Directory · 344 sections

All sections

Every section title in the knowledge base, in module order. Each link opens the module at that section.

00Start Here: How SCIF Security Fits Together

  1. What a SCIF is (and what it is not)
  2. SCIF vs SAPF vs NISPOM open storage area vs GSA container
  3. The three things every accreditation proves
  4. The object model
  5. Object model reference table
  6. How the pieces flow from concept to re-evaluation
  7. Lifecycle states of a SCIF
  8. The document stack in one table
  9. Naming quirks: acronyms that mean two things
  10. Version and terminology traps
  11. Where a low-voltage integrator fits
  12. How to use this knowledge base

01Governance & Document Hierarchy

  1. The document hierarchy at a glance
  2. ICD 705: what the directive requires
  3. ICS 705-1: physical and technical security standards
  4. ICS 705-2: accreditation and reciprocal use
  5. The IC Tech Spec: purpose and applicability
  6. Tech Spec v1.5.1 chapter map
  7. Tech Spec version history
  8. Tech Spec forms and plans (Chapter 14)
  9. Reported 2025–2026 changes to SCIF requirements
  10. DoDM 5105.21: DoD's SCI security manual
  11. DoDM 5205.07 (2025) and legacy SAP standards
  12. 32 CFR Part 117 (NISPOM) and 32 CFR Part 2001
  13. DCSA's role, and what it does not do
  14. Cognizant Security Authorities for SCI at a glance
  15. UFC 4-010-05: DoD design criteria for SCIFs and SAPFs
  16. Reciprocity and waivers

02Roles & Responsibilities

  1. Roles at a glance: who produces and signs what
  2. IC element head and the Director, NCSC
  3. Accrediting Official (AO)
  4. Cognizant Security Authority (CSA)
  5. SAPF Accrediting Official and SAP security roles
  6. Site Security Manager (SSM)
  7. SSO, SSR and CSSO: running the accredited space
  8. Certified TEMPEST Technical Authority (CTTA)
  9. Construction surveillance technicians, cleared guards and escorts
  10. TSCM teams
  11. Sponsors, program managers and co-use tenants
  12. Designer of record (architect-engineer)
  13. General contractor responsibilities
  14. Low-voltage and IDS integrator responsibilities
  15. Authority Having Jurisdiction (AHJ) and life safety
  16. Role separation rules and common confusions

03Accreditation Lifecycle

  1. Accreditation is a lifecycle: the step table
  2. Sponsorship, concept approval and early AO coordination
  3. Site survey, risk assessment and the Pre-Construction Checklist
  4. TEMPEST Checklist and CTTA review
  5. Design approval and the Construction Security Plan
  6. Construction surveillance and the evidence trail
  7. Systems installation, testing and certificates
  8. Final Fixed Facility Checklist and operating documents
  9. Final inspection, TSCM and interim accreditation
  10. Accreditation issuance: what the letter says
  11. Continuous monitoring and periodic re-evaluation
  12. Modifications and re-accreditation triggers
  13. Waiver requests: package contents and consequences
  14. De-accreditation, withdrawal and re-use
  15. Co-Use Agreements: process and paperwork
  16. What to have ready at inspection

04Facility Types, Modes & Overseas Categories

  1. Facility types at a glance
  2. Closed storage SCIFs
  3. Open storage SCIFs
  4. Continuous operation SCIFs
  5. Secure Working Areas (SWA)
  6. Temporary Secure Working Areas (TSWA)
  7. Temporary, airborne, shipboard and prefabricated SCIFs
  8. Compartmented Areas and Second Party spaces
  9. Vaults
  10. Co-use, joint use and reciprocity
  11. IDS and alarm response by mode
  12. Security-in-Depth: definition and primary means
  13. What Security-in-Depth changes
  14. Inside vs outside the U.S.: three construction regimes
  15. Overseas threat Categories I–III

05Perimeter Construction & Vaults

  1. What the SCIF perimeter is and what it must do
  2. Physical protection vs. visual evidence of surreptitious penetration
  3. True floor to true ceiling: slab-to-slab construction
  4. Wall A, Wall B and Wall C specifications
  5. Choosing a wall type by storage mode
  6. Existing masonry, fire-retardant plywood and higher-STC walls
  7. RF and TEMPEST treatment of perimeter walls
  8. Ceilings and floors
  9. False ceilings and raised floors
  10. Utilities mounted on perimeter walls
  11. Windows: minimize, fix shut and protect
  12. The 18-foot rule for windows and daylighting
  13. When a vault is used
  14. Vault construction under Tech Spec 3.C.5
  15. Tech Spec vaults vs. FED-STD 832 Class A, B and C
  16. Common perimeter mistakes

