and Protocols List.xls XLS spreadsheet
Show all 50

TOTAL ENGINEERING and INTEGRATION SERVICES-TEIS IV has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Technical Specifications for Construction and

Management of Sensitive Compartmented

Information Facilities

VERSION 1.4

IC Tech Spec – for ICD/ICS 705

An Intelligence Community Technical Specification

Prepared by the

National Counterintelligence and Security Center

September 28, 2017

This page intentionally left blank.

SUBJECT: Technical Specifications for Construction and Management of Sensitive

Compartmented Information Facilities, Version 1.4 ii

Distribution:

Secretary of State, Department of State

Secretary of the Treasury, Department of the Treasury

Secretary of Defense, Department of Defense

Attorney General, Department of Justice

Secretary of the Interior, Department of the Interior

Secretary of Agriculture, Department of Agriculture

Secretary of Commerce, Department of Commerce

Secretary of Labor, Department of Labor

Secretary of Health and Human Services, Department of Health and Human Services

Secretary of Housing and Urban Development, Department of Housing and Urban Development

Secretary of Transportation, Department of Transportation

Secretary of Energy, Department of Energy

Secretary of Education, Department of Education

Secretary of Veterans Affairs, Department of Veterans Affairs

Secretary of Homeland Security, Department of Homeland Security

Administrator, Executive Office of the President

Administrator, Environmental Protection Agency

Director, Office of Management and Budget

United States Trade Representative

Administrator, Small Business Administration

Director, National Drug Control Policy

Director, Central Intelligence Agency

Administrator, Equal Employment Opportunity Commission

Chairman, Federal Communications Commission

Chairman, Federal Maritime Commission

Chairman, Federal Reserve System

Chairman, Federal Trade Commission

Administrator, General Services Administration

Administrator, National Aeronautics and Space Administration

Archivist, National Archives and Records Administration

Director, National Science Foundation

Chairman, Nuclear Regulatory Commission

Director, Office of Government Ethics

Chairman, Privacy and Civil Liberties Oversight Board

Chairman, Security and Exchange Commission

Director, Selective Service System

Commissioner, Social Security Administration

Administrator, United States Agency for International Development

United States Postal Service

Chairman, United States International Trade Commission

Director, United States Peace Corps

Office of the Chief Administrative Officer

Change History iii

Change History Rev. # Date Page Changes Approver

1.2 04/23/12 Cover Banner Graphic, Version, Date PTSEWG

1.2 04/23/12 4

Added note to warn users of classification when associating threat information and facility location.

PTSEWG

1.2 04/23/12 5 Re-worded approval of CAs to designate the AO as the primary approval authority of Compartmented

Areas within SCIFs.

PTSEWG

1.2 04/23/12 9-10 Changed “Type X Gypsum” to

“wallboard” to remove the standard of fire resistant gypsum and permit use of other wallboard types.

PTSEWG

1.2 04/23/12 9-10 Changed references to wall design drawings to “suggested” wall types to enable variety of wall construction techniques to meet the security standards.

PTSEWG

1.2 04/23/12 10 Added explanation to glue and screw plywood to ceiling and floor to clarify standard. Stud placement changed to 16 on center to match drawing and correct error.

PTSEWG

1.2 04/23/12 11 Added statement to finish wall and paint from true floor to true ceiling in

Walls B and C to clarify and equal

Type A Wall.

PTSEWG

1.2 04/23/12 9-10 Replaced drawings to reflect

“suggested” wall construction methods and remove references to “Type X gypsum wallboard”.

PTSEWG

1.2 04/23/12 17-19 Replaced drawings to reflect

“suggested” wall construction methods and remove references to “Type X gypsum wallboard”.

PTSEWG

1.2 04/23/12 56 Updated Federal Information

Processing Standards (FIPS) encryption standards and certification to remove a standard that could not be met by commercial alarm systems.

PTSEWG

1.2 04/23/12 64 Replaced FIPS 140-2 with Advanced

Encryption Standard (AES) to remove a standard that could not be met by commercial alarm systems.

PTSEWG

iv

Rev. # Date Page Changes Approver

1.2 04/23/12 TEMPEST

Checklist

Removed references to “inspectable space” as requested by the TEMPEST

Advisory Group (TAG).

PTSEWG

1.2 04/23/12 TEMPEST

Checklist

Removed references to “Red-SCI” information.

PTSEWG

1.2 04/23/12 TEMPEST

Checklist

Removed parenthetical reference to cell phones and Bluetooth.

PTSEWG

1.2 04/23/12 CA

Checklist

Replaced Compartmented Area

Checklist to reflect IC standards.

PTSEWG

1.2 04/23/12 SCIF Co-Use

Request and

MOA Form

Replaced Co-Use and MOA Form to include “joint-use” statements.

PTSEWG

1.3 03/26/15 Cover Banner change, version, date PTSEWG

1.3 03/26/15 B-C Appended “D/NCSC Memorandum” PTSEWG

1.3 03/26/15 D-G “Appended Change History” PTSEWG

1.3 03/26/15 3 Chapter 2.A (2)(a) Added: “NOTE” regarding prefabricated modular SCIFs.

PTSEWG

1.3 03/26/15 9 Chapter 3.C

Corrected wording to match wall drawings on p.21.

PTSEWG

1.3 03/26/15 14 Chapter 3.G (7)(c.4) Correction and addition of guidance on vents and ducts perimeter protection.

PTSEWG

1.3 03/26/15 17-19 Reformatted wall types to reflect correct architectural graphics for prescribed materials.

PTSEWG

1.3 03/26/15 53 Chapter 7.A (2)(d)

Added requirement for HSS switches.

PTSEWG

1.3 03/26/15 54 Chapter 7.A (2)(k) Changed to reflect restrictions on dissemination of installation plans.

