PED policy and risk levels, lockers, RF and ferrous detection, vestibule workflows, TSG telephone rules, notification back feed and CCTV at SCIF entrances.
ICS 705-1 §G.2.e states the risk: "Portable Electronic Devices pose a risk to SCI since they often include capabilities to interact with other information systems and can enable hostile attacks targeting classified information in SCIFs." It sends readers to the IC Tech Spec for PED restrictions. ICS 705-1 §G.2.a adds that RF transmitters are not allowed in a SCIF unless a competent authority, such as the CTTA, evaluates and mitigates them to low risk and the AO approves.
Layer
Document
What it controls
IC standard
ICS 705-1 §G.2.a, §G.2.e
RF transmitters and PED risk
IC specification
Tech Spec Ch. 10, Portable Electronic Devices with Recording Capabilities and Embedded Technologies
Radio transmitters and receivers inside the SCIF or within 3 m of the perimeter wall
DoD SCI
DoDM 5105.21 Vol. 2
PEDs governed through the SCIF SOP; photographic equipment follows local PED policy
DoD SAP
DoDM 5205.07; DCSA SAP checklist (Jan 2026)
Medical devices and PEDs approved before introduction
DoD design
UFC 4-010-05 §3-4.7
PED lockers outside the primary entrance
The site SOP turns these documents into local rules, and the AO (or the PSO for a SAP) decides what may enter. The integrator's job is narrower: lockers, signage, detection and entry sequencing that support the policy without adding a new transmitter, microphone or network path at the perimeter.
Tech Spec Chapter 10 has four parts: A. Approved Use of PEDs/RCET in a SCIF; B. Prohibitions; C. PED/RCET Risk Levels; D. Risk Mitigation. The chapter title pairs PEDs with "Recording Capabilities and Embedded Technologies" (RCET); the acronym's exact expansion was not verified. Instead of one banned-items list, the chapter uses risk levels: the AO approves specific device types with specific mitigations.
Topic
Tech Spec text (public copy)
RF transmitters
Approval requires that "the AO and the Certified TEMPEST Technical Authority (CTTA) collaborate and approve"
Personal devices
"Personally-owned PEDs/RCETs are prohibited from processing SCI."
Low risk
No recording or transmitting capability
Medium risk
Recording or transmitting features that "can be physically disabled"
High risk
Devices that need "more extensive or technically complex mitigation measures"
Mitigation
IC element programs use user agreements that include consent to forensic seizure
Medical devices
Reviewed through IC medical-device processes plus a technical security review
What this means in practice
An approval attaches to a device type and its mitigation, not to "phones" or "watches" in general.
The medium tier turns on physical disabling. A settings toggle is a different claim, and only the AO decides whether it is acceptable.
User agreements and forensic-seizure consent are administrative controls run by the security office. Detection systems and entry logs can support them but do not replace them.
Any approved transmitter involves both the AO and the CTTA. An approval from one alone is incomplete.
Lockers and signs are the first PED control and the cheapest one. They give people a place to leave devices before they reach the first SCIF reader, and they make the rule impossible to miss.
Element
Rule
Source
Location
"Provide lockable metal cabinets outside the primary entrance for the storage of PEDs."
UFC 4-010-05 §3-4.7
Separation
PED cabinets may not be within 10 ft (3 m) of equipment processing unencrypted national security information
UFC 4-010-05 §3-4.7
Mounting
Recessed PED cabinets are prohibited on perimeter walls
UFC 4-010-05 §3-4.7
Signage
Signs at all entry points listing prohibited and restricted items, such as cell phones and cameras
12 FAM 715.4-1(h) (State example)
Prohibited categories
Personally owned devices with recording or transmission capability: cell phones, PDAs, tablets, personal computers, MP3 players, e-readers, mobile hotspots, wireless fitness devices, personal GPS, Bluetooth devices, smartwatches
12 FAM 718.1-1(a) (State example)
Entry routine (design practice)
Place the locker bank on the approach path, before the first controlled door, where people naturally stop.
Post the prohibited-items sign at the lockers and again at the entrance.
If a detector is used, put it after the lockers, so a detection means a device got past the locker point.
Keep the locker area outside the perimeter and away from any rooms processing unencrypted information.
Not every electronic device at the door is contraband. Government-issued equipment, medical devices and some wearables can be approved, but only through a specific process, and the approval is local.
Device class
Rule
Source
Medical devices (IC)
Reviewed through IC medical-device processes plus a technical security review
Tech Spec Ch. 10 (public copy)
Medical devices (State example)
Reasonable-accommodation request, technical security review and written AO approval. The approval does not transfer to other agencies.
12 FAM 710
Government-owned PEDs (State example)
Advance written approval
12 FAM 718.2-1
Medical devices and PEDs (SAP)
"Have any medical devices or other portable electronic devices (PEDs) been approved for introduction and use in the SAPF? If yes, were all required approvals obtained before introduction of the device?"
DCSA SAP checklist F-10
Wearable fitness devices (DoD collateral)
Qualifying trackers allowed in DoD accredited spaces up to TOP SECRET collateral: no photo, video or audio recording; wireless other than Bluetooth disabled; no connection to government systems; no charging accessories
DoD CIO memo (2016)
The 2016 DoD CIO wearables memo is often misread. Its own FAQ says it does not apply to SCIFs or SAPFs, which follow IC directives.
Detection systems must handle approved devices. An approved medical device may itself transmit. Bastille says its system supports allow-listing of "personal medical devices" [vendor claim]. Whatever the product, the allow-list is a security-office record, and each entry should trace to a written approval.
After the April 2023 unauthorized disclosure case, the Secretary of Defense signed the memorandum "Security Review Follow-on Actions" on 30 June 2023. Two of its directions concern PEDs.
Direction
Memo language
Date
User certification
"Issue policy guidance to ensure all SCIF and SAPF users and occupants certify their adherence to policies prohibiting use of personal or portable electronic devices within SCIFs and SAPFs by September 30, 2023."
30 Sep 2023
Detection
Components "program for appropriate electronic device detection systems and mitigation measures in all DoD SCIFs and SAPFs by September 30, 2024."
30 Sep 2024
Reporting
SCIF and SAPF reporting
30 Sep 2023
The common overstatement. Vendor-authored trade articles have described the memo as requiring detection systems to be in place in every DoD SCIF and SAPF by 30 September 2024. The memo's verb is "program for." That is planning and budgeting language: put detection and mitigation into the component's program and budget. It is not the same as "installed and operating by" that date. The memo also pairs detection systems with "mitigation measures."
How to use it correctly
Quote the memo, not a summary of it.
Do not tell a DoD customer they are "out of compliance" for lacking a detector. What is fielded depends on component implementation guidance and the AO's decisions.
The memo applies to DoD SCIFs and SAPFs. IC element and civilian agency facilities follow their own policy.
DCSA's DoW SAP Security Compliance Checklist (January 2026, v2) ties SAP security questions to DoDM 5205.07, which DoD consolidated on 17 January 2025 (Volume 3 cancelled). Several items touch PEDs and wireless.
Item
What it asks
Basis cited
F-10
"Have any medical devices or other portable electronic devices (PEDs) been approved for introduction and use in the SAPF? If yes, were all required approvals obtained before introduction of the device?"
DoDM 5205.07 §15.12.a; Tech Spec 1.5.1 Ch. 10
E-9, E-10
Wireless and mobile-device controls
DoDM 5205.07
F-13
Whether the PSM/PSO has decided "an internal warning system" is needed when non-accessed people are present
DoDM 5205.07 §9.5.c
What this means for design (derived)
Approval comes first. F-10 asks whether approvals were obtained before a device entered. A detector that finds an unapproved device afterward supports the program but does not answer F-10.
SAP and SCI PED rules converge. The SAP checklist cites Tech Spec Chapter 10 directly, so a SAPF PED design should read that chapter as closely as a SCIF design does.
Co-utilized facilities take the stricter rule. Tech Spec 1.B.2 holds a co-utilized SAPF to the highest requirement, so the tighter PED policy governs.
Warning beacons are perimeter devices. An F-13 beacon or annunciator adds wiring and hardware at the boundary. Route it inside the perimeter and include it in CTTA review.
Deliverables that help the PSO answer these items
An equipment list for any detection system, including sensor locations and data paths
Written approvals for any sensor or transmitter placed inside the SAPF
A description of how detector alerts reach security staff and where logs are kept
Listen passively. The sensors receive and never transmit. That matters in a SCIF: a detector that transmitted would itself be an RF transmitter needing CTTA evaluation and AO approval under ICS 705-1 §G.2.a. Cellbusters states its Zone Protector "does not have any jamming abilities" [vendor].
Classify. Sensor networks decode protocols, such as cellular, Wi-Fi, Bluetooth, Bluetooth Low Energy (BLE) and other IoT radios. Simpler detectors measure energy in frequency bands without identifying the device.
Locate. Several sensors together estimate a position on a floor plan. Handheld units use direction-finding antennas to walk an operator to the source.
Category
How it works
Detects
Limits
Passive RF sensor network (WIDS)
Ceiling or wall receivers decode protocols and plot emitters on a floor plan
Transmitting cellular, Wi-Fi, Bluetooth/BLE and IoT devices
Misses powered-off devices and devices silent at that moment. Sensors inside the SCIF need AO/CTTA review.
Fixed standalone RF detector
Wideband or band-energy detection at an entry, with local alert and relay output
Cellular, often Wi-Fi and Bluetooth, within a set radius
Cannot identify the device; may alarm on legitimate outside RF or on phones in nearby lockers
Handheld detector or direction finder
Operator sweeps and localizes
Cellular; some models also Wi-Fi and Bluetooth/BLE
Identifying repeat devices. Radio identifiers such as MAC addresses change (see the next section), so vendors describe device "fingerprinting" to recognize a device across sessions [vendor claim]. Bastille, for example, claims coverage of "50+ wireless protocols" and location "down to 1-3 meters" [vendor claim].
RF detection only finds devices that are transmitting while a sensor is listening. Every limit below follows from that one fact.
Limitation
What happens
Source
Powered off
A powered-off device emits nothing, so RF sensors cannot see it. Bastille frames its alerts around when "an inactive personal cell phone becomes active."
Bastille [vendor]
Airplane mode
Airplane mode is not radio silence. Apple: "you can still use Wi-Fi and Bluetooth in Airplane Mode," and the device remembers that choice.
Apple Support
Standby
Phones in standby transmit infrequently, and BVS notes detection reliability "decreases when phones are in standby." A short walk through a vestibule can miss them.
BVS [vendor]
Randomized Wi-Fi addresses
Apple rotates private Wi-Fi addresses per network; the rotating mode changes the address "every 2 weeks."
Apple Support
Randomized Bluetooth addresses
Bluetooth LE Privacy replaces the advertised MAC "with a random value that changes at timing intervals determined by the manufacturer."
Bluetooth SIG
Band coverage
Not every detector covers every band. The BVS Wolfhound-Ultra covers "2G/3G/4G and non-mmWave 5G bands."
BVS [vendor]
RF environment
Building DAS, neighboring Wi-Fi and phones in nearby lockers can cause nuisance alarms
Industry, derived
Design responses (derived)
Layer it. Pair RF detection with PED policy, lockers and signage, and add ferrous or metal screening if the AO wants powered-off devices addressed.
Give it time. A vestibule dwell period gives an idle phone more chance to transmit (design practice).
Don't allow-list by MAC address. Randomization makes MAC-based allow-lists unreliable. Ask the vendor how its system recognizes approved devices.
Survey first. Measure the ambient RF at the entry before choosing detector sensitivity and location.
Because RF sensors cannot see a powered-off phone, some programs add screening that senses the device's physical materials instead of its radio.
Method
How it works
Strength
Weakness
Ferromagnetic (passive magnetic) screening
Senses ferrous mass moving past a pole or panel
Works whether the device is on or off
Does not identify a phone specifically; also responds to other ferrous items
Walk-through metal detector
Active induction field in a portal
Detects metallic objects
Not phone-specific; false alarms from keys and belts; slows throughput
Handheld metal detector
Operator wand, active induction
Resolves a portal alarm on a specific person
Operator time; not phone-specific
Verified product example. Metrasens markets the Ultra as ferrous-object screening in free-standing or wall-mounted form, with MQTT integration to "VMS, PSIM, access control" [vendor claim]. Claims that it detects phones specifically, or powered-off phones, were not found on the pages reviewed for this knowledge base. Do not repeat them without the vendor's written documentation.
How the layers fit
Layer
Catches
Misses
Policy, lockers, signage
Compliant people
Forgetful or deliberate carriers
RF detection
Transmitting devices
Powered-off devices
Ferrous or metal screening
Devices on or off
Tells you "metal," not "phone"; needs a resolution step
Security officer
Resolves alarms
Staffing cost
Operational reality. Screening that alarms on keys and belts needs a place and a person to resolve the alarm, or people learn to ignore it. In a vestibule, design the resolution path: a shelf or tray outside the inner door, a sign, and a defined response from the security office.
The table repeats only what each manufacturer states about its own product on the pages reviewed. It is not an endorsement or an independent test, and inclusion does not mean the AO will approve a product.
Product
Type
Manufacturer claims (verified on vendor pages)
Notes
Bastille Enterprise WIDS
Passive sensor network
"50+ wireless protocols" including cellular, Wi-Fi, Bluetooth, BLE and IoT; location "down to 1-3 meters"; geofenced policies that "alert when a phone enters"; allow-listing of "personal medical devices"; integrations with "Splunk and Elasticsearch/Kibana, PagerDuty, SMS and email"
NIAP, TAA, FIPS and ATO status not stated on the pages reviewed
Berkeley Varitronics Systems WallHound-Pro
Fixed or stanchion detector
Cellular 690–2700 MHz; Wi-Fi 2.4/5 GHz; Bluetooth/BLE including AirTags; range "125 Feet (up to 250 feet using optional DF antenna…)"; "Dry contacts for external trigger of cameras, DVR and speakers"; no Ethernet; passive; marketed for "government SCIFs"
Dry-contact output can feed an ACS input (derived)
BVS Wolfhound-Ultra
Handheld with direction finding
"2G/3G/4G and non-mmWave 5G bands"; DF antennas; used for "facility sweeps, TSCM… SCIFs"; passive; reliability "decreases when phones are in standby"
Not for mmWave 5G
Cellbusters Zone Protector / Zone Manager
Fixed detector, standalone or networked
20 MHz–6 GHz programmable, 127 channels; 2G–5G, Wi-Fi, Bluetooth; range 5–150 ft; "does not have any jamming abilities"; outputs "Audio Announcer, High Visibility LEDs, Silent Logging, Relay Alert"; PoE
Networked mode and web interface inside secure space need AO review (derived)
Metrasens Ultra
Ferrous-object screening
Free-standing or wall-mounted; MQTT integration with "VMS, PSIM, access control"
Phone-specific and powered-off claims not found
Not included: vendors whose sites could not be reached or whose pages were not reviewed, and companies selling coverage systems (DAS or emergency responder radio) rather than detection.
A detector is not neutral furniture. Once mounted in or next to a SCIF, it is electronic equipment with power, cabling, sometimes a network port, and a log that records who carried what. Each of those draws review.
Design question
Why it matters
Who decides
Does any sensor sit inside the SCIF?
Equipment inside the perimeter needs AO/CTTA review. Sensors must not transmit.
AO, CTTA
Does it have Ethernet, Wi-Fi, a web interface or cloud reporting?
A network path from inside the SCIF raises the same encryption and head-end location questions as ACS and IDS
AO, CTTA; system owner
Where does its data go?
Alert and data lines that leave protected space need the same protection thinking as ACS lines
AO
Is it an unclassified system?
Unclassified systems in a SCIF are evaluated by the CTTA and approved by the AO (ICS 705-1 §G.2.d)
CTTA, AO
Is a certification required?
Vendors market NIAP/Common Criteria and similar certifications; whether one is required is set by the customer
AO; customer IT authority
Where are logs kept, and who sees them?
Logs tie device detections to badge events and times
SSO or PSO
Choosing the connection style (derived)
Contact-closure only. A unit with dry contacts and no Ethernet, such as the WallHound-Pro as described by BVS, keeps the integration to a supervised input on the ACS. It is the simplest design to review.
Relay plus local logging. Cellbusters lists relay alerts and "Silent Logging" among its outputs and offers standalone or networked operation.
Networked sensor platform. Sensor networks with dashboards and integrations provide location and history, and they bring a full network review with them.
Records. Treat detection logs as security records. Keep them on the security office's systems, not the integrator's laptop or a vendor cloud, unless the AO approves otherwise.
A vestibule (two doors with a small space between them) gives detection its best chance: a known person, a closed space, and a few seconds of dwell before the inner door opens. The sequence below is a public-level concept. The site SOP and AO approval govern the real one.
Step
Event
System action
1
Person reaches the PED lockers outside the primary entrance and stores devices
Signage lists prohibited items
2
Presents a credential at the outer vestibule door
ACS grants entry; interlock keeps the inner door locked while the outer door is open
3
Outer door closes; person waits in the detection zone for a set dwell period
Fixed RF detector or sensor-network zone evaluates; optional ferrous or metal screen
4a
No detection
Inner reader enabled; credential plus PIN (at least two technologies) grants entry
4b
Detection
Detector contact, relay or software event reaches the ACS: inner-door grant inhibited, local annunciation, event sent to the SCI-indoctrinated monitor; person returns to the lockers
5
Inside the SCIF
Sensor network, if fielded, keeps monitoring its zones; approved medical devices handled as the AO's approval specifies
Rules the sequence must keep
Egress is never blocked. Detection and interlock logic apply to entry only. Anyone inside the vestibule or the SCIF can always leave.
Two technologies stay two technologies. A clean detection result is not an authentication factor. The inner door still needs credential plus PIN or biometric.
Alarms go to the right people. Detection events go to SCI-indoctrinated staff, the same people who monitor the entrance.
Visitors follow the same path under escort. A detection on a visitor is resolved by the escort, not by the visitor.
The integration is ordinary access control engineering: the detector becomes an input, and ACS logic decides what the inner door does. The discipline is in what the detector must not touch.
Signal path
Implementation
Label
Detector to ACS
Dry contact (BVS WallHound-Pro) or relay alert (Cellbusters) to a supervised ACS input
Vendor outputs; wiring derived
ACS logic
Input active: inhibit inner-door grant, trigger local sounder or beacon, log event
Networked platforms offer APIs or MQTT (Metrasens)
Vendor; adds network review
Priority
"Notifications from the ACS shall be subordinate in priority to IDS alarms"
Tech Spec 7.A.2.i (public copy)
What the detector must never do
Never shunt or mask the IDS. Detector logic runs in the ACS. It must not bypass or delay the UL 634 door contact or any IDS zone.
Never drive a lock on the egress side. Free egress comes from the mechanical door hardware.
Never change IDS modes. Only SCIF personnel inside the SCIF change IDS access modes.
Fail-state decisions to put in writing (derived)
Detector power loss or trouble: does the inner door stay available, or does it require security-office release? Either answer is defensible. An unrecorded answer is not.
ACS server offline: confirm the interlock and detector input logic run at the door controller, not only on the server.
A security vestibule where one door stays locked while the other is open is also a path of egress. Fire and building officials treat it that way.
What the model codes say (practitioner reading). Allegion's I Dig Hardware blog reports:
"The model codes do not currently include prescriptive requirements for control vestibules in use groups other than I-3" (2021).
"Interlocks are not currently addressed in the model codes, so each interlock application must be approved by the Authority Having Jurisdiction" (2023).
Factors the AHJ may weigh (per Allegion)
Factor
Question to answer in the submittal
Use group and occupant load
How many people use this path, and in what occupancy?
Fire suppression and detection
Is the building sprinklered and alarmed?
Fire alarm
Does the interlock release on alarm?
Power failure
What do both doors do on loss of power?
Egress-side override
How does a person inside leave if the other door is open?
Signage
What instructions are posted?
Number of vestibules
Is this one of several in the egress path?
Listing
Are the interlock components UL 294 listed?
SCIF-specific coordination (derived)
The egress side of each SCIF door keeps FF-L-2890 one-motion mechanical free egress.
Fire alarm and power loss release the interlock logic, as the AHJ approves. The FF-L-2740 lock and FF-L-2890 deadbolt are different: they secure the SCIF when it is unoccupied, and FF-L-2890 hardware for occupied doors still gives one-hand mechanical egress from inside, so a person left inside is not trapped.
Emergency exit doors stay alarmed 24/7 with local annunciation (UFC 3-4.6.10).
The fire alarm interface is a conductor crossing the perimeter. Coordinate it with the CTTA.
For RF-shielded vestibules, the guide specification calls for electric interlocks between the shielded doors, wired per the door manufacturer's instructions.
Tech Spec Chapter 11, Telecommunications Systems, covers unclassified telephone systems, unclassified information systems, CCTV at entry points, unclassified wireless, environmental infrastructure systems, emergency notification, system access, unclassified cable control and protected distribution systems.
Telephone security standards were historically written by the Telephone Security Group (TSG). According to a NITAAC vendor showcase, that work now sits with the National Telecommunications Security Working Group under CNSS, and the standards are published as CNSS instructions.
Standard
Covers
What the Fixed Facility Checklist asks
CNSSI 5006 (TSG-6)
Approved telephones and disconnect devices
Each unclassified phone on the public network has on-hook protection by a TSG-6 approved instrument or disconnect device, with line disconnect and ringer protection
CNSSI 5002 (TSG-2)
Computerized telephone system (CTS/PBX) configuration
Is the CTS TSG-2 configured? Where is it, and is that space controlled like the SCIF? Are cables, media and backups protected? Can the CTS force or hold a station off-hook? How is remote maintenance done? Are installers cleared or escorted?
CNSSI 5000
Voice over IP telephone systems
Do all unclassified phones have hold, mute and/or push-to-talk handset capability? Is the space housing the IP system access-controlled, and at what level? Cable protection, remote diagnostics, installer clearance
Stricter agency example. State's 5 FAH-2 H-621.1 requires TSG-approved instruments or disconnects in controlled access areas, prohibits speakerphones, cordless phones and stand-alone answering machines, and requires the phone system to be inside a controlled area or a locked, alarmed room.
Beyond telephones, the Fixed Facility Checklist asks about every other system that can carry sound, images or data across the perimeter. None is automatically forbidden. Each must be declared and configured as the AO approves.
System
What the checklist asks
Integrator action
Speakerphones and microphones (§F.2)
"Are speakerphones/microphones enabled?" Remote room monitoring disabled; use AO approved
Specify devices whose microphones can be disabled; document the setting
Voicemail and unified messaging (§F.2)
Configured to block unauthorized access from remote diagnostic ports
Coordinate with the phone system owner
Copiers, printers, fax (M-FOMs, §F.3)
Functions, volatile or non-volatile memory, hard drives, maintenance and disposal, voice or handset features
Provide model data sheets
VTC (§F.4)
Location and classification levels
Declare every codec and camera
Commercial television (§F.5)
Receivers inside the SCIF need an annotated floor plan of the cable TV system
Show every CATV outlet and cable path
Building automation (§F.6)
Countermeasures against "malicious activity, intrusion, and exploitation"
Declare HVAC and BAS controllers, including any with wireless or cellular modules
PA, music, emergency notification (§G)
"fiber isolation, self-amplified speakers, other method to ensure no audio back feed from the system"
Design one-way audio into the SCIF; coordinate AHJ, AO and CTTA
Wireless. Tech Spec 11.E covers unclassified wireless network technology. Under ICS 705-1 §G.2.a, any RF transmitter needs CTTA evaluation and AO approval, and the TEMPEST Checklist asks about transmitters within 3 m of the perimeter. That includes building Wi-Fi access points and DAS antennas mounted on the outside face of a SCIF wall.
Intercoms. Interior intercom stations carry the same audio back-feed and on-hook concerns as telephones. A video intercom at the primary entrance may provide remote door release (UFC 3-4.17.2).
CCTV at a SCIF has one job: help people inside see who is at the door. It supplements access control. It never replaces the lock, the ACS or the IDS, and it must never become a way to see inside.
Item
Rule
Source
Purpose
CCTV "may be used to supplement the monitoring of a SCIF entrance for remote control of the door from within the SCIF," with "no technical security hazard"
Tech Spec 8.E (public copy)
Controls
The remote control device is "within the interior of the SCIF"
Tech Spec 8.E
View and operators
"a clear view of the SCIF entrance," "monitored/operated by SCI-indoctrinated personnel within the SCIF"
Tech Spec 8.E
Lines
Lines "should be located within the SCIF"; external lines installed "to prevent tampering as approved by the AO"
Tech Spec 8.E
No interior view
"Cameras are not allowed within the perimeter or enable observation within the perimeter." A video intercom may provide remote release at the primary entrance.
UFC 3-4.17.2
Keypads
Installed "to preclude unauthorized observation of the combination"
Tech Spec 8.F.5.a
IDS with audio or video
Needs AO approval and countermeasures
Tech Spec 7.A.2.l
Design guidance (practitioner)
Aim. Frame the approach and the face of the person at the door. Keep the keypad, the FF-L-2740 dial and the view through the open door out of frame. VMS privacy masking is a backup, not the primary control.
Inside controls. Monitor, intercom master and release button go inside the SCIF, operated by SCI-indoctrinated staff.
No audio. Specify cameras and intercoms without microphones, or with microphones physically disabled.
Cabling. Keep camera runs outside the SCIF where possible. A line that must enter is a perimeter conductor for CTTA review.
Recording. An exterior-view recorder is normally an unclassified system kept off SCIF networks. Its footage shows who enters, so restrict operator access.
Security-in-Depth. List corridor and building cameras in the checklist's Security-in-Depth section with coverage maps.