Attachment 4. MAHG211140 - Cybersecurity Guidance.pdf
PDF 1 MB Posted
- Attached to
- MAHG 21-1140 Controls Phase 2 Federal contract opportunity
- Solicitation number
- FA301024R0007
About this file
This document is a Department of the Air Force Guidance Memorandum (DAFGM) that provides policy and guidance for securing and mitigating cybersecurity risks to Civil Engineer (CE)-owned control systems, including supervisory control and data acquisition (SCADA) systems, building automation systems, life safety systems, utility monitoring and control systems, and other control systems.
The key details are:
- This DAFGM applies to all DAF civilians, Space Force, Air Force, Air Force Reserve, and Air National Guard personnel, as well as those with contractual obligations to follow DAF policies. Compliance is mandatory.
- It defines roles and responsibilities for managing control systems cybersecurity risk under the Risk Management Framework (RMF).
- It provides requirements for control systems inventories, vulnerability management, connectivity, continuous monitoring, physical access controls, software/hardware security, patch management, change management, maintenance procedures, and incident response planning.
- It includes specific requirements for incorporating cybersecurity into control systems contracts, including use of open standards, data interoperability, secure protocols, vendor maintenance, and software/hardware disposal procedures.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF THE AIR FORCE
HEADQUARTERS UNITED STATES AIR FORCE
WASHINGTON, DC
DAFGM2023-32-01
27 June 2023
MEMORANDUM FOR MAJCOMs/FLDCOMs/FOAs/DRUs
DISTRIBUTION ON C
FROM: HQ USAF/A4
1030 Air Force Pentagon
Washington DC 20330-1030
SUBJECT: Department of the Air Force Guidance Memorandum, Civil Engineer Control Systems
Cybersecurity
ACCESSIBILITY: Publication and forms are available on the e-Publishing website at www.e-Publishing.af.mil for downloading or ordering.
RELEASABILITY: There are no releasability restrictions on this publication.
OPR: AF/A4CS, Systems & Data Division
By Order of the Secretary of the Air Force, this Department of the Air Force Guidance
Memorandum (DAFGM) re-issues the March 2022 DAFGM that establishes cybersecurity policy for Civil Engineer (CE)-owned control systems and these systems’ associated components, devices, networks, applications and/or data (hereinafter referred to as “control systems”). This
Memorandum details the unique operational characteristics of control systems, implements policy for securing and mitigating cybersecurity risk to control systems, and outlines roles and responsibilities for managing risk under the Risk Management Framework (RMF) pertaining to control systems. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Department of the
Air Force (DAF).
This Guidance Memorandum applies to all DAF civilians and uniformed members of the
United States Space Force, Regular Air Force, the Air Force Reserve, the Air National Guard, and those with a contractual obligation to abide by the terms of DAF issuances.
Compliance with this Memorandum is mandatory. To the extent its direction is inconsistent with other Department of the Air Force publications, the information herein prevails, in accordance with Department of the Air Force Instruction (DAFI) 90-160, Publications and Forms Management. Refer recommended changes and questions about this publication to the OPR using the DAF Form 847, Recommendation for Change of Publication;
route DAF Forms 847 from the field through the appropriate functional chain of command. The authorities to waive wing/delta unit level requirements in this publication are identified with a
Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See DAFI 90-160, Publications and Forms Management, for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to
Attachment 4
FA301024R0007
http://www.e-publishing.af.mil/ http://static.e-publishing.af.mil/production/1/saf_aa/publication/afi33-360/afi33-360.pdf http://static.e-publishing.af.mil/production/1/saf_aa/publication/afi33-360/afi33-360.pdf
2 DAFGM2023-32-01 JUNE 2023
the appropriate Tier waiver approval authority, or alternately, to the requestor’s commander for non-tiered compliance items.”
Ensure all records generated as a result of processes prescribed in this publication adhere to Air Force Instruction 33-322, Records Management and Information Governance Program, and are disposed in accordance with the Air Force Records Disposition Schedule, which is located in the Air Force Records Information Management System. This Memorandum becomes void after one year has elapsed from the date of this Memorandum or upon the publication of a new Instruction permanently establishing the guidance, whichever is earlier.
TOM MILLER, Lieutenant General, USAF
DCS/Logistics, Engineering & Force Protection
Chapters:
1. Overview
2. Roles and Responsibilities
3. Cybersecurity Implementation
4. Control Systems Cyber Hygiene
Attachments:
1. Glossary of References and Supporting Information
Attachment 4
FA301024R0007
DAFGM2023-32-01 JUNE 2023 3
Chapter 1
OVERVIEW
1.1. Control Systems Background.
1.1.1. Operational Technology1 has become ubiquitous and integrated into every piece of modern life. Throughout the DAF, control systems2 (a subset of operational technology) are extensively used to monitor, operate, and/or control equipment, infrastructure, and their associated devices (e.g., power generation and distribution, air conditioning, water and wastewater plants, natural gas distribution).
1.1.1.1. A control system is a collection of technological components that monitor, manage, and/or control the behavior of people, devices, and systems. Control systems can take various forms according to size, complexity, function, or configuration. Some types of control systems may exist as building automation systems, energy management control systems, or industrial control systems.
Typically, they consist of components that can be categorized as inputs, controllers, actuators, sensors, and outputs.
1.1.2. Control systems support nearly all aspects of DAF core mission areas; by extension, if the control systems can be compromised, so can the mission(s) they support.
Unmitigated vulnerabilities can be exploited by adversaries, (1) potentially leading to mission failure, extended operational impacts, and physical damage to critical infrastructure, and/or (2) providing an attack vector into the broader Air Force
Information Network and business systems.
1 “Operational Technology is defined in National Institute of Standards and Technology Special Publication (NIST SP) 800-37r2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and
Privacy, Dec. 2018 (pg. 101).
2 Defined as, “a system in which deliberate guidance or manipulation is used to achieve a prescribed value for a variable. Control
Systems include [supervisory control and data acquisition (SCADA) systems], [distributed control systems (DCS)], [programmable logic controllers (PLC)] and other types of industrial measurement and control systems.” [NIST SP 800-82r2, May 2015]
4 DAFGM2023-32-01 JUNE 2023
Figure 1: Terminology
1.1.3. The difference between information technology (IT) and operational technology drives the approach of control system cybersecurity to prioritize and enable the continued availability, operational functionality, and integrity of these systems, slightly above the protection/confidentiality of their transmitted data and information. While security principles are well-defined for IT, these principles are not consistently tailored to or implemented across control systems. Security controls and solutions applied to control systems environments should be: (1) extensive without sacrificing control systems performance and reliability, (2) tailored to the specific control systems environment, (3) verified to ensure control systems continues to operate as intended in a cyber contested environment and (4) effective against today’s threats.
1.1.4. Because of the increased reliance on systems within cyberspace under the Civil
Engineer portfolio, the Civil Engineer community is a stakeholder (along with mission owners and cyber defenders) in mitigating the rising threats to infrastructure and supporting control systems as part of Civil Engineers’ mission to establish, operate, maintain, and protect installations. Cyber risk management has become a critical element of Civil Engineers’ efforts to ensure infrastructure is always available to support the DAF mission.
1.2. Scope. This Guidance Memorandum supplements existing policies, such as Department of
Defense Instruction (DoDI) 8500.01 Cybersecurity, DoD’s RMF (outlined in DoDI 8510.01,)
DoDI 8530 Cybersecurity Activities Support to DoD Information Network Operations, UFC 4-
010-06 Cybersecurity of Facility Related Control Systems, and AFI 17-101, Risk Management
Framework (RMF) for Air Force Information Technology (IT)), by providing more explanatory guidance on security measures and responsibility specifically for control systems.
Per the Department of the Air Force Chief Information Security Officer’s (CISO) (SAF/CNZ)
Authorizing Official (AO) appointment letter as required by AFI 17-101, the CE Control System boundary includes DAF CE-owned control systems as well as IT that directly supports the operation, maintenance, and security of the logically-segmented, CE control systems network enclave (e.g., Community of Interest Network (COIN)). The authorization boundary includes, but is not limited to, the following types of systems (and their associated points, devices, components, equipment, control panels, means of connectivity, software, controllers, workstations, servers, etc.):
1.2.1. Supervisory Control and Data Acquisition systems
1.2.1.1. Protective relays (microprocessor-based)
1.2.1.2. Cathodic protection systems
1.2.1.3. Natural gas distribution systems
1.2.1.4. Power generation systems, including renewable systems
1.2.1.5. Water/wastewater distribution systems
1.2.1.6. Water/wastewater treatment systems
1.2.2. Building Automation Systems
1.2.2.1. Energy Management Control Systems
1.2.2.3 Heating Ventilation & Air Conditioning
1.2.2.3. Advanced Meter Reading Systems
1.2.2.4. Interior/exterior lighting controls
Attachment 4
FA301024R0007
http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf
DAFGM2023-32-01 JUNE 2023 5
1.2.3. Life Safety systems3
1.2.3.1. Fire Alarm Reporting Systems
1.2.3.2. Fire Suppression Systems
1.2.3.3. Facility Mass Notification Systems
1.2.4. Utility Monitoring and Control Systems
1.2.4.1. Electrical distribution systems
1.2.4.2. Generator monitoring systems
1.2.4.3. Uninterrupted Power Supply system
1.2.4.3. Electrical Vehicle Supply Equipment
1.2.5. Airfield Control Systems
1.2.5.1. Airfield Lighting Control Systems4
1.2.5.2. Aircraft Arresting Systems
1.2.5.3. Runway Ice Detection Systems
1.2.5.4. Bird Scare System
1.2.5.5. Ramp Lighting control systems
1.2.6. Traffic Control Systems
1.2.6.1. Drop-arm barriers
1.2.6.2. Pop-up barriers
1.2.6.3. Traffic signal systems
1.2.7. Intrusion Detection Systems5
1.2.7.1. Closed-Circuit Television (CCTV) Systems
1.2.7.2. Digital Video Management Systems
1.2.7.3. Electronic Security Systems
1.2.8. CE control systems network enclave (e.g., COIN)
1.2.9. The Civil Engineer control systems boundary does not include:
1.2.9.1. Systems in the CE IT and CE Platforms boundaries (e.g., NexGen IT, BUILDER, survey equipment, Explosive Ordnance Disposal (EOD) robots, Research, Development, Test & Evaluation (RDT&E) equipment, unmanned aerial systems (UAS)).
1.2.9.2. Control systems such as those contained in other organizations (e.g., force protection, depots, nuclear, medical) as well as control systems embedded in weapons systems/platforms.
3 Life Safety systems are control systems that must function reliably, safely, and meet applicable codes and standards. Life
Safety systems protect personnel against undue risk of fire, environmental, and/or other hazards that could potentially result in loss of life.
4 Airfield Lighting systems are control systems that must function reliably, safely, and meet applicable codes and standards.
Airfield lighting systems protect personnel against undue risk of fire, environmental, and/or other hazards that could potentially result in loss of life.
5 Most of these systems fall within Security Forces ownership; however, this Memorandum applies to those that fall within Civil
Engineer ownership.
6 DAFGM2023-32-01 JUNE 2023
Chapter 2
ROLES AND RESPONSIBILITIES
2.1. Technical Director-Control Systems Cybersecurity Department of the Air Force. Serves as the Department of the Air Force (DAF) Director of critical infrastructure and control systems’ cybersecurity and cyber resilience, providing technical oversight for world-wide operations of
USAF and USSF objectives, and provides direction and recommended actions on matters pertaining to formulation, review and execution of plans, policies, technical capabilities and programs related to the entire spectrum of control systems activities across the DAF. (T-1).
2.2. Chief Information Security Officer (CISO), SAF/CNZ. Develops, implements, maintains, and enforces the DAF Cybersecurity Program and the RMF process, roles, and responsibilities