Best practice for planning a sweep
- The absolute minimum number of people should be aware of this process. This must be adhered to
- No details whatsoever are discussed on any known phones
- No details are discussed in any potentially compromised areas (this may not just be the place of work, but known vehicles and private residences).
- No detailed communication on email
- The client and service provider need to meet at a neutral venue to discuss the service required
- All details to be discussed face-to-face in a neutral venue
- The client needs to disclose relevant concerns and issues for the sweep to be most effective. This is a two-way trust based relationship and is key to all successful TSCM services
- An assessment of the area(s) to be swept is made. This would normally be carried out ‘out of hours’ so as not to draw any attention to the work. Should any explanation be needed either ‘telecoms’ or ‘IT’ consultants may be appropriate cover stories
- An appropriate level of work is agreed on (subject to threat assessment and survey) and a date is set (this date must NOT be published or made public in any way)
See:
Technical Surveillance Counter Measures (TSCM) Services - aka Bug Sweeping / Debugging
