Format. The Defense Information Systems Agency (DISA) publishes it in STIG format. It is a non-automated, "traditional" (non-cyber) security checklist. No scanner can evaluate it. A reviewer walks the site and reads the documents.
Basis. The public mirror describes it this way: "These requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents." It also references DoD 5220.22-M and CJCSI 6510.01F.
Scope. Several items apply specifically to facilities "Connected to the DISN" and to SIPRNet environments.
What it covers
Covered
Not the same as
Collateral classified vaults and secure rooms (open storage) protecting information systems
Protected Distribution Systems, TEMPEST, environmental controls
A CTTA TEMPEST evaluation
Personnel, industrial security, marking, destruction, CUI
An RMF authorization package
SCIF nuance. The vault and secure-room items cover collateral classified open storage. For example, item V-245808 refers to "collateral classified open storage area access doors." The checklist has no standalone SCIF item. SCI facilities remain governed by ICD 705, ICS 705-1 and the IC Tech Spec. The two regimes overlap heavily, but passing one does not certify the other.
What the public mirror shows (checked 11 September 2026)
Source
Version / date
Findings
CAT I
CAT II
CAT III
stigviewer.com listing
Version 2, 2024-08-09
145
39
66
40
ID range. The V2 list runs from V-245722 through V-245873, with gaps. That matches the 145-finding count.
Legacy IDs. The earlier Version 1 checklist used different, older V-IDs, and its legacy pages are still on the mirror. Do not mix V1 and V2 IDs in one review record.
Stale mirror. The newest date anywhere on the mirror site was 2025-01-15, so a later DISA release may not have reached it yet.
Practical handling
Get the current checklist file from the DoD Cyber Exchange and open it in DISA STIG Viewer.
Compare it with the version your last review used. Look for added, removed or merged requirements. A drop from 145 to 144 findings, for example, would mean one requirement was removed or merged.
Re-map any site procedures, drawings or SOP references that cite V-IDs.
Show severity (CAT) levels only as the current file states them. Severities from older versions may have changed.
The V2 (2024-08-09) requirement titles fall into twelve topic areas. Counts are approximate groupings by V-ID range.
#
Area
V-ID range (V2)
Approx. count
1
COMSEC account management and training; classified transmission via NSA-authorized crypto
V-245722 to V-245727
6
2
Protected Distribution System (PDS): construction, documentation, monitoring
V-245728 to V-245743
16
3
Environmental IA controls: emergency power off (EPO), emergency lighting and exits, voltage, emergency power, temperature, humidity, fire detection and suppression
V-245744 to V-245753
10
4
TEMPEST: countermeasures; RED/BLACK separation of processors and cables
V-245754 to V-245756
3
5
Foreign national system and physical access controls
V-245757 to V-245770
13
6
Information assurance: SOPs, COOP, incidents, DD 2875, training, accreditation, KVM switches, PEDs and wireless in classified areas, physical protection of network devices, wall jack security
Classified annual review; position of trust; clearance validation; out-processing
V-245851 to V-245860
6
12
IDS monitoring and installation personnel suitability; physical security plan; risk assessment; restricted and controlled areas; security-in-depth; visitor control; key, lock and access card control; physical penetration testing; staff training; counterintelligence
V-245861 to V-245873
13
Reading the map
Integrators. Areas 2, 4, 8 and 12 affect low-voltage, IDS and access control integrators most directly.
Emergency plans. There is no item named "emergency action plan." The related items are the COOP plan, classified emergency destruction plans, and emergency lighting, exits and EPO.
Scope. Many items are procedural, such as marking, training and records, and belong to the facility's security officials, not to an installer.
The titles below appear as listed on the public V2 (2024-08-09) mirror. An ellipsis (…) marks a shared leading prefix that has been shortened. Severities are deliberately omitted. The V2 page does not show per-item severity, and the current release may assign different CAT levels. Check the current DISA file.
#
V2 ID
Title
1
V-245795
Information Security (INFOSEC) - Vault/Secure Room Storage Standards - Door Combination Lock Meeting Federal Specification
Protected Distribution System (PDS) Construction - Hardened Carrier
16
V-245735
Protected Distribution System (PDS) Construction - Alarmed Carrier
17
V-245755
TEMPEST - Red/Black separation (Processors)
18
V-245756
TEMPEST - Red/Black separation (Cables)
19
V-245789
Information Assurance - Network Connections - Wall Jack Security on Classified Networks (IEEE 802.1X NOT Implemented)
20
V-245862
Intrusion Detection System (IDS) Installation and Maintenance Personnel - Suitability Checks
21
V-245867
Security-in-Depth (AKA: Defense-in-Depth) - Minimum Physical Barriers and Access Control Measures
Two more items are relevant: V-245869, "Sensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems," and V-245870, "Physical Penetration Testing - of Facilities or Buildings Containing Information Systems Connected to the DISN."
ACS head-end inside the SCIF or a SECRET-controlled alarmed area (FFC §C.1)
—
AECS Door Locks
Fail-secure, UL 1034 electric strikes (UFC 3-4.6.5)
—
Security-in-Depth
SID as defined in Tech Spec 2.B
Response time effects
This mapping is our own comparison of titles against the Tech Spec. It is not an official crosswalk.
Practical points
Joint facilities. A SCIF that also hosts DoD information systems may face both an AO accreditation inspection and a Traditional Security review. Prepare one evidence set that satisfies the stricter requirement on each item.
Separate authorities. A favorable STIG review does not accredit a SCIF, and SCIF accreditation does not close STIG findings.
Procedural items. Items such as marking, destruction and training live in the facility security program, not in construction documents.
Definition. CNSSI 4009-2022, as quoted in the NIST CSRC glossary, defines a Protected Distribution System (PDS) as a:
"Wireline or fiber-optic distribution system used to transmit unencrypted classified national security information through an area of lesser classification or control."
Element
Detail
Governing issuance
CNSSI No. 7003, Protected Distribution Systems (PDS)
Chapter 11.J is titled "Protected Distribution Systems"
DISA checklist
16 PDS items (V-245728 to V-245743) covering construction, documentation and monitoring
Who decides
The AO, with CTTA and communications security guidance for the specific installation
When PDS applies and when it does not
It applies to unencrypted classified signal paths that cross an area of lesser classification or control.
It usually does not apply to properly encrypted classified traffic. Properly encrypted traffic is treated as BLACK for distribution purposes. See: RED/BLACK, TEMPEST & EMI Filters.
Most SCIF IDS and ACS cabling is not PDS. Those lines are protected by staying inside the perimeter, by FIPS encryption, or by sealed ferrous conduit under Tech Spec Chapter 7. They do not carry classified information.
The DISA checklist names several ways to protect a PDS run. The plain-language descriptions below come from the requirement titles. Construction details are set by CNSSI 7003 and the approving authority.
Carrier or component
What it means
STIG item
Point of Presence (PoP) and terminals
Both ends of the PDS sit inside properly protected, access-controlled space
V-245728
Hardened carrier
Physically robust carrier, such as rigid metallic conduit, that makes tampering difficult and evident
V-245729
Alarmed carrier
Carrier with an intrusion or tamper sensing system that alarms when disturbed; can reduce the visual inspection burden
V-245735
Continuously viewed carrier
Carrier kept under continuous observation, for example by personnel, instead of being hardened or alarmed
V-245733
Buried carrier
PDS run underground
V-245731
External suspended carrier
PDS run suspended outside buildings
V-245732
Pull boxes
Access points that must be secured, for example with locks and seals
V-245730
Sealed joints
Carrier joints sealed so they cannot be opened without evidence
V-245737
Visible and marked
Carrier kept visible for inspection and identifiable along its length
V-245736
Tactical PDS
Field and tactical applications
V-245734
How the choice plays out
Hardened carriers need frequent visual inspection, because the protection depends on someone noticing tampering.
Alarmed carriers add sensing and monitoring. They need alarm response and maintenance, much like an IDS.
Continuously viewed carriers depend on staffing, so they are rarely practical over long runs.
Hidden carriers fight the inspection requirement. Runs above hard ceilings or inside walls are hard to inspect, and inspectability drives most layout decisions.
The design rule. UFC 4-010-05 §3-4.20 applies CNSSI 7003 when signal distribution with unencrypted national security information passes through lesser-classified areas. It advises: "Avoid the use of PDS whenever possible due to inspection requirements."
Why the burden is high. A PDS is only as good as its inspection program. The DISA checklist expects all of the following for the life of the system:
daily visual checks
incident reporting
periodic technical inspections
an initial inspection
signed approval and request-for-approval documentation
Every foot of carrier adds inspection time. Every pull box adds a lock and seal to control. Renovation work near the route can affect the approval.
How designers eliminate or shorten PDS
Strategy
Source
"Locate telecommunication spaces that contain the encryption equipment within or adjacent (shared wall) to the secure area to enhance security and minimize or eliminate Protected Distribution System (PDS) requirements"
UFC 4-010-05 §3-3.3.2
Encrypt classified traffic with NSA-authorized cryptography before it leaves controlled space, so the path is BLACK
DISA checklist COMSEC area
Bring cabling into the SCIF at a single, labeled entry point, color-coded or marked by classification
UFC 4-010-05 §3-4.19
Keep RED equipment and RED cabling inside the accredited space. Separation rules come from the CTTA, not from public tables.
Derived from UFC §3-3.3.2 and §3-4.20; CTTA guidance
The V2 checklist groups 16 PDS requirements (V-245728 to V-245743) into construction, documentation and monitoring. A reviewer typically works through these topics:
Group
Check topic
STIG item(s)
Construction
Point of Presence and terminal equipment are in protected, access-controlled space
V-245728
Construction
Hardened carrier construction
V-245729
Construction
Pull box security
V-245730
Construction
Buried carrier
V-245731
Construction
External suspended carrier
V-245732
Construction
Continuously viewed carrier
V-245733
Construction
Tactical PDS
V-245734
Construction
Alarmed carrier
V-245735
Construction
Carrier visible and marked
V-245736
Construction
Sealed joints
V-245737
Documentation
Signed approval
V-245738
Documentation
Request-for-approval package
V-245739
Monitoring
Daily visual checks
V-245740 to V-245743 (group)
Monitoring
Incident reporting
V-245740 to V-245743 (group)
Monitoring
Periodic technical inspections
V-245740 to V-245743 (group)
Monitoring
Initial inspection
V-245740 to V-245743 (group)
The "check topic" wording paraphrases the requirement titles. Use the current DISA file for exact titles and check text.
Evidence to have ready
Approval: the signed PDS approval and the approval request package.
Drawings: the carrier route with PoPs, pull boxes and terminal locations.
Inspection logs: daily visual inspection logs, plus technical inspection reports.
Incidents: incident reports and corrective actions.
Alarmed carriers: alarm test and response records.
Most Traditional Security items belong to the site security program. A handful fall directly on the people who design, install and maintain intrusion detection, access control and network cabling.
STIG item (V2)
What it means for the integrator
V-245862 IDS Installation and Maintenance Personnel - Suitability Checks
Technicians must pass the facility's suitability or clearance vetting before working on the IDS. Plan staffing around it.