AFI 17-101 Risk Management Framework (RMF) for AF Information Technology (IT).pdf

PDF 758 KB Posted

Attached to
Guided Missile Test Sets - Hill Air Force Base, UT Federal contract opportunity
Solicitation number
FA822724R0002
Issued by
Department of the Air Force Materiel Command Air Force Sustainment Center

About this file

This document is an Air Force Instruction (AFI) that provides implementation instructions for the Risk Management Framework (RMF) methodology for Air Force (AF) Information Technology (IT). The RMF replaces the DoD Information Assurance Certification and Accreditation Process (DIACAP) and manages the life-cycle cybersecurity risk to AF IT. The instruction establishes associated cybersecurity policy, assigns responsibilities for executing and maintaining the RMF, and provides details on the 6-step RMF process, the Approval to Connect (ATC) process, security control overlays, and the transition from DIACAP to RMF. Key roles defined include the Authorizing Official (AO), Security Control Assessor (SCA), Information System Owner (ISO), and Program Manager (PM). The instruction also covers considerations for Platform Information Technology (PIT) systems, the Air Force Information Networks (AFIN), and the handling of systems without an assigned AO.

View the file

Other files for this federal contract opportunity

Other files attached to Guided Missile Test Sets - Hill Air Force Base, UT, newest first.
File Type Posted
GMTS CDRL List Exhibits A and B.xlsx XLSX spreadsheet
Solicitation - FA822724R0002.pdf PDF
GMTS CDRL Package.pdf PDF
GMTS Section L_LPTA_Past Performance.pdf PDF
GMTS Section M__LPTA_Past Performance.pdf PDF
GFP Attachment Dated9May 2024 Pgs 3.pdf PDF
AFNWCNM-HB-63-1128T Technical Design Review.pdf PDF
MIL-HDBK-61B DoD Configuration Management Guidance.pdf PDF
MMIIISD-HB-63-1101 TBC Rev 9.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF THE AIR FORCE

WASHINGTON, DC

AFI17-101_AFGM2019-01

17 July 2019

MEMORANDUM FOR DISTRIBUTION C

MAJCOMs/FOAs/DRUs

FROM: SAF/CN

1800 Air Force Pentagon

Washington, DC 20330-1800

SUBJECT: Air Force Guidance Memorandum to AFI 17-101, Risk Management Framework

(RMF) for Air Force Information Technology (IT)

By Order of the Secretary of the Air Force, this Air Force Guidance Memorandum immediately changes Air Force Instruction (AFI) 17-101, Risk Management Framework (RMF) for Air Force

Information Technology (IT), 2 February 2017. Compliance with this Memorandum is mandatory.

To the extent its directions are inconsistent with other Air Force publications, the information herein prevails, in accordance with (IAW) AFI 33-360, Publications and Forms Management Ensure all records created as a result of processes prescribed in this publication are maintained in accordance with

Air Force Manual 33-363, Management of Records, and disposed of in accordance with the Air Force

Records Disposition Schedule located in the Air Force Records Information Management System.

AFI 17-101 is hereby updated to reflect the changes as noted in the included attachment. I hereby direct the Office of Primary Responsibility (OPR) for AFI 17-101 to conduct a special review in accordance with AFI33-360 to align its content with the attached .This will result in an Interim

Change, rewrite or rescind action of AFI 17-101.

This Memorandum becomes void after one-year has elapsed from the date of this Memorandum, or upon publication of an Interim Change or rewrite of the affected publication, whichever is earlier.

WILLIAM E. MARION II, SES, DAF

Deputy Chief Information Officer

Attachment:

Interim Guidance for AFI 17-101, Risk Management Framework (RMF) for Air Force Information

Technology (IT)

AFGM2019-01 [date]

AFI 17-101, Risk Management Framework (RMF) for Air Force Information Technology (IT)

ATTACHMENT

Interim Guidance on management of the Air Force Information Technology Categorization and

Selection Checklist

This guidance provides interim policy concerning the appropriate management of the Air Force

Information Technology Categorization and Selection Checklist (ITCSC). This guidance applies to

Chapter 3, RMF Methodology, of AFI 17-101, Risk Management Framework (RMF) for Air Force

Information Technology (IT).

(REPLACE) 3.2.2. Each AF IT, IAW AFI 17-110, must be registered in ITIPS, as the governance tool for the AF CIO, with the exception of those identified by other policy (i.e. Space, Nuclear, Command, Control, and Communication (NC3), Joint) to be registered in another repository. (T-1)

ITIPS will systematically assign a temporary registration number for all registered AF IT until the next scheduled replication with DoD Information Technology Portfolio Repository (DITPR). A

DITPR number will then be systematically assigned and included in ITIPS as the permanent official registration number for AF systems as applicable.

(REPLACE) 3.2.3 PMs or ISOs deploying systems across DoD/AF Components will register AF IT and post the IT Categorization and Selection Checklist to ITIPS as an artifact documenting PM and

AO concurrence on RMF CATEGORIZE and SELECT elements.

(ADD) NOTE: Posting of the IT Categorization and Selection Checklist in eMASS is encouraged, but not required.

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE INSTRUCTION 17-101

2 FEBRUARY 2017

Cyberspace

RISK MANAGEMENT FRAMEWORK

(RMF) FOR AIR FORCE

INFORMATION TECHNOLOGY (IT)

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available for downloading or ordering on the e-Publishing website at www.e-publishing.af.mil.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/CIO A6ZC

Supersedes: AFI33-210, 23 December 2008

Certified by: SAF/CIO A6Z

(Peter E. Kim, AF CISO)

Pages: 49

This Air Force Instruction (AFI) implements Air Force Policy Directive (AFPD) 17-1, Information Dominance Governance and Management, 12 April 2016, AFPD 33-3, Information

Management, 8 September, 2011, DoDI 8510.01, Risk Management Framework (RMF) for DoD

Information Technology (IT), 12 March 2014, and associated processes outlined on the AF RMF

Knowledge Service (KS), for managing the life-cycle cybersecurity risk to Air Force Information

Technology (IT) consistent with the Federal Information Security Modernization Act (FISMA) of 2014, DoDI 8500.01, Cybersecurity, 14 March 2014, and DoD Directive 8000.01, Management of the Department of Defense Information Enterprise, 10 February 2009. This instruction is consistent with Chairman Joint Chiefs of Staff Instruction (CJCSI) 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND). Direct questions, comments, recommended changes, or conflicts to this publication through command channels using the AF Form 847, Recommendation for Change of Publication, to SAF/CIO A6.

