Module 17 · 10 sections

DISA Traditional Security STIG & PDS

What the DISA Traditional Security Checklist covers, how it relates to ICD 705 inspections, and the basics of Protected Distribution Systems.

On this page
  1. 17.01What the DISA Traditional Security Checklist is
  2. 17.02Version status: which release is current
  3. 17.03Topic area map of the checklist
  4. 17.04Example physical and technical security requirements
  5. 17.05How the STIG relates to ICD 705 inspections
  6. 17.06Protected Distribution Systems: definition and governing issuance
  7. 17.07PDS carrier types and components
  8. 17.08Why DoD avoids PDS where possible
  9. 17.09PDS inspection checks named in the STIG
  10. 17.10STIG items that land on IDS and access control integrators
17.01

What the DISA Traditional Security Checklist is

What it is

  • Format. The Defense Information Systems Agency (DISA) publishes it in STIG format. It is a non-automated, "traditional" (non-cyber) security checklist. No scanner can evaluate it. A reviewer walks the site and reads the documents.
  • Basis. The public mirror describes it this way: "These requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents." It also references DoD 5220.22-M and CJCSI 6510.01F.
  • Scope. Several items apply specifically to facilities "Connected to the DISN" and to SIPRNet environments.

What it covers

Covered Not the same as
Collateral classified vaults and secure rooms (open storage) protecting information systems An ICD 705 SCIF accreditation
Physical controls: locks, doors, walls, openings, IDS, BMS, motion detection, automated entry control (AECS) A UL 2050 certificate
Protected Distribution Systems, TEMPEST, environmental controls A CTTA TEMPEST evaluation
Personnel, industrial security, marking, destruction, CUI An RMF authorization package

SCIF nuance. The vault and secure-room items cover collateral classified open storage. For example, item V-245808 refers to "collateral classified open storage area access doors." The checklist has no standalone SCIF item. SCI facilities remain governed by ICD 705, ICS 705-1 and the IC Tech Spec. The two regimes overlap heavily, but passing one does not certify the other.

Sources Traditional Security Checklist (stigviewer) · 32 CFR 117.15 · IC Tech Spec v1.5.1

17.02

Version status: which release is current

What the public mirror shows (checked 11 September 2026)

Source Version / date Findings CAT I CAT II CAT III
stigviewer.com listing Version 2, 2024-08-09 145 39 66 40
  • ID range. The V2 list runs from V-245722 through V-245873, with gaps. That matches the 145-finding count.
  • Legacy IDs. The earlier Version 1 checklist used different, older V-IDs, and its legacy pages are still on the mirror. Do not mix V1 and V2 IDs in one review record.
  • Stale mirror. The newest date anywhere on the mirror site was 2025-01-15, so a later DISA release may not have reached it yet.

Practical handling

  1. Get the current checklist file from the DoD Cyber Exchange and open it in DISA STIG Viewer.
  2. Compare it with the version your last review used. Look for added, removed or merged requirements. A drop from 145 to 144 findings, for example, would mean one requirement was removed or merged.
  3. Re-map any site procedures, drawings or SOP references that cite V-IDs.
  4. Show severity (CAT) levels only as the current file states them. Severities from older versions may have changed.

Sources Traditional Security Checklist (stigviewer) · stigviewer STIG index · Legacy Traditional Security (V1) · DoD Cyber Exchange STIG downloads

17.03

Topic area map of the checklist

The V2 (2024-08-09) requirement titles fall into twelve topic areas. Counts are approximate groupings by V-ID range.

# Area V-ID range (V2) Approx. count
1 COMSEC account management and training; classified transmission via NSA-authorized crypto V-245722 to V-245727 6
2 Protected Distribution System (PDS): construction, documentation, monitoring V-245728 to V-245743 16
3 Environmental IA controls: emergency power off (EPO), emergency lighting and exits, voltage, emergency power, temperature, humidity, fire detection and suppression V-245744 to V-245753 10
4 TEMPEST: countermeasures; RED/BLACK separation of processors and cables V-245754 to V-245756 3
5 Foreign national system and physical access controls V-245757 to V-245770 13
6 Information assurance: SOPs, COOP, incidents, DD 2875, training, accreditation, KVM switches, PEDs and wireless in classified areas, physical protection of network devices, wall jack security V-245771 to V-245790 18
7 Industrial security: DD 254, visit authorization letters, contract guard vetting V-245791 to V-245793 3
8 INFOSEC vault / secure room storage standards: locks, doors, walls, openings over 96 sq in, windows, IDS, BMS, motion, IDS line security, AECS, tamper, power, monitoring V-245794 to V-245821 28
9 Marking, handling, cover sheets, monitors and displays, end-of-day checks, reproduction, destruction, emergency destruction plans, spillage, classification guides V-245822 to V-245842 21
10 Controlled Unclassified Information (CUI) V-245843 to V-245850 8
11 Classified annual review; position of trust; clearance validation; out-processing V-245851 to V-245860 6
12 IDS monitoring and installation personnel suitability; physical security plan; risk assessment; restricted and controlled areas; security-in-depth; visitor control; key, lock and access card control; physical penetration testing; staff training; counterintelligence V-245861 to V-245873 13

Reading the map

  • Integrators. Areas 2, 4, 8 and 12 affect low-voltage, IDS and access control integrators most directly.
  • Emergency plans. There is no item named "emergency action plan." The related items are the COOP plan, classified emergency destruction plans, and emergency lighting, exits and EPO.
  • Scope. Many items are procedural, such as marking, training and records, and belong to the facility's security officials, not to an installer.

See: RED/BLACK, TEMPEST & EMI Filters for TEMPEST concepts. This knowledge base does not publish separation distances.

Sources Traditional Security Checklist (stigviewer)

17.04

Example physical and technical security requirements

The titles below appear as listed on the public V2 (2024-08-09) mirror. An ellipsis (…) marks a shared leading prefix that has been shortened. Severities are deliberately omitted. The V2 page does not show per-item severity, and the current release may assign different CAT levels. Check the current DISA file.

# V2 ID Title
1 V-245795 Information Security (INFOSEC) - Vault/Secure Room Storage Standards - Door Combination Lock Meeting Federal Specification
2 V-245798 … Vault/Secure Room Storage Standards - Openings in Perimeter Exceeding 96 Square Inches
3 V-245802 … Secure Room Storage Standards - Balanced Magnetic Switch (BMS) on Perimeter Doors
4 V-245803 … Secure Room Storage Standards - Interior Motion Detection
5 V-245805 Vault/Secure Room Storage Standards - IDS Transmission Line Security
6 V-245806 Vault/Secure Room Storage Standards - IDS Access/Secure Control Units Location
7 V-245808 Vault/Secure Room Storage Standards - Access Control During Working Hours Using Visual Control or AECS
8 V-245809 Vault/Secure Room Storage Standards - AECS and IDS Head-End Equipment Protection
9 V-245812 Vault/Secure Room Storage Standards - Masking of IDS Sensors Displayed at the IDS Monitoring Station
10 V-245814 Vault/Secure Room Storage Standards - IDS/AECS Primary and Emergency Power Supply
11 V-245815 Vault/Secure Room Storage Standards - IDS/AECS Component Tamper Protection
12 V-245818 Vault/Secure Room Storage Standards - AECS Transmission Line Security
13 V-245819 Vault/Secure Room Storage Standards - AECS Door Locks
14 V-245821 Vault/Secure Room Storage Standards - AECS Keypad Device Protection
15 V-245729 Protected Distribution System (PDS) Construction - Hardened Carrier
16 V-245735 Protected Distribution System (PDS) Construction - Alarmed Carrier
17 V-245755 TEMPEST - Red/Black separation (Processors)
18 V-245756 TEMPEST - Red/Black separation (Cables)
19 V-245789 Information Assurance - Network Connections - Wall Jack Security on Classified Networks (IEEE 802.1X NOT Implemented)
20 V-245862 Intrusion Detection System (IDS) Installation and Maintenance Personnel - Suitability Checks
21 V-245867 Security-in-Depth (AKA: Defense-in-Depth) - Minimum Physical Barriers and Access Control Measures

Two more items are relevant: V-245869, "Sensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems," and V-245870, "Physical Penetration Testing - of Facilities or Buildings Containing Information Systems Connected to the DISN."

Sources Traditional Security Checklist (stigviewer) · Legacy Traditional Security (V1)

17.05

How the STIG relates to ICD 705 inspections

STIG topic (V2 title keyword) ICD 705 / Tech Spec counterpart Watch for
Door Combination Lock Meeting Federal Specification FF-L-2740 lock on the primary door (3.E.2) Same lock family
Openings in Perimeter Exceeding 96 Square Inches Bars, grilles or baffles over 96 in² (3.G.7.c) Same threshold
BMS on Perimeter Doors; Interior Motion Detection UL 634 Level II HSS and motion on every perimeter door (7.A.2.d, 7.A.3.a(7)) ICD 705 requires both on every perimeter door
IDS Transmission Line Security FIPS-certified encryption or sealed conduit (7.A.3.b(10), 7.A.2.e) Tech Spec names specific FIPS standards
IDS Access/Secure Control Units Location PCU inside the SCIF (7.A.3.b(1))
Masking of IDS Sensors Displayed at the Monitoring Station Shunted or masked points displayed at the station (7.B.4)
IDS/AECS Primary and Emergency Power Supply 24 hours of uninterruptible power (7.B.5) Confirm the STIG's own criterion in the current file
IDS/AECS Component Tamper Protection Tamper annunciation; external ACS tamper (7.A.3.b(7); FFC §C.1)
AECS and IDS Head-End Equipment Protection ACS head-end inside the SCIF or a SECRET-controlled alarmed area (FFC §C.1)
AECS Door Locks Fail-secure, UL 1034 electric strikes (UFC 3-4.6.5)
Security-in-Depth SID as defined in Tech Spec 2.B Response time effects

This mapping is our own comparison of titles against the Tech Spec. It is not an official crosswalk.

Practical points

  • Joint facilities. A SCIF that also hosts DoD information systems may face both an AO accreditation inspection and a Traditional Security review. Prepare one evidence set that satisfies the stricter requirement on each item.
  • Separate authorities. A favorable STIG review does not accredit a SCIF, and SCIF accreditation does not close STIG findings.
  • Procedural items. Items such as marking, destruction and training live in the facility security program, not in construction documents.

Sources Traditional Security Checklist (stigviewer) · IC Tech Spec Ch. 7 · IC Tech Spec v1.5.1 · SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05

17.06

Protected Distribution Systems: definition and governing issuance

Definition. CNSSI 4009-2022, as quoted in the NIST CSRC glossary, defines a Protected Distribution System (PDS) as a:

"Wireline or fiber-optic distribution system used to transmit unencrypted classified national security information through an area of lesser classification or control."

Element Detail
Governing issuance CNSSI No. 7003, Protected Distribution Systems (PDS)
Referenced by UFC 4-010-05 §3-4.20 (DoD SCIF/SAPF design criteria)
IC Tech Spec Chapter 11.J is titled "Protected Distribution Systems"
DISA checklist 16 PDS items (V-245728 to V-245743) covering construction, documentation and monitoring
Who decides The AO, with CTTA and communications security guidance for the specific installation

When PDS applies and when it does not

  • It applies to unencrypted classified signal paths that cross an area of lesser classification or control.
  • It usually does not apply to properly encrypted classified traffic. Properly encrypted traffic is treated as BLACK for distribution purposes. See: RED/BLACK, TEMPEST & EMI Filters.
  • Most SCIF IDS and ACS cabling is not PDS. Those lines are protected by staying inside the perimeter, by FIPS encryption, or by sealed ferrous conduit under Tech Spec Chapter 7. They do not carry classified information.

Sources NIST CSRC glossary: PDS · UFC 4-010-05 · IC Tech Spec v1.5.1 · Traditional Security Checklist (stigviewer)

17.07

PDS carrier types and components

The DISA checklist names several ways to protect a PDS run. The plain-language descriptions below come from the requirement titles. Construction details are set by CNSSI 7003 and the approving authority.

Carrier or component What it means STIG item
Point of Presence (PoP) and terminals Both ends of the PDS sit inside properly protected, access-controlled space V-245728
Hardened carrier Physically robust carrier, such as rigid metallic conduit, that makes tampering difficult and evident V-245729
Alarmed carrier Carrier with an intrusion or tamper sensing system that alarms when disturbed; can reduce the visual inspection burden V-245735
Continuously viewed carrier Carrier kept under continuous observation, for example by personnel, instead of being hardened or alarmed V-245733
Buried carrier PDS run underground V-245731
External suspended carrier PDS run suspended outside buildings V-245732
Pull boxes Access points that must be secured, for example with locks and seals V-245730
Sealed joints Carrier joints sealed so they cannot be opened without evidence V-245737
Visible and marked Carrier kept visible for inspection and identifiable along its length V-245736
Tactical PDS Field and tactical applications V-245734

How the choice plays out

  • Hardened carriers need frequent visual inspection, because the protection depends on someone noticing tampering.
  • Alarmed carriers add sensing and monitoring. They need alarm response and maintenance, much like an IDS.
  • Continuously viewed carriers depend on staffing, so they are rarely practical over long runs.
  • Hidden carriers fight the inspection requirement. Runs above hard ceilings or inside walls are hard to inspect, and inspectability drives most layout decisions.

Sources Traditional Security Checklist (stigviewer) · NIST CSRC glossary: PDS · UFC 4-010-05

17.08

Why DoD avoids PDS where possible

The design rule. UFC 4-010-05 §3-4.20 applies CNSSI 7003 when signal distribution with unencrypted national security information passes through lesser-classified areas. It advises: "Avoid the use of PDS whenever possible due to inspection requirements."

Why the burden is high. A PDS is only as good as its inspection program. The DISA checklist expects all of the following for the life of the system:

  • daily visual checks
  • incident reporting
  • periodic technical inspections
  • an initial inspection
  • signed approval and request-for-approval documentation

Every foot of carrier adds inspection time. Every pull box adds a lock and seal to control. Renovation work near the route can affect the approval.

