Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities
Cessna 177 Cardinal · Other Documents
Overview
This document is a technical specification for the construction and management of Sensitive Compartmented Information Facilities (SCIFs) within the Intelligence Community. It outlines the physical and technical security standards necessary to protect sensitive information and ensure compliance with established directives. The document serves as a guideline for the construction, renovation, and operation of SCIFs, detailing requirements for security measures, risk management, and facility accreditation. It is intended for use by personnel involved in the design, construction, and management of SCIFs, ensuring that all facilities meet the necessary security standards to protect sensitive information from unauthorized access and disclosure.
Document
Source
Originally published by www.dni.gov. Sprinkle hosts a reference copy with an added summary, specifications and searchable full text.
Document details
- Type
- Other Documents
- Year
- 2020
- Pages
- 209
- File size
- 7.1 MB
- Publisher
- www.dni.gov
Common. Rarer than 9% of the aircraft models we track.
Most owners only have the POH. Here's the essential set for the Cessna 177 Cardinal.
- Pilot's Operating Handbook / AFM
- Checklist
- Maintenance Manual
- Parts Catalog (IPC)
- Systems & Wiring
- Service Bulletins
- Type Certificate (TCDS)
Cessna 177 Cardinal for sale now
Free — save the 177 Cardinal to your watchlist and track it in one place.
More Cessna 177 Cardinalmanuals & documents
- CESSNA STC SHOULDER HARNESS KITSSupplemental Type Certificate
- Rosen Sunvisor Systems PMM / IPC for Sunvisor Assembly (p/n R1180005-0)Maintenance Manual
- Deutscher Luft- und Raumfahrtkongress 2012Performance Data
- SCHEDULE OF AIRWORTHINESS DIRECTIVESAirworthiness Directives
- Cessna 177 Cardinal Flight Maneuvers ChecklistChecklist
- Pilot's Operating HandbookPilot's Operating Handbook
- Weight & Balance for Cessna 177 CardinalWeight And Balance
If you fly the Cessna 177 Cardinal, you may also be researching these.
In this document
Introduction
The introduction outlines the purpose of the document, which is to provide technical specifications for the construction and management of SCIFs. It emphasizes the importance of adhering to the standards set forth in the Intelligence Community directives to ensure the protection of Sensitive Compartmented Information (SCI).
Risk Management
This section discusses the analytical risk management process, which involves evaluating threats, vulnerabilities, and assets to determine necessary countermeasures for security. It highlights the importance of coordinating security plans with the Accrediting Official (AO) before construction begins.
Construction Security
The construction security section provides guidelines for the physical security measures that must be implemented during the construction of SCIFs. It includes criteria for perimeter wall construction, door and window specifications, and alarm response times.
Access Control Systems
This section details the requirements for access control systems within SCIFs, including the use of identification systems, physical barriers, and monitoring procedures to prevent unauthorized access.
Management and Operations
The management and operations section outlines the responsibilities of personnel in maintaining SCIF security, including documentation requirements, inspections, and emergency plans.
Full document text
Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities VERSION 1.5 IC Tech Spec – for ICD/ICS 705 An Intelligence Community Technical Specification Prepared by the National Counterintelligence and Security Center March 13, 2020 This page intentionally left blank. OFFICE OF THE DIRECT OR OF NATIONAL INTELLIGENCE DIRECT OR OF THE NATIONAL COUNTERINTELLIGENCE AND SECURITY CENTER WASHINGTO N, DC 20511 NCSC 19-686 MEMORANDUM FOR: SUBJECT: REFERENCES: Distribution Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 A. (U) D/NCSC Memo NCSC-19-329, Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.4, 28 Sep 17 (U) B. (U) Technical Specifications, Version 1.4, 28 Sep 17 (U) C. (U) ICD 705, Sensitive Compartmented Information Facilities, 26 May 10 (U) D. (U) ICS 705-01, Physical and Technical Standards for Sensitive Compartmented Information Facilities, 27 Sep 10 (U) E. (U) ICS 705-02, Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information Facilities, 22 Dec 16 (U) This memorandum promulgates Version 1.5 of the Technical Specification for Construction and Management of Sensitive Compartmented Information Facilities to the Intelligence Community, which replaces Version 1.4 (Ref A), effective immediately. The Technical Specifications was designed to be a living document that enables periodic updates to keep up with changing and emerging technology. Based on input from the Intelligence Community (IC) and as a result of a cooperative effort by physical and technical experts from IC elements and our industrial partners, this Version 1.5 of the Technical Specifications has been updated to meet the needs of the community and enhance the standards identified in ICS 705-01, Physical Security Standards for Sensitive Compartmented Information Facilities (Ref C) and ICS 705-02, Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information Facilities (Ref D). Questions may be directed to the National Counterintelligence and Security Center's Special Security Directorate NI-NCSC-SSD-CSG-PTSP-Mailbox@cia.ic.gov. William R. Evanina Date UNCLASSIFIED SUBJECT: Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 ii UNCLASSIFIED Distribution: Secretary of State, Department of State Secretary of the Treasury, Department of the Treasury Secretary of Defense, Department of Defense Attorney General, Department of Justice Secretary of the Interior, Department of the Interior Secretary of Agriculture, Department of Agriculture Secretary of Commerce, Department of Commerce Secretary of Labor, Department of Labor Secretary of Health and Human Services, Department of Health and Human Services Secretary of Housing and Urban Development, Department of Housing and Urban Development Secretary of Transportation, Department of Transportation Secretary of Energy, Department of Energy Secretary of Education, Department of Education Secretary of Veterans Affairs, Department of Veterans Affairs Secretary of Homeland Security, Department of Homeland Security Administrator, Executive Office of the President Administrator, Environmental Protection Agency Director, Office of Management and Budget United States Trade Representative Administrator, Small Business Administration Director, National Drug Control Policy Director, Central Intelligence Agency Administrator, Equal Employment Opportunity Commission Chairman, Federal Communications Commission Chairman, Federal Maritime Commission Chairman, Federal Reserve System Chairman, Federal Trade Commission Administrator, General Services Administration Administrator, National Aeronautics and Space Administration Archivist, National Archives and Records Administration Director, National Science Foundation Chairman, Nuclear Regulatory Commission Director, Office of Government Ethics Chairman, Privacy and Civil Liberties Oversight Board Chairman, Security and Exchange Commission Director, Selective Service System Commissioner, Social Security Administration Administrator, United States Agency for International Development United States Postal Service Chairman, United States International Trade Commission Director, United States Peace Corps UNCLASSIFIED SUBJECT: Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.5 iii UNCLASSIFIED Distribution, cont.: Office of the Chief Administrative Officer Change History iv Change History Rev. # Date Page Changes Approver 1.2 04/23/12 Cover Banner Graphic, Version, Date PTSEWG 1.2 04/23/12 4 Added note to warn users of classification when associating threat information and facility location. PTSEWG 1.2 04/23/12 5 Re-worded approval of CAs to designate the AO as the primary approval authority of Compartmented Areas within SCIFs. PTSEWG 1.2 04/23/12 9-10 Changed “Type X Gypsum” to “wallboard” to remove the standard of fire resistant gypsum and permit use of other wallboard types. PTSEWG 1.2 04/23/12 9-10 Changed references to wall design drawings to “suggested” wall types to enable variety of wall construction techniques to meet the security standards. PTSEWG 1.2 04/23/12 10 Added explanation to glue and screw plywood to ceiling and floor to clarify standard. Stud placement changed to 16 on center to match drawing and correct error. PTSEWG 1.2 04/23/12 11 Added statement to finish wall and paint from true floor to true ceiling in Walls B and C to clarify and equal Type A Wall. PTSEWG 1.2 04/23/12 9-10 Replaced drawings to reflect “suggested” wall construction methods and remove references to “Type X gypsum wallboard”. PTSEWG 1.2 04/23/12 17-19 Replaced drawings to reflect “suggested” wall construction methods and remove references to “Type X
Show full textShow less
gypsum wallboard”. PTSEWG 1.2 04/23/12 56 Updated Federal Information Processing Standards (FIPS) encryption standards and certification to remove a standard that could not be met by commercial alarm systems. PTSEWG 1.2 04/23/12 64 Replaced FIPS 140-2 with Advanced Encryption Standard (AES) to remove a standard that could not be met by commercial alarm systems. PTSEWG Change History v Rev. # Date Page Changes Approver 1.2 04/23/12 TEMPEST Checklist Removed references to “inspectable space” as requested by the TEMPEST Advisory Group (TAG). PTSEWG 1.2 04/23/12 TEMPEST Checklist Removed references to “Red-SCI” information. PTSEWG 1.2 04/23/12 TEMPEST Checklist Removed parenthetical reference to cell phones and Bluetooth. PTSEWG 1.2 04/23/12 CA Checklist Replaced Compartmented Area Checklist to reflect IC standards. PTSEWG 1.2 04/23/12 SCIF Co-Use Request and MOA Form Replaced Co-Use and MOA Form to include “joint-use” statements. PTSEWG 1.3 03/26/15 Cover Banner change, version, date PTSEWG 1.3 03/26/15 B-C Appended “D/NCSC Memorandum” PTSEWG 1.3 03/26/15 D-G “Appended Change History” PTSEWG 1.3 03/26/15 3 Chapter 2.A (2)(a) Added: “NOTE” regarding prefabricated modular SCIFs. PTSEWG 1.3 03/26/15 9 Chapter 3.C Corrected wording to match wall drawings on p.21. PTSEWG 1.3 03/26/15 14 Chapter 3.G (7)(c.4) Correction and addition of guidance on vents and ducts perimeter protection. PTSEWG 1.3 03/26/15 17-19 Reformatted wall types to reflect correct architectural graphics for prescribed materials. PTSEWG 1.3 03/26/15 53 Chapter 7.A (2)(d) Added requirement for HSS switches. PTSEWG 1.3 03/26/15 54 Chapter 7.A (2)(k) Changed to reflect restrictions on dissemination of installation plans. PTSEWG 1.3 03/26/15 54 Chapter 7.A (3)(a.2) Added exception that sensors must be located within SCIF perimeter. PTSEWG 1.3 03/26/15 55 Chapter 7.A (3)(b.7.e) Replaced “Zones” with “IDE sensor points”. PTSEWG 1.3 03/26/15 56 Chapter 7.A (3)(c.1) Added language for approval authority. PTSEWG 1.3 03/26/15 56 Chapter 7.A (3)(c.2) Added language for integrated IDS and Remote Access. PTSEWG 1.3 03/26/15 56-57 Chapter 7.A (3)(c.2) Added system application software requirements. PTSEWG 1.3 03/26/15 58-59 Replaced “access/secure” with “arm/disarm” throughout. PTSEWG Change History vi Rev. # Date Page Changes Approver 1.3 03/26/15 58 Chapter 7.B (2) Added “A record shall be maintained that identifies the person responsible for disarming the system”. PTSEWG 1.3 03/26/15 87 Chapter 12.G (2) Changed Section header to read “Inspections/Reviews, added same where the term “inspection” or “review” used. The responsibility to perform as such was changed from “IC element head” to the AO, or designee. PTSEWG 1.3 03/26/15 SCIF Co-Use Request and MOA Form Appended Co-Use Request and MOA Form PTSEWG 1.4 06/27/17 Cover Banner change, version, date PTSEWG 1.4 06/27/17 i-iii Appended “D/NCSC Memorandum” PTSEWG 1.4 06/27/17 iv-vii “Appended Change History” PTSEWG 1.4 06/27/17 1 Chapter 1.B.2 Added SAPF Language PTSEWG 1.4 06/27/17 12 Chapter 3.E.1.b Added egress device language PTSEWG 1.4 06/27/17 60 Chapter 7.C.1.c Added, “…IAW UL 2050 requirements (60 minutes)” PTSEWG 1.4 06/27/17 71-74 Chapter 10 Revised PTSEWG 1.4 06/27/17 75-76 Chapter 11.B.5 Added sub-bullets to address CNSSI 5002 PTSEWG 1.4 06/27/17 90-91 Chapter 12.L1/2/7 Added clarification language PTSEWG 1.4 06/27/17 91-92 Chapter 12.M.4 Synchronized bullets PTSEWG 1.5 11/13/19 3-4 Chapter 2.A.3.a Added clarification language PTSEWG 1.5 11/13/19 5-6 Chapter 2.C.2 Defined CA Types PTSEWG 1.5 11/13/19 8 Chapter 3. Added Pre-Construction Checklist language PTSEWG 1.5 11/13/19 13-15 Chapter 3.E Expanded SCIF Door Criteria PTSEWG 1.5 11/13/19 30 Chapter 4.E.2 Added reference to Inspectable Materials Checklist PTSEWG Change History vii 1.5 11/13/19 35 Chapter 5.A Added language in Applicability PTSEWG 1.5 11/13/19 46 Chapter 6.A.1.a Added exception language PTSEWG 1.5 11/13/19 74-77 Chapter 10 Changed “CSA” to “AO” where appropriate PTSEWG 1.5 11/13/19 90 Chapter 12.G.8 Added TSCM language to Inspections/Reviews PTSEWG 1.5 11/13/19 95-97 Chapter 12.N/O/P Added CUA instructions PTSEWG 1.5 11/13/19 98 Chapter 13 Updated FFC and added CUA Guide and Cancellation Forms, Inspectable Materials Checklist, Pre- Construction Checklist PTSEWG This page intentionally left blank. viii Table of Contents ix Table of Contents Chapter 1. Introduction……………………………………………………………………… 1 A. Purpose………………………………………………………………………………… 1 B. Applicability…………………………………………………………………………… 1 Chapter 2. Risk Management………………………………………………………………... 