PTSEWG

1.3 03/26/15 54 Chapter 7.A (3)(a.2) Added exception that sensors must be located within SCIF perimeter.

PTSEWG

1.3 03/26/15 55 Chapter 7.A (3)(b.7.e) Replaced

“Zones” with “IDE sensor points”.

PTSEWG

1.3 03/26/15 56 Chapter 7.A (3)(c.1) Added language for approval authority.

PTSEWG

1.3 03/26/15 56 Chapter 7.A (3)(c.2) Added language for integrated IDS and

Remote Access.

PTSEWG

1.3 03/26/15 56-57 Chapter 7.A (3)(c.2) Added system application software requirements.

PTSEWG

1.3 03/26/15 58-59 Replaced “access/secure” with

“arm/disarm” throughout.

v

Rev. # Date Page Changes Approver

1.3 03/26/15 58 Chapter 7.B (2) Added “A record shall be maintained that identifies the person responsible for disarming the system”.

PTSEWG

1.3 03/26/15 87 Chapter 12.G (2)

Changed Section header to read

“Inspections/Reviews, added same where the term “inspection” or

“review” used. The responsibility to perform as such was changed from “IC element head” to the AO, or designee.

PTSEWG

1.3 03/26/15 SCIF Co-Use

Request and

MOA Form

Appended Co-Use Request and MOA

Form

PTSEWG

1.4 06/27/17 Cover Banner change, version, date PTSEWG

1.4 06/27/17 i-iii Appended “D/NCSC Memorandum” PTSEWG

1.4 06/27/17 iv-vii “Appended Change History” PTSEWG

1.4 06/27/17 1 Chapter 1.B.2

Added SAPF Language

PTSEWG

1.4 06/27/17 12 Chapter 3.E.1.b

Added egress device language

PTSEWG

1.4 06/27/17 60 Chapter 7.C.1.c

Added, “…IAW UL 2050 requirements

(60 minutes)”

PTSEWG

1.4 06/27/17 71-74 Chapter 10 Revised PTSEWG

1.4 06/27/17 75-76 Chapter 11.B.5

Added sub-bullets to address CNSSI

PTSEWG

1.4 06/27/17 90-91 Chapter 12.L1/2/7

Added additional clarification language

PTSEWG

1.4 06/27/17 91-92 Chapter 12.M.4

Synchronized bullets vi

Table of Contents vii

Table of Contents Chapter 1. Introduction……………………………………………………………………… 1

A. Purpose………………………………………………………………………………… 1

B. Applicability…………………………………………………………………………… 1

Chapter 2. Risk Management ………………………………………………………………... 3

A. Analytical Risk Management Process………………………………………………… 3

B. Security in Depth (SID)………………………………………………………………. 4

C. Compartmented Area (CA) …………………………………………………………... 5

Chapter 3. Fixed Facility SCIF Construction………………………………………………... 7

A. Personnel…………………………………………………………………………

B. Construction Security………………………………………………………………….. 8

C. Perimeter Wall Construction Criteria…………………………………………………. 9

D. Floor and Ceiling Construction Criteria……………………………….………….…... 12

E. SCIF Door Criteria………………………………………………………………….… 12

F. SCIF Window Criteria………………………………………………………………. 13

G. SCIF Perimeter Penetrations Criteria…………………………………………………. 14

H. Alarm Response Time Criteria for SCIFs within the U.S. …………………………… 15

I. Secure Working Areas (SWA) ……………………………………………………….. 15

J. Temporary Secure Working Area (TSWA) ………………………………………….. 16

Chapter 4. SCIFs Outside the U.S. and NOT Under Chief of Mission (COM) Authority….. 21