How designers eliminate or shorten PDS

Strategy Source
"Locate telecommunication spaces that contain the encryption equipment within or adjacent (shared wall) to the secure area to enhance security and minimize or eliminate Protected Distribution System (PDS) requirements" UFC 4-010-05 §3-3.3.2
Encrypt classified traffic with NSA-authorized cryptography before it leaves controlled space, so the path is BLACK DISA checklist COMSEC area
Bring cabling into the SCIF at a single, labeled entry point, color-coded or marked by classification UFC 4-010-05 §3-4.19
Keep RED equipment and RED cabling inside the accredited space. Separation rules come from the CTTA, not from public tables. Derived from UFC §3-3.3.2 and §3-4.20; CTTA guidance

See: RED/BLACK, TEMPEST & EMI Filters and See: Construction Security & Build Sequence.

Sources UFC 4-010-05 · Traditional Security Checklist (stigviewer) · NIST CSRC glossary: PDS

17.09

PDS inspection checks named in the STIG

The V2 checklist groups 16 PDS requirements (V-245728 to V-245743) into construction, documentation and monitoring. A reviewer typically works through these topics:

Group Check topic STIG item(s)
Construction Point of Presence and terminal equipment are in protected, access-controlled space V-245728
Construction Hardened carrier construction V-245729
Construction Pull box security V-245730
Construction Buried carrier V-245731
Construction External suspended carrier V-245732
Construction Continuously viewed carrier V-245733
Construction Tactical PDS V-245734
Construction Alarmed carrier V-245735
Construction Carrier visible and marked V-245736
Construction Sealed joints V-245737
Documentation Signed approval V-245738
Documentation Request-for-approval package V-245739
Monitoring Daily visual checks V-245740 to V-245743 (group)
Monitoring Incident reporting V-245740 to V-245743 (group)
Monitoring Periodic technical inspections V-245740 to V-245743 (group)
Monitoring Initial inspection V-245740 to V-245743 (group)

The "check topic" wording paraphrases the requirement titles. Use the current DISA file for exact titles and check text.

Evidence to have ready

  • Approval: the signed PDS approval and the approval request package.
  • Drawings: the carrier route with PoPs, pull boxes and terminal locations.
  • Inspection logs: daily visual inspection logs, plus technical inspection reports.
  • Incidents: incident reports and corrective actions.
  • Alarmed carriers: alarm test and response records.

Sources Traditional Security Checklist (stigviewer) · NIST CSRC glossary: PDS · UFC 4-010-05

17.10

STIG items that land on IDS and access control integrators

Most Traditional Security items belong to the site security program. A handful fall directly on the people who design, install and maintain intrusion detection, access control and network cabling.

STIG item (V2) What it means for the integrator
V-245862 IDS Installation and Maintenance Personnel - Suitability Checks Technicians must pass the facility's suitability or clearance vetting before working on the IDS. Plan staffing around it.
V-245802 / V-245803 BMS on Perimeter Doors / Interior Motion Detection Expect door switches and motion coverage to be checked in the field, not only on drawings
V-245805 IDS Transmission Line Security Communicator and path encryption must be documented. See: Intrusion Detection & UL 2050 / Extent 3
V-245806 IDS Access/Secure Control Units Location Control unit location is checked; ICD 705 puts the PCU inside the SCIF
V-245809 AECS and IDS Head-End Equipment Protection Head-end protection is checked; the SCIF checklist places ACS head-ends inside the SCIF or a SECRET-controlled alarmed area
V-245812 Masking of IDS Sensors Displayed at the IDS Monitoring Station Masked or inactive sensors must show at the station. Demonstrate it.
V-245814 IDS/AECS Primary and Emergency Power Supply Battery and backup power design must be documented
V-245815 IDS/AECS Component Tamper Protection Enclosures and external devices need tamper protection
V-245818 AECS Transmission Line Security The risk is people "not vetted to at least the same level of classification" gaining access to the lines
V-245819 AECS Door Locks Covers the "variety of locking mechanisms" on primary and secondary doors, including fail-secure behavior
V-245821 AECS Keypad Device Protection Protect PIN entry from observation, for example with scrambled keypads and viewing restrictors, and aim cameras away
V-245789 Wall Jack Security on Classified Networks (IEEE 802.1X NOT Implemented) Physical protection of classified network jacks
V-245870 Physical Penetration Testing Facilities connected to the DISN may be penetration tested; doors, readers and alarm response are part of the physical attack surface

Sources Traditional Security Checklist (stigviewer) · IC Tech Spec Ch. 7 · SCIF Fixed Facility Checklist v1.5