3 A. Analytical Risk Management Process………………………………………………… 3 B. Security in Depth (SID)………………………………………………………………. 4 C. Compartmented Area (CA) …………………………………………………………... 5 Chapter 3. Fixed Facility SCIF Construction………………………………………………... 8 A. Personnel…………………………………………………………………………........ 8 B. Construction Security………………………………………………………………….. 9 C. Perimeter Wall Construction Criteria…………………………………………………. 10 D. Floor and Ceiling Construction Criteria……………………………….………….…... 13 E. SCIF Door Criteria………………………………………………………………….… 13 F. SCIF Window Criteria….….....…………………………………………………..…….15 G. SCIF Perimeter Penetrations Criteria…………………………………………………. 15 H. Alarm Response Time Criteria for SCIFs within the U.S. …………………………… 17 I. Secure Working Areas (SWA) ……………………………………………………….. 17 J. Temporary Secure Working Area (TSWA) ………………………………………….. 18 Chapter 4. SCIFs Outside the U.S. and NOT Under Chief of Mission (COM) Authority….. 23 A. General………………………………………………………………………………… 23 B. Establishing Construction Criteria Using Threat Ratings…………………………….. 23 C. Personnel………………………………………………………………………………. 26 D. Construction Security Requirements…………………………………………………. 27 E. Procurement of Construction Materials……………………………………………….. 30 F. Secure Transportation for Construction Material……………………………………… 31 G. Secure Storage of Construction Material……………………………………………… 32 H. Technical Security……………………………………………………………………. 33 I. Interim Accreditations………………………………………………………………… 33 Chapter 5. SCIFs Outside the U.S. and Under Chief of Mission Authority………………… 35 A. Applicability…………………………………………………………………………… 35 B. General Guidelines…………………………………………………………………….. 35 C. Threat Categories……………………………………………………………………… 36 D. Construction Requirements…………………………………………………………… 36 E. Personnel………………………………………………………………………………. 38 F. Construction Security Requirements…………………………………………………. 39 G. Procurement of Construction Materials……………………………………………….. 42 H. Secure Transportation for Construction Material……………………………………… 43 I. Secure Storage of Construction Material……………………………………………… 44 Table of Contents x J. Technical Security…………..…………………………………………………………....44 K. Interim Accreditations………………………………………………………………… 45 Chapter 6. Temporary, Airborne, and Shipboard SCIFs……………………………………. 46 A. Applicability………………………………………………………………………….. 46 B. Ground-Based T-SCIFs………………………………………………………………. 46 C. Permanent and Tactical SCIFS Aboard Aircraft……………………………………... 48 D. Permanent and Tactical SCIFs on Surface or Subsurface Vessels…………………… 50 Chapter 7. Intrusion Detection Systems (IDS) ……………………………………………… 56 A. Specifications and Implementation Requirements…………………………………….. 56 B. IDS Modes of Operation………………………………………………………………. 61 C. Operations and Maintenance of IDS…………………………………………………… 63 D. Installation and Testing of IDS………………………………………………………… 64 Chapter 8. Access Control Systems (ACS) ………………………………………………… 66 A. SCIF Access Control…………………………………………………………………. 66 B. ACS Administration…………………………………………………………………… 67 C. ACS Physical Protection………………………………………………………………. 67 D. ACS Recordkeeping…………………………………………………………………… 67 . E. Using Closed Circuit Television (CCTV) to Supplement ACS……………………….. 68 F. Non-Automated Access Control………………………………………………………. 68 Chapter 9. Acoustic Protection……………………………………………………………… 70 A. Overview………………………………………………………………………………. 70 B. Sound Group Ratings………………………………………………………………….. 70 C. Acoustic Testing……………………………………………………………………… 70 D. Construction Guidance for Acoustic Protection……….……………………………… 71 E. Sound Transmission Mitigations………………………………………………………. 71 Chapter 10. Portable Electronic Devices with Recording Capabilities and Embedded Technologies (PEDs/RCET)………………………………….…………….………………… 74 A. Approved Use of PEDs/RECET in a SCIF…………………………………………… 74 B. Prohibitions……………………………………………………………………………. 75 C. PED/RCET Risk Levels………………………………………………………………. 75 D. Risk Mitigation………………………………………………………………………… 76 Chapter 11. Telecommunications Systems………………………………………………….. 78 A. Applicability…………………………………………………………………………… 78 B. Unclassified Telephone Systems………………………………………………………. 78 C. Unclassified Information Systems…………………………………………………….. 80 D. Using Closed Circuit Television (CCTV) to Monitor the SCIF Entry Point(s) ……… 80 E. Unclassified Wireless Network Technology…………………………………………. 80 F. Environmental Infrastructure Systems………………………………………………… 81 G. Emergency Notification Systems……………………………………………………… 81 Table of Contents xi H. System Access………………………………………………………………………… 82 I. Unclassified Cable Control……………………………………………………………. 82 J. Protected Distribution Systems………………………………………………………… 83 K. References……………………………………………………………………………....83 Chapter 12. Management and Operations…………………………………………………… 86 A. Purpose………………………………………………………………………………… 86 B. SCIF Repository………………………………………………………………………. 86 C. SCIF Management…………………………………………………………….......…... 87 D. SOPs………………………………………….………………………………….....… 88 E.Changes in Security and Accreditation……………………………………………..…. 89 F. General………………………………………………...……………………………… 89 G. Inspections/Reviews…………………………………………………………………… 90 H. Control of Combinations………………………………………………………………. 90 I. De-Accreditation Guidelines…………………………..……………………….……… 91 J. Visitor Access………………………………………………………………………….. 91 K. Maintenance……..………………………………………………….………………… 93 L. IDS and ACS Documentation Requirements……………………………….………….. 93 M. Emergency Plan……………………………………………………………………….. 94 N. SCIF Co-Use and Joint Use……..…………………………………………………….. 95 O. CUA Form and Instructions…..……………………………………………………….. 96 P. CUA Cancellation..…………………………………………………………………….. 97 Chapter 13. Forms and Plans………………………………………………………………… 98 Fixed Facility Checklist TEMPEST Checklist Compartmented Area Checklist Shipboard Checklist Submarine Checklist Aircraft/UAV Checklist SCIF Co-Use/Joint-Use Request SCIF Co-Use/Joint-Use Request Users Guide Cancellation of SCIF Co-Use/Joint-Use Pre-Construction Checklist Construction Security Plan (CSP) Inspectable Materials Checklist xii This page intentionally left blank. Chapter 1 Introduction 1 Chapter 1. Introduction A. Purpose This Intelligence Community (IC) Technical Specification sets forth the physical and technical security specifications and best practices for meeting standards of Intelligence Community Standard (ICS) 705-01 (Physical and Technical Standards for Sensitive Compartmented Information Facilities). When the technical specifications herein are applied to new construction and renovations of Sensitive Compartmented Information Facilities (SCIFs), they shall satisfy the standards outlined in ICS 705-01 to enable uniform and reciprocal use across all IC elements and to assure information sharing to the greatest extent possible. This document is the implementing specification for Intelligence Community Directive (ICD) 705 (Sensitive Compartmented Information Facilities), ICS 705-01, and ICS 705-02 (Standards for Accreditation and Reciprocal Use of Sensitive Compartmented Information Facilities. The specifications contained herein will facilitate the protection of Sensitive Compartmented Information (SCI) against compromising emanations, inadvertent observation and disclosure by unauthorized persons, and the detection of unauthorized entry. B. Applicability IC Elements shall fully implement this standard within 180 days of its signature. 1. SCIFs that have been de-accredited but controlled at the SECRET level (IAW 32 Code of Federal Regulations (CFR) parts 2001 and 2004) for less than one year may be re-accredited. The IC SCIF repository shall indicate that the accreditation was based upon the previous standards. 2. When the technical specifications herein have been applied to new construction, renovations, and operation of Special Access Program Facilities (SAPFs), those facilities shall satisfy the standards outlined in ICD 705 to enable uniform use across all IC elements for accreditation by IC elements as a Sensitive Compartmented Information Facility. a) Accreditation of a SAPF as a SCIF will be based upon a review of all required SCIF construction documentation to ensure all ICD 705 requirements were met in the construction, maintenance, and operation of the SAPF. b) The Accrediting Official (AO) will conduct a review of all SAPF accreditation documentation for compliance with the technical specifications herein. (1) If all required documentation is available and correct, the AO will issue SCIF accreditation. (2) If all required documentation is not available and correct, or waivers have been authorized, the AO is not required to issue SCIF accreditation. Chapter 1 Introduction 2 c) If the facility is to be maintained as a SAPF and co-utilized as a SCIF, the security posture of the facility will be to the highest requirement of the two. (1) The AO may issue a more restrictive accreditation based upon the SCI requirements associated with the new SCIF accreditation. For example, 5 minute response versus 15 minutes, or Closed Storage versus Open Storage. (2) Program indoctrination will be coordinated as part of the co-utilization agreement. Compartmented Areas may be utilized, but no other sub- division of the facility will be permitted. Facilities requiring additional protections are not suitable for co-utilization. 3 Chapter 2 Risk Management Chapter 2. Risk Management A. Analytical Risk Management Process 1. The Accrediting Official (AO) and the Site Security Manager (SSM) should evaluate each proposed SCIF for threats, vulnerabilities, and assets to determine the most efficient countermeasures required for physical and technical security. In some cases, based upon that risk assessment, it may be determined that it is more practical or efficient to mitigate a standard. In other cases, it may be determined that additional security measures should be employed due to a significant risk factor. 2. Security begins when the initial requirement for a SCIF is known. To ensure the integrity of the construction and final accreditation, security plans should be coordinated with the AO before construction plans are designed, materials ordered, or contracts let. a) Security standards shall apply to all proposed SCI facilities and shall be coordinated with the AO for guidance and approval. Location of facility construction and or fabrication does not exclude a facility from security standards and or review and approval by the AO. SCI facilities include but are not limited to fixed facilities, mobile platforms, prefabricated structures, containers, modular applications or other new or emerging applications and technologies that may meet performance standards for use in SCI facility construction. NOTE: Advertised claims by manufactures that their product(s), to include mobile platforms, prefabricated structures, containers and modular structures are built to SCIF standards and can be accredited without modification may not be accurate. AOs are responsible for ensuring security controls spelled out in the ICD/ICS 705 series and this document are implemented to protect the security integrity of the proposed SCIF prior to accreditation. b) Mitigations are verifiable, non-standard methods that shall be approved by the AO to effectively meet the physical/technical security protection level(s) of the standard. While most standards may be effectively mitigated via non-standard construction, additional security countermeasures and/or procedures, some standards are based upon tested and verified equipment (e.g., a combination lock meeting Federal Specification FF-L 2740) chosen because of special attributes and could not be mitigated with non-tested equipment. The AO’s approval is documented to confirm that the mitigation is at least equal to the physical/technical security level of the standard. c) Exceeding a standard, even when based upon risk, requires that a waiver be processed and approved in accordance with ICD 705. 