top of page

Role Confusion Is the Fastest Way to Delay a SCIF Project

Every SCIF project I have been on has stalled at least once because someone was routing a decision to the wrong person. The problem is not usually skill or effort. It is role confusion. The people on the project are capable. They just do not know who owns what.

SCIF project role diagram showing AO, CTTA, SSM, Design Lead, GC Superintendent, and Owner Rep with a role responsibilities matrix
Who owns which question

ICD 705 names three roles specifically. The Accrediting Official (AO), the Certified TEMPEST Technical Authority (CTTA), and the Site Security Manager (SSM). Knowing what each one actually does is the difference between a project that moves and a project that circles.


The AO is the person or office that accepts the residual risk of the SCIF once it is built. Every consequential decision that affects the protection of the space eventually needs the AO's concurrence or approval. The AO is not a rubber stamp. The AO reads the risk picture, weighs the mitigations, and signs off on the accreditation. If the risk documentation is thin or the mitigations are not defensible, the AO says no. The AO is also the person who authorizes the Construction Security Plan before construction begins and re-approves it when consequential changes occur.


The CTTA handles the TEMPEST side of the project. TEMPEST covers the electromagnetic and acoustic emanations that could compromise classified information if not controlled. On projects that require TEMPEST treatment, the CTTA sets the countermeasures, reviews the shielding and filtering plans, and validates that the emissions envelope is acceptable. Not every project needs a CTTA. When one is needed, they are engaged early and their decisions drive real cost. Skipping the CTTA conversation until late in design is one of the more expensive mistakes in secure construction.


The SSM runs the security operation on the ground during construction and, in many programs, into operations. The SSM writes and maintains the CSP. The SSM reports violations within 72 hours. The SSM coordinates with the AO on every measure that affects the protection of the space. For most first-time SSMs, the CSP is the most demanding document they will produce. Many lean on ICD 705 consultants or experienced general contractors for the first draft. The work product still belongs to the SSM.


Around those three, the rest of the project team has to work in a specific way. The design team produces drawings and specifications that meet the standard but do not exceed it in ways the risk picture cannot justify. The contractor builds to those drawings and follows the construction security controls the CSP requires. The owner represents the mission and makes the budget calls. The operations team, who will eventually use the space, informs the layout, the workflow, and the compartmentation strategy.


The handoffs between these groups are where projects go wrong. A few patterns show up repeatedly.


The design team writes a specification without checking whether the AO would accept it. Six months later, at the AO review, the specification is rejected and the drawings get redone. The delay is not the AO being difficult. It is the team never having the conversation early.


The contractor gets a set of drawings and starts ordering long-lead items before the CSP is approved. When the CSP eventually gets approved with changes, the ordered items no longer match the plan. Rework follows.


The SSM is new to the role and reports to a program manager instead of directly to the AO on security matters. Guidance from the program manager conflicts with what the AO would sign off on. The SSM does not know which authority to follow. The project waits.


The operations team gets involved at 60 percent design and asks for changes that would have been trivial at 15 percent design. The changes are made, but the cost and schedule impact is real, and the project loses a month.


The pattern behind all of these is the same. The right stakeholder is not in the room at the right time. The remedy is not more meetings. It is knowing who owns which question and involving them at the point where the question is cheapest to answer.


Two practical takeaways.


First, when a new decision comes up on a SCIF project, ask which of the three named roles has authority over it. If it is a risk-acceptance question, that is the AO. If it is a TEMPEST question, that is the CTTA. If it is a security execution question during construction, that is the SSM. Route it there first. Do not process it through anyone else's opinion.


Second, treat the early stages of the project as the cheapest time to bring the right people into the conversation. The AO who reviews the concept plan is faster and easier to work with than the AO who reviews the 90 percent design after the first three iterations. The CTTA who scopes the TEMPEST envelope at 15 percent design saves months compared to the CTTA who inherits a completed design and has to walk it back.


Role confusion is the fastest way to delay a SCIF project. Clarity on who owns what is the fastest way to ship one.


This material is taught at greater depth in Module 3 of the ICD 705 Foundations Series. The full Series is available at psc-consultant.com/on-demand-education.

 
 
 

Comments


bottom of page