Directory · 344 sections
All sections
Every section title in the knowledge base, in module order. Each link opens the module at that section.
00Start Here: How SCIF Security Fits Together
- What a SCIF is (and what it is not)
- SCIF vs SAPF vs NISPOM open storage area vs GSA container
- The three things every accreditation proves
- The object model
- Object model reference table
- How the pieces flow from concept to re-evaluation
- Lifecycle states of a SCIF
- The document stack in one table
- Naming quirks: acronyms that mean two things
- Version and terminology traps
- Where a low-voltage integrator fits
- How to use this knowledge base
01Governance & Document Hierarchy
- The document hierarchy at a glance
- ICD 705: what the directive requires
- ICS 705-1: physical and technical security standards
- ICS 705-2: accreditation and reciprocal use
- The IC Tech Spec: purpose and applicability
- Tech Spec v1.5.1 chapter map
- Tech Spec version history
- Tech Spec forms and plans (Chapter 14)
- Reported 2025–2026 changes to SCIF requirements
- DoDM 5105.21: DoD's SCI security manual
- DoDM 5205.07 (2025) and legacy SAP standards
- 32 CFR Part 117 (NISPOM) and 32 CFR Part 2001
- DCSA's role, and what it does not do
- Cognizant Security Authorities for SCI at a glance
- UFC 4-010-05: DoD design criteria for SCIFs and SAPFs
- Reciprocity and waivers
02Roles & Responsibilities
- Roles at a glance: who produces and signs what
- IC element head and the Director, NCSC
- Accrediting Official (AO)
- Cognizant Security Authority (CSA)
- SAPF Accrediting Official and SAP security roles
- Site Security Manager (SSM)
- SSO, SSR and CSSO: running the accredited space
- Certified TEMPEST Technical Authority (CTTA)
- Construction surveillance technicians, cleared guards and escorts
- TSCM teams
- Sponsors, program managers and co-use tenants
- Designer of record (architect-engineer)
- General contractor responsibilities
- Low-voltage and IDS integrator responsibilities
- Authority Having Jurisdiction (AHJ) and life safety
- Role separation rules and common confusions
03Accreditation Lifecycle
- Accreditation is a lifecycle: the step table
- Sponsorship, concept approval and early AO coordination
- Site survey, risk assessment and the Pre-Construction Checklist
- TEMPEST Checklist and CTTA review
- Design approval and the Construction Security Plan
- Construction surveillance and the evidence trail
- Systems installation, testing and certificates
- Final Fixed Facility Checklist and operating documents
- Final inspection, TSCM and interim accreditation
- Accreditation issuance: what the letter says
- Continuous monitoring and periodic re-evaluation
- Modifications and re-accreditation triggers
- Waiver requests: package contents and consequences
- De-accreditation, withdrawal and re-use
- Co-Use Agreements: process and paperwork
- What to have ready at inspection
04Facility Types, Modes & Overseas Categories
- Facility types at a glance
- Closed storage SCIFs
- Open storage SCIFs
- Continuous operation SCIFs
- Secure Working Areas (SWA)
- Temporary Secure Working Areas (TSWA)
- Temporary, airborne, shipboard and prefabricated SCIFs
- Compartmented Areas and Second Party spaces
- Vaults
- Co-use, joint use and reciprocity
- IDS and alarm response by mode
- Security-in-Depth: definition and primary means
- What Security-in-Depth changes
- Inside vs outside the U.S.: three construction regimes
- Overseas threat Categories I–III
05Perimeter Construction & Vaults
- What the SCIF perimeter is and what it must do
- Physical protection vs. visual evidence of surreptitious penetration
- True floor to true ceiling: slab-to-slab construction
- Wall A, Wall B and Wall C specifications
- Choosing a wall type by storage mode
- Existing masonry, fire-retardant plywood and higher-STC walls
- RF and TEMPEST treatment of perimeter walls
- Ceilings and floors
- False ceilings and raised floors
- Utilities mounted on perimeter walls
- Windows: minimize, fix shut and protect
- The 18-foot rule for windows and daylighting
- When a vault is used
- Vault construction under Tech Spec 3.C.5
- Tech Spec vaults vs. FED-STD 832 Class A, B and C
- Common perimeter mistakes
06Doors, Locks & Security Containers