3. The risk management process includes a critical evaluation of threats, vulnerability, and assets to determine the need and value of countermeasures. The process may include the following: a) Threat Analysis. Assess the capabilities, intentions, and opportunity of an adversary to exploit or damage assets or information. For SCI Facilities under Chief of Mission (COM) authority or established on a permanent or temporary 4 Chapter 2 Risk Management basis within or on U.S. diplomatic facilities/compounds, use the Overseas Security Policy Board (OSPB), Security Environment Threat List (SETL) to determine technical threat to a location. When evaluating for TEMPEST, the Certified TEMPEST Technical Authorities (CTTA) shall use the National Security Agency Information Assurance (NSA IA) list as an additional resource for specific technical threat information. NOTE: These threat documents are classified. Associating the threat level or other threat information with the SCIF location (including country, city, etc.) will normally carry the same classification level identified in the threat document. Ensure that SCIF planning documents and discussions that identify threat with the country or SCIF location are protected accordingly. It is critical to identify other occupants of common and adjacent buildings. (However, do not attempt to collect information against U.S. persons in violation of Executive Order (EO) 12333.) In areas where there is a diplomatic presence of high and critical technical threat countries, additional countermeasures may be necessary. b) Vulnerability Analysis. Assess the inherent susceptibility to attack of a procedure, facility, information system, equipment, or policy. c) Probability Analysis. Assess the probability of an adverse action, incident, or attack occurring. d) Consequence Analysis. Assess the consequences of such an action (expressed as a measure of loss, such as cost in dollars, resources, programmatic effect/mission impact, etc.). B. Security in Depth (SID) 1. SID describes the factors that enhance the probability of detection before actual penetration to the SCIF occurs. The existence of a layer or layers of security that offer mitigations for risks may be accepted by the AO. An important factor in determining risk is whether layers of security already exist at the facility. If applied, these layers may, with AO approval, alter construction requirements and extend security alarm response time to the maximum of 15 minutes. Complete documentation of any/all SID measures in place will assist in making risk decisions necessary to render a final standards decision. 2. SID is mandatory for SCIFs located outside the U.S. due to increased threat. 3. The primary means to achieve SID are listed below and are acceptable. SID requires that at least one of the following mitigations is applied: a) Military installations, embassy compounds, U.S. Government (USG) compounds, or contractor compounds with a dedicated response force of U.S. persons. b) Controlled buildings with separate building access controls, alarms, elevator controls, stairwell controls, etc., required to gain access to the buildings or elevators. These controls shall be fully coordinated with a formal agreement or managed by the entity that owns the SCIF. 5 Chapter 2 Risk Management c) Controlled office areas adjacent to or surrounding SCIFs that are protected by alarm equipment installed in accordance with manufacturer’s instructions. These controls shall be fully coordinated with a formal agreement or managed by the entity that owns the SCIF. d) Fenced compounds with access controlled vehicle gate and/or pedestrian gate. e) The AO may develop additional strategies to mitigate risk and increase probability of detection of unauthorized entry. C. Compartmented Area (CA) 1. Definition A CA is an area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled Access Programs. 2. CA Types a) Type I CAs are intended for workstation environments that are used to view and process compartmented information. These areas may be comprised of open bays, open spaces, or a set of rooms with multiple cubicles in an accredited SCIF. Within these areas, compartmented information may be securely viewed and/or processed via an approved computer workstation by authorized personnel. Workstations in these environments may include computers with single or multiple monitors. When monitor positioning alone will not adequately protect the material from unauthorized viewing, i.e., shoulder surfing, polarized privacy screens shall be used. Compartmented data shall never be openly displayed on a monitor that faces a primary door or common work area. In addition to processing compartmented information on approved computer workstations, Type I CAs may also include the use of printers, copiers, and scanners if appropriate procedures for control of hard copy material have been established and approved by the AO. No storage or discussion is authorized, logical and/or physical. b) Type II CAs are areas where discussions of compartmented information may take place. If so equipped and approved, compartmented information may also be viewed and processed. This CA comprises a room, e.g., office or conference room, inside an accredited SCIF where compartmented discussions may be held by authorized personnel. All Type II CAs must meet existing sound transmission class (STC) requirements per ICS 705-1 to ensure that the room or office retains sound within its perimeter. In addition to compartmented discussions, Type II CAs may be used for secure video teleconferencing (SVTC) and related communication conferencing and the use of secure telephones for compartmented discussions. The use of printers, scanners, fax, copiers, and the secure transfer of data to approved removable media require prior approval. No storage is authorized, logical and/or physical. c) Type III: A restricted discussion area used for viewing, processing, printing, copying, storage and control of accountable compartmented information. This CA is 6 Chapter 2 Risk Management intended for storing and retaining compartmented information when accountability and strict control of compartmented program information is required. This includes, but is not limited to: notes, briefs, slides, electronic presentations, analytic papers, removable hard drives, field packs, thumb drives, laptops, personal electronic devices (PEDs) (see Chapter 10) or hand-held devices that store compartmented information. In addition to the storage of compartmented material in a GSA-approved container, Type III CAs may be used for processing compartmented information on approved computer workstations; the use of printers, scanners, and copiers; the secure transfer of data to approved removable media; the use of secure facsimile machines; and the use of secure telephone equipment (STE) for compartmented discussions. All personnel residing within or who have unfettered access to a Type III CA must be formally briefed into all compartments that reside within the Type III CA. Visitors are permitted within Type III areas only when all compartmented information (for which the visitor is not briefed) is stored within containers, out of sight, and no compartmented discussions occur. 3. Requirements a) The CA shall be approved by the AO with the concurrence of the CA Program Manager or designee. The CA Checklist (Chapter 13) shall be used to request approval. b) Any construction or security requirements above those listed herein require prior approval from the element head as described in ICS 705-2. 4. Access Control a) Access control to the CA may be accomplished by visual recognition or mechanical/electronic access control devices. b) Spin-dial combination locks shall not be installed on CA doors. c) Independent alarm systems shall not be installed in a CA. 5. Visual Protection of CA Workstations If compartmented information will be displayed on a computer terminal or group of terminals in an area where everyone is not accessed to the program, the following measures may be applied to reduce the ability of “shoulder surfing” or inadvertent viewing of compartmented information: • Position the computer screen away from doorway/cubicle opening. • Use a polarizing privacy screen. • Use partitions and/or signs. • Existing private offices or rooms may be used but may not be a mandatory requirement. 7 Chapter 2 Risk Management 6. Closed Storage When the storage, processing, and use of compartmented information, product, or deliverables is required, and all information shall be stored while not in use, then all of the following shall apply: a) Access and visual controls identified above shall be the standard safeguard. b) Compartmented information shall be physically stored in a General Services Administration (GSA) approved safe. 7. Open Storage In rare instances when open storage of information is required, the following apply: a) If the parent SCIF is accredited for open storage, a private office with access control on the door is adequate physical security protection. b) If the parent SCIF has been built and accredited for closed storage, then the CA perimeter shall be constructed and accredited to open storage standards. c) The CA AO may approve open or closed storage within the CA. Storage requirements shall be noted in both the CA Fixed Facility Checklist (FFC) and, if appropriate, in a Memorandum of Understanding (MOU). 8. Acoustic and Technical Security a) All TEMPEST, administrative telephone, and technical surveillance countermeasure (TSCM) requirements for the parent SCIF shall apply to the CA and shall be reciprocally accepted. b) When compartmented discussions are required, the following apply: (1) Use existing rooms that have been accredited for SCI discussions. (2) Use administrative procedures to restrict access to the room during conversations. 8 Chapter 3 Fixed Facility SCIF Construction Chapter 3. Fixed Facility SCIF Construction Requirements outlined within this chapter apply to all fixed facility SCIFs. The SCIF Pre- Construction Checklist is found in Chapter 13 and may be completed and sent to the Cognizant Security Authority (CSA) and/or AO as part of the concept approval process. All questions about the checklist content and expected information should be directed to the project CSA/AO. Additional information and requirements for facilities located outside the U.S., its possessions or territories, are found in Chapters 4 and 5. Additional information and requirements for temporary SCIFs are described in Chapter 6. A. Personnel Roles and responsibilities of key SCIF construction personnel are identified in ICS 705-1 and restated here for reference. 1. AO Responsibilities a) Provide security oversight of all aspects of SCIF construction under their security purview. b) Review and approve the design concept, Construction Security Plan (CSP), and final design for each construction project prior to the start of SCIF construction. c) Depending on the magnitude of the project, determine if the Site Security Manager (SSM) performs duties on a full-time, principal basis, or as an additional duty to on-site personnel. d) Accredit SCIFs under their cognizance. e) Prepare waiver requests for the IC element head or designee. f) Provide the timely input of all required SCIF data to the IC SCIF repository. g) Consider SID on USG or USG-sponsored contractor facilities to substitute for standards herein. (SID shall be documented in the CSP and the FFC.) 2. Site Security Managers (SSMs) Responsibilities a) Ensure the requirements herein are implemented and advise the AO of compliance or variances. b) In consultation with the AO, develop a CSP regarding implementation of the standards herein. (This document shall include actions required to document the project from start to finish.) c) Conduct periodic security inspections for the duration of the project to ensure compliance with the CSP. d) Document security violations or deviations from the CSP and notify the AO within 3 business days. e) Ensure that procedures to control site access are implemented. 