06Doors, Locks & Security Containers

  1. The three SCIF perimeter door categories
  2. Requirements for every perimeter door
  3. Door fabrication requirements
  4. Roll-up, double-leaf and adjoining-SCIF doors
  5. FF-L-2740B combination locks and approved models
  6. FF-L-2890C pedestrian door device types
  7. Approved FF-L-2890 products and the revision question
  8. Electrified hardware: UL 1034 fail-secure strikes and the FF-L-2740 lock
  9. STC-rated door assemblies
  10. GSA-approved security containers: Class 5 and Class 6
  11. Black-label container phase-out timeline
  12. GSA vault doors under AA-D-600D
  13. The DoD Lock Program and technical support hotline
  14. Combination changes under 32 CFR 2001.43
  15. SF 700, SF 701 and SF 702
  16. Common door, lock and container failures

07Penetrations, Utilities & Life Safety

  1. General rules for perimeter penetrations
  2. Vents and ducts: the 96 square inch and 6 inch trigger
  3. Man-bars, grilles and metal baffles
  4. Inspection access ports and IDS on ducts
  5. Pipes, conduit and sprinkler lines
  6. Non-conductive (dielectric) breaks
  7. Single point of utility entry and spare conduit
  8. Grounding at perimeter penetrations
  9. Life safety: the AHJ and the AO both have jurisdiction
  10. Egress doors, delayed egress and panic hardware
  11. Accessibility: ADA and ABA in secure spaces
  12. Fire alarm and mass notification devices inside the SCIF
  13. Power, UPS and generators
  14. HVAC serving a SCIF
  15. Low-voltage wiring rules for IDS, access control and telecom
  16. Common penetration and utility failures

08Acoustics & Sound Masking

  1. What SCIF acoustic protection is for
  2. Plain-English guide to STC and NIC
  3. Sound Group 3 vs. Sound Group 4
  4. Where each Sound Group applies
  5. ASTM E90, E413 and E336 explained
  6. Lab ratings vs. field results: why components are rated higher
  7. Acoustic testing at accreditation: audio vs. instrumented tests
  8. Instrumented test setup
  9. Building walls for acoustic performance
  10. Doors, windows and ducts: the usual weak points
  11. Mitigations when construction falls short
  12. Sound masking rules under the Tech Spec
  13. Amplified audio, public address and notification speakers
  14. Common acoustic failures
  15. Masking versus construction: why masking never replaces STC
  16. Masking system architecture: what goes inside the SCIF
  17. The exterior door speaker exception: AO low-risk finding and rigid conduit
  18. Transducers vs speakers: doors, walls, windows and ducts
  19. Network ports and paging inputs: the connectivity problem
  20. Sound masking vendors: what is verified and what to ask
  21. Commissioning and documenting masking for the inspector

09Intrusion Detection & UL 2050 / Extent 3

  1. What an IDS must accomplish in a SCIF
  2. What Extent 3 actually means
  3. The 12 numbers every SCIF IDS installer should know
  4. Sensors: UL 634 Level II switches and UL 639 motion detection
  5. Premise control unit: location, display and reset
  6. Integrated and networked IDS, hosts and remote terminals
  7. Modes of operation: armed, disarmed and maintenance
  8. Electrical power: 24 hours uninterruptible
  9. Monitoring stations and who may staff them
  10. Alarm response times and Security-in-Depth
  11. Maintenance, semiannual testing and false alarm limits
  12. Installation and acceptance testing
  13. IDS records retention
  14. UL 2050 overview: edition, scope and listing categories
  15. The CS-ASD-NISS form, the certificate and investigator response times
  16. UL audits and how to verify a UL 2050 certificate
  17. UL 681 vs UL 2050 extents: what is and isn't known
  18. Related UL standards and their roles
  19. NISPOM 32 CFR 117.15 intrusion detection requirements
  20. SAPF intrusion detection under DoDM 5205.07 and the DCSA checklist
  21. Communicators, line security and the FIPS 140-2 transition
  22. SCIF vs SAPF vs NISPOM open storage vs GSA container
  23. Common IDS findings at accreditation
  24. Vetting a UL 2050 alarm company