A. General………………………………………………………………………………… 21

B. Establishing Construction Criteria Using Threat Ratings…………………………….. 21

C. Personnel………………………………………………………………………………. 24

D. Construction Security Requirements…………………………………………………. 25

E. Procurement of Construction Materials……………………………………………….. 28

F. Secure Transportation for Construction Material……………………………………… 29

G. Secure Storage of Construction Material……………………………………………… 30

H. Technical Security……………………………………………………………………. 31

I. Interim Accreditations………………………………………………………………… 31

Chapter 5. SCIFs Outside the U.S. and Under Chief of Mission Authority………………… 33

A. Applicability…………………………………………………………………………… 33

B. General Guidelines…………………………………………………………………….. 33

C. Threat Categories……………………………………………………………………… 34

D. Construction Requirements…………………………………………………………… 34

E. Personnel………………………………………………………………………………. 36

F. Construction Security Requirements…………………………………………………. 37

G. Procurement of Construction Materials……………………………………………….. 40

H. Secure Transportation for Construction Material……………………………………… 41

I. Secure Storage of Construction Material……………………………………………… 42 viii

J. Technical Security……………………………………………………………………. 42

K. Interim Accreditations………………………………………………………………… 42

Chapter 6. Temporary, Airborne, and Shipboard SCIFs……………………………………. 43

A. Applicability………………………………………………………………………….. 43

B. Ground-Based T-SCIFs………………………………………………………………. 43

C. Permanent and Tactical SCIFS Aboard Aircraft……………………………………... 45

D. Permanent and Tactical SCIFs on Surface or Subsurface Vessels…………………… 47

Chapter 7. Intrusion Detection Systems (IDS) ……………………………………………… 53

A. Specifications and Implementation Requirements…………………………………….. 53

B. IDS Modes of Operation………………………………………………………………. 58

C. Operations and Maintenance of IDS…………………………………………………… 60

D. Installation and Testing of IDS………………………………………………………… 61

Chapter 8. Access Control Systems (ACS) ………………………………………………… 63

A. SCIF Access Control…………………………………………………………………. 63

B. ACS Administration…………………………………………………………………… 64

C. ACS Physical Protection………………………………………………………………. 64

D. ACS Recordkeeping…………………………………………………………………… 64

. E. Using Closed Circuit Television (CCTV) to Supplement ACS……………………….. 65

F. Non-Automated Access Control………………………………………………………. 65

Chapter 9. Acoustic Protection……………………………………………………………… 67

A. Overview………………………………………………………………………………. 67

B. Sound Group Ratings………………………………………………………………….. 67

C. Acoustic Testing……………………………………………………………………… 67

D. Construction Guidance for Acoustic Protection……….……………………………… 68

E. Sound Transmission Mitigations………………………………………………………. 68

Chapter 10. Portable Electronic Devices with Recording Capabilities and Embedded

Technologies (PEDs/RCET)………………………………….…………….………………… 71

A. Approved Use of PEDs/RECET in a SCIF…………………………………………… 71

B. Prohibitions……………………………………………………………………………. 72

C. PED/RCET Risk Levels………………………………………………………………. 72

D. Risk Mitigation………………………………………………………………………… 73

Chapter 11. Telecommunications Systems………………………………………………….. 75

A. Applicability…………………………………………………………………………… 75

B. Unclassified Telephone Systems………………………………………………………. 75

C. Unclassified Information Systems…………………………………………………….. 77

D. Using Closed Circuit Television (CCTV) to Monitor the SCIF Entry Point(s) ……… 77

E. Unclassified Wireless Network Technology…………………………………………. 77

F. Environmental Infrastructure Systems………………………………………………… 78

G. Emergency Notification Systems……………………………………………………… 78 ix

H. System Access………………………………………………………………………… 79

I. Unclassified Cable Control……………………………………………………………. 79

J. Protected Distribution Systems………………………………………………………… 80

K. References……………………………………………………………………………. 80

Chapter 12. Management and Operations…………………………………………………… 83

A. Purpose………………………………………………………………………………… 83

B. SCIF Repository………………………………………………………………………. 83

C SCIF Management……………………………………………………………………... 84

D. SOPs…………………………………………………………………………………… 85

E. Changes in Security and Accreditation……………………………………………..…. 86

F. General………………………………………………………………………………… 86

G. Inspections/Reviews…………………………………………………………………… 87

H. Control of Combinations………………………………………………………………. 87

I. De-Accreditation Guidelines…………………………..……………………….……… 88

J. Visitor Access………………………………………………………………………….. 88

K. Maintenance………………………………………………………….………………… 90

L. IDS and ACS Documentation Requirements……………………………….………….. 90

M. Emergency Plan……………………………………………………………………….. 91

Chapter 13. Forms and Plans………………………………………………………………… 93

Fixed Facility Checklist

TEMPEST Checklist

Compartmented Area Checklist

Shipboard Checklist

Submarine Checklist

Aircraft/UAV Checklist

SCIF Co-Use Request and MOA

Construction Security Plan (CSP) x

Chapter 1

Introduction

Chapter 1. Introduction

A. Purpose This Intelligence Community (IC) Technical Specification sets forth the physical and technical security specifications and best practices for meeting standards of Intelligence

Community Standard (ICS) 705-1 (Physical and Technical Standards for Sensitive

Compartmented Information Facilities). When the technical specifications herein are applied to new construction and renovations of Sensitive Compartmented Information Facilities

(SCIFs), they shall satisfy the standards outlined in ICS 705-1 to enable uniform and reciprocal use across all IC elements and to assure information sharing to the greatest extent possible. This document is the implementing specification for Intelligence Community

Directive (ICD) 705 (Sensitive Compartmented Information Facilities), ICS 705-1, and ICS

705-2 (Standards for Accreditation and Reciprocal Use of Sensitive Compartmented

Information Facilities.

The specifications contained herein will facilitate the protection of Sensitive Compartmented

Information (SCI) against compromising emanations, inadvertent observation and disclosure by unauthorized persons, and the detection of unauthorized entry.

B. Applicability IC Elements shall fully implement this standard within 180 days of its signature.

1. SCIFs that have been de-accredited but controlled at the SECRET level (IAW 32

Code of Federal Regulations (CFR) parts 2001 and 2004) for less than one year may be re-accredited. The IC SCIF repository shall indicate that the accreditation was based upon the previous standards.

2. When the technical specifications herein have been applied to new construction, renovations, and operation of Special Access Program Facilities (SAPFs), those facilities shall satisfy the standards outlined in ICD 705 to enable uniform use across all IC elements for accreditation by IC elements as a Sensitive Compartmented

Information Facility.

a) Accreditation of a SAPF as a SCIF will be based upon a review of all required

SCIF construction documentation to ensure all ICD 705 requirements were met in the construction, maintenance, and operation of the SAPF.

b) The AO will conduct a review of all SAPF accreditation documentation for compliance with the technical specifications herein.

(1) If all required documentation is available and correct, the AO will issue

SCIF accreditation.

(2) If all required documentation is not available and correct, or waivers have been authorized, the AO is not required to issue SCIF accreditation.

Chapter 1

Introduction

c) If the facility is to be maintained as a SAPF and co-utilized as a SCIF, the security posture of the facility will be to the highest requirement of the two.

(1) The AO may issue a more restrictive accreditation based upon the SCI requirements associated with the new SCIF accreditation. For example, 5 minute response versus 15 minutes, or Closed Storage versus Open

Storage.

(2) Program indoctrination will be coordinated as part of the co-utilization agreement. Compartmented Areas may be utilized, but no other sub-division of the facility will be permitted. Facilities requiring additional protections are not suitable for co-utilization.

Chapter 2

Risk Management

Chapter 2. Risk Management

A. Analytical Risk Management Process

1. The Accrediting Official (AO) and the Site Security Manager (SSM) should evaluate each proposed SCIF for threats, vulnerabilities, and assets to determine the most efficient countermeasures required for physical and technical security. In some cases, based upon that risk assessment, it may be determined that it is more practical or efficient to mitigate a standard. In other cases, it may be determined that additional security measures should be employed due to a significant risk factor.