9 Chapter 3 Fixed Facility SCIF Construction 3. CTTA Responsibilities a) Review SCIF construction or renovation plans to determine if TEMPEST countermeasures are required and recommend solutions. To the maximum extent practicable, TEMPEST mitigation requirements shall be incorporated into the SCIF design. b) Provide the CSA and AO with documented results of review with recommendations. 4. Construction Surveillance Technicians (CSTs) Responsibilities a) Supplement site access controls, implement screening and inspection procedures, as well as monitor construction and personnel, when required by the AO. b) In low and medium technical threat countries, begin surveillance of non-cleared workers at the start of SCIF construction or the installation of major utilities, whichever comes first. c) In high and critical technical threat countries, begin surveillance of non-cleared workers at the start of: construction of public access or administrative areas adjacent to the SCIF; SCIF construction; or the installation of major utilities, whichever comes first. B. Construction Security 1. Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO. 2. Construction plans and all related documents shall be handled and protected in accordance with the CSP. 3. For SCIF renovation projects, barriers shall be installed to segregate construction workers from operational activities and provide protection against unauthorized access and visual observation. Specific guidance shall be contained in the CSP. 4. Periodic security inspections shall be conducted by the SSM or designee for the duration of the project to ensure compliance with construction design and security standards. 5. Construction and design of SCIFs should be performed by U.S. companies using U.S. citizens to reduce risk, but may be performed by U.S. companies using U.S. persons (an individual who has been lawfully admitted for permanent residence as defined in 8 U.S.C. § 1101(a)(20) or who is a protected individual as defined by Title 8 U.S.C. § 1324b (a)(3)). The AO shall ensure mitigations are implemented when using non-U.S. citizens. These mitigations shall be documented in the CSP. 6. All site control measures used shall be documented in the CSP. Among the control measures that may be considered are the following: • Identity verification. • Random searches at site entry and exit points. 10 Chapter 3 Fixed Facility SCIF Construction • Signs at all entry points listing prohibited and restricted items (e.g., cameras, firearms, explosives, drugs, etc.). • Physical security barriers to deny unauthorized access. • Vehicle inspections. C. Perimeter Wall Construction Criteria 1. General a) SCIF perimeters include all walls that outline the SCIF confines, floors, ceilings, doors, windows and penetrations by ductwork, pipes, and conduit. This section describes recommended methods to meet the standards described within ICS 705-1 for SCIF perimeters. b) Perimeter wall construction specifications vary by the type of SCIF, location, use of SID, and discussion requirements. c) Closed storage areas that do not require discussion areas do not have any forced entry or acoustic requirements. d) Open storage facilities without SID require additional protection against forced and surreptitious entry. e) When an existing wall is constructed with substantial material (e.g., brick, concrete, cinderblock, etc.) equal to meet the perimeter wall construction standards, the existing wall may be utilized to satisfy the specification. 2. Closed Storage, Secure Working Area (SWA), Continuous Operation, or Open Storage with SID - Use Wall A - Suggested Standard Acoustic Wall (see construction drawing for details). a) Three layers ⅝ inch-thick gypsum wallboard (GWB), one layer on the uncontrolled side of the SCIF and two on the controlled side of the SCIF, to provide adequate rigidity and acoustic protection (Sound Class 3). b) Wallboard shall be attached to 3 ⅝ inch-wide 16 gauge metal studs or wooden 2 x 4 studs placed no less than 16” on center (o.c.). c) 16 gauge continuous track (top & bottom) w/ anchors at 32” o.c. maximum) – bed in continuous bead of acoustical sealant. d) The interior two layers of wallboard shall be mounted so that the seams do not align (i.e., stagger joints). e) Acoustic fill 3 ½ “ (89mm) sound attenuation material, fastened to prevent sliding down and leaving void at the top. f) The top and bottom of each wall shall be sealed with an acoustic sealant where it meets the slab. 11 Chapter 3 Fixed Facility SCIF Construction g) Fire safe non-shrink grout, or acoustic sealant in all voids above/below track both sides of partition. h) Entire wall assembly shall be finished and painted from true floor to true ceiling. 3. Open Storage without SID -- Use Wall B - Suggested Wall for Expanded Metal or Wall C - Suggested Wall for Plywood. a) Three layers of ⅝ inch-thick GWB, one layer on the uncontrolled side of the SCIF and two on the controlled side of the SCIF to provide adequate rigidity and acoustic protection (Sound Class 3). b) Wallboard shall be attached to 3 ⅝ inch-wide 16 gauge metal studs or wooden 2 x 4 studs placed no less than 16” o.c. c) 16 gauge continuous track (top & bottom) w/ anchors at 32” on center (o.c.) maximum) – bed in continuous bead of acoustical sealant. d) Wall B - Suggested Wall for Expanded Metal (see drawing for Wall B-Suggested Construction for Expanded Metal). (1) Three-quarter inch mesh, # 9 (10 gauge) expanded metal shall be affixed to the interior side of all SCIF perimeter wall studs. (2) Expanded metal shall be spot-welded to the studs every six inches along the length of each vertical stud and at the ceiling and floor. (3) Hardened screws with one inch washers or hardened clips may be used in lieu of welding to fasten metal to the studs. Screws shall be applied every six inches along the length of each vertical stud and at the ceiling and floor. (4) Fastening method shall be noted in the FFC. (5) Entire wall assembly shall be finished and painted from true floor to true ceiling. e) Wall C - Suggested Wall for Plywood (see drawing for Wall C-Suggested Construction for Plywood). (1) Three layers of ⅝ inch-thick GWB, two layers on the uncontrolled side and one layer GWB over minimum ½ ” plywood on the controlled side of the SCIF. NOTE: CTTA recommended countermeasures (foil backed GWB or layer of approved Ultra Radiant R-Foil) shall be installed in accordance with (IAW) best practices for architectural Radio Frequency (RF) shielding. Foil shall be located between the layer of plywood and GWB. (2) 1/2" Plywood affixed 8’ vertical by 4’ horizontal to 16 gauge studs using glue and #10 steel tapping screws at 12 o.c. (3) GWB shall be mounted to plywood with screws avoiding contact with studs to mitigate any possible acoustic flanking path. (4) 16 gauge continuous track (top & bottom) w/ anchors at 32” o.c. maximum) – bed in continuous bead of acoustical sealant. 12 Chapter 3 Fixed Facility SCIF Construction (5) Fire safe non-shrink grout, or acoustic sealant in all voids above/below track both sides of partition. (6) Entire wall assembly shall be finished and painted from true floor to true ceiling. 4. Radio Frequency (RF) Protection for Perimeter Walls a) RF protection shall be installed at the direction of the CTTA when a SCIF utilizes electronic processing and does not provide adequate RF attenuation at the inspectable space boundary. It is recommended for all applications where RF interference from the outside of the SCIF is a concern inside the SCIF. b) Installation of RF protection should be done using either the drawings or Best Practices Guidelines for Architectural Radio Frequency Shielding, prepared by the Technical Requirements Steering Committee under the Center for Security Evaluation. This document is available through the Center for Security Evaluation, Office of the Director of National Intelligence (NCSC/CSE). 5. Vault Construction Criteria GSA-approved modular vaults meeting Federal Specification AA-V-2737 or one of the following construction methods may be used: a) Reinforced Concrete Construction (1) Walls, floor, and ceiling will be a minimum thickness of eight inches of reinforced concrete. (2) The concrete mixture will have a comprehensive strength rating of at least 2,500 pounds per square inch (psi). (3) Reinforcing will be accomplished with steel reinforcing rods, a minimum of ⅝ inches in diameter, positioned centralized in the concrete pour and spaced horizontally and vertically six inches on center; rods will be tied or welded at the intersections. (4) The reinforcing is to be anchored into the ceiling and floor to a minimum depth of one-half the thickness of the adjoining member. b) Steel-Lined Construction Where Unique Structural Circumstances Do Not Permit Construction of a Concrete Vault (1) Construction will use ¼ inch-thick steel alloy-type plates having characteristics of high-yield and high-tensile strength. (2) The steel plates are to be continuously welded to load-bearing steel members of a thickness equal to that of the plates. (3) If the load-bearing steel members are being placed in a continuous floor and ceiling of reinforced concrete, they must be firmly affixed to a depth of one-half the thickness of the floor and ceiling. (4) If floor and/or ceiling construction is less than six inches of reinforced concrete, a steel liner is to be constructed the same as the walls to form the floor 13 Chapter 3 Fixed Facility SCIF Construction and ceiling of the vault. Seams where the steel plates meet horizontally and vertically are to be continuously welded together. All vaults shall be equipped with a GSA-approved Class 5 vault door. D. Floor and Ceiling Construction Criteria 1. Floors and ceilings shall be constructed to meet the same standards for force protection and acoustic protection as walls. 2. All floor and ceiling penetrations shall be kept to a minimum. E. SCIF Door Criteria 1. Door type definitions: a) Primary door: A SCIF perimeter door recognized as the main entrance. b) Secondary door: A SCIF perimeter door employed as both an entry and egress door that is not the Primary door. c) Emergency egress-only door: A SCIF perimeter door employed as an emergency egress door with no entry capability. 2. Primary door criteria: a) There shall be only one Primary door to a SCIF. b) The Primary door shall be equipped with the following: (1) A GSA-approved pedestrian door deadbolt meeting the most current version of Federal Specification FF-L-2890. Previously AO-approved FFL-2740 integrated locking hardware may be used. Additional standalone and flush- mounted dead bolts are prohibited. (2) A combination lock meeting the most current version of Federal Specification FFL- 2740. Previously AO-approved combination lock or deadbolt lock type may be used. (3) An approved access control device (see Chapter 8). May be equipped with a by-pass keyway for use in the event of an access control system failure. (4) Include requirements in E.5 below. 3. Secondary door criteria: a) Secondary doors may be established with AO approval and as required by building code, safety and accessibility requirements, (1) Secondary doors shall: (a) Be equipped with a GSA-approved pedestrian door egress device with deadbolt meeting the most current version of Federal Specification FF-L-2890 for secondary door use. An AO-approved 14 Chapter 3 Fixed Facility SCIF Construction alternate device with similar functionality may be authorized. Additional standalone and flush-mounted deadbolts are prohibited. (b) Have approved access control hardware (see Chapter 8). The access control system must be deactivated when the SCIF is not occupied, or as determined by the AO. (c) Include requirements in E.5 below. 4. Emergency Egress-only doors shall: a) Be installed as required by building code, safety and accessibility requirements. b) Be equipped with GSA-approved pedestrian door emergency egress device with deadbolt configuration meeting the most current version of Federal Specification FF- L-2890 for exit only door use. An AO-approved alternate device with similar functionality and no exterior hardware may be authorized. Additional standalone and flush-mounted deadbolts are prohibited. c) Be alarmed 24/7 and have a local audible annunciator that must be activated if the door is opened. d) Include requirements in E.5 below. 