10Access Control, Identity & Hirsch

  1. The role of access control in a SCIF
  2. Entrance requirements: two technologies at the door
  3. Where the ACS head-end must live
  4. Protecting ACS lines, outside readers and enrollment data
  5. Secondary and emergency doors: shut the ACS off when unoccupied
  6. Electric strikes, UL 1034 and the FF-L-2740 lock
  7. Duty hours vs unoccupied: who controls the door
  8. Visitor control at the SCIF entrance
  9. Access control records
  10. HSPD-12, FIPS 201-3, PIV/CAC and SP 800-116 security areas
  11. Buying PACS: the GSA FIPS 201 APL and FICAM
  12. Hirsch spotlight: corporate status and Velocity 3.9
  13. Hirsch Mx controllers, SNIB3 and alarm line modules
  14. Hirsch readers: TS ScramblePad and ScrambleFactor
  15. Hirsch intrusion integration and SCIF requirement mapping
  16. What not to claim about Hirsch or any SCIF access control product
  17. Competitor landscape for enterprise and high-security PACS
  18. CCTV at SCIF entrances
  19. Nested areas: the one-way rule
  20. Integrator traps for access control and door hardware
  21. One-way access in the governing text: high inside low
  22. Clearance is not access: need-to-know at every inner door
  23. The nesting model: boundaries, credentials and IDS status by layer
  24. Compartmented areas: no spin-dial locks and no independent alarms
  25. Multiple SCIFs on one control unit: independent partitions
  26. ACS patterns for nested areas: requirement, feature or practice
  27. Head-end placement and operator partitioning in shared systems
  28. Information flow: Bell–LaPadula, data diodes and cross-domain solutions
  29. Worked example: four nested boundaries from lobby to Type III CA
  30. Common compartmented access design mistakes

11RED/BLACK, TEMPEST & EMI Filters

  1. RED and BLACK in plain English
  2. Why many SCIFs are not shielded but still need RED/BLACK discipline
  3. The CTTA and the TEMPEST countermeasures review
  4. When countermeasures are triggered and what the Tech Spec says
  5. Inspectable space: the concept
  6. The TEMPEST checklist: what the public form asks
  7. RED/BLACK installation concepts: equipment and cabling
  8. RED/BLACK installation concepts: power, grounding and fiber
  9. EMI/RFI filters: what they do
  10. Line side vs load side: which side goes where
  11. Mounting filters at the shield boundary: bonding, boxes and conduit
  12. Signal, data and telephone filters
  13. HEMP filters and MIL-STD-188-125
  14. MIL-STD-220 insertion loss testing
  15. Leakage current, grounding and GFCI coordination
  16. Stored charge: bleeder resistors and electrician safety
  17. Generators, UPS and kVAR
  18. Filter basics at a glance
  19. Common filter mistakes
  20. Case study: data about secure systems leaks too (INSCOM, 2017)

12RF Shielding, Penetrations & Installer Methods

  1. What an RF shield is and when one is required
  2. Shielded enclosure types
  3. Attenuation, frequency and the weakest-link rule
  4. Every penetration is a potential leak: treatments at a glance
  5. Single-point entry and the penetration panel
  6. Dielectric breaks
  7. Waveguide-beyond-cutoff in plain English
  8. The cutoff formula and a worked example
  9. Honeycomb vents for HVAC
  10. Pipe waveguides for sprinklers and water
  11. Fiber-optic penetrations
  12. RF doors: knife-edge, finger stock and gaskets
  13. RF door and seam maintenance
  14. Grounding and bonding the shield
  15. Testing: IEEE 299 and retest after every penetration
  16. Never fasten through the shield
  17. GC and installer preconstruction checklist
  18. Sixteen common shielding mistakes and their fixes
  19. Build sequence for a shielded room
  20. The no-fastener rule: what each source actually says
  21. Mounting an HSS above an RF or STC-rated door without penetrating
  22. HSS mounting methods compared
  23. What the switch manufacturer's instructions require
  24. Adhesive mounting is not a documented method for listed switches
  25. Routing surface conduit and raceway to the penetration panel
  26. Conduit bonding at the shield: two views and one resolution
  27. Furred walls and secondary stud walls as device chases
  28. Card readers and keypads mounted outside the SCIF
  29. Electrified hardware across an RF door: transfer hinge or door loop
  30. Protect RF door contacts and hang doors before the shield test
  31. When a hole is made in the shield
  32. Installer do and don't table
  33. Pre-cover and pre-test hold points for low-voltage work
  34. MIL-HDBK-232A lesson: a RED/BLACK design can still fail TEMPEST
  35. NSTISSI 7000 concepts: inspectable space and cost-effective countermeasures

13PEDs, Wireless Detection, Telecom & CCTV

  1. Why PEDs are controlled in SCIFs and SAPFs
  2. Tech Spec Chapter 10: approvals, prohibitions and risk levels
  3. PED lockers, signage and the entry routine
  4. Government-owned, medical and wearable devices
  5. The 30 June 2023 SECDEF memo: "program for," not "installed by"
  6. SAPF PED items in the DCSA January 2026 checklist
  7. How RF device detection works
  8. What RF detection cannot see
  9. Non-RF screening: ferromagnetic and metal detection
  10. PED detection products: verified vendor claims compared
  11. Detection sensors are equipment too: review, networks and records
  12. Vestibule PED detection workflow, step by step
  13. Wiring PED detection into the ACS and door interlock
  14. Interlocked vestibules and life safety: get the AHJ first
  15. Telephones in SCIFs: TSG-6, TSG-2 and VoIP rules
  16. Speakerphones, notification, cable TV and building controls
  17. CCTV at the SCIF entrance: Tech Spec 8.E and camera design
  18. Common PED, wireless, telecom and CCTV traps

14Construction Security & Build Sequence

  1. Construction security roles
  2. U.S. construction security requirements
  3. Who may design, build and install
  4. The Construction Security Plan: what it contains
  5. CSTs, cleared escorts and site access control
  6. Material procurement, shipping and secure storage
  7. Outside the U.S.: key construction differences
  8. The build sequence at a glance
  9. Phase 0: sponsorship and site due diligence
  10. Phase 1: planning and pre-design submittals
  11. Phase 2: design
  12. Phase 3: procurement and award
  13. Phase 4: construction
  14. Phase 5: testing, inspection and accreditation
  15. Coordinating the AO, CTTA and AHJ
  16. Most common construction mistakes

15Traps & Common Failures

  1. Top 25 inspection killers
  2. Planning and paperwork traps
  3. Perimeter and ceiling traps
  4. Door and lock traps
  5. Penetration and utility traps
  6. Acoustic traps
  7. Intrusion detection traps
  8. Access control traps
  9. RED/BLACK and filter traps
  10. Shielding and installer damage traps
  11. PED, telecom and CCTV traps
  12. Life safety and AHJ conflict traps
  13. Naming and version traps

16History of TEMPEST & Shielding Specs

  1. Timeline: discovery to the FOIA releases (WWII–2000)
  2. Timeline: the CNSS era to today (2004–2025)
  3. The discovery: Bell 131-B2 and the covername TEMPEST
  4. Rediscovery and the first control standards (1951–1982)
  5. Public research: van Eck and after
  6. The NSA shielded-enclosure specification lineage
  7. What NSA 94-106 covered
  8. The RED/BLACK and facility countermeasure guidance lineage
  9. The IC's move from DCID 6/9 to ICD 705
  10. Why history matters to today's designers
  11. Public reading list

17DISA Traditional Security STIG & PDS

  1. What the DISA Traditional Security Checklist is
  2. Version status: which release is current
  3. Topic area map of the checklist
  4. Example physical and technical security requirements
  5. How the STIG relates to ICD 705 inspections
  6. Protected Distribution Systems: definition and governing issuance
  7. PDS carrier types and components
  8. Why DoD avoids PDS where possible
  9. PDS inspection checks named in the STIG
  10. STIG items that land on IDS and access control integrators

18Playbooks: Real-World Scenarios

  1. We won a contract that requires a SCIF. Where do we start?
  2. Can we convert leased office space into a SCIF?
  3. Our architect put a sprinkler main through the SCIF. What now?
  4. The duct is bigger than 96 square inches. What do we install?
  5. Do we need RF shielding?
  6. The CTTA says we need filters. What does the electrician do?
  7. How do we mount a door contact on a shielded or STC-rated door?
  8. How do we choose and verify a UL 2050 alarm company?
  9. Our IDS failed the walk test. How do we find and fix the problem?
  10. How do we design access for two compartments inside one SCIF?
  11. Can we add wireless device detection at the mantrap?
  12. The fire marshal wants magnetic locks on the SCIF door
  13. Sound masking or a higher STC rating: which do we need?
  14. Our accreditation is up for re-evaluation. How do we prepare?
  15. We need to add a penetration to an accredited SCIF. What is the process?
  16. We need a SCIF for a short program. What are our options?
  17. We are building a SAPF. What changed with the 2025 DoDM 5205.07?
  18. Our communicator is FIPS 140-2. Is that a problem after 21 September 2026?
  19. What can our integrator see, keep and send about a SCIF project?
  20. We want Hirsch Velocity for a new SCIF. What should we confirm with the AO?
  21. Can we put a camera on the SCIF entrance?
  22. The fire alarm contractor needs speakers and strobes inside the SCIF
  23. Can one alarm panel cover our SCIF and the collateral area around it?