2. Security begins when the initial requirement for a SCIF is known. To ensure the integrity of the construction and final accreditation, security plans should be coordinated with the AO before construction plans are designed, materials ordered, or contracts let.

a) Security standards shall apply to all proposed SCI facilities and shall be coordinated with the AO for guidance and approval. Location of facility construction and or fabrication does not exclude a facility from security standards and or review and approval by the AO. SCI facilities include but are not limited to fixed facilities, mobile platforms, prefabricated structures, containers, modular applications or other new or emerging applications and technologies that may meet performance standards for use in SCI facility construction.

NOTE: Advertised claims by manufactures that their product(s), to include mobile platforms, prefabricated structures, containers and modular structures are built to SCIF standards and can be accredited without modification may not be accurate. AOs are responsible for ensuring security controls spelled out in the

ICD/ICS 705 series and this document are implemented to protect the security integrity of the proposed SCIF prior to accreditation.

b) Mitigations are verifiable, non-standard methods that shall be approved by the

AO to effectively meet the physical/technical security protection level(s) of the standard. While most standards may be effectively mitigated via non-standard construction, additional security countermeasures and/or procedures, some standards are based upon tested and verified equipment (e.g., a combination lock meeting Federal Specification FF-L 2740) chosen because of special attributes and could not be mitigated with non-tested equipment. The AO’s approval is documented to confirm that the mitigation is at least equal to the physical/technical security level of the standard.

c) Exceeding a standard, even when based upon risk, requires that a waiver be processed and approved in accordance with ICD 705.

3. The risk management process includes a critical evaluation of threats, vulnerability, and assets to determine the need and value of countermeasures. The process may include the following:

a) Threat Analysis. Assess the capabilities, intentions, and opportunity of an adversary to exploit or damage assets or information. For SCI Facilities under

Chief of Mission (COM) authority use the Overseas Security Policy Board

(OSPB), Security Environment Threat List (SETL) to determine technical threat to a location. When evaluating for TEMPEST, the Certified TEMPEST

Technical Authorities (CTTA) shall use the National Security Agency

Information Assurance (NSA IA) list as an additional resource for specific technical threat information. NOTE: These threat documents are classified.

Associating the threat level or other threat information with the SCIF location

(including country, city, etc.) will normally carry the same classification level identified in the threat document. Ensure that SCIF planning documents and discussions that identify threat with the country or SCIF location are protected accordingly. It is critical to identify other occupants of common and adjacent buildings. (However, do not attempt to collect information against U.S. persons in violation of Executive Order (EO) 12333.) In areas where there is a diplomatic presence of high and critical technical threat countries, additional countermeasures may be necessary.

b) Vulnerability Analysis. Assess the inherent susceptibility to attack of a procedure, facility, information system, equipment, or policy.

c) Probability Analysis. Assess the probability of an adverse action, incident, or attack occurring.

d) Consequence Analysis. Assess the consequences of such an action (expressed as a measure of loss, such as cost in dollars, resources, programmatic effect/mission impact, etc.).

B. Security in Depth (SID)

1. SID describes the factors that enhance the probability of detection before actual penetration to the SCIF occurs. The existence of a layer or layers of security that offer mitigations for risks may be accepted by the AO. An important factor in determining risk is whether layers of security already exist at the facility. If applied, these layers may, with AO approval, alter construction requirements and extend security alarm response time to the maximum of 15 minutes. Complete documentation of any/all SID measures in place will assist in making risk decisions necessary to render a final standards decision.

2. SID is mandatory for SCIFs located outside the U.S. due to increased threat.

3. The primary means to achieve SID are listed below and are acceptable. SID requires that at least one of the following mitigations is applied:

a) Military installations, embassy compounds, U.S. Government (USG) compounds, or contractor compounds with a dedicated response force of U.S.

persons.

b) Controlled buildings with separate building access controls, alarms, elevator controls, stairwell controls, etc., required to gain access to the buildings or elevators. These controls shall be fully coordinated with a formal agreement or managed by the entity that owns the SCIF.

c) Controlled office areas adjacent to or surrounding SCIFs that are protected by alarm equipment installed in accordance with manufacturer’s instructions. These controls shall be fully coordinated with a formal agreement or managed by the entity that owns the SCIF.

d) Fenced compounds with access controlled vehicle gate and/or pedestrian gate.

e) The AO may develop additional strategies to mitigate risk and increase probability of detection of unauthorized entry.

C. Compartmented Area (CA)

1. Definition

A CA is an area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled

Access Programs.

2. Requirements

a) The CA shall be approved by the AO with the concurrence of the CA Program

Manager or designee. The CA Checklist (Chapter 13) shall be used to request approval.

b) Any construction or security requirements above those listed herein require prior approval from the element head as described in ICS 705-2.

3. Access Control

a) Access control to the CA may be accomplished by visual recognition or mechanical/electronic access control devices.

b) Spin-dial combination locks shall not be installed on CA doors.

c) Independent alarm systems shall not be installed in a CA.

4. Visual Protection of CA Workstations

If compartmented information will be displayed on a computer terminal or group of terminals in an area where everyone is not accessed to the program, the following measures may be applied to reduce the ability of “shoulder surfing” or inadvertent viewing of compartmented information:

Position the computer screen away from doorway/cubicle opening.

Use a polarizing privacy screen.

Use partitions and/or signs.

Existing private offices or rooms may be used but may not be a mandatory requirement.

5. Closed Storage

When the storage, processing, and use of compartmented information, product, or deliverables is required, and all information shall be stored while not in use, then all of the following shall apply:

a) Access and visual controls identified above shall be the standard safeguard.

b) Compartmented information shall be physically stored in a General Services

Administration (GSA) approved safe.

