Module 10 · 30 sections

Access Control, Identity & Hirsch

How electronic access control supports SCIF entry: two-factor readers, head-end placement, encryption, door hardware, PIV/CAC, Hirsch and CCTV.

On this page
  1. 10.01The role of access control in a SCIF
  2. 10.02Entrance requirements: two technologies at the door
  3. 10.03Where the ACS head-end must live
  4. 10.04Protecting ACS lines, outside readers and enrollment data
  5. 10.05Secondary and emergency doors: shut the ACS off when unoccupied
  6. 10.06Electric strikes, UL 1034 and the FF-L-2740 lock
  7. 10.07Duty hours vs unoccupied: who controls the door
  8. 10.08Visitor control at the SCIF entrance
  9. 10.09Access control records
  10. 10.10HSPD-12, FIPS 201-3, PIV/CAC and SP 800-116 security areas
  11. 10.11Buying PACS: the GSA FIPS 201 APL and FICAM
  12. 10.12Hirsch spotlight: corporate status and Velocity 3.9
  13. 10.13Hirsch Mx controllers, SNIB3 and alarm line modules
  14. 10.14Hirsch readers: TS ScramblePad and ScrambleFactor
  15. 10.15Hirsch intrusion integration and SCIF requirement mapping
  16. 10.16What not to claim about Hirsch or any SCIF access control product
  17. 10.17Competitor landscape for enterprise and high-security PACS
  18. 10.18CCTV at SCIF entrances
  19. 10.19Nested areas: the one-way rule
  20. 10.20Integrator traps for access control and door hardware
  21. 10.21One-way access in the governing text: high inside low
  22. 10.22Clearance is not access: need-to-know at every inner door
  23. 10.23The nesting model: boundaries, credentials and IDS status by layer
  24. 10.24Compartmented areas: no spin-dial locks and no independent alarms
  25. 10.25Multiple SCIFs on one control unit: independent partitions
  26. 10.26ACS patterns for nested areas: requirement, feature or practice
  27. 10.27Head-end placement and operator partitioning in shared systems
  28. 10.28Information flow: Bell–LaPadula, data diodes and cross-domain solutions
  29. 10.29Worked example: four nested boundaries from lobby to Type III CA
  30. 10.30Common compartmented access design mistakes
10.01

The role of access control in a SCIF

ICS 705-1 §G.2.b limits SCIF access to authorized personnel, with access control methods approved by the AO. The approved methods are:

  • "automated access control systems using at least two technologies (badge, PIN, biometric, etc.)"
  • electromechanical or mechanical devices
  • personal recognition (in small facilities and/or where there is a single monitored entrance)

ICS 705-1 is explicit that these methods are not approved for securing SCIF entrances when the SCIF is unoccupied.

Layer Job Governs
Access control system (ACS) Authenticates people at the door during occupied hours and logs entries ICS 705-1 §G.2.b; Tech Spec Ch. 8
FF-L-2740 lock on FF-L-2890 hardware Secures the primary door when the SCIF is unoccupied Tech Spec 3.E.2
IDS (UL 2050 Extent 3) Detects intrusion when unoccupied Tech Spec Ch. 7
CCTV Supplements entry control only; no cameras inside the perimeter under DoD criteria Tech Spec 8.E, 11.D; UFC 3-4.17.2

Tech Spec Chapter 8 has six parts:

  • A. SCIF Access Control
  • B. ACS Administration
  • C. ACS Physical Protection
  • D. ACS Recordkeeping
  • E. Using CCTV to Supplement ACS
  • F. Non-Automated Access Control

If the ACS is integrated with the IDS, access control notifications must rank below IDS alarms (Tech Spec 7.A.2.i). DoDM 5105.21 Volume 2 limits IDS and access control device codes to SCI-indoctrinated personnel with a need to know.

Sources ICS 705-1 · IC Tech Spec v1.5.1 · UFC 4-010-05 · DoDM 5105.21 Vol. 2

10.02

Entrance requirements: two technologies at the door

An automated SCIF entry point must verify at least two things about the person, such as something they have (a badge) and something they know (a PIN) or something they are (a biometric). ICS 705-1 §G.2.b calls this "at least two technologies (badge, PIN, biometric, etc.)."

Requirement Source
Automated ACS uses at least two technologies ICS 705-1 §G.2.b
"At a minimum, provide card reader with keypad at the primary entrance and when provided, the secondary entrance." UFC 4-010-05 3-4.17.1
The Common Access Card (CAC) is the default DoD ACS credential UFC 4-010-05
Primary entrance: "An approved access control device (see Chapter 8). May be equipped with a by-pass keyway for use in the event of an access control system failure." Tech Spec 3.E.2
The Fixed Facility Checklist asks "Is there a by-pass key?" and how it is protected FFC v1.5 §C.1
Personal recognition is acceptable in small facilities and/or at a single monitored entrance ICS 705-1 §G.2.b
Only one primary entrance, unless the AO approves otherwise Tech Spec 3.E.2

How this maps to federal identity. A PIV or CAC card plus PIN is a two-factor "Limited" configuration under NIST SP 800-116 Rev. 1. Adding a biometric makes it an "Exclusion" configuration. Both satisfy the two-technology rule. A proximity card alone, or a keypad alone, does not.

Sources ICS 705-1 · UFC 4-010-05 · IC Tech Spec v1.5.1 · SCIF Fixed Facility Checklist v1.5 · NIST SP 800-116 Rev. 1

10.03

Where the ACS head-end must live

Source Wording
SCIF Fixed Facility Checklist v1.5, §C.1 "Is automated access control system located within a SCIF or an alarmed area controlled at the SECRET level?"
UFC 4-010-05 Equipment holding the access control software goes "within the perimeter or a SECRET controlled area"; transmission lines leaving that protection use FIPS AES certified encryption
Vendor paraphrase of the NCSC Tech Spec (DAQ Electronics) "equipment containing access-control software programs be located within a SCIF or a SECRET controlled area"
Fixed Facility Checklist, §C.1 Also asks whether the ACS is integrated with the IDS and/or a LAN/WAN

Design consequences

  • A building-wide or cloud-hosted head-end in unsecured space does not meet this unless the AO approves the architecture.
  • Enterprise E-PACS installations often solve this with a local SCIF controller or partition, or an architecture the AO has approved. Get the AO's approval in writing.
  • If the ACS shares a networked host with the IDS, the host also has to meet the Tech Spec 7.A.3.c(2)(a) requirements for a "Physically Protected Space": a locked room, UL 437 cylinders, and a UL Extent 3 alarm plus access control unless the room is staffed 24 hours. See: Intrusion Detection & UL 2050 / Extent 3.
  • Where the ACS is integrated, disclose the integration and the LAN/WAN connections on the checklist.

Sources SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05 · DAQ Electronics: SCIF ACS (vendor) · IC Tech Spec Ch. 7

10.04

Protecting ACS lines, outside readers and enrollment data

Control Requirement Source
Transmission lines "Are access control transmission lines protected by 128-bit encryption/FIPS 140?" FFC v1.5 §C.1
Lines leaving protected space FIPS AES certified encryption UFC 4-010-05
Readers and panels outside the SCIF "Does external access control outside SCIF have tamper protection?" FFC v1.5 §C.1
ID data and PINs "Is the access control system encoded and is ID data and PINs restricted to SCI-indoctrinated personnel?" FFC v1.5 §C.1
Codes Access codes to IDS and access control devices limited to SCI-indoctrinated personnel with a need to know DoDM 5105.21 Vol. 2
PIN observation DISA's Traditional Security Checklist item "AECS Keypad Device Protection" addresses someone observing an authorized user's PIN at a classified storage area entrance V-245821

What this means in the field

  • Every run that leaves protected space counts. That includes reader-to-controller wiring. An unencrypted Wiegand run from a corridor reader back to a panel outside the perimeter does not meet the encryption question. Plan for encrypted or secure-channel readers and FIPS-validated controllers.
  • Tamper protection for outside devices: tamper-switched enclosures, secure mounting, and supervised wiring.
  • Enrollment, PIN resets, database backups and remote support are restricted to SCI-indoctrinated staff. That rules out routine remote support by uncleared vendor technicians.
  • FIPS 140-2 moves to the NIST historical list on 21 September 2026. For new controllers, ask for FIPS 140-3 validated modules and the CMVP certificate numbers.

Sources SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05 · DoDM 5105.21 Vol. 2 · Traditional Security Checklist (stigviewer) · NIST FIPS 140-3 transition

10.05

Secondary and emergency doors: shut the ACS off when unoccupied

Door type Locking hardware (Tech Spec) ACS rule
Primary entrance (3.E.2) FF-L-2890 deadbolt plus an FF-L-2740 combination lock (or FF-L-2740 integrated hardware the AO previously approved) Approved access control device; by-pass keyway allowed for ACS failure
Secondary door (3.E.3), AO authorization required FF-L-2890 egress device with deadbolt Approved ACS hardware. "The access control system must be deactivated when the SCIF is not occupied."
Emergency egress-only (3.E.4), required by building code FF-L-2890 emergency egress device, exit-only No entry hardware. Alarmed 24/7 with a local audible annunciator.
All perimeter doors (3.E.5–3.E.6) Automatic non-hold closer on the SCIF side; exterior hinge pins made non-removable; alarmed per Ch. 7; TEMPEST per CTTA guidance

UFC 4-010-05 3-4.6.8 and 3-4.6.10 prohibit adding separate standalone and flush-mounted deadbolts to secondary and emergency doors.

Why secondary-door ACS must go dark. An unoccupied SCIF has to be secured by the combination lock and the IDS, not by a card reader (ICS 705-1 §G.2.b). A secondary-door reader that still grants access after hours is an unapproved entry point into an unoccupied SCIF.

Doing it reliably

  • Tie deactivation to the closing procedure, such as the IDS arming sequence or a supervised "SCIF closed" door mode, rather than to a clock schedule alone. Schedules drift, and holidays break them.
  • Write the procedure into the SCIF SOP, and show the reader's disabled state during the acceptance walk-through.
  • Emergency egress doors are IDS points, not ACS doors. They get an HSS, motion coverage, and a local annunciator.

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 · FF-L-2890C

10.06

Electric strikes, UL 1034 and the FF-L-2740 lock

FF-L-2890C (22 Feb 2019; supersedes FF-L-2890B) defines pedestrian door lock extensions:

  • Types II, IV, VII and VIII provide "fail secure, electric release capability for use with existing automated building access control systems." The electric strikes in these assemblies are UL 1034 listed.
  • Types I and III are stand-alone units with an integrated mechanical or electronic keypad using at least a 4-digit code.
  • Once the combination-lock bolt is extended, it cannot be unlocked from outside without dialing the combination again.
  • The exterior key bypass is for ACS failure only. Removing the bypass cylinder must not expose the primary lock mechanism.

UFC 4-010-05 3-4.6.5: "Electric door strikes or electrified mortise locks installed with an access control system (ACS) must have a positive engagement, fail secure, and approved under UL 1034 for burglar resistance."

Component Controlled by When
Latch (electric strike or electrified trim) ACS, after two-factor authentication Occupied hours
Deadbolt FF-L-2740 combination lock Closing and unoccupied hours
Door position IDS HSS, plus motion coverage Always monitored; alarms when armed

The qualified products list QPL-FF-L-2890-5 (21 Mar 2022) names Kaba Mas CDX-10, the Lockmasters LKM10K series, and the Sargent & Greenleaf 2890 series. The 2890 hardware provides one-handed, single-motion egress. The DoD Lock Program tells buyers to check with the local fire marshal (AHJ) before buying. A hardware practitioner notes that Type V and VI configurations with escape mechanisms are intended for rooms that are not regularly occupied.

Sources FF-L-2890C · QPL-FF-L-2890-5 · UFC 4-010-05 · DoD Lock Program · I Dig Hardware: SCIF egress (practitioner)

10.07

Duty hours vs unoccupied: who controls the door

SCIF state Primary door Secondary door Emergency egress door IDS Source
Occupied / open for business Approved ACS with at least two technologies, or personal recognition by SCIF staff at a monitored single entrance. Visitor control happens here. ACS active, if the AO authorized the door Alarmed 24/7; exit only Disarmed, but tamper and emergency-exit circuits stay armed ICS 705-1 §G.2.b; Tech Spec 3.E.2–3.E.4, 7.B.2; UFC 3-4.6.7
Closing Last person verifies the space is clear, locks the FF-L-2740 (throwing the 2890 deadbolt), and arms the IDS within the entry/exit delay ACS deactivated Alarmed Armed; record of who armed it Tech Spec 3.E.3, 7.B.3
Unoccupied FF-L-2740 lock and IDS only. ACS and personal recognition are "not approved for securing SCIF entrances when the SCIF is unoccupied." ACS off; door secured by its 2890 deadbolt Alarmed Armed (secure mode) ICS 705-1 §G.2.b; Tech Spec 3.E.3
Opening Authorized SCI-indoctrinated person dials the combination, enters, and disarms from inside the SCIF within 30 seconds Reactivate per SOP Alarmed Disarmed; record of who disarmed it Tech Spec 7.A.3.a(6), 7.A.3.b(1), 7.B.2

Common points of confusion

  • "Our strike is fail-secure, so the door is locked." A locked latch is still not an FF-L-2740 lock. The deadbolt has to be thrown.
  • "Anti-passback prevents misuse." Anti-passback is a useful control, but it does not change the rule for an unoccupied SCIF.
  • "The IDS will catch it." The IDS and the lock are both required. Neither one substitutes for the other.

Sources ICS 705-1 · IC Tech Spec v1.5.1 · IC Tech Spec Ch. 7 · UFC 4-010-05

10.08

Visitor control at the SCIF entrance

Where visitors are controlled. UFC 4-010-05 3-4.6.7 says: "Unless approved by the AO, provide one primary entrance where visitor control is conducted." Tech Spec Chapter 12.J covers Visitor Access.

Who may visit. DoDM 5105.21 Volume 2 requires the host facility to limit visitors to the areas and information they need for official business. The host verifies clearances through IC or DoD clearance databases (Scattered Castles for the IC).

Example agency practice (Department of State, 12 FAM 717). This is State Department practice only. Other agencies may differ.

  • Visitors are asked about portable electronic devices (PEDs) before entry.
  • They cannot enter until those devices are secured outside.
  • SCIF visitor logs are kept two years.

How the ACS and entry design support visitor control

  • Single primary entrance. Keep visitor processing, PED lockers and the sign-in point at the primary entrance, outside the perimeter. UFC 3-4.7 prohibits PED lockers recessed into the perimeter wall or placed within 10 ft of NSI processing.
  • Visitor credentials. Avoid issuing visitor credentials that open SCIF doors on their own. Treat the ACS as the log of cleared staff movements and the sign-in record as the visitor log.
  • Uncleared presence. UFC 3-4.15 approves a flashing or rotating light, with controls inside the perimeter at each entrance, to warn occupants that non-indoctrinated people are present.
  • Video intercoms at the door. The UFC allows an exterior camera at the primary entrance for remote door control. It must not look into the SCIF.

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · 12 FAM 710 (State)

10.09

Access control records

What the Tech Spec says. Tech Spec Chapter 8.D (ACS Recordkeeping) and Chapter 12.L (IDS and ACS Documentation Requirements) set documentation rules. The exact ACS retention period was not confirmed in public text for this article.

Related federal records schedules

Record Retention Source
Visitor logs, areas under the highest level of security Destroy when 5 years old NARA GRS 5.6, item 110
Visitor logs, other areas Destroy when 2 years old GRS 5.6, item 111
Key and electronic access card accountability, high security (FSL V) 3 years after return GRS 5.6, item 020
Key and electronic access card accountability, other 6 months after return GRS 5.6, item 021
PIV/CAC application records and credentials Per schedule GRS 5.6, items 120/121
SF 702 Security Container Check Sheet Per the component's records schedule (CDSE). State Department: 90 days after the last entry unless an incident occurred. CDSE; 12 FAM 717
IDS arm/disarm failures, tests, battery maintenance 2 years Tech Spec 7.B.3, 7.C.2, 12.L.6

What to configure in the ACS

  • Keep transaction history long enough to meet the longest retention period the AO sets. Document the setting.
  • Restrict report and export rights to SCI-indoctrinated administrators, because the history reveals ID data and patterns of movement.
  • Include ACS database and log backups in the retention plan. Store backups under the same protection as the head-end.

The DISA Traditional Security Checklist has an item titled "Sensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems." Card issuance and recovery records are inspected, not just door events.

Sources IC Tech Spec v1.5.1 · NARA GRS 5.6 · CDSE SF 702 guide · 12 FAM 710 (State) · Traditional Security Checklist (stigviewer)

10.10

HSPD-12, FIPS 201-3, PIV/CAC and SP 800-116 security areas

The framework

  • HSPD-12 requires a common, secure, interoperable federal credential.
  • FIPS 201-3 (January 2022) is the current PIV standard. FIPS 201-2 is withdrawn.
  • Supporting NIST publications:
    • SP 800-73-5 (card interfaces, Jul 2024)
    • SP 800-76-2 (biometrics)
    • SP 800-78-5 (cryptography, Jul 2024)
    • SP 800-79-2 (issuer accreditation)
    • SP 800-157 (derived PIV credentials)
    • SP 800-116 Rev. 1 (29 Jun 2018), Guidelines for the Use of PIV Credentials in Facility Access
  • OMB M-19-17 requires PIV-based facility access and rescinded M-11-11.
SP 800-116 Rev. 1 security area Factors Example mechanism
Controlled 1 (have) PKI-CAK: Card Authentication Key challenge/response
Limited 2 (have + know) PKI-AUTH + PIN
Exclusion 3 (have + know + are) PKI-AUTH + PIN + biometric (BIO/BIO-A or OCC-AUTH)

FIPS 201-3 authentication mechanisms: PKI-AUTH, PKI-CAK, BIO/BIO-A, OCC-AUTH (on-card comparison) and SM-AUTH (secure messaging).

Relevance to a SCIF door

  • The Tech Spec and ICS 705-1 text reviewed here does not require FIPS 201 by name. They require an AO-approved ACS with at least two technologies, encrypted lines and a protected head-end.
  • A Limited (card + PIN) or Exclusion (card + PIN + biometric) configuration fits the two-technology rule naturally.
  • DoD: UFC 4-010-05 makes the CAC the default SCIF/SAPF credential.
  • FIPS 201-3 defines several authentication mechanisms with different assurance. Specify the mechanism (for example PKI-AUTH + PIN), not just "PIV-compatible reader."

Sources NIST PIV standards · NIST SP 800-116 Rev. 1 · IDManagement: FIPS 201 · IDManagement: PACS · UFC 4-010-05 · ICS 705-1

10.11

Buying PACS: the GSA FIPS 201 APL and FICAM

The Approved Products List (APL). GSA's FIPS 201 Evaluation Program (idmanagement.gov) runs the FIPS 201 APL. Under OMB M-05-24, agencies must buy products on the approved products list.

APL category Notes
PACS Infrastructure Head-end and controllers, approved as part of a tested solution
Validation Systems Certificate validation for PIV, PIV-I, CAC
PIV PACS Readers Approved only as part of a complete tested solution
PIV card stock Legacy card stock purchasing restricted through 30 Jun 2027; all legacy card stock use ends 30 Jun 2032

Topologies. Readers are approved inside specific topologies:

  • 13.01: three separate components
  • 13.02: infrastructure and validation combined, plus the reader
  • cloud variants

Changing one component can take the system outside its approved topology.

GSA PACS Customer Ordering Guide (Dec 2025)

  • MAS SIN 334290PACS covers FIPS 201 APL PACS.
  • SIN 541330SEC covers security system integration.
  • SIN 334290L covers legacy non-FIPS PACS, for non-Executive-Branch agencies only.
  • At least one contractor employee on design, installation, configuration, acceptance testing and maintenance must be a Certified System Engineer ICAM PACS (CSEIP).
  • Cloud PACS must be FedRAMP-authorized.

Sources IDManagement: FIPS 201 · IDManagement: PACS · IDManagement: Buy · GSA PACS Customer Ordering Guide (Dec 2025) · SCIF Fixed Facility Checklist v1.5

10.12

Hirsch spotlight: corporate status and Velocity 3.9

Date Event
2009 SCM Microsystems merged with Hirsch Electronics; the combined company became Identive Group, shortened to Identiv in 2014
27 Apr 2017 End of sale for DIGI*TRAC controllers M2N, M2N2, M8N, M8N2, MSPN-8R and MSPN2-8R. Mx controllers are the direct replacements.
3 Apr 2024 Identiv agrees to sell its physical security, access card and identity reader business to Vitaprotech (France)
15 Aug 2024 CFIUS finds "no unresolved national security concerns"
9 Sep 2024 Sale completed
2026 "Vitaprotech became Hirsch Group," operating under the Hirsch and Prysm brands; headquarters in Lyon, France; U.S. operation in Santa Ana, California
  • Website and documentation. The website is hirschsecure.com, and vitaprotech.com redirects there. Technical documentation moved to hirschdocs.atlassian.net.
  • Safe wording: "Hirsch (Hirsch Group, formerly Vitaprotech; previously part of Identiv)."
  • Avoid: "American-owned" (the parent company is French), and "Identiv Hirsch" as a current name.

Velocity Security Management System. Hirsch's 2026 software and federal datasheets describe Velocity 3.9 as "the latest iteration." According to Hirsch, it:

  • manages access control and security operations "from single high secure rooms to multi-building, multi-location campuses"
  • includes an Alarm Viewer (forced entry, door open too long)
  • includes a Who's Inside view for emergency egress
  • includes enrollment, IDS integrations and video integrations
  • offers a web client optimized for Chrome-based browsers

The Velocity Certificate Checking Service (VCCS) validates PIV, PIV-I, CAC and TWIC credentials in Hirsch's FICAM solution. VEL-EXPRESS is a reduced edition that lacks some plugins.

Sources Hirsch: About · Identiv: sale completed · Identiv: CFIUS clearance · Identiv (Wikipedia) · DIGI*TRAC end-of-sale FAQ · Velocity Software datasheet · Velocity Federal datasheet · EB2-2D encryption bridge

10.13

Hirsch Mx controllers, SNIB3 and alarm line modules

All specifications below are as Hirsch's datasheets state them (2025–2026 revisions). They are manufacturer claims. They are not approvals by an AO or CSA.

Product Datasheet claims relevant to SCIF work
Mx controllers (Mx-2, Mx-4, Mx-8) 2-, 4- and 8-door "fully supervised" models. "UL 294: Access Control Systems Units; UL 1076: Proprietary Burglar Alarm Systems." "FIPS 140-3 certified cryptography, including TLS v1.3." Enclosure door tamper switch and key lock. Up to 500,000 credentials in the SNIB3 database.
Integrated Mx controllers Supports "two person rule, occupancy counting, individual user tagging, door interlocking, and anti-passback," plus "high-security supervised alarm inputs." UL 294 and UL 1076. Encrypted communication over XNET2/XNET3 on TCP/IP.
Mx-1 Single-door PoE+ edge controller. UL 294 and UL 1076. "FIPS AES 256 encryption." "TLS 1.2 Encryption (Requires Velocity 3.7 SP2 or later)." OSDP or Wiegand.
SNIB3 Network interface board. Crypto options: AES-256 (FIPS 140-2), AES-128 (FIPS 197), TLS v1.3 (FIPS 140-3), TLS v1.2 (FIPS 140-2). Stated "GSA APL Approved."
Alarm Line Modules (MELM1/2/3, DTLM1/2/3) "High-security line supervision and alarm masking functionality." Circuit resistance measured "100 times per second." 2% supervision (DTLM3/MELM3); 4% (DTLM1/2, MELM1/2). UL 294 and UL 1076.
SBMS-L2HSS door contact "Meets UL 634 Level 2 high security standards"

How these features map to SCIF needs

  • Two-person rule and door interlocking: support vault-style entry procedures and airlock (mantrap) vestibules. Interlocks are not addressed prescriptively in the model codes, so each interlocked vestibule needs AHJ approval and must never block egress.
  • Occupancy counting: supports "is anyone still inside" checks before closing. Hirsch literature does not name a "first-in/last-out" feature, so don't claim one.
  • Line supervision and masking: support supervised alarm points. When the ACS is integrated with the IDS, its events must still rank below IDS alarms (Tech Spec 7.A.2.i).
  • UL 1076 with FIPS 140-3 claims: relevant to Tech Spec 7.A.3.b(10), which requires FIPS 140-2 certified encryption for a UL 1076 listed PCU. Whether an Mx is accepted as the SCIF PCU is the AO's accreditation decision.

Sources Mx Controller datasheet · Integrated Mx datasheet · Mx-1 datasheet · SNIB3 datasheet · Alarm Line Modules datasheet · IC Tech Spec Ch. 7 · I Dig Hardware: interlocks and delayed egress (practitioner)

10.14

Hirsch readers: TS ScramblePad and ScrambleFactor

The PIN observation problem. A standard keypad lets a patient observer, or a camera, learn a PIN from finger position. Worn keys can also give it away. SCIF entrances depend on the PIN as the second factor, so protecting it from observation matters. The DISA Traditional Security Checklist addresses this for classified storage entrances in its "AECS Keypad Device Protection" item.

Reader Datasheet claims
TS ScramblePad (8332/8352), TS ScramblePad HF (8330/8350), TS ScramblePad SC (8336/8356, contact smart card) "Patented scrambling of the illuminated keypad digits." Digits reorder each time START is pressed. Viewing restrictors limit side viewing. Certifications listed: "FCC, UL 294, CE, IC, RCM, RoHS2, REACH, UKCA, GSA APL." Stated "approved by the General Services Administration (GSA) for use in FIPS201/FICAM environments." Credentials: PIV, PIV-I, CIV, CAC, TWIC, DESFire EVx, MIFARE, 125 kHz prox. RS-485/OSDP.
ScrambleFactor SF.1 / SF.3 4.3-inch touchscreen with scrambled PIN, contact and contactless card, and fingerprint. "FBI certified (FIPS 201, PIV, and Mobile ID FAP 10 compliant)." UL 294. "Requires Hirsch Velocity." Launched March 2024.

Where each fits

  • TS ScramblePad SC is a CAC contact reader with a scrambled PIN. It fits the UFC 3-4.17.1 call for a "card reader with keypad" and can support SP 800-116 Limited (two-factor) use when configured in an approved topology.
  • ScrambleFactor adds a biometric for Exclusion (three-factor) configurations, or where the AO wants biometric verification.

Sources TS ScramblePad datasheet · TS ScramblePad product page · ScrambleFactor datasheet · Identiv: ScrambleFactor launch · UFC 4-010-05 · Traditional Security Checklist (stigviewer)

10.15

Hirsch intrusion integration and SCIF requirement mapping

DMP integration. Hirsch's datasheet says Velocity 3.8 or later integrates with DMP XR150 and XR550 intrusion panels. The integration can:

  • arm and disarm areas
  • bypass and reset zones
  • trigger outputs
  • silence bells
  • show status on graphical maps

A Bosch IDS integration datasheet also exists, but the supported panel models were not confirmed.

Integration rules that still apply

  • IDS alarms rank above access control notifications (Tech Spec 7.A.2.i).
  • "There shall be no remote capability for changing the mode of operation by non-SCI cleared personnel" (7.B.1). Velocity operator roles must keep uncleared enterprise operators from arming, disarming or bypassing SCIF zones.
  • The PCU stays inside the SCIF, and mode changes start there (7.A.3.b(1)).
  • The UL 2050 certificate covers the installed IDS. Any integration change after certification requires renewing the certificate (ICS 705-1).
SCIF requirement Relevant Hirsch capability (manufacturer claim; not an approval)
ACS lines "protected by 128-bit encryption/FIPS 140" (FFC §C.1) Mx/SNIB3 FIPS 140-2/140-3 crypto; OSDP readers
Head-end "within a SCIF or an alarmed area controlled at the SECRET level" Velocity server and Mx panels placed there (a design choice, not a product feature)
ID data and PINs restricted to SCI-indoctrinated personnel Velocity operator roles and permissions (configuration and procedure)
Tamper protection on external devices Enclosure tamper switch and key lock; supervised inputs
Card reader with keypad at the primary entrance (UFC 3-4.17.1) TS ScramblePad SC; ScrambleFactor
Secondary-door ACS deactivated when unoccupied (3.E.3) Velocity schedules and door modes (site procedure)
UL 634 Level 2 switches on perimeter doors SBMS-L2HSS

Sources Velocity IDS with DMP datasheet · Velocity IDS with Bosch datasheet · Hirsch: Government · IC Tech Spec Ch. 7 · SCIF Fixed Facility Checklist v1.5 · ICS 705-1

10.16

What not to claim about Hirsch or any SCIF access control product

Safe to say (verifiable from Hirsch literature) Avoid unless independently verified
Hirsch Mx controllers are UL 294 and UL 1076 listed "SCIF-certified," "ICD 705 certified" or "ICD 705 compliant" products
Mx controllers use FIPS 140-3 certified cryptography with TLS 1.3 (per Hirsch) Specific CMVP certificate numbers not published by Hirsch or NIST
Mx supports two-person rule, occupancy counting, door interlocks and high-security line supervision with alarm masking "First-in/last-out" as a named feature
TS ScramblePad readers scramble keypad digits on every use and include viewing restrictors "STIG-compliant Velocity" or "meets all DISA Traditional Security STIG requirements"
Hirsch lists its FICAM PACS solution on the GSA FIPS 201 APL (per Hirsch; confirm the listing on the GSA APL) "DoDIN APL," "Army CoN" or "ATO-ready"
Velocity integrates with DMP XR-series intrusion panels for arm/disarm and zone control "UL 2050 listed Hirsch." UL 2050 certifies the alarm service company, not a product.
Hirsch (Hirsch Group, formerly Vitaprotech; previously part of Identiv) "American-owned" or "Identiv Hirsch"

Say instead: "installed under a UL 2050 certificate by a certified alarm service company" and "UL 1076 listed alarm inputs; IDS design subject to AO/CSA approval."

Always add: "Final system design, IDS/ACS integration and door hardware are subject to approval by the Accrediting Official (AO) / Cognizant Security Authority (CSA) and the Certified TEMPEST Technical Authority (CTTA) where TEMPEST applies."

Integrator credentials. Hirsch runs partner programs:

  • ICAN: system integrators
  • ITAN: technology partners
  • ACES: architects, consultants and engineers

Claim partner or certification status only if the company actually holds it. Hirsch does not publish course names or certification levels on its partner page.

Sources Mx Controller datasheet · TS ScramblePad datasheet · FICAM Solution datasheet · Hirsch: Partners · Traditional Security Checklist (stigviewer)

10.17

Competitor landscape for enterprise and high-security PACS

Integrators on SCIF projects often inherit an existing enterprise platform, or must price against one. The table below is a neutral orientation. It is not a ranking. We did not check federal listings (GSA APL, FICAM) for these platforms, so this article makes no comparison of compliance.

Platform Vendor / owner Neutral description
Hirsch Velocity Hirsch Group (France; U.S. operation in California) High-security PACS with FICAM solution, Mx controllers and scrambled-PIN readers (see Hirsch sections)
LenelS2 OnGuard Honeywell Enterprise access control described as "feature-rich, comprehensive," integrating with many building and security systems
Software House C•CURE 9000 / C•CURE IQ Johnson Controls Enterprise access control and event management. C•CURE IQ is offered as "part of your standard C•CURE 9000 license" (on-premises, hybrid, cloud).
AMAG Symmetry Not confirmed "Intelligent, scalable and integrative access control," with Symmetry CONNECT for identity management
Genetec Synergis Genetec Access control module of the Genetec Security Center unified platform
Gallagher Command Centre Gallagher Group (New Zealand) Integrated security management; lists a "High Security" category with PIV software

Questions to ask of any platform on a SCIF door

  1. Can the head-end, or a local controller that runs independently, sit inside the SCIF or a SECRET-controlled alarmed area?
  2. Which controller-to-host and reader-to-controller links use FIPS 140-validated modules, and what are the CMVP certificate numbers?
  3. Does the reader perform PKI-based PIV/CAC authentication plus PIN, and is that exact configuration on the GSA APL if the agency requires it?
  4. Can operator roles keep uncleared enterprise administrators from changing SCIF doors, enrollment or integrated IDS zones?
  5. Are the controllers and readers UL 294 listed? If alarm inputs are used, are they UL 1076 listed?
  6. Can secondary-door readers be deactivated by procedure when the SCIF closes?

Sources LenelS2 (Honeywell) · Software House · AMAG · Genetec · Gallagher Security · SCIF Fixed Facility Checklist v1.5

10.18

CCTV at SCIF entrances

What is verifiable

  • Supplement only. Tech Spec Chapters 8.E ("Using CCTV to Supplement ACS") and 11.D ("Using CCTV to Monitor Entry Points") treat CCTV as a supplement to access control and entry monitoring. It does not replace the combination lock, the ACS or the IDS.
  • No cameras inside (DoD). UFC 4-010-05 3-4.17.2: "Cameras are not allowed within the perimeter or enable observation within the perimeter." An exterior camera at the primary entrance is permitted for remote control of the door, and a video intercom system may provide this.
  • Checklist. The Fixed Facility Checklist §B (Security-in-Depth) asks "Is there external CCTV coverage?" It asks for a description and for monitor and coverage locations on the map. There is no checklist item for CCTV inside the SCIF.
  • Not a substitute for IDS. IDS must meet UL 2050 Extent 3 (ICS 705-1).

Practitioner guidance

Do Don't
Aim entrance cameras at faces and the door approach Capture keypad PIN entry, the FF-L-2740 dial or display, badge data, or a view into the SCIF when the door opens
Treat the video system as an unclassified system evaluated by the CTTA and AO (ICS 705-1 §G.2.d) Put IP cameras, video doorbells, intercoms with microphones, or cameras built into displays or VTC codecs inside the perimeter without specific AO approval
Keep the camera network off SCIF networks; route camera cabling outside the SCIF Run camera cable through the SCIF to reach the other side of the building
Specify models without audio, or disable microphones, near SCIF walls Leave microphones active at the perimeter (acoustic leakage risk)
Document exterior and corridor coverage on the checklist maps to support Security-in-Depth Present CCTV as a reason to relax the lock, ACS or IDS

See: PEDs, Wireless Detection, Telecom & CCTV.

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · SCIF Fixed Facility Checklist v1.5 · ICS 705-1

10.19

Nested areas: the one-way rule

The building blocks

  • Compartmented Area (CA). Tech Spec 2.C defines a CA as "An area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled Access Programs." The AO approves it, with concurrence from the CA Program Manager.
  • Graded security areas. NIST SP 800-116 Rev. 1 describes Controlled, Limited and Exclusion areas, requiring one, two and three authentication factors.

One-way rule: design concepts, not quoted requirements

Principle What it means for the ACS
Enter through, never around An inner area can be reached only through its parent area's controlled entry. No inner door opens directly to uncontrolled space.
Access flows from higher to lower, never the reverse Authorization for an inner (higher) area may include the outer path. Enrollment in an outer area grants nothing inside an inner area.
Inner events are never masked by outer settings Outer-area schedules, holidays or operator actions cannot unlock, shunt or silence inner-area points. IDS alarms already outrank ACS events (Tech Spec 7.A.2.i).
Administration follows the highest area People who enroll, configure or report on an inner area are indoctrinated for it. The checklist restricts ID data and PINs to SCI-indoctrinated personnel.
Factors never decrease going inward An inner door requires at least as many authentication factors as the door outside it

Tools that support the pattern: door interlocks, anti-passback, two-person rule and occupancy counting. Hirsch Mx controllers list all of these, and other enterprise platforms offer similar features.

Sources IC Tech Spec v1.5.1 · NIST SP 800-116 Rev. 1 · Integrated Mx datasheet · SCIF Fixed Facility Checklist v1.5

10.20

Integrator traps for access control and door hardware

# Trap Basis
1 Treating the electric strike as the SCIF lock. An unoccupied SCIF is secured by the FF-L-2740 lock throwing the FF-L-2890 deadbolt, with the IDS armed. ICS 705-1 §G.2.b; Tech Spec 3.E.2–3
2 Fail-safe strikes or maglocks. DoD criteria require positive engagement, fail-secure, UL 1034 strikes or electrified mortise locks. UFC 3-4.6.5; FF-L-2890C
3 Mixing non-2890 hardware onto the door. Extra standalone or flush-mounted deadbolts on secondary and emergency doors are prohibited. UFC 3-4.6.8, 3-4.6.10
4 Secondary-door ACS left active after hours Tech Spec 3.E.3
5 REX devices that can be triggered from outside, or that shunt IDS door contacts Practitioner
6 Head-end, server or database outside the SCIF, or in the cloud, without AO approval FFC §C.1; UFC
7 Unencrypted reader or panel wiring leaving the SCIF, including Wiegand runs FFC §C.1; UFC
8 Uncleared vendor technicians with admin rights or remote support FFC §C.1; DoDM 5105.21 Vol. 2
9 Readers or panels outside the SCIF without tamper protection FFC §C.1
10 Cameras inside the perimeter, or exterior cameras that see in or capture PIN or dial entry UFC 3-4.17.2
11 IP cameras, video intercoms or door stations with microphones near SCIF walls Practitioner; Tech Spec Ch. 9
12 Wireless devices: wireless locks, Wi-Fi/BLE readers or credentials with active radios, wireless IDS sensors, LTE communicators. RF transmitters need CTTA evaluation and AO approval. ICS 705-1 §G.2.a
13 Buying "GSA" hardware off the wrong list: FF-L-2937 (AA&E) locks or MIL-DTL-43607 key padlocks for classified use. Confirm with the DoD Lock Program. DoD Lock Program
14 Assuming a GSA FIPS 201 APL listing makes a PACS "SCIF-approved" IDManagement; practitioner
15 ACS or IDS panels outside the perimeter; standby power not sized UFC 3-4.17.3.5, 3-4.17.3.7

Sources UFC 4-010-05 · SCIF Fixed Facility Checklist v1.5 · ICS 705-1 · FF-L-2890C · DoD Lock Program · IDManagement: PACS

10.21

One-way access in the governing text: high inside low

The DoD design criteria turn the idea into layout rules. UFC 4-010-05 §3-3.3.1 notes that "having multiple zones within a facility can enhance the security of the higher security zones." §3-3.3.2 directs designers to "Maximize the vertical and horizontal separation between the lowest and highest security areas," and states the key rule: "Entry into a lower security area cannot be through a higher security area. This would require escorts." §3-3.3.3 adds: "locate other areas that require access control adjacent to or surrounding the SCIF or SAPF." The Tech Spec applies the same logic at building scale: "When the SCIF is an entire building, access control shall occur at the building perimeter" (8.A.1, public copy).

Movement Result Basis
Person with higher access enters a lower area Permitted, through an explicit grant on that door UFC zoning; derived
Person with lower access enters a higher area Denied, or escorted UFC §3-3.3.2; visitor entrances "under continuous visual observation" (Tech Spec 8.A.1)
A lower area's only route runs through a higher area Layout error: every trip becomes an escort UFC §3-3.3.2
People leave a higher area through lower areas Normal; egress is always free Derived

Layout checks before the door schedule (derived)

  1. Draw the security rings on the floor plan first: building, controlled suite, SCIF, compartmented areas.
  2. Confirm every lower area has its own path to building circulation.
  3. Put shared support space, such as break rooms and restrooms, outside the highest ring unless the AO agrees otherwise.
  4. Confirm the SCIF primary entrance opens from the ring immediately outside it.

See: Facility Types, Modes & Overseas Categories

Sources UFC 4-010-05 · IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · IC Tech Spec v1.5.1

10.22

Clearance is not access: need-to-know at every inner door

A security clearance says a person may be given classified information. It does not say which information, or which rooms. Executive Order 13526 §4.1(a) sets three conditions before anyone gets access, and all three must be true:

Condition E.O. 13526 §4.1(a) wording ACS consequence (derived)
Eligibility "a favorable determination of eligibility" Necessary, never sufficient, for any door grant
Agreement "signed… nondisclosure agreement" No enrollment on a compartment's doors until the read-in is complete
Need-to-know "a need to know" Each inner boundary gets its own authorization list tied to mission need

The Tech Spec makes this concrete for Type III compartmented areas: everyone with "unfettered access… must be formally briefed into all compartments" in that CA (v1.5.1 §2.C.2). Two people with identical clearances can have completely different door grants.

What it means for ACS configuration (derived)

  • Build a level per boundary. Avoid a single "SCIF plus everything" level. Each inner door group gets its own level, schedule and authentication mode.
  • Grant explicitly. A higher-access person holds explicit grants for the lower doors they use. Nothing inherits silently.
  • Tie changes to read-in and read-out. When the security office debriefs someone from a compartment, the door grant comes off at the same time.
  • Never provision from an HR clearance field. A clearance level in a personnel system is eligibility only. It is not an access decision.
  • Restrict who administers. "ACS administrators shall be SCI-indoctrinated" (Tech Spec 8.B.1, public copy), and the Fixed Facility Checklist restricts ID data and PINs to SCI-indoctrinated personnel.

Sources E.O. 13526 · IC Tech Spec v1.5.1 · IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · SCIF Fixed Facility Checklist v1.5

10.23

The nesting model: boundaries, credentials and IDS status by layer

Secure space nests in layers, and each layer has a different governing document, credential rule and alarm rule. Mixing the rules from two layers is the most common source of compartmented-design errors.

Layer Credential required IDS status Governing text
Building or floor Enterprise badge Building alarms and access control count toward Security-in-Depth Tech Spec 2.B; UFC §3-3.3
Collateral open storage area (e.g., SECRET) Controls approved by the CSA IDS per 32 CFR 117.15(d) 32 CFR 117.15
SCIF Automated ACS using "at least two technologies (badge, PIN, biometric, etc.)"; UFC card reader with keypad; FF-L-2740 lock secures it when unoccupied SCIF IDS to UL 2050 Extent 3; PCU inside the SCIF ICS 705-1 §G.2.b; Tech Spec Chs. 7–8
Compartmented area (CA) "Visual recognition or mechanical/electronic access control devices"; no spin-dial combination locks No independent alarm system; the SCIF IDS covers it Tech Spec v1.5.1 §2.C.4
Adjacent SCIFs (same element or co-use) Separate authorization list per SCIF One PCU may be partitioned into independent units Tech Spec 7.A.2.f; ICS 705-2
SAP inside a SCIF Program-briefed access list Compartmented area pattern DoDM 5105.21 Vol. 2

Reading the table

  • Credentials escalate inward; alarms do not multiply inward. The SCIF is the alarm boundary. A CA inside it adds access control, not another IDS.
  • Outer credentials never open inner doors (derived). A collateral-area grant opens nothing in the SCIF.
  • Each layer has its own paperwork. Security-in-Depth goes in the Fixed Facility Checklist, CAs use the Compartmented Area Checklist, and shared SCIFs use a Co-Use Agreement. DoDM 5105.21 Vol. 2 says that if only part of a SCIF is used for a SAP, "it will be treated as a compartmented area… a CUA must be established."

Sources IC Tech Spec v1.5.1 · ICS 705-1 · 32 CFR 117.15 · UFC 4-010-05 · ICS 705-2 · DoDM 5105.21 Vol. 2

10.24

Compartmented areas: no spin-dial locks and no independent alarms

Two prohibitions every CA design must honor. Tech Spec v1.5.1 §2.C.4:

  • "Spin-dial combination locks shall not be installed on CA doors."
  • "Independent alarm systems shall not be installed in a CA."

A compartmented area is an access-control boundary inside a SCIF, not a second alarm boundary. §2.C.1 defines it as "an area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled Access Programs." The AO approves it "with the concurrence of the CA Program Manager or designee," and access is by visual recognition or mechanical or electronic access control devices.

Type Purpose (v1.5.1 §2.C.2) Integrator impact (derived)
I Viewing and processing; no storage. "Compartmented data shall never be openly displayed on a monitor that faces a primary door or common work area." Check sight lines at doors and vision lites
II Discussion; "Must meet existing sound transmission class (STC) requirements per ICS 705-1." No storage. Acoustic door assembly; reader and REX penetrations must keep the STC
III Viewing, processing, printing, storage and control of accountable compartmented information, in "a GSA-approved container" ACS roster must match the compartment roster exactly

UFC 4-010-05 §3-4.2 agrees on acoustics: "Type I is an area where discussion is not authorized so there is no sound rated construction required. Type II & III… require acoustic protection."

Design consequences (derived)

  • The CA door gets an electronic lock or strike with card plus PIN, or a mechanical pushbutton lock if the AO approves.
  • CA door events are ACS events: no IDS partition, no separate keypad, no separate control panel.
  • After hours, the SCIF's own IDS sensors cover the CA as the SCIF design requires.
  • The CA Checklist v1.5 asks about the access device make and model, "shoulder-surfing," acoustics, briefing of unescorted personnel and GSA containers. It asks no IDS questions.

Sources IC Tech Spec v1.5.1 · CA Fixed Facility Checklist v1.5 · UFC 4-010-05

10.25

Multiple SCIFs on one control unit: independent partitions

Separate SCIFs next to each other may share IDS hardware, but they may not share control. The public Tech Spec copy allows contiguous SCIFs that support the same IC element, or that operate under a Co-Use Agreement, to use one premise control unit (PCU) programmed into "multiple logical units or partitions… that function as individual control units… operated independently of one another" (7.A.2.f).

Rule Text Tech Spec (public copy)
Partitioning Partitions "function as individual control units" 7.A.2.f
PCU location "PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes." UFC §3-4.17.3 agrees. 7.A.3.b(1)
Who arms "Changing arm/disarm status of the system shall be limited to SCI-indoctrinated personnel"; no remote mode changes by non-SCI-cleared personnel 7.B.1
Shared monitoring "If a monitoring station is responsible for more than one IDS, there shall be an audible and visible annunciation for each IDS." 7.A.2.g
Keypad placement "Every effort shall be made to design and install the alarm-monitoring panel in a location that prevents observation by unauthorized persons." 7.A.3.b(5)
False alarms "False alarms shall not exceed one alarm per 30-day period per IDS partition." 7.A.2.p

Design choices (derived)

  • Place the PCU in the SCIF whose staff administer it. Record the other SCIF's arm and disarm authority in the Co-Use Agreement and SOP.
  • Plan where each SCIF's staff arm their own partition, normally from inside their own SCIF.
  • Issue each partition's codes only to that SCIF's staff.
  • Partitions are for separate SCIFs, never for compartmented areas inside one SCIF.

SCIF inside a collateral open storage area. The PCU must be inside the SCIF, and only SCIF personnel change its modes. A collateral partition on the SCIF PCU would have non-SCI users operating SCI equipment. Separate panels are the simpler design.

See: Intrusion Detection & UL 2050 / Extent 3

Sources IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · UFC 4-010-05 · ICS 705-2 · IC Tech Spec v1.5.1

10.26

ACS patterns for nested areas: requirement, feature or practice

Bid documents often blur three different things: what the rules require, what a product can do, and what good designers usually do. The table keeps them apart.

Pattern What it does Status Basis
Two technologies at the SCIF entrance Badge plus PIN or biometric Requirement when an automated ACS is used (ICS 705-1 also permits mechanical devices or personal recognition); DoD UFC calls for a card reader with keypad ICS 705-1 §G.2.b; UFC §3-4.17.1
Area access levels Groups doors into zones with their own levels and schedules Design practice supporting UFC zoning UFC §3-3.3.1
Card plus PIN at a CA door Adds a factor at the inner boundary Design practice; §2.C.4 allows visual recognition or devices Tech Spec v1.5.1 §2.C.4
Escort for visitors Visitors under "constant escort"; badge opens no doors Requirement (escort); badge setup is practice SAP checklist A-30 (DoDM 5205.07 §9.5.a)
Bypass release inside Release button inside the SCIF with "continuous visual observation of personnel entering" Requirement (public copy) Tech Spec 8.B.2
Two-person integrity "at least two authorized persons" present Program requirement where set; ACS supports it NIST glossary; SAP checklist D-15, H-9; Hirsch Mx "two person rule" [vendor]
Anti-passback Blocks re-entry without a logged exit (hard, soft or timed) Vendor feature; not a Tech Spec rule Hirsch Integrated Mx "anti-passback" [vendor]; exit readers add secure-side devices
Occupancy counting Head count per area Vendor feature Hirsch Mx "occupancy counting" [vendor]; a named "first-in/last-out" feature was not verified
Door interlock One vestibule door open at a time Vendor feature; needs AHJ approval Hirsch Mx "door interlocking" [vendor]; Allegion
Internal warning beacon Signals that non-accessed people are present Program decision by the PSM/PSO SAP checklist F-13 (DoDM 5205.07 §9.5.c)

How to use the table

  • A requirement goes in the specification as a "shall."
  • A vendor feature goes in only when the AO, SSO or PSO asks for the behavior it provides.
  • Any added device inside the perimeter, such as an exit reader for anti-passback or a warning beacon, is new wiring at the boundary and needs AO review.

Sources ICS 705-1 · UFC 4-010-05 · IC Tech Spec v1.5.1 · DCSA SAP Compliance Checklist (Jan 2026) · NIST: two-person integrity · Integrated Mx datasheet

10.27

Head-end placement and operator partitioning in shared systems

Many SCIFs sit inside organizations that already run an enterprise access control system. The question is whether SCIF doors can live on that system, and if so, how to keep enterprise operators out of them.

Rules that do not change (see "Where the ACS head-end must live")

  • ACS software is located in the SCIF or a SECRET controlled area (Tech Spec Ch. 8.C, public copy; UFC §3-4.17.1).
  • "ACS administrators shall be SCI-indoctrinated" (Tech Spec 8.B.1, public copy).
  • ID data and PINs are restricted to SCI-indoctrinated personnel (Fixed Facility Checklist §C.1).
  • ACS notifications rank below IDS alarms (Tech Spec 7.A.2.i).

Operator partitioning (concept). In a shared head-end, software partitions keep enterprise operators from seeing or editing SCIF and CA doors, access levels, PINs and audit logs. Genetec's documentation gives a generic definition: a partition "defines a set of entities that are only visible to a specific group of users." Other platforms use different terms for similar controls.

Hirsch Velocity, as verified. Hirsch documents Velocity operator roles and permissions, which support this separation as configuration and procedure, not as a certification. Velocity's datasheet lists an Alarm Viewer and a "Who's Inside" view, and Velocity 3.8 or later integrates with DMP XR150 and XR550 intrusion panels to arm and disarm areas.

Decision Constraint Who decides
Shared enterprise server or a local SCIF server Partitions do not relax the rule on where SCIF software and data live AO, in writing
Which operators see SCIF doors SCI-indoctrinated administrators only SSO
IDS arming from the head-end No remote mode changes by non-SCI-cleared personnel (Tech Spec 7.B.1) AO
Vendor remote support No uncleared technician with administrator access SSO
Lines leaving protected space Encrypted as the AO approves AO

Sources IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · UFC 4-010-05 · SCIF Fixed Facility Checklist v1.5 · Genetec: about partitions · Hirsch Velocity datasheet · Velocity with DMP datasheet

10.28

Information flow: Bell–LaPadula, data diodes and cross-domain solutions

Bell–LaPadula (Bell and LaPadula, 1973; unified exposition 1976). Two rules protect confidentiality:

  • Simple Security Property ("no read up"): "A subject at a given security level may not read an object at a higher security level."
  • Star Property ("no write down"): "A subject at a given security level may not write to any object at a lower security level."

The model covers confidentiality only. The Biba model addresses integrity.

Data diodes. A unidirectional network lets data travel in only one direction, and the guarantee is physical. It is "often used to move information from low-security domains to secret enclaves while assuring that information cannot escape."

Cross-domain solutions (CDS). CNSSI 4009 defines a CDS as "A form of controlled interface that provides the ability to manually and/or automatically access and transfer information between different security domains." Secondary sources report that U.S. CDS evaluation falls primarily under NSA's National Cross Domain Strategy and Management Office (NCDSMO), and that DoD sites implement solutions from a baseline list.

Direction Information (Bell–LaPadula) People Things carried
High to low Read down allowed Allowed, with an explicit grant at each door High-side material does not go into lower areas
Low to high No read up Denied, or escort only PED policy controls what comes in
Into the high side Low to high through a diode or CDS Visitors under escort Inspection and policy
Out of the high side Blocked or reviewed Egress always free Removal controlled by procedure, such as SAP dual authorization for media

Sources Bell–LaPadula model · Unidirectional network · NIST glossary: cross domain solution · Cross-domain solution · DCSA SAP Compliance Checklist (Jan 2026)

10.29

Worked example: four nested boundaries from lobby to Type III CA

This conceptual example traces one generic facility from the street to a Type III compartmented area. It describes no real site. Every choice in it remains subject to the AO, CSA and CTTA.

Boundary Who may pass Credential mode Device notes Administered by
B1 Building or floor All badged employees; visitors after check-in Card Enterprise access control; turnstile or lobby reader; counts toward Security-in-Depth Corporate security
B2 Collateral open storage area (e.g., SECRET) People eligible and approved for that area Card plus PIN, per the CSA IDS under 32 CFR 117.15; a separate area in the ACS Facility security officer
B3 SCIF primary entrance (vestibule) SCI-indoctrinated people on the SCIF access list; escorted visitors At least two technologies; FF-L-2740 lock on FF-L-2890 hardware when unoccupied Head-end in the SCIF or a SECRET controlled area; encrypted lines outside; tamper-protected readers; PCU and remote release inside SCI-indoctrinated ACS administrator; SSO
B4 Type III CA Only people briefed into all compartments in the CA Card plus PIN; two-person if the program requires it Electronic lock or strike; no spin-dial lock; no independent alarm; SCIF IDS covers the room SSO, with CA Program Manager concurrence

Movement check

  • A B4 person walks B4 → B3 → B2 → B1 freely. Each door is an explicit grant, not inheritance.
  • A B3 person not briefed into B4 works in the SCIF but cannot open B4.
  • A B2-only person cannot open B3. Inside B3 they are escorted. Under the UFC layout rule, their daily route never crosses B3 or B4.
  • A visitor holds a badge that opens nothing and stays under escort in B3.

Alarm check

  • One IDS boundary at B3 (plus B2's separate collateral IDS). B4 adds no alarm system.
  • ACS events at B3 and B4 rank below IDS alarms.

Sources UFC 4-010-05 · IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · IC Tech Spec v1.5.1 · 32 CFR 117.15

10.30

Common compartmented access design mistakes

# Mistake Rule it breaks
1 Separate IDS keypad, partition or panel for a compartmented area "Independent alarm systems shall not be installed in a CA" (Tech Spec 2.C.4)
2 Spin-dial combination lock on a CA door Tech Spec 2.C.4
3 A lower area whose only route passes through a higher area UFC §3-3.3.2
4 Access levels that silently inherit inner doors from outer grants Need-to-know per boundary (E.O. 13526 §4.1); derived
5 Door grants provisioned automatically from a clearance field E.O. 13526 §4.1(a)
6 Type III CA roster that does not match compartment briefings Tech Spec 2.C.2
7 Monitors in a Type I CA facing the door or a common work area Tech Spec 2.C.2
8 CA door reader or REX penetrations that break the Type II or III STC Tech Spec 2.C.2; UFC §3-4.2
9 Collateral partition on a SCIF PCU operated by non-SCI staff without written acceptance Tech Spec 7.A.3.b(1), 7.B.1
10 Shared monitoring station without separate audible and visible annunciation for each IDS Tech Spec 7.A.2.g
11 Enterprise operators able to view or edit SCIF doors, PINs or logs Tech Spec 8.B.1; FFC §C.1
12 Anti-passback exit readers or warning beacons added inside the perimeter without review AO review of added devices; derived
13 "Required by ICD 705" written against vendor features such as anti-passback No public requirement; derived

See: Traps & Common Failures

Sources IC Tech Spec v1.5.1 · IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · UFC 4-010-05 · E.O. 13526 · SCIF Fixed Facility Checklist v1.5