Classified Facility Communications Cabling Infrastructure Design Basics. Pedro De Jesus, PE, RCDD, DCDC Senior Technical Consultant CH2M Hill

Similar documents
This publication is available digitally on the AFDPO WWW site at:

Bravo AV s Structured or Whole-House Wiring Approach

Minimum qualifications for the Telecommunications Engineer are: A. Texas Licensed Profession Engineer (PE)

384A Adapter Installation Instructions

What is TEMPEST Chapter 1

COMMON WORK RESULTS FOR INTEGRATED AUTOMATION DESIGN AND CONSTRUCTION STANDARD

SECTION TESTING, IDENTIFICATION AND ADMINISTRATION

Telecommunciations Infrastructure Project September 20, A. Broadband radio frequency active and passive components

Coastal Carolina University RE-BID WILLIAMS BRICE RENOVATION AND REPAIR October 19, 2018 Construction Documents

ENGINEER S REPORT. of the SAFETY OF MAW COMMUNICATIONS FIBER OPTIC CABLE INSTALLATION

SEL-3405 High-Accuracy IRIG-B Fiber-Optic Transceiver

ANSI/TIA-PN D. Broadband Coaxial Cabling and Components Standard Draft 1, October 11, 2016 TABLE OF CONTENTS

Class B digital device part 15 of the FCC rules

UNIFIED FACILITIES GUIDE SPECIFICATIONS

CATEGORY 6A CABLING SOLUTIONS

CATEGORY 6A CABLING SOLUTIONS

SECTION 7 -- CROSS-CONNECT SYSTEMS

Traditional RF Splitter/Combiner and Directional Coupler User Manual

ANSI/TIA-PN D-R1. Broadband Coaxial Cabling and Components Standard Draft 2, March 8, 2017 TABLE OF CONTENTS

SPECIAL SPECIFICATION 6559 Telecommunication Cable

ENGINEERING COMMITTEE Interface Practices Subcommittee AMERICAN NATIONAL STANDARD ANSI/SCTE

LYNX ULTRA Series Hubs and Baluns

SPECIAL SPECIFICATION 8540 Telecommunication Cable

Traditional RF Splitter/Combiner and Directional Coupler User Manual

BILOXI PUBLIC SCHOOL DISTRICT. Biloxi Junior High School

Amphenol. Amphenol-Tuchel Electronics GmbH. C 112 Series M12 - Connectors

AMERICAN NATIONAL STANDARD

HDBaseT Installation Guide

Public Works Division Lighting District Fiber Optic Specifications April 2009

Rogers Communication Center Cable Documentation and Identification Policy

Pre-bid Supplement #01 Communications Specifications and Additional Scope Project Bid: CM Date: 05/26/2017

INSTRUCTION DE SÉCURITÉ SAFETY INSTRUCTION Mandatory as defined in SAPOCO/42 FIRE PREVENTION FOR CABLES, CABLE TRAYS AND CONDUITS

ELECTROMAGNETIC FIELDS AND PUBLIC HEALTH

Register your product and get support at SDV5122/27. EN User manual

ODW-621. RS-232 Point-to-point applications

CGA0101 Wireless Cable Gateway Quick Installation Guide

Interaction of Infrared Controls And Fluorescent Lamp/Ballast Systems In Educational Facilities

AMERICAN NATIONAL STANDARD

HARTING Ethernet cabling cables and connectors, 4 wire

Instructions for Use P.154-UP (9/4) P.155-UP (9/8) P.150-UP-12 (9/12) P.150-UP-16 (9/16)

Instrumentation Cables

Instructions for Use P.160-AP-8 (13/8) P.160-CP-8 (13/8) P.160-CP-12 (13/12) P.160-CP-16 (13/16)

PREMIUM 5e F/UTP PRODUCTS

Mediacom Upgrade/Splicing Procedures (based on original document from Corporate dated 4/16/98)

ENGINEERING COMMITTEE Interface Practices Subcommittee AMERICAN NATIONAL STANDARD ANSI/SCTE

CATEGORY 6 CABLING SOLUTIONS

Product information 19" 1U HD Patch Panel 48xRJ45/s, Cat. 6A, gray, fully populated

1 Channel VGA Over Fiber Transmitter and Receiver Extender. User Manual L-1VGA-FE

GOODMAN BENTLEY STEREOPHONIC STETHOSCOPE OPERATING INSTRUCTIONS

APPENDIX D TECHNOLOGY. This Appendix describes the technologies included in the assessment

ENGINEERING COMMITTEE Interface Practices Subcommittee AMERICAN NATIONAL STANDARD ANSI/SCTE

Cable installation guidelines

UNM IT/Telecommunications Guide Specification Labeling 11/07/

SECTION MASTER TELEVISION ANTENNA SYSTEM (MTAS)

UNIVERSITY of NORTH DAKOTA LOW VOLTAGE COMMUNICATIONS STANDARDS FOR CABLING, PATHWAYS, AND SPACE

Fibre Optic Modem ODW-622

ENGINEERING COMMITTEE

Multi-Media Installation Guide

2179-CD Series Fiber Optic Splice Closure. Installation Instructions

The University of Texas at Austin September 30, 2011


Compact live fiber identifier with integrated optical power meter

Preparing a home for TransACT fibre-to-the-premise (FTTP) services

ENGINEERING COMMITTEE Interface Practices Subcommittee AMERICAN NATIONAL STANDARD ANSI/SCTE Specification for F Connector, Male, Pin Type

Kramer Electronics, Ltd. USER MANUAL. Optical All-Fiber DVI Cable Model: C-AFDM/AFDM. Available from 164 to 1640 feet

EXHIBIT A Zones Zone 1 (Urban): Zone 2 (Suburban): Zone 3 (Exurban) Blended Rates/Multiple Zones:

ULTIMATE SNAP-N-SEAL


Kwangil Electronic Introduction

Underground Installation of Optical Fiber Cable by Pulling

Copper Solution Contents Cabinets Fiber Optic Solution

LANmark PCB patch panel, 1HU INSTALLATION GUIDE. LANmark PCB patch panel, 1 HU

CONTRACTORS SPECIFICATION

The Newsletter of Delta Automation Inc.

Spec Sheet. InterReach Fusion Wideband 2.5 GHz WiMAX. In-Building Wireless Networking System. Product Highlights

DVBus and Multiplexer and demultiplexer assemblies for video channels, with bidirectional audio and data USER MANUAL

UNIFIED FACILITIES GUIDE SPECIFICATIONS

STRUCTURED CABLING SYSTEMS (SCS)

AMERICAN NATIONAL STANDARD

NAVSEA STANDARD ITEM. 1.1 Title: Fiber Optic Component; remove, relocate, repair, and install

ENGINEERING COMMITTEE Interface Practices Subcommittee AMERICAN NATIONAL STANDARD ANSI/SCTE

Drop Passives: Splitters, Couplers and Power Inserters

ELECTRICAL SAFETY INSPECTION REPORT. MTM Garments Ltd.

SECTION MEDIUM VOLTAGE CABLE INSTALLATION. 1. Section Underground Ducts and Manholes.

HD/SD-SDI Over Fiber Transmitter and Receiver Extender Kit. User Manual L-1SDI-SFE-TX/RX

SECTION INTERCOMMUNICATIONS AND PROGRAM SYSTEMS

Broadband System - D

Obtain HDMI Serenity with Tributaries. Joe Knows HDMI Joe Perfito, President

ENGINEERING COMMITTEE Interface Practices Subcommittee SCTE Test Method for Cable Weld Integrity

ENGINEERING COMMITTEE

MOST. Getting the. BMW Assist. Climate. Settings

Tender Report for Supply and installation of LAN in *Biomedical Imaging and Bioinformatics Lab*

LONWORKS Fibre Optic Converter

NAVSEA STANDARD ITEM. 1.1 Title: Shipboard Electrical/Electronic Cable Procedure; accomplish

CATEGORY 5e CABLING SOLUTIONS

Content BULK CABLES VIDEO CABLES AUDIO CABLES EXTENDERS USB CABLES ETHERNET CABLES VIDEO BALUNS CONNECTORS ADAPTERS PATCH PANELS & WALLPLATES TOOLS

SUBCARRIER TRANSFER FILTER INSTRUCTION BOOK IB622702

CONTENTS. Product Guide 1. Multi Conductor Cable 11. Paired Cable 20. RS-232 Application Cable 27. RS-422 Application Cable 28

Video & Audio Transmission

ENGINEERING COMMITTEE

Transcription:

Classified Facility Communications Cabling Infrastructure Design Basics Pedro De Jesus, PE, RCDD, DCDC Senior Technical Consultant CH2M Hill

What is a Classified Network? This training covers design requirements for communications cabling that transports National Security Information (NSI). United States (US) Government defines and assigns one of 3 levels of secrecy: Top Secret Highest Level Secret 2nd Highest Level Confidential - Lowest Level

Classified Info Keeping it Secret! Federal and military facilities require safeguarding Classified electronic information and infrastructure. Eliminating emanation of signals associated with structured communications cabling systems. Countermeasures designed to reduce the risk of exploitation of information by adversaries using sophisticated electronic devices. Facility and/or equipment shielding may also be required.

What are we protecting? TEMPEST Study of the security of telecommunications devices that emit electromagnetic radiation. TEMPEST originated as a code name of a classified study by the US Military in the late 1960 s. Later the term became an Acronym for Telecommunications Electronics Material Protected from Emanating Spurious Transmissions.

TEMPEST TEMPEST cont. Today the term also encompasses sound and mechanical vibrations. Basically any signal that could be exploited to compromise information. (including unintentional radio or electrical signals, sounds, and vibrations)

Who provides Guidance? Committee on National Security Systems (CNSS) Sets policy for security of the US security systems. CNSSAM TEMPEST/1-13 (CNSS Advisory Memorandum), the RED/BLACK Installation Guidance. [Supersedes NSTISSAM TEMPEST/2-95 and TEMPEST/2-95 Addendum February 2000] The primary standard for structured cabling. Measures are also known as emissions security (EMSEC) which is a subset of communications security (COMSEC). 17 Jan 14

Who Approves? Certified TEMPEST Technical Authority (CTTA) Experienced, technically qualified US Gov t employee providing guidance/solutions for facilities, system and equipment identified as requiring TEMPEST countermeasures.

RED/BLACK Installation Guidance - Concept RED/BLACK Installation Guidance (CNSSAM TEMPEST/1-13) Separating electrical and electronics circuits, components, equipment, and systems into: RED - handles unencrypted Classified or what is called National Security Information (NSI). BLACK - handles non-national security and properly encrypted NSI.

RED/BLACK - Separation Separation is composed of 2 parts: Physical Separation - RED/BLACK physical separation to decrease probability of EMI/EMR between RED and BLACK. Electrical Separation - Addresses signal distribution, power distribution, and grounding. Port-to-port isolation of switches is also applied.

RED/BLACK - Facility Considerations First steps in selection of proper RED/BLACK controls for the facility is: Identify geographic location. Level and type of Classified data processed. Inspectable Space.

RED/BLACK Physical Considerations Physical security is a key element in deciding which RED/BLACK countermeasures will be implemented. Inspectable Space is an important factor in determining necessary safeguards for equipment and systems that process NSI. Security officials, the CTTA, and/or others responsible for certifying the building should be involved in facility planning.

Inspectable Space Definition- amount of three dimensional space surrounding equipment that processes classified and/or sensitive information within which TEMPEST exploitation is not considered practical or where legal authority to identify and remove a potential TEMPEST exploitation exists and is exercised. This space is determined by the Certified TEMPEST Technical Authority(CTTA). Often times the CTTA may require exceeding the minimum requirements due to specific threats.

Inspectable Space Often times CTTA s are overly cautious about required countermeasures. Countermeasure required are in CNSSI No. 7000 which is classified Confidential.

Inspectable Space Size Inspectable space is defined by the cognizant CTTA. Categorized by distance: Less than 20 meters (m). Greater than or equal to 20m, but less than 100m. Equal to or greater than 100m.

Required 3 Levels of RED/BLACK Isolation 3 levels of RED/BLACK isolation Levels. Level I - most stringent Level II - less stringent Level III least stringent Levels correspond to the level of protection need to contain compromising emanations within inspectable space.

RED/BLACK Requirements Level Matrix Below table is random sample of Requirement Level Matrix. Location Classification Level Inspectable Space (IS) Level Within the US Within the US Outside the US Outside the US Outside the US Collateral Secret and below Special Category and Top Secret Special Category and Top Secret Collateral Secret and below Special Category and Top Secret < 20 meters Table 4 >/= 100 meters Table 4 < 20 meters Table 4 >/= 20 meters but < 100 meters Table 4 >/= 100 meters Table 4 Table 4 is U//FOUO so levels are not shown.

Facility RED/BLACK Physical Isolation Requirement RED equipment to BLACK wires that connect to a transmitter. RED equipment to BLACK wires that directly leave Inspectable Space (IS). RED equipment to BLACK equipment with lines that leave IS. RED equipment to BLACK wires that leave IS through digital switch. RED equipment to BLACK equipment with lines that connect to RF transmitter. RED wires to Black wires that leave the IS or connect to RF transmitter. RED wires are shielded. RED lines have distinguishing marking or color coding for identification. RF wires such as CATV and satellite TV isolated within the IS. Common Criteria 1 m 1 m 1 m 50 cm 50 cm 5 cm /15cm* Yes Yes Yes * RED Parallel runs up to 30m to be separated by a minimum of 5 cm (2 ). Runs with over 30m separation shall be 15 cm (6 ). Cables crossing at 90deg shall be separated by 5 cm. Connectors to be a minimum of 5cm apart.

quipment Separation Telecommunications Room - Equipment - RED Black Separation. - Cabling - All levels of classified Red cabling can be run together. Red must be separated from Black.

RED Systems Distribution & Patching Separate RED and Black Distribution panels. Separate distribution panels for each classification level of NSI and for each Special Category of NSI. Separate outlet boxes for RED and Black. Keyed connectors at both outlet and distribution panels, should be used for different classifications levels, unclassified levels and compartments of data, but is not mandatory.

RED Systems Distributing & Patching cont. - Non-Keyed Fiber connectors require separation at the patch panels and outlet boxes for differing Classified systems. - Keyed/Dissimilar Connectors are required if combination Outlets or Patch Panels are used.

Exceptions Fiber Cable - No Separation required. But outlet and Patch Panels may require separation if Dissimilar connectors are not used. - Some agencies will still require Red/Black Separation. Shielded - No separation required. - Most agencies will still require Separation. - When shielded cable is required, the wireline pairs or wireline bundles shall be individually shielded or shall have a minimum of one overall shield, and the cable shall have an outside non-conductive sheath. Screened cable is another term used for a cable with one overall shield. The shield shall be a non-ferrous metallic foil shield with an uninsulated and tinned drain wire or shall be a braided metallic shield with a minimum of 85 percent coverage. Except for coaxial cables, the shield shall not be used as a signal return or a signal carrying conductor.

RED Systems Protected Distribution System RED cables traversing an area controlled to a lower level of classification or access control shall be in a Protected Distribution System (PDS) in accordance with NSTISSI No 7003 ( not CNSSI No 7003, typo in Red/Black Reference). Request site specific requirements from CTTA. DOCUMENT ALL Direction provided. PDS Types: Simple - constructed of wood, PVC or EMT. Hardened - EMT, ferrous conduit or pipe, or rigid-sheet steel ducting

Protected Distribution System (PDS) - Example Underground Special Requirements CONUS Concrete encasement encouraged but not required OCONUS- 8 inches of concrete or steel container 1 meter deep minimum but greater depth may be required by CTTA MH s with GSA Approved Lock or alarm. Rodger Jones, Opinion Blog http://dallasmorningviewsblog.dallasnews.com Special Requirements Manhole covers Welded shut Since 9/11 some bases lock all manholes 8 deep duct bank Common to apply OCONUS requirement in US.

Access Areas and Threat Areas 3 levels of access areas are: Controlled Access Area (CAA) - direct physical control within which unauthorized persons are denied access. Even with granted access they must be escorted by authorized persons or under continuous surveillance. Special Type CAA - Open Storage is a secure room or vault that has met certain construction standards and PDS is not required inside.

Access Areas and Threat Areas cont. Limited Controlled Area (LCA) - The space surrounding a PDS within which exploitation is not considered likely or legal authority to identify or remove a potential exploitation exists.. Uncontrolled Access Area - An area open to the public. PDS required.

CATV and Satellite TV Isolation Cables shall be isolated before the cables leave the inspectable space. For SCIFs and SAPFs, the isolation must be within boundary of the SCIF or SAPF. May be achieved by: convert copper wireline to fiber optic. A 12 db minimum gain one-way RF amplifier and a 12 db min. loss RF attenuator inline with the cable.

CATV and Satellite TV Isolation Not required for receive-only systems entirely contained within inspectable space Cables that connect to audio/visual systems that also display NSI must meet electrical isolation requirements.

Power Considerations Requirement for RED power (power filter) determined by a CTTA. RF transmitters shall not be powered from same circuit as RED equipment. RED power distribution must be designed such that neither BLACK equipment nor utility equipment is connected to it. Need is dependent On size Inspectable Space. Location and size of transformer. Presence of foreign nationals Specific Threat Typical Power Filter application Inside large Military Base in CONUS- None Commercial Tenant Space- Filter Overseas Base share with allies- Filter

Fortuitous Conductors CTTA may require isolation of fortuitous conductors. All pipes, conduits, ducts, and other metallic distribution systems that leave the inspectable space Ground within inspectable space. Or Non-conductive sections to be inserted Electrical isolation Acoustic isolation Unused cables that leave the inspectable space are to be removed or shortened to be contained within the inspectable space.

RED Systems - Cable Identification Must have prominently displayed distinguishing label, marking, or color that indicates the classification level and/or compartmentalization of the data. Identification to be located at both ends and at sufficient intervals as determined by the CTTA OR the entire cable may be the distinguishing color. Table 1(U//FOUO) defines colors. Coordinate Colors with user. Identifying actual classifications may be not be allowed.

Practical Applications Slide Requirement Red-Black separation only Required if Black exits IS Dielectric Breaks may be required by CTTA but no specific criteria is provided Alarmed Exterior PDS Typical Practice Red Black always separate. Many CTTAs will require, though the effectiveness is questionable if shielded walls are not applied as well. Alarms rarely employed due to nuisance alarm.

Conclusion Any questions? Pedro De Jesus, PE, RCDD/DCDC Senior Technical Consultant Advanced Facilities- ISR, C4, C5 Operations CH2M HILL Military and Government Facilities 2411 Dulles Corner Park, Suite 500 Herndon, VA 20171 pedro.dejesus@ch2m.com Office: 703-376-5324