6. Open Storage

In rare instances when open storage of information is required, the following apply:

a) If the parent SCIF is accredited for open storage, a private office with access control on the door is adequate physical security protection.

b) If the parent SCIF has been built and accredited for closed storage, then the

CA perimeter shall be constructed and accredited to open storage standards.

c) The CA AO may approve open or closed storage within the CA. Storage requirements shall be noted in both the CA Fixed Facility Checklist (FFC) and, if appropriate, in a Memorandum of Understanding (MOU).

7. Acoustic and Technical Security

a) All TEMPEST, administrative telephone, and technical surveillance countermeasure (TSCM) requirements for the parent SCIF shall apply to the CA and shall be reciprocally accepted.

b) When compartmented discussions are required, the following apply:

(1) Use existing rooms that have been accredited for SCI discussions.

(2) Use administrative procedures to restrict access to the room during conversations.

Chapter 3

Fixed Facility SCIF Construction

Chapter 3. Fixed Facility SCIF Construction Requirements outlined within this chapter apply to all fixed facility SCIFs. Additional information and requirements for facilities located outside the U.S., its possessions or territories, are found in Chapters 4 and 5. Additional information and requirements for temporary SCIFs are described in Chapter 6.

A. Personnel

Roles and responsibilities of key SCIF construction personnel are identified in ICS 705-1 and restated here for reference.

1. AO Responsibilities

a) Provide security oversight of all aspects of SCIF construction under their security purview.

b) Review and approve the design concept, Construction Security Plan (CSP), and final design for each construction project prior to the start of SCIF construction.

c) Depending on the magnitude of the project, determine if the Site Security

Manager (SSM) performs duties on a full-time, principal basis, or as an additional duty to on-site personnel.

d) Accredit SCIFs under their cognizance.

e) Prepare waiver requests for the IC element head or designee.

f) Provide the timely input of all required SCIF data to the IC SCIF repository.

g) Consider SID on USG or USG-sponsored contractor facilities to substitute for standards herein. (SID shall be documented in the CSP and the FFC.)

2. Site Security Managers (SSMs) Responsibilities

a) Ensure the requirements herein are implemented and advise the AO of compliance or variances.

b) In consultation with the AO, develop a CSP regarding implementation of the standards herein. (This document shall include actions required to document the project from start to finish.)

c) Conduct periodic security inspections for the duration of the project to ensure compliance with the CSP.

d) Document security violations or deviations from the CSP and notify the AO within 3 business days.

e) Ensure that procedures to control site access are implemented.

3. CTTA Responsibilities

a) Review SCIF construction or renovation plans to determine if TEMPEST countermeasures are required and recommend solutions. To the maximum extent practicable, TEMPEST mitigation requirements shall be incorporated into the SCIF design.

b) Provide the Cognizant Security Authority (CSA) and AO with documented results of review with recommendations.

4. Construction Surveillance Technicians (CSTs) Responsibilities

a) Supplement site access controls, implement screening and inspection procedures, as well as monitor construction and personnel, when required by the AO.

b) In low and medium technical threat countries, begin surveillance of non-cleared workers at the start of SCIF construction or the installation of major utilities, whichever comes first.

c) In high and critical technical threat countries, begin surveillance of non-cleared workers at the start of: construction of public access or administrative areas adjacent to the SCIF; SCIF construction; or the installation of major utilities, whichever comes first.

B. Construction Security

1. Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO.

2. Construction plans and all related documents shall be handled and protected in accordance with the CSP.

3. For SCIF renovation projects, barriers shall be installed to segregate construction workers from operational activities and provide protection against unauthorized access and visual observation. Specific guidance shall be contained in the CSP.

4. Periodic security inspections shall be conducted by the SSM or designee for the duration of the project to ensure compliance with construction design and security standards.

5. Construction and design of SCIFs should be performed by U.S. companies using U.S.

citizens to reduce risk, but may be performed by U.S. companies using U.S. persons (an individual who has been lawfully admitted for permanent residence as defined in 8

U.S.C. § 1101(a)(20) or who is a protected individual as defined by Title 8 U.S.C. §

1324b (a)(3)). The AO shall ensure mitigations are implemented when using non-U.S.

citizens. These mitigations shall be documented in the CSP.

6. All site control measures used shall be documented in the CSP. Among the control measures that may be considered are the following:

Identity verification.

Random searches at site entry and exit points.

Signs at all entry points listing prohibited and restricted items (e.g., cameras, firearms, explosives, drugs, etc.).

Physical security barriers to deny unauthorized access.

Vehicle inspections.

C. Perimeter Wall Construction Criteria

1. General

a) SCIF perimeters include all walls that outline the SCIF confines, floors, ceilings, doors, windows and penetrations by ductwork, pipes, and conduit. This section describes recommended methods to meet the standards described within ICS 705-1 for SCIF perimeters.

b) Perimeter wall construction specifications vary by the type of SCIF, location, use of SID, and discussion requirements.

c) Closed storage areas that do not require discussion areas do not have any forced entry or acoustic requirements.

d) Open storage facilities without SID require additional protection against forced and surreptitious entry.

e) When an existing wall is constructed with substantial material (e.g., brick, concrete, cinderblock, etc.) equal to meet the perimeter wall construction standards, the existing wall may be utilized to satisfy the specification.

2. Closed Storage, Secure Working Area (SWA), Continuous Operation, or Open

Storage with SID - Use Wall A - Suggested Standard Acoustic Wall (see construction drawing for details).

a) Three layers ⅝ inch-thick gypsum wallboard (GWB), one layer on the uncontrolled side of the SCIF and two on the controlled side of the SCIF, to provide adequate rigidity and acoustic protection (Sound Class 3).

b) Wallboard shall be attached to 3 ⅝ inch-wide 16 gauge metal studs or wooden 2 x

4 studs placed no less than 16” on center (o.c.).

c) 16 gauge continuous track (top & bottom) w/ anchors at 32” o.c. maximum) – bed in continuous bead of acoustical sealant.

d) The interior two layers of wallboard shall be mounted so that the seams do not align (i.e., stagger joints).

e) Acoustic fill 3 ½ “ (89mm) sound attenuation material, fastened to prevent sliding down and leaving void at the top.

f) The top and bottom of each wall shall be sealed with an acoustic sealant where it meets the slab.

g) Fire safe non-shrink grout, or acoustic sealant in all voids above/below track both sides of partition.

h) Entire wall assembly shall be finished and painted from true floor to true ceiling.

