|
|
UNCLASSIFIED//FOR OFFICIAL USE ONLY
72
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Maintenance equipment that has the capability of retaining information must be appropriately
sanitized by established procedures (see Chapter 21) before being released. If the equipment cannot
be sanitized, it must remain within the facility, be destroyed, or be released under procedures
approved by the DAA Rep/SCO.
· Replacement equipment or components that are brought into the SCIF for the purpose of
swapping-out facility components are allowed. However, any component introduced into an IS will
remain in the facility until proper release procedures are completed.
· Devices with transmit capability (e.g., IR, RF, etc.) shall remain outside the SCIF.
13.3.3 (U) Maintenance and System Security
After maintenance, and before return to operation, the ISSM, or designee, shall check the security
features on the IS to assure that they still function properly. Additionally, any maintenance changes
that impact the security of the system shall receive a configuration management review.
13.3.4 (U) Remote Maintenance Requirements/Considerations
· The Installation and use of remote diagnostic links must be preapproved and procedures addressed
in the SSAA/SSP.
· An audit log shall be maintained for five years of all remote maintenance, diagnostic, and service
transactions and periodically reviewed by the ISSO/ SA.
· Other techniques to consider when remote maintenance is required include encryption and
decryption of diagnostic communications, strong identification and authentication techniques such
as tokens and remote disconnect verification.
13.3.4.1 (U) Maintenance Performed with the same Level of Security
Remote Diagnostic Maintenance service may be provided by a service or organization that does
possess the same level and category(ies) of security. The communications links connecting the
components of the systems, plus associated data communications and networks, shall be protected
IAW national security policies and procedures applicable to the sensitivity level of the data being
transmitted.
13.3.4.2 (U) Maintenance Performed with a different Level of Security
If remote diagnostic or maintenance services are required from a service or organization that does
not provide the same level of security required for the IS being maintained, the system must be
cleared; placed in a standalone configuration prior to the connection of the remote access line; and
maintenance personnel must possess the appropriate clearance to perform the maintenance. If the
system cannot be cleared (e.g., due to a system crash), remote diagnostics and maintenance shall
not be allowed.
13.3.4.3 (U) Initiating and Terminating Remote Access
The initiation and termination of the remote access must be performed by the ISSM or designee.
13.3.4.4 (U) Keystroke Monitoring Requirements
Keystroke monitoring shall be performed on all remote diagnostic or maintenance services. So far
as practicable, a technically qualified person shall review the maintenance log to assure the
detection of unauthorized changes. The ISSM, or designee, will assure that maintenance technicians
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
73
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
responsible for performing remote diagnosis/maintenance are advised
(contractually, verbally,
banner, etc.) prior to remote diagnostics/maintenance that keystroke monitoring will be performed.
13.3.5 (U) Life Cycle Maintenance
The requirement for, and vulnerabilities of, IS maintenance, whether performed by military or
contractor personnel, must be addressed during all phases of the system’s life cycle. The security
implications of IS maintenance must be specifically addressed when entering into contract
negotiations for any maintenance activity.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
74
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 14 - DIGITAL AND MULTI-FUNCTION DEVICES (COPY/PRINT/SCAN/FAX)
14.1 (U) PURPOSE
This section provides the guidance for the acquisition and life-cycle maintenance for multi-function
devices having the capability to copy, print, scan, and fax, either in a standalone mode or
networked. These devices include digital copiers, copier or printer centers. These devices are
computer driven and therefore constitute as an Information System (IS) and are subject to many of
the same security vulnerabilities as any other computer devices.
These computer-based, network-capable devices with processors, memory, hard-drives, image
retention components, and, in some cases, cellular phone transmitters with vendor auto-alert
features, are to be classified as IS equipment and are governed by organizational information
systems security policies. Some concerns are memory capability, service technician laptop
connectivity, repair capabilities and remote diagnostics.
Job queues are capable of holding up to 1500 images or more, depending on the size and
complexity of the images. These images are compressed and encrypted with built-in proprietary
capabilities. Under normal circumstances these images are not accessible but may be copied and
later opened by technically competent personnel. All images retained in the memory remain in the
memory until over-written by subsequent printing images. The memory is non-volatile, so if power
is lost the images remain on the hard drive. This creates a problem when service technicians
respond to repair the unit. The laptop computer utilized by the service technicians has the capability
of downloading the information stored in the copy/printer center’s hard drive. Although this
information may be compressed and encrypted with proprietary encryption capabilities, technically
competent personnel may later retrieve the information.
14.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
YES
DESIGN PHASE
YES
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
14.3 (U) POLICY
These multi-function printer/copier devices have to meet the same Certification and Accreditation
(C&A) requirements as specified in references and internal C&A process requirements. They are
under the management of the organizations’ Designated Accrediting Authority. Additionally:
· In the event that any key provisions regarding these multi-function printer/copier devices cannot be
met, associated risks must be identified and a waiver request submitted for approval to the DAA or
their representative, who has the sole authority to grant exceptions to this policy.
· Networked multi-functional printer/copier devices are only permitted to process information at the
accredited classification level of the network itself.
· When connected to a network, multi-functional printer/copier devices will assume the highest
classification for which the network is accredited and, if also operated as a standalone device, they
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
75
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
will assume the highest classification of copied documents. It should be kept in mind when using
multi-functional printer/copier equipment that the document image will remain on the imaging
drum/belt, hard drives, and static RAM.
14.4 (U) PROCEDURES
Since these copiers have internal electronic memory components it is necessary to purchase them
outright
(not lease them) and maintain absolute control of all electronic parts that contain a
memory/data remanence capacity, and to have a maintenance contract that provides for
maintenance support by cleared personnel. The only exceptions to this maintenance policy are
specified in Section 8.B.8.b. of DCID 6/3.
·
If laptops are required for diagnostics, they must be purchased (software included) and maintained
in appropriate secure facilities. The service technician must not be permitted to connect a
proprietary laptop to the copy/printer center as the technician may download classified information
onto the laptop. Nor may the copy/printer center, primarily the hard drive, be removed from the
SCIF to a non-SCIF area. Consideration should be given to obtain a proper security clearance for
the service technician and provide a government laptop with proprietary diagnostic and repair
information installed. The laptop must remain within the classified area and may not be utilized by
personnel other than the repair technician.
·
Purchase the copy/printer center with a removable hard drive vice an internal hard drive.
Consideration for a second hard drive for diagnostic and repair only should be available to allow
the service technician lap top connectivity. The built-in internal hard drive may be extremely
difficult to access and remove, requiring disassembly. The classified information stored on the hard
drive is the property of the United States and must not be released outside official channels.
·
Whether previous systems have been purchased or leased with either an internal or removable hard
drive, you are required to purchase a second replacement hard drive. Usually under lease
agreements, the equipment must be returned with all parts. Once the hard drive is removed, it can
then be replaced with the second non-classified hard drive for turn-in and the lease agreement
should then remain valid.
·
Removal/return of purely mechanical or electro-mechanical parts to a vendor will only be permitted
based on a risk determination that includes consideration of threat, vulnerability, impact, and cost.
Printed circuit boards/memory boards are to be destroyed as classified trash. It is advised that no
parts should be released in overseas locales, or other high counterintelligence threat areas. The
cognizant Security Officer, Special Security Officer (SSO), Information Systems Security Officer
(ISSO), or Contractor Security Officer (CSO), is responsible for on-site decisions. The only
exception permitted is if a part can be absolutely cleansed in accordance with the documented
guidance in Chapter 20 of this document.
·
All communications ports not specifically required for networked or contractual maintenance must
be removed or permanently disabled. Only hardwired connections are permitted (no IR, RF, or
Audio communications). This provision must be included in the purchase contract.
·
Passwords are set at the factory. Some of these passwords can be changed by the user, however
some passwords can not. Additionally, all factory set passwords are the same for each machine.
Ensure the passwords have been changed by the ISSO/ISSM where feasible.
·
The site SSO shall make information regarding installation of new copiers and major repairs to
existing copiers available to Technical Security evaluators.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
76
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· The Equipment Receiving Facility shall physically inspect incoming shipments for evidence of
tampering.
14.4.1 (U) FAX Capabilities
The multi-function printer/copier devices may contain a cellular telephone with FAX capability. The
FAX is usually factory set to automatically send a page (i.e., once every 100 copies) to the
manufacturer so the manufacturer can ensure quality copies. A firewall should be installed between
the FAX and the hard drive or have the FAX capability disabled.
14.5 (U) RESPONSIBILITIES
14.5.1 (U) The DAA representative shall:
· Ensure that system owners provide appropriate Certification and Accreditation
documentation/authorizations to the DAA
· Inform their customers of this policy.
14.5.2 (U) ISSOs and/or Information Systems Security Managers shall:
· Ensure that each user receives appropriate awareness training;
· Ensure that installed systems meet the TEMPEST standards of NSTISSP 300, “National Policy on
Control of Compromising Emanations”;
· Ensure that appropriate classification and usage labels are properly affixed to the equipment;
· Update all SSPs/SSAAs to reflect copier locations, model and serial numbers. In addition to the
SSP/SSAA, the Certification and Accreditation package should include maintenance procedures
which comply with the policies specified in this document; and
· Ensure the management of packaging, shipping, receiving, and inspection processes by trusted
vendors. For added security, the application of tamper evident seals is recommended.
14.5.3 (U) USERS shall:
· Notify their ISSO, ISSM, or ISSPM in advance of the purchase of Multi-functional printer/copier
devices to ensure SSPs/SSAAs are created or updated as appropriate, and approved prior to
purchase;
· Protect the peripherals (copiers) located in their area in accordance with local/organizational
policies;
· Safeguard the output in accord with daily security checklist procedures if there is no name on an
output that can be attributed to an individual;
· Report any IS security incidents in accord with local/organizational procedures; and
· Adhere to their responsibilities as an IS User and as outlined in local/organizational policies and
procedures.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
77
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 15 - PORTABLE ELECTRONIC DEVICES
15.1 (U) PURPOSE
This chapter identifies procedures for the entry and exit of portable electronic devices into SCIFs.
A portable electronic device is a generic term used to describe the myriad of small electronic items
that are widely available. The rapid growth in technological capabilities of portable electronic
devices/portable computing devices (PEDs/PCDs) has led to concerns about their portability into
and out of SCIFs. PEDs include cellular telephones, two way pagers, palm sized computing
devices, two-way radios, audio/video/data recording, playback features, personal digital assistants,
palm tops, laptops, notebooks, data diaries, and watches with communications software and
synchronization hardware, that may be used to telecommunicate. These devices must be closely
monitored to ensure effective control and protection of all information on our IS.
15.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
YES
DESIGN PHASE
YES
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
15.3 (U) RISK
Because PEDs are designed to freely and openly exchange information, most users may not be
aware of the technologies that reside in the various PEDs. PEDs may contain wireless or infrared
capabilities. Thus, users do not always know when automated information transfer is active or that
the PED is being reprogrammed or reconfigured remotely without their knowledge
15.3.1 (U) Classified Information
The introduction of unauthorized classified information to a PED, will result in a security violation
(see Chapter 8). For example: aggregation of data, inadvertent wireless connection, and POCs
maintained through classified or sensitive contracting mechanisms. If this occurs to an unclassified
PED, the PED needs to be controlled as classified material (e.g., this could include confiscation of
the PED). If a PED is already classified, and unauthorized classified information is found (higher
than authorized for the PED), the PED needs to be controlled at the higher, more restrictive level.
15.4 (U) PROCEDURES
The use of PEDs in a SCI environment presents a high degree of risk for the compromise of
classified or sensitive information. PEDs will only be used to fulfill mission requirements.
Additionally, very specific handling procedures must be developed and made available to the user
of the PED. The Agency in charge of any given SCIF is the authority for the procedures to move
PEDs in or out of their facilities.
15.4.1 (U) Approval Requirements
All of the following requirements must be satisfied prior to approving the use of portable electronic
devices:
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
78
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
15.4.1.1 (U) Personal PEDs
· Personal PEDs, hardware/software associated with them, and media are prohibited from
entering/exiting a SCIF unless authorized by the Agency granting SCIF accreditation.
· Personal PEDs are prohibited from operating within a SCIF unless authorized by the agency
granting SCIF accreditation. If approved, the owner of these devices and his/her supervisor must
sign a statement acknowledging that they understand and will adhere to the restrictions identified
below.
· Connection of a Personal PED to any IS within a SCIF is prohibited.
· PEDs with wireless, Radio Frequency (RF), Infrared (IR) technology, microphones, or recording
capability will not be used unless these capabilities are turned off or physically disabled (i.e.,
metallic tape over IR port(s)).
15.4.1.2 (U) Government Owned PEDs
· Government PEDs, hardware/software associated with them, and media must be controlled when
entering/exiting a SCIF.
· Government PEDs are prohibited from operating within a SCIF unless authorized and accredited by
the agency granting the SCIF accreditation. As part of the accreditation requirements, the user of
these devices and his/her supervisor must sign a statement acknowledging that they understand and
will adhere to the restrictions identified below.
· Connection of a Government PED to any IS within a SCIF must be approved by the ISSM in
writing.
· PEDs with wireless, RF, IR technology, microphones, or recording capability will not be used
unless these capabilities are turned off or physically disabled (i.e., metallic tape over IR port(s)).
· Specified PEDs may be used to process classified information. In addition, these PEDs may be
granted approval to connect to ISs on a case-by-case basis in writing by the ISSM. Specified PEDs
approved to process classified information must meet minimum technical security requirements will
be determined by the ISSM.
· If approved, the PED and associated media must be transported and stored in a manner that affords
security sufficient to preclude compromise of information, sabotage, theft, or tampering.
Procedures for handling the PED in a SCIF must be available and provided to the user.
15.4.1.3 (U) Contractor Business Owned PEDs
· Contractor Business Owned PEDs will follow all requirements identified in paragraph 15.4.1.2.
· All Contractor Business Owned PEDs must support a specific Government contract. Documented
identification of the equipment in support of the contract must be provided prior to entry into a
SCIF.
15.4.2 (U) Handling Procedures
When it has been determined that the use of PEDs is absolutely necessary to fulfill mission
requirements, and the requirements set forth in paragraph
15.4.1 are satisfied, the following
procedures must be implemented and followed.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
79
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
15.4.2.1 (U) Standard Operating Procedure (SOP) Development
The responsible organization must develop a case specific SOP and/or ensure procedures are
addressed in the site CONOPs. The following information must be considered and, where
applicable, included in the SOP:
· The SOP must include the organization and name of the ISSM and SSO responsible for the issue
and control of PEDs.
· Prior to the introduction of PEDs into a SCIF, it must be approved by the appropriate security
personnel having security cognizance for the facility.
· PEDs must operate within one common accredited security parameter (i.e., protection level/level of
concern, classification, etc.) as approved by the DAA Rep/SCO.
· All programs, equipment or data diskettes used with the PED must be marked with a label
identifying the appropriate classification. Labeling exemption for OPSEC requirements may be
granted within local policy with DAA/DAA Rep concurrence.
· If unauthorized classified information is identified on a PED, procedures for control of the
information and the PED must be established. For example, classified information on an unclassified
PED may result in confiscation of the device as an incident (see Chapter 8).
· Every effort should be made to ensure that security control features are implemented when possible
(e.g., access control through userid/password).
15.4.2.2 (U) SOP Approval
The organization requesting the use of PEDs must submit the SOP (as part of the certification and
accreditation documentation) to the ISSM/SSO for coordination and approval.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
80
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 16 - SECURITY PROCEDURES FOR INFORMATION SYSTEMS (IS)
AND
FACSIMILE (FAX) USE OF THE PUBLIC TELEPHONE NETWORK
16.1 (U) PURPOSE
This chapter outlines the minimum-security requirements for the control and accounting of ISs and
facsimile (FAX) use of the public telephone network. ISSM is responsible for enforcing policy for
the level of control and accounting appropriate for facsimile machine(s) within his/her site. This
policy should be coordinated with the SCO and the appropriate SSO. The potential for covert or
inadvertent release of SBU and classified information to an unintended destination is considered to
be highly probable and is reduced significantly through rigorously enforcing policies and
continuously monitoring these policies.
16.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
NO
DESIGN PHASE
YES
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
NO
16.3 (U) PROCEDURES
External connectivity through the use of telephones or networks requires that users take every
security precaution possible to prevent the loss of National Security Information (NSI) and SBU
information via the public communications systems. Classified information shall not be
transmitted, processed or stored on any unclassified facsimile or an unclassified IS with
either a modem or direct digital connection. Telephone communications, voice or digital, must
meet certain installation and equipment standards to ensure security. Telephone communications to
external locations using computer-telephone connections must be approved before installation and
activation to minimize the threat to the information.
16.3.1 (U) FAX Connectivity
16.3.1.1 (U) FAX Approval
The SSO, in coordination with the ISSM, is the approval authority for any facsimile operated
within a SCIF. Specific FAX approval authority is delegated to command/site ISSMs who may
approve unclassified and secure FAX machines within a SCIF. This authority is for single mode use
only. ISSMs must ensure that any/all dual mode features are disabled. Dual mode
(unclassified/secure) configurations are not approved for use in any facility under DIA/NSA
cognizance. Transmission of information at levels above SI/TK (i.e., accountable SCI) requires
applicable program manager’s concurrence. Multi-function FAX/print machines with
workstation/network connectivity/permanent storage/scan and text recognition capabilities are not
to be approved for use of any feature other than secure facsimile transmission. Site ISSMs
exercising SCI IS approval authority for these machines must ensure the following minimum
security requirements are satisfied for unclassified and classified FAX connections. For non-
inspectable space sites, coordinate with the organization TEMPEST officer and telephone control
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
81
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
officer before installing any facsimile equipment in a secure area and for requests for telephone
service IAW Telephone Security Guidelines (TSG).
16.3.1.1.1 (U) Unclassified FAX.
· Unclassified FAX machines must be clearly marked for unclassified use only and consent to
monitoring notification.
· Any change of equipment or location must be locally documented, to include building/room,
manufacturer/model, serial number, verification of SSO authorization and point of contact
information.
· Multi-function FAX/print machines with workstation/network connectivity/permanent storage/scan
and text recognition capabilities must be approved. Requests for this type of equipment should be
submitted to the DAA Rep/SCO via the ISSM.
· Sites should refer to local counsel on information that can be revealed in an unclassified FAX
header.
16.3.1.1.2 (U) Classified FAX
· Classified FAX is normally a connection of the output of a FAX to the input port of a STU-
III/STE, whose encrypted output is connected to the unclassified telephone lines. The procedures
defined in this chapter are in addition to the policy and procedures addressed in NSTISSI 3013 or
other appropriate SCI regulations. ISSMs are delegated approval authority for secure FAX
machines operating up to the TS/SCI SI/TK level.
· Secure FAX machines must be clearly marked for the highest level of classified information
processed.
· ISSMs will ensure that all operators understand the requirement to verify the level at which their
STU-III/STE is connected to the recipient’s STU-III/STE and verify the level at which the
recipient is cleared before transmission commences.
· Information or additional compartments above the SI/TK level cannot be processed without prior
approval from the appropriate data owner.
· The STU-III/STE is designed to prevent disclosure of information while it is being transmitted.
Authorized users must verify the identity and clearance level of the distant party. If there is a human
interface at the remote end, a challenge and reply authentication scheme will be used.