5. Criteria for all SCIF perimeter doors: a) All SCIF perimeter doors shall comply with applicable building code, safety, and accessibility requirements as determined by the Authority Having Jurisdiction. b) Ensure SCIF Standard Operating Procedures (SOP) includes procedures to ensure all doors are secured at end of day. c) All SCIF perimeter pedestrian doors shall be equipped with an automatic, non- hold door-closer which shall be installed internal to the SCIF. d) Door hinge pins that are accessible from outside of the SCIF shall be modified to prevent removal of the door, e.g., welded, set screws, dog bolts, etc. e) SCIF perimeter doors and frame assemblies shall meet acoustic requirements as described in Chapter 9 unless declared a non-discussion area. f) All SCIF perimeter doors shall be alarmed in accordance with Chapter 7. g) SCIF Perimeter doors shall meet TEMPEST requirements per CTTA guidance. h) When practical and permissible, SCIF entry doors should incorporate a vestibule to preclude visual observation and enhance door acoustic protection. 6. SCIF door fabrication and unique criteria: a) Wooden SCIF doors shall be 1 ¾ inch-thick solid wood core (i.e. wood stave, structural composite lumber). b) Steel doors shall meet following specifications: (1) 1 ¾ inch-thick face steel equal to minimum 18-gauge steel. (2) Hinges reinforced to 7-gauge steel and preferably a lift hinge. (3) Door closure installation reinforced to 12-gauge steel. 15 Chapter 3 Fixed Facility SCIF Construction (4) Lock area predrilled and/or reinforced to 10-gauge steel. c) Vault doors shall not be used to control day access to a facility. To mitigate both security and safety concerns, a vestibule with an access control device may be constructed for the purpose of day access to the vault door. d) Roll-up Doors shall be minimum 18-gauge steel and shall be secured inside the SCIF using dead-bolts on both the right and left side of the door and alarmed in accordance with Chapter 7. e) SCIF perimeter Double Door Specifications: (1) The fixed leaf shall be secured at the top and bottom with deadbolts. (2) An astragal shall be attached to one door. (3) Each leaf of the door shall have an independent security alarm contact. f) Adjacent SCIF adjoining doors: (1) Doors that join adjacent SCIFs, not required for emergency egress, shall: (a) Be dead bolted on both sides. (b) Be alarmed on both sides according to chapter 7. (c) Meet acoustic requirements as required. (d) Be covered by AO SOP. g) Other door types shall be addressed on an individual basis as approved by the AO. F. SCIF Window Criteria 1. Every effort should be made to minimize or eliminate windows in the SCIF, especially on the ground floor. 2. Windows shall be non-opening. 3. Windows shall be protected by security alarms in accordance with Chapter 7 when they are within 18 feet of the ground or an accessible platform. 4. Windows shall provide visual and acoustic protection. 5. Windows shall be treated to provide RF protection when recommended by the CTTA. 6. All windows less than 18 feet above the ground or from the nearest platform affording access to the window (measured from the bottom of the window), shall be protected against forced entry and meet the standard for the perimeter. G. SCIF Perimeter Penetrations Criteria 1. All penetrations of perimeter walls shall be kept to a minimum. 2. Metallic penetrations may require TEMPEST countermeasures, to include dielectric breaks or grounding, when recommended by the CTTA. 3. Utilities servicing areas other than the SCIF shall not transit the SCIF unless mitigated with AO approval. This restriction does not apply to secure communication 16 Chapter 3 Fixed Facility SCIF Construction lines required to transit a SCIF to service an adjacent SCIF through a common perimeter surface. 4. Electrical Utilities should enter the SCIF at a single point. 5. All utility (power and signal) distribution on the interior of a perimeter wall treated for acoustics or RF shall be surface mounted, contained in a raceway, or an additional wall shall be constructed using furring strips as stand-off from the existing wall assembly. If the construction of an additional wall is used, gypsum board may be ⅜ inch-thick and need only go to the false ceiling. 6. Installation of additional conduit penetration for future utility expansion is permissible provided the expansion conduit is filled with acoustic fill and capped (end of pipe cover). 7. Vents and Ducts a) All vents and ducts shall be protected to meet the acoustic requirements of the SCIF. (See Figure 4, Typical Air (Z) Duct Penetration, for example.) b) Walls surrounding duct penetrations shall be finished to eliminate any opening between the duct and the wall. c) All vents or duct openings that penetrate the perimeter walls of a SCIF and exceed 96 square inches shall be protected with permanently affixed bars or grills. (1) If one dimension of the penetration measures less than six inches, bars or grills are not required. (2) When metal sound baffles or wave forms are permanently installed and set no farther apart than six inches in one dimension, then bars or grills are not required. (3) If bars are used, they shall be a minimum of ½ inch diameter steel, welded vertically and horizontally six inches on center; a deviation of ½ inch in vertical and/or horizontal spacing is permissible. (4) If grilles are used they shall be of: (a) ¾ inch-mesh, #9 (10 gauge), case-hardened, expanded metal; or (b) expanded metal diamond mesh, 1-1/2” #10 (1-3/8” by 3” openings, 0.093” thickness, with at least 80% open design) tamperproof; or (c) welded wire fabric (WWF) 4x4 W2.9xW2.9 (6 gauge smooth steel wire welded vertically and horizontally four inches o.c.). (5) If bars, grilles, or metal baffles/wave forms are required, an access port shall be installed inside the secure perimeter of the SCIF to allow visual inspection of the bars, grilles, or metal baffles/wave forms. If the area outside the SCIF is controlled (SECRET or equivalent proprietary space), the inspection port may be 17 Chapter 3 Fixed Facility SCIF Construction installed outside the perimeter of the SCIF and be secured with an AO-approved high-security lock. This shall be noted in the FFC. H. Alarm Response Time Criteria for SCIFs within the U.S. Response times for Intrusion Detection Systems (IDS) shall meet 32 CFR Parts 2001 and 2004. a) Closed Storage response time of 15 minutes. b) Open Storage response time within 15 minutes of the alarm annunciation if the area is covered by SID or a five minute alarm response time if it is not. I. Secure Working Areas (SWA) SWAs are accredited facilities used for discussing, handling, and/or processing SCI, but where SCI will not be stored. 1. The SWA shall be controlled at all times by SCI-indoctrinated individuals or secured with a GSA-approved combination lock. 2. The SCIF shall be alarmed in accordance with Chapter 7 with an initial alarm response time of 15 minutes. 3. Access control shall be in accordance with Chapter 8. 4. Perimeter construction shall comply with section 3.C. above. 5. All SCI used in an SWA shall be removed and stored in GSA-approved security containers within a SCIF, a vault, or be destroyed when the SWA is unoccupied. 18 Chapter 3 Fixed Facility SCIF Construction J. Temporary Secure Working Area (TSWA) TSWAs are accredited facilities where handling, discussing, and/or processing of SCI is limited to less than 40-hours per month and the accreditation is limited to 12 months or less. Extension requests require a plan to accredit as a SCIF or SWA. Storage of SCI is not permitted within a TSWA. 1. When a TSWA is in use at the SCI level, access shall be limited to SCI- indoctrinated persons. 2. The AO may require an alarm system. 3. No special construction is required. 4. When the TSWA is approved for SCI discussions, sound attenuation specifications of Chapter 9 shall be met. 5. The AO may require a TSCM evaluation if the facility has not been continuously controlled at the SECRET level. 6. When the TSWA is not in use at the SCI level, the following shall apply: a) The TSWA shall be secured with a high-security, AO-approved key or combination lock. b) Access shall be limited to personnel possessing a minimum U.S. SECRET clearance. 19 Chapter 3 Fixed Facility SCIF Construction Figure 1 Wall A – Suggested Standard Acoustic Wall Construction 20 Chapter 3 Fixed Facility SCIF Construction Figure 2 Wall B - Suggested Construction for Expanded Metal 21 Chapter 3 Fixed Facility SCIF Construction Figure 3 Wall C – Suggested Construction for Plywood 22 Chapter 3 Fixed Facility SCIF Construction Figure 4 SECURE SIDE Acoustically lined, thru-wall sheet metal transfer duct Access hatch (In bottom of duct) Man-bar at partition if duct opening size exceeds 96 SI min. Acoustically rated partition (Plan view) 3x 3x SECURE SIDE x Rev. 04-05 Typical Perimeter Air (Z) Duct Penetration 23 Chapter 4 SCIFs Outside the U.S. and NOT Under COM Chapter 4. SCIFs Outside the U.S. and NOT Under Chief of Mission (COM) Authority A. General 1. Requirements outlined here apply only to SCIFs located outside of the U.S., its territories and possessions that are not under COM authority. 2. The application and effective use of SID may allow AOs to deviate from this guidance at Category II and III facilities. B. Establishing Construction Criteria Using Threat Ratings 1. The Department of State’s (DoS) Security Environment Threat List (SETL) shall be used in the selection of appropriate construction criteria based on technical threat rating. 2. If the SETL does not have threat information for the city of construction, the SETL threat rating for the closest city within a given country shall apply. When only the capital is noted, it will represent the threat for all SCIF construction within that country. 3. Based on technical threat ratings, building construction has been divided into the following three categories for construction purposes: • Category I - Critical or High Technical Threat, High Vulnerability Buildings • Category II - High Technical Threat, Low Vulnerability Buildings • Category III - Low and Medium Technical Threat 4. Facilities in Category I Areas a) Open Storage Facilities (1) Open storage is to be avoided in Category I areas. The head of the IC element shall certify mission essential need and approve on case-by-case basis. When approved, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel. (2) SCI shall be contained within approved vaults or Class M or greater modular vaults. (3) The SCIF shall be alarmed in accordance with Chapter 7. (4) Access control shall be in accordance with Chapter 8. (5) An alert system and/or duress alarm is recommended. (6) Initial alarm response time shall be five minutes. 24 Chapter 4 SCIFs Outside the U.S. and NOT Under COM b) Closed Storage Facilities (1) The SCIF perimeter shall provide five minutes of forced-entry protection. (Refer to Wall B or Wall C construction methods.) (2) The SCIF shall be alarmed in accordance with Chapter 7. (3) Access control system shall be in accordance with Chapter 8. (4) SCI shall be stored in GSA-approved containers or in an area that meets vault construction standards. (5) Initial alarm response time shall be within 15 minutes. c) Continuous Operation Facilities (1) An alert system and duress alarm is required. (2) The capability shall exist for storage of all SCI in GSA-approved security containers or vault. (3) The emergency plan shall be tested semi-annually. (4) Perimeter walls shall comply with enhanced wall construction methods in accordance Wall B or C standards. (5) The SCIF shall be alarmed in accordance with Chapter 7. (6) Access control shall be in accordance with Chapter 8. (7) Initial response time shall be five minutes. d) SWAs Construction and use of SWAs is not authorized for facilities in Category I areas because of the significant risk to SCI. e) TSWAs Construction and use of TSWAs is not authorized for facilities in Category I areas because of the significant risk to SCI. 5. Facilities in Category II and III Areas a) Open Storage Facilities (1) Open storage is to be avoided in Category II areas. The head of the IC element shall certify mission essential need and approve on case-by-case basis. When approved, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel. (2) In Category III areas, open storage should only be allowed when the host facility is manned 24-hours-per-day by a cleared U.S. presence or the SCIF is continuously occupied by U.S. SCI-indoctrinated personnel. (3) The SCIF perimeter shall provide five minutes of forced-entry protection. (Refer to Wall B or Wall C construction methods.) 