- The three SCIF perimeter door categories
- Requirements for every perimeter door
- Door fabrication requirements
- Roll-up, double-leaf and adjoining-SCIF doors
- FF-L-2740B combination locks and approved models
- FF-L-2890C pedestrian door device types
- Approved FF-L-2890 products and the revision question
- Electrified hardware: UL 1034 fail-secure strikes and the FF-L-2740 lock
- STC-rated door assemblies
- GSA-approved security containers: Class 5 and Class 6
- Black-label container phase-out timeline
- GSA vault doors under AA-D-600D
- The DoD Lock Program and technical support hotline
- Combination changes under 32 CFR 2001.43
- SF 700, SF 701 and SF 702
- Common door, lock and container failures
07Penetrations, Utilities & Life Safety
- General rules for perimeter penetrations
- Vents and ducts: the 96 square inch and 6 inch trigger
- Man-bars, grilles and metal baffles
- Inspection access ports and IDS on ducts
- Pipes, conduit and sprinkler lines
- Non-conductive (dielectric) breaks
- Single point of utility entry and spare conduit
- Grounding at perimeter penetrations
- Life safety: the AHJ and the AO both have jurisdiction
- Egress doors, delayed egress and panic hardware
- Accessibility: ADA and ABA in secure spaces
- Fire alarm and mass notification devices inside the SCIF
- Power, UPS and generators
- HVAC serving a SCIF
- Low-voltage wiring rules for IDS, access control and telecom
- Common penetration and utility failures
08Acoustics & Sound Masking
- What SCIF acoustic protection is for
- Plain-English guide to STC and NIC
- Sound Group 3 vs. Sound Group 4
- Where each Sound Group applies
- ASTM E90, E413 and E336 explained
- Lab ratings vs. field results: why components are rated higher
- Acoustic testing at accreditation: audio vs. instrumented tests
- Instrumented test setup
- Building walls for acoustic performance
- Doors, windows and ducts: the usual weak points
- Mitigations when construction falls short
- Sound masking rules under the Tech Spec
- Amplified audio, public address and notification speakers
- Common acoustic failures
- Masking versus construction: why masking never replaces STC
- Masking system architecture: what goes inside the SCIF
- The exterior door speaker exception: AO low-risk finding and rigid conduit
- Transducers vs speakers: doors, walls, windows and ducts
- Network ports and paging inputs: the connectivity problem
- Sound masking vendors: what is verified and what to ask
- Commissioning and documenting masking for the inspector
09Intrusion Detection & UL 2050 / Extent 3
- What an IDS must accomplish in a SCIF
- What Extent 3 actually means
- The 12 numbers every SCIF IDS installer should know
- Sensors: UL 634 Level II switches and UL 639 motion detection
- Premise control unit: location, display and reset
- Integrated and networked IDS, hosts and remote terminals
- Modes of operation: armed, disarmed and maintenance
- Electrical power: 24 hours uninterruptible
- Monitoring stations and who may staff them
- Alarm response times and Security-in-Depth
- Maintenance, semiannual testing and false alarm limits
- Installation and acceptance testing
- IDS records retention
- UL 2050 overview: edition, scope and listing categories
- The CS-ASD-NISS form, the certificate and investigator response times
- UL audits and how to verify a UL 2050 certificate
- UL 681 vs UL 2050 extents: what is and isn't known
- Related UL standards and their roles
- NISPOM 32 CFR 117.15 intrusion detection requirements
- SAPF intrusion detection under DoDM 5205.07 and the DCSA checklist
- Communicators, line security and the FIPS 140-2 transition
- SCIF vs SAPF vs NISPOM open storage vs GSA container
- Common IDS findings at accreditation
- Vetting a UL 2050 alarm company
10Access Control, Identity & Hirsch
- The role of access control in a SCIF
- Entrance requirements: two technologies at the door
- Where the ACS head-end must live
- Protecting ACS lines, outside readers and enrollment data
- Secondary and emergency doors: shut the ACS off when unoccupied
- Electric strikes, UL 1034 and the FF-L-2740 lock
- Duty hours vs unoccupied: who controls the door
- Visitor control at the SCIF entrance
- Access control records
