Reference · 218 terms

Glossary

Acronyms and terms you will meet in ICD 705, the IC Tech Spec, TEMPEST guidance and UL 2050, defined in plain English and linked to the module that explains them.

A

AA-D-600D

GSA federal specification for security vault doors, including Class 5-A (armory, AA&E only), Class 5-B (ballistic) and Class 5-V (national security information).

See Doors, Locks & Security Containers

AA&E arms, ammunition and explosives

Material protected under DoD AA&E rules rather than classified-information rules; FF-L-2937 locks and Class 5-A vault doors are AA&E hardware, and UL 2050 covers AA&E storage areas at Extent 2 or 3.

See Doors, Locks & Security Containers

AA-V-2737

GSA federal specification for modular vault systems; the Tech Spec allows GSA-approved modular vaults meeting it as one vault construction method.

See Perimeter Construction & Vaults

Acceptance test

The test of a complete IDS required before operational use and before accreditation, including motion walk tests, high security switch tests and tamper tests on every equipment cover (Tech Spec 7.D.3).

See Intrusion Detection & UL 2050 / Extent 3

Access control system ACS

The electronic or mechanical system that controls SCIF entry during occupied hours; automated systems use at least two technologies (badge, PIN or biometric) and are not approved for securing an unoccupied SCIF (ICS 705-1).

See Access Control, Identity & Hirsch

Accreditation

The AO's formal written approval that a facility meets physical, technical and procedural standards for SCI; ICS 705-2 calls it the beginning of a life-cycle process of monitoring and re-evaluation.

See Accreditation Lifecycle

Accrediting Official AO

The single named official to whom an IC element head delegates authority to accredit, re-accredit and de-accredit SCIFs (ICD 705); the AO approves the design concept, CSP and final design but may never be the waiver official.

See Roles & Responsibilities

Alarmed room

A system type on the UL CS-ASD-NISS form for a room given alarm protection at Extent 3, or at Extent 5 with prior CSA approval.

See Intrusion Detection & UL 2050 / Extent 3

Anti-passback

An access control feature that blocks re-entry without a logged exit, in hard (deny), soft (allow and alarm) or timed forms; it is an industry feature, not a Tech Spec requirement.

See Access Control, Identity & Hirsch

Approved Products List APL

GSA's FIPS 201 Evaluation Program list of tested PACS infrastructure, validation systems, PIV readers and card stock; an APL listing is not SCIF approval.

See Access Control, Identity & Hirsch

Architectural shielding

RF shielding built from foil, metalized fabric or foil-backed wallboard applied over drywall; it is the Tech Spec's foil-backed wallboard or approved R-Foil path and is highly workmanship-dependent.

See RF Shielding, Penetrations & Installer Methods

Arm / disarm

The two IDS operating modes, formerly called secure and access; armed mode sends any intrusion to the monitoring station, and in disarmed mode tamper and emergency-exit circuits stay active (Tech Spec 7.B).

See Intrusion Detection & UL 2050 / Extent 3

ASTM E336

Field test method for airborne sound attenuation between rooms in buildings; it measures the as-built condition, including flanking paths, and yields NIC.

See Acoustics & Sound Masking

ASTM E413

Classification standard that converts sound test data into single-number ratings such as STC from laboratory data and NIC from field data.

See Acoustics & Sound Masking

ASTM E90

Laboratory test method for airborne sound transmission loss of partitions and building elements; it is the basis of published STC ratings for walls, doors and windows.

See Acoustics & Sound Masking

Authority Having Jurisdiction AHJ

The official, often the fire marshal or building official, who enforces building, fire, life-safety and accessibility codes; every SCIF perimeter door must comply with codes as the AHJ determines (Tech Spec 3.E.5).

See Penetrations, Utilities & Life Safety

Authority to Operate ATO

A cybersecurity authorization under the Risk Management Framework required before an IDS host connects to a U.S. Government network; it is separate from facility accreditation.

See Intrusion Detection & UL 2050 / Extent 3

B

Balanced magnetic switch BMS

A magnetic door-position switch designed to resist defeat; UFC 4-010-05 states that UL 634 Level 2 rated switches only include balanced magnetic switches that pass additional performance testing.

See Intrusion Detection & UL 2050 / Extent 3

Bell 131-B2

A World War II Bell Telephone mixing device whose electrical spikes, seen on an oscilloscope, revealed plain text and led to the discovery of compromising emanations.

See History of TEMPEST & Shielding Specs

BLACK

Equipment, wiring and signals that carry only unclassified or properly encrypted information; building power, telephones, the unclassified LAN, fire alarm, IDS and ACS circuits are normally BLACK.

See RED/BLACK, TEMPEST & EMI Filters

Black-label container

A pre-1990 GSA security container with a silver label and black letters that cannot be recertified; black-label Class 1–4 cabinets became obsolete on 1 October 2024, and Class 5 and 6 follow by 1 October 2028.

See Doors, Locks & Security Containers

Bleeder resistor

A resistor that drains stored charge from filter capacitors after power is removed; technicians still verify with a meter and a shorting stick before touching a filter.

See RED/BLACK, TEMPEST & EMI Filters

Bypass keyway

A key override on a primary SCIF door's access control device for use only when the access control system fails; removing the cylinder must not expose the primary lock mechanism.

See Doors, Locks & Security Containers

C

Cam-lift hinge

A hinge that raises the door as it opens; UFC 4-010-05 requires perimeter door hinges reinforced to at least 7 gauge and cam-lift for acoustical door assemblies.

See Doors, Locks & Security Containers

Catastrophic failure plan

A DoD accreditation package document describing actions if security systems fail; FFC Section E asks whether the AO has approved one.

See Accreditation Lifecycle

Center for Development of Security Excellence CDSE

DCSA's security training organization, which publishes SCI and SAP physical security student guides and courses such as SA501.

See Governance & Document Hierarchy

Certified TEMPEST Technical Authority CTTA

The qualified government official who reviews SCIF plans and the TEMPEST Checklist, determines whether countermeasures such as RF shielding, filters or dielectric breaks are needed, and documents recommendations for the AO.

See Roles & Responsibilities

Chief of Mission (COM) authority

The ambassador's authority over U.S. executive-branch personnel abroad; SCIFs under COM authority must meet both ICD 705 and OSPB standards published in 12 FAH-6.

See Facility Types, Modes & Overseas Categories

Class 5 security container

A GSA-approved container rated for 10 minutes of forced entry, 30 minutes of covert entry and 20 hours of surreptitious entry, used for classified material, weapons and sensitive items.

See Doors, Locks & Security Containers

Class 5-V vault door

The AA-D-600D security vault door fitted with an FF-L-2740B lock for national security information; the Tech Spec requires a GSA-approved Class 5 vault door on every vault.

See Doors, Locks & Security Containers

Class 6 security container

A GSA-approved container for classified information with no forced-entry rating but 30 minutes of covert and 20 hours of surreptitious entry resistance.

See Doors, Locks & Security Containers

Cleared American Guard CAG

A U.S. citizen guard holding at least a SECRET clearance who screens people and materials at an overseas SCIF construction access control point.

See Construction Security & Build Sequence

Closed area

The legacy NISPOM term for a contractor area approved to hold collateral classified material outside containers; 32 CFR Part 117 replaced it with "open storage area," and it is not a SCIF.

See Facility Types, Modes & Overseas Categories

Closed storage

A SCIF accreditation in which all SCI is stored in GSA-approved security containers when not in use; the alarm response time inside the U.S. is 15 minutes.

See Facility Types, Modes & Overseas Categories

CNSSAM TEMPEST/1-13

The CNSS advisory memorandum on RED/BLACK installation guidance, listed publicly as dated 17 January 2014; it is marked U//FOUO, is not publicly releasable, and reaches projects through the CTTA.

See RED/BLACK, TEMPEST & EMI Filters

CNSSI 5006, 5002 and 5000

CNSS telephone security instructions referenced by the Fixed Facility Checklist: 5006 (TSG-6) for approved telephones and disconnect devices, 5002 (TSG-2) for computerized telephone systems, and 5000 for VoIP systems.

See PEDs, Wireless Detection, Telecom & CCTV

CNSSI 7000

TEMPEST Countermeasures for Facilities (May 2004), the CNSS instruction on selecting facility TEMPEST countermeasures and defining inspectable space; it is distribution-restricted and not reproduced publicly.

See RED/BLACK, TEMPEST & EMI Filters

CNSSI 7003

The CNSS instruction on Protected Distribution Systems for unencrypted classified signal lines that pass through areas of lesser classification or control.

See DISA Traditional Security STIG & PDS

CNSSP 300

National Policy on Control of Compromising Emanations (April 2004), the national TEMPEST policy that DoD implements through DoDI 8523.01; it is not reproduced publicly.

See RED/BLACK, TEMPEST & EMI Filters

Cognizant Security Authority CSA

In SCI usage, the official with authority over all aspects of a security program who ensures re-evaluations and concurs on co-use; in NISPOM usage, CSA means Cognizant Security Agency (DoD, DOE, NRC, ODNI or DHS).

See Roles & Responsibilities

Committee on National Security Systems CNSS

The interagency body that issues national security system policies (CNSSP), instructions (CNSSI) and advisory memoranda (CNSSAM), including TEMPEST and telephone security guidance.

See RED/BLACK, TEMPEST & EMI Filters

Common Access Card CAC

DoD's PIV-compliant smart card and the default SCIF and SAPF access control credential in UFC 4-010-05.

See Access Control, Identity & Hirsch

Compartmented Area CA

An area, room or set of rooms within a SCIF that separates compartments or programs; Types I, II and III are approved by the AO with the CA Program Manager's concurrence, with no spin-dial locks and no independent alarm system.

See Facility Types, Modes & Overseas Categories

Compromising emanations CE

Unintentional radiated or conducted signals that, if intercepted and analyzed, could disclose the information being processed.

See RED/BLACK, TEMPEST & EMI Filters

Concept approval

DoD approval, granted by a Service CSA or senior intelligence official, validating the need for a new SCIF; proof of sponsorship is a SCIF number or written concept approval (UFC 4-010-05 2-2.1).

See Accreditation Lifecycle

Construction Security Plan CSP

The project security plan developed by the SSM and approved by the AO that covers document control, personnel, site access, materials and inspections; no construction contract is awarded without it.

See Construction Security & Build Sequence

Construction Surveillance Technician CST

A cleared person who supplements site access controls and monitors construction and workers when the AO requires it; CSTs working outside the U.S. hold U.S. TOP SECRET clearances.

See Construction Security & Build Sequence

Continuous operation

A SCIF staffed and operated 24 hours a day, seven days a week; in DoD, changing from continuous operation to open or closed storage requires re-accreditation.

See Facility Types, Modes & Overseas Categories

Contractor Special Security Officer CSSO

In SCI usage, the contractor counterpart to the SSO who runs a contractor SCIF's security program; in SAP usage, the same acronym means Contractor SAP Security Officer.

See Roles & Responsibilities

Co-Use Agreement CUA

The signed agreement, on the Tech Spec co-use form, that lets a tenant use a host's accredited SCIF under the host's accreditation; it is required for each contractor effort and before SAP enters a SCIF.

See Accreditation Lifecycle

CRZH

UL's listing category for National Industrial Security Systems, held by alarm service companies that install, service and certify UL 2050 systems.

See Intrusion Detection & UL 2050 / Extent 3

CRZM

UL's listing category for national industrial security monitoring stations, including National Industrial Monitoring Stations.

See Intrusion Detection & UL 2050 / Extent 3

CS-ASD-NISS

UL's Alarm System Description form for National Industrial Security Systems, completed by the alarm company for each protected area; the CSA signs items needing prior approval, such as Extent 5 or data-network transmission.

See Intrusion Detection & UL 2050 / Extent 3

Cutoff frequency

The frequency below which a waveguide will not propagate a wave; for a rectangular guide it equals c/2a, and fields below it decay exponentially along the tube.

See RF Shielding, Penetrations & Installer Methods

CVSG

UL's mercantile security alarm service category; a CVSG certificate can show "Extent 3" but is not a UL 2050 certificate.

See Intrusion Detection & UL 2050 / Extent 3

D

DAC

DIA's SCI accreditation office, described in DoDM 5105.21 Vol. 2 as the sole accrediting authority for physical and TEMPEST security of DoD permanent SCI facilities outside NSA, NGA and NRO cognizance.

See Governance & Document Hierarchy

DCID 6/9

The Director of Central Intelligence Directive on SCIF physical security that ICD 705 rescinded on 26 May 2010; it is historical only.

See History of TEMPEST & Shielding Specs

De-accreditation

Formal notification to the DNI, through the IC SCIF Repository, that a facility is no longer accredited; a SCIF de-accredited but controlled at the SECRET level for less than one year may be re-accredited.

See Accreditation Lifecycle

Defense Counterintelligence and Security Agency DCSA

The DoD agency that administers the National Industrial Security Program and approves contractor open storage areas and their IDS; it does not accredit SCIFs.

See Governance & Document Hierarchy

Delayed egress

Exit hardware that holds a door for a set time after an exit attempt; UFC 4-010-05 recommends it for SCIF emergency exits with NFPA 101 compliance, only where the AHJ and code permit.

See Penetrations, Utilities & Life Safety

Dielectric break

A short, listed non-conductive section in a metal pipe, conduit or duct that interrupts a conductive path across the perimeter; it is installed when the CTTA recommends it (Tech Spec 3.G.2).

See RF Shielding, Penetrations & Installer Methods

DoD Lock Program

The NAVFAC Engineering and Expeditionary Warfare Center program that serves as DoD's technical authority for locks, safes, vaults, seals and containers protecting national security information and AA&E.

See Doors, Locks & Security Containers

DoDM 5105.21

DoD's three-volume SCI Administrative Security Manual; Volume 2 (Change 2, effective 2 November 2020) covers SCIF physical security, visitor control and technical security.

See Governance & Document Hierarchy

DoDM 5205.07

DoD's Special Access Program Security Manual, consolidated and effective 17 January 2025, which cancelled Volumes 1–3 and moved SAPF physical security into Section 15.

See Governance & Document Hierarchy

Dual-technology sensor

A motion sensor that combines two detection methods, such as PIR and microwave; it is allowed in a SCIF only if each technology reports alarms independently (Tech Spec 7.A.3.a(4)).

See Intrusion Detection & UL 2050 / Extent 3

Duress alarm

A signal that initiates an alarm at the central monitoring station with no audible or visual signal in the protected area (UFC 4-010-05 3-4.16).

See Intrusion Detection & UL 2050 / Extent 3

E

Electromagnetic interference EMI

Unwanted electromagnetic energy from functional, incidental or natural sources that couples into circuits by conduction or radiation; filters, isolation and shielding control it.

See RED/BLACK, TEMPEST & EMI Filters

Electromechanical combination lock

A dial-operated lock with electronic combination processing, such as the Kaba Mas X-10 or S&G 2740B; every lock currently approved under FF-L-2740B is of this type.

See Doors, Locks & Security Containers

Emergency action plan

The SCIF emergency plan required among accreditation documents; it must address IDS failure (Tech Spec 7.A.1.e), and DoD requires it to be exercised annually.

See Accreditation Lifecycle

Emergency egress-only door

A SCIF perimeter door used only for emergency exit, with no exterior hardware, an FF-L-2890 exit device and an alarm active 24/7 with a local audible annunciator.

See Doors, Locks & Security Containers

Entry delay

The time allowed at the primary entrance to change the IDS mode before an alarm; it must be 30 seconds or less (Tech Spec 7.A.3.a(6)).

See Intrusion Detection & UL 2050 / Extent 3

Executive Order 13526

The order governing classified national security information; access requires a favorable eligibility determination, a signed nondisclosure agreement and a need-to-know.

See Access Control, Identity & Hirsch

Extent 3

The UL 2050 extent of protection required for every SCIF and SAPF IDS and the standard level for NISPOM alarmed areas; the best public description is contacts on all probable entry points plus motion in probable intruder paths.

See Intrusion Detection & UL 2050 / Extent 3

Extent 5

A reduced UL extent based on patrolling employees and CSA approval of security-in-depth; it needs CSA authorization and is not an option under ICD 705.

See Intrusion Detection & UL 2050 / Extent 3

Extent of protection

The UL designation used to describe the amount of alarm protection installed to protect a particular area, room or container.

See Intrusion Detection & UL 2050 / Extent 3

F

Federal Identity, Credential, and Access Management FICAM

The federal identity framework under which GSA's FIPS 201 Evaluation Program tests and lists PACS components and PIV card stock.

See Access Control, Identity & Hirsch

FED-STD-809

The federal standard for neutralizing and repairing GSA containers; NISPOM cites it for the rule that no IDS sensors are installed on GSA-approved security containers.

See Doors, Locks & Security Containers

FED-STD-832

GSA's Construction Methods and Materials for Vaults (1 September 2002), which defines Class A, B and C vaults and is the typical reference for collateral vaults.

See Perimeter Construction & Vaults

FF-L-2740B

The federal specification for electromechanical combination locks protecting classified material on containers, vault doors and SCIF door deadbolts; current approved models are the Kaba Mas X-10 and S&G 2740B.

See Doors, Locks & Security Containers

FF-L-2890C

The federal specification (22 February 2019) for pedestrian door lock extensions, Types I–X, covering primary, secondary, unoccupied-room and exit-only doors with code-compliant egress.

See Doors, Locks & Security Containers

FF-L-2937

The federal specification for a mechanical combination lock used mainly for AA&E; it is not the lock for SCIF doors or classified containers.

See Doors, Locks & Security Containers

Finger stock

Spring contact strips, typically beryllium copper, that an RF door's knife edge seats into to keep the shield continuous; they must stay clean, unpainted and undamaged.

See RF Shielding, Penetrations & Installer Methods

FIPS 140-2 / FIPS 140-3

NIST standards for validating cryptographic modules; FIPS 140-2 validations move to the CMVP Historical List on 21 September 2026.

See Intrusion Detection & UL 2050 / Extent 3

FIPS 197 AES

The Advanced Encryption Standard algorithm; the Tech Spec allows it for UL 1610 listed PCUs and, with AO approval, for LAN/WAN transmission.

See Intrusion Detection & UL 2050 / Extent 3

FIPS 201

The federal Personal Identity Verification standard; FIPS 201-3 (January 2022) is the current revision.

See Access Control, Identity & Hirsch

Fixed Facility Checklist FFC

The Tech Spec form, in Sections A–I, that documents a SCIF's physical, technical and procedural security for accreditation; a filled-in FFC may be CUI or classified.

See Accreditation Lifecycle

Fortuitous conductor

Metal not intended to carry signals, such as conduit, pipe, duct, cable armor or a steel strength member, that can nevertheless carry signals across a boundary.

See RED/BLACK, TEMPEST & EMI Filters

Furred wall

A secondary stud wall built as a stand-off from a treated perimeter wall so utilities can be distributed without penetrating the acoustic or RF assembly (Tech Spec 3.G.5).

See Perimeter Construction & Vaults

G

Government Contractor Monitoring Station GCMS

A contractor-operated station that monitors industrial security systems; under the UL 2050 Edition 5 briefing, monitored systems must be within 240 miles of it.

See Intrusion Detection & UL 2050 / Extent 3

Government SAP Security Officer GSSO

The government facility-level official who maintains a SAPF's security program and coordinates with program security officials.

See Roles & Responsibilities

GSA-approved security container

A container certified by GSA and labeled by class, such as Class 5 or Class 6; red labels can be recertified, while black labels are being phased out.

See Doors, Locks & Security Containers

H

High Security Switch HSS

A UL 634 listed door switch rated Level I or Level II; new SCIF and SAPF accreditations require Level II, and the alarm must trip before the door opens beyond its own thickness.

See Intrusion Detection & UL 2050 / Extent 3

High-altitude electromagnetic pulse HEMP

A very large, fast incoming electromagnetic pulse addressed by MIL-STD-188-125; HEMP protection is a different threat model from TEMPEST and is not required for SCIF accreditation.

See RF Shielding, Penetrations & Installer Methods

Honeycomb vent

An array of small hexagonal waveguide cells that passes air while blocking RF, bonded into HVAC ducts where they cross an RF shield.

See RF Shielding, Penetrations & Installer Methods

HSPD-12

Homeland Security Presidential Directive 12, which requires a common, secure, interoperable identity credential for federal employees and contractors, implemented through PIV.

See Access Control, Identity & Hirsch

I

IC element head

The head of an Intelligence Community element, who holds original authority to accredit and de-accredit SCIFs and grant waivers, and who delegates AO authority to a single named official.

See Roles & Responsibilities

IC SCIF Repository

The NCSC-managed inventory of SCIF accreditation, waiver, re-evaluation and de-accreditation data.

See Accreditation Lifecycle

IC Tech Spec

Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, the build-to document for ICD 705; the current public version is 1.5.1 (26 July 2021).

See Governance & Document Hierarchy

ICD 705

The DNI directive (26 May 2010) requiring that SCI be handled only in accredited SCIFs built to uniform standards for reciprocal use, and setting accreditation and waiver authority.

See Governance & Document Hierarchy

ICS 705-1

Physical and Technical Security Standards for Sensitive Compartmented Information Facilities (17 September 2010), the IC standard for perimeter, IDS, access control, TEMPEST, acoustic and PED requirements.

See Governance & Document Hierarchy

ICS 705-2

Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information Facilities (22 December 2016), covering accreditation criteria, re-evaluation, de-accreditation, reciprocity and co-use.

See Governance & Document Hierarchy

Insertion loss

The reduction in power delivered to a load when a filter is inserted, expressed in decibels and measured under MIL-STD-220.

See RED/BLACK, TEMPEST & EMI Filters

Inspectable space

The three-dimensional space around classified processing within which TEMPEST exploitation is not considered practical or legal authority exists to identify and remove it; the CTTA determines it.

See RED/BLACK, TEMPEST & EMI Filters

Interim accreditation

A provisional accreditation that an AO may issue pending documentation or final inspection, expressly provided for overseas SCIFs in Tech Spec Chapters 4 and 5.

See Accreditation Lifecycle

Interlocked vestibule (mantrap)

A two-door entry in which only one door can open at a time; model codes do not currently address interlocks, so each application needs AHJ approval and must never block egress.

See PEDs, Wireless Detection, Telecom & CCTV

Intrusion detection equipment IDE

The sensors and devices that make up an IDS; since v1.3 the Tech Spec refers to "IDE sensor points" rather than zones.

See Intrusion Detection & UL 2050 / Extent 3

Intrusion detection system IDS

The alarm system that detects unauthorized human entry into an unoccupied SCIF, installed to UL 2050 Extent 3 with its premise control unit inside the SCIF.

See Intrusion Detection & UL 2050 / Extent 3

J

JAFAN 6/9

The legacy Joint Air Force–Army–Navy manual for SAP facility physical security; new SAPFs are not designed to it, since current SAPF construction follows the IC Tech Spec through DoDM 5205.07.

See Governance & Document Hierarchy

K

Knife-edge door

An RF-shielded door whose metal edge seats into rows of finger stock; ETS-Lindgren's DKE door uses a bronze double knife-edge with beryllium copper finger stock.

See RF Shielding, Penetrations & Installer Methods

kVAR

Reactive power; high-capacitance EMI filters can create enough kVAR to destabilize a generator or prevent it from starting, so low-kVAR filter designs exist for backed-up SCIF power.

See RED/BLACK, TEMPEST & EMI Filters

L

Leakage current

Continuous 60 Hz current that flows to ground through a filter's line-to-case capacitors; it adds up across filters and can nuisance-trip an upstream GFCI.

See RED/BLACK, TEMPEST & EMI Filters

Letter of accreditation

The AO's written accreditation identifying the SCIF, its type, its effective date, a statement of compliance and any approved waivers (ICS 705-2).

See Accreditation Lifecycle

Limited Exclusion Area LEA

A historical MIL-HDBK-232A term for the area that protects RED systems to a level equivalent to the information they contain.

See History of TEMPEST & Shielding Specs

Line security

Electronic supervision and/or encryption of the alarm path from the protected area to the monitoring station to detect tampering; UL certificates record it as None, Standard or Encrypted.

See Intrusion Detection & UL 2050 / Extent 3

Line side / load side

The unfiltered ("dirty") input side of a filter, whose conductors terminate on the unprotected side and never cross, and the filtered ("clean") output side, whose conductors are the only ones that continue into the room. A rule about conductors, not about which way the housing projects.

See RED/BLACK, TEMPEST & EMI Filters

M

Maintenance mode

An IDS state, started only by SCI-cleared administrators or the SSO, in which points may be shunted or masked; the monitoring station is notified and logs the event (Tech Spec 7.B.4).

See Intrusion Detection & UL 2050 / Extent 3

Man-bars

Steel bars of at least ½-inch diameter, welded 6 inches on center, that protect perimeter duct and vent openings over 96 square inches unless one dimension is under 6 inches (Tech Spec 3.G.7).

See Penetrations, Utilities & Life Safety

MIL-HDBK-1195

Radio Frequency Shielded Enclosures, a historical Navy handbook that states it shall not be used as a reference for procurement of facilities construction; it is useful as background only.

See History of TEMPEST & Shielding Specs

MIL-HDBK-232A

RED/BLACK Engineering-Installation Guidelines, a historical DoD handbook on grounding, bonding, shielding, separation and filtering; current RED/BLACK practice follows CNSS guidance as applied by the CTTA.

See History of TEMPEST & Shielding Specs

MIL-STD-188-125

The DoD standard for HEMP protection of ground-based facilities performing critical, time-urgent missions, with separate parts for fixed and transportable systems.

See RF Shielding, Penetrations & Installer Methods

MIL-STD-220

The test method standard for measuring filter insertion loss; datasheet values are relative to 50-ohm source and load impedances, so installed performance can differ.

See RED/BLACK, TEMPEST & EMI Filters

N

NACSIM 5000

TEMPEST Fundamentals (1 February 1982), an early national document that framed the separation of RED and BLACK circuits; it is historical.

See History of TEMPEST & Shielding Specs

National Counterintelligence and Security Center NCSC

The ODNI center, led by the D/NCSC, that issues the ICS 705 standards and IC Tech Spec and manages the IC SCIF Repository.

See Governance & Document Hierarchy

National Industrial Monitoring Station NIMS

A UL CRZM-listed station that monitors national industrial security systems, including systems more than 240 miles away under the Edition 5 rules.

See Intrusion Detection & UL 2050 / Extent 3

Nationally Recognized Testing Laboratory NRTL

A laboratory recognized under 29 CFR 1910.7; NISPOM requires IDS installation by an alarm company certified by an NRTL and a valid NRTL certificate.

See Intrusion Detection & UL 2050 / Extent 3

Need-to-know

A determination that a person requires specific classified information; it is required in addition to eligibility and a signed nondisclosure agreement.

See Access Control, Identity & Hirsch

NFPA 101

The Life Safety Code, which governs egress and drives SCIF door hardware, panic hardware and delayed-egress decisions made with the AHJ.

See Penetrations, Utilities & Life Safety

NISPOM 32 CFR Part 117

The federal rule for cleared contractors that replaced DoD 5220.22-M on 24 February 2021; §117.15 covers classified storage, open storage areas and intrusion detection.

See Governance & Document Hierarchy

Noise Isolation Class NIC

A field-measured single-number rating of sound isolation between spaces; the Tech Spec equates NIC 40 with Sound Group 3 and NIC 45 with Sound Group 4.

See Acoustics & Sound Masking

Nonconductive union

An insulating fitting inside the perimeter that breaks a metal conduit path at a penetration, an alternative to grounding the conduit when the TEMPEST review requires treatment (UFC 4-010-05 3-4.11.2).

See Penetrations, Utilities & Life Safety

NSA 94-106

National Security Agency Specification for Shielded Enclosures (24 October 1994), a FOUO-marked specification released under FOIA in 2000; it is historical and not a current requirement.

See History of TEMPEST & Shielding Specs

NSTISSAM TEMPEST/2-95

RED/BLACK Installation Guidance (12 December 1995), a FOIA-released predecessor to today's restricted CNSS RED/BLACK guidance; it is historical and useful for concepts only.

See History of TEMPEST & Shielding Specs

NSTISSI 7000

TEMPEST Countermeasures for Facilities (29 November 1993), superseded by CNSSI 7000 in May 2004; the redacted FOIA release is useful for concepts only.

See History of TEMPEST & Shielding Specs

O

On-hook security

Protection against a telephone passing room audio while hung up, provided by CNSSI 5006 (TSG-6) approved telephones or disconnect devices.

See PEDs, Wireless Detection, Telecom & CCTV

Open storage

A SCIF accreditation allowing SCI to be kept outside GSA containers within the SCIF; inside the U.S., alarm response is 15 minutes with Security-in-Depth or 5 minutes without it.

See Facility Types, Modes & Overseas Categories

Open storage area

The 32 CFR Part 117 term, replacing "closed area," for a DCSA-approved contractor space holding collateral classified material outside containers.

See Facility Types, Modes & Overseas Categories

Overseas Security Policy Board (OSPB) standards

Department of State security standards, published in 12 FAH-6, that apply alongside ICD 705 to SCIFs under Chief of Mission authority; the more stringent standard governs.

See Facility Types, Modes & Overseas Categories

P

Periodic re-evaluation

The CSA-driven review of an accredited SCIF based on program sensitivity, threat, modifications and past security performance, or at least every five years (ICS 705-2).

See Accreditation Lifecycle

Personal Identity Verification PIV

The federal smart-card credential defined by FIPS 201; card-plus-PIN or card-plus-PIN-plus-biometric configurations fit the SCIF two-technology entry rule.

See Access Control, Identity & Hirsch

Physical access control system PACS

The federal term for an electronic access control system, typically tied to PIV credentials and bought from the GSA FIPS 201 APL.

See Access Control, Identity & Hirsch

Physically Protected Space

A locked room with fixed walls, floor and ceiling, open only to SCI-cleared staff, with UL 437 key cylinders and a UL Extent 3 alarm unless staffed 24 hours; it houses a networked IDS host (Tech Spec 7.A.3.c).

See Intrusion Detection & UL 2050 / Extent 3

Portable electronic device PED

Any portable device that can record, store or transmit, such as a phone, smartwatch, fitness tracker or laptop; PEDs are prohibited in SCIFs unless approved under Tech Spec Chapter 10.

See PEDs, Wireless Detection, Telecom & CCTV

Pre-Construction Checklist

A Tech Spec form added in v1.5 that gives the AO project information, points of contact and site security details so requirements can be set early.

See Accreditation Lifecycle

Premise control unit PCU

The IDS control panel that monitors sensors and reports to the monitoring station; it must be located inside the SCIF, and only SCIF personnel may change its modes.

See Intrusion Detection & UL 2050 / Extent 3

Primary door

The single main entrance to a SCIF, fitted with an FF-L-2890 deadbolt, an FF-L-2740 combination lock and an AO-approved access control device.

See Doors, Locks & Security Containers

Program Security Officer PSO

A government SAP security official for a program; UFC 4-010-05 notes the Navy routes SAPF concept approval through the PSO and the government program manager.

See Roles & Responsibilities

Protected distribution system PDS

A wireline or fiber-optic distribution system used to transmit unencrypted classified national security information through an area of lesser classification or control; UFC 4-010-05 advises avoiding PDS whenever possible.

See DISA Traditional Security STIG & PDS

Protected side

The secure, inside face of a perimeter door or wall, where hinge pins, hardware, wiring and devices belong.

See Doors, Locks & Security Containers

R

Radio frequency interference RFI

Electromagnetic interference in the radio frequency range; EMI/RFI filters and shields keep conducted and radiated RF from entering or leaving a shielded room.

See RF Shielding, Penetrations & Installer Methods

RCET

The Tech Spec Chapter 10 term paired with PEDs, from the chapter title covering portable electronic devices with recording capabilities and embedded technologies; Chapter 10 assigns low, medium and high risk levels.

See PEDs, Wireless Detection, Telecom & CCTV

Re-accreditation

A new accreditation required for major modifications or changes in program sensitivity or threat, and in DoD for perimeter, storage-mode or continuous-operation changes.

See Accreditation Lifecycle

Reciprocity

The principle that a SCIF accredited by one IC element without waivers is accepted for use by all IC elements; any waiver removes mandatory reciprocal use.

See Governance & Document Hierarchy

RED

Equipment, wiring and signals that carry unencrypted classified information.

See RED/BLACK, TEMPEST & EMI Filters

RED/BLACK concept

Physical and electrical separation of RED circuits and equipment from BLACK so classified signals cannot couple onto anything that leaves the controlled area; current installation guidance is restricted and applied by the CTTA.

See RED/BLACK, TEMPEST & EMI Filters

Red-label container

A GSA security container with a silver label and red letters that GSA-certified inspectors can recertify after neutralization under FED-STD-809.

See Doors, Locks & Security Containers

Removal tamper

A tamper feature that alarms when a switch is pried off its mounting surface; it depends on a mechanical mount and is wired to a 24-hour circuit.

See Intrusion Detection & UL 2050 / Extent 3

Request-to-exit device REX

A motion sensor or switch that unlocks or shunts an access-controlled door for egress; it is mounted inside and must not bypass IDS door switches without an AO-approved design.

See Access Control, Identity & Hirsch

Response force

The personnel who respond to SCIF alarms within 5 or 15 minutes and protect the space until an SCI-indoctrinated person arrives, within 60 minutes under UL 2050 or the AO-approved time.

See Intrusion Detection & UL 2050 / Extent 3

Restricted area

A NISPOM controlled access area for classified material that cannot be protected by usual safeguards during working hours but can be stored in an approved repository after hours (32 CFR 117.3).

See Facility Types, Modes & Overseas Categories

RF shielding

A conductive enclosure of foil, sheet steel or welded steel, with RF doors, filters and waveguides, that attenuates radio frequency energy; a SCIF gets it at the CTTA's direction.

See RF Shielding, Penetrations & Installer Methods

S

SAP compartmented area SAPCA

The SAP equivalent of a Compartmented Area inside a SAPF or SCIF; a Co-Use Agreement is required before one is created in a SCIF.

See Facility Types, Modes & Overseas Categories

SAPF Accrediting Official SAPF-AO

The official appointed in writing by the CA SAPCO or designee who approves SAPF preconstruction plans and inspects, accredits, re-accredits and de-accredits SAPFs (DoDM 5205.07).

See Roles & Responsibilities

Secondary door

A SCIF perimeter door used for both entry and exit that is not the primary door; it uses an FF-L-2890 egress device, and its access control must be deactivated when the SCIF is unoccupied.

See Doors, Locks & Security Containers

Secure Working Area SWA

An accredited area for discussing, handling or processing SCI where SCI is not stored; it is alarmed with a 15-minute initial response.

See Facility Types, Modes & Overseas Categories

Security Environment Threat List SETL

The Department of State threat list whose technical threat rating sets overseas SCIF construction Categories I–III; country-to-category associations are not published.

See Facility Types, Modes & Overseas Categories

Security-in-Depth SID

Layered, complementary factors that raise the chance of detection before a SCIF is penetrated; it is optional in the U.S., where it can permit a 15-minute open storage response, and mandatory overseas.

See Facility Types, Modes & Overseas Categories

Sensitive Compartmented Information SCI

Classified national intelligence protected within formal access control systems established by the DNI.

See Start Here: How SCIF Security Fits Together

Sensitive Compartmented Information Facility SCIF

An accredited area where SCI is processed, stored, used or discussed.

See Start Here: How SCIF Security Fits Together

SF 700

The Security Container Information form recording a container or door, its lock and the people to contact if it is found open; the combination portion is sealed and kept separately.

See Doors, Locks & Security Containers

SF 701

The Activity Security Checklist used for the end-of-day check confirming classified material is secured and the work area is locked.

See Doors, Locks & Security Containers

SF 702

The Security Container Check Sheet that logs each opening, closing and check of vaults, secure rooms including the SCIF door, and containers.

See Doors, Locks & Security Containers

Shielding effectiveness

A shield's ability to screen electric, magnetic and plane-wave fields, measured for enclosures by methods such as IEEE 299.

See RF Shielding, Penetrations & Installer Methods

Shunt / mask

Temporarily excluding IDS sensor points from alarm reporting during maintenance; shunted points display at the monitoring station and re-arm at the next armed-to-disarmed transition.

See Intrusion Detection & UL 2050 / Extent 3

Single point of entry

The planned single location where power and signal utilities cross the perimeter, which simplifies sealing, TEMPEST treatment and inspection (Tech Spec 3.G.4).

See Penetrations, Utilities & Life Safety

Site Security Manager SSM

The person responsible for security during SCIF planning, design and construction, who develops the CSP, inspects the work and reports violations to the AO within three business days.

See Roles & Responsibilities

Sound Group 3

The default SCIF perimeter acoustic level, STC 45 or better, at which loud speech inside can be faintly heard but not understood outside.

See Acoustics & Sound Masking

Sound Group 4

The acoustic level, STC 50 or better, for conference, VTC and other rooms where amplified audio is used.

See Acoustics & Sound Masking

Sound masking

AO-approved noise or vibration applied to leakage paths when construction is inadequate; the generator is permanently installed inside the SCIF with no AM/FM receiver and recording disabled.

See Acoustics & Sound Masking

Sound Transmission Class STC

A single-number laboratory rating of how well a wall, door or window blocks airborne sound, calculated from ASTM E90 data.

See Acoustics & Sound Masking

Special Access Program Facility SAPF

An accredited area for SAP material, built to the equivalent IC Tech Spec SCIF criteria and accredited by a SAPF-AO.

See Facility Types, Modes & Overseas Categories

Special Security Officer SSO

The official who manages the SCI security program for a SCIF, maintains SOPs and emergency plans, and initiates withdrawal of accreditation.

See Roles & Responsibilities

Special Security Representative SSR

The person who manages a facility's SCI security program day to day under the SSO's direction.

See Roles & Responsibilities

Standard operating procedures SOP

The written SCIF operating rules required among accreditation documents, covering matters such as end-of-day checks, visitors, alarm failures and PEDs.

See Accreditation Lifecycle

T

Tamper

Detection of opened equipment covers or interference with IDS devices; tamper signals annunciate immediately and continuously and stay active even when the IDS is disarmed.

See Intrusion Detection & UL 2050 / Extent 3

Technical surveillance countermeasures TSCM

Inspections to detect technical surveillance devices and hazards; TSCM may be required for new SCIFs or significant renovations, and practitioners quote the Tech Spec as limiting it to U.S. Government teams.

See Roles & Responsibilities

Telephone Security Group TSG

The group that historically developed telephone security standards, reported by a NITAAC vendor showcase to now be the National Telecommunications Security Working Group under CNSS; its standards appear as CNSSI 5000-series instructions and an approved endpoints list.

See PEDs, Wireless Detection, Telecom & CCTV

TEMPEST

An NSA covername, not an acronym, for the investigation, study and control of compromising emanations from equipment that processes classified information.

See RED/BLACK, TEMPEST & EMI Filters

TEMPEST Checklist

The Tech Spec form, also used as the FFC TEMPEST addendum, that gives the CTTA facts such as distance to the inspectable space boundary, radios within three meters of the perimeter, and signal and power lines that exit.

See RED/BLACK, TEMPEST & EMI Filters

TEMPEST Countermeasure Review TCR

The CTTA's documented evaluation of the TEMPEST Checklist with recommended countermeasures for the AO; some sources expand TCR as TEMPEST Countermeasure Requirements.

See RED/BLACK, TEMPEST & EMI Filters

Temporary SCIF T-SCIF

A SCIF accredited for a limited time to meet tactical, emergency or immediate operational needs; DoD approvals are valid for up to one year.

See Facility Types, Modes & Overseas Categories

Temporary Secure Working Area TSWA

An accredited area where SCI work is limited to less than 40 hours per month, with accreditation of 12 months or less and no SCI storage.

See Facility Types, Modes & Overseas Categories

Threat Categories I–III

The Tech Spec's overseas construction categories, based on the SETL technical threat rating and building vulnerability, ranging from Category I (critical or high technical threat, high-vulnerability buildings) to Category III (low and medium technical threat).

See Facility Types, Modes & Overseas Categories

True floor to true ceiling

Perimeter construction that runs from the structural slab to the underside of the floor or roof deck above rather than stopping at a drop ceiling or raised floor.

See Perimeter Construction & Vaults

Two-person integrity TPI

A control requiring at least two authorized persons to be present for a task; access control systems can support it with a two-person rule.

See Access Control, Identity & Hirsch

U

UFC 4-010-05

SCIF/SAPF Planning, Design, and Construction (26 May 2023), the DoD Unified Facilities Criteria that implements the Tech Spec for DoD projects and adds design detail.

See Governance & Document Hierarchy

UFGS 13 49 20.00 10

The DoD unified facilities guide specification for RFI/EMI shielding, which prohibits self-tapping screws for shield attachment and requires a filter on each power, data and signal line penetrating the enclosure.

See RF Shielding, Penetrations & Installer Methods

UL 1034

The UL standard for burglary-resistant electric locking mechanisms; SCIF access control strikes and electrified mortise locks must be UL 1034 approved, fail secure and positively engaging.

See Doors, Locks & Security Containers

UL 1076

The UL standard for proprietary burglar alarm units and systems; under the Tech Spec, a UL 1076 listed PCU must have FIPS 140-2 certified encryption.

See Intrusion Detection & UL 2050 / Extent 3

UL 1610

The UL listing path for central-station burglar alarm units; under the Tech Spec, a UL 1610 listed PCU may use FIPS 197 (AES) or FIPS 140-2 encryption.

See Intrusion Detection & UL 2050 / Extent 3

UL 2050

National Industrial Security Systems (Edition 6, 7 April 2025), the UL standard for installing, monitoring and servicing alarm systems that protect classified material, and the source of Extent 3.

See Intrusion Detection & UL 2050 / Extent 3

UL 2050 certificate

The National Industrial Security System certificate issued through a CRZH-listed alarm company, listing system type, extent, monitoring, line security and approved response time; it must be renewed after IDS changes.

See Intrusion Detection & UL 2050 / Extent 3

UL 294

The UL standard for access control system units such as card readers and controllers; an access control system does not replace a SCIF's IDS.

See Access Control, Identity & Hirsch

UL 437

The UL key lock standard cited for high-security key cylinders on the door of a Physically Protected Space housing a networked IDS host.

See Intrusion Detection & UL 2050 / Extent 3

UL 634

The UL standard for connectors and switches used with burglar alarm systems, including high security switches rated Level I or Level II.

See Intrusion Detection & UL 2050 / Extent 3

UL 639

The UL standard for intrusion-detection units such as PIR, microwave and dual-technology motion sensors required in SCIFs.

See Intrusion Detection & UL 2050 / Extent 3

UL 681

Installation and Classification of Burglar and Holdup Alarm Systems, which holds the extent-of-protection requirements that the UL 2050 form instructions reference.

See Intrusion Detection & UL 2050 / Extent 3

UL 827

Central-Station Alarm Services, the UL standard for central station construction, staffing and operation.

See Intrusion Detection & UL 2050 / Extent 3

UL Product iQ

UL's online certification directory, used to confirm CRZH alarm companies, CRZM monitoring stations and listed components.

See Intrusion Detection & UL 2050 / Extent 3

U.S. citizen / U.S. person

Workforce terms in the Tech Spec: SCIF design and construction should use U.S. companies with U.S. citizens but may use U.S. persons with AO mitigations, while IDS installation inside the U.S. requires U.S. citizens.

See Construction Security & Build Sequence

V

Vault

A storage room built to Tech Spec vault criteria or FED-STD-832, such as 8 inches of reinforced concrete or steel-lined construction, with a GSA-approved Class 5 vault door; vault doors cannot serve as day-access doors.

See Perimeter Construction & Vaults

Vestibule

An entry space at a SCIF door recommended to preclude visual observation and enhance acoustic protection; UFC 4-010-05 programs vestibule space at the primary entrance.

See Doors, Locks & Security Containers

Visual evidence of surreptitious penetration

The perimeter design goal that any hole, cut or patch would be noticeable on inspection, which is why walls are finished slab to slab and penetrations are sealed and finished.

See Perimeter Construction & Vaults

W

Waiver

An approved departure from a standard, granted by the IC element head or a single named senior official who may never be the AO; waivers are reported to the D/NCSC within 30 days and remove mandatory reciprocity.

See Accreditation Lifecycle

Walk test

The motion sensor test in which each trial is four steps at one step per second and the alarm must activate on at least three of every four trials (Tech Spec 7.D.3).

See Intrusion Detection & UL 2050 / Extent 3

Wall A / Wall B / Wall C

The Tech Spec perimeter wall types: Wall A (three layers of ⅝-inch wallboard) for closed storage, SWAs, continuous operation or open storage with SID, and Walls B (expanded metal) and C (plywood) for open storage without SID.

See Perimeter Construction & Vaults

Waveguide-beyond-cutoff WBC

A metal tube or cell sized so frequencies of concern fall below its cutoff, letting air, water or dielectric fiber pass while blocking RF; a metallic conductor through it defeats the effect.

See RF Shielding, Penetrations & Installer Methods

Wireless intrusion detection system WIDS

A passive RF sensor network that detects and locates transmitting cellular, Wi-Fi and Bluetooth devices; it cannot see powered-off devices.

See PEDs, Wireless Detection, Telecom & CCTV

Z

Z-duct

An offset acoustic duct penetration detail that limits sound transmission through the perimeter; UFC 4-010-05 notes that acoustic Z-ducts can increase the above-ceiling space requirement.

See Acoustics & Sound Masking