3. Open Storage without SID -- Use Wall B - Suggested Wall for Expanded Metal or

Wall C - Suggested Wall for Plywood.

a) Three layers of ⅝ inch-thick GWB, one layer on the uncontrolled side of the SCIF and two on the controlled side of the SCIF to provide adequate rigidity and acoustic protection (Sound Class 3).

b) Wallboard shall be attached to 3 ⅝ inch-wide 16 gauge metal studs or wooden 2 x

4 studs placed no less than 16” o.c.

c) 16 gauge continuous track (top & bottom) w/ anchors at 32” on center (o.c.)

maximum) – bed in continuous bead of acoustical sealant.

d) Wall B - Suggested Wall for Expanded Metal (see drawing for Wall B-Suggested

Construction for Expanded Metal).

(1) Three-quarter inch mesh, # 9 (10 gauge) expanded metal shall be affixed to the interior side of all SCIF perimeter wall studs.

(2) Expanded metal shall be spot-welded to the studs every six inches along the length of each vertical stud and at the ceiling and floor.

(3) Hardened screws with one inch washers or hardened clips may be used in lieu of welding to fasten metal to the studs. Screws shall be applied every six inches along the length of each vertical stud and at the ceiling and floor.

(4) Fastening method shall be noted in the FFC.

(5) Entire wall assembly shall be finished and painted from true floor to true ceiling.

e) Wall C - Suggested Wall for Plywood (see drawing for Wall C-Suggested

Construction for Plywood).

(1) Three layers of ⅝ inch-thick GWB, two layers on the uncontrolled side and one layer GWB over minimum ½ ” plywood on the controlled side of the SCIF.

NOTE: CTTA recommended countermeasures (foil backed GWB or layer of approved Ultra Radiant R-Foil) shall be installed in accordance with (IAW) best practices for architectural Radio Frequency (RF) shielding. Foil shall be located between the layer of plywood and GWB.

(2) 1/2" Plywood affixed 8’ vertical by 4’ horizontal to 16 gauge studs using glue and #10 steel tapping screws at 12 o.c.

(3) GWB shall be mounted to plywood with screws avoiding contact with studs to mitigate any possible acoustic flanking path.

(4) 16 gauge continuous track (top & bottom) w/ anchors at 32” o.c. maximum)

– bed in continuous bead of acoustical sealant.

(5) Fire safe non-shrink grout, or acoustic sealant in all voids above/below track both sides of partition.

(6) Entire wall assembly shall be finished and painted from true floor to true ceiling.

4. Radio Frequency (RF) Protection for Perimeter Walls

a) RF protection shall be installed at the direction of the CTTA when a SCIF utilizes electronic processing and does not provide adequate RF attenuation at the inspectable space boundary. It is recommended for all applications where RF interference from the outside of the SCIF is a concern inside the SCIF.

b) Installation of RF protection should be done using either the drawings or Best

Practices Guidelines for Architectural Radio Frequency Shielding, prepared by the

Technical Requirements Steering Committee under the Center for Security

Evaluation. This document is available through the Center for Security Evaluation, Office of the Director of National Intelligence (NCSC/CSE).

5. Vault Construction Criteria

GSA-approved modular vaults meeting Federal Specification AA-V-2737 or one of the following construction methods may be used:

a) Reinforced Concrete Construction

(1) Walls, floor, and ceiling will be a minimum thickness of eight inches of reinforced concrete.

(2) The concrete mixture will have a comprehensive strength rating of at least

2,500 pounds per square inch (psi).

(3) Reinforcing will be accomplished with steel reinforcing rods, a minimum of

⅝ inches in diameter, positioned centralized in the concrete pour and spaced horizontally and vertically six inches on center; rods will be tied or welded at the intersections.

(4) The reinforcing is to be anchored into the ceiling and floor to a minimum depth of one-half the thickness of the adjoining member.

b) Steel-Lined Construction Where Unique Structural Circumstances Do Not Permit

Construction of a Concrete Vault

(1) Construction will use ¼ inch-thick steel alloy-type plates having characteristics of high-yield and high-tensile strength.

(2) The steel plates are to be continuously welded to load-bearing steel members of a thickness equal to that of the plates.

(3) If the load-bearing steel members are being placed in a continuous floor and ceiling of reinforced concrete, they must be firmly affixed to a depth of one-half the thickness of the floor and ceiling.

(4) If floor and/or ceiling construction is less than six inches of reinforced concrete, a steel liner is to be constructed the same as the walls to form the floor and ceiling of the vault. Seams where the steel plates meet horizontally and vertically are to be continuously welded together.

All vaults shall be equipped with a GSA-approved Class 5 vault door.

D. Floor and Ceiling Construction Criteria

1. Floors and ceilings shall be constructed to meet the same standards for force protection and acoustic protection as walls.

2. All floor and ceiling penetrations shall be kept to a minimum.

E. SCIF Door Criteria

1. There shall be only one primary SCIF entrance where visitor control is conducted.

a) Primary entrance doors shall be equipped with the following:

(1) A GSA-approved pedestrian door deadbolt meeting Federal Specification FF-

L- 2890.

(2) A combination lock meeting Federal Specification FF-L 2740.

(3) An approved access-control device (see Chapter 8).