25 Chapter 4 SCIFs Outside the U.S. and NOT Under COM (4) The SCIF shall be alarmed in accordance with Chapter 7. (5) Access control shall be in accordance with Chapter 8. (6) An alert system and/or duress alarm is recommended. (7) Initial alarm response time shall be five minutes. b) Closed Storage Facilities (1) The SCIF perimeter shall provide five minutes of forced-entry protection. (Refer to Wall B or Wall C construction methods.) (2) The SCIF must be alarmed in accordance with Chapter 7. (3) Access control system shall be in accordance with Chapter 8. (4) SCI shall be stored in GSA-approved containers. (5) Initial alarm response time shall be within 15 minutes. c) Continuous Operation Facilities (1) Wall A - Standard wall construction shall be utilized. (2) The SCIF shall be alarmed in accordance with Chapter 7. (3) Access control shall be in accordance with Chapter 8. (4) Initial response time shall be five minutes. (5) An alert system and/or duress alarm is recommended. (6) The capability shall exist for storage of all SCI in GSA-approved security containers. (7) The emergency plan shall be tested semi-annually. d) SWAs (1) Perimeter walls shall comply with standard Wall A construction. (2) The SCIF shall be alarmed in accordance with Chapter 7. (3) Access control shall be in accordance with Chapter 8. (4) Initial alarm response time shall be within 15 minutes. (5) The SWA shall be controlled at all times by SCI-indoctrinated individuals or secured with a GSA-approved combination lock. (6) An alert system and/or duress alarm is recommended. (7) All SCI used in an SWA shall be removed and stored in GSA-approved security containers within a SCIF or be destroyed. (8) The emergency plan shall be tested semi-annually. e) TSWAs (1) No special construction is required. (2) The AO may require an alarm system. 26 Chapter 4 SCIFs Outside the U.S. and NOT Under COM (3) When the TSWA is approved for SCI discussions, sound attenuation specifications of Chapter 9 shall be met. (4) When a TSWA is in use at the SCI level, access shall be limited to SCI- indoctrinated persons. (5) The AO may require a TSCM evaluation if the facility has not been continuously controlled at the SECRET level. (6) When a TSWA is not in use at the SCI level, the following shall apply: (a) The TSWA shall be secured with a high security, AO-approved key or combination lock. (b) Access shall be limited to personnel possessing a U.S. SECRET clearance. C. Personnel 1. SSM Responsibilities a) Ensures the security integrity of the construction site (hereafter referred to as the “site”). b) Develops and implements a CSP. c) Ensures that the SSM shall have 24-hour unrestricted access to the site (or alternatives shall be stated in CSP). d) Conducts periodic security inspections for the duration of the project to ensure compliance with the CSP. e) Documents security violations or deviations from the CSP and notifies the AO. f) Maintains a list of all workers used on the project; this list shall become part of the facility accreditation files. g) Implements procedures to deny unauthorized site access. h) Works with the construction firm(s) to ensure security of the construction site and compliance with the requirements set forth in this document. i) Notifies the AO if any construction requirements cannot be met. 2. CST Requirements and Responsibilities a) Possesses U. S. TOP SECRET clearances. b) Is specially trained in surveillance and the construction trade to deter technical penetrations and thwart implanted technical collection devices. c) Supplements site access controls, implements screening and inspection procedures, and, when required by the CSP, monitors construction and personnel. d) Is not required when U.S. TOP SECRET-cleared contractors are used e) In Category III countries, must do the following: 27 Chapter 4 SCIFs Outside the U.S. and NOT Under COM (1) Shall begin surveillance of non-cleared workers at the start of SCIF construction or the installation of major utilities, whichever comes first. (2) Upon completion of all work, shall clear and secure the areas for which they are responsible prior to turning control over to the cleared American guards (CAGs). f) In Category I and II countries, must do the following: (1) Shall begin surveillance of non-cleared workers at the start of construction of public access or administrative areas adjacent to the SCIF, SCIF construction, or the installation of major utilities, whichever comes first. (2) Upon completion of all work, shall clear and secure the areas for which the CST is responsible prior to turning over control to the CAGs. g) On U.S. military installations, when the AO considers the risk acceptable, alternative countermeasures may be substituted for the use of a CST as prescribed in the CSP. 3. CAG Requirements and Responsibilities a) Possesses a U.S. SECRET clearance (TOP SECRET required under COM authority) b) Performs access-control functions at all vehicle and pedestrian entrances to the site except as otherwise noted in the CSP. (1) Screens all non-cleared workers, vehicles, and equipment entering or exiting the site. (2) Denies introduction of prohibited materials, such as explosives, weapons, electronic devices, or other items as specified by the AO or designee. (3) Conducts random inspections of site areas to ensure no prohibited materials have been brought on to the site. (All suspicious materials or incidents shall be brought to the attention of the SSM or CST.) D. Construction Security Requirements 1. Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO. 2. Construction plans and all related documents shall be handled and protected in accordance with the CSP. 3. For SCIF renovation projects, barriers shall be installed to segregate construction workers from operational activities. These barriers will provide protection against unauthorized access and visual observation. Specific guidance shall be contained in the CSP. 4. When expanding existing SCIF space into areas not controlled at the SECRET level, maximum demolition of the new SCIF area is required. 28 Chapter 4 SCIFs Outside the U.S. and NOT Under COM 5. For areas controlled at the SECRET level, or when performing renovations inside existing SCIF space, maximum demolition is not required. 6. All requirements for demolition shall be documented in the CSP. 7. Citizenship and Clearance Requirements for SCIF Construction Personnel a) Use of workers from countries identified in the SETL as “critical technical threat level” or listed on the DoS Prohibited Countries Matrix is prohibited. b) General construction of SCIFs shall be performed using U.S. citizens and U.S. firms. c) SCIF finish work (work that includes closing up wall structures; installing, floating, taping and sealing wallboards; installing trim, chair rail, molding, and floorboards; painting; etc.) in Category III countries shall be accomplished by SECRET-cleared, U.S. personnel. d) SCIF finish work (work that includes closing up wall structures; installing, floating, taping and sealing wallboards; installing trim, chair rail, molding, and floorboards; painting; etc.) in Category I and II countries shall be accomplished by TOP SECRET-cleared, U.S. personnel. e) On military facilities, the AO may authorize foreign national citizens or firms to perform general construction of SCIFs. In this situation, the SSM shall prescribe, with AO approval, mitigating strategies to counter security and counterintelligence threats. f) All non-cleared construction personnel shall provide the SSM with biographical data (full name, current address, Social Security Number (SSN), date and place of birth (DPOB), proof of citizenship, etc.), and fingerprint cards as allowed by local laws prior to the start of construction/renovation. (1) Two forms of I-9 identification are required to verify U.S. persons. (2) Whenever host nation agreements or Status of Forces Agreements make this information not available, it shall be addressed in the CSP. g) When non-U.S. citizens are authorized by the AO: (1) The SSM shall conduct checks of criminal and subversive files, local, national, and host country agency files, through liaison channels and consistent with host country laws. (2) Checks shall be conducted of CIA indices through the country’s Director of National Intelligence (DNI) representative and appropriate in-theater U.S. military authorities. h) Access to sites shall be denied or withdrawn if adverse security, Counterintelligence (CI), or criminal activity is revealed. The SSM shall notify the AO when access to the site is denied or withdrawn. i) For new facilities, the following apply: (1) Non-cleared workers, monitored by CSTs, may perform the installation of major utilities and feeder lines. 29 Chapter 4 SCIFs Outside the U.S. and NOT Under COM (2) Installation shall be observed at perimeter entry points and when any trenches are being filled. (3) The number of CSTs shall be determined by the size of the project (square footage and project scope) as outlined in the CSP. j) For existing facilities, the following apply: (1) Non-cleared workers, monitored by CSTs or cleared escorts, may perform maximum demolition and debris removal. (2) TOP SECRET-cleared workers shall be used to renovate or construct SCIF space. (3) SECRET-cleared individuals may perform the work when escorted by TOP SECRET-cleared personnel. (4) SCI-indoctrinated escorts are not required when the existing SCIF has been sanitized or a barrier has been constructed to separate the operational areas from the areas identified for construction. k) Prior to initial access to the site, all construction personnel shall receive a security briefing by the SSM or designee on the security procedures to be followed. l) If a construction worker leaves the project under unusual circumstances, the SSM shall document the occurrence and notify the AO. The AO shall review for CI concerns. m) The SSM may require cleared escorts or CSTs for non-cleared workers performing work exterior to the SCIF that may affect SCIF security. n) The ratio of escort personnel to construction personnel shall be determined by the SSM on a case-by-case basis and documented in the CSP. Prior to assuming escort duties, all escorts shall receive a briefing regarding their responsibilities. 8. Access Control of Construction Sites a) Access control to the construction site and the use of badges are required. b) Guards are required for SCIF construction outside the U.S. c) All site control measures used shall be documented in the CSP. The following are site control measures that should be considered: • Identity verification. • Random searches at site entry and exit points. • Signs, in English and other appropriate languages, at all entry points listing prohibited and restricted items (e.g., cameras, firearms, explosives, drugs, etc.). • Physical security barriers to deny unauthorized access. • Vehicle inspections. 30 Chapter 4 SCIFs Outside the U.S. and NOT Under COM d) Guards (1) Local guards, supervised by CAGs and using procedures established by the AO and documented in the CSP, may search all non-cleared personnel, bags, toolboxes, packages, etc., each time they enter or exit the site. (2) In Category I countries, CAGs shall be assigned to protect the site and surrounding area as defined in the CSP. (3) For existing SCIFs, TOP SECRET/SCI-indoctrinated guards are not required to control access to the site or secure storage area (SSA) provided that TOP SECRET/SCI-indoctrinated personnel are present on a 24-hour basis and prescribed post security resources are in place. (4) Use of non-cleared U.S. guards or non-U.S. guards to control access to the site or SSA requires the prior approval of the AO. A SECRET-cleared, U.S. citizen must supervise any non-cleared or non-U.S. guards. Non-cleared or non- U.S. guards shall not have unescorted access to the site. E. Procurement of Construction Materials 1. General Standards. These standards apply to construction materials (hereafter referred to as “materials”) used in SCIF construction outside the U.S. These standards do not apply to installations on a roof contiguous to the SCIF provided there is no SCIF penetration. a) Procurements shall be in accordance with Federal Acquisition Regulations. b) In exceptional circumstances, SSMs may deviate from procurement standards with a waiver; such deviation shall be noted in the CSP. c) For building construction projects in Category III countries, cleared U.S. citizens may randomly select up to 35% of building materials from non-specific general construction materials for SCIF construction. Random selection may exceed 35% only if materials can be individually inspected. d) For building construction projects in Category I and II countries, cleared U.S. citizens may randomly select up to 25% of building materials from non-specific general construction materials for SCIF construction. Random selection may exceed 25% only if materials can be individually inspected. e) Procurement of materials from host or third party countries identified in the SETL as critical for technical intelligence or listed in the DoS Prohibited Countries Matrix is prohibited. f) All such materials must be selected immediately upon receipt of the shipment and transported to secure storage. 