This publication applies to all military and civilian AF personnel, members of the AF Reserve

Command (AFRC), Air National Guard (ANG), third-party governmental employee and contractor support personnel in accordance with appropriate provisions contained in memoranda support agreements and AF contracts.

The authorities to waive requirements in this publication are identified with a Tier number (T-0, T-1, T-2, T-3) following the compliance statement. See AFI 33-360, Publications and Forms

Management, Table 1.1 for a description of the authorities associated with the Tier numbers.

Submit requests for waivers through the chain of command to the appropriate Tier waiver http://www.e-publishing.af.mil/

2 AFI17-101 2 FEBRUARY 2017

approval authority, or alternately, to the Publication office of primary responsibility (OPR) for non-tiered compliance items. Send any supplements to this publication to SAF/CIO A6 for review, coordination, and approval prior to publication. Unless otherwise noted, the SAF/CIO

A6 is the waiver authority to policies contained in this publication. Ensure all records created as a result of processes prescribed in this publication are maintained in accordance with (IAW)

AFMAN 33-363, Management of Records, and disposed of IAW Air Force Records Disposition

Schedule (RDS) located in the Air Force Records Information Management System (AFRIMS).

SUMMARY OF CHANGES

This document is substantially changed and must be reviewed in its entirety. This instruction reissues, renames, supersedes, and rescinds AFI 33-210, Air Force Certification and

Accreditation Program, to AFI 17-101, Risk Management Framework for Air Force Information

Technology. This directive establishes the Risk Management Framework (RMF) for AF IT, establishes associated cybersecurity policy, and assigns responsibilities for executing and maintaining the RMF. The RMF replaces the DoD Information Assurance Certification and

Accreditation Process (DIACAP) and manages the life-cycle cybersecurity risk to AF IT.

Chapter 1— PROGRAM OVERVIEW 5

1.1. Purpose

1.2. Applicability

Figure 1.1. Air Force IT Categories

1.3. Objectives

Chapter 2— ROLES AND RESPONSIBILITIES 7

2.1. Secretary of the Air Force, Office of Information Dominance and Chief

Information Officer (SAF/CIO A6)

2.2. Administrative Assistant to the Secretary of the Air Force (SAF/AA)

2.3. Secretary of the Air Force for Acquisition (SAF/AQ)

2.4. Deputy Chief of Staff, Intelligence, Surveillance, and Reconnaissance (AF/A2). . 8

2.5. Chief Information Security Officer (CISO), SAF/CIO A6Z

2.6. Authorizing Official (AO)

2.7. Air Force Enterprise Authorizing Official (AF Enterprise AO)

2.8. AO Designated Representative (AODR)

2.9. Security Control Assessor (SCA)

2.10. Security Controls Assessor Representative (SCAR)

AFI17-101 2 FEBRUARY 2017 3

2.11. Agent of the Security Controls Assessor (ASCA)

2.12. Information System Owners (ISO)

2.13. Program Manager (PM)

2.14. Unit Communications Squadron Commander (CS/CC)

2.15. Information System Security Manager (ISSM)

2.16. Information System Security Officer (ISSO)

2.17. Information Systems Security Engineer (ISSE)

2.18. Information Owner (IO)/Steward

2.19. MAJCOM Cybersecurity Office or Function

2.20. User Representative (UR)

2.21. Additional Responsibilities

Table 2.1. AF RMF Appointment Matrix

2.22. Cybersecurity Forums

Chapter 3— RMF METHODOLOGY 19

3.1. Overview

Figure 3.1. RMF for AF IT

3.2. RMF Step 1, CATEGORIZE System

3.3. RMF Step 2, SELECT Security Controls

3.4. RMF Step 3, IMPLEMENT Security Controls

3.5. RMF Step 4, ASSESS Security Controls

3.6. RMF Step 5, AUTHORIZE System

3.7. Denial of Authorization to Operate (DATO)

3.8. RMF Step 6, MONITOR Security Controls

3.9. Resources and Tools

Chapter 4— APPROVAL TO CONNECT (ATC) PROCESS 25

4.1. Overview

4.2. Duration and Expiration

4.3. Connection to the DoDIN

4.4. Connection to the Air Force Information Networks (AFIN)

4 AFI17-101 2 FEBRUARY 2017

4.5. Guest System Registration

4.6. ATC Process for Air Force Functional/Mission Systems

4.7. Continuous Monitoring

4.8. Denial of Approval to Connect (DATC)

Chapter 5— SECURITY CONTROL OVERLAYS 28

5.1. Overview

5.2. Policy

5.3. Development and Approval Process

5.4. Review and Coordinate Finalized Overlay

5.5. Coordinate with DISA to Implement Overlay in eMASS

Chapter 6— TRANSFER OF IT BETWEEN AUTHORIZING OFFICIALS 30

6.1. Overview

6.2. Transition Process

6.3. IT With No AO Assigned

Chapter 7— RMF TRANSITION 32

7.1. Overview

7.2. Transition Timeline

7.3. RMF Deviation Requests

Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 33

Attachment 2— AF IT ASSESS ONLY REQUIREMENTS 40

Attachment 3— FINANCIAL IMPROVEMENT AND AUDIT READINESS (FIAR) IT

CONTROLS GUIDANCE (OPR: AF/FM) 42

AFI17-101 2 FEBRUARY 2017 5

Chapter 1

PROGRAM OVERVIEW

1.1. Purpose. This AFI provides implementation instructions for the Risk Management

Framework (RMF) methodology for Air Force (AF) Information Technology (IT) according to

AFPD 17-1, Information Dominance Governance and Management, and AFI 17-130, Air Force

Cybersecurity Program Management, which is only one component of cybersecurity.