· The ISSM should approve only certified digital Faxes. The ISSM can obtain a list of certified
secure digital facsimiles from the DAA/DAA Rep/SCO.
16.3.1.1.3 (U) Non-Standard Secure Fax
A non-standard secure FAX consists of a group 3 (GS3) rated standard business FAX with an
approved secure protocol adapter (SPA) and an approved STU-III/STE secure data terminal
(SDT). In an effort to support cost effective alternatives to the certified list of digital Faxes, non-
standard secure Faxes may be purchased and used with approval from the appropriate DAA.
Memory in standard business FAX machines is not designed to meet any of the stringent
requirements outlined above, and therefore cannot be trusted beyond the level of TS SI/TK when
connected to an approved SPA
INTELINK).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
82
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
16.3.1.1.4 (U) Procedures
Each facsimile requires written SOP, or identified procedures within the site CONOPs that outline
the security requirements for that system. The SOP shall be approved by the ISSM and include, at
minimum, the following:
·
Appropriate hardware marking requirements. For example, the unclassified facsimile must be
clearly marked for the transmission of unclassified information only and must have consent to
monitor stickers.
·
Segregation from classified systems and media.
·
Point of Contact authorized to monitor operations.
·
A FAX cover sheet or equivalent will accompany each FAX transmission. This cover sheet will
contain:
o The number of pages transmitted;
o The signature of the official approving the FAX transmission;
o The classification level of the overall information being transmitted;
o The sender’s name and telephone number; and
o The intended recipient’s name and telephone number.
·
Audit logs will be used to record the transmission of any data over a FAX connected to a STU-
III/STE. These logs will be maintained for one year and must include the following information:
o User ID;
o Date and time of FAX transmission;
o The classification level of the information; and
o The recipient’s name, organization and telephone number.
·
The ISSM will require the following minimum information to make an appropriate evaluation:
o Building/Room Number FAX is located;
o FAX manufacture/model number;
o FAX Serial number;
o Verification that the SSO has authorized the introduction of the equipment; and
o Point of Contact’s name and phone number.
·
The following information should be documented and maintained with SCIF records:
o Location and/or location changes;
o Justification;
o Standard operating procedures;
o Identification of equipment (manufacturer, model, serial number, etc);
o Verification of SSO authorization;
o Approval level (matches the STU-III key); and
o Point of contact information.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
83
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
16.3.1.1.5 (U) FAX Accreditation
All facsimile machines within a SCIF must be accredited. All documentation and approval letters
must be maintained with SCIF records.
16.3.2 (U) Computer-FAX/Modem Connectivity
A computer-FAX/modem provides a means for a computer to communicate data via telephone
modem along a wired path to a distant end.
16.3.2.1 (U) Unclassified Computer-FAX/Modem Accreditation Approval
An SSAA/SSP, fully documenting the computer equipment to be used, shall be submitted to the
ISSM. The SSAA/SSP will be processed via the SSO and ISSM for approval.
16.3.2.2 (U) Physical Disconnect of Unclassified Computer-FAX/Modems
The use of acoustic coupled modems is prohibited. Therefore, the physical disconnect of
unclassified computer-FAX/modem equipment from the phone lines is not required.
16.3.3 (U) Computer-Modem Connectivity
16.3.3.1 (U) Unclassified Computer-Modem Connectivity
Access to Commercial Internet Service Provider (ISP). “Dial-out” computer or data terminal
access can only be to those unclassified systems deemed mission essential and approved in writing
by the DAA Rep/SCO. Connectivity of unclassified systems to unclassified networks that are
outside of SCIFs can pose a significant security risk.
16.3.3.1.1 (U) ISP Connectivity
The following procedures and guidelines pertain to those systems connected to networks which
make it possible to connect to, or communicate with, any non-DoD IS.
· The system should be configured to present an unfavorable environment to any attacker, whether
internal or external. The system should have only the functionality required for mission
accomplishment. All other unnecessary services should be eliminated.
· The IS should use available auditing techniques to the fullest extent possible, to ensure the system
is not compromised by attacks. Attacks may occur from across the network or from a legitimate
system user. The SA shall monitor audit logs regularly (preferably daily) and investigate any
abnormalities which may indicate a security compromise. Any attacks detected against Government
systems will be classified Confidential (at a minimum) and reported IAW Chapter 8.
· SA’s should monitor all available resources that provide warnings of system vulnerabilities or on-
going network attacks. Examples include advisories from the military service Computer Emergency
Response Teams (CERT) (i.e., Air Force (AF) AFCERT, Navy NAVCIRT [Computer Incident
Response Team], Army ACERT), and Automated Systems Security Incident Support Team
(ASSIST) bulletins from the Defense Information Systems Agency (DISA).
16.3.3.1.2 (U) IS to IS Connectivity
The following procedures and guidelines deal with those systems connected only to independent IS
systems, either point-to-point or within a community of interest (COI).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
84
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· The system should be configured to present an unfavorable environment to any attacker, whether
internal or external. The system should have only the functionality required for mission
accomplishment, eliminating unnecessary services.
· The IS should use available auditing techniques to the fullest extent possible, to ensure the system
is not compromised by attacks. Attacks may occur from a legitimate system user. The SA shall
monitor audit logs regularly (preferably daily) and investigate any abnormalities which may indicate
a security compromise. Any attacks detected against Government systems will be classified
Confidential (at a minimum) and reported IAW Chapter 8.
· SA’s should monitor all available resources that provide warnings of system vulnerabilities or
ongoing attacks from connected IS. Examples include advisories from the military service
Computer Emergency Response Teams (CERT) (i.e., AFCERT, NAVCIRT [Computer Incident
Response Team], ACERT), and ASSIST bulletins from the DISA.
16.3.3.2 (U) Classified Computer-Modem Connectivity
The only mechanism for using a modem with classified communications is by first using NSA
certified encryption mechanisms. Approval for such connections must be obtained from the DAA
Rep/SCO.
· Identification and Authentication. The NSA encryption mechanism is designed to prevent
disclosure of information while it is being transmitted. Authorized users must verify the identity and
clearance level of the distant party. Access to a host IS must not be made using auto-answer
capabilities unless the host IS enforces access controls for the connection separate from the
communications link controls.
16.3.3.3 (U) Classified Computer-STU-III/STE Data Port Connectivity
The following procedures and guidelines are established for using the data port of a STU-III/STE
terminal and apply to all STU-III/STE users.
· STU-III Data Port Connectivity within a SCIF. Requests for STU-III/STE data port connections
will be submitted to, and evaluated by the DAA Rep/SCO, on a case-by-case basis. An SSAA/SSP
shall be submitted to the appropriate DAA Rep/SCO IAW Chapters 3 and 4 as applicable.
· Identification and Authentication. The STU-III/STE is designed to prevent disclosure of
information while it is being transmitted. Authorized users must verify the identity and clearance
level of the distant party. Access to a host IS must not be made using auto-answer capabilities
unless the host IS enforces access controls for the connection separate from the communications
link controls.
· Connectivity Requirements.
o For all connections of an IS or network to a STU-III/STE, the STU-III Security Access
Control system (SACS) must be employed. Exceptions may be granted by the DAA
Rep/SCO.
o The associated STU-IIIs/STEs must be keyed to the appropriate level to protect the data
contained in the ISs.
o Community of Interest. All connected ISs using the STU-III/STE data port in a COI must
be identified and accredited with identical Accredited Security Parameters (ASP)
(classification levels, compartments, caveats, and mode of operation).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
85
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Connectivity Restrictions. For all connections of an IS to a STU-III/STE data port, the following
restrictions apply:
o Use of the STU-III/STE in the non-secure data mode is prohibited.
o Use of the STU-III/STE data port feature will be limited to connectivity of a specific set of
STU-III/STE terminal units and ISs called a COI.
o The cable connecting an IS to a STU-III/STE data port must be installed IAW the National
TEMPEST technical requirements.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
86
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 17 - INTERCONNECTING INFORMATION SYSTEMS
17.1 (U) PURPOSE
This chapter describes policies, issues, and guidance for manual as well as automated processes that
can be used to process and move sanitized and collateral information across boundaries of different
levels of classification. The primary emphasis in managing information to support the war-fighter is
to push information out of the SCI-controlled security domains into collateral security domains.
17.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
YES
DESIGN PHASE
YES
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
NO
17.3 (U) DISCUSSION
Policy requires that SCI information be safeguarded during all phases of operation, processing or
storage on ISs. This is required for individual ISs as well as ISs that are connected, particularly
when operating at different levels. Different levels refers to two security domains which differ in
some component of classification level, including respective compartments, sub-compartments,
caveats, control markings or special handling marking. Different levels can also refer to the users
(their security clearances, accesses, or need-to-know) of each respective system and the related
Levels of Concern (LOC), Protection Level (PL), and the respective technical features implemented
within each IS and security domain. When at least one system processes SCI, inter-domain
connections will follow the TOP SECRET And Below Interoperability (TSABI) accreditation
process. See IC CIO Top Secret/Sensitive Compartmented Information
(SCI) and Below
Interoperability Policy (TSABI), 7 February 2000
17.3.1 (U) Interconnected Information Systems
Interconnected IS are composed of separately accredited IS’s. Whenever separately accredited IS
are interconnected, each DAA shall review the security attributes of each system to determine
additional security requirements to be imposed. Such a determination will be based on: the technical
operating level of each system (LOC/PL); the classification level of the information on each system;
or the combination of users who have access to the respective IS. Respective DAAs shall document
the interconnection requirements as part of the accreditation for the interconnected systems. Such
interconnection determination also applies to support architecture connections, e.g., between
networks.
17.3.2 (U) Inter-Domain Connections
When two different ISs are connected and the IS operate at different levels, the connection is an
inter-domain connection. Any inter-domain connection, whether between IS or between networks,
will comply with DCID 6/3, Section 7.B, Controlled Interface requirements, to provide appropriate
confidentiality and integrity adjudication. The accreditation shall follow the TSABI process.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
87
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
17.3.3 (U) Controlled Interface
The controlled interface requirements may be met by the IS devices themselves, or by a separate
device or system added between two domains. Any IS or specific device (or combination) which
facilitates the connection between two security domains, IS or networks, is considered a controlled
interface. The specific requirements imposed on a controlled interface are highly dependent upon
the expected flow of information between the two domains. All controlled interfaces have common
requirements to maintain the integrity of the critical processes that control the information flow
across the connections. These mandate physical protection of the controlled interface, preventing
users from modifying the capabilities of the controlled interface, monitoring usage, and monitoring
the interface for failure or compromise. In general, any protocols or services, which are not
explicitly authorized, should be denied.
17.3.3.1 (U) One-Way Connections
When information flows in only one direction, the controlled interface requirements may be
simplified, but are no less important. A controlled interface used in connection with controlling
information flow in only one direction will shut off services and data flow in the reverse direction.
The controlled interface may provide automated formatted or pre-determined acknowledge/non-
acknowledge messages which do not contain any substantive information to the source IS, without
altering the designation as a one-way controlled interface.
17.3.3.1.1 (U) Equal Classification Connections
Connections between ISs or networks of equal classification occur when security domain levels are
the same, but are maintained separate for other reasons, e.g. system technical features implemented
on the respective IS or the set of users (their security clearances, accesses, or need-to-know).
17.3.3.1.2 (U) Low-to-High Connections
The information being passed from the low side will not have a confidentiality requirement; but the
controlled interface will have to maintain the confidentiality of information at the high side from any
exposure to the systems or users on the low side. The primary concern of a low-to-high connection
is allowing information to flow without significant impairment but with appropriate integrity
controls to protect the high side IS and their data. As more unstructured data types are identified
for transfer, it becomes more difficult to prevent malicious code from being passed along with the
desired information.
17.3.3.1.3 (U) High-to-Low Connections
The primary requirement for high-to-low connections is to protect the confidentiality of information
that is not authorized for transfer to the low side. All information being transferred out of a domain,
which has classified information that should not be passed across the boundary, will require a
process that makes the determination on releasability. The processes that make this determination
are called reliable review processes. These processes may be manual (reliable human review),
automated
(for highly formatted, integrity-wrapped, or reliably labeled information), or a
combination depending upon the type and format of the data.
17.3.3.1.4 (U) Other Unequal Classification Level Connections
Sometimes, there is no real high/low relation between two domains, but simply a difference in
information where separate data owners on each side of a connection have their own unique
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
88
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
requirements. In this instance, each side is responsible for establishing the confidentiality controls
and restrictions for review and release of information to the other side.
17.3.3.2 (U) Dual-Direction Connections
When information is expected to flow in both directions, the requirements of low-to-high, high-to-
low, and other equal or unequal level connections must be combined within the implementation of
the controlled interface.
17.3.3.3 (U) Multi-Domain Connections
Some controlled interface devices are designed to provide support for connections between more
than two domains simultaneously. The implementation for these connections should comply with
the requirements for all of the individual combinations of paired connections within the controlled
interface device (e.g., three domains have three connection pairs, four domains have six connection
pairs, etc.).
17.3.4 (U) Review Procedures
Review procedures for all data transfers are discussed in further detail in 18.3.1.
17.3.4.1 (U) Reliable Human Review
Human review of information has to meet two aspects to be sufficient. First, a review of the
information content to validate that it meets criteria for transfer across the domain boundary.
Second, a technical review of the information as assembled to ensure that information normally
hidden within a presentation is also authorized for transfer across the domain boundary. Any human
review process conducted with an IS implements a combination of system capabilities to allow the
human to conduct a review of the information. Presentation applications will help the human review
data in its presentation form (e.g., a picture looks like a picture). Sometimes these applications will
also meet the criteria for technical review by showing data in alternate forms including appended
information. If these applications do not have this capability, then other applications may be
required to complete technical data reviews. Because a human is interacting with automated
processes to conduct reviews, the information being reviewed should have an integrity feature that
validates that the review process does not alter the information being reviewed. This added
capability is what makes the human review a reliable human review. Integrity and accountability
requirements on the reliable human review process will require strong control of the information
through the review process and control and accountability for the users associated with the reliable
human review.
17.3.4.2 (U) Automated Review
When information is highly formatted, integrity-wrapped, or reliably labeled information, some
automated processing may aid a human or may even make the decisions instead of a human. For
automation to eliminate the reliable human review, the automated processes need to emulate all
activities that would be performed by a human. When the information is not highly formatted,
human review will still be required.
17.3.5 (U) Foreign National Access to Systems Processing Classified Information
U.S. Government classified information is not releasable to foreign nationals except as authorized
by the U.S. Government.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
89
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Data owners can designate their information as releasable to individuals of specific nationalities.
The PAA/DAA shall obtain the written permission of all applicable data owners before allowing
access by foreign nationals to a system that contains information that is not releasable to individuals
of those nationalities.
The decision to allow foreign nationals access to systems that process classified information shall be
explicit and shall be in writing. This includes controls over foreign national access or proximity to
systems that process NOFORN classified information.
If a proposed IS serves as a controlled interface connection to an IS with foreign national users, the
IS must meet controlled interface requirements of DCID 6/3 Chapter 7. The DAA Rep/SCO must
ensure that written concurrence for the controlled interface is obtained from data owners and
affected DAAs prior to permitting implementation of the connection. Controlled interfaces which
connect to an IS that processes SCI information must be accredited through the TSABI process as
noted in Chapter 17.
Foreign national ISs may only be allowed in shared SCIF facilities with formal joint approval.
Connections between IS are only permitted among systems at the same classification level, upon
the approval of the PAA.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
90
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 18 - INFORMATION TRANSFER AND ACCOUNTING PROCEDURES
18.1 (U) PURPOSE
This chapter outlines procedures for the transfer of information or software among ISs of different
classification levels using information storage media. The procedures are intended to protect the
confidentiality of information on the media as well as other data on the end-point IS at different
levels, prevent transfers of malicious code (Chapter 10 is germane), and prevent violation of legal
copyright or license rights.
18.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
NO
DESIGN PHASE
NO
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
18.3 (U) PROCEDURES
This chapter outlines procedures for the transfer of classified information at varying levels to ISs of
different classification levels. For any system that operates with PL-3 and below functionality,
media that is placed into that system must be classified at the highest level of information on the
system until reviewed and validated. The following address proper classification determination
during the access and transfer process. Procedures for data transfers must be approved by the
ISSM.
18.3.1 (U) Reliable Human Review of Data
Reliable Human Review is the combination of the data content review, review for hidden data, and
integrity controls applied to the information. Human review is a process of validating the
classification of data
(classification level, compartments, sub-compartments, caveats, control
markings or special handling marking) when it is stored or moved from an IS. Human review may
be required for validating data classification for hardcopy prints (from systems with less than PL-4
labeling functionality), data being transferred to media, or manual transfers between security
domains.
· Human review of information has to meet two criteria to be sufficient: a review of the information
content to validate the actual classification level of the data, and a review of embedded or hidden
information that is part of the data.
· Human review requires an individual who is knowledgeable of the subject matter to inspect the
contents and provide validation of the data classification. This individual has to be able to see the
information in its presentation form to make this determination.
· Information in its presentation form does not always show embedded or hidden data. This data may
require a different process or application (or tools) to reveal the hidden data for the human review.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
91
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Many users do not realize that some computers often store data on media in fixed length blocks,
segments, or tracks. Because data records do not always fill the available space, residual
information from memory is appended to the data record. The content of this information is
unpredictable and may contain classified or other information from unrelated processes.
· Residual data that exists within information stored in memory may get copied as part of the data
whenever it is duplicated.
· There are tools that can aid the human who conducts the review process. Tools (e.g., BUSTER)
can aid in the review of large amounts of data. A review of data is more reliable if it includes both a
human review and review using tools. Reviews should not rely solely on an automated review.
Automated reviews such as tools within guards may be the only authorized exceptions to human
review. All automated review processes must be approved by the appropriate DAA.
· Because a human is interacting with automated processes to conduct reviews, the information being
reviewed should have an integrity feature so that the review process does not alter the information
being reviewed. For example, write protect media before the information review.
· A reliable human review may be a required component of a GUARD or Controlled Interface.
Integrity and accountability requirements on the reliable human review process will require strong
control of the information and its integrity through the review process, and added controls for
accountability for the users associated with the reliable human review.
18.3.2 (U) Media Transfers In/Out of an Organization
All personnel will process outgoing media or report the receipt of media through the ISSM/ISSO
or his/her designee before shipment out or use of such media. To ensure the correct classification
(including unclassified) and appropriate labeling is being used, conduct reliable human review of
100% of information on the media. During the reliable human reviews, media should be write-
protected so that no changes can occur. Identification of incorrect write protection requires
installation of correct write protection and then proper conduct (or repetition) of the reliable human
review. Virus policy prohibits movement of floppy disks between systems unless appropriate
scanning procedures are implemented. If any problems are found, the media is not to be transferred
or used, and appropriate reports will be generated and provided to the ISSM/ISSO. If the media is
to be subsequently accounted for, make appropriate entries in the organization media accounting
system.
18.3.3 (U) Disposition of Excess or Obsolete COTS Software
Software may be reused or released for resale only if:
· The software is still in its original unopened shipping wrapper.
· The user has personal knowledge that the software is not classified and is documented accordingly.
If the user cannot substantiate that the software is not classified, then he/she must ensure classified
reutilization within the agency or organization or destruction by approved methods, as appropriate.