2. Inspectable (e.g., See Chapter 13 Inspectable Materials Checklist) Materials a) Inspectable materials may be procured from U.S. suppliers without security restrictions. 31 Chapter 4 SCIFs Outside the U.S. and NOT Under COM b) The purchase of inspectable materials from host or third party countries requires advanced approval from the AO. c) Procurement of materials from host or third party countries identified in the SETL as critical for technical intelligence or listed in the DoS Prohibited Countries Matrix is prohibited. d) All inspectable materials procured in host and third party countries, or shipped to site in unsecured manner, shall be inspected using an AO-approved method as outlined in the CSP and then moved to an SSA. e) Random selection of all inspectable material selected from stock stored outside of the SSA shall be inspected using AO-approved methods outlined in the CSP prior to use in SCIF construction. 3. Non-Inspectable Materials a) Non-inspectable materials may be procured from U.S. suppliers or other AO- approved channels with subsequent secure transportation to the SSA at the construction site. b) Non-inspectable materials may be procured in a host or third party country if randomly selected by U.S. citizens with a security clearance level approved by the AO. c) Materials shall be randomly chosen from available suppliers (typically three or more) without advance notice to, or referral from, the selected supplier and without reference of the intended use of material in a SCIF. d) Selections shall be made from available shelf stock and transported securely to an SSA. e) Procurement officials should be circumspect about continually purchasing non- inspectable materials from the same local suppliers, and thereby establishing a pattern that could be reasonably discernible by hostile intelligence services, foreign national staff, and suppliers. F. Secure Transportation for Construction Material 1. Inspectable Materials a) Secure transportation of inspectable materials is not required, but materials shall be inspected using procedures approved by the AO prior to use. b) Once inspected, all inspectable materials shall be stored in a SSA prior to use. c) If securely procured, securely shipped, and stored in a secure environment, inspectable materials may be utilized within the SCIF without inspection. 2. Non-Inspectable Materials a) Non-inspectable materials include inspectable materials when the site does not possess the capability to inspect them by AO-approved means. 32 Chapter 4 SCIFs Outside the U.S. and NOT Under COM b) Non-inspectable materials shall be securely procured and shipped to site by secure transportation from the U.S., a secure logistics facility, or low threat third party country using one of the following secure methods: (1) Securely packaged or containerized and under the 24-hour control of an approved courier or escort office. (Escorted shipments shall be considered compromised if physical custody or direct visual observation is lost by the escort officer during transit. Non-inspectable materials that are confirmed or suspected of compromise shall not be used in a SCIF.) (2) Securely shipped using approved transit security technical safeguards capable of detecting evidence of tampering or compromise. (An unescorted container protected by technical means (“trapped”) is considered compromised if evidence of tampering of the protective technology is discovered, or if an unacceptable deviation from the approved transit security plan occurs. Non-inspectable materials that are confirmed or suspected of compromise shall not be used in a SCIF.). (3) Non-inspectable materials shall be shipped using the following surface and air carriers in order of preference: • U.S. Military • U.S. Flag Carriers • Foreign Flag Carriers G. Secure Storage of Construction Material 1. A SSA shall be established and maintained for the secure storage of all SCIF construction material and equipment. An SSA is characterized by true floor to true ceiling, slab-to-slab construction of some substantial material, and a solid wood-core or steel-clad door equipped with an AO-approved security lock. 2. All inspected and securely shipped materials shall be placed in the SSA upon arrival and stored there until required for installation. 3. Alternative SSAs may include the following: a) A shipping container located within a secure perimeter that is locked, alarmed, and monitored. b) A room or outside location enclosed by a secure perimeter that is under direct observation by a SECRET-cleared U.S. citizen. 4. The SSA shall be under the control of CAGs or other U.S. personnel holding at least U.S. SECRET clearances. 5. Supplemental security requirements for SSAs shall be set forth in the CSP and may vary depending on the location and/or threat to the construction site. 33 Chapter 4 SCIFs Outside the U.S. and NOT Under COM H. Technical Security 1. TEMPEST countermeasures shall be pre-engineered into the construction of the SCIF. 2. In Category I countries, a TSCM inspection shall be required for new SCIF construction or for significant renovations (50% or more of SCIF replacement cost). 3. In Category II and III countries, a TSCM inspection may be required by the AO for new SCIF construction or significant renovations (50% or more of SCIF replacement cost). 4. A TSCM inspection shall be required if uncontrolled space is converted (maximum demolition) to new SCIF space. 5. When a TSCM inspection is not conducted, a mitigation strategy based on a physical security inspection that identifies preventative and corrective countermeasures shall be developed to address any technical security concerns. I. Interim Accreditations 1. Upon completion of a successful inspection, the respective agency’s AO may issue an Interim Accreditation pending receipt of required documentation. 2. If documentation is complete, AOs may issue an Interim Accreditation pending the final inspection. 34 Chapter 4 SCIFs Outside the U.S. and NOT Under COM This page intentionally left blank. 35 Chapter 5 SCIFs Outside the U.S. and Under COM Chapter 5. SCIFs Outside the U.S. and Under Chief of Mission Authority A. Applicability 1. This portion applies to the construction of SCIFs located overseas and that are on any compound that falls under the DoS COM authority or created to support any Tenant Agency that falls under COM authority. 2. The creation of new SCIF space at facilities that fall under COM authority is governed by both ICDs and Overseas Security Policy Board (OSPB) standards published as 12 Foreign Affairs Handbook-6 (12 FAH-6). If there is a conflict between the standards, the more stringent shall apply. 3. For SCIFs constructed in new facilities (new compound or new office building under COM authority), the proponent activity shall coordinate specific requirements for the proposed SCIF with the DoS/Overseas Buildings Operations (OBO). 4. For SCIFs constructed in existing facilities under COM authority, the project proponent activity must coordinate SCIF requirements with DoS/Bureau of Diplomatic Security (DS), the affected Embassy or Consulate (through the Regional Security Officer (RSO) and General Services Officer (GSO)), and DoS/OBO. 5. Upon an upgrade in the SETL Technical Threat rating for a facility under COM authority, the tenant agency in concert with the RSO, shall conduct a survey for OSPB compliance to the new technical threat requirements, and document any compliance issues accordingly. Upgrade requirements shall be coordinated through the RSO, GSO, and DoS/OBO and DS. 6. Temporary SCIFs may only be authorized by exception for facilities under COM authority. The AO of the tenant agency shall notify both the RSO and the DoS AO of the requirement and the expected duration of these facilities. Prior to accreditation, the tenant agency AO must coordinate with the DoS AO. B. General Guidelines 1. SCIFs located under COM authority outside the U.S. are located within the CAA. 2. Prior to initiating any SCIF implementation process for upgrade or new construction in an existing office building, the tenant agency CSA shall do the following: a) Obtain concurrence from the Post‘s Counterintelligence Working Group (CIWG). b) Obtain written approval from the COM. c) Notify the DoS AO of CWIG and COM approvals. d) Coordinate OSPB preliminary survey with the post RSO/Engineering Services Office (ESO) if space is not core CAA. 3. A Preliminary Survey shall be developed by the RSO/ESO and submitted to DoS/DS for review and approval prior to awarding a construction contract. A CSP shall then be developed by the tenant and forwarded to DoS/OBO for processing. 36 Chapter 5 SCIFs Outside the U.S. and Under COM 4. All SCIF design, construction, or renovation shall be in compliance with OSPB standards for facilities under COM authority. 5. Any waivers that are granted for a SCIF by a waiver authority that would result in non-compliance with OSPB standards shall require an exception to OSPB standards from DoS/DS. 6. Written approval of the request for an exception to OSPB standards must be received prior to the commencement of any construction projects. 7. Upon completion of construction, the tenant agency AO will accredit the SCIF for SCI operations. C. Threat Categories 1. The DoS SETL shall be used in the selection of appropriate construction criteria. Based on technical threat ratings, building construction has been divided into three categories for construction purposes: • Category I - Critical or High Technical Threat, High Vulnerability Buildings • Category II - High Technical Threat, Low Vulnerability Buildings • Category III - Low and Medium Technical Threat 2. High and Low Vulnerability Buildings will be determined in accordance with the definitions in the OSPB standards. 3. SCIF design and construction shall comply with the building codes utilized by DoS/OBO. 4. SCIF construction projects are subject to the DoS Construction Security Certification requirements stipulated in Section 160 (a), Public Law 100-204, as amended. Construction activities may not commence until the required certification has been obtained from DoS. 5. SCIF construction projects are subject to permit requirements established by DoS/OBO. 6. Open storage in Category I and II areas is to be avoided. The CSA shall certify mission-essential need and approve on a case-by-case basis. 7. Open storage shall only be allowed for Category III posts when the host facility is manned 24-hours per day by a cleared U.S. presence (i.e., Marine Security Guard). 8. Open storage of SCI material is not authorized in lock-and-leave facilities (i.e., no Marine Security Guard). D. Construction Requirements 1. Perimeter Wall Construction (all facilities regardless of type or location). 37 Chapter 5 SCIFs Outside the U.S. and Under COM a) Perimeter walls shall comply with enhanced wall construction (See drawings for Walls B and C.) b) Perimeter shall meet acoustic protection standards unless designated as a non- discussion area. 2. All SCIFs must be alarmed in accordance with Chapter 7. 3. Initial alarm response times shall be within 15 minutes for closed storage and five minutes for open storage. 4. Access control systems shall be in accordance with Chapter 8. 5. SCI shall be stored in GSA-approved containers. 6. An alert system and/or duress alarm is recommended. 7. Continuous Operation Facilities a) An alert system and/or duress alarm is recommended. b) The capability shall exist for storage of all SCI in GSA-approved security containers. c) The emergency plan shall be tested semi-annually. d) The SCIF shall be alarmed in accordance with Chapter 7. e) Access control shall be in accordance with Chapter 8. f) Initial response time shall be five minutes. 8. TSWAs a) When a TSWA is in use at the SCI level, the following apply: (1) Unescorted access shall be limited to SCI-indoctrinated persons. (2) The AO may require an alarm system. (3) No special construction is required. (4) When the TSWA is approved for SCI discussions the following apply: (a) Sound attenuation specifications of Chapter 9 shall be met. (b) The AO may require a TSCM evaluation if the facility has not been continuously controlled at the SECRET level. b) When the TSWA is not in use at the SCI level, the following shall apply: (1) The TSWA shall be secured with a DoS/DS-approved key or combination lock. (2) Unescorted access shall be limited to personnel possessing a U.S. SECRET clearance. 