(4) May be equipped with a high security keyway for use in the event of an access control system failure.

b) With AO approval, additional entrance doors may be designated for use by SCIF residents provided that the doors are equipped with an approved access control system and are secured with an approved dead bolt or lock when the SCIF is not occupied. The dead-bolt shall not be accessible from the exterior.

(1) A GSA-approved pedestrian door egress device meeting Federal

Specification FF-L-2890, specifically modified for secondary SCIF door use with no combination lock and a capability of deadlocking the access control feature after hours.

2. When practical, entrance doors should incorporate a vestibule to preclude visual observation and enhance acoustic protection.

3. All perimeter SCIF doors shall be equipped with an automatic, non-hold door-closer which shall be installed internal to the SCIF, if possible.

4. Emergency exit doors shall:

a) Be secured with deadlocking panic hardware on the inside.

(1) A GSA-approved pedestrian door meeting Federal Specification FF-L-2890, type III, specifically modified for emergency exit applications with no external hardware.

b) Have no exterior hardware.

c) Be alarmed 24/7.

d) Provide a local audible annunciation when opened.

5. Hinge pins that are accessible from outside of the SCIF door shall be modified to prevent removal of the door, e.g., welded, set screws, etc.

6. SCIF doors and frame assemblies shall meet acoustic requirements as described in

Chapter 9 unless declared a non-discussion area.

7. All perimeter doors shall be alarmed in accordance with Chapter 7.

8. Perimeter doors shall comply with applicable building, safety, and accessibility codes and requirements.

9. Perimeter doors shall meet TEMPEST requirements when applicable.

10. Wood doors shall be 1 ¾ inch-thick solid wood core (wood stave).

11. Steel doors shall meet following specifications:

a) 1 ¾ inch-thick face steel equal to 18 gauge.

b) Hinges reinforced to 7 gauge.

c) Door closure reinforced to 12 gauge.

d) Lock area predrilled and/or reinforced to 10 gauge.

12. A vault door shall not be used to control day access to a facility. To mitigate both security and safety concerns, a vestibule with an access control device may be constructed.

13. Roll-up Door Specifications

a) A roll-up door cannot be treated for acoustics and shall only be located in an area of the SCIF that is designated as a non-discussion area.

b) Roll-up doors shall be 18 gauge steel or greater and shall be secured inside the

SCIF using dead-bolts on both the right and left side of the door.

14. Double Door Specifications

a) One of the doors shall be secured at the top and bottom with deadbolts.

b) An astragal strip shall be attached to one door (could be either the secured or the movable door depending on the inward/outward swing of door assembly) to prevent observation of the SCIF through the cracks between the doors.

c) Each door shall have an independent high-security switch.

F. SCIF Window Criteria

1. Every effort should be made to minimize or eliminate windows in the SCIF, especially on the ground floor.

2. Windows shall be non-opening.

3. Windows shall be protected by security alarms in accordance with Chapter 7 when they are within 18 feet of the ground or an accessible platform.

4. Windows shall provide visual and acoustic protection.

5. Windows shall be treated to provide RF protection when recommended by the CTTA.

6. All windows less than 18 feet above the ground or from the nearest platform affording access to the window (measured from the bottom of the window), shall be protected against forced entry and meet the standard for the perimeter.

G. SCIF Perimeter Penetrations Criteria

1. All penetrations of perimeter walls shall be kept to a minimum.

2. Metallic penetrations may require TEMPEST countermeasures, to include dielectric breaks or grounding, when recommended by the CTTA.

3. Utilities servicing areas other than the SCIF shall not transit the SCIF unless mitigated with AO approval.

4. Electrical Utilities should enter the SCIF at a single point.

5. All utility (power and signal) distribution on the interior of a perimeter wall treated for acoustics or RF shall be surface mounted, contained in a raceway, or an additional wall shall be constructed using furring strips as stand-off from the existing wall assembly.

If the construction of an additional wall is used, gypsum board may be ⅜ inch-thick and need only go to the false ceiling.

6. Installation of additional conduit penetration for future utility expansion is permissible provided the expansion conduit is filled with acoustic fill and capped (end of pipe cover).

7. Vents and Ducts

a) All vents and ducts shall be protected to meet the acoustic requirements of the

SCIF. (See Figure 4, Typical Air (Z) Duct Penetration, for example.)

b) Walls surrounding duct penetrations shall be finished to eliminate any opening between the duct and the wall.

c) All vents or duct openings that penetrate the perimeter walls of a SCIF and exceed

96 square inches shall be protected with permanently affixed bars or grills.

(1) If one dimension of the penetration measures less than six inches, bars or grills are not required.

(2) When metal sound baffles or wave forms are permanently installed and set no farther apart than six inches in one dimension, then bars or grills are not required.

(3) If bars are used, they shall be a minimum of ½ inch diameter steel, welded vertically and horizontally six inches on center; a deviation of ½ inch in vertical and/or horizontal spacing is permissible.

(4) If grilles are used they shall be of:

(a) ¾ inch-mesh, #9 (10 gauge), case-hardened, expanded metal; or

(b) expanded metal diamond mesh, 1-1/2” #10 (1-3/8” by 3” openings, 0.093” thickness, with at least 80% open design) tamperproof; or

(c) welded wire fabric (WWF) 4x4 W2.9xW2.9 (6 gauge smooth steel wire welded vertically and horizontally four inches o.c.).

(5) If bars, grilles, or metal baffles/wave forms are required, an access port shall be installed inside the secure perimeter of the SCIF to allow visual inspection of the bars, grilles, or metal baffles/wave forms. If the area outside the SCIF is controlled (SECRET or equivalent proprietary space), the inspection port may be installed outside the perimeter of the SCIF and be secured with an AO-approved high-security lock. This shall be noted in the FFC.

