What is a Protected Distribution System?

Introduction

The goal of this lesson is to explain the physical efforts used to protect our nation’s most sensitive secrets. Upon completion, you should be able to describe:

  • Purpose of a PDS
  • Components of a PDS
  • Categories and types of PDS
  • Criteria determining PDS selection
  • Types of PDS inspections
Listen to this lesson: What is a PDS? (3:44)

What is a PDS?

Think about this scenario. You are in charge of protecting top secret or highly classified information – what the US government calls NSI or National Security Information. Now imagine you have NSI that needs to get from a secure telecommunication room on one side of a facility over to a classified work station on the opposite side. But there’s the catch – the data isn’t encrypted. And it has to travel through unsecured hallways or rooms with personnel that are not cleared to access this information.

How do you physically protect sensitive data between the origin and destination points without digital encryption?

The answer is a Protected Distribution System.

A Protected Distribution System (PDS) is a highly specialized, regularly inspected system that uses conduit to physically protect the wire line or optical fiber inside that transmits unencrypted NSI data.

In other words, a PDS acts like an armored convoy to protect sensitive information over a network.

PDS: Protective Distribution System. An armored convoy for data.

Design Philosophy: Detection Over Prevention

Security officials understood that for a PDS to be successfully implemented nationwide, it would need to be standardized. In 1996, the Committee on National Security Systems issued a policy document known as NSTISSI 7003 to set forth these standards.

Government planners also realized that a system built to prevent every conceivable type of attack across all government and military facilities would be cost prohibitive. Instead of attempting the impossible task of making a pathway completely impenetrable, a key pillar of PDS design philosophy emphasizes detection over prevention.

A Protected Distribution System is designed to:

  • significantly deter anyone from unauthorized physical access.
  • make any attempt to tamper the carrier—reliably discovered by an inspection.

Finally, the document also emphasizes that PDS are best suited for low and medium threat locations and is NOT recommended for use in high or critical threat locations. This is due to the high risk of unencrypted data being accessed before an inspection could conceivably detect a breach.

In 2010, the instruction was rebranded as CNSSI 7003 to bridge the gap between legacy physical security practices and modern cybersecurity requirements. Last updated in 2015, CNSSI 7003 continues to be the definitive source of truth for PDS design, installation, maintenance, and inspection procedures.

Evolution of PDS Standards. A lineage of CNSSI 7003.
Review your PDS with an RCDD expert.

Why not use Encryption?

At this point you may be wondering why an organization would even bother constructing what is essentially a fortress around network infrastructure. Why not just use encryption? There are four reasons for this:

  1. Expense: Encryption can have a greater total cost of ownership than a PDS. These devices are expensive to scale for the number needed across a campus.
  2. Supply Issues: Because encryption is earmarked for the highest security information, device availability is constrained to critical locations.
  3. Bandwidth Limitations: encryption limits network traffic which can impact critical missions with high data throughput (examples: real-time video streams, surveillance imagery, voice traffic or telemetry).
  4. By Design: Remember that a PDS provides adequate protection based on the perceived threat levels.
Common barriers for using encryption versus a protected distribution system.

Components of a PDS

It may be easy to simplify PDS as just a pipe, but It is important to remember that it is a system comprised of multiple components and procedures:

  1. Connections: elbows, couplers, and other fittings that connect the conduit sections of the pathway.
  2. Enclosures: secure boxes or panels that can be accessed frequently such as pull boxes, junction boxes and user drop boxes used for cable installation, branching or the termination endpoint such as a user workstation.
  3. Locks: used to secure any enclosure.
  4. Tamper Seals: used in conjunction with locks to provide evidence of unauthorized entry.
  5. Sealing: connections or covers that are not accessed frequently must be secured with welds, epoxy or fusion.
  6. Markings: the carrier must be clearly marked to aid inspection.
  7. Inspection Ports: allows inspectors to observe the entire surface of the conduit as it passes an object like a wall.
  8. Data Cabling: the actual communication medium being protected such as copper wiring or fiber optic cabling.
  9. Standard Operating Procedures: instructions governing maintenance, operation, inspection and procedures in the event of a breach.

Now that we understand the purpose of a PDS and its components, let’s dive into the different varieties of PDS, which are based on a combination of security risk assessments and the route of the PDS pathway.

Anatomy of a Protected Distribution System.

Categories of PDS Security: Simple vs. Significant

There are two categories of PDS protection based on threat level and risk analysis.

Category 1 is called a simple carrier because it’s meant to be used inside highly secure, highly controlled access areas with a lower risk of a data breach. Since the area itself is well protected, the PDS carrier offers simple protection with lighter/thinner metal or even PVC pipe, which reduces costs and complexity.

Category 2 is for riskier limited access areas. There are five specific types of Category 2 PDS which provide significant physical levels of security protection:

  1. Hardened Carrier is thick metal tubing run between secure rooms.
  2. Buried Carrier is placed deep underground to safely route data between two different buildings.
  3. Suspended Carrier is elevated high in the air for short physical runs.
  4. Alarmed Carrier uses highly advanced electronic monitoring to detect tiny movements or tampering, which is perfect for when humans can’t easily check the pipes every single day.
  5. Continuously Viewed Carrier where the pipes literally have human eyes or dedicated cameras staring at them 24-7 each one of these is specifically engineered to neutralize a unique physical threat.
Comparison of PDS Categories: Simple vs Hardened Carriers
Five carrier types of category 2 PDS

Understanding Access Areas: UAA, LAA and CAA

Before we can even think about laying down a protected pathway, we have to understand the spatial blueprint of a facility. Because the environment entirely dictates the security required. We can define a facility into three specific zones:

  • Uncontrolled Access Area (UAA) – The area external or internal to a facility over which no personnel access controls are or can be exercised or any area not meeting the definition of Controlled Access Area (CAA) or LAA.
  • Limited Access Area (LAA) – The space surrounding a PDS within which PDS exploitation is not considered likely or where legal authority to identify and remove a potential exploitation exists.
  • Controlled Access Area (CAA) – The complete building or facility area under direct physical control within which unauthorized persons are denied unrestricted access and are either escorted by authorized persons or are under continuous physical or electronic surveillance.

Regarding access areas, CNSSI 7003 makes certain requirements very clear:

  • A PDS must originate and terminate in a CAA.
  • The security levels at the start and end must match the classification of data being carried by the PDS.
  • For a Category 2 PDS, if a carrier between two CAAs passes through a UAA, then the data must be encrypted.
Facility access areas for PDS: uncontrolled access area, limited access area and controlled access area.

Selecting an appropriate PDS

The guidance for selecting a Category 1 or Category 2 PDS is based on three factors:

  1. Classification (Confidential, Secret, Top Secret, and Sensitive Compartmented Information) of the data being transmitted.
  2. The threat level where the PDS is installed (Low or Medium).
  3. Type of access area that the PDS routes through (CAA, LAA or UAA).

Selecting the actual carrier type is based upon the physical conditions of the area the PDS traverses, the location of the PDS terminations, and the cost of implementation. The cost of implementing the PDS includes not only the cost of the initial installation, but also the recurring costs of inspection and maintenance.

We should also note that any PDS design must be approved by an Authorizing Official (AO).

PDS selection matrix by threat level

Maintaining PDS Integrity with Inspections

A protected distribution system is only as secure as the highly trained eyes watching it. CNSSI 7003 policy mandates that inspectors actively assess the system for signs of penetration on a routine basis. A scratch on the paint, a slightly loose screw on a pull box, or a tamper seal that looks out of place. Security teams rely on a two inspection approaches:

Visual Inspections. Depending on the data classification, someone might literally have to physically walk the entire length of the pipeline every single day, even using mirrors to look at the back side of the pipes just to spot any physical changes. The frequency of inspections is based on the data classification level.

Technical Inspections. These are random verifications specifically designed to catch highly sophisticated tampering that a simple visual walk around might miss entirely. Certain electrical measurements taken after installation are used to compare new readings to detect tampering, even if the conduit looks untouched on the outside.

PDS Inspection approaches

Conclusion

By now you should have a general understanding of the purpose and scope of Protected Distribution Systems as well as the different types available for protecting unencrypted NSI data. This lesson was meant to be a broad overview of the topic so we encourage you to explore the rest of the series to dive deeper into installation requirements and more detailed studies on the most common carrier types.

Test your knowledge with a quiz.