1.1.1. The RMF incorporates strategy, policy, awareness/training, assessment, continuous monitoring, authorization, implementation, and remediation.

1.1.2. The RMF aligns with SAF/CIO A6’s AF Information Dominance Flight Plan key concept of increasing cybersecurity of AF information systems; therefore, robust risk assessment and management is required.

1.1.3. The RMF process encompasses life cycle risk management to determine and manage the residual cybersecurity risk to the AF created by the vulnerabilities and threats associated with objectives in military, intelligence, and business operations.

1.1.4. Effective implementation and resultant residual risk associated with security controls implementation is assessed and mitigated, aligns with DoDI 8510.01, and as documented in the RMF security authorization package for AF IT.

1.1.5. Discrete classes of systems (i.e., AF financial systems) are subject to additional requirements contained in Attachment 3 to this document. Guidance contained in

Attachment 3 are intended to supplement, but not replace, the policy limits articulated in this

Instruction.

1.2. Applicability.

1.2.1. This publication is binding on all military, civilian and contract employees, and other individuals or organizations as required by binding agreement or obligation with the

Department of the Air Force, who develop, acquire, deliver, use, operate, support, or manage

AF IT. This publication applies to all networked or standalone IT used to receive, process, store, display, or transmit AF information (or Government information where the AF agreed to manage the information/infrastructure), as well as DoD partnered systems where it is agreed that DoD standards are followed. AF IT (see Figure 1.1) includes but is not limited to: information systems (IS) (major applications and enclaves), platform information technology (PIT) (PIT systems, PIT subsystems, and PIT products), IT services (Internal &

External), and IT products (software, hardware, and applications).

1.2.2. This AFI does not apply to the protection of Sensitive Compartmented Information

(SCI) systems or intelligence, surveillance, reconnaissance mission and mission support systems or higher authoritative guidance governing Special Access Program (SAP) systems.

1.2.3. Authority for AF space systems rests with AF Space Command (AFSPC) as delegated by United States Strategic Command (USSTRATCOM). AF space systems follow AF cybersecurity policy and processes; where exceptions exist, this Instruction is annotated accordingly. NOTE: Space systems supporting more than one DoD Component will follow

6 AFI17-101 2 FEBRUARY 2017

cybersecurity policy and guidance in DoDI 8581.01, Information Assurance (IA) Policy for

Space Systems Used by the Department of Defense.

1.2.4. For IT not centrally managed or has yet to be assigned an Authorizing Official (AO), the unit responsible for ownership or operation of the IT shall assign duties for the minimum

RMF relevant roles (see Table 2.1) required to comply with RMF. The duties shall include the roles and responsibilities for reporting, oversight, and risk management to the AF.

Figure 1.1. Air Force IT Categories.

1.3. Objectives.

1.3.1. The RMF replaces the DIACAP and manages the life-cycle cybersecurity risk to AF

IT. The RMF provides a disciplined and structured process to perform AF IT security and risk management activities and to integrate those activities into the system development life cycle. The RMF changes the traditional focus of certification and accreditation (C&A) as a static, procedural activity to a more dynamic approach to more effectively manage mission and cybersecurity risks in diverse environments of complex, evolving, and sophisticated cyber threats and vulnerabilities.

1.3.2. The RMF ensures AF IT assets are assessed for cybersecurity risk to the AF, the discovered weaknesses are documented in a plan of action and milestones (POA&M) to mitigate residual risk, and an AO, supported by the RMF team members, identified at Table

2.1, accepts the risk to the AO’s area of responsibility, IAW AFPD 16-14, Security

Enterprise Governance, and DoDI 8510.01.

AFI17-101 2 FEBRUARY 2017 7

Chapter 2

ROLES AND RESPONSIBILITIES

2.1. Secretary of the Air Force, Office of Information Dominance and Chief Information

Officer (SAF/CIO A6). The SAF/CIO A6 will:

2.1.1. Appoint the Chief Information Security Officer (CISO) who develops, implements, maintains, and enforces the AF Cybersecurity Program.

2.1.2. Maintain visibility of the cybersecurity posture for AF IT through automated tools or designated repositories in support of DoD CIO and appointed AOs. (T-0)

2.1.3. Provide guidance to organizations on how to implement solutions for operational requirements in support of established National, DoD, Joint Chiefs of Staff (JCS), or AF security controls for IT and remain within established risk tolerance levels. (T-0)

2.1.4. Appoint AOs in coordination with the appropriate Mission Area Owner (MAO).

2.1.5. Ensure an Information System Owner (ISO) is appointed for all AF IT.

2.1.6. Appoint the AF Chief Architect with responsibility for the AF Cybersecurity

Architecture IAW AFI 17-140, Air Force Architecting.

2.1.7. Define cybersecurity performance measurements and metrics to identify enterprise-wide cybersecurity trends and status of mitigation efforts, IAW NIST SP 800-55, Performance Measurement Guide for Information Security. (T-0)

2.1.8. Be responsible for the security controls implemented across the IT enterprise.

2.2. Administrative Assistant to the Secretary of the Air Force (SAF/AA).

2.2.1. Works with the CISO to oversee the establishment of risk tolerance and security controls for IT owned by Headquarters Air Force (HAF) organizations without a functional

CIO (HAF Portfolio).

2.2.2. Provides guidance to organizations on how to implement solutions for operational requirements for the HAF Portfolio.

2.2.3. Maintains visibility of the cybersecurity posture of HAF Portfolio IT through automated assessment and authorization tools.

2.3. Secretary of the Air Force for Acquisition (SAF/AQ).

2.3.1. Acquires all AF electronic systems through organic programs within the AF, commercial-off-the-shelf (COTS) systems, or non-developmental item (NDI) programs. The

PM shall pursue comprehensive integrated risk analysis throughout the life cycle of all programs and shall prepare and maintain a risk management plan.

2.3.2. Works with the CISO to oversee the establishment of risk tolerance and security controls for AF IT. Provides guidance to organizations on how to implement solutions for operational requirements.

8 AFI17-101 2 FEBRUARY 2017

2.3.3. Ensures all cyber /IT security controls are translated into security requirements via systems security engineering and are written into the System Requirement Document (SRD) on all acquisitions.