H. Alarm Response Time Criteria for SCIFs within the U.S.

Response times for Intrusion Detection Systems (IDS) shall meet 32 CFR Parts 2001 and

2004.

a) Closed Storage response time of 15 minutes.

b) Open Storage response time within 15 minutes of the alarm annunciation if the area is covered by SID or a five minute alarm response time if it is not.

I. Secure Working Areas (SWA)

SWAs are accredited facilities used for discussing, handling, and/or processing SCI, but where SCI will not be stored.

1. The SWA shall be controlled at all times by SCI-indoctrinated individuals or secured with a GSA-approved combination lock.

2. The SCIF shall be alarmed in accordance with Chapter 7 with an initial alarm response time of 15 minutes.

3. Access control shall be in accordance with Chapter 8.

4. Perimeter construction shall comply with section 3.C. above.

5. All SCI used in an SWA shall be removed and stored in GSA-approved security containers within a SCIF, a vault, or be destroyed when the SWA is unoccupied.

J. Temporary Secure Working Area (TSWA)

TSWAs are accredited facilities where handling, discussing, and/or processing of SCI is limited to less than 40-hours per month and the accreditation is limited to 12 months or less. Extension requests require a plan to accredit as a SCIF or SWA. Storage of SCI is not permitted within a TSWA.

1. When a TSWA is in use at the SCI level, access shall be limited to SCI- indoctrinated persons.

2. The AO may require an alarm system.

3. No special construction is required.

4. When the TSWA is approved for SCI discussions, sound attenuation specifications of

Chapter 9 shall be met.

5. The AO may require a TSCM evaluation if the facility has not been continuously controlled at the SECRET level.

6. When the TSWA is not in use at the SCI level, the following shall apply:

a) The TSWA shall be secured with a high-security, AO-approved key or combination lock.

b) Access shall be limited to personnel possessing a minimum U.S. SECRET clearance.

Figure 1

Wall A --- Suggested Standard Acoustic Wall Construction

Figure 2

Wall B - Suggested Construction for Expanded Metal

Figure 3

Wall C --- Suggested Construction for Plywood

Figure 4

Typical Perimeter Air (Z) Duct Penetration

Acoustically rated partition (Plan view)

Acoustically lined, thru-wall sheet metal transfer duct

Man-bar at partition if duct opening size exceeds 96 SI

Rev. 04-05

3x x

Access hatch (In bottom of duct)

SECURE SIDE

SECURE SIDE

3x min.

Chapter 4

SCIFs Outside the U.S. and NOT Under COM

Chapter 4. SCIFs Outside the U.S. and NOT Under Chief of Mission (COM)

Authority

A. General

1. Requirements outlined here apply only to SCIFs located outside of the U.S., its territories and possessions that are not under COM authority.

2. The application and effective use of SID may allow AOs to deviate from this guidance at Category II and III facilities.

B. Establishing Construction Criteria Using Threat Ratings

1. The Department of State’s (DoS) Security Environment Threat List (SETL) shall be used in the selection of appropriate construction criteria based on technical threat rating.

2. If the SETL does not have threat information for the city of construction, the SETL threat rating for the closest city within a given country shall apply. When only the capital is noted, it will represent the threat for all SCIF construction within that country.

3. Based on technical threat ratings, building construction has been divided into the following three categories for construction purposes:

Category I - Critical or High Technical Threat, High Vulnerability Buildings

Category II - High Technical Threat, Low Vulnerability Buildings

Category III - Low and Medium Technical Threat

4. Facilities in Category I Areas

a) Open Storage Facilities

(1) Open storage is to be avoided in Category I areas. The head of the IC element shall certify mission essential need and approve on case-by-case basis.

When approved, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel.

(2) SCI shall be contained within approved vaults or Class M or greater modular vaults.

(3) The SCIF shall be alarmed in accordance with Chapter 7.

(4) Access control shall be in accordance with Chapter 8.

(5) An alert system and/or duress alarm is recommended.

(6) Initial alarm response time shall be five minutes.

b) Closed Storage Facilities

(1) The SCIF perimeter shall provide five minutes of forced-entry protection.

(Refer to Wall B or Wall C construction methods.)

(2) The SCIF shall be alarmed in accordance with Chapter 7.

(3) Access control system shall be in accordance with Chapter 8.

(4) SCI shall be stored in GSA-approved containers or in an area that meets vault construction standards.

(5) Initial alarm response time shall be within 15 minutes.

c) Continuous Operation Facilities

(1) An alert system and duress alarm is required.

(2) The capability shall exist for storage of all SCI in GSA-approved security containers or vault.

(3) The emergency plan shall be tested semi-annually.

(4) Perimeter walls shall comply with enhanced wall construction methods in accordance Wall B or C standards.

(5) The SCIF shall be alarmed in accordance with Chapter 7.

(6) Access control shall be in accordance with Chapter 8.

(7) Initial response time shall be five minutes.

d) SWAs

Construction and use of SWAs is not authorized for facilities in Category I areas because of the significant risk to SCI.

e) TSWAs

Construction and use of TSWAs is not authorized for facilities in Category I areas because of the significant risk to SCI.

5. Facilities in Category II and III Areas

a) Open Storage Facilities

(1) Open storage is to be avoided in Category II areas. The head of the IC element shall certify mission essential need and approve on case-by-case basis.

When approved, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel.

(2) In Category III areas, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel.

(3) The SCIF perimeter shall provide five minutes of forced-entry protection.

(Refer to Wall B or Wall C construction methods.)

(4) The SCIF shall be alarmed in accordance with Chapter 7.

(5) Access control shall be in accordance with Chapter 8.

(6) An alert system and/or duress alarm is recommended.

(7) Initial alarm response time shall be five minutes.

b) Closed Storage Facilities

(1) The SCIF perimeter shall provide five minutes of forced-entry protection.

(Refer to Wall B or Wall C construction methods.)

(2) The SCIF must…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .