Module 13 · 18 sections

PEDs, Wireless Detection, Telecom & CCTV

PED policy and risk levels, lockers, RF and ferrous detection, vestibule workflows, TSG telephone rules, notification back feed and CCTV at SCIF entrances.

On this page
  1. 13.01Why PEDs are controlled in SCIFs and SAPFs
  2. 13.02Tech Spec Chapter 10: approvals, prohibitions and risk levels
  3. 13.03PED lockers, signage and the entry routine
  4. 13.04Government-owned, medical and wearable devices
  5. 13.05The 30 June 2023 SECDEF memo: "program for," not "installed by"
  6. 13.06SAPF PED items in the DCSA January 2026 checklist
  7. 13.07How RF device detection works
  8. 13.08What RF detection cannot see
  9. 13.09Non-RF screening: ferromagnetic and metal detection
  10. 13.10PED detection products: verified vendor claims compared
  11. 13.11Detection sensors are equipment too: review, networks and records
  12. 13.12Vestibule PED detection workflow, step by step
  13. 13.13Wiring PED detection into the ACS and door interlock
  14. 13.14Interlocked vestibules and life safety: get the AHJ first
  15. 13.15Telephones in SCIFs: TSG-6, TSG-2 and VoIP rules
  16. 13.16Speakerphones, notification, cable TV and building controls
  17. 13.17CCTV at the SCIF entrance: Tech Spec 8.E and camera design
  18. 13.18Common PED, wireless, telecom and CCTV traps
13.01

Why PEDs are controlled in SCIFs and SAPFs

ICS 705-1 §G.2.e states the risk: "Portable Electronic Devices pose a risk to SCI since they often include capabilities to interact with other information systems and can enable hostile attacks targeting classified information in SCIFs." It sends readers to the IC Tech Spec for PED restrictions. ICS 705-1 §G.2.a adds that RF transmitters are not allowed in a SCIF unless a competent authority, such as the CTTA, evaluates and mitigates them to low risk and the AO approves.

Layer Document What it controls
IC standard ICS 705-1 §G.2.a, §G.2.e RF transmitters and PED risk
IC specification Tech Spec Ch. 10, Portable Electronic Devices with Recording Capabilities and Embedded Technologies Approved use, prohibitions, risk levels, mitigation
TEMPEST form SCIF TEMPEST Checklist Radio transmitters and receivers inside the SCIF or within 3 m of the perimeter wall
DoD SCI DoDM 5105.21 Vol. 2 PEDs governed through the SCIF SOP; photographic equipment follows local PED policy
DoD SAP DoDM 5205.07; DCSA SAP checklist (Jan 2026) Medical devices and PEDs approved before introduction
DoD design UFC 4-010-05 §3-4.7 PED lockers outside the primary entrance

The site SOP turns these documents into local rules, and the AO (or the PSO for a SAP) decides what may enter. The integrator's job is narrower: lockers, signage, detection and entry sequencing that support the policy without adding a new transmitter, microphone or network path at the perimeter.

Sources ICS 705-1 · IC Tech Spec v1.5.1 · SCIF TEMPEST Checklist · DoDM 5105.21 Vol. 2 · DCSA SAP Compliance Checklist (Jan 2026) · UFC 4-010-05

13.02

Tech Spec Chapter 10: approvals, prohibitions and risk levels

Tech Spec Chapter 10 has four parts: A. Approved Use of PEDs/RCET in a SCIF; B. Prohibitions; C. PED/RCET Risk Levels; D. Risk Mitigation. The chapter title pairs PEDs with "Recording Capabilities and Embedded Technologies" (RCET); the acronym's exact expansion was not verified. Instead of one banned-items list, the chapter uses risk levels: the AO approves specific device types with specific mitigations.

Topic Tech Spec text (public copy)
RF transmitters Approval requires that "the AO and the Certified TEMPEST Technical Authority (CTTA) collaborate and approve"
Personal devices "Personally-owned PEDs/RCETs are prohibited from processing SCI."
Low risk No recording or transmitting capability
Medium risk Recording or transmitting features that "can be physically disabled"
High risk Devices that need "more extensive or technically complex mitigation measures"
Mitigation IC element programs use user agreements that include consent to forensic seizure
Medical devices Reviewed through IC medical-device processes plus a technical security review

What this means in practice

  • An approval attaches to a device type and its mitigation, not to "phones" or "watches" in general.
  • The medium tier turns on physical disabling. A settings toggle is a different claim, and only the AO decides whether it is acceptable.
  • User agreements and forensic-seizure consent are administrative controls run by the security office. Detection systems and entry logs can support them but do not replace them.
  • Any approved transmitter involves both the AO and the CTTA. An approval from one alone is incomplete.

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · IC Tech Spec v1.5.1 · IC Tech Spec v1.4 (archived)

13.03

PED lockers, signage and the entry routine

Lockers and signs are the first PED control and the cheapest one. They give people a place to leave devices before they reach the first SCIF reader, and they make the rule impossible to miss.

Element Rule Source
Location "Provide lockable metal cabinets outside the primary entrance for the storage of PEDs." UFC 4-010-05 §3-4.7
Separation PED cabinets may not be within 10 ft (3 m) of equipment processing unencrypted national security information UFC 4-010-05 §3-4.7
Mounting Recessed PED cabinets are prohibited on perimeter walls UFC 4-010-05 §3-4.7
Signage Signs at all entry points listing prohibited and restricted items, such as cell phones and cameras 12 FAM 715.4-1(h) (State example)
Prohibited categories Personally owned devices with recording or transmission capability: cell phones, PDAs, tablets, personal computers, MP3 players, e-readers, mobile hotspots, wireless fitness devices, personal GPS, Bluetooth devices, smartwatches 12 FAM 718.1-1(a) (State example)

Entry routine (design practice)

  1. Place the locker bank on the approach path, before the first controlled door, where people naturally stop.
  2. Post the prohibited-items sign at the lockers and again at the entrance.
  3. If a detector is used, put it after the lockers, so a detection means a device got past the locker point.
  4. Keep the locker area outside the perimeter and away from any rooms processing unencrypted information.

Sources UFC 4-010-05 · 12 FAM 710 (State)

13.04

Government-owned, medical and wearable devices

Not every electronic device at the door is contraband. Government-issued equipment, medical devices and some wearables can be approved, but only through a specific process, and the approval is local.

Device class Rule Source
Medical devices (IC) Reviewed through IC medical-device processes plus a technical security review Tech Spec Ch. 10 (public copy)
Medical devices (State example) Reasonable-accommodation request, technical security review and written AO approval. The approval does not transfer to other agencies. 12 FAM 710
Government-owned PEDs (State example) Advance written approval 12 FAM 718.2-1
Medical devices and PEDs (SAP) "Have any medical devices or other portable electronic devices (PEDs) been approved for introduction and use in the SAPF? If yes, were all required approvals obtained before introduction of the device?" DCSA SAP checklist F-10
Wearable fitness devices (DoD collateral) Qualifying trackers allowed in DoD accredited spaces up to TOP SECRET collateral: no photo, video or audio recording; wireless other than Bluetooth disabled; no connection to government systems; no charging accessories DoD CIO memo (2016)

The 2016 DoD CIO wearables memo is often misread. Its own FAQ says it does not apply to SCIFs or SAPFs, which follow IC directives.

Detection systems must handle approved devices. An approved medical device may itself transmit. Bastille says its system supports allow-listing of "personal medical devices" [vendor claim]. Whatever the product, the allow-list is a security-office record, and each entry should trace to a written approval.

Sources IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · 12 FAM 710 (State) · DCSA SAP Compliance Checklist (Jan 2026) · DoD CIO wearable devices memo (2016) · Bastille: WIDS

13.05

The 30 June 2023 SECDEF memo: "program for," not "installed by"

After the April 2023 unauthorized disclosure case, the Secretary of Defense signed the memorandum "Security Review Follow-on Actions" on 30 June 2023. Two of its directions concern PEDs.

Direction Memo language Date
User certification "Issue policy guidance to ensure all SCIF and SAPF users and occupants certify their adherence to policies prohibiting use of personal or portable electronic devices within SCIFs and SAPFs by September 30, 2023." 30 Sep 2023
Detection Components "program for appropriate electronic device detection systems and mitigation measures in all DoD SCIFs and SAPFs by September 30, 2024." 30 Sep 2024
Reporting SCIF and SAPF reporting 30 Sep 2023

The common overstatement. Vendor-authored trade articles have described the memo as requiring detection systems to be in place in every DoD SCIF and SAPF by 30 September 2024. The memo's verb is "program for." That is planning and budgeting language: put detection and mitigation into the component's program and budget. It is not the same as "installed and operating by" that date. The memo also pairs detection systems with "mitigation measures."

How to use it correctly

  • Quote the memo, not a summary of it.
  • Do not tell a DoD customer they are "out of compliance" for lacking a detector. What is fielded depends on component implementation guidance and the AO's decisions.
  • The memo applies to DoD SCIFs and SAPFs. IC element and civilian agency facilities follow their own policy.

Sources SECDEF memo, Security Review Follow-on Actions (30 Jun 2023) · IC Insiders article (vendor-authored) · Military Embedded Systems article (vendor-authored)

13.06

SAPF PED items in the DCSA January 2026 checklist

DCSA's DoW SAP Security Compliance Checklist (January 2026, v2) ties SAP security questions to DoDM 5205.07, which DoD consolidated on 17 January 2025 (Volume 3 cancelled). Several items touch PEDs and wireless.

Item What it asks Basis cited
F-10 "Have any medical devices or other portable electronic devices (PEDs) been approved for introduction and use in the SAPF? If yes, were all required approvals obtained before introduction of the device?" DoDM 5205.07 §15.12.a; Tech Spec 1.5.1 Ch. 10
E-9, E-10 Wireless and mobile-device controls DoDM 5205.07
F-13 Whether the PSM/PSO has decided "an internal warning system" is needed when non-accessed people are present DoDM 5205.07 §9.5.c

What this means for design (derived)

  • Approval comes first. F-10 asks whether approvals were obtained before a device entered. A detector that finds an unapproved device afterward supports the program but does not answer F-10.
  • SAP and SCI PED rules converge. The SAP checklist cites Tech Spec Chapter 10 directly, so a SAPF PED design should read that chapter as closely as a SCIF design does.
  • Co-utilized facilities take the stricter rule. Tech Spec 1.B.2 holds a co-utilized SAPF to the highest requirement, so the tighter PED policy governs.
  • Warning beacons are perimeter devices. An F-13 beacon or annunciator adds wiring and hardware at the boundary. Route it inside the perimeter and include it in CTTA review.

Deliverables that help the PSO answer these items

  • An equipment list for any detection system, including sensor locations and data paths
  • Written approvals for any sensor or transmitter placed inside the SAPF
  • A description of how detector alerts reach security staff and where logs are kept

Sources DCSA SAP Compliance Checklist (Jan 2026) · IC Tech Spec v1.5.1

13.07

How RF device detection works

Three jobs a detection system does

  1. Listen passively. The sensors receive and never transmit. That matters in a SCIF: a detector that transmitted would itself be an RF transmitter needing CTTA evaluation and AO approval under ICS 705-1 §G.2.a. Cellbusters states its Zone Protector "does not have any jamming abilities" [vendor].
  2. Classify. Sensor networks decode protocols, such as cellular, Wi-Fi, Bluetooth, Bluetooth Low Energy (BLE) and other IoT radios. Simpler detectors measure energy in frequency bands without identifying the device.
  3. Locate. Several sensors together estimate a position on a floor plan. Handheld units use direction-finding antennas to walk an operator to the source.
Category How it works Detects Limits
Passive RF sensor network (WIDS) Ceiling or wall receivers decode protocols and plot emitters on a floor plan Transmitting cellular, Wi-Fi, Bluetooth/BLE and IoT devices Misses powered-off devices and devices silent at that moment. Sensors inside the SCIF need AO/CTTA review.
Fixed standalone RF detector Wideband or band-energy detection at an entry, with local alert and relay output Cellular, often Wi-Fi and Bluetooth, within a set radius Cannot identify the device; may alarm on legitimate outside RF or on phones in nearby lockers
Handheld detector or direction finder Operator sweeps and localizes Cellular; some models also Wi-Fi and Bluetooth/BLE Operator-dependent; standby phones transmit infrequently

Identifying repeat devices. Radio identifiers such as MAC addresses change (see the next section), so vendors describe device "fingerprinting" to recognize a device across sessions [vendor claim]. Bastille, for example, claims coverage of "50+ wireless protocols" and location "down to 1-3 meters" [vendor claim].

Sources ICS 705-1 · Bastille: WIDS · Bastille: classified areas · Cellbusters Zone Protector · BVS Wolfhound-Ultra

13.08

What RF detection cannot see

RF detection only finds devices that are transmitting while a sensor is listening. Every limit below follows from that one fact.

Limitation What happens Source
Powered off A powered-off device emits nothing, so RF sensors cannot see it. Bastille frames its alerts around when "an inactive personal cell phone becomes active." Bastille [vendor]
Airplane mode Airplane mode is not radio silence. Apple: "you can still use Wi-Fi and Bluetooth in Airplane Mode," and the device remembers that choice. Apple Support
Standby Phones in standby transmit infrequently, and BVS notes detection reliability "decreases when phones are in standby." A short walk through a vestibule can miss them. BVS [vendor]
Randomized Wi-Fi addresses Apple rotates private Wi-Fi addresses per network; the rotating mode changes the address "every 2 weeks." Apple Support
Randomized Bluetooth addresses Bluetooth LE Privacy replaces the advertised MAC "with a random value that changes at timing intervals determined by the manufacturer." Bluetooth SIG
Band coverage Not every detector covers every band. The BVS Wolfhound-Ultra covers "2G/3G/4G and non-mmWave 5G bands." BVS [vendor]
RF environment Building DAS, neighboring Wi-Fi and phones in nearby lockers can cause nuisance alarms Industry, derived

Design responses (derived)

  • Layer it. Pair RF detection with PED policy, lockers and signage, and add ferrous or metal screening if the AO wants powered-off devices addressed.
  • Give it time. A vestibule dwell period gives an idle phone more chance to transmit (design practice).
  • Don't allow-list by MAC address. Randomization makes MAC-based allow-lists unreliable. Ask the vendor how its system recognizes approved devices.
  • Survey first. Measure the ambient RF at the entry before choosing detector sensitivity and location.

Sources Bastille: classified areas · Apple Support: Airplane Mode · Apple Support: private Wi-Fi addresses · Bluetooth SIG: privacy · BVS Wolfhound-Ultra

13.09

Non-RF screening: ferromagnetic and metal detection

Because RF sensors cannot see a powered-off phone, some programs add screening that senses the device's physical materials instead of its radio.

Method How it works Strength Weakness
Ferromagnetic (passive magnetic) screening Senses ferrous mass moving past a pole or panel Works whether the device is on or off Does not identify a phone specifically; also responds to other ferrous items
Walk-through metal detector Active induction field in a portal Detects metallic objects Not phone-specific; false alarms from keys and belts; slows throughput
Handheld metal detector Operator wand, active induction Resolves a portal alarm on a specific person Operator time; not phone-specific

Verified product example. Metrasens markets the Ultra as ferrous-object screening in free-standing or wall-mounted form, with MQTT integration to "VMS, PSIM, access control" [vendor claim]. Claims that it detects phones specifically, or powered-off phones, were not found on the pages reviewed for this knowledge base. Do not repeat them without the vendor's written documentation.

How the layers fit

Layer Catches Misses
Policy, lockers, signage Compliant people Forgetful or deliberate carriers
RF detection Transmitting devices Powered-off devices
Ferrous or metal screening Devices on or off Tells you "metal," not "phone"; needs a resolution step
Security officer Resolves alarms Staffing cost

Operational reality. Screening that alarms on keys and belts needs a place and a person to resolve the alarm, or people learn to ignore it. In a vestibule, design the resolution path: a shelf or tray outside the inner door, a sign, and a defined response from the security office.

Sources Metrasens Ultra · UFC 4-010-05 · Bastille: classified areas

13.10

PED detection products: verified vendor claims compared

The table repeats only what each manufacturer states about its own product on the pages reviewed. It is not an endorsement or an independent test, and inclusion does not mean the AO will approve a product.

Product Type Manufacturer claims (verified on vendor pages) Notes
Bastille Enterprise WIDS Passive sensor network "50+ wireless protocols" including cellular, Wi-Fi, Bluetooth, BLE and IoT; location "down to 1-3 meters"; geofenced policies that "alert when a phone enters"; allow-listing of "personal medical devices"; integrations with "Splunk and Elasticsearch/Kibana, PagerDuty, SMS and email" NIAP, TAA, FIPS and ATO status not stated on the pages reviewed
Berkeley Varitronics Systems WallHound-Pro Fixed or stanchion detector Cellular 690–2700 MHz; Wi-Fi 2.4/5 GHz; Bluetooth/BLE including AirTags; range "125 Feet (up to 250 feet using optional DF antenna…)"; "Dry contacts for external trigger of cameras, DVR and speakers"; no Ethernet; passive; marketed for "government SCIFs" Dry-contact output can feed an ACS input (derived)
BVS Wolfhound-Ultra Handheld with direction finding "2G/3G/4G and non-mmWave 5G bands"; DF antennas; used for "facility sweeps, TSCM… SCIFs"; passive; reliability "decreases when phones are in standby" Not for mmWave 5G
Cellbusters Zone Protector / Zone Manager Fixed detector, standalone or networked 20 MHz–6 GHz programmable, 127 channels; 2G–5G, Wi-Fi, Bluetooth; range 5–150 ft; "does not have any jamming abilities"; outputs "Audio Announcer, High Visibility LEDs, Silent Logging, Relay Alert"; PoE Networked mode and web interface inside secure space need AO review (derived)
Metrasens Ultra Ferrous-object screening Free-standing or wall-mounted; MQTT integration with "VMS, PSIM, access control" Phone-specific and powered-off claims not found

Not included: vendors whose sites could not be reached or whose pages were not reviewed, and companies selling coverage systems (DAS or emergency responder radio) rather than detection.

Sources Bastille · Bastille: WIDS · BVS WallHound-Pro · BVS Wolfhound-Ultra · Cellbusters Zone Protector · Metrasens Ultra

13.11

Detection sensors are equipment too: review, networks and records

A detector is not neutral furniture. Once mounted in or next to a SCIF, it is electronic equipment with power, cabling, sometimes a network port, and a log that records who carried what. Each of those draws review.

Design question Why it matters Who decides
Does any sensor sit inside the SCIF? Equipment inside the perimeter needs AO/CTTA review. Sensors must not transmit. AO, CTTA
Does it have Ethernet, Wi-Fi, a web interface or cloud reporting? A network path from inside the SCIF raises the same encryption and head-end location questions as ACS and IDS AO, CTTA; system owner
Where does its data go? Alert and data lines that leave protected space need the same protection thinking as ACS lines AO
Is it an unclassified system? Unclassified systems in a SCIF are evaluated by the CTTA and approved by the AO (ICS 705-1 §G.2.d) CTTA, AO
Is a certification required? Vendors market NIAP/Common Criteria and similar certifications; whether one is required is set by the customer AO; customer IT authority
Where are logs kept, and who sees them? Logs tie device detections to badge events and times SSO or PSO

Choosing the connection style (derived)

  • Contact-closure only. A unit with dry contacts and no Ethernet, such as the WallHound-Pro as described by BVS, keeps the integration to a supervised input on the ACS. It is the simplest design to review.
  • Relay plus local logging. Cellbusters lists relay alerts and "Silent Logging" among its outputs and offers standalone or networked operation.
  • Networked sensor platform. Sensor networks with dashboards and integrations provide location and history, and they bring a full network review with them.

Records. Treat detection logs as security records. Keep them on the security office's systems, not the integrator's laptop or a vendor cloud, unless the AO approves otherwise.

Sources ICS 705-1 · BVS WallHound-Pro · Cellbusters Zone Protector · Bastille: WIDS

13.12

Vestibule PED detection workflow, step by step

A vestibule (two doors with a small space between them) gives detection its best chance: a known person, a closed space, and a few seconds of dwell before the inner door opens. The sequence below is a public-level concept. The site SOP and AO approval govern the real one.

Step Event System action
1 Person reaches the PED lockers outside the primary entrance and stores devices Signage lists prohibited items
2 Presents a credential at the outer vestibule door ACS grants entry; interlock keeps the inner door locked while the outer door is open
3 Outer door closes; person waits in the detection zone for a set dwell period Fixed RF detector or sensor-network zone evaluates; optional ferrous or metal screen
4a No detection Inner reader enabled; credential plus PIN (at least two technologies) grants entry
4b Detection Detector contact, relay or software event reaches the ACS: inner-door grant inhibited, local annunciation, event sent to the SCI-indoctrinated monitor; person returns to the lockers
5 Inside the SCIF Sensor network, if fielded, keeps monitoring its zones; approved medical devices handled as the AO's approval specifies

Rules the sequence must keep

  • Egress is never blocked. Detection and interlock logic apply to entry only. Anyone inside the vestibule or the SCIF can always leave.
  • Two technologies stay two technologies. A clean detection result is not an authentication factor. The inner door still needs credential plus PIN or biometric.
  • Alarms go to the right people. Detection events go to SCI-indoctrinated staff, the same people who monitor the entrance.
  • Visitors follow the same path under escort. A detection on a visitor is resolved by the escort, not by the visitor.

See: Access Control, Identity & Hirsch

Sources UFC 4-010-05 · IC Tech Spec Chs. 7–10 (v1.4 archive; text source) · ICS 705-1 · BVS WallHound-Pro

13.13

Wiring PED detection into the ACS and door interlock

The integration is ordinary access control engineering: the detector becomes an input, and ACS logic decides what the inner door does. The discipline is in what the detector must not touch.

Signal path Implementation Label
Detector to ACS Dry contact (BVS WallHound-Pro) or relay alert (Cellbusters) to a supervised ACS input Vendor outputs; wiring derived
ACS logic Input active: inhibit inner-door grant, trigger local sounder or beacon, log event Derived
Interlock Only one vestibule door unlocks at a time Hirsch Integrated Mx lists "door interlocking" [vendor]
Supervision Cut or shorted detector wiring reports as trouble, not as "clear" Hirsch Integrated Mx lists "high-security supervised alarm inputs" [vendor]; practice derived
Software integration Networked platforms offer APIs or MQTT (Metrasens) Vendor; adds network review
Priority "Notifications from the ACS shall be subordinate in priority to IDS alarms" Tech Spec 7.A.2.i (public copy)

What the detector must never do

  • Never shunt or mask the IDS. Detector logic runs in the ACS. It must not bypass or delay the UL 634 door contact or any IDS zone.
  • Never drive a lock on the egress side. Free egress comes from the mechanical door hardware.
  • Never change IDS modes. Only SCIF personnel inside the SCIF change IDS access modes.

Fail-state decisions to put in writing (derived)

  • Detector power loss or trouble: does the inner door stay available, or does it require security-office release? Either answer is defensible. An unrecorded answer is not.
  • ACS server offline: confirm the interlock and detector input logic run at the door controller, not only on the server.

See: Intrusion Detection & UL 2050 / Extent 3

Sources Integrated Mx datasheet · BVS WallHound-Pro · Cellbusters Zone Protector · Metrasens Ultra · IC Tech Spec Chs. 7–10 (v1.4 archive; text source)

13.14

Interlocked vestibules and life safety: get the AHJ first

A security vestibule where one door stays locked while the other is open is also a path of egress. Fire and building officials treat it that way.

What the model codes say (practitioner reading). Allegion's I Dig Hardware blog reports:

  • "The model codes do not currently include prescriptive requirements for control vestibules in use groups other than I-3" (2021).
  • "Interlocks are not currently addressed in the model codes, so each interlock application must be approved by the Authority Having Jurisdiction" (2023).

Factors the AHJ may weigh (per Allegion)

Factor Question to answer in the submittal
Use group and occupant load How many people use this path, and in what occupancy?
Fire suppression and detection Is the building sprinklered and alarmed?
Fire alarm Does the interlock release on alarm?
Power failure What do both doors do on loss of power?
Egress-side override How does a person inside leave if the other door is open?
Signage What instructions are posted?
Number of vestibules Is this one of several in the egress path?
Listing Are the interlock components UL 294 listed?

SCIF-specific coordination (derived)

  • The egress side of each SCIF door keeps FF-L-2890 one-motion mechanical free egress.
  • Fire alarm and power loss release the interlock logic, as the AHJ approves. The FF-L-2740 lock and FF-L-2890 deadbolt are different: they secure the SCIF when it is unoccupied, and FF-L-2890 hardware for occupied doors still gives one-hand mechanical egress from inside, so a person left inside is not trapped.
  • Emergency exit doors stay alarmed 24/7 with local annunciation (UFC 3-4.6.10).
  • The fire alarm interface is a conductor crossing the perimeter. Coordinate it with the CTTA.
  • For RF-shielded vestibules, the guide specification calls for electric interlocks between the shielded doors, wired per the door manufacturer's instructions.

See: Penetrations, Utilities & Life Safety

Sources I Dig Hardware: control vestibules (2021) · I Dig Hardware: interlocks (2023) · UFC 4-010-05 · UFGS 13 49 20.00 10

13.15

Telephones in SCIFs: TSG-6, TSG-2 and VoIP rules

Tech Spec Chapter 11, Telecommunications Systems, covers unclassified telephone systems, unclassified information systems, CCTV at entry points, unclassified wireless, environmental infrastructure systems, emergency notification, system access, unclassified cable control and protected distribution systems.

Telephone security standards were historically written by the Telephone Security Group (TSG). According to a NITAAC vendor showcase, that work now sits with the National Telecommunications Security Working Group under CNSS, and the standards are published as CNSS instructions.

Standard Covers What the Fixed Facility Checklist asks
CNSSI 5006 (TSG-6) Approved telephones and disconnect devices Each unclassified phone on the public network has on-hook protection by a TSG-6 approved instrument or disconnect device, with line disconnect and ringer protection
CNSSI 5002 (TSG-2) Computerized telephone system (CTS/PBX) configuration Is the CTS TSG-2 configured? Where is it, and is that space controlled like the SCIF? Are cables, media and backups protected? Can the CTS force or hold a station off-hook? How is remote maintenance done? Are installers cleared or escorted?
CNSSI 5000 Voice over IP telephone systems Do all unclassified phones have hold, mute and/or push-to-talk handset capability? Is the space housing the IP system access-controlled, and at what level? Cable protection, remote diagnostics, installer clearance

Stricter agency example. State's 5 FAH-2 H-621.1 requires TSG-approved instruments or disconnects in controlled access areas, prohibits speakerphones, cordless phones and stand-alone answering machines, and requires the phone system to be inside a controlled area or a locked, alarmed room.

Sources SCIF Fixed Facility Checklist v1.5 · IC Tech Spec v1.5.1 · TSG approved endpoints list (May 2026) · NITAAC: TSG phones (vendor showcase) · 5 FAH-2 H-620 (State)

13.16

Speakerphones, notification, cable TV and building controls

Beyond telephones, the Fixed Facility Checklist asks about every other system that can carry sound, images or data across the perimeter. None is automatically forbidden. Each must be declared and configured as the AO approves.

System What the checklist asks Integrator action
Speakerphones and microphones (§F.2) "Are speakerphones/microphones enabled?" Remote room monitoring disabled; use AO approved Specify devices whose microphones can be disabled; document the setting
Voicemail and unified messaging (§F.2) Configured to block unauthorized access from remote diagnostic ports Coordinate with the phone system owner
Copiers, printers, fax (M-FOMs, §F.3) Functions, volatile or non-volatile memory, hard drives, maintenance and disposal, voice or handset features Provide model data sheets
VTC (§F.4) Location and classification levels Declare every codec and camera
Commercial television (§F.5) Receivers inside the SCIF need an annotated floor plan of the cable TV system Show every CATV outlet and cable path
Building automation (§F.6) Countermeasures against "malicious activity, intrusion, and exploitation" Declare HVAC and BAS controllers, including any with wireless or cellular modules
PA, music, emergency notification (§G) "fiber isolation, self-amplified speakers, other method to ensure no audio back feed from the system" Design one-way audio into the SCIF; coordinate AHJ, AO and CTTA

Wireless. Tech Spec 11.E covers unclassified wireless network technology. Under ICS 705-1 §G.2.a, any RF transmitter needs CTTA evaluation and AO approval, and the TEMPEST Checklist asks about transmitters within 3 m of the perimeter. That includes building Wi-Fi access points and DAS antennas mounted on the outside face of a SCIF wall.

Intercoms. Interior intercom stations carry the same audio back-feed and on-hook concerns as telephones. A video intercom at the primary entrance may provide remote door release (UFC 3-4.17.2).

See: Acoustics & Sound Masking

Sources SCIF Fixed Facility Checklist v1.5 · ICS 705-1 · SCIF TEMPEST Checklist · UFC 4-010-05 · IC Tech Spec v1.5.1

13.17

CCTV at the SCIF entrance: Tech Spec 8.E and camera design

CCTV at a SCIF has one job: help people inside see who is at the door. It supplements access control. It never replaces the lock, the ACS or the IDS, and it must never become a way to see inside.

Item Rule Source
Purpose CCTV "may be used to supplement the monitoring of a SCIF entrance for remote control of the door from within the SCIF," with "no technical security hazard" Tech Spec 8.E (public copy)
Controls The remote control device is "within the interior of the SCIF" Tech Spec 8.E
View and operators "a clear view of the SCIF entrance," "monitored/operated by SCI-indoctrinated personnel within the SCIF" Tech Spec 8.E
Lines Lines "should be located within the SCIF"; external lines installed "to prevent tampering as approved by the AO" Tech Spec 8.E
No interior view "Cameras are not allowed within the perimeter or enable observation within the perimeter." A video intercom may provide remote release at the primary entrance. UFC 3-4.17.2
Keypads Installed "to preclude unauthorized observation of the combination" Tech Spec 8.F.5.a
IDS with audio or video Needs AO approval and countermeasures Tech Spec 7.A.2.l

Design guidance (practitioner)

  1. Aim. Frame the approach and the face of the person at the door. Keep the keypad, the FF-L-2740 dial and the view through the open door out of frame. VMS privacy masking is a backup, not the primary control.
  2. Inside controls. Monitor, intercom master and release button go inside the SCIF, operated by SCI-indoctrinated staff.
  3. No audio. Specify cameras and intercoms without microphones, or with microphones physically disabled.
  4. Cabling. Keep camera runs outside the SCIF where possible. A line that must enter is a perimeter conductor for CTTA review.
  5. Recording. An exterior-view recorder is normally an unclassified system kept off SCIF networks. Its footage shows who enters, so restrict operator access.
  6. Security-in-Depth. List corridor and building cameras in the checklist's Security-in-Depth section with coverage maps.

See: Access Control, Identity & Hirsch

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · UFC 4-010-05 · IC Tech Spec v1.4 (archived) · SCIF Fixed Facility Checklist v1.5

13.18

Common PED, wireless, telecom and CCTV traps

# Trap Why it fails Basis
1 Quoting the SECDEF memo as requiring detectors "installed by 30 Sep 2024" The memo says components "program for" detection SECDEF memo
2 Selling RF detection as "no phones inside" Powered-off devices are invisible; airplane mode can leave Wi-Fi and Bluetooth on Vendor, Apple
3 MAC-address allow-lists for approved devices Wi-Fi and BLE addresses are randomized Apple, Bluetooth SIG
4 Detector with Wi-Fi, cloud reporting or a web interface installed without review New transmitter or network path in secure space ICS 705-1 §G.2.a
5 Interlocked vestibule without AHJ approval Interlocks are approved case by case Allegion
6 Detector or interlock logic that can delay egress or shunt the IDS Egress must stay free; ACS ranks below IDS Tech Spec 7.A.2.i
7 PED lockers recessed in the perimeter wall or within 10 ft of NSI processing Prohibited placement UFC 3-4.7
8 Standard desk sets, speakerphones or cordless phones Need TSG-6 instruments or disconnects; speakerphones need AO approval FFC §F.1–F.2
9 Paging, music or fire alarm speakers wired straight from the building system Audio back feed FFC §G
10 Cable TV run in without a declared floor plan Undeclared system FFC §F.5
11 Wi-Fi access points or DAS antennas on the outside face of a SCIF wall Transmitters near the perimeter are reported and reviewed TEMPEST Checklist
12 Entrance camera that sees the keypad, the dial or into the SCIF Enables observation within the perimeter UFC 3-4.17.2
13 Cameras or intercoms with live microphones at the door Audio pickup at the perimeter Practitioner
14 Citing the 2016 DoD wearables memo to allow fitness bands in a SCIF The memo excludes SCIFs and SAPFs DoD CIO memo

See: Traps & Common Failures

Sources SECDEF memo (30 Jun 2023) · SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05 · ICS 705-1 · I Dig Hardware: interlocks (2023) · DoD CIO wearable devices memo (2016)