No compromising radiation (HF) measures are required (except for the 'Declaration of Conformity') when processing 'Reserved' classified information. It is only recommended to place the monitor in such a way that optical reading of the contents of the monitor screen is not possible.

In the case of the processing of classified information classified as "Confidential", account shall be taken of the nature of the organisation operating the IS and the nature of the information processed, the extent of the processing of classified information classified as "Confidential", its timing and the manner in which it is processed. The risk from the point of view of KV is mainly related to displaying classified information on a monitor, inserting it using a keyboard, printing and storing it on backup media. In terms of timing, a higher risk is associated with the regular processing of classified information or with processing, the initiation of which may be inferred by the interested party from certain symptoms. If classified information related to crisis planning, intelligence activities, activities and security of embassies and other important objects, cryptographic protection of classified information, operational technology, military and nuclear material and other critical areas is processed, stricter requirements must be applied regardless of their amount.

For information classified as "Confidential", the employee of the TEMPEST NÚKIB department will assess whether zoning will be carried out from the supplied documentation or directly on site.

Where processing of classified information classified as 'Secret' or 'Top Secret' is envisaged, zone measurements shall, as a general rule, always be carried out.

Where classified information classified ‘Confidential’, ‘Secret’ or ‘Top secret’ is being processed, some installations specified in security standards require power supply from a network line equipped with a high-frequency filter. For the processing of classified information classified ‘Confidential’, it is necessary to use an appropriate type with attenuation of at least 30dB in the 100 kHz – 1 GHz frequency band. Consultation with TEMPEST NÚKIB is required for the processing of classified information classified ‘Secret’ or ‘Top secret’. To use the attenuation properties of the connected filters, it is necessary to install them appropriately (appropriate separation of the conductors of the input and output parts).

If the IS contains a transmitter (radio station, radio modem, Wi-Fi, infrared transmission, etc.), it is always necessary to consult the TEMPEST NÚKIB department.

For IS components that contain RAM (e.g. printers, etc.), it is necessary to take into account that the information in these memories may remain even after the power supply voltage is disconnected. The handling regime for these components needs to be adapted to this. In the event of dispatch to the workshop or other manipulation, when the equipment will not be under the supervision of the responsible person, the contents of the memory must be demonstrably overwritten with non-classified information.

IS users should be reminded of the possibility of inserting interception devices (so-called "bugs") into IS components, e.g. keyboard, cables or the possibility of other modification of IS at a time when IS or part of it is out of control (service, loan, etc.). The modification may consist in the installation of malware that affects the operation of HW (e.g. eye-detectable modulation of LEDs, use of acoustic signals, etc.), replacement of cables or other parts of IS. Any changes to the approved HW configuration should be assessed in accordance with the instructions below.

A similar risk (e.g. installation of interception devices) exists for secure areas (SZ). If these suspicions arise, the TEMPEST NÚKIB department should be consulted.

The use of so-called "masking generators", which should "cover up" KV, is advisable to consult with the TEMPEST NÚKIB department.

It is recommended that the IS user at the design stage takes into account the appropriate location of the IS with respect to the surrounding so-called "controlled space". A well-chosen IS location within the building (thus a better zone) reduces the requirements for the class of the used device in terms of KV and significantly saves hardware costs. IS should be located as far as possible from freely accessible places (public parking, objects to which the IS operator does not have access), rather in rooms situated in the courtyard of the object, not in the street, or in basement rooms without windows. Rooms of at least one floor above and below should be in a ‘controlled area’. It should also be borne in mind that IS must be appropriately located within the room, i.e. keep certain distances from telephones, faxes, but also data, power and other metallic lines (e.g. air conditioning, heating, water, etc.), and also with regard to the windows of the room.

N.B.: "Controlled area" is a three-dimensional space, surrounding the IS, in which it is ensured that an unauthorized person will not carry out uncontrollable activities in order to obtain classified information in the form of compromising radiation. The size of the area checked shall be given in metres. In English, it is referred to as "inspectable space."

IS designated for the classification level "Confidential" newly certified and all IS for the classification level "Secret" must be subject to installation control as part of the certification or recertification. The on-site installation inspection is usually carried out by an OBIT NÚKIB employee at the time when the IS is fully ready for operation and the ZO is structurally and organizationally in its final state.

Inspection of the installation can be carried out by another workplace after prior consultation with the head of the TEMPEST NÚKIB department. The results of such an inspection will be recognised as valid provided that the applicant submits a report on the outcome of the inspection carried out by the workplace with which the NÚKIB has concluded a contract for such activity (according to the law No. 412/2005 Coll.)

On the basis of this check, the so-called Installation Record (IZ) is drawn up. This IS is then part of the IS security documentation.

Guidance on the assessment of HW changes in a certified IS– impact on the evaluation:

  • IS for classification level Confidential

    1. Changes requiring repeated measurements:

      • change of processor
      • change of motherboard
      • change of power supply
      • change of graphics card
      • Change of monitor
      • change or replacement of the data cable to the monitor
      • change the resolution of the graphics adapter, including changing the vertical frequency
    2. Changes requiring notification to the NÚKIB and assessment by the NÚKIB expert department:

      • change HDD when changing data interface
      • change of internal and external data storage devices - FDD, CD, DVD, B-Ray, ZIP when changing the type and/or data interface
      • change the smart card reader internal when changing the data interface
      • change/addition of expansion internal and external cards (audio, network, etc.)
      • change of the power vf filter when changing the type
      • Changing the keyboard while maintaining the data interface
      • change of peripherals (printer, projector, scanner, plotter, etc.) while maintaining the same type and the same interconnecting data cables
      • replacement of cables to printer, scanner, plotter, etc. while maintaining the same type and data interface
      • changing the mouse when changing the data interface, adding the mouse to the report
      • change of optical converters, switches, etc. while maintaining the same type
      • changes in the BIOS of the PC resulting in the modification of the clock frequencies of the processor, graphics card, buses or a change in their working mode (Spread spectrum)
      • Changing the PC Cabinet
    3. Unannounced changes – made by the user himself:

      • Change (increase/decrease) RAM
      • change HDD when changing the type, but maintaining the data interface
      • change internal and external FDD, CD, DVD, B-Ray, ZIP while maintaining the type and data interface
      • change the smart card reader internal while maintaining the data interface
      • change of the power vf filter while maintaining the type
      • Mouse change while maintaining the data interface
      • Replace the HDD frame while maintaining the data interface
      • replacement of power cables
      • short-term connection of an external HDD for secure erasure
      • removing the HDD frame and mounting the HDD directly to the PC on the same bus
  • IS for the classification level Secret

    1. Changes requiring repeated measurements:

      • change of processor
      • change of motherboard
      • change of power supply
      • change of graphics card
      • Change of monitor
      • change of internal and external FDD, CD, DVD, B-Ray, ZIP when changing the type and/or data interface
      • change/addition of expansion internal and external cards (audio, network, optical, etc.)
      • change HDD when changing the data interface
      • change of smart card reader
      • change of the power vf filter when changing the type
      • Changing the keyboard
      • change of peripherals (printer, projector, scanner, plotter, etc.)
      • change the resolution of the graphics adapter, including changing the vertical frequency
      • change of data cables to the monitor and/or other peripherals
      • change of optical converters, switches, etc.
      • Modification of "active" DVI-Display Port reductions, etc.
      • changing the mouse when changing the data interface, adding the mouse to the report
      • changes in the BIOS of the PC resulting in the modification of the clock frequencies of the processor, graphics card, buses or a change in their working mode (Spread spectrum)
      • Changing the PC Cabinet
    2. Changes requiring notification to the NÚKIB and assessment by the NÚKIB expert department:

      • Change FDD, CD, DVD, B-Ray, ZIP while maintaining type and data interface
      • change the HDD type while maintaining the data interface
      • Mouse change while maintaining type and data interface
      • Replacement of power cables for Class 0 (Level A) devices
      • change of the power vf filter while maintaining the type
      • removing the HDD frame and mounting the HDD directly to the PC on the same bus
    3. Unannounced changes – made by the user himself:

      • Change (increase/decrease) RAM
      • Replace the HDD frame while maintaining the data interface
      • replacement of power cables outside Class 0 (Level A) equipment
  • Other communication and information systems

    • Consultation with the NÚKIB professional office is always necessary.

N.B.: In case of other changes, consultation with the TEMPEST NÚKIB department is required.