Do not return the software to the issuing authority if it cannot be reused.
18.3.4 (U) High-to-Low Data Transfer by Media
This section addresses use of media to transfer information from a higher classified system to a
lower classified system or a system with a different Accredited Security Parameters
(ASP),
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
92
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
including Unclassified. The procedures will differ based on the system capabilities present for
different PL levels.
18.3.4.1 (U) PL-3 and Below Functionality
A local SOP must be written to outline the steps to protect the information when transferring data.
The following general steps will be identified in the procedures and followed accordingly:
· The DAA Rep/SCO and ISSPM/ISSM must approve the procedures and individuals involved.
· The ISSM/ISSO or designee must approve each transfer on a case-by-case basis.
· The media to be used in the process must be new.
· The information to be transferred is placed on the media. Then the media should be write-
protected.
· Perform a reliable human review of 100% of the information as stored on the media to verify its
classification level.
· Perform scanning of the media for viruses.
· Remove, validate write-protection and mark the media at the appropriate classification level as
determined by the human review.
· The media may now be handled as marked.
18.3.4.2 (U) PL-4 and Above Functionality
A local SOP must be written to outline the steps to protect the information when transferring data.
The following general steps will be identified in the procedures and followed accordingly:
· The DAA Rep/SCO and ISSPM/ISSM must approve the procedures and individuals involved.
· The media to be used in the process must be new.
· Copy the information to the media.
· Perform scanning of the media for viruses.
· Remove, write protect, and mark the media at the appropriate classification level (trusted from the
PL-4 and above system).
· The media may now be handled as marked.
18.3.5 (U) Low-to-High Data Transfer by Media
This section addresses use of media to transfer information from a lower classified system,
including unclassified, to a higher classified system or a system with a different ASP. A local SOP
must be written to outline the steps to protect the media and systems involved when transferring
data. One obvious reason for these procedures is to permit unclassified software such as Lotus and
dBase to be installed into an IS containing classified information without requiring the media to
become classified.
· The DAA Rep/SCO and ISSPM/ISSM must approve the procedures and individuals involved.
· The media to be used in the process must be new or an approved transfer disk that has been virus
checked.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
93
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Transfer information onto the media.
· Perform scanning of the media for viruses.
· Ensure the transfer media is adequately write-protected if it is to remain classified at the lower
level.
· If the write-protect mechanism on the media is securely maintained, the media may remain at its
lower classification level (the factory-write protect mechanism on a diskette is adequate).
· If the write protect mechanism is not correctly maintained, the media must be marked and handled
at the highest classification level with the most restrictive handling caveats of the information
processed by the IS.
· Floppies can be physically write-protected, zip drives can be electronically write-protected and
CD/DVDs can remain at the lower classification level when used in read only devices.
· Before transferring information to the higher classified system, perform scanning of the media for
viruses.
· Transfer the data from the media to the higher classified IS.
· Following transfer, examine the write-protect device to validate that it is still securely intact.
18.3.6 (U) Demonstration Software
Floppy diskettes and removable hard disks used for demonstrations, with the intent of being
returned to a vendor, must be processed on a computer that has never processed or stored
classified data. Otherwise, the demonstration media cannot be released back to the vendor and
should be destroyed. If returned to the vendor, a fully cleared and indoctrinated individual must
verify that the media was used only in an unclassified computer.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
94
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 19 - MULTI-POSITION SWITCHES
19.1 (U) PURPOSE
The purpose of this chapter is to provide the policy and procedures outlining the minimum
requirements for the management of multi-position switches. This policy applies to all elements that
use multi-position switches to share a common keyboard, mouse and monitor between different
CPU’s. These CPU’s may process, store, produce, or transmit information of different
classifications, compartments, sub-compartments, code words or releasability.
19.2 (U) SCOPE
This chapter states the policy for Key Board/Video/Mouse (KVM) or Key Board/Monitor/Mouse
(KMM) Switches used to connect systems operating at different classification levels,
compartments, sub-compartments, caveats, control markings or special handling marking under the
cognizant security authority of DIA/NSA including those of contractors. This policy does not
restrict the use of these types of devices based on the sensitivity of the information or levels of
classification of the data processed on the CPU’s that are shared. This policy applies to all
individuals who have authorized access to these devices on the systems they use. Not all users are
approved for this type of access, and this policy does not provide that approval or countermand in
any way any restrictions already placed on the user for the use of these devices.
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
YES
DESIGN PHASE
YES
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
19.3 (U) POLICY
Only KVM switches on the DIA Standard Products List for SCIFs accredited by DIA and KVM
switches on the NSA Network Enterprise Solutions (NES) approved products list for SCIFs
accredited by NSA shall be used within corresponding SCIFs when sharing a Key Board, Video
Monitor or Mouse between CPUs at different classification and/or compartment levels. KVM
switches currently in use that do not meet tempest or IS requirements must be replaced with
DIA/NSA approved switches. Authorizations are required from the DAAs of the respective
systems when using a KVM switch to share the Key Board, Video Monitor, or Mouse. The DAAs
are DIA for JWICS, NSA for NSANET, and DISA for NIPRnet and SIPRnet. The use of
switchboxes for print services between classification and compartment levels is prohibited.
Switchboxes may be used between the same classification and compartment levels for print
services.
19.4 (U) RESPONSIBILITIES
19.4.1 (U) DAA Rep
· Ensure all authorizations from DAAs of respective systems are obtained.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
95
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
19.4.2 (U) ISSM
· Maintain the KVM Switch User Agreements files.
· The ISSM will verify that the user has the necessary training and complies with the requirements
for the introduction and use of multi-position switches.
19.4.3 (U) ISSO/System Administrator
· Ensure that the Configuration Management Board (CMB) approves the systems.
· Ensure that the systems are installed correctly and meet all TEMPEST Standards.
· Ensure the desktop banners, backg2rounds, and screen locks have the proper classification banner.
· Ensure the KVM is documented and approved in all pertinent SSP/SSAAs.
19.4.4 (U) User
· Protect the Information System and KVM in your area.
· Report any spillage of classified information IAW the JDCSISSS.
· Safeguard and report any unexpected or unrecognized computer output, including both displayed
and printed products IAW JDCSISSS.
· Use different passwords on each system connected through a KVM.
· Ensure that each systems screen lock displays the classification level and that a password is
required to regain entry to the system.
· Ensure that the systems screen lock is invoked if the system is left unattended or if there is a 15-
minute period of inactivity for each system.
· Responsible for marking/maintaining magnetic media IAW Chapter 12 of JDCSISSS.
19.5 (U) IS REQUIREMENTS
The introduction and use of multi-position switches in a SCI environment presents a moderate
degree of risk to classified or sensitive information and systems. Therefore, all users will be
responsible for the management of these devices. To minimize the risk of inadvertently entering
information onto the wrong network, the following requirements must be met. Authorization of the
KVMs must be documented within all respective certification and accreditation documents.
· Port Separation. The switch must be used with ports one and two for one classification level (i.e.
unclassified and/or secret) and ports three and four for higher classification levels (i.e. JWICS and
NSANet).
o For example and additional protection using the approved 4-port switchbox for three
different classifications, use Port 1 for Unclassified, Port 2 for Secret and Port 4 for SCI.
· Labels. All information systems components must be labeled IAW DCID 6/3, Paragraph 8.B.2 (a
and b). All switch positions, cables, and connectors must be clearly marked with the appropriate
classification labels.
· Desktop Backgrounds. To avoid inadvertent compromises, systems joined by multi-position
switches will utilize desktop backg2rounds that display classification banners at the top or bottom.
The classification banner will state the overall classification of the system in large bold type, and the
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
96
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
banner backg2round will be in a solid color that matches the classification (SCI - yellow, Top Secret
- orange, Secret - red, Confidential - blue, Unclassified - green). When systems have a similar
classification level, but require separation for releasability or other constraints, use of unique colors
for the different systems is permissible.
·
Screen Locks. Screen Lock applications must display the maximum classification of the system on
which the system is currently logged into and shall implement a lockout feature to re-authenticate
the user.
·
Smart Keys/Permanent Storage Medium. Systems using KVM switches must not employ “smart”
or memory enhanced/data retaining keyboards, monitors or mice. These types of interfaces provide
memory retention that creates a risk of data transfer between systems of different classifications.
·
Hot Key Capability. Switches that support “Hot-Key” capability to switch, toggle or otherwise
affect the switching between CPUs are prohibited.
·
Scanning Capability. Switches with the ability to automatically scan and switch to different CPUs
are prohibited.
·
Wireless or Infrared Technology. Systems using KVM switches must not use keyboards or mice
with wireless or infrared technology
·
Unique Password Requirement. At a minimum, users must ensure that they use different/unique
passwords for each system connected through a multi-position switch. Whenever possible, system
administrators should employ different logon USERIDs to help users further distinguish between
the systems.
·
Data Hierarchy. Data of a higher classification must not be introduced to a system of a lower
classification.
·
Security CONOPS. A site with a requirement for multi-position switches must include the KVM
procedures within the site’s SECONOPS. The approval authority will be the Site ISSM.
·
Training. ISSMs/ISSOs/Supervisors will ensure user training and compliance to the requirements
associated with the introduction and use of multi-position switches.
·
TEMPEST. Blanket approval to install KVM switches is granted within DIA accredited SCIFs
located within the US and meeting NSTISSAM TEMPEST/2-95A, 3 Feb 00, recommendation “I”
(having 100 meters of inspectable space) as defined by the SCIF’s TEMPEST accreditation
document from DIA/DAC-2A. Blanket approval to install KVM switches is granted within NSA
accredited SCIFs located within the US and meeting NSTISSAM TEMPEST/2-95A, 3 Feb 00,
Zones C and D having more than 100 meters of inspectable space. Prior approval is required for
overseas facilities and all other recommendations.
19.6 (U) Procedures for LOGON/Switching Between Systems
19.6 1 (U) Logging on to systems
· Identify the classification of the system currently selected.
· Use the login and password appropriate to that system.
· Verify the classification of the present system by checking the classification label.
· Begin processing.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
97
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
19.6.2 (U) Switching between systems
· Select desired system with the multi-position switch.
· Verify the classification of the present system by checking the classification label.
· Begin processing at the new classification level.
EXCEPTIONS. Any exception to this policy requires approval of the DAA Rep responsible for
the Certification/accreditation of systems in your SCIF.
19.7 (U) KVM SWITCH USER AGREEMENT
The user agreement (Figure 19-1) documents training and certification for personnel using the
KVM switch.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
98
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
KVM USER AGREEMENT FORM
1. (U) KVM SWITCH USER AGREEMENT. The user agreement documents training and certification
for personnel using the KVM switch.
1.1.
(U) Procedures for LOGIN and Switching Between Systems. This process must be performed
for each switch between systems. When the DoDIIS system is not selected, it is
required
to
be
screenlocked.
1.1.1.
(U) Logging onto a System.
· Identify the classification of the system currently selected
· Use the login and password(s) appropriate to that system
· Verify the classification of the present system by checking the classification label
· Begin Processing
1.1.2.
(U) Switching Between Systems.
· Screenlock the system you are currently working on.
· Select desired system with the KVM switch.
· Enter your user id and password to deactivate the screen lock.
· Verify the classification of the present system by checking the classification label.
1.1.3.
(U) Logging Off of a System.
· Close all applications processing on the active system
· Logout of the system when processing in no longer required on the system
· Logout of system at the end of duty day
1.2.
(U) A weekly inspection of tamper seals (if any) will be performed by the user.
1.3.
(U) Any suspected tampering and/or mishandling of KVM will be reported to your site ISSM.
Printed Name of User
__________________________________________________
Signature ____________________________
Date
__________________
The above individual has received the necessary training and has complied with the requirements
for
application and use of KVM switches
Printed Name of ISSM
__________________________________________________
Signature ____________________________
Date
__________________
Figure 19.1 (U) Kvm Switch User Agreement Form.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
99
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 20 - COLLABORATIVE COMPUTING
20.1 (U) PURPOSE
The purpose of this chapter is to provide guidance and procedures to for use of video cameras and
microphones on information systems within SCIFs. This guidance applies to all organizations using
video cameras and microphones on information systems for collaborative computing. This guidance
also applies regardless of the sensitivity of the information or levels of classification for which the
video cameras/microphones are being used.
20.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
NO
DESIGN PHASE
NO
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
20.3 (U) IMPLEMENTATION PROCEDURES
If not correctly configured and controlled, collaborative computing technologies can allow an
unauthorized user to see and hear national security information and material at another user’s
workstation area that they may not be cleared for. This policy establishes the minimum technical
and procedural controls that must be in place to limit these risks.
20.3.1 (U) Collaborative Computing Activation
Collaborative computing mechanisms shall not be remotely activated, nor may they have any auto-
answer capabilities that automatically activate the video and audio recording/transmitting devices.
Activation requires an explicit action by the workstation user (e.g., in the case of a desktop video
teleconference, the user of the desktop shall be required to take an explicit action to turn on the
camera and microphone). Remote activation of a user’s camera or microphone is prohibited.
· Collaborative computing mechanisms that provide video and/or audio conference capabilities shall
provide a clear visible indication that the video and audio mechanisms are operating to alert SCIF
personnel when recording or transmitting.
· While conducting a collaborative computing session, the user shall take all reasonable measures to
ensure that no sensitive information is inadvertently made either auditibly or visually accessible to
the collaborative computing mechanism. This includes advising all personnel in the immediate area
that the collaborative computing mechanism will be operating as well as sanitizing any other
sensitive material/system that may be in view of the video recording/transmitting equipment.
· Once the collaborative session is completed, the user shall immediately take an explicit action to
disconnect/terminate the collaborative computing mechanism.
· Users shall not leave the workstation unattended while a peer-to-peer collaborative computing
mechanism is in progress.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
100
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
20.3.2 (U) Video cameras/microphones connected to SCI information systems
· Camera(s) must have a device or clear visible display that notifies the user when it is in use (e.g.,
light).
· Camera(s) will be turned off and lens will be covered with an opaque covering, when camera is not
in use.
· Microphone(s) should have a push to talk button (implemented in hardware or software), but must
have a mute or hold capability (e.g., on/off switch).
· Use of cameras/microphones must have written approval from the site ISSM and all collaborative
computing devices must be identified on the facility’s baseline.
· Desktop level collaborative computing mechanisms must use a headset. If external loud
speakers/amplified sound are used, the system speakers must be installed within a closed room with
walls that meet the requirements of DCID 6/9, of sound transmission class (STC) 50 or better,
(sound group 4).
20.3.3 (U) Video cameras/microphones connected to collateral/unclassified information systems
· Cameras must be placed in an enclosed area with a door that is acoustically isolated from the other
SCI discussion areas.
· No systems/documents/media of greater classification may be displayed or in view of the camera(s).
· Camera(s) must have a device or clear visible display that notifies the user when it is in use (e.g.
light).
· Camera lens will be covered with an opaque covering, when the camera is not in use.
· A classification sign will be placed on door when camera or microphone is in use.
· Microphone(s) should have a push to talk button (implemented in software or hardware), but must
have a mute or hold capability (e.g., on/off switch).
· Use of cameras/microphones must have written approval from the site ISSM and all collaborative
computing devices must be identified on the facility’s baseline.
· Unclassified video teleconferencing centers (VTC) and/or like video/audio recording equipment
must be deactivated and disconnected when not in use.
20.3.4 (U) Collaborative Computing Approval
Any multi-classification collaborative computing mechanisms, VTC or like systems that have video
and/or audio capability integrated into one system must be previously approved by the DIA
certified tempest technical authority (CTTA). Approval may be requested by submitting appendix
“j” of DoD 5105.21-M-1 to DIA/DAC-2A for review.
20.3.5 (U) Responsibilities
· ISSM:
· Verify that the user has the necessary training and complies with the requirements for the
introduction and use of video cameras/microphones.
· ISSO/system administrator:
· Ensure that the configuration management board approves the cameras/microphones.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
101
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Ensure that the video cameras/microphones are installed correctly and meet all TEMPEST
standards, (i.e., refer to your facilities TEMPEST accreditation for the specific red/black
installation guidance and outlined in NSTISSAM TEMPEST 2-95(a) Dtd: 03 Feb 2000
(U//FOUO).
· User:
· Protect the information system in your area;
· Ensure camera/microphone is off when not in use;
· Ensure cover is placed over lens of camera when not in use;
· Report any violation of this policy to the site ISSM as a security incident.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
102
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 21 - CLEARING, SANITIZING, AND RELEASING COMPUTER COMPONENTS
21.1 (U) PURPOSE
The purpose of this chapter is to provide guidance and procedures to clear and sanitize magnetic storage
media that is no longer useable, requires transfer, or should be released from control. These
procedures apply to all ISs containing electronic, electromagnetic, electrostatic, or magnetic
storage media. For clarification, Magnetic storage media is considered to be any component of a
system that, by design, is capable of retaining information without power.
21.2 (U) SCOPE
These procedures are effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
NO
DESIGN PHASE
NO
DEVELOPMENT PHASE
YES
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
21.3 (U) RESPONSIBILITIES
The ISSM is responsible for the security of all ISs and media assigned to the organization and
under his/her purview. To protect these assets, he/she must ensure the security measures and
policies contained within this chapter are followed. Additionally, the ISSM will publish
supplemental organizational procedures (SOPs, etc.), if needed, to implement the requirements
herein.
21.4 (U) Review of Terms
To better understand the procedures contained herein, it should be understood that overwriting,
clearing, purging, degaussing, and sanitizing are not synonymous with declassification. The
following are definitions:
· Clearing. Clearing is the process of removing information from a system or the media to facilitate
continued use and to preclude the IS from recovering previously stored data. In general, laboratory
techniques allow the retrieval of information that has been cleared, but normal operations do not
allow such retrieval. Clearing can be accomplished by overwriting or degaussing.
· Sanitizing (Also purging). Sanitizing is the process of removing information from the media or
equipment such that data recovery using any known technique or analysis is prevented. Sanitizing
shall include the removal of data from the media, as well as the removal of all classified labels,
markings, and activity logs. In general, laboratory techniques cannot retrieve data that has been
sanitized/purged. Sanitizing may be accomplished by degaussing.
· Destruction. Destruction is the process of physically damaging media so that it is not usable and
there is no known method of retrieving the data.
· Declassification. Declassification is an administrative process used to determine whether media no
longer requires protection as classified information. The procedures for declassifying media require
DAA Rep or SCO approval.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
103
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Periods Processing. Provided the sanitization procedures between each protection level segment
have been approved by the DAA Rep/SCO based on guidelines from the data owner(s) or
responsible official(s), the system need meet only the security requirements of each processing
period, while in that period. If the DAA Rep/SCO approves the sanitization procedures for use
between periods, the security requirements for a given period are considered in isolation, without
consideration of other processing periods. Such sanitization procedures shall be detailed in the
SSAA/SSP.
*NOTE: Periods processing will not be approved for NSA accredited system.
21.5 (U) PROCEDURES
The procedures contained below meet the minimum-security requirements for the clearing,
sanitizing, releasing, and disposal of magnetic media as well as guidance for other types of
information storage media. These procedures will be followed when it becomes necessary to release
magnetic media, regardless of classification, from SCI channels. Overwriting can not sanitize media
that has ever contained SCI, other intelligence information, or Restricted Data. Such media must be
degaussed before release.
21.5.1 (U) Overwriting Media
Overwriting is a software process that replaces the data previously stored on magnetic storage
media with a predetermined set of meaningless data. Overwriting is an acceptable method for
clearing. However, the effectiveness of the overwrite procedure may be reduced by several factors:
ineffectiveness of the overwrite procedures, equipment failure (e.g., misalignment of read/write
heads), or inability to overwrite bad sectors or tracks or information in inter-record gaps. Software
overwrite routines may be corrupted by hostile computer viruses. Overwriting is not an acceptable
method to declassify media.
· Overwriting Procedure. The preferred method to clear magnetic disks is to overwrite all locations
with a pseudo-random pattern twice and then overwrite all locations with a known pattern.
· Overwrite Verification. Overwrite procedures must be verified by the ISSM or his/her designee.
21.5.2 (U) Degaussing Media
Degaussing (i.e., demagnetizing) is a procedure that reduces the magnetic flux on media virtually to
zero by applying a reverse magnetizing field. Properly applied, degaussing renders any previously
stored data on magnetic media unreadable and may be used in the sanitization process. Degaussing
is more effective than overwriting magnetic media.
Magnetic media is divided into four types (I, II, IIA, III) based on their coercivity. Coercivity of
magnetic media defines the magnetic field necessary to reduce a magnetically saturated material’s
magnetization to zero. The level of magnetic media coercivity must be ascertained prior to
executing any degaussing procedure.
21.5.2.1 Types of Degausser
The individual performing the physical degaussing of a component must ensure that the capability
of the degausser meets or exceeds the coercivity factor of the media, and that the proper type of
degausser is used for the material being degaussed. The four types of degaussers are:
· Type I. Used to degauss Type I media (i.e., media whose coercivity is no greater than 350 Oersteds
[Oe]).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
104
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· Type II. Used to degauss Type II media (i.e., media whose coercivity is no greater than 750 Oe).
· Type IIA. Used to degauss Type IIA media (i.e., media whose coercivity ranges from 751 to 900
Oe).
· Type III. Used to degauss Type III media (i.e. media whose coercivity ranges from 901 to 1700
Oe). Currently, there are no degaussers that can effectively degauss all Type III media. Some
degaussers are rated above 901Oe, and their specific approved rating will be determined prior to
use.
21.5.2.2 (U) Degausser Requirements
Refer to the current issue of the National Security Agency (NSA) Information Systems Security
Products and Services Catalogue (Degausser Products List Section), for the identification of
degaussers acceptable for the procedures specified herein. These products will be periodically
tested to assure continued compliance with the appropriate specification. National specifications
provide a test procedure to verify continued compliance with the specification.
21.5.2.3 (U) Use of a Degausser
Once a degausser has been purchased and has become operational, the gaining organization must
establish a SOP explaining how it will be used. The degausser must be certified annually.
21.5.3 (U) Sanitizing Media
Tables
21-1 and
21-2 provide instructions for sanitizing data storage media and system
components.
Table 21.1. (U) Sanitizing Data Storage Media
MEDIA TYPE
PROCEDURE(S)
Magnetic Tape
Type I
a or b
Type II,IIA
b
Type III
Destroy
Magnetic Disk Packs
Type I
a or b
Type II,IIA
b
Type III
Destroy
MEDIA TYPE
PROCEDURE(S)
Magnetic Disks
Floppies
a or b, then Destroy
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
105
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Bernoullis
Destroy
Removable Hard Disks
a or b
Non-Removable Hard Disks
a or b
Optical Disks
Read Only (including CD-ROMs)
Destroy
Write Once, Read Many (WORM)
Destroy
Read Many, Write Many
Destroy
PROCEDURES
These procedures will be performed or supervised by the ISSO.
a. Degauss with a Type I degausser. See 21.4.3.2.
b. Degauss with a Type II, IIA degausser. See 21.4.3.2.
Table 21.2. (U) Sanitizing System Components
TYPE OF COMPONENT
PROCEDURE(S)
Magnetic Bubble Memory
a or b or c
Magnetic Core Memory
a or b or d
Magnetic Plated Wire
d or e
Magnetic-Resistive Memory
Destroy
SOLID STATE MEMORY COMPONENTS
Dynamic Random Access Memory (DRAM) (Volatile)
e and i
if RAM is functioning
d, then e and i
if RAM is defective
f, then e and i
Static Random Access Memory (SRAM)
j
Programmable ROM (PROM)
Destroy (see h)
Erasable Programmable ROM (EPROM/UVPROM)
g, then c and i
Electronically Erasable PROM (EEPROM)
d, then i
Flash EPROM (FEPROM)
d, then i
PROCEDURES
These procedures will be performed or supervised by the ISSO.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
106
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
a. Degauss with a Type I degausser.
b. Degauss with a Type II, IIA degausser.
c. Overwrite all locations with any random character.
d. Overwrite all locations with a random character, a specified character, then its complement. (Contact
vendor for specific erase procedures, usually accomplished via the command prompt/MS-DOS prompt)
e. Remove all power, including batteries and capacitor power supplies from RAM circuit board.
f. Perform three-power on/off cycles (60 seconds on, 60 seconds off each cycle, at a minimum).
g. Perform an ultraviolet erase according to manufacturer’s recommendation, but increase time
requirements by a factor of 3.
h. Destruction required only if ROM contained a classified algorithm or classified data.
i. Check with the ISSPM/DAA Rep/SCO to see if additional procedures are required.
j. Store a random unclassified test pattern for a time period comparable to the normal usage cycle.
21.5.4 (U) Destroying Media
Data storage media will be destroyed IAW DAA/DAA Rep/SCO approved methods.
21.5.4.1 (U) Expendable Item Destruction
Expendable items (e.g., floppy diskettes and hard drives) are not authorized for release and reuse
outside of the SCI community after they have been degaussed (Table 21.1). If these items are
damaged or no longer deemed usable, they will be destroyed. When destroying, remove the media
(magnetic mylar, film, ribbons, etc.) from any outside container (reels, casings, hard cases or soft
cases, envelopes, etc.) and dispose of the outside container in a regular trash receptacle. Cut the
media into pieces (a crosscut chipper/shredder may be used to cut the media into pieces) and then
burn all pieces in a secure burn facility or pulverize to 2.5mm (3/16-inch) specification. If the
Environmental Protection Agency
(EPA) does not permit burning of a particular magnetic
recording item, it will be degaussed, cut into pieces (a chipper/shredder preferred) and disposed of
in a regular trash receptacle.
Note: Use of a burn bag does not necessarily mean that organizations actually burn. Many
organizations have pulverization facilities that handle all burn bags.
21.5.4.1.1 (U) Shipping Instructions
Below are the shipping instructions for destruction of other classified items to include floppy discs,
typewriter ribbons, magnetic tapes, hard drives that have been removed from the reels, film,
viewgraphs, chips, circuit boards, exterior cases and paper. Paperwork required is either an SF153
Destruction Form or a DD1149 (shipping document). POC is at NSA LL24, commercial (301)
688-6136/DSN 644-6136 (NSTS 972-7248), Suite 6875;
· COMSEC MATERIAL, send by regular mail to:
· DIRNSA ATTN: LL24
· Account #889999
· Fort Meade, MD 20755-6000
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
107
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· NON-COMSEC MATERIAL CLASSIFIED UP TO AND INCLUDING SECRET, send by
regular mail to:
National Security Agency
ATTN: CMC - LL24 - Suite 6890
9800 Savage Road
Fort George G. Meade, MD 20755-6890
· NON-COMSEC MATERIAL CLASSIFIED HIGHER THAN SECRET, send by DCS to:
·
449563 - BA20
· Film Destruction Facility
21.5.4.2 (U) Destruction of Hard Disks
Hard disks are expendable items and are not authorized for release and reuse outside of the SCI
community. Each item is considered classified to the highest level of data stored or processed on
the IS in which it was used. If hard disks are damaged, or no longer deemed usable, they will be
degaussed and then destroyed. If the platter(s) of the defective unit can be removed and the
removal is cost effective, then destruction of a hard disk consists of dismantling the exterior case
and removing the platter from the case then degaussing the platter. Techniques that remove the
recording surface (grinding or chemical etching the oxide surface) prior to disposal do not enhance
security and are unnecessary. They may be disposed of by using approved procedures for the
destruction or disposal of unclassified metal waste.
21.5.4.2.1 (U) Shipping Instructions
Below are the shipping instructions for destruction of magnetic media, including cassette tapes,
videotapes, hard disks, optical disks (including CDs) and magnetic tapes on reels. Paperwork
required is either a DD1149 (shipping document) or 1295A (transmittal of classified material
document). POC is at NSA LL24, (301) 688-6136 DSN 644-6136 (NSTS 977-7248).
· CLASSIFIED UP TO AND INCLUDING SECRET, send by regular mail to:
National Security Agency
9800 Savage Road
Fort George Meade, MD 20755-6875
SAB-3, Suite 6875
Attn: CMC, Degaussing
· CLASSIFIED HIGHER THAN COLLATERAL SECRET, send via Defense Courier Service
(DCS) to:
449276-BA21
DIRNSA, FT MEADE
Degaussing
· CLASSIFIED EQUIPMENT UP TO AND INCLUDING SECRET, send by regular mail:
National Security Agency
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
108
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
9800 Savage Road
Fort George Meade, MD 20755-6632
SAB-4, Suite 6632
Attn: LL23 Cleansweep
· CLASSIFIED EQUIPMENT HIGHER THAN COLLATERAL SECRET, send via Defense
Courier Service (DCS) to:
449276-BA21
DIRNSA, FT MEADE
CLEANSWEEP
Note: Phone POC for equipment questions, (301) 688-6776 or (NSTS) 977-7183.
21.5.4.3 (U) Destruction of Disk Packs
Each item is considered classified to the highest level of data stored or processed on the IS in which
it was used. If disk packs are damaged, or no longer deemed usable, they will be degaussed and
then destroyed. Techniques that remove the recording surface (grinding or chemical etching the
oxide surface) prior to disposal do not enhance security and are unnecessary. They may be disposed
of by using approved procedures for the degauss and destruction or disposal of unclassified metal
waste.
21.5.4.4 (U) Optical Storage Media Destruction
Optical mass storage, including compact disks (CD, CDE, CDR, CDROM), optical disks (DVD),
and magneto-optical disks (MO) shall be declassified by means of destruction. Optical media shall
be destroyed by burning, pulverizing, or grinding the information bearing surfaces. When material is
pulverized or ground, all residue must be reduced to pieces sized 0.25mm or smaller. Burning shall
be performed in an approved facility certified for the destruction of classified materials; residue
must be reduced to white ash.
21.5.5 (U) Malfunctioning Media
Magnetic storage media that malfunctions or contains features that inhibit overwriting or
degaussing will be reported to the ISSO/SA. The ISSO/SA will coordinate the repair or destruction
of the media with the ISSM and responsible DAA Rep/SCO. If the hard drive is under a warranty
that requires return of the hard drive, dismantle the hard drive and return the case but do not send
the platter to the manufacturer.
21.5.6 (U) Release of Memory Components and Boards
Prior to the release of any malfunctioning components proper coordination, documentation, and
written approval must be obtained by the ISSM. This section applies only to components identified
by the vendor or other technically-knowledgeable individual as having the capability of retaining
user-addressable data; it does not apply to other items (e.g., cabinets, covers, electrical components
not associated with data), which may be released without reservation. For the purposes of this
chapter, a memory component is considered to be the Lowest Replaceable Unit (LRU) in a
hardware device. Memory components reside on boards, modules, and sub-assemblies. A board can
be a module, or may consist of several modules and sub-assemblies. Unlike magnetic media
sanitization, clearing may be an acceptable method of sanitizing components for release (See Table
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
109
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
21-2). Memory components are specifically handled as either volatile or non-volatile, as described
below.
21.5.6.1 (U) Volatile Memory Components
Memory components that do not retain data after removal of all electrical power sources, and
when re-inserted into a similarly configured system, are considered volatile memory components.
Volatile components that have contained extremely sensitive or classified information may be
released only IAW procedures developed by the ISSM, or designee, and documented in the
SSAA/SSP. A record must be maintained of the equipment release indicating that, per a best
engineering assessment, all component memory is volatile and that no data remains in or on the
component when power is removed.
21.5.6.2 (U) Non-volatile Memory Components
Components that do retain data when all power sources are discontinued are nonvolatile memory
components. Some nonvolatile memory components
(e.g., Read Only Memory
(ROM),
Programmable ROM (PROM), or Erasable PROM (EPROM)) and their variants that have been
programmed at the vendor’s commercial manufacturing facility, and are considered to be
unalterable in the field, may be released. All other nonvolatile components (e.g., removable/non-
removable hard disks) may be released after successful completion of the procedures outlined in
Table
21-2. Failure to accomplish these procedures will require the ISSM, or designee, to
coordinate with the DAA Rep/SCO to determine releasability.
21.5.6.3 (U) Other Non-volatile Media
The following non-volatile media could possibly retain data when all power sources are
discontinued.
21.5.6.3.1 (U) Visual Displays
A visual display may be considered sanitized if no sensitive information is etched into the visual
display phosphor. The ISSO should inspect the face of the visual display without power applied. If
sensitive information is visible, destroy the visual display before releasing it from control. If nothing
is visible, the ISSO/SA shall apply power to the visual display; then vary the intensity from low to
high. If sensitive information is visible on any part of the visual display face, the visual display shall
be destroyed before it is released from control.
21.5.6.3.2 (U) Printer Platens and Ribbons
Printer platens and ribbons shall be removed from all printers before the equipment is released.
One-time ribbons and inked ribbons shall be destroyed as sensitive material. The rubber surface of
platens shall be sanitized by wiping the surface with alcohol.
21.5.6.3.3 (U) Laser Printer Drums, Belts, and Cartridges
· Laser printer components containing light-sensitive elements (e.g., drums, belts, and complete
cartridges) shall be sanitized before release from control.
· Elements containing intelligence information shall be sanitized IAW the policy contained in the
DCID 6/9.
· Used toner cartridges from properly operating equipment that properly completed the last printing
cycle may be treated, handled, stored and disposed of as UNCLASSIFIED.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
110
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
· When a laser printer does not complete a printing cycle (e.g., a paper jam or power failure occurs)
completing a subsequent print cycle before removal of the cartridge is sufficient to wipe residual
toner from the cartridge drum.
· If the toner cartridge is removed without completing a print cycle, inspect the cartridge drum by
lifting the protective flap and viewing the exposed portion of the drum. If residual toner is present,
manually rotating the drum is sufficient action to wipe off residual toner material present.
· After completing actions for incomplete print cycles, the toner cartridge may be treated, handled,
stored and disposed of as UNCLASSIFIED.
21.5.7 (U) Clearing Systems for Periods Processing
Systems authorized for periods processing must be cleared of any information that is not authorized
between the different defined periods of mode/level of operation. All system components must be
cleared IAW guidance of this chapter.
· Most systems will have volatile memory components. Removing power (turning the system off) can
clear these components.
· Some systems have removable media designed to save time and be more convenient for changing
between modes/levels (e.g., this avoids having to overwrite the media and re-install all of the
software including complex operating system software). The IS should be shut down before the
removable media is exchanged.
· Nonvolatile memory components, which are significant components of a system, could retain
information between the periods. When relying on removable media, the system should have no
significant nonvolatile memory components that could contain unauthorized information remaining
within the system.
· Any system approved for periods processing will be prohibited from containing nonvolatile memory
or a fixed hard drive.
· For example, a PL-2 system with a removable hard drive “for data” which is interchanged between
periods is not sufficient if a permanent hard drive remains inside the IS with “just the operating
system”. The PL-2 system does not provide sufficient controls to trust against unauthorized
information inadvertently being stored to the operating system hard drive.
21.5.8 (U) Release of Systems and Components
The ISSM, or designee, shall develop equipment removal procedures for systems and components
and these procedures shall be stated in the SSAA/SSP. When such equipment is no longer needed,
it can be released if:
· It is inspected by the ISSM, or designee. This inspection will assure that all media, including
internal disks, have been removed or sanitized.
· A record is created of the equipment release indicating the procedure used for sanitization and to
whom the equipment was released. The record of release shall be retained for a period prescribed
by the DAA Rep/SCO.
· Procedures specified by the DAA Rep/SCO are used.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
111
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
21.5.8.1 (U) Documenting IS Release or Disposal
The NSA/CSS Form G6522, shown in Figure 21.1, or similar form/documentation, will be used to
document the local release or disposal of any IS or processing component.
Figure 21.1. (U) Sample NSACSS Form G6522
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
112
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CHAPTER 22 - INFORMATION SYSTEMS
(IS) AND NETWORK SECURITY SELF-
INSPECTION AID
22.1 (U) PURPOSE
The purpose of this chapter is to provide an aid for the inspection, certification, and accreditation of SCI
ISs. The checklist is based upon the criteria contained in this document and other applicable DoD security
regulations/directives. This checklist can be used as follows:
· To inspect IS operations periodically throughout their life cycle
· To inspect organizational IS security program
· Incorporated as part of an organization’s self-inspection program
· In preparation for formal inspections, IS certifications and accreditations
22.2 (U) SCOPE
This aid is effective in the following life cycle phases:
CONCEPTS DEVELOPMENT PHASE
NO
DESIGN PHASE
NO
DEVELOPMENT PHASE
NO
DEPLOYMENT PHASE
YES
OPERATIONS PHASE
YES
RECERTIFICATION PHASE
YES
DISPOSAL PHASE
YES
22.3 (U) APPLICABILITY
This checklist is applicable to those systems and security programs that support DoD SCI operations. The
ISSM/ISSO should periodically complete the checklist (recommended annually).
22.4 (U) PROCEDURES
The completion of this self-inspection checklist is basically self-explanatory and may be locally reproduced
to meet the self-inspection and IS certification and accreditation requirements of an organization.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
113
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Table 22.1 (U) IS AND NETWORK SECURITY SELF-INSPECTION CHECKLIST
IS AND NETWORK SECURITY SELF-INSPECTION CHECKLIST
SECTION A - IS SECURITY PROGRAM MANAGEMENT & DOCUMENTATION
YES
NO
NA
1.
Is the IS Security Program being supported by supervisors and senior
managers?
2.
Has an IS and Network Security Program been established?
3.
Is the ISSM appointed in writing and has a copy of the appointment letter
been forwarded to to the Designated Accrediting Authority (DAA) /DAA
Representative (REP)/Service Certifying Organization (SCO), and does the
ISSM maintain a copy of the appointment letter on file at the unit?
[JDCSISSS 1.5.8]
a. Has an IS Security Training Program been established to ensure DoD
certification of SAs, ISS personnel and IS users? [JDCSISSS 1.5.8]
b. Has the ISSM attended training (Information Security)? [JDCSISSS
1.5.8]
c. Has the ISSM ensured all ISSO’s received the necessary Technical &
Security training to carry out their duties? (OIAC 2225, or the
Department of Defense Intelligence Information Systems (DoDIIS)
Site ISSM Course or equivalent course) [JDCSISSS 1.5.8]
d. Are signs posted throughout the organization with the names and
phone numbers of the Security Officers?
e. Has a self-inspection of the organization IS and Network Security
Program been conducted?
f. Have identified deficiencies been documented?
g. Does the responsible authority review self-inspection reports to ensure
follow-up actions are taken to correct all identified deficiencies?
h. Have all identified deficiencies been corrected?
4.
Are assistance visits conducted to assist subordinate units (if any) in the
development of their IS & Network Security Programs?
5.
Are appropriate IS security regulations/policy documents being maintained,
and are they accessible to the ISSM, ISSO, SA and system users? Are they
on file and used effectively to manage the organization’s IS & Network
Security Program?
a. HQs-level advisory messages. Is there a procedure in place to ensure
that all Bulletins/IAVAs (or Defense Information Systems Agency’s
(DISA) Automated System Security Incident Support Team
(ASSIST) and the Service’s Computer Emergency/Incident Response
Team (CERT/CIRT).) are reviewed and applied as necessary?
[JDCSISSS 1.5.8]
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
114
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
b. Policy letters and directives.
c. SSAA/SSPs and any associated approval to operate documentation.
d. SCIF Accreditation Documentation on each SCIF on file?
e. If your Site/SCIF contains other organizations, are there
Memorandums of agreement (MOA) in place detailing the nature of
IS accreditation support provided by each organization? [DOD
5105.21-M-1, Chapter 1, para F.4.f]
f. If “Guest” systems are located within the SCIF, does the ISSM have
approved documentation for approval to operate? [JDCSISSS 4.6.1]
g. Are current Physical Security accreditation’s for each SCIF on file?
h. Is the site CONOPs current and being followed by your Site/SCIF?
[DCID 6/3 4.B.1.c(1)(b) and DCID 6/3 9.D.3.b.2]
i.
Risk analysis and vulnerability reports.
j.
TEMPEST checklists, certificates, and waivers, if applicable, for all
installed ISs? [JDCSISSS 5.5.2]
k. Self-inspection reports and appropriate follow-up actions.
6.
Are the results of security incidents/violations investigated, reported IAW
applicable regulations, and reviewed to determine whether changes to IS
policy/procedures are required?
a. Are all personnel aware of their responsibilities in reporting IS
incidents and violation?
SECTION B - ACCREDITATION AND CERTIFICATION
7. Has a System Security Authorization Agreement [SSAA]/ Systems Security
Plan [SSP]) been:
a. Does the ISSM (or equivalent) review and endorse all IS
accreditation/certification support documentation packages? [DCID
6/3 2.B.6.c.6 and JDCSISSS 1.5.8]
b. Are the accreditation packages in the prescribed format and submitted
on ALL systems? [DCID 6/3 Chapter 9.C.3 and JDCSISSS
Chapter 3 & 4]
c. Is a program/procedure in place ensuring re-certification of each
accredited IS is completed upon its three year anniversary? [DCID
6/3 9.D.7.b and JDCSISSS 3.4.5]
d. Does the accreditation package submitted have the appropriate
classification level? [JDCSISSS 3.5.6 & 4.7.1]
e. Is the accreditation process included in annual IS and network
security training? [JDCSISSS 6.3.9]
f. Are IS connectivity drawings available? [DCID 6/3 2.B.7.c(7)]
g. If Site-Based, do you have current accreditations from the appropriate
Designated Approval Authority (DAA) for all SAP/SAR, collateral
and unclassified systems within your site? [DCID 6/3 2.B.6.c(8)]
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
115
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
h. If not Site Based do you have current accreditations for all systems
within your Site/SCIF?
i.
If Site-Based, is the “Change” block of the Baseline used to track
changes to the accredited Baseline?
j.
Developed for the Information Systems?
k. Properly coordinated within the organization (ISSM, ISSO/SA,
Physical Security personnel, TEMPEST Officer, etc.)? {TEMPEST
change ICW Chapter 5?}
l.
Reviewed by the ISSM for appropriate action?
m. A file copy maintained by ISSM/ISSO?
n. Has the ISSM/ISSO coordinated the accreditation documentation
with their CCB?
o. Is appropriate accreditation/IATO documentation maintained by
ISSM/ISSO for each IS?
p. Have all ISs been certified and accredited prior to operation or an
IATO granted?
q. Forwarded to the appropriate DAA/DAA Rep/SCO?
8.
Is the SSAA/SSP updated as follows:
a. When hardware/software configuration changes occur?
b. When the system is relocated?
c. When the security mode/protection level changes?
d. When connected to additional networks?
9.
Have all external connections to installed ISs been validated and approved
by the DAA Rep/SCO?
10.
Are the ISSM/ISSOs aware of the SABI/TSABI process when connecting
systems/networks of different classifications?
SECTION C - IS & NETWORK SECURITY
11. Are systems which process SCI information located in areas according to
DCID 1-21?
12. Is only authorized software being used?
13. Are the ISSM, ISSOs/SAs, and users knowledgeable of virus protection
and reporting procedures?
14. Virus software
a. Is the DoD-contract anti-virus software (Norton Anti-Virus or
Network Associates VirusScan) running on all ISs? [JDCSISSS
10.4.1]
b. Are the software version and signature files for each IS the most
current available? [DCID 6/3 5.B.1.a.4] & [JDCSISSS 10.4.1]
c. Is there a procedure in place for updating signature files on a monthly
basis for all ISs including stand-alone systems? [DCID 6/3 5.B.1.a.4]
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
116
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
d. Are procedures in place for dealing with virus incidents? [JDCSISSS
8.3.3] [DCID 6/3 8.B.7]
e. Is anti-virus software setup to automatically run whenever media is
introduced into the system? [JDCSISSS 6.3.6]
15.
Are documented software patches current and installation dates
documented?
a. Do all ISs use approved operating system software (Windows NT or
Solaris)?
[Assistant Secretary of Defense Letter dated 22 Aug 96]
b. Are all game software removed from all ISs? [JDCSISSS 11.6.3
11.6.4]
c. Is the Configuration Management (CM) plan current and is it being
followed by all organizations within the Site/SCIF? [DCID 6/3
2.B.7.c(7)]
d. Does the ISSM review all proposed hardware and software changes
to the Site/SCIF? (Some minor changes may be made without ISSM
approval such as switching out peripheral equipment and adding
security patches to software programs)
[DCID 6/3 2.B.6.c(14)]
16.
Audit Trails:
a. Are audit trails enabled for every IS? [JDCSISSS 7.5.3]
b. Are they set to capture the minimum events? [JDCSISSS 7.5.3.1 and
DCID 6/3 4.B.2.a.4.a, 4.B.2.a.4.d[1-3] and 4.B.2.a.5.a]
c. Are computers without automatic audit trails using ISSPM/SCO
approved manual audit trails?
[JDCSISSS 7.5.3.2]
d. Reviews being limited to the ISSM, or alternate, and ISSOs/SAs?
e. Are audit trails reviewed at least weekly or as directed by the ISSM
and appropriate action taken, where applicable? [JDCSISSS 7.5.3.4]
f. Summary reports and SCI system audits being maintained for five
years? [JDCSISSS 7.5.3.5] [DCID 6/3 4.B.2.a.4.c]
g. Are accounts audited at a minimum of annually to ensure old, unused
accounts are deleted? [JDCSISSS 7.5.1.4]
h. Are annual account audits documented? [JDCSISSS 7.5.1.4]
17.
Is the Access Request and Verification Roster:
a. Acknowledged and signed?
b. Periodically validated?
c. Updated to indicate final access removal?
d. Appropriately classified?
e. Maintained by the SA?
18.
Account / Password Procedures
a. Do all users have a unique login ID (or is a waiver on file from the
DAA allowing group accounts)? [JDCSISSS 6.3.1]
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
117
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
b.
Is each password at least 8 alphanumeric/special characters long?
[JDCSISSS 6.3.2]
c.
Do all ISs automatically invoke a password-protected screen lock
after the IS is idle for more than 15 minutes? [DCID 6/3 4.B.2.a.14.a
and JDCSISSS 7.5.6]
d.
Are users automatically logged out from ISs when they leave for an
extended period of time? [DCID 6/3 4.B.2.16.b and JDCSISSS
7.5.4]
e.
Is the security clearance of each user verified to be equal to or greater
than that of the IS to which they are gaining access prior to the
issuance of the passwords.
f.
Is the need-to-know of each user verified prior to the issuance of the
password? [JDCSISSS 7.5.1.3]
g.
Is each user or process granted the most restrictive set of privileges or
access needed for the performance of authorized tasks? [DCID 6/3
4.B.2.a.10]
h.
Is the issuance of passwords documented with an NSA/CSS Form
6521 or similar form?
i.
Are initial passwords distributed in a secure manner? [JDCSISSS
7.5.1.2]
j.
Are passwords protected at the same level as the information they
protect?
k.
Are passwords suppressed when entered?
l.
Are Access Authorization Letters retained for 1 year after access has
been removed? [JDCSISSS 7.5.1.2]
m. When users out-process the unit (for permanent departure), are they
required to go through the ISSM (or designated individual) to have
their active accounts terminated?
n.
When users out-process the unit for TDYs longer than 60 days, are
they required to go through the ISSM (or designated individual) to
have their active accounts disabled?
o.
Is the number of privileged users kept to a minimum? [DCID 6/3
2.B.8.b(3)]
p.
Are users with “group” privileges required to login as themselves
prior to exercising their “group” privileges?
(Users must not be able
to login directly as “Root,” “Administrator,” or any other generic
System group account) [DCID 6/3 4.B.2.a.7.b]
q.
Are there written procedures for establishing an account? (i.e.
required paperwork and processes). [DCID 6/3 4.B.2.a.3.b]
r.
Are password “cracking” tools used to routinely check the strength of
user passwords? [DCID 6/3 4.B.2.a.9]
s.
Is a history of old passwords (last 5recommended) kept by the system
to prevent users from changing their password and then quickly
changing back to their old password?
t.
Is there a minimum time that must expire before a user can change
their password again? (90 days is recommended )
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
118
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
u. Do all ISs limit the number of failed login attempts to no more than
five (three is recommended)? [DCID 6/3 4.B.2.a.16.c and
JDCSISSS 7.5.5]
v. Are passwords changed quarterly for SBU and other classified
systems, at least semiannually (180 days) for SCI systems?
w. If a special situation warrants, are Group accounts approved by the
DAA/SCO? [JDCSISSS 7.5.1.6]
19.
Are the ISSOs/SAs implementing the appropriate countermeasures to
protect against vulnerabilities?
20.
Are procedures in effect to ensure the proper classification markings of all
computer-generated products?
21.
Are appropriate Government warning banners and labels being used on
systems?
a. Are IS components (CPU, monitor, printer, scanner) marked with
appropriate classification labels (e.g. 700-series or equivalent)?
[DCID 6/3 subsection 8.B.2 and JDCSISSS 6.3.7]
b. Is the Consent to Monitoring label attached to the monitor of all IS’s.
[JDCSISSS 9.3.2]
c. Does a classification-warning banner appear on all systems that are
using an approved KMM switch? [JDCSISSS 1.5.10]
i. Are approved keyboard-monitor-mouse (KMM) switches installed
between IS which are connected to a network or another IS at
different classification levels?
ii. Are appropriate procedures implemented and followed in using
KMM switches?
d. Has the proper authority approved the use of the KMM?
e. Do all ISs display the approved Consent to Monitoring Banner prior
to logging in?
22.
Is formal documentation used (i.e. 6522 or equivalent form) to record all IS
release actions; are they completed and verified by appropriate IS personnel
and filed with the SSAA/SSP?
23.
Are DD254s reviewed periodically to validate contractor access to data on
SCI IS?
24.
Has an IS Contingency Plan:
a. Been developed?
b. Been successfully tested in the past year?
c. Been periodically reviewed and updated?
25.
Does the approved SSAA/SSP and unit Standard Operating Procedures
(SOPs) cover the following security related topics:
a. Procedures for securely bringing the system up/down?
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
119
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
b. Security responsibilities encompassing all personnel?
c. Security marking of output products?
d. Procedures for downgrading and/or releasing output or media?
e. Procedures for media degaussing, destruction, and/or downgrading?
f. Procedures for generating and reviewing the audit data?
g. Procedures for adding/removing users from the IS/LAN?
h. Procedures establishing access control privileges for users?
i.
Operational Security (OPSEC)?
j.
Virus and Incident reporting procedure?
k. Contingency Plan procedures?
l.
Information Storage Media control and accounting procedures?
m. Password Management procedures?
n. Procedures for obtaining appropriate authorization to conduct
monitoring of suspicious or illegal activity?
26.
Is the audit data protected by the Security Support Structure (operating
system or security software)?
27.
Are data access controls automatically set to limit access when any new file
or data set is created?
28.
Are system privileges limited to those necessary to perform assigned tasks
(e.g. SUPERUSER, System Programmers, etc.)?
29.
Are the following features installed and activated?
a. Screen Blanking
b. Screen Lock
c. Deadman Timeout
30.
If an IS (Fax) is connected to a STU-III/STE data port, has the appropriate
approval letters been received from the proper authority? [JDCSISSS
16.3.1.1]
a. Are written Operating Instructions been developed for Fax machine
usage and located next to the machine? [JDCSISSS 16.3.1.1.4]
b. Are audit log’s used to record all transmissions over a Fax machine
connected to a STU-III/STE? [JDCSISSS 16.3.1.1.4]
31.
Has the proper authority approved the use of the dial-in modems?
32.
Is the Auto Answering feature of all STU-IIIs/STEs configured IAW
applicable policy?
33.
Has the proper authority approved the use of the STU-III/STE Auto
Answering feature?
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
120
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Answering feature?
34.
Is the speaker phone feature disabled from all STU-IIIs within the SCIF (or
is an appropriate waiver on file)? [DCID 1/21 6.5.2]
35.
Are unclassified ISs connected directly to the public telephone network; if
so, has approval been received from proper authority?
36.
Is the use of dial-in modems connected to ISs/LANs IAW applicable
policy?
37.
Are communications links connecting the components of the IS processing
classified or sensitive unclassified information protected IAW National
COMSEC policies?
38.
Are all critical systems backed up by an Un-interruptible Power Supply
(UPS) system?
39.
Are IS microphones turned off or unplugged when not in use?
40.
Is the Red/Black separation criteria being strictly enforced?
41.
Has the operator and supervisor signed a PED acknowledgement form
indication operating restrictions? [JDCSISSS 15.4.1.1]
42.
Has the SCIF Accreditation authority approved all PED for operation
within the SCIF? [JDCSISSS 15.4.1.1]
43.
If PED’s will be connected to a SCIF IS, has the ISSM given written
approval on a case by case basis? [JDCSISSS 15.4.1.2]
44.
Has a case specific Standard Operating Procedure been developed for all
PED’s? [JDCSISSS 15.4.2.1]
SECTION D - IS MAINTENANCE
45. Has a maintenance policy and procedure been developed and implemented?
46. Is a functional Configuration Management Program in place?
47. Are personnel who perform maintenance on classified systems cleared and
indoctrinated to the highest classification of information processed?
[JDCSISSS 13.3.1.1]
48. Are maintenance personnel U.S. citizens?
49. Are uncleared maintenance personnel escorted by fully cleared and
technically qualified personnel?
50. Are IS components purged of all classified or unclassified information prior
to removal from IS spaces, and are these actions appropriately
documented?
51. Are storage media removed from ISs prior to being released for service or
repair?
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
121
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
52. Are areas sanitized prior to maintenance performed by unclear personnel?
53. Is a maintenance log, documenting repairs, used and maintained for the life
of each IS?
[JDCSISSS 13.3.2.1]
54. Is a remote maintenance, diagnostic, and service transaction logs maintained
for five years? [JDCSISSS 13.3.4]
55. Are controls in place for maintenance of diagnostic hardware or software?
SECTION E - INFORMATION STORAGE MEDIA CONTROL & LABELING
56.
Has a SOP been written outlining the procedures to be followed for the
introduction and removal of storage media into and out of secure facilities
IAW national policy?
57.
Has the Cdr/Commanding Officer publicized/developed policy identifying
the level of control and accountability of information storage media in the
organization?
58.
Have procedures been developed for the control of information storage
media IAW national-level policy?
59.
Are media marked and labeled with the correct classification and handling
instructions (Standard 700 series labels or equivalent, Privacy Act, Special
Access Programs [SAP], etc.)?
a. Are all diskettes labeled with the appropriate classification labels?
[JDCSISSS 12.4]
b. Are all diskettes labeled with SF711s (Data Descriptor Labels) and
filled in with the organization, office symbol, and classification (of the
data)? [JDCSISSS 12.4.1]
c. Are all SF712 stickers supplemented with the highest level of
associated caveats (Note: Do not use the SF Form 706 to supplement
a
TS marking) for the IS? (i.e. a label indicating “SI/TK/G” or the
same thing written on the SF712 itself) [DCID 6/3 subsection 8.B.2
and JDCSISSS 12.4.1]
d. Are CD-ROM cases, not the CD itself, labeled with the appropriate
classification labels?
[JDCSISSS 12.4.1.1]
e. If required are CD-ROMs marked with a control number (using a non-
toluene paint-pen) which matches a corresponding control number on
its container or envelope (which is also labeled with the classification
sticker)? [JDCSISSS 12.4.1.1]
f. Are music CDs prohibited from all ISs?
[JDCSISSS 11.6.4]
60.
Does the ISSM ensure excess or obsolete commercial software is free of
classified information prior to release or reuse?
61.
Are procedures established which outline steps to be taken when
transferring data to and from systems of unequal accreditation (classification
and/or sensitivity)?
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
122
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
62. Are reused removable media used at the same or higher classification level?
63. Do users follow the approved procedures for transferring files from higher
classified system to a lower classified system [JDCSISSS 18.3.4]
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
123
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
APPENDIX A - REFERENCES
(U) The following publications are the primary security regulations associated with, and affecting
Information Systems (IS) Intelligence operations. This appendix is not an inclusive list of all security
regulations.
PUBLIC LAWS
Computer Fraud and Abuse Act, 18 U.S. Code section 1030, 1984.
Electronic Communications Privacy Act, 18 U.S. Code Section 2510, 1986.
Public Law 100-235, The Computer Security Act of 1987, 8 January 1988.
EXECUTIVE ORDERS
Executive Order 12333, United States Intelligence Activities, 4 December 1981.
Executive Order 12829, National Industrial Security Program, 6 January 1993.
Executive Order 12958, Classified National Security Information, 20 April 1995.
NATIONAL PUBLICATIONS
Common Criteria for Information Technology Security Evaluation, CCIB-98-026, Version 2.0, May 1998.
DCID
6/3, Director of Central Intelligence
(DCI) Directive
(DCID)
6/3, Protecting Sensitive
Compartmented Information within Information Systems, 5 June 1999.
DCID 6/3, Protecting Sensitive Compartmented Information within Information Systems, Industry Annex,
12 April 2002.
DCID 6/1, Security Policy for Sensitive Compartmented Information and Security Policy Manual, 1 March
1995, Administrative Corrections 23 December 2002.
DCID 6/9, Physical Security Standards for Sensitive Compartmented Information Facilities (SCIFs),
18 November 2002.
DCID 2/12P, Community Open Source Program, 1 March 1994.
The Intelligence Community Open Source Strategic Plan, 21 April 1993.