2.3.4. Ensures system security engineering is accomplished through the acquisition process for all new and upgrade capability developments.

2.4. Deputy Chief of Staff, Intelligence, Surveillance, and Reconnaissance (AF/A2).

2.4.1. Maintains visibility of the cybersecurity posture of AF SCI and the DoD portion of the

Intelligence Mission Area (DIMA) IT through automated assessment and authorization tools.

2.4.2. Oversees the establishment of risk tolerance and baseline security controls for AF SCI and DIMA IT. Consults with SAF/A6 CISO as appropriate. Provides RMF implementation guidance to AF ISR systems and network organizations.

2.5. Chief Information Security Officer (CISO), SAF/CIO A6Z. Will develop, implement, maintain, and enforce the AF Cybersecurity Program and the RMF process, roles, and responsibilities. The CISO will advocate for any budgets associated with duties below and advocate for AF-wide cybersecurity solutions through the planning, programming, budget and execution process on behalf of the SAF/CIO A6. As a CISO, the role requires individuals be a

DoD official (O-7 or SES at a minimum) and a United States citizen. (T-1) The CISO will:

2.5.1. Complete training and maintain cybersecurity certifications IAW AFMAN 17-1303, Cybersecurity Workforce Improvement Program. (T-1)

2.5.2. Monitor, evaluate, and provide advice to the SAF/CIO A6 regarding AF cybersecurity posture.

2.5.3. In coordination with the SAF/CIO A6 and AOs, ensure the cybersecurity risk posture, risk tolerance levels, and risk acceptance decisions for AF IT meet mission and business needs, IAW Commander, USSTRATCOM, 24 AF/CC, and AFI 10-1701, Command and

Control (C2) for Cyberspace Operations, while also minimizing the operations and maintenance burden on the organization.

2.5.4. Perform as the Security Control Assessor (SCA) or appoint SCAs.

2.5.5. Provide guidance and direction on Agent of the Security Control Assessor (ASCA) establishment and licensing in support of RMF requirements. (T-1)

2.5.6. Oversee establishment and enforcement of the AF RMF, roles, and responsibilities;

review approval thresholds and milestones within the RMF. (T-1)

2.5.7. Chair the Air Force Risk Management Council (AFRMC). (T-1)

2.5.8. Participate in Federal, Joint, DoD, and AF cybersecurity and RMF technical working groups and forums (e.g., Defense Information Assurance Security Accreditation Working

Group (DSAWG)).

2.5.9. Adjudicate IT determinations, in coordination with the AFRMC, when a conflict in the IT determination process is identified. (T-1)

2.5.10. Appoint AF members to the DoD RMF TAG.

AFI17-101 2 FEBRUARY 2017 9

2.5.11. Review and approve Privacy Impact Assessments (PIAs) submitted IAW AFI 33-

332, The AF Privacy and Civil Liberties Program. The approval of the PIA cannot be delegated. (T-1)

2.5.12. Approve national security system (NSS) designations for AF IT. (T-1)

2.5.13. Ensure AF RMF guidance is posted to the AF Component Workspace portion of the

DoD Knowledge Service (KS) and is consistent with DoD policy and guidance.

2.6. Authorizing Official (AO). The AO is the official with the authority responsible for accepting a level of risk for a system balanced with mission requirements, except for IT with unmitigated “Very High” and “High” risk. The AO is the only person with authority to grant authorization decisions within their area of responsibility. All AOs have the flexibility in augmenting, executing, and implementing RMF for systems in their AOR. For example, AOs can create a community-specific guidebook for better clarifying guidance. AOs will:

2.6.1. Be a DoD official (O-7 or SES at a minimum) and a U.S. citizen. (T-1)

2.6.2. Complete training and certification requirements IAW AFMAN 17-1303. (T-1)

2.6.3. Be appointed by SAF/CIO A6, in coordination with the appropriate MAO. The appointment grants authority to authorize IT as defined in the AO appointment memo.

2.6.4. Advocate for cybersecurity-related positions in accordance with DoDI 8500.01, (T-0)

AFI 17-130, and AFMAN 17-1303. (T-1)

2.6.5. Ensure an Information System Owner (ISO) (i.e., the owner, operator, maintainer of the IT) is appointed prior to issuing an authorization decision. (T-1)

2.6.6. Ensure ISOs participate throughout the RMF process and understand the risk imposed on the mission due to operating the IT.

2.6.7. Ensure verification through the AF Ports, Protocols, and Services (PPS) Office

(af.pps@us.af.mil) that Internet protocols, data services, and associated ports (internal and external) of the system/enclave comply with the requirements outlined in DoDI 8551.01

Ports, Protocols, and Services Management (PPSM). (T-0)

2.6.8. Assist the SAF/CIO A6 in providing guidance to organizations on how to implement solutions for operational requirements exceeding the established National, DoD, JCS, or AF baseline controls for IT.

2.6.9. Render authorization decisions that balance mission needs with security concerns for

IT within the AO’s area of responsibility. The Authorization Decision Documentation will be digitally signed and generated via Enterprise Mission Assurance Support Service

(eMASS), except PIT. Any exceptions to or conditions of the authorization decision must be articulated within the Authorization Decision Document. (T-0)

2.6.10. Review the security assessment report (SAR), risk assessment report (RAR), and

POA&M to ensure there is a clearly defined course of action, see also NIST SP 800-30, Guide for Conducting Risk Assessments. An AO may downgrade or revoke an authorization decision at any time, if risk conditions or concerns so warrant. (T-0)

2.6.11. Review and approve the security assessment plan (SAP), the security plan, and system-level information security continuous monitoring (ISCM) strategy.

mailto:af.pps@us.af.mil

10 AFI17-101 2 FEBRUARY 2017

2.6.12. Ensure all AF IT comply with DoD and AF connection approval processes, see

Chapter 4.

2.6.13. Not delegate authorization decision authority (i.e., to formally accept risk for a system). (T-0)

NOTE: Appointment letters and AO Boundaries are located on the AF RMF KS.

2.7. Air Force Enterprise Authorizing Official (AF Enterprise AO). The AF Enterprise AO is the only authority permitted to grant an Approval to Connect (ATC) to the Air Force

Information Networks (AFIN). The Enterprise AO may delegate this authority to appropriate deputies with concurrence of the SAF/CIO A6. In addition to the AO responsibilities in paragraph 2.6 above, the Enterprise AO will:

2.7.1. Establish acceptable security controls and risk tolerance for connecting to the AFIN and provide guidance to implementing organizations to mitigate risk commensurate with established risk tolerance.

2.7.2. Review the Security Authorization Package, as a minimum, for all requests to connect to the AFIN and assess the impact to enterprise community risk. (T-1)

2.7.3. Render authorization decisions in the form of an authorization to operate (ATO) for

AF systems not falling under another AO. Render AFIN connection decisions in the form of an ATC (see Chapter 4) for non-AF systems and for AF systems falling under another AO.

(T-1)

2.7.4. The Enterprise AO or designee will expediently respond to urgent/emergency requests to connect to the AFIN.

2.7.5. See AFI 17-130, for additional information in support of this position.

2.8. AO Designated Representative (AODR). The AODR will:

2.8.1. Be appointed by the AO, and at a minimum, be an O-5 or GS-14. Appointments will be in writing (to include duties and responsibilities) to support the RMF. Digital signatures are authorized for appointment letters. (T-1)

2.8.2. The AODR may be supplemented with contractor support, however contractors are not permitted to make decisions on behalf of the government and may only provide advice and guidance.

2.8.3. Perform responsibilities as assigned by the AO. The AODR may perform any and all duties of an AO except for accepting risk by issuing an authorization decision.

2.8.4. Complete AO training and maintain cybersecurity certifications consistent with duties and responsibilities of an AO and IAW AFMAN 17-1303. (T-1)

2.8.5. Provide recommendations to the AO to render authorization decisions based on input from the SCA, ISO, PM, and other AOs and AODRs.

2.9. Security Control Assessor (SCA). The SCA will:

2.9.1. Be appointed by the CISO and will be at least an O-4 or GS-13 with the authority and responsibility for the assessment determination within their assigned area of responsibility.

AFI17-101 2 FEBRUARY 2017 11

2.9.2. Complete training and maintain appropriate cybersecurity certification IAW AFMAN

17-1303. It is highly recommended SCAs complete both the AO training module and attain the Committee on National Security Systems Instruction (CNSSI) 4016, National

Information Assurance Training Standard for Risk Analysts, certificate for supplemental training. (T-1)

2.9.3. Develop the SAP and ensure its integration into the program office’s Test and

Evaluation Master Plan (TEMP) IAW DoDI 5000.02, Operation of the Defense Acquisition

System. (T-0)

2.9.4. Prepare the SAR documenting the issues, findings, and recommendations from the security control assessment, and reassess remediated controls, as required. (T-0)

2.9.5. Periodically assess security controls employed within and inherited by the IT IAW the

Information Security Continuous Monitoring strategy. (T-0)

2.10. Security Controls Assessor Representative (SCAR). This position may be an organic or contracted resource. The SCAR works with the PM, ISSM, ISSO, and RMF team to assess security controls for the SCA. The SCAR will:

2.10.1. Complete training and maintain appropriate cybersecurity certification IAW

AFMAN 17-1303. It is recommended SCARs also complete the AO training module and attain the CNSSI No. 4016 certificate for supplemental training. (T-1)

2.10.2. Serve as an active member of the RMF team from its inception, to assist with planning of cybersecurity requirements. The SCAR ensures security controls are implemented IAW the security plan and are assessed IAW the SAP. (T-0)

2.10.3. Validate assessment results from others' (e.g., ASCA or ISSM) hands-on, comprehensive evaluations of the technical and non-technical security controls for the IT, determine the degree to which the IT satisfies the applicable security controls.

2.10.4. Should the SCAR be a contractor, the SCAR is not permitted to make decisions on behalf of the government but can only provide advice and guidance.

2.11. Agent of the Security Controls Assessor (ASCA). The ASCA is a licensed 3rd-party agent assisting in assessment activities and provides an independent report for the SCA. This position cannot make decisions on behalf of the government but can only provide advice and guidance. The ASCA will:

2.11.1. Achieve and maintain an ASCA license per the AF and Space ASCA Licensing

Guide. (T-0)

2.11.2. Respond to PM, ISO, SCAR, SCA, and AO requests for information regarding their respective systems.

2.11.3. Perform comprehensive evaluation of the technical and non-technical security controls for the IT, determine the degree to which the IT satisfies the applicable security controls, and provide mitigation recommendations.

2.11.4. Perform assessment procedures for each applicable security control as outlined in the

DoD RMF KS. (T-0)

12 AFI17-101 2 FEBRUARY 2017

2.11.5. Meet the intent of RMF independence between the PM or ISO and the individuals performing security control assessments; the ASCA reports only to the SCA.

2.11.6. The ASCA will not be part of the development team or program office. The PM or

ISO provides funding for organizations or contractors to perform ASCA responsibilities; the

PM or ISO does not provide direction or oversight to organizations or contractors in support of ASCA responsibilities.

2.11.7. All ASCA agreements must include safeguards to prevent a conflict of interests with the development team.

2.12. Information System Owners (ISO). Official responsible for the overall procurement, development, integration, modification, and operation and maintenance of AF IT. (T-1) An ISO is appointed and performs all PM roles and responsibilities when a PM is not assigned. For AF-wide systems (e.g., AFNET and LOGMOD), the ISO is appointed by the HAF/SAF 3-letter responsible for the capability. For MAJCOM-level or base-level IT, to include base enclaves, and PIT, the appropriate MAJCOM 2-letter appoints the ISO. (T-1) No further appointment is required. This ISO role is not the same as the TEMPEST ISO. The ISO will:

2.12.1. Identify the requirement for the IT and request funds to operate and maintain the IT in order to assure mission effectiveness. (T-2)

2.12.2. Ensure, with coordination of the PM staff, the development, maintenance, and tracking of the security plan for assigned IT. (T-1)

2.12.3. Ensure, with coordination of the PM staff, the development of an ISCM strategy to monitor the effectiveness of all security controls employed within or inherited by the system, and to monitor any proposed or actual changes to the system and its environment of operation. (T-0)

2.12.4. Report the security status of the IT including the effectiveness of security controls employed within and inherited by the system to the AO and other appropriate organizational officials on an ongoing basis in accordance with the ISCM strategy.

2.12.5. Decide, in coordination with the Information Owner (IO)/Steward, who has access to the system (and what types of privileges or access rights) and ensure system users and support personnel receive the requisite security training. (T-2)

2.12.6. Inform, based on guidance from the SCA and AO, appropriate organizational officials to conduct the Authorize and Assess process or the Assess Only process; ensure the necessary resources are available for the effort, and provide the required IT access, information, and documentation to the SCA.

2.12.7. Conduct the initial remediation actions on security controls based on the findings and recommendations of the SAR and work with the SCA to reassess remediated controls.

2.12.8. Ensure the POA&M is developed for all identified weaknesses and the appropriate steps to mitigate those weaknesses are identified. Take appropriate steps to reduce or eliminate weaknesses, then generate the security authorization package and submit the package to the SCA for assessment. (T-0)

2.12.9. Ensure open POA&M items are updated and closed in a timely manner. (T-2)

AFI17-101 2 FEBRUARY 2017 13

2.12.10. Ensure consolidated RMF documentation is maintained for systems with instances at multiple locations.

2.12.11. Thoroughly review the security controls assessment and risk assessment results before submitting the security authorization package to the AO, ensuring the system’s cybersecurity posture satisfactorily supports mission, business, and budgetary needs (i.e., indicates the mission risk is acceptable).

2.12.12. Ensure, with the assistance of the ISSM, and coordination with the PM staff, the system is deployed and operated according to the approved security plan and the authorization package (i.e., the AO’s authorization decision). (T-0)

2.13. Program Manager (PM). The ISO is assigned the PM duties when no PM is assigned.

The PM will:

2.13.1. Identify, implement, and ensure full integration of cybersecurity into all phases of the acquisition, upgrade, or modification programs, including initial design, development, testing, fielding, operation, and sustainment IAW AFI 63-101, Integrated Life Cycle

Management, and DoDI 8510.01, the DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition

Lifecycle. (T-0)

2.13.2. Ensure the Program Management Office (PMO) is resourced to support information system security engineering (ISSE) requirements and security technical assessments of the IT for the SCA’s recommendation, the AOs authorization decision, and other security-related assessments (e.g., Financial Improvement and Audit Readiness IT testing, Inspector General audits). (T-1)

2.13.3. Ensure cybersecurity-related positions are assigned in accordance with Table 2.1 and

AFMAN 17-1303. (T-1)

2.13.4. Appoint an ISSM, IAW DoDI 8510.01, for the program office and ensure the ISSM is certified IAW AFMAN 17-1303. (T-0)

2.13.5. Ensure the IT is registered IAW AFI 17-110, Air Force Information Technology

Portfolio Management and Investment Review. (T-1)

2.13.6. Develop and maintain a cybersecurity strategy for IT IAW AFMAN 17-1402, Air

Force Clinger-Cohen Act (CCA) Compliance Guide, and AFI 63-101/20-101. (T-1)

2.13.7. Ensure applicable Cyber Tasking Orders (CTO) are received and acted upon per the

CTO directions. (T-1)

2.13.8. Ensure periodic reviews, testing, or assessment of assigned IT are conducted at least annually, and IAW the ISCM strategy.

2.13.9. Ensure operational systems maintain a current ATO and recommend to the AO that systems without a current authorization are identified for removal from operation. (T-1)

2.13.10. Ensure all system changes are approved through a configuration management process, are assessed for cybersecurity impacts, and coordinated with the SCA, AO, and other affected parties, such as IOs/Stewards and AOs of interconnected boundaries.

14 AFI17-101 2 FEBRUARY 2017

2.13.11. Track and implement the corrective actions identified in the POA&M, in order to provide visibility and status to the ISO, IO, AO, and CISO. (T-0)

2.13.12. Report security incidents to stakeholder organizations and the SCA. Conduct root cause analysis for incidents and develop corrective action plans as input to the POA&M.

2.13.13. Ensure a PIA is completed (DD Form 2930) for IT that process and/or store

Personal Identifiable Information (PII)/Personal Health Information (PHI) IAW AFI 33-332, Air Force Privacy and Civil Liberties Program. (T-1)

2.14. Unit Communications Squadron Commander (CS/CC). Serves as the PM or ISO for the base enclave and performs duties IAW DoDI 5000.02 and AFI 17-130.

2.15. Information System Security Manager (ISSM). The ISSM is the primary cybersecurity technical advisor to the AO, PM, and ISO. For base enclaves, the ISSM manages the installation cybersecurity program, typically as a function of the Wing Cybersecurity Office. That program

ISSM may also serve as the system ISSM for the enclave and reports to the CS/CC as the PM for the base enclave. The ISSM will:

2.15.1. Ensure the integration of cybersecurity into and throughout the lifecycle of the IT on behalf of the AO. (T-0)

2.15.2. Complete and maintain required cybersecurity certification IAW AFMAN 17-1303.

Individuals in this position must be U.S. citizens. (T-0)

2.15.3. Ensure all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals. (T-1)

2.15.4. Support the PM or ISO in maintaining connection (ATC) and authorization (ATO) approvals and provide support to the PM or ISO in implementing corrective actions identified in the POA&M.

2.15.5. Coordinate, with the PM and AO staffs, development of an ISCM strategy and monitor any proposed or actual changes to the system and its environment.

2.15.6. Continuously monitor the IT and environment for security-relevant events, assess proposed configuration changes for potential impact to the cybersecurity posture, and assess the quality of security controls implementation against performance indicators such as security incidents, feedback from external inspection agencies, exercises, and operational evaluations. (T-0)

2.15.7. Ensure cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected IT.

2.15.8. Appoint Information System Security Officers (ISSOs) and provide oversight to ensure ISSOs follow established cybersecurity policies and procedures IAW DoDI 8500.01.

(NOTE: ISSO appointments are not required if the ISSM has purview over a small amount of IT, but ISSO appointments are advisable when the ISSM has purview over multiple IT).

(T-0)

2.15.9. Ensure all ISSOs and privileged users receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303 and maintain proper clearances IAW DoDI 8500.01. (T-0)

AFI17-101 2 FEBRUARY 2017 15

2.15.10. Ensure the AF IT is acquired, documented, operated, used, maintained, and disposed of properly and IAW DoDI 5000.02 and DoDI 8510.01. (T-0)

2.16. Information System Security Officer (ISSO). The ISSO is responsible for ensuring the appropriate operational security posture is maintained for assigned IT. The ISSM will take on these responsibilities should no ISSO be assigned. This includes the following activities related to maintaining situational awareness and initiating actions to improve or restore cybersecurity posture. ISSOs (formerly system-level IA Officers) will:

2.16.1. Implement and enforce all AF cybersecurity policies, procedures, and countermeasures. (T-1)

2.16.2. Complete and maintain required cybersecurity certification IAW AFMAN 17-1303.

Individuals in this position must be U.S. citizens. (T-0)

2.16.3. Ensure all users have the requisite security clearances and need-to-know, complete annual cybersecurity training, and are aware of their responsibilities before being granted access to the IT according to AFMAN 17-1301. (T-1)

2.16.4. Maintain all authorized user access control documentation IAW the applicable AF

Records Information Management System (AFRIMS). (T-1)

2.16.5. Ensure software, hardware, and firmware complies with appropriate security configuration guidelines (e.g., Security Technical Implementation Guides (STIGs)/Security

Requirement Guides (SRG)). (T-1)

2.16.6. Ensure proper configuration management procedures are followed prior to implementation and contingent upon necessary approval. Coordinate changes or modifications with the system-level ISSM, SCA, and/or the Wing Cybersecurity office. (T-

1)

2.16.7. Initiate protective or corrective measures, in coordination with the security manager, when a security incident or vulnerability is discovered. (T-3)

2.16.8. Report security incidents or vulnerabilities to the system-level ISSM and wing cybersecurity office according to AFI 17-130. (T-2)

2.16.9. Initiate exceptions, deviations, or waivers to cybersecurity requirements. (T-1)

2.17. Information Systems Security Engineer (ISSE). The ISSE is an individual, group, or organization responsible for conducting information system security engineering activities. ISSE captures and refines information security requirements and ensures the requirements are effectively integrated into IT products and information systems through purposeful security architecting, design, development, and configuration. Reference DoDI 5000.02, and NIST SP

800-160, Systems Security Engineering - A Multidisciplinary Approach to Building Trustworthy

Resilient Systems, for additional details on systems engineering and information systems engineering processes. The ISSE traces security controls (which are high-level cybersecurity capability needs), with the RMF team, to the actual system security requirements documented in the acquisition process (i.e., many security requirements are derived from security controls). The

ISSE will:

16 AFI17-101 2 FEBRUARY 2017

2.17.1. Employ best practices when implementing security controls, including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.

2.17.2. Coordinate their security-related activities with the information security architect, ISSO, ISO, and common control provider.

2.17.3. Complete training and maintain certification IAW AFI 17-1303. Personnel performing any IA Workforce System Architecture and Engineering (IASAE) specialty function(s) (one or more functions) at any level must be certified to the highest level function(s) performed. (T-0)

2.18. Information Owner (IO)/Steward. An organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, classification, collection, processing, dissemination, and disposal as defined in CNSSI No. 4009. The IO/Steward will:

2.18.1. Provide input to the ISO regarding security requirements and security controls for the

IT where the information is processed, stored, or transmitted. (T-2)

2.18.2. Establish the rules for appropriate use and protection of the information, during generation, collection, processing, dissemination, and disposal and retain that responsibility even when the information is shared with or provided to other organizations. (T-1)

2.18.3. Provide input to ISOs on the security controls selection (e.g., during system categorization and security controls tailoring) and on the derived security requirements for the systems where the information is processed, stored, or transmitted (A single IS, PIT system, or PIT subsystem may contain information from multiple IO/stewards.) (T-1)

2.19. MAJCOM Cybersecurity Office or Function. The MAJCOM Cybersecurity Office or

Function will:

2.19.1. Develop, implement, oversee, and maintain a MAJCOM cybersecurity program that adheres to cybersecurity architecture, requirements, objectives, policies, processes, and procedures.

2.19.2. Tracks and reports Federal Information Security Modernization Act of 2014

(FISMA) metrics to SAF/CIO A6 Cybersecurity on a monthly, quarterly, and annual basis as required via Enterprise Information Technology Data Repository / Information Technology

Investment Portfolio System (EITDR/ITIPS) or DoD Cyberscope (DCS).

2.20. User Representative (UR). The User Representative is the individual or organization that represents operational and functional requirements of the user community for a particular system during the RMF process. The UR supports the security controls selection, implementation, and assessment to ensure user community needs are met. While this role is not mandatory, it is highly recommended this role be used. The individuals in this role understand the operating environment, mission criticality, reliability and survivability requirements, etc., of the system.

AFI17-101 2 FEBRUARY 2017 17

2.21. Additional Responsibilities. Additional responsibilities and authorities relevant to many of the roles listed above are contained in the attachments.

Table 2.1. AF RMF Appointment Matrix.

Role Appointed/ Identified By Rank

Minimum Reference(s)

SAF/CIO A6+ SecAF (established) O-9 HAF MD1-26

CISO SAF-CIO A6 O-7 / SES DoDI 8500.01

MAO Identified O-7 / SES AFPD 16-14

AO*+ SAF-CIO A6 O-7 / SES AFI 17-130

AODR AO O-5 / GS-14 AFI 17-130

SCA*+ CISO O-4 / GS-13 AFI 17-130

PM+ For programs of record, Service

Acquisition Executive (SAE) (as applicable); otherwise, ISO performs duties.

