NSA gatekept government contracts by dictating which systems were trusted

By Miriam Adler ·

Vendors had to submit to rigid agency standards to win deals, while the agency monitoring global communications wrote the rules for the hardware used.

Orange, tan, bright blue, aqua, burgundy, lavender. At first glance, the list appears to be a primary school syllabus or a guide to interior design. In reality, the FAS Intelligence Resource Program’s catalogue entry for the NSA/NCSC Rainbow Series describes a rigid set of manuals designed to dictate what the United States government considers a "Trusted Computer System."

For an agency specializing in signals intelligence (SIGINT) and clandestine collection, the concept of trust is rarely about faith. It is about control, verification, and the elimination of the unexpected. The Rainbow Series was the blueprint for this control, providing the standards by which the National Security Agency (NSA) evaluated the integrity of the machines processing the state's most sensitive data.

"Trusted Computer Systems"

According to the catalogue, the primary volume is the Orange Book, upon which all other manuals expound. The series as a whole sought to standardize the evaluation of systems, creating a taxonomy of security that stripped away ambiguity. This wasn't merely a technical exercise; it was an exercise in power. When a government agency defines what is "trusted," it is simultaneously defining what is suspicious, what is aberrant, and what must be purged.

Detailed guidelines cover everything from the "Bright Blue Book" (Trusted Product Evaluation - A Guide for Vendors) to the "Lavender Book" (A Guide to Understanding Trusted Distribution in Trusted Systems). The dates on these documents—mostly clustered between 1987 and 1988—mark a period when the digital landscape was shifting from isolated mainframes to networked environments. The NSA was not merely observing this shift; it was attempting to codify it.

By issuing guides like the "Orange Book" on Discretionary Access Control (September 30, 1987) and the "Red Book" on Trusted Network Interpretation (July 31, 1987), the agency established a gatekeeping mechanism. To be "trusted" was to be compliant. For the vendors listed in the Bright Blue Book, compliance was the only path to government contracts. This created a closed loop where the agency that monitors global communications also wrote the rulebook for the hardware used to do the monitoring.

October 1992

As the series evolved, the focus shifted toward the remnants of data and the invisibility of threats. The catalogue lists a "CSL Bulletin" from October 1992 regarding the "Disposition of Sensitive Automated Information." This reflects a growing anxiety over the persistence of digital footprints—the idea that information, once written, is never truly gone unless forced.

This anxiety is further evidenced by the "Forrest Green Book" (NCSC-TG-025), a guide to understanding "Data Remanence in Automated Information Systems," updated in September 1991. The agency was obsessed with the ghosts in the machine: the fragments of data that remain on a disk after a file has been deleted. To the NSA, data remanence is a vulnerability; to anyone seeking accountability from the state, it is a potential lifeline.

Beyond the colorful manuals, the FAS mirror lists other specialized publications that reveal the agency's broader reach. There are "TEMPEST Fundamentals" (NACSIM 5000) and "TEMPEST Guidelines for Equipment/System Design Standard" (NACSEM 5201). In the public record, TEMPEST refers to the study of compromising emanations—the way electronic equipment leaks signals that can be intercepted from a distance. The Rainbow Series wasn't just about the software inside the box; it was about the physical reality of the box itself and the radiation it emitted into the air.

Data Remanence

The list of publications descends into the granular and the violent. We see a "National Security Agency/CSS Degausser Products List" dated September 25, 2001, and specific "Degaussing Level Performance Test Procedures." Degaussing is the process of using a powerful magnetic field to erase data permanently, effectively murdering the information on a drive.

There is a stark contrast between the "Light Pink Book" (November 1993), which discusses "Covert Channel Analysis," and the manuals on "Trusted Facility Management" (the Brown Book). One deals with the invisible pathways used to leak information; the other deals with the physical walls and guards used to keep people out. Together, they describe a world where the human element is a liability to be managed, and the machine is a tool to be perfected.

Even the treatment of threats was formalized. The catalogue notes a technical report—NCSC C-Technical Report-001—titled "Computer Viruses: Prevention, Detection, and Treatment." Here, the language of medicine is applied to the machine. The NSA positioned itself as the physician for the state's digital health, diagnosing infections and prescribing the cure.

While the FAS record lists these manuals as a historical archive, a note from 2003 observes that portions of the Rainbow Series, specifically the Orange and Red books, have been superseded by the Common Criteria Evaluation and Validation Scheme (CCEVS). The colors have faded, but the logic remains. The question the record leaves unanswered is how many "trusted" systems we currently rely on that were built upon these early, clandestine foundations, and who is now defining the terms of that trust.