9. SWA a) Initial alarm response times shall be within 15 minutes. 38 Chapter 5 SCIFs Outside the U.S. and Under COM b) The SWA shall be controlled at all times by SCI-indoctrinated individuals or secured with a GSA-approved combination lock. c) The SWA shall be alarmed in accordance with Chapter 7. d) Access control shall be in accordance with Chapter 8. e) Perimeter walls shall comply with standard Wall A. f) An alert system and/or duress alarm is recommended. g) All SCI used in a SWA shall be removed and stored in GSA-approved security containers within a SCIF or be destroyed. h) There shall be an emergency plan that is tested semi-annually. E. Personnel 1. SSM Requirements and Responsibilities a) Possesses a U.S. TOP SECRET clearance. b) Ensures the security integrity of the construction site. c) Develops and implements a CSP. d) Shall have 24-hour unrestricted access to the site (or alternatives shall be stated in CSP). e) Conducts periodic security inspections for the duration of the project to ensure compliance with the CSP. f) Documents security violations or deviations from the CSP and notifies the RSO and the tenant AO. g) Maintains a list of all workers utilized on the project; this list shall become part of the facility accreditation files. h) Implements procedures to deny unauthorized site access. i) Works with the construction firm(s) to ensure security of the construction site and compliance with the requirements set forth in this document. j) Notifies the RSO and tenant AO if any construction requirement cannot be met. 2. CST Requirements and Responsibilities a) Possesses a TOP SECRET clearance. b) Is specially trained in surveillance and the construction trade to deter technical penetrations and to detect implanted technical collection devices. c) Supplements site access controls, implements screening and inspection procedures, and when required by the CSP, monitors construction and personnel. d) Is not required when contractors who are U.S. citizens with U.S. TOP SECRET clearances are used. 39 Chapter 5 SCIFs Outside the U.S. and Under COM e) In Category III countries the following shall apply: (1) The CST shall begin surveillance of non-cleared workers at the start of SCIF construction. (2) Upon completion of all work, the CST shall clear and secure the areas for which they are responsible prior to turning control over to the CAGs. f) In Category I and II countries the following shall apply: (1) The CST shall begin surveillance of non-cleared workers at the start of construction of public access or administrative areas adjacent to the SCIF, or SCIF construction, whichever comes first. (2) Upon completion of all work, the CST shall clear and secure the areas for which the CST is responsible prior to turning over control to the CAGs. 3. CAG Requirements and Responsibilities a) Possesses a U.S. TOP SECRET clearance. b) Performs access control functions at all vehicle and pedestrian entrances to the site except as otherwise noted in the CSP. (1) Screens all non-cleared workers, vehicles, and equipment entering or exiting the site. (2) Uses walk-through and/or hand-held metal detectors or other means approved by the RSO or designee to deny introduction of prohibited materials such as explosives, weapons, electronic devices, or other items as specified by the RSO or designee. (3) Conducts random inspections of site areas to ensure no prohibited materials have been brought on to the site. All suspicious materials or incidents shall be brought to the attention of the SSM. c) In Category III countries, CAGs shall be assigned to protect the site and surrounding area at the start of construction of the SCIF or commencement of operations of the SSA. d) In Category I and II countries, CAGs shall be assigned to protect the site and surrounding area at the start of construction of the SCIF, areas adjacent to the SCIF, or commencement of operations of the SSA. e) For existing SCIFs, TOP SECRET/SCI-indoctrinated U.S. citizen guards are not required to control access to the site or SSA provided the following apply: (1) TOP SECRET/SCI-indoctrinated U.S. citizens are present on a 24-hour basis in the SCIF or the SCIF can be properly secured and alarmed. (2) Prescribed post security resources are in place to monitor the SSA. F. Construction Security Requirements 40 Chapter 5 SCIFs Outside the U.S. and Under COM 1. Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by DoS/DS and DoS/OBO and the tenant AO. 2. Construction plans and all related documents shall be handled and protected in accordance with the CSP. 3. For SCIF renovation projects, barriers shall be installed to segregate construction workers from operational activities. These barriers will provide protection against unauthorized access and visual observation. Specific guidance shall be contained in the CSP. 4. When expanding existing SCIF space into areas not controlled at the SECRET level, maximum demolition of the new SCIF area is required. 5. For areas controlled at the SECRET level that meet OSPB pre-conditions, or when performing renovations inside existing SCIF space, maximum demolition is not required. 6. All requirements for demolition shall be documented in the CSP. 7. Periodic security inspections shall be conducted by the SSM or designee for the duration of the project to ensure compliance with construction design and security standards. 8. Citizenship and Clearance Requirements for SCIF Construction Personnel a) Use of workers from countries identified as critical for Technical or Human Intelligence threat, or listed on the DoS Prohibited Countries Matrix, is prohibited. b) General construction and finish work is defined by OSPB standards. c) General construction of SCIFs shall be performed using U.S. citizens and U.S. firms. Use of foreign national citizens or firms to perform general construction of SCIFs may be authorized in accordance with OSPB standards. In this situation, the CSP shall prescribe mitigating strategies to counter security and counterintelligence threats. d) SCIF finish work shall be accomplished by appropriately cleared personnel as directed by OSPB standards for CAA construction. e) All non-cleared construction personnel shall provide the SSM with biographical data (full name, current address, SSN, DPOB, proof of citizenship, etc.), and fingerprint cards as allowed by local laws prior to the start of construction/renovation. f) Two forms of I-9 identification are required to verify U.S. persons. g) Whenever host nation agreements make this information not available, it shall be addressed in the CSP. h) When non-U.S. citizens are authorized, the following shall apply: (1) The SSM shall conduct, through liaison channels, checks of criminal and subversive files, local and national; and host country agencies, consistent with host country laws. (2) Checks shall also be conducted of CIA indices through the country’s DNI representative and appropriate in-theater U.S. military authorities. 41 Chapter 5 SCIFs Outside the U.S. and Under COM (3) Access to sites shall be denied or withdrawn if adverse security, CI, or criminal activity is revealed. The SSM shall notify the AO and RSO when access to the site is denied or withdrawn. (4) For existing facilities, the following apply: (a) Non-cleared workers monitored by CSTs may perform maximum demolition for conversion of non-CAA to SCIF. Debris removal by non- cleared workers must be monitored at a minimum by cleared U. S. citizen escorts. (b) TOP SECRET-cleared U.S. citizens must perform maximum demolition within, or penetrating the perimeter of, an existing SCIF. (c)TOP SECRET-cleared U.S. citizens shall be used to renovate SCIF space. (d) SECRET-cleared individuals may perform the work when escorted by TOP SECRET-cleared U.S. citizens. (e) SCI-indoctrinated escorts are not required when the existing SCIF has been sanitized or a barrier has been constructed to separate the operational areas from the areas identified for construction. i) Prior to initial access to the site, all construction personnel shall receive a security briefing by the SSM or designee on the security procedures to be followed. j) If a construction worker leaves the project under unusual circumstances, the SSM shall document the occurrence and notify the RSO and tenant AO. The RSO shall review for CI concerns. k) The SSM may require cleared escorts or CSTs for non-cleared workers performing work exterior to the SCIF that may affect SCIF security. l) The ratio of escort personnel to construction personnel shall be determined by the SSM on a case-by-case basis and documented in the CSP. Prior to assuming escort duties, all escorts shall receive a briefing regarding their responsibilities. 9. Access Control of Construction Sites a) Access control to the construction site and the use of badges are required. b) Guards are required for SCIF construction outside the U.S. c) All site control measures used shall be documented in the CSP. d) The following site control measures should be considered: (1) Identity verification. (2) Random searches at site entry and exit points. (3) Signs, in English and other appropriate languages, at all entry points listing prohibited and restricted items (e.g., cameras, firearms, explosives, drugs, etc.). (4) Physical security barriers to deny unauthorized access. (5) Vehicle inspections. 10. Local Guards 42 Chapter 5 SCIFs Outside the U.S. and Under COM a) Local guards, supervised by CAGs and using procedures established by the RSO and documented in the CSP, may search all non-cleared personnel, bags, toolboxes, packages, etc., each time they enter or exit the site. b) Use of non-cleared U.S. guards or non-U.S. guards to control access to the site or secure storage area (SSA) requires the prior approval of the RSO. A SECRET- cleared U.S. citizen must supervise non-cleared or non-U.S. guards. Non-cleared or non-U.S. guards shall not have unescorted access to the site. G. Procurement of Construction Materials 1. General Standards a) These standards apply to construction materials used in SCIF construction under COM authority. These standards do not apply to installations on a roof contiguous to the SCIF provided there is no SCIF penetration. b) Procurements shall be in accordance with Federal Acquisition Regulations. c) In exceptional circumstances, SSMs may deviate from procurement standards with a waiver; such deviation shall be noted in the CSP. d) For building construction projects in Category III countries, cleared U.S. citizens may randomly select up to 35% of building materials from non-specific general construction materials for SCIF construction. Random selection may exceed 35% only if materials can be individually inspected. e) For building construction projects in Category I and II countries, cleared U.S. citizens may randomly select up to 25% of building materials from non-specific general construction materials for SCIF construction. Random selection may exceed 25% only if materials can be individually inspected. f) All such materials must be selected immediately upon receipt of the shipment and transported to secure storage. g) Procurement of materials from host or third party countries identified in the SETL as critical for technical intelligence, or listed on the DoS Prohibited Countries Matrix, is prohibited. 2. Inspectable Materials Specifically Destined for SCIF Construction a) Inspectable materials specifically destined for SCIF construction may be procured from U.S. third-country or local suppliers without security restrictions. b) All inspectable materials specifically destined for SCIF construction procured in host and third party countries or shipped to site in an unsecured manner from the U.S. shall be inspected using a DoS/DS-approved method and then moved to an SSA. c) All inspectable material selected from stock stored outside of the SSA shall be inspected using DoS/DS-approved methods prior to use in SCIF construction. 3. Non-Inspectable Materials Specifically Destined for SCIF Construction 43 Chapter 5 SCIFs Outside the U.S. and Under COM a) Non-inspectable materi
2,004 Cessna 177 Cardinal parts for sale
See all →





Parts listed for sale by vetted eBay sellers — confirmed on eBay at checkout.