Any government official

DoDI 5000.02

ISO*+ For programs of record, Service

Acquisition Executive (SAE) (as applicable); otherwise, HAF/SAF 3-letter or MAJCOM 2-letter (as applicable)

Any AFI 17-101

IO/Steward Identified by the ISSM Any DoDI 8500.01, NIST SP 800-37r1

ISSE+ PM Any DoDI 8510.01

ISSM*+ PM or ISO Any DoDI 8510.01

ISSO+ ISSM Any AFI 17-130

UR ISO Any DoDI 8510.01

1. * Denotes minimum system-level RMF positions

2. + Denotes additional responsibilities and authorities assigned in Attachments

2.22. Cybersecurity Forums. The AF leverages existing DoD and AF governance bodies (e.g., Air Force Security Enterprise Executive Board (AFSEEB), Information Technology Governance

Executive Board (ITGEB)) to discuss cybersecurity risk topics and make organizational and mission area risk decisions. This Instruction does not define the scope or responsibilities of these existing bodies. The following forums provide focused management and oversight of the AF

Cybersecurity Program.

2.22.1. AF Cybersecurity Technical Advisory Group (AFCTAG). The AFCTAG provides technical cybersecurity subject matter experts (SMEs) from across the MAJCOMs and functional communities to facilitate the management, oversight, and execution of the AF

18 AFI17-101 2 FEBRUARY 2017

Cybersecurity Program. The AFCTAG examines cybersecurity-related issues common across AF entities and provides recommendations to the CISO and DSAWG on changes to the minimally required security controls (for AFIN connection) or configurations.

2.22.2. Air Force Risk Management Council (AFRMC). The AFRMC provides a forum for the senior cybersecurity professionals to discuss issues concerning cybersecurity risk from a mission and business perspective. The council reviews proposed Mission Area or AF RMF control overlays, and RMF guidance. The council standardizes the cybersecurity implementation processes for both the acquisition and lifecycle operations for IT. The

AFRMC advises and makes recommendations to existing governance bodies. Finally, the

AFRMC recommends assignment of IT to the appropriate AO for systems that fall outside of all defined authorization boundaries.

2.22.3. AF AO Summit. The AO Summit is not a governance body but rather an enabler for both an enterprise-wide and converged organizational perspective to cybersecurity policy development, oversight, implementation, and training. This venue provides the SAF/CIO A6 and AOs an opportunity to discuss issues relevant to the RMF, AO Boundaries, IT, AOs, and

SCAs.

2.22.4. For additional information on these forums, please see the SAF/CIO A6Z

Cybersecurity Division site, AFI 17-130, applicable charters, and process guides.

AFI17-101 2 FEBRUARY 2017 19

Chapter 3

RMF METHODOLOGY

3.1. Overview.

3.1.1. The 6-Step RMF process at RMF Tier 3 (system level) is based on the process outlined in NIST SP 800-37r1 and DoDI 8510.01 and is illustrated in Figure 3.1. Where possible, this Instruction also identifies steps required for the “Assess Only” process. This process is iterative throughout the entire lifecycle for IT IAW DoDI 5000.02 and the DoD

Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management

Framework (RMF) into the System Acquisition Lifecycle (DoD PM Guidebook).

3.1.2. The DoD RMF KS is the authoritative source for RMF implementation, planning, and execution.

3.1.3. This chapter highlights the AF-specific implementation, key AF roles in each step, and additional resources required to complete the process. This Instruction is intended to be a companion to the DoD implementation instructions. Specific implementation guidance is available on the DoD RMF KS. Additionally, supplementary guidance concerning the execution of RMF steps for discrete classes of AF systems (e.g., financial systems) is contained in the Attachments.

Figure 3.1. RMF for AF IT.

3.2. RMF Step 1, CATEGORIZE System. References DoDI 8510.01, CNSSI No.1253, NIST

SP 800-53r4, NIST SP 800-60, Guide for Mapping Types of Information and Information

Systems to Security Categories, and the DoD RMF KS.

20 AFI17-101 2 FEBRUARY 2017

3.2.1. Begin this step by completing the RMF IT Categorization and Selection Checklist and

DD Form 2930, Privacy Impact Assessment. During categorization, the impact to confidentiality, integrity, and accessibility is categorized into one of three designations (low, moderate, or high) to address the impact of a loss. If the program’s primary mission is not represented on the form’s Authorization Boundary list, the PM or ISO will check “other” on the IT Categorization Checklist and submit the completed document to the AFRMC for disposition; send to SAF/CIO A6ZC Cybersecurity Division, usaf.pentagon.saf-cio-a6.mbx.a6sc-workflow@mail.mil. SAF/CIO A6ZC retains the IT categorized as “other” until the new AO Authorization Boundary is created or an AO is assigned. If an existing boundary is determined, the Checklist is returned to the PM/ISO for staffing to and approval by the determined AOs.

3.2.2. Each AF IT, IAW AFI 17-110, must be registered in EITDR, as the governance tool for the AF CIO, with the exception of those identified by other policy (i.e., space, Nuclear

Command, Control, and Communication (NC3), Joint) to be registered in another repository.

(T-1) EITDR/ITIPS will systematically assign a temporary registration number for each registered IT until the next scheduled replication with DoD Information Technology

Portfolio Repository (DITPR). A DITPR number will then be systematically assigned and included in EITDR/ITIPS as the permanent official IT registration number for all registered

AF IT.

NOTE: The EITDR system is transitioning to ITIPS by the end of 2nd quarter of 2017. When this system, or any future tracking system, is implemented, the EITDR registration requirements still apply in the current tracking system. All instances within this Instruction that reference

EITDR is equivalent to ITIPS; consider these names interchangeable.

3.2.3. PMs or ISOs deploying systems across DoD/AF Components will register the system and post the categorization checklist to Enterprise Mission Assurance Support Service

(eMASS).

3.2.4. For programs where the sensitivity of information may present a cybersecurity concern, the program (e.g., Aircraft, C2, and Weapons Systems) is required to upload only the following information/documentation into eMASS: PM and System Information eMASS fields, IT Categorization and Selection Checklist document, Cybersecurity Strategy document, Authorization Decision Memo document, and a Statement…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .