USAREUR Pamphlet 380-40
Security
Communications Security (COMSEC) Custodian Guide
3 March 1997
For the Commander in Chief:
ROBERT S. COFFEY
Major General, GS
Chief of Staff
Official:
Seal
ROBERT L. NABORS
Brigadier General, GS
Deputy Chief of Staff,
Information Management
Summary. This pamphlet is a guide for communications security account personnel in USAREUR. This pamphlet will be used with AR 380-40, USAREUR Regulation 380-40, and Technical Bulletin 380-41.
Applicability. This pamphlet applies to organizations and activities in USAREUR. This pamphlet also applies to units supported by USAREUR.
Forms. Only -R forms may be reproduced locally on 8½ - by 11-inch paper through the servicing forms management office. Other forms will not be reproduced; they will be ordered by the unit or organization publications officer from the United States Army Printing and Publications Center, Europe, or as stated in the prescribing directive.
Suggested Improvements. The proponent of this pamphlet is the Office of the Deputy Chief of Staff, Intelligence, HQ USAREUR/7A (AEAGB-CI-S, 370-7214). Users may send suggestions to improve this pamphlet on DA Form 2028 (Recommended Changes to Publications and Blank Forms) to the Commander in Chief, USAREUR, ATTN: AEAGB-CI-S, Unit 29351, APO AE 09014.
Distribution. Distribute according to DA Form 12-88-E, block 0800, command level A.
CONTENTS
SECTION I
INTRODUCTION
SECTION II
PHYSICAL PROTECTION AND ACCOUNTABILITY OF COMSEC MATERIAL
SECTION III
PROTECTING COMSEC MATERIAL IN EMERGENCIES
SECTION IV
COMSEC FACILITIES
SECTION V
KEY MANAGEMENT
SECTION VI
INSPECTIONS, REVIEWS, AND INVENTORIES
SECTION VII
SURVEILLANCE
SECTION VIII
CONTROLLED CRYPTOGRAPHIC ITEMS
SECTION IX
DEPARTMENT OF THE ARMY CRYPTOGRAPHIC ACCESS PROGRAM
Appendixes
A. References
B. ACCLAIMS Instructions
C. Emergency Plan
D. Hand-Receipt Holder, User, and Witness Responsibilities
E. Sample Key Management Standing Operating Procedure
F. Command Inspections
G. Standardized COMSEC Custodian Course
H. Mail and Message Addresses
I. Sample COMSEC Incident or CCI Incident Report
Glossary
SECTION I
INTRODUCTION
1. PURPOSE
This pamphlet--
a. Establishes a guide for USAREUR communications security (COMSEC) account custodians. Commanders and COMSEC custodians will ensure this pamphlet is available at the user level. This pamphlet will be used with AR 380-19, Information Systems Security; AR 380-40, Policy for Safeguarding and Controlling Communications Security (COMSEC) Material; DA Pamphlet 25-16, Security Procedures for the Secure Telephone Unit, Third Generation (STU-III); DA Pamphlet 25-380-2, Security Procedures for Controlled Cryptographic Items; Technical Bulletin (TB) 380-41, Procedures for Safeguarding, Accounting, and Supply Control of COMSEC Material; and USAREUR Regulation 380-40, Safeguarding and Controlling Communications Security Material.
b. Shows the interface between Army and theater components.
c. Standardizes COMSEC procedures throughout the command.
d. Is a training aid for new COMSEC custodians.
e. Applies to--
2. REFERENCES
Appendix A lists references.
3. ABBREVIATIONS AND TERMS
AR 380-19, AR 380-40, USAREUR Regulation 380-40, and publications listed in this pamphlet, appendix A, explain terms used in this pamphlet. The glossary defines abbreviations used in this pamphlet.
4. RESOLVING CONFLICTS
a. In cases of conflict between this pamphlet and applicable regulations, the procedure that provides a higher degree of security or control will be used until the conflict is resolved.
b. Commanders will send requests to resolve conflicts through command channels to the Commander in Chief, USAREUR, ATTN: AEAGB-CI-S, Unit 29351, APO AE 09014.
SECTION II
PHYSICAL PROTECTION AND ACCOUNTABILITY OF COMSEC MATERIAL
5. CONTROL OF CLASSIFIED COMSEC MATERIAL
Classified COMSEC material, when not stored according to AR 380-5, AR 380-40, USAREUR Regulation 380-40, and TB 380-41, will be in the physical possession of a properly cleared personnel.
6. ACCOUNTING LEGEND CODE (ALC) 3 MATERIAL
The Army is eliminating accounting legend code (ALC) 3 material from its inventory. The Army plans a time-phased transition from ALC 3 to ALC 1 or ALC 4. Army COMSEC accounts will not adhere to another service or joint-serve controlling authority (CONAUTH) instructions for the conversion of ALC 3 key unless specifically instructed by the United States Army Communications-Electronic Command, Communications Security Logistics Activity (USACCSLA).
NOTE: Short titles managed by non-Army controlling authorities are not affected by these instructions. The following procedure explains message, HQ USACCSLA, SELCL-KP-KEY, 171458Z April 1996, subject: Accounting Legend Code (ALC) 3 Material.
a. ALC 3 keying material on hand in an account (material not already issued to a user) will remain ALC 3 until destroyed. The ALC block on the item register (IR) card does not change. New material may or may not have the same short title as ALC 3 material already on hand in the account. Custodians must check the SF 153 (COMSEC Material Report) transfer reports to ensure new material is brought under control. New material must have a new IR card if the ALC is changed from ALC 3 to ALC 1 or ALC 4, regardless of the short title. New material may be added to a current IR card only if the short title and ALC are exactly the same as the material already on the card.
b. Custodians of automated accounts will process new material using the short titles listed on the SF 153. Like the manual accounts, ALC 3 will be part of the short title until destroyed. Custodians will add new ALC 1 or ALC 4 material into the Army COMSEC Commodity Logistics Accounting and Information Management System (ACCLAIMS) database (app B). The history file will automatically record the correct ALC. The ALC of material on hand in the account and already entered in the ACCLAIMS database must not be changed.
c. When the term "discontinued" appears next to a short title in paragraphs 13 and 14 of the message (NOTE above), the short title has been discontinued. The short title may have been replaced or no longer needed. The term "pending" next to a short title means that the National Security Agency (NSA) has not finished the edition.
d. Custodians will not destroy the older ALC 3 material to exhaust existing supplies.
e. Short titles and editions listed in paragraphs 13 and 14 of the message (NOTE above) will change to ALC 1 or ALC 4 with new short titles.
f. When the NSA sends keying material with the new ALC, it automatically will be added to the Army COMSEC Central Office of Record (ACCOR) database with the correct ALC. A special possession report or a conversion report is not needed. Non-Army CONAUTHs may require a special possession report for non-Army controlled ALC 3 material. The COMSEC Logistics Assistance Office (375-7424) can help with this procedure.
g. ALC 3 already issued to a user in a given account should not be recalled. ALC 3 is permanently issued and cannot be recalled.
7. CONTROL OF TOP SECRET KEYING MATERIAL
a. Top Secret keying material will be safeguarded and controlled according to AR 380-40, USAREUR Regulation 380-40, and this pamphlet.
b. SF 702 (Security Container Check Sheet) will be attached to each container. Print the words "RED" and BLUE" at the top of the form if container is used to store two-person integrity (TPI) material, to indicate which side of the form each team initials for its particular control function (fig 2-1).
8. TRANSPORTING COMSEC MATERIAL
a. Ground Transporting. Only U.S. Government-owned or -leased and host-nation military-support ground vehicles will be used by U.S. unit couriers to transport COMSEC material. Commanders may give written approval to use privately-owned vehicles (POVs) for emergency situations when Government transportation is not available. The courier must carry the approval.
b. Air Transporting. Only U.S. Government-owned or -leased and host-nation military aircraft may be used by U.S. unit couriers to transport classified COMSEC material.
c. Transporting Exceptions. Exceptions to use commercial aircraft (U.S. Flag and non-U.S. Flag aircraft) to transport COMSEC material will be requested according to USAREUR Regulation 380-40, paragraph 7, and this pamphlet, figure 2-2.
d. Courier Authorization Card. Commanders will use DD Form 2501 (Courier Authorization Card) to appoint official unit couriers to transport classified COMSEC material outside U.S. military garrisons and field-operating sites within the same country according to AR 380-5 and USAREUR Supplement 1. (DD Form 2501 is an account-able form, valid for 1 year from date of issue (fig 2-3).)
e. Accountability Register. COMSEC custodians will sign for a block of DD 2501 forms from their security manager on AE Form 380-40A-R (Accountability Register for DD Form 2501 (Courier Authorization)). Custodians will assign the DD Form 2501 to COMSEC couriers as needed. COMSEC couriers will sign for the DD Form 2501 from their COMSEC custodian on AE Form 380-40A-R.
9. COMSEC MATERIAL TURN-IN PROCEDURES
a. COMSEC custodians turn in COMSEC material and equipment as follows:
(1) "Zeroize" equipment (including secure telephone unit-third generation (STU-III) equipment) and, if possible, place switches in the Z-ALL position.
___________________________________________________________________________
DEPARTMENT OF THE ARMY
444th MILITARY INTELLIGENCE BATTALION
UNIT 12345
APO AE 09000
AEAXX-XX 1 November 1996
MEMORANDUM FOR Deputy Chief of Staff, Intelligence, USAREUR, ATTN:
AEAGB-CI-S, Unit 29351, PO AE 09014
SUBJECT: Request for Exception to Policy to Transport Classified COMSEC
Material Aboard Non-U.S. Flag Aircraft.
1. References:
a. AR 380-40, Policy for Safeguarding and Controlling Communications
Security (COMSEC) Material.
b. USAREUR Regulation 380-40, Safeguarding and Controlling
Communications Security Material.
2. According to the above references, request approval to courier Secret
collateral keying material (USKAT-11111) aboard a non-U.S. flag aircraft
to Zagreb, Croatia, to support Operation Joint Endeavor.
3. AR 380-40 allows USAREUR commanders to approve transporting COMSEC
material on non-U.S. flag aircraft in an operational necessity. The AR
restricts this approval to the lowest general-officer level.
4. The keying material is essential for mission-accomplishment. The
material must be in the sight of the courier at all times.
NOTE: List information required in USAREUR Regulation 380-40, paragraph
7, here.
5. Point of contact is CW4 Robert Jones, 444-1111/2222.
FOR THE COMMANDER:
JOHN H. WILLIAMS
Lieutenant Colonel, MI
Plans and Operations Officer
___________________________________________________________________________
Figure 2-2. Sample Request to Courier Classified COMSEC Material Aboard Non-U.S. Flag Aircraft
(2) Remove batteries when storing equipment, except STU-IIIs, longer than 2 days. STU-IIIs are issued with a manufacturer-installed battery. These batteries are used for maintaining keying material, setup options, and memory-dialing sequences during loss of power. The average battery-life is 7 years. These batteries should be removed only for replacement. STU-III batteries will be retained with the equipment during shipment and storage. Batteries should not be removed in the STU-III for shipping or when returning unserviceable STU-IIIs.
(3) "Power-up" the equipment, if possible, before it is turned in to ensure all key is zeroized.
(4) Ship equipment that cannot be zeroized or identified as being zeroized by defense courier service (DCS).
(5) Ship unkeyed and unclassified controlled cryptographic item (CCI) equipment by registered mail.
(6) Perform a technical inspection (TI) on all equipment.
(7) Ensure that KT-83s, HGX-83s, and KGX-93s are certified and that security seals are intact.
b. Custodians may only open equipment they are authorized to repair (listed on a custodian's DD Form 1435 (COMSEC Maintenance Training and Experience Record)).
c. Security-related turn-in procedures are as follows:
(1) Ensure equipment is stored according to the highest classification of the equipment or of the key stored in the equipment.
(2) Direct questions about equipment security or shipping procedures to the local security manager, COMSEC custodian, COMSEC Logistics Assistance Representative (LAR), or the United States Army Theater COMSEC Management Office-Europe (USATCMO-E) at 382-5828. Direct questions about maintenance or equipment modifications to the Theater COMSEC Logistic Support Center-Europe (TCLSC-E) at 382-5816.
SECTION III
PROTECTING COMSEC MATERIAL IN EMERGENCIES
10. PRIORITY FOR EMERGENCY-DESTRUCTION OF MATERIAL
TB 380-41 lists priorities for destroying classified and unclassified sensitive material (precautionary or total destruction) in emergencies.
11. COORDINATION AND APPROVAL
The COMSEC custodian will prepare an emergency plan according to TB 380-41, AR 190-13, USAREUR Regulation 190-13, and this pamphlet, for the installation physical-security plan (app C). Commanders will approve the plan after coordinating it with staff agencies. The plan will list organizations that must be notified during an emergency. A sample emergency plan is in this pamphlet, appendix C.
a. The basic emergency plan normally will be marked "FOR OFFICIAL USE ONLY" with exemption category-2 according to AR 25-55, unless it contains classified information.
b. Specific short titles of positive-controlled material will not be listed in the plan with their associated status (for example, effective, reserve, exercise). Short titles and status for COMSEC material that is not positive-controlled may be listed.
c. The emergency plan will include an evacuation site and an alternate site. Evacuation-route diagrams will be marked FOR OFFICIAL USE ONLY.
d. Emergency plans will provide for cryptoequipment mounted on tactical conveyances (ground and air vehicles).
e. Part of the plan will be practiced at least once every 3 months. The "dry run" will be witnessed by appropriate neutral personnel (for example, post or unit fire marshal) or a representative from at least one of the following organizations: The provost marshal office (PMO), motorpool, intelligence (S2), or operations and training (S3). All participating personnel (including witnesses) will be documented in an annex of the basic plan (app D). Current operational key will not be destroyed or moved during the dry run.
f. Emergency task cards are optional (TB 380-41, para 5.19).
g. A written record of practice results will be filed in the COMSEC account with the emergency plan.
h. In an actual emergency, keying material and classified COMSEC publications must be destroyed beyond recognition. Any method approved for routine destruction (for example, burning, chopping, pulverizing) is acceptable. Shredders that do not meet the requirements of TB 380-41 may be used only to reduce bulk; residue must be destroyed by other means (for example, burning, chopping, pulverizing).
i. In an actual emergency, equipment will be destroyed to ensure cryptologic data cannot be reconstructed. All classified components of the equipment (for example, printed circuit boards, keyed permuting devices) will be removed and destroyed. Operating instructions and maintenance manuals list items that should be destroyed beyond recognition and provide preferred methods of destruction.
j. TB 380-41 describes cryptographic-material destruction devices.
SECTION IV
COMSEC FACILITIES
12. ESTABLISHING COMSEC FACILITIES
a. When establishing a new COMSEC facility, commanders will send a COMSEC facility approval request (CFAR) with the information required by TB 380-41, chapter 2. Figure 4-1 is a sample CFAR. A CFAR will be sent through command channels to the Director, United States Army Communications-Electronics Command COMSEC Logistics Activity, ATTN: SELCL-KP-AU, Fort Huachuca, Arizona 85613-7090. A completed copy of DA Form 2012 (COMSEC Account Data) (para 4-2) must be included with the CFAR. (DA Form 2012 will be kept in the inactive file for 1 year after the outgoing COMSEC custodian leaves.)
b. Subaccount or hand-receipt holder user COMSEC facilities do not require USACCSLA approval. Subaccount and hand-receipt holder command facilities must meet physical-security standards in AR 190-13, AR 380-5, and AR 380-40. Command COMSEC facility approval may be granted by the appropriate commander (for example, a platoon leader storing COMSEC in the platoon room before deployment). Secure subscriber terminals will be approved as part of the request for accreditation by the designated accreditation authority (AR 380-19).
c. Automated information systems used to process the ACCLAIMS will be accredited for unclassified sensitive information according to AR 380-19 before loading master-asset files. The automatic data-processing information systems security officer (ISSO) or information systems security manager (ISSM) will provide assistance.
d. Command COMSEC facility approvals for automated facilities accredited under AR 380-19 will be updated every 3 years. Other approvals will remain in effect as long as the physical protective measures and security procedures in force for the approval remain unchanged.
13. MOSS HAMILTON X-07 LOCK
The Moss Hamilton X-07 Lock is the primary replacement lock for existing mechanical combination locks. This lock has three system selections.
a. Single-Lock. This selection is the same as standard combination locks. This lock is opened by dialing the correct combination.
b. Dual-Lock. This selection should be used for TPI material. To open this lock, two individuals must enter their combinations within a 40-second period. If the process takes more than 40 seconds, the lock shuts down and the display will go blank.
c. Supervisor-and-Subordinate. This selection is used when a supervisor has responsibility for the control of the safe but does not have access to the contents of the safe. To use this option, the supervisor enters the first combination at the beginning of the day or shift. After the first combination has been entered, the lock can be opened by any person with the second combination. At the end of the day or shift, the supervisor reenters the first combination and the lock cannot be opened until the supervisor enters the first combination at the beginning of next day or shift.
14. COMSEC ACCOUNT DATA FORM
Figure 4-2 is a sample DA Form 2012 completed according to TB 380-41, paragraph 2.12.4.
___________________________________________________________________________
DEPARTMENT OF THE ARMY
HEADQUARTERS, V CORPS
UNIT 29335
APO AE 09014
AETV-IM-CCMO (380-40a) 1 November 1996
MEMORANDUM THRU Commander, (Your higher headquarters, mailing address) (Any
thru lines must be initialed)
FOR Director, United States Army, Communications-Electronic Command,
Communications-Electronic Command,
Communications Security Logistics Activity, ATTN: SELCL-KP-AU, Fort
Huachuca, AZ 85613-7090
SUBJECT: COMSEC Facility Approval Request (CFAR)
1. References:
a. AR 380-5, Department of the Army Information Security Program, 25
February 1988, appendix H.
b. AR 380-40, Policy for Safeguarding and Controlling Communications
Security (COMSEC) Material, 1 September 1994, chapter 4.
c. TB 380-41, Procedures for Safeguarding, Accounting, and Supply
Control of COMSEC Material, 1 October 1994, paragraph 2.1.2.
2. This command has a requirement to establish or update (as appropriate)
a COMSEC facility.
a. General Information:
(1) Commander, V Corps
ATTN: AETV-IM-CCMO/5CE016
Unit 29335
APO AE 09014
(2) UIC: WCDWAA
(3) Telephone Numbers: Commercial: 49-6221-57-5635, DSN: 370-
5635/5634.
(4) COMSEC Account Number: 5CE016. (to be announced (TBA), if account
number not assigned)
(5) Facility Location: Room 006, Basement Floor, Building 5, Campbell
Barracks, Heidelberg, Germany. If requesting a safe as the facility state,
"General Services Administration (GSA)-approved safe in room x."
(6) Point of Contact: CW2 Rocha or SFC Morales (telephone number if
different from (3) above).
(7) Type of Request: Update or (Initial because of Establishment or
Relocation).
(8) Classification Information: Top Secret (TS) or (highest
classification of material received or held).
b. Purpose: Operations, distribution, maintenance, administrative,
storage, or other, according to TB 380-41, para 2.1.2b. Indicate primary
purpose (for example, storage, and distribution).
c. General Cryptosystems: Use short-title of "System" on hand or
authorized that the account will be supporting (for example, Vinson,
mobile subscriber equipment (MSE), secure telephone unit-third
generation (STU-III), KG-84, Global Positioning system (GPS)).
d. Physical Security: Provide physical security description of the
facility according to TB 380-41, paragraph 2.1.2d, and AR 380-5,
appendix H. Also, identify any type of alarm system (for example, the
building that will house COMSEC Account 5CE016 is of substantial brick
masonry construction. The class "A" vault-type room has three rooms and
an entry hall that meets the standards in AR 380-5, app H).
(1) Walls: The perimeter walls are 8" thick and have three air vents
and two windows. The air vents and windows are barred.
(2) Floor: The floor is solid concrete with tile covering.
(3) Ceiling: The ceiling is solid concrete.
(4) Windows: This facility has two 17 1/2" X 26 1/2" windows. Each
window has five vertical and three horizontal bars with a distance of 4
inches between them. The windows are mounted in the concrete wall.
(5) Entry and Exit: This COMSEC facility has one, single reinforced,
3 inch-thick steel door with built-in three-position, group one, dial
combination-lock, along with a steel day gate equipped with an electronic
cipher lock used as entry and exit. Between the steel door and the day
gate there is another door that has a dead bolt lock. The vault is also
secured with a standard JSIIDS alarm system connected to the military
police desk at the front gate of Campbell Barracks. The alarm is activated
during non-duty hours. In the event of an alarm, security personnel can
respond within 15 minutes.
NOTE: If request is for a TS facility, identify the provisions to
store material, according to TPI. If facility is to be a GSA-approved
safe, identify secondary barriers, include access control when container
is open.
(6) There are three rooms within the vault: a storage room between
the first door and the day gate, the middle room that houses the safes,
and the back room that is office space. There is also a hallway that
houses a telephone distribution box for the building.
e. Material and Equipment Security: (Describe protection of material
during nonworking hours, according to TB 380-41, para 2.1.2e.) All
classified and COMSEC material not under the direct continuous control
of cleared and authorized personnel is stored in GSA-approved containers
that are in the COMSEC facility.
(1) Top Secret (TS) keying material is managed and stored in a no-
lone zone. When not stored, TS material is handled according to two-person
integrity (TPI) rules (in possession of two TS-cleared persons).
(2) TS keying material is secured in a four-drawer, five-lock GSA-
modified approved container. One of the five locks is identified as the
"RED" side and another one as the "BLUE" side. The "BLUE" side has one
Sergeant and Greenleaf three-position lock. The "RED" side has four
Sergeant and Greenleaf padlocks located at each drawer (Federal
Specifications FF-P-110 8077A).
f. Standards Statement: Applicable standards can (or can not) be met
for the storage and destruction of COMSEC material as required by TB 380-
41, paragraph 2.1.2f.
FOR THE COMMANDER:
GENE TYLER
Lieutenant Colonel, GS
Deputy Chief of Staff, Information Management
(CFAR must be signed by the commander or an authorized representative.)
AR 25-55, para 3-200, exemption 3a, prescribes protective markings.
(At a minimum, memorandum will be marked:)
FOR OFFICIAL USE ONLY
___________________________________________________________________________
Figure 4-1. Sample COMSEC Facility Approval Request
15. IDENTIFYING COMSEC FACILITIES
A bilingual RESTRICTED AREA sign will be posted as prescribed in TB 380-41, chapter 5. AR 190-13, paragraph 6-4, and USAREUR Regulation 190-13, appendix E, prescribe formats for USAREUR RESTRICTED AREA warning signs. External signs will not identify COMSEC facilities.
16. USE OF CAMERAS, REPRODUCTION, AND ELECTRONIC EQUIPMENT IN COMSEC FACILITIES
Use of cameras and electronic equipment in COMSEC facilities is controlled by--
a. TB 380-41. The TB gives restrictions on personal and Government-owned electronic equipment (for example, cameras, microwave ovens, radios, stereos, televisions, portable cassette players, videocassette recorders). These restrictions do not apply to secure subscriber terminal (SST) areas or COMSEC facilities used only for administration or storage.
b. The COMSEC facility standing operating procedure (SOP). The SOP will include instructions on controlling and detecting unauthorized reproduction on Government-owned copying or reproduction equipment operated in the facility.
17. RELEASING COMSEC MATERIAL TO CONTRACTORS
The COMSEC supplement to the National Industrial Security Program Operating Manual (NISPOM) gives guidance for releasing COMSEC material to Government contractors. The statement "COMSEC material access by contractor personnel restricted to U.S. citizens holding final Government clearance" will be on the front cover of the COMSEC document. This statement must also be on the SF 153 after "NOTHING FOLLOWS".
18. CLOSING COMSEC ACCOUNTS
To close a COMSEC account, follow the guidance in TB 380-41, paragraph 2.14.
a. The closure notification message will include the information required in TB 380-41 and the following:
(1) Intended closure date.
(2) Reason for closure and, when appropriate, the address of the new COMSEC support account.
(3) Number of COMSEC incident cases pending closure.
(4) Date the DCS was notified to cease delivery.
(5) Confirmation that controlling authorities have been notified.
(6) Date the account is expected to reach zero balance.
(7) Disposition of records.
(8) Disposition of the account's ACCLAIMS harddrive and software disks.
(9) Request for relief of accountability of the COMSEC custodian by name, rank, and social security number.
b. The COMSEC custodian will send the COMSEC account closure message for the commander to the addresses shown in figure 4-3.
19. COMSEC SUPPORT MEMORANDUM OF AGREEMENT
a. A COMSEC support memorandum of agreement (MOA) establishes an agreement between a unit commander (supported activity) who wants COMSEC support but does not have the personnel or financial resources and a unit commander who has an account and will provide COMSEC support (supporting activity).
b. All parties must understand their responsibilities before signing the MOA. Figure 4-4 is a sample MOA.