NSTISSAM TEMPEST/2-95, National Security Telecommunications and Information Systems Security
Advisory Memorandum (NSTISSAM) TEMPEST/2-95 (formerly NACSIM 5203), Red/Black Installation
Guidelines, 12 December 1995.
NSTISSI 3013, National Security Telecommunication and Information Systems Security Instruction
(NSTISSI) 3013, Operational Security Doctrine for the Secure Telephone Unit III (STU-III) Type 1
Terminal, 8 February 1990.
NSTISSI 4009, National Security Telecommunication and Information Systems Security Instruction
(NSTISSI) 4009, National Information Systems Security (INFOSEC) Glossary, September 2000.
NSTISSI 7000, National Security Telecommunications and Information Systems Security Instruction
(NSTISSI) 7000, TEMPEST Countermeasures For Facilities, 29 November 1993.
NSTISSI 7003, National Security Telecommunications and Information Systems Security Instruction
(NSTISSI) 7003 (C/NF), Protected Distribution Systems, 13 December 1996.
NSTISSP 11, National Information Assurance Acquisition Policy, dated January 2000.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
124
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
NSTISSP
300, National Security Telecommunications and Information Systems Security Policy
(NSTISSP) 300, National Policy on Control of Compromising Emanations, 29 November 1993.
OMB Circular A-130, Management of Federal Information Resources, 15 July 1994, and principally,
Appendix III, Security of Federal Automated Information, February 1996.
DEPARTMENT OF DEFENSE (DoD) PUBLICATIONS
DoD 5105.21-M-1, Sensitive Compartmented Information Administrative Security Manual (U), August
1998.
DoD Directive 5200.1-R, Information Security Program Regulation, January 1997.
DoD Directive 5200.2-R, Policy on Investigation and Clearance of DoD Personnel for Access to Classified
Defense Information, 15 February 1986
DoD Directive C-5200.5, Communications Security (COMSEC), 21 April 1990.
DoD Directive C-5200.19, Control of Compromising Emanations, 16 May 1995.
DoD Directive 8500.1, Information Assurance, 24 October 2002..
DoD Directive 5215.1, Computer Security Evaluation Center, 25 October 1982.
DoD Directive 5220.22, DoD Industrial Security Program, 8 December 1980.
DoD 5220.22-R, Industrial Security Regulation, December 1985.
DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), January 1995, and
its Supplement, dated February 1995.
DoD Directive 5240.4, Reporting of Counterintelligence and Criminal Violations, 22 September 1992.
DEFENSE INTELLIGENCE AGENCY (DIA) PUBLICATIONS
DIA Manual 50-4, Department of Defense (DoD) Intelligence Information Systems (DoDIIS) Information
Systems Security (INFOSEC) Program, 30 April 1997.
DIA Regulation 50-2, Information Security Program, 15 July 93.
Defense Intelligence Management Document SC-2610-141-93, DoDIIS Site Information Systems Security
Officer’s (ISSO) Handbook, November 1993.
Defense Intelligence Management Document DS-2610-142-00, DoD Intelligence Information System
(DoDIIS) Security Certification and Accreditation Guide April 2000.
Defense Intelligence Management Document SC-2610-143-93, DoDIIS Site Certifier’s Guide, November
1993.
NATIONAL SECURITY AGENCY
(NSA)/CENTRAL SECURITY SERVICE
(CSS)
PUBLICATIONS
NSA/CSS Circular 25-5, Systems Acquisition Management, 3 April 1991.
NSA/CSS Circular 90-11, Protected Wireline Distribution System for COMINT Facilities, 7 June 1993.
NSA/CSS Classification Guide 75-98, 20 February 1998.
NSA/CSS Directive 21-1, DoD Computer Security Center Operations, 29 March 1984.
NSA/CSS Directive 130-1, Operational Information System & Network Security Policy, 13 March 1995.
NSA/CSS Manual 130-1, Operational Information Systems Security Manual, January 2001.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
125
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
NSA/CSS Manual 130-2, Media Declassification and Destruction Manual, November 2000.
NSA/CSS Regulation 120-1, Reporting of Security Incidents and Criminal Violations, 16 March 1989.
NSA/CSS Regulation 120-24, STU-III Security Requirements, 25 April 2000.
NSA/CSS Regulation 130-2, Computer Virus Prevention Policy, March 1995.
NSA/CSS Regulation 130-3, Security Testing of NSA/CSS Automated Information Systems (IS) and
Networks, 24 July 1992.
NSA/CSS Regulation 130-4, Connection of an Information System (IS) to the STU-III (type 1) Terminal
Data Port, March 1995.
NSA/CSS Regulation 130-5, Use of Unclassified Publicly Accessible Computer Networks and information
Systems such as the INTERNET (U), 15 July 1996.
USSID 12, United States Signals Intelligence (SIGINT) Directive 12, Automatic Data Processing (ADP)
Policy for SIGINT Operations, 11 December 1990.
NSA/CSS Information Systems Certification and Accreditation Process (NISCAP), 31October 2002.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
126
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
APPENDIX B - ACRONYMS & ABBREVIATIONS
(U) The following acronyms/abbreviations are expanded for clarification.
ACERT
Army Computer Emergency Response Team
AF
Air Force
AFCERT
Air Force Computer Emergency Response Team
AIA
Air Intelligence Agency
IS
Automated Information System
ASP
Accredited Security Parameters
ASSIST
Automated Systems Security Incident Support Team
AUTODIN
Automatic Digital Network
BDS
Broadband Distribution System
C&A
Certification and Accreditation
CCB
Configuration Control Board
CD
Compact Disk
CDE
Compact Disk Extra
CD-R
Compact Disk-Read
CDR
Critical Design Review
CD-ROM
Compact Disk-Read Only Memory
CERT
Computer Emergency Response Team
CIRT
Computer Incident Response Team
CM
Configuration Management
CMB
Configuration Management Board
CO
Commanding Officer
COI
Community Of Interest
COMINT
Communications Intelligence
COMNAVSECG
Commander Naval Security Group
RU
COMSEC
Communications Security
CONOP
Concept of Operation
COTS
Commercial Off-The-Shelf
CPU
Central Processing Unit
CRYPTO
Cryptologic
CSE
Client-Server Environment
CSS
Central Security Service
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
127
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
CTTA
Certified TEMPEST Technical Authority
DAA
Designated Approving/Accrediting Authority
DAA Rep
Designated Approving/Accrediting Authority Representative (i.e., SCO)
DAC
Discretionary Access Control
DCI
Director, Central Intelligence
DCID
Director of Central Intelligence Directive
DEXA
DoDIIS Executive Agent
DIA
Defense Intelligence Agency
DIAM
Defense Intelligence Agency Manual
DIRNSA
Director, National Security Agency
DISA
Defense Information Systems Agency
DMS
Defense Messaging System
DoD
Department of Defense
DoDIIS
Department of Defense Intelligence Information Systems
DOS
Disk Operating System
DRAM
Dynamic Random Access Memory
DSN
Defense Switching Network
DVD
Digital Video Disk
EEFI
Essential Elements of Friendly Information
EEPROM
Electronically Erasable Programmable Read Only Memory
EO
Executive Order
EPA
Environmental Protection Agency
EPROM
Erasable Programmable Read Only Memory
ERB
Engineering Review Board
FAX
Facsimile
FEPROM
Flash Erasable Programmable Read Only Memory
FOUO
For Official Use Only
FTS
Federal Telecommunications Service
FW&A
Fraud Waste & Abuse
GENSER
General Service
GOTS
Government Off-The-Shelf
HOIS
Hostile Intelligence Services
HQ
Headquarters
HSO
Host Security Office
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
128
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
IA
Information Assurance
IATO
Interim Approval To Operate
IATT
Interim Approval To Test
IAVA
Information Assurance Vulnerability Assessment
IAW
In Accordance With
IA
Information Assurance
ID
Identification
IG
Inspector General
INSCOM
Intelligence and Security Command
IOC
Initial Operational Capability
IR
Infrared
IS
Information System
ISD
Inspectable Space Determination
ISS
Information System Security
ISSE
Information Systems Security Engineer
ISSM
Information Systems Security Manager
ISSO
Information Systems Security Officer
ISSPM
Information Systems Security Program Manager
JAG
Judge Advocate General
LAN
Local Area Network
LOC
Level-of-Concern
LRU
Lowest Replaceable Unit
MILNET
Military Network
MO
Magneto-Optical
MOU
Memorandum Of Understanding
NACSIM
National COMSEC Information Memorandum
NAVCIRT
Navy Computer Incident Response Team
NCS
National Cryptologic School
NIMA
National Imagery and Mapping Agency
NIPRNET
uNclassified Internet Protocol Router NETwork
NISP
National Industrial Security Program
NISPOM
National Industrial Security Program Operating Manual
NISSIB
NSA/CSS Information System Security Incident Board
NOFORN
No Foreign National
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
129
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
NSA
National Security Agency
NSA/CSS
National Security Agency/Central Security Service
NSI
National Security Information
NSN
National Stock Number
NSO
Network Security Officer
NSTISSAM
National Security Telecommunications Information Systems Security
Advisory Memorandum
NSTISSC
National Security Telecommunications Information System Security
Committee
NSTISSI
National Security Telecommunications Information System Security
Instruction
NSTISSP
National Security Telecommunications Information System Security Policy
Oe
Oersteds
OPSEC
Operational Security
PAA
Principal Accrediting Authority
PDA
Personal Digital Assistant
PDD
Personal Digital Diary
PDR
Preliminary Design Review
PDS
Protected Distribution System
PED
Portable Electronic Device
PL
Protection Level
PM
Program Manager
PMO
Program Management Office
POC
Point of Contact
PROM
Programmable Read Only Memory
RAM
Random Access Memory
RF
Radio Frequency
RFI
Radio Frequency Interference
ROM
Read Only Memory
SA
System Administrator
SACS
Security Access Control System
SAP
Special Access Program
SAPI
Special Access Program - Intelligence
SBU
Sensitive But Unclassified
SCE
Service Cryptologic Element
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
130
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
SCI
Sensitive Compartmented Information
SCIF
Sensitive Compartmented Information Facility
SCO
Service Certifying Organization (i.e., DAA Rep)
SDD
Secure Data Device
SDSO
System Design Security Officer
SF
Standard Form
SI
Special Intelligence
SIGAD
SIGINT Address
SIGINT
Signals Intelligence
SIM
System Integration Management
SIMO
System Integration Management Office
SIO
Senior Intelligence Officer
SISSPM
Senior Information Systems Security Program Manager
SOP
Standard Operating Procedure
SOW
Statement Of Work
SRAM
Static Random Access Memory
SSAA
System Security Authorization Agreement
SSAN
Social Security Account Number
SSO
Special Security Office/Special Security Officer
SSP
System Security Plan
STE
Secure Telephone Equipment
STU-III
Secure Telephone Unit III
ST&E
Security Test and Evaluation
T&E
Test and Evaluation
TDY
Temporary Duty
TK
Talent Keyhole
TS
Top Secret
UCMJ
Uniform Code of Military Justice
UPS
Un-interruptible Power Supply
US
United States
USERID
User Identification
USSID
United States Signals Intelligence Directive
USSS
United States SIGINT System
WAN
Wide Area Network
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
131
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
WORM
Write Once Read Many
APPENDIX C - GLOSSARY OF TERMS
The following terms and definitions have been extracted from various documents and are provided for
information and clarification. They are restricted to issues addressing information systems and related
security matters.
Access. The ability and means to communicate with (input to or receive output from), or otherwise make
use of any information, resource, or component in an information system (IS); or to have authorized entry
to a specified area.
Accreditation. The official management decision to permit operation of an IS in a specified environment at
an acceptable level of risk, based on the implementation of an approved set of technical, managerial, and
procedural safeguards. This authorization is granted by the appropriate Designated Accrediting Authority
(DAA), on a case-by-case basis, permitting the processing of SCI information on an IS. Approval is based
upon the DAA’s review of the SSAA/SSP. Under certain conditions interim approval-to-operate (IATO)
may be granted by designees of the DAA.
Accredited Security Parameters
(ASP). The security classification levels; compartments and
subcompartments at which an information system (IS) or network is accredited to operate (e.g. Top Secret
[TS]/Special Intelligence [SI]/Talent Keyhole [TK]).
Authentication. (1) To establish the validity of a claimed identity. (2) To provide protection against
fraudulent transactions or logons by establishing the validity of a USERID, message, station, individual or
originator.
Availability. Timely, reliable access to data and information services for authorized users.
Beta I. Security Certification testing performed in a lab environment or other facility as appropriate.
Beta II. Security Certification testing performed at designated operational installations(s) until stable
baseline is achieved (configuration differences or other factors may necessitate multiple Beta II test sites).
BLACK. A designation applied to telecommunications and information systems (ISs), and to associated
areas, circuits, components, and equipment, in which only unclassified signals are processed.
Broadband Distribution System (BDS). Any broadband system which can carry multiple channels of
information. A BDS is not a local area network (LAN), however, it is capable of being the backbone for
multiple LANs.
Buster. A computer program - part of the Computer Security Toolbox. BUSTER is a MS-DOS based
program used to perform a binary search of a disk or diskette for any word or set of words found in a
search definition file by performing a linear search on a disk or diskette, four sectors at a time. BUSTER
uses the “LIMITS.TXT” file as its document for search word patterns.
Certification. The comprehensive evaluation of the technical and non-technical security features of an IS
and other safeguards, made as part of and in support of the accreditation process, to establish the extent to
which a particular design and implementation meet a set of specified security requirements.
Certified TEMPEST Technical Authority
(CTTA). A U.S. Government or U.S. Government
contractor employee designated to review the TEMPEST countermeasures programs of a federal
department or agency.
Classified Information. National security information (NSI) that has been classified pursuant to Executive
Order 12958.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
132
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Clearing. Removal of data from an IS, its storage devices, and other peripheral devices with storage
capacity, in such a way that the data may not be reconstructed using common system capabilities (i.e.,
through the keyboard); however, the data may be reconstructed using laboratory methods.
Collateral. (1) Classified Non-Sensitive Compartmented Information (SCI) material to include General
Service (GENSER) - an intelligence community term. (2) All national security information (NSI) classified
under the provisions of an Executive Order (EO) for which special Intelligence community systems of
compartmentation (i.e., SCI) are not formally established.
Command Authority. The individual responsible for the appointment of user representatives for a
department, agency, or organization and their key ordering privileges.
Communications Security (COMSEC). Measures and controls taken to deny unauthorized persons
information derived from telecommunications and ensure the authenticity of such telecommunications.
COMSEC includes cryptosecurity, transmission security, emission security, and physical security of
COMSEC material.
Community-of-Interest (COI). A restricted network of users, each having an information system (IS)
with an accredited security parameter identical to the others and having the need to communicate securely
with other members of the network.
Compromising Emanations. Unintentional signals that, if intercepted and analyzed, would disclose the
information transmitted, received, handled or otherwise processed by telecommunications or information
systems (IS) equipment. (See TEMPEST).
Computer Security (COMPUSEC). See INFOSEC.
Computer Security Toolbox. A set of tools designed specifically to assist Information Systems Security
Officers
(ISSOs)/System Administrators
(SAs) in performing their duties. The functions within the
TOOLBOX can erase appended data within files, eliminate appended data in free or unallocated space,
search for specific words or sets of words for verifying classification and locating unapproved shareware
programs. It also includes a program which allows you to clear laser toner cartridges and drums.
Confidentiality. Assurance that information is not disclosed to unauthorized entities or processes.
Configuration Control. The process of controlling modifications to a telecommunications or information
system (IS) hardware, firmware, software, and documentation to ensure the system is protected against
improper modifications prior to, during, and after system implementation.
Configuration Management. The management of security features and assurances through control of
changes made to hardware, software, firmware, documentation, test, test fixtures, and test documentation
of an information system (IS), throughout the development and operational life of the system.
Connectivity. A word which indicates the connection of two systems regardless of the method used in
physical connection.
Contingency Plan. A plan maintained for emergency response, backup operations, and post-disaster
recovery for an information system (IS), as a part of its security program, that will ensure the availability of
critical resources and facilitate the continuity of operations in an emergency situation. Synonymous with
Disaster Plan and Emergency Plan.
Controlled interface. A mechanism that facilitates the adjudication of different interconnected system
security policies (e.g., controlling the flow of information into or out of an interconnected system).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
133
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Critical Design Review (CDR). A formal review conducted on each configuration item when design is
complete. Determines that the design satisfies requirements, establishes detailed compatibility, assesses
risk, and reviews preliminary product specifications.
Crypto-Ignition Key (CIK). A device or electronic key used to unlock the secure mode of crypto
equipment.
Cryptologic Information System (IS). A Cryptologic IS is defined as any IS which directly or indirectly
supports the cryptologic effort, to include support functions, such as, administrative and logistics,
regardless of manning, location, classification, or original funding citation. This includes strategic, tactical,
and support ISs; terrestrial, airborne, afloat, in-garrison, and spaceborne ISs; ISs dedicated to information
handling; and information-handling portions of ISs that perform other functions.
Declassification (of IS Storage Media). An administrative action following sanitization of the IS or the
storage media that the owner of the IS or media takes when the classification is lowered to unclassified.
Declassification allows release of the media from the controlled environment if approved by the appropriate
authorities. The procedures for declassifying media require Designated Accrediting Authority
(DAA)
Representative (Rep)/Service Certifying Organization (SCO) approval.
Defense Intelligence Agency
(DIA). The Director, DIA is the authority for the promulgation of
intelligence information systems (ISs) computer security policy, and is also the Principal Approving
Authority (PAA) for the Security Accreditation against that policy of all ISs and networks processing,
using, storing, or producing intelligence information.
Degauss. (1) To reduce the magnetization to zero by applying a reverse (coercive) magnetizing force
commonly referred to as demagnetizing, or (2) to reduce the correlation between previous and present data
to a point that there is no known technique for recovery of the previous data. NOTE: A list of approved
degaussers is updated and published quarterly in the “National Security Agency (NSA) Information
Security Products and Services Catalog”.
Department/Agency/Organization (DAO) Code. A 6-digit identification number assigned by the Secure
Telephone Unit
(STU)-III/Secure Telephone Equipment
(STE) Central Facility to organizational
descriptions. The DAO code must be used by units when placing an order for STU-III/STE keying
material.
Designated Accrediting Authority
(DAA). The official with the authority to formally assume
responsibility for operating a system (or network) at an acceptable level of risk.
DAA Representative (DAA Rep). An official or service certification organization (SCO) responsible for
ensuring conformance to prescribed security requirements for components of sites under their purview.
SCOs are listed in the Department of Defense Intelligence Information Systems (DoDIIS) Information
System Security Officer (ISSO) Handbook.
Destroying. Destroying is the process of physically damaging the media to the level that the media is not
usable, and that there is no known method of retrieving the data.
Discretionary Access Control (DAC). A means of restricting access to objects (e.g., files, data entities)
based on the identity and need-to-know of subjects (e.g., users, processes) and/or groups to which the
object belongs. The controls are discretionary in the sense that a subject with a certain access permission is
capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by
mandatory access control).
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
134
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Diskette. A metal or plastic disk, coated with iron oxide, on which data are stored for use by an
information system (IS). The disk is circular, rotates inside a square lubricated envelope that allows the
read/write head access to the disk.
Department Of Defense (DoD) Intelligence Information Systems (DoDIIS). The aggregation of DoD
personnel, procedures, equipment, computer programs, and supporting communications that support the
timely and comprehensive preparation and presentation of intelligence to military commanders and national
level decision makers. For the purpose of this document, DoDIIS encompasses the Military Services,
Defense Agencies, Defense Activities, Offices of the Secretary and Assistant Secretaries of Defense, the
Organization of the Joint Chiefs of Staff, and the Unified Commands.
DoDIIS Site. An administrative grouping of a combination of Department of Defense Intelligence
Information Systems (DoDIIS) accredited and managed collectively on the basis of geographical or
organizational boundaries. Each DoDIIS Site contains multiple DoD intelligence information systems (ISs)
which support the site’s intelligence mission.
EEPROM. Acronym for electrically erasable programmable read-only memory. Pronounced double-e-
prom or e-e-prom, an EEPROM is a special type of PROM that can be erased by exposing it to an
electrical charge. Like other types of PROM, EEPROM retains its contents even when the power is turned
off. Also like other types of ROM, EEPROM is not as fast as RAM. EEPROM is similar to flash memory
(sometimes called flash EEPROM). The principal difference is that EEPROM requires data to be written or
erased one byte at a time whereas flash memory allows data to be written or erased in blocks. This makes
flash memory faster.
EPROM. Acronym for erasable programmable read-only memory, and pronounced e-prom, EPROM is a
special type of memory that retains its contents until it is exposed to ultraviolet light. The ultraviolet light
clears its contents, making it possible to reprogram the memory. To write to and erase an EPROM, you
need a special device called a PROM programmer or PROM burner. An EPROM differs from a PROM in
that a PROM can be written to only once and cannot be erased. EPROMs are used widely in personal
computers because they enable the manufacturer to change the contents of the PROM before the computer
is actually shipped. This means that bugs can be removed and new versions installed shortly before
delivery. A note on EPROM technology: The bits of an EPROM are programmed by injecting electrons
with an elevated voltage into the floating gate of a field-effect transistor where a 0 bit is desired. The
electrons trapped there cause that transistor to conduct, reading as 0. To erase the EPROM, the trapped
electrons are given enough energy to escape the floating gate by bombarding the chip with ultraviolet
radiation through the quartz window. To prevent slow erasure over a period of years from sunlight and
fluorescent lights, this quartz window is covered with an opaque label in normal use.
Fixed Disk. A magnetic storage device used for high volume data storage and retrieval purposes, which is
not removable from the disk drive in which it operates.
Flash Memory. A special type of EEPROM that can be erased and reprogrammed in blocks instead of one
byte at a time. Many modern PCs have their BIOS stored on a flash memory chip so that it can easily be
updated if necessary. Such a BIOS is sometimes called a flash BIOS. Flash memory is also popular in
modems because it enables the modem manufacturer to support new protocols as they become
standardized.
Flush. A computer program which is part of the Computer Security Toolbox. FLUSH is a MS-DOS based
program used to eliminate appended data within a file or files and appended data located in unallocated or
free space on a disk or diskette.
FRAM. Short for Ferro electric Random Access Memory, a type of non-volatile memory developed by
Ramtron International Corporation. FRAM combines the access speed of DRAM and SRAM with the non-
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
135
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
volatility of ROM. Because of its high speed, it is replacing EEPROM in many devices. The term FRAM
itself is a trademark of Ramtron.
General User. A person accessing an information system (IS) by direct connections (e.g., via terminals) or
indirect connections. NOTE: “Indirect connection” relates to persons who prepare input data or receive
output that is not reviewed for content or classification by a responsible individual.
Government-Approved Facility. Any Government owned room or outside of a Sensitive Compartmented
Information Facility (SCIF) with controlled or restricted access designed to limit public access which has
operational procedures in place to actually limit access; any Government owned SCIF or area within a
SCIF.
Guest system. Any system that enters the SCIF which has not already been certified or accredited by the
respective cognizant SCIF authority is considered a Guest system.
Hard Disk. A magnetic storage device used for high volume data storage and retrieval purposes to include
ones which are both removable and non-removable from the disk drives in which they operate.
Information Assurance. Information Operations that protect and defend data and IS by ensuring their
availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing
restoration of IS by incorporating protection, detection, and reaction capabilities.
Information System (IS). Any telecommunications and/or computer related equipment or interconnected
system or subsystems of equipment that is used in the automated acquisition, storage, manipulation,
management, movement, control, display, switching, interchange, transmission or reception of voice and/or
data (digital or analog) and includes software, firmware, and hardware. Included are computers, word
processing systems, networks, or other electronic information handling systems, and associated equipment.
Information Systems (IS) and Network Security. IS and network security is the protection afforded to
information systems in order to preserve the availability, integrity, and confidentiality of the systems and
the information contained within the system. Such protection is the integrated application of
communications security (COMSEC), TEMPEST, and information systems security (INFOSEC) executed
in liISon with personnel security, operations security, industrial security, resources protection, and physical
security.
Information Systems Security
(INFOSEC). The protection of information systems
(ISs) against
unauthorized access to or modification of information, whether in storage, processing or transit, and
against the denial of service to authorized users or the provision of service to unauthorized users, including
those measures necessary to detect, document, and counter such threats.
Information Systems Security Engineer (ISSE). The person responsible for ensuring the security and
integrity of a system during its life cycle and interfacing with other program elements to ensure security
functions and safeguards are effectively integrated into the total system engineering effort. See SDSO.
Information Systems Security Manager (ISSM). The manager responsible for an organization’s IS
security program. Appointed by the Commander/Commanding Officer, the ISSM is the single point of
contact for his/her organization concerning security matters to the Designated Accrediting Authority
(DAA) Representative (Rep)/Service Certifying Organization (SCO).
Information Systems Security Program Manager (ISSPM). The Air Force (AF) Air Intelligence
Agency (AIA)/Army Intelligence and Security Command (INSCOM)/Navy Commander, Naval Security
Group
(COMNAVSECGRU) individual appointed by the Service Cryptologic Element
(SCE)
Commander/Commanding Officer as being the manager responsible for the SCE-level information systems
(IS) and network security program and the security of all the agency’s/command’s ISs. Additionally, the
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
136
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
ISSPM is the Designated Accrediting Authority (DAA) for the accreditation of systems on behalf of the
NSA/CSS Senior Information Systems Security Program Manager (SISSPM).
Information Systems Security Officer (ISSO). The person responsible to the ISSM for ensuring that
operational security is maintained for a specific IS, sometimes referred to as a Network Security Officer.
Each organizational level unit assigns one ISSO per system. A ISSO may have the responsibility for more
than one system. See System Administrator (SA).
Inspectable Space. A determination of the three-dimensional space surrounding equipment that processes
classified and/or sensitive information within which TEMPEST exploitation is not considered practical, or
where legal authority to identify and/or remove a potential TEMPEST exploitation exists.
Integrity. Protection against unauthorized modification or destruction of information. Evident as an IS
Security characteristic ensuring computer resources operate correctly and data in the system is accurate.
This characteristic is applicable to hardware, software, firmware, and the databases used by the computer
system.
Intelligence Community. A term which, in the aggregate, refers to the following Executive Branch
organizations and activities: the Central Intelligence Agency (CIA); the National Security Agency (NSA);
the Defense Intelligence Agency (DIA); offices within the Department of Defense; and others organized for
collection of specialized national foreign intelligence through reconnISsance programs.
Interconnected System. A set of separately accredited systems that are connected together.
Interim Approval To Operate (IATO). Temporary authorization granted by a Designated Accrediting
Authority (DAA) Representative (Rep)/Service Certifying Organization (SCO) for an information system
(IS) to process classified information in its operational environment based on preliminary results of a
security evaluation of the system.
Interoperability. The capability of one system to communicate with another system through common
protocols.
Initial Operating Capability
(IOC). A time when the persons in authority
(e.g. program/project
managers [PMs] or operations personnel) declare that a system meets enough requirements to formally be
declared operational while the system may not meet all of the original design specifications to be declared
fully operational.
Key Material Identification Number (KMID). A unique number automatically assigned to each piece of
Secure Telephone Unit (STU)-III/Secure Telephone Equipment (STE) keying material by the STU-
III/STE.
Laptop. See Portable Computer System.
Level of Concern. The Level of Concern is a rating assigned to an IS by the DAA. A separate Level of
Concern is assigned to each IS for confidentiality, integrity and availability. The Level of Concern for
confidentiality, integrity, and availability can be Basic, Medium, or High. The Level of Concern assigned to
an IS for confidentiality is based on the sensitivity of the information it maintains, processes and transmits.
The Level of Concern assigned to an IS for integrity is based on the degree of resistance to unauthorized
modifications. The Level of Concern assigned to an IS for availability is based on the needed availability of
the information maintained, processed, and transmitted by the systems for mission accomplishment, and
how much tolerance for delay is allowed.
Limited Release. A procedure to be used by United States SIGINT System (USSS) activities to control
the release of storage media devices that have contained classified information to other activities outside
the USSS community.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
137
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Local Area Network (LAN). Any local area capability to provide interoperability. See network.
Logic Bomb. A logic bomb is a program or code fragment which triggers an unauthorized, malicious act
when some predefined condition occurs. The most common type is the “time bomb”, which is programmed
to trigger an unauthorized or damaging act long after the bomb is “set”. For example, a logic bomb may
check the system date each day until it encounters the specified trigger date and then executes code that
carries out its hidden mission. Because of the built-in delay, a logic bomb virus is particularly dangerous
because it can infect numerous generations of backup copies of data and software before its existence is
discovered.
Malicious Code. Software or firmware that is designed with the intent of having some adverse impact on
the confidentiality, integrity, or availability of an IS. It may be included in hardware, software, firmware or
data. Computer Viruses, Worms, Trojan Horses, Trapdoors, and Logic/Time Bombs all fall under the
definition of malicious code. Computer viruses pose the primary threat to ISs because of their reproductive
capability.
Malicious Code Screening. Screening is the process of monitoring for the presence of malicious code.
Malicious code occurs in different forms, which may have different methods for screening. Malicious code
can arrive through either media that are introduced to IS or as mobile code that arrives through
connections to other systems and networks.
Master Crypto-Ignition Key (CIK) Custodian. An individual at each node in a Community of Interest
(COI) who is responsible for controlling and maintaining the Master CIK and programming the security
features of the Secure Telephone Unit (STU)-III/STE.
Mission-Essential. In the context of information, that information which is an essential portion of a unit’s
mandatory wartime capability.
Mobile Code. The code obtained from remote systems, transmitted across a network, and then
downloaded onto and executed on a local system. Mobile code has come to refer to web-based code
downloaded onto a user’s client and run by the user’s browser. The larger set of mobile code normally
involves an explicit decision to execute—either by the user (manually) or by an application—and an
implicit decision autonomously made by an application.
Modem. A device that electronically Modulates and Demodulates signals, hence the abbreviation
MODEM.
National Security Agency/Central Security Service
(NSA/CSS). The Director, NSA/CSS is the
authority for promulgation of computer security policy, and is also the Principal Approving Authority
(PAA) for the security accreditation against that policy of all information systems (ISs) and networks
processing, using, storing, or producing cryptologic information.
National Security Information (NSI). Information that has been determined, pursuant to Executive
Order (EO) 12958 or any predecessor order, to require protection against unauthorized disclosure, and
that is so designated.
National Security-Related Information. Unclassified information related to national defense or foreign
relations of the United States.
Need-to-Know. A determination made by an authorized holder of classified information that a prospective
recipient of information requires access to specific classified information to perform or assist in a lawful
and authorized Government function, such as that required to carry out official duties.
Network. A combination of information transfer resources devoted to the interconnection of two or more
distinct devices, systems, or gateways.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
138
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Network Manager. The individual who has supervisory or management responsibility for an organization,
activity, or functional area that owns or operates a network.
Network Security Officer
(NSO). An Individual formally appointed by a Designated Accrediting
Authority (DAA)/Service Certifying Organization (SCO) to ensure that the provisions of all applicable
directives are implemented throughout the life cycle of an information system (IS) network.
Network System. A system that is implemented with a collection of interconnected network components.
A network system is based on a coherent security architecture and design.
Non-Volatile Memory Components. Memory components that DO RETAIN data when all power
sources are disconnected.
Notebook. See Portable Computer System.
NVRAM. Abbreviation of Non-Volatile Random Access Memory, a type of memory that retains its
contents when power is turned off. One type of NVRAM is SRAM that is made non-volatile by connecting
it to a constant power source such as a battery. Another type of NVRAM uses EEPROM chips to save its
contents when power is turned off. In this case, NVRAM is composed of a combination of SRAM and
EEPROM chips.
Object Reuse. Reassignment of a storage medium (e.g., page frame, disk sector, or magnetic tape) that
contained one or more objects, after ensuring that no residual data remained on the storage medium.
Optical Storage Media. Optical mass storage, including compact disks (CD, CDE, CDR, CDROM),
optical disks (DVD), and magneto-optical disks (MO)
Orange Book. Synonymous with the Department of Defense (DoD) Trusted Computer System Evaluation
Criteria, DoD 5200.28-STD.
Organizational-level Commander/Commanding Officer. The individual, regardless of rank, which has
been appointed as the officer-in-command of a physical organization.
Overwrite Procedure (for purposes of downgrading in limited cases). Process which removes or
destroys data recorded on an information system (IS) storage medium by writing patterns of data over, or
on top of, the data stored on the medium.
Overwrite Verification Procedure. A visual validation procedure that provides for reviewing, displaying,
or sampling the level of success of an overwrite procedure.
Palmtop. See Portable Computer System.
Pass Phrase. Sequence of characters, longer than the acceptable length of a password that is transformed
by a password system into a virtual password of acceptable length.
Password. Protected/private character string used to authenticate an identity or to authorize access to
data.
Password Shadowing. The ability within any operating system which physically stores the password
and/or encrypted password results in a mass storage area of the system other than the actual password file
itself. This feature prevents the theft of passwords by hackers. Usually a UNIX feature.
Periods Processing. The processing of various levels of classified and unclassified information at distinctly
different times. Under the concept of periods processing, the system must be cleared of all information
from one processing period before transitioning to the next. A system is said to operate in a “Periods
Processing” environment if the system is appropriately sanitized between operations in differing protection
level periods, or with differing user communities or data.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
139
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Peripheral. Any devices which are part of an information system (IS), such as printers, hard and floppy
disk drives, and video display terminals.
Personal Digital Assistants (PDA)/Diaries (PDD). These items are mini processors with computing
power that are generally smaller than laptop, notebook, or palmtop computers. Some examples include, but
are not limited to, the Newton, Boss, Wizard, etc.
Phonemes. A phonetic word which sounds similar to an actual word. (Example, “fone” for “phone,”
“lafter” for “laughter”).
Portable Computer System. Any computer system specifically designed for portability and to be hand
carried by an individual (e.g., Grid, Laptop, Notebook, Palmtop, etc.).
Principal Accrediting Authority (PAA). The senior official having the authority and responsibility for all
IS within an agency. Within the intelligence community, the PAAs are the DCI, EXDIR/CIA, AS/DOS
(Intelligence and research), DIRNSA, DIRDIA, ADIC/FBI
(National Security Div.), D/Office of
Intelligence/DOE, SAS/Treasury (National Security), D/NIMA and the D/NRO.
Privacy (Not Security). The rights of an individual or organizations to determine for themselves when,
how, and to what extent information about them is to transmitted to others.
Privileged User. The user of an information system (IS) who has root user authority.
Project/Program Manager (PM). The single individual responsible for a project or program who
manages all day-to-day aspects of the project or program.
PROM. Pronounced prom, an acronym for programmable read-only memory. A PROM is a memory chip
on which data can be written only once. Once a program has been written onto a PROM, it remains there
forever. Unlike RAM, PROMs retain their contents when the computer is turned off. The difference
between a PROM and a ROM (read-only memory) is that a PROM is manufactured as blank memory,
whereas a ROM is programmed during the manufacturing process. To write data onto a PROM chip, you
need a special device called a PROM programmer or PROM burner. The process of programming a
PROM is sometimes called burning the PROM. An EPROM (erasable programmable read-only memory) is
a special type of PROM that can be erased by exposing it to ultraviolet light. Once it is erased, it can be
reprogrammed. An EEPROM is similar to a PROM, but requires only electricity to be erased.
Protected Distribution System (PDS). A wireline or fiber-optic telecommunications system that includes
terminals and adequate acoustic, electrical, electromagnetic, and physical safeguards to permit its use for
the unencrypted transmission of classified information.
Protocols. Set of rules and formats, semantic and syntactic, that permits entities to exchange information.
Public Domain Software. Programs/software that is uncopyrighted because the author intended to share
them with everyone in the public domain. Source code is usually included and the author grants you the
right to copy, distribute and modify the software.
Purge. The removal of data from an information system (IS), its storage devices, or other peripheral
devices with storage capacity in such a way that the data may not be reconstructed. Note: An IS must be
disconnected from any external network before a purge. See Clearing.
RED. A designation applied to telecommunications and information systems (ISs), plus associated areas,
circuits, components, and equipment which, when classified plain text signals are being processed therein,
require protection during electrical transmission.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
140
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Red/Black Concept. Separation of electrical and electronic circuits, components, equipment, and systems
that handle classified plain text (RED) information, in electrical signal form, from those which handle
unclassified (BLACK) information in the same form.
Remote Maintenance. An operational procedure that involves connection of a system to an external (i.e.,
outside of the facility securing the system), remote service for analysis or maintenance.
Removable Hard Disk. A hard disk contained in a removable cartridge type casing.
Risk Analysis. Synonymous with Risk Assessment.
Risk Assessment. Process of analyzing threats to and vulnerabilities of an information system (IS), and the
potential impact that the loss of information or capabilities of a system would have on national security and
using the analysis as a basis for identifying appropriate and cost-effective measures.
Risk Management. The discipline of identifying and measuring security risks associated with an IS, and
controlling and reducing those risks to an acceptable level.
Routine Changes. Changes which have a minimal effect on the overall TEMPEST security of the
Sensitive Compartmented Information
(SCI) Facility
(SCIF). Adding a different type of electronic
information processing equipment (unless the equipment added is known to have an unusually large
TEMPEST profile), movement of the equipment within the facility, and minor installation changes are
examples of routine changes.
Sanitizing (Also Purging). The removal of information from media or equipment such that the data
recovery using any known technique or analysis is prevented, as well as the removal of all classified labels
and markings. Sanitizing allows moving the media to an environment with lower protection requirements.
In general, laboratory techniques cannot retrieve data that has been sanitized/purged.
Sealed Disk Drive. See “Hard Disk”.
Secure Copy. A computer program which is part of the Computer Security Toolbox. Secure Copy
(SCOPY) is a MS-DOS based program used to eliminate appended data within a file or files while
transferring the same from a source disk or diskette to a target disk or diskette.
Secure Data Device (SDD). The SDD provides a simple and cost-effective way to protect classified
Government data transmissions. The SDD provides Secure Telephone Unit (STU)-III/Secure Telephone
Equipment (STE) secure data transmission functions without voice features and is fully interoperable with
all other STU-III/STE products. It allows the user to access a computer database, send a facsimile (FAX)
message, or use electronic mail and be sure the information is protected. The SDD was developed under
the U.S. Government’s STU-III/STE program and is approved for use by Federal departments, agencies,
and Government contractors.
Secure Telephone Unit III (STU-III). The STU-III family includes several interoperable terminals
capable of transmitting voice and data through the public telephone network. The STU-III can be used as
an ordinary telephone, and can also be used as a secure terminal, connected through the public telephone
network to other STU-IIIs. A STU-III Secure Data Device
(SDD) provides STU-III secure data
transmission functions without voice features. STU-IIIs are endorsed by the National Security Agency
(NSA) for protecting classified or sensitive, unclassified U.S. Government information, when appropriately
keyed.
Security. The protection of information to assure it is not accidentally or intentionally disclosed to
unauthorized personnel.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
141
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Security Environment Changes. Changes which have a detrimental effect on the facility. Changes to the
inspectable space (IS), addition of a radio transmitter or a modem for external communications, removal or
reduction of an existing TEMPEST countermeasure (Radio Frequency Interference [RFI] Shielding,
Filters, Control/Inspectable space, etc.) would be changes to the security environment.
Security Testing. The process to determine that an information system (IS) protects data and maintains
functionality as intended.
Security Training, Education and Motivation (STEM). A security education program designed to
educate and motivate personnel concerning the protection of priority resources and the safeguarding of
classified information.
Senior Information Systems Security Program Manager (SISSPM). The national-level individual
appointed by the Director, National Security Agency (DIRNSA) as being the manager responsible for the
national-level Service Cryptologic Element
(SCE) Information Systems
(IS) and Network Security
Program, the security of all Cryptologic ISs, and is the Designated Accrediting Authority (DAA) for the
accreditation of systems on behalf of the DIRNSA.
Senior Intelligence Officer (SIO). The highest ranking military or civilian individual charged with direct
foreign intelligence missions, functions, or responsibilities within a department, agency, component, or
element of an intelligence community organization or Department of Defense (DoD) Intelligence Activity
assigned responsibilities or designated authorities by a Senior Official of the Intelligence Community
(SOIC).
Senior Officials of the Intelligence Community (SOIC). The heads of organizations or their designated
representatives within the Intelligence Community, as defined by Executive Order (EO) 12333.
Sensitive But Unclassified (SBU) Information. Information collected, maintained, and/or disseminated
by an agency that is not classified but whose unauthorized release or use could compromise or damage
privacy or proprietary rights, critical agency decision making, and/or the enforcement or implementation of
public law or regulations under which the agency operates.
Sensitive Compartmented Information
(SCI). Classified information concerning or derived from
intelligence sources, methods, or analytical processes, which is required to be handled within formal access
control systems established by the Director of Central Intelligence (DCID 1/19).
Sensitive Compartmented Information (SCI) Facility (SCIF). An accredited area, room, group of
rooms, or installation where SCI may be stored, used, discussed and/or electronically processed.
Service Certifying Organization (SCO). The organization responsible for ensuring conformance to
prescribed security requirements for components of sites under their purview. SCOs are listed in the
Department of Defense Intelligence Information Systems (DoDIIS) Information System Security Officer
(ISSO) Handbook.
Service Cryptologic Elements (SCE). A term used to designate, separately or together, those elements of
the U.S. Army, Navy, and Air Force which perform cryptologic functions. The Air Force Air Intelligence
Agency (AIA), Army Intelligence and Security Command (INSCOM), and Navy Commander Naval
Security Group (COMNAVSECGRU) are the SCEs responsible to the National Security Agency/Central
Security Service (NSA/CSS) for accreditation of all cryptologic information systems (ISs) within their
respective services.
Site Information Systems Security Manager (Site ISSM). The single information systems (IS) security
focal point for a defined site. The site ISSM supports two organizations: User organization and technical
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
142
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
organization. The site ISSM is responsible for managing the baseline and ensuring that changes to the site
baseline are properly controlled.
Site Integration Management Office (SIMO). The major functions of the SIMO are: Establishing
baselines, monitoring compliance, configuration management, and integration transition. There are three
levels of such offices: DoDIIS, Service, and site. Only the larger sites will have a site SIMO.
Special Access Program (SAP). Any program imposing “need-to-know” or access controls beyond those
normally provided for access to Confidential, Secret, or Top Secret information. Such a program includes,
but is not limited to, special clearance, adjudication, or investigative requirements; special designation of
officials authorized to determine
“need-to-know”; or special lists of persons determined to have a
“need-to-know”.
Special Security Officer (SSO). The individual assigned responsibility for the security management,
operation, implementation, use and dissemination of all Sensitive Compartmented Information (SCI)
material within his/her respective organization.
Stand-Alone System. An information system (IS) operating independent of any other IS within an
environment physically secured commensurate with the highest classification of material processed or
stored thereon.
Survivability. The capability of a system to withstand a man-made or natural hostile environment without
suffering an abortive impairment of its ability to accomplish its dedicated mission.
SYSOP. An operator responsible for performing system-oriented procedures. See System Administrator.
System. A generic name for an Information System (IS).
System Administrator
(SA). The individual responsible for maintaining the system in day-to-day
operations. The SA has responsibility to: manage system hardware and software, data storage devices and
application software; manage system performance; provide system security and customer support; perform
equipment custodian duties; maintain software licenses and documentation; monitor hardware and software
maintenance contracts; establish USERIDs and passwords; ensure adequate network connectivity; review
audit trails; and provide backup of system operations and other system unique requirements. See
Information System Security Officer (ISSO).
System Design Security Officer (SDSO). An individual responsible for ensuring that adequate security
requirements are stated in the design specifications of new systems and system upgrades during the design
phase of their life cycle. This individual works closely with all project/program acquisition managers. See
ISSE.
System Security Engineering. The efforts that help achieve maximum security and survivability of a
system during its life cycle and interfacing with other program elements to ensure security functions are
effectively integrated into the total system engineering effort.
System Security Authorization Agreement (SSAA). A formal document that fully describes the planned
security tasks required to meet system or network security requirements. The package must contain all
information necessary to allow the DAA Rep/SCO to make an official management determination for
authorization for a system, network, or site to operate in a particular security mode of operation; with a
prescribed set of safeguards, against a defined threat with stated vulnerabilities and countermeasures; in a
given operational environment; under a stated operational concept; with stated interconnections to external
systems; and at an acceptable level of risk.
System Security Plan (SSP). See System Security Authorization Agreement.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
143
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Technical Vulnerability. A hardware, firmware, communication, or software weakness which leaves an
information system (IS) open for potential exploitation or damage, either externally or internally resulting
in risk for the owner, user, or manager of the IS.
TEMPEST. A short name referring to investigation, study, and control of compromising emanations from
telecommunications and information system (IS) equipment. TEMPEST must be considered during all life
cycle phases of equipment. (See Compromising Emanations).
TEMPEST Approved. This term applies to equipment or systems which have been built and certified to
meet Level I of National Security Telecommunications Information Systems Security Advisory
Memorandum (NSTISSAM) TEMPEST/1-92, Compromising Emanations Laboratory Test Requirements.
TEMPEST Zone. A defined area within a facility where equipment with appropriate TEMPEST
characteristics
(TEMPEST zone assignment) may be operated without emanating electromagnetic
radiation beyond the controlled space boundary of the facility.
TEMPEST Zoned Equipment. Equipment that has been evaluated and assigned an equipment zone
corresponding to the level in National Security Telecommunications Information Systems Security
Advisory Memorandum (NSTISSAM) TEMPEST/1-92. This equipment must be installed according to the
NSTISSAM and HQ-Level specialized installation instructions.
Terminal Area. A subset or part of the overall work space assigned to a specific area within an
organization. An area within the typical office environment restrictive in size such that it permits one
person to observe and monitor access with the intent of preventing Information System (IS) abuse and
unauthorized IS access.
Threat Assessment. The process of formally evaluating the degree of threat to an information system and
describing the nature of the threat.
Threat Monitoring. The analysis, assessment, and review of Information Systems (ISs) audit trails and
other data collected for the purpose of searching out system events that may constitute violations or
attempted violations of data or system security.
Toolbox. See Computer Security Toolbox.
Trapdoor. Operating system and application safeguards that usually prevent unauthorized personnel from
accessing or modifying programs. During software development, however, these built-in security measures
are usually bypassed. Programmers often create entry points into a program for debugging and/or insertion
of new code at a later date. These entry points (trapdoors) are usually eliminated in the final stages of
program development, but they are sometimes overlooked, accidentally or intentionally. A perfect example
of a trapdoor was dramatized in the movie War Games, where the teen-age hacker enters the special
password “Joshua” and gains unrestricted access to a mainframe computer in NORAD headquarters. Such
a mechanism in a computer’s operating system can grant an attacker unlimited and virtually undetectable
access to any system resource after presenting a relatively trivial control sequence or password.
Trojan Horse. A computer program containing an apparent or actual useful function that contains
additional (hidden) functions that allows unauthorized collection, falsification, or destruction of data. This
is the most commonly used method for program-based frauds and sabotage.
Trusted Computing Base (TCB). The totality of protection mechanisms within a computer system,
including hardware, firmware, and software, the combination of which is responsible for enforcing a
security policy. NOTE: The ability of a TCB to enforce correctly a unified security policy depends on the
correctness of the mechanisms within the TCB, the protection of those mechanisms to ensure their
correctness, and the correct input of parameters related to the security policy.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
144
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
Trusted Path. A mechanism by which a person using a terminal can communicate directly with the trusted
computing base (TCB). NOTE: The trusted path can only be activated by the person or the TCB and
cannot be initiated by untrusted software.
uNclassified Internet Protocol Router NETwork. The unclassified network which replaced the military
unclassified network. Provides connection to the world wide web.
Unclassified Sensitive. For computer applications, this term refers to any information, the loss, misuse, or
unauthorized access to or modification of which could adversely affect the national interest or the conduct
of Federal programs, or the privacy to which individuals are entitled under the section 552a of title 5,
United States Code (the Privacy Act), but which has not been specifically authorized under the criteria
established by an Executive Order or an Act of Congress to be kept secret in the interest of national
defense or foreign policy. (Computer Security Act of 1987, Public Law 100-235). Also see Sensitive but
Unclassified (SBU) Information.
User Identification (USERID). A unique symbol or character string that is used by an information system
(IS) to uniquely identify a specific user.
User Network Manager (UNM). Each sponsor of a Community-of-Interest (COI) must designate an
individual who will be responsible for the management of the network, request permission to use the data
port, and ensure compliance with the security procedures defined in appropriate security policy documents
and those specifically defined in the approval process.
User Representative (UR). A person formally designated, on behalf of the Command Authority, who is
responsible for preparing and submitting all key orders (including Sensitive Compartmented Information
[SCI]) to the Central Facility. The UR has the responsibility for monitoring the status of those orders, to
include keeping the Communications Security (COMSEC) manager informed of the pending key request in
situations where the UR is other than the COMSEC manager.
Virus. A self replicating, malicious program segment that attaches itself to an application program or other
executable system component and leaves no external signs of its presence.
Volatile Memory. Random Access Memory (RAM) which is not retained upon system shutdown.
Vulnerability. A weakness in an information system (IS), or cryptographic system, or components (e.g.,
system security procedures, hardware design, internal controls), that could be exploited.
Wide Area Network (WAN). A computer network that services a large area. WANs typically span large
areas (states, countries, and continents) and are owned by multiple organizations. See Local Area Network
and Network.
Worm. A worm is a program, originally developed by systems programmers, which allows the user to tap
unused network resources to run large computer programs. The worm would search the network for idle
computing resources and use them to execute a program in small segments. Built-in mechanisms would be
responsible for maintaining the worm, finding free machines, and replicating the program. Worms can tie
up all the computing resources on a network and essentially shut it down. A worm is normally activated
every time the system is booted up. This is differentiated from WORM (write-once, read many) descriptive
of optical (compact disk) media with single write capability.
Write Protect. A term used to indicate that there is a machine hardware capability which may be manually
used to protect some storage media from accidental or unintentional overwrite by inhibiting the write
capability of the system. (For example, write protection of magnetic tapes is accomplished by the physical
removal of the “write-ring” from the back of the tape. Write protection of three and one half inch floppy
diskettes refers to the correct placement of the sliding tab to the open position which inhibits the hardware
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
145
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
capability to perform a physical write to the diskette. Write protection includes using optical disks within
CD read-only devices.)
UNCLASSIFIED//FOR OFFICIAL USE ONLY
UNCLASSIFIED//FOR OFFICIAL USE ONLY
146
Joint DoDIIS/Cryptologic SCI Information Systems Security Standards
11 April 2003
APPENDIX D - SUMMARY OF CHANGES
UNCLASSIFIED//FOR OFFICIAL USE ONLY
Integration of Civil Unmanned
Aircraft Systems (UAS) in the
National Airspace System
(NAS) Roadmap
First Edition - 2013
A
DRAFT
November 7, 2013
Dear Members of the Aviation Community:
I am pleased to present the Federal Aviation Administration’s (FAA) Roadmap for Integration of Civil
Unmanned Aircraft Systems (UAS) in the National Airspace System (NAS). The FAA and the UAS Aviation
Rulemaking Committee (ARC) worked together for the past year to produce this roadmap. Unmanned
aircraft offer new ways for commercial enterprises and public operators to increase operational
efficiency, decrease costs, and enhance safety; and this roadmap will allow us to safely and efficiently
integrate them into the NAS.
The FAA is committed to the safe and efficient integration of UAS into the NAS. However, as safety is our top priority,
UAS integration must be accomplished without reducing existing capacity, decreasing safety, impacting current
operators, or placing other airspace users or persons and property on the ground at increased risk. We have made great
progress in accommodating public UAS operations, but challenges remain for the safe, long-term integration of both
public and civil UAS in the NAS.
This roadmap outlines the actions and considerations needed to enable UAS integration into the NAS. The roadmap also
aligns proposed FAA actions with Congressional mandates from the FAA Modernization and Reform Act of 2012. This plan
also provides goals, metrics, and target dates for the FAA and its government and industry partners to use in planning
key activities for UAS integration.
We will update the specific implementation details (goals, metrics, target dates) as we learn from our current UAS
operations, leverage ongoing research, and incorporate the work of our government and industry partners in all
related areas.
Thank you for your continued support and active participation in the safe and efficient integration of UAS in the NAS.
Michael P. Huerta
Administrator
Table of Contents
Executive Summary
4
2.2.4
Managing the Challenges
20
1
Purpose and Background of Civil UAS Roadmap
6
3
Perspective 1: Accommodation
22
1.1
History of UAS
7
3.1
Overview
22
1.2
Proposed Civil and Commercial Applications
7
3.2
Standards
23
1.3
Definitions
8
3.3
Rules and Regulations
24
1.4
Policy
9
3.4
Airworthiness Certification of the UAS
25
1.4.1
FAA UAS Policy Basis
9
3.5
Procedures and Airspace
27
1.4.2
International Civil Aviation Organization
3.6
Training (Pilot, Flightcrew Member, Mechanic,
(ICAO) Policy
10
and Air Traffic Controller)
28
1.4.3
Industry Policy Recommendations
11
3.7
Research and Development (R&D) / Technology
28
1.4.4
Privacy and Civil Liberties Considerations
11
4
Perspective 2: Integration
32
4.1
Overview
32
1.4.5
National Security Issues
12
4.2
Standards
34
2
UAS Operations in the NAS
14
4.3
Rules and Regulations
34
2.1
FAA’s Dual Role for UAS Integration
14
4.4
Airworthiness Certification of the UAS
34
2.2
UAS Challenges
14
4.5
Procedures and Airspace
35
2.2.1
Policy, Guidance, and Regulatory
4.6
Training (Pilot, Flightcrew Member, Mechanic,
Product Challenges
14
and Air Traffic Controller)
35
2.2.2
Air Traffic Operational Challenges
17
4.7
Research and Development (R&D) /Technology
36
2.2.3
Technological Challenges
18
Integration of Civil Unmanned Aircraft Systems (UAS) in the National Airspace System (NAS) Roadmap
ii
DRAFT
4.8
Test Ranges
37
C.3
Ground Based Sense and Avoid (GBSAA)
53
5
Perspective 3: Evolution
38
C.4
Airborne Sense and Avoid (ABSAA)
54
5.1
Overview
38
C.5
Control and Communications (C2)
56
5.2
Standards
38
C.6
Small UAS (sUAS) and Other Rules
58
5.3
Rules and Regulations
38
C.7
Test Ranges
60
5.4
Airworthiness Certification of the UAS
38
C.8
Air Traffic Interoperability
60
5.5
Procedures and Airspace
39
C.9
Miscellaneous
61
5.6
Training (Pilot, Flightcrew Member, Mechanic,
Appendix D: FAA Modernization and Reform Act of 2012
and Air Traffic Controller)
39
Reference Text
66
5.7
Research and Development (R&D) / Technology
39
6
Conclusions
42
6.1
Summary
42
6.2
Outlook
42
Appendix A: Acronyms
44
Appendix B: Glossary
46
Appendix C: Goals, Metrics, and Target Dates
50
C.1
Certification Requirements (Airworthiness)
51
C.2
Certification Requirements (Pilot/Crew)
52
Table of Contents
iii
Executive Summary
Expanding Operations of Unmanned Aircraft Systems in
the NAS
Ultimately, UAS must be
Since the early 1990s, unmanned aircraft systems (UAS) have operated
integrated into the NAS
on a limited basis in the National Airspace System (NAS). Until recently,
UAS mainly supported public operations, such as military and border
without reducing existing
security operations. The list of potential uses is now rapidly expanding to
capacity, decreasing safety,
encompass a broad range of other activities, including aerial photography,
surveying land and crops, communications and broadcast, monitoring
negatively impacting
forest fires and environmental conditions, and protecting critical
current operators, or
infrastructures. UAS provide new ways for commercial enterprises (civil
operations) and public operators to enhance some of our nation’s aviation
increasing the risk
operations through increased operational efficiency and decreased costs,
while maintaining the safety of the NAS.
to airspace users or
As stated in Destination 2025 (2011):
persons and property
“The Federal Aviation Administration’s (FAA) mission is to provide the
on the ground any more
safest, most efficient aviation system in the world. What sets the
United States apart is the size and complexity of our infrastructure,
than the integration of
the diversity of our user groups, our commitment to safety and
comparable new and novel
excellence, and a history of innovation and leadership in the world’s
aviation community. Now we are working to develop new systems and
technologies.
to enhance a culture that increases the safety, reliability, efficiency,
capacity, and environmental performance of our aviation system.”
The FAA created the Unmanned Aircraft Systems Integration Office to facilitate integration of UAS safely and
efficiently into the NAS. Toward that goal, the FAA is collaborating with a broad spectrum of stakeholders, which
includes manufacturers, commercial vendors, industry trade associations, technical standards organizations,
academic institutions, research and development centers, governmental agencies, and other regulators. Ultimately,
UAS must be integrated into the NAS without reducing existing capacity, decreasing safety, negatively impacting
current operators, or increasing the risk to airspace users or persons and property on the ground any more than
the integration of comparable new and novel technologies. Significant progress has been made toward UAS-NAS
integration, with many challenges and opportunities ahead.
Integration of Civil Unmanned Aircraft Systems (UAS) in the National Airspace System (NAS) Roadmap
4
|
||
|
|
|