- HSPD-12, FIPS 201-3, PIV/CAC and SP 800-116 security areas
- Buying PACS: the GSA FIPS 201 APL and FICAM
- Hirsch spotlight: corporate status and Velocity 3.9
- Hirsch Mx controllers, SNIB3 and alarm line modules
- Hirsch readers: TS ScramblePad and ScrambleFactor
- Hirsch intrusion integration and SCIF requirement mapping
- What not to claim about Hirsch or any SCIF access control product
- Competitor landscape for enterprise and high-security PACS
- CCTV at SCIF entrances
- Nested areas: the one-way rule
- Integrator traps for access control and door hardware
- One-way access in the governing text: high inside low
- Clearance is not access: need-to-know at every inner door
- The nesting model: boundaries, credentials and IDS status by layer
- Compartmented areas: no spin-dial locks and no independent alarms
- Multiple SCIFs on one control unit: independent partitions
- ACS patterns for nested areas: requirement, feature or practice
- Head-end placement and operator partitioning in shared systems
- Information flow: Bell–LaPadula, data diodes and cross-domain solutions
- Worked example: four nested boundaries from lobby to Type III CA
- Common compartmented access design mistakes
11RED/BLACK, TEMPEST & EMI Filters
- RED and BLACK in plain English
- Why many SCIFs are not shielded but still need RED/BLACK discipline
- The CTTA and the TEMPEST countermeasures review
- When countermeasures are triggered and what the Tech Spec says
- Inspectable space: the concept
- The TEMPEST checklist: what the public form asks
- RED/BLACK installation concepts: equipment and cabling
- RED/BLACK installation concepts: power, grounding and fiber
- EMI/RFI filters: what they do
- Line side vs load side: which side goes where
- Mounting filters at the shield boundary: bonding, boxes and conduit
- Signal, data and telephone filters
- HEMP filters and MIL-STD-188-125
- MIL-STD-220 insertion loss testing
- Leakage current, grounding and GFCI coordination
- Stored charge: bleeder resistors and electrician safety
- Generators, UPS and kVAR
- Filter basics at a glance
- Common filter mistakes
- Case study: data about secure systems leaks too (INSCOM, 2017)
12RF Shielding, Penetrations & Installer Methods
- What an RF shield is and when one is required
- Shielded enclosure types
- Attenuation, frequency and the weakest-link rule
- Every penetration is a potential leak: treatments at a glance
- Single-point entry and the penetration panel
- Dielectric breaks
- Waveguide-beyond-cutoff in plain English
- The cutoff formula and a worked example
- Honeycomb vents for HVAC
- Pipe waveguides for sprinklers and water
- Fiber-optic penetrations
- RF doors: knife-edge, finger stock and gaskets
- RF door and seam maintenance
- Grounding and bonding the shield
- Testing: IEEE 299 and retest after every penetration
- Never fasten through the shield
- GC and installer preconstruction checklist
- Sixteen common shielding mistakes and their fixes
- Build sequence for a shielded room
- The no-fastener rule: what each source actually says
- Mounting an HSS above an RF or STC-rated door without penetrating
- HSS mounting methods compared
- What the switch manufacturer's instructions require
- Adhesive mounting is not a documented method for listed switches
- Routing surface conduit and raceway to the penetration panel
- Conduit bonding at the shield: two views and one resolution
- Furred walls and secondary stud walls as device chases
- Card readers and keypads mounted outside the SCIF
- Electrified hardware across an RF door: transfer hinge or door loop
- Protect RF door contacts and hang doors before the shield test
- When a hole is made in the shield
- Installer do and don't table
- Pre-cover and pre-test hold points for low-voltage work
- MIL-HDBK-232A lesson: a RED/BLACK design can still fail TEMPEST
- NSTISSI 7000 concepts: inspectable space and cost-effective countermeasures
13PEDs, Wireless Detection, Telecom & CCTV
- Why PEDs are controlled in SCIFs and SAPFs
- Tech Spec Chapter 10: approvals, prohibitions and risk levels
- PED lockers, signage and the entry routine
- Government-owned, medical and wearable devices
- The 30 June 2023 SECDEF memo: "program for," not "installed by"
- SAPF PED items in the DCSA January 2026 checklist
- How RF device detection works
- What RF detection cannot see
- Non-RF screening: ferromagnetic and metal detection
- PED detection products: verified vendor claims compared
- Detection sensors are equipment too: review, networks and records
- Vestibule PED detection workflow, step by step
- Wiring PED detection into the ACS and door interlock
- Interlocked vestibules and life safety: get the AHJ first
- Telephones in SCIFs: TSG-6, TSG-2 and VoIP rules
- Speakerphones, notification, cable TV and building controls
- CCTV at the SCIF entrance: Tech Spec 8.E and camera design
- Common PED, wireless, telecom and CCTV traps
14Construction Security & Build Sequence
- Construction security roles
- U.S. construction security requirements
- Who may design, build and install
- The Construction Security Plan: what it contains
- CSTs, cleared escorts and site access control
- Material procurement, shipping and secure storage
- Outside the U.S.: key construction differences
- The build sequence at a glance
- Phase 0: sponsorship and site due diligence
- Phase 1: planning and pre-design submittals
- Phase 2: design
- Phase 3: procurement and award
- Phase 4: construction
- Phase 5: testing, inspection and accreditation
- Coordinating the AO, CTTA and AHJ
- Most common construction mistakes
15Traps & Common Failures
- Top 25 inspection killers
- Planning and paperwork traps
- Perimeter and ceiling traps
- Door and lock traps
- Penetration and utility traps
- Acoustic traps
- Intrusion detection traps
- Access control traps
- RED/BLACK and filter traps
- Shielding and installer damage traps
- PED, telecom and CCTV traps
- Life safety and AHJ conflict traps
- Naming and version traps
16History of TEMPEST & Shielding Specs
- Timeline: discovery to the FOIA releases (WWII–2000)
- Timeline: the CNSS era to today (2004–2025)
- The discovery: Bell 131-B2 and the covername TEMPEST
- Rediscovery and the first control standards (1951–1982)
- Public research: van Eck and after
- The NSA shielded-enclosure specification lineage
- What NSA 94-106 covered
- The RED/BLACK and facility countermeasure guidance lineage
- The IC's move from DCID 6/9 to ICD 705
- Why history matters to today's designers
- Public reading list
17DISA Traditional Security STIG & PDS
- What the DISA Traditional Security Checklist is
- Version status: which release is current
- Topic area map of the checklist
- Example physical and technical security requirements
- How the STIG relates to ICD 705 inspections
- Protected Distribution Systems: definition and governing issuance
- PDS carrier types and components
- Why DoD avoids PDS where possible
- PDS inspection checks named in the STIG
- STIG items that land on IDS and access control integrators
18Playbooks: Real-World Scenarios
- We won a contract that requires a SCIF. Where do we start?
- Can we convert leased office space into a SCIF?
- Our architect put a sprinkler main through the SCIF. What now?
- The duct is bigger than 96 square inches. What do we install?
- Do we need RF shielding?
- The CTTA says we need filters. What does the electrician do?
- How do we mount a door contact on a shielded or STC-rated door?
- How do we choose and verify a UL 2050 alarm company?
- Our IDS failed the walk test. How do we find and fix the problem?
- How do we design access for two compartments inside one SCIF?
- Can we add wireless device detection at the mantrap?
- The fire marshal wants magnetic locks on the SCIF door
- Sound masking or a higher STC rating: which do we need?
- Our accreditation is up for re-evaluation. How do we prepare?
- We need to add a penetration to an accredited SCIF. What is the process?
- We need a SCIF for a short program. What are our options?
- We are building a SAPF. What changed with the 2025 DoDM 5205.07?
- Our communicator is FIPS 140-2. Is that a problem after 21 September 2026?
- What can our integrator see, keep and send about a SCIF project?
- We want Hirsch Velocity for a new SCIF. What should we confirm with the AO?
- Can we put a camera on the SCIF entrance?
- The fire alarm contractor needs speakers and strobes inside the SCIF
- Can one alarm panel cover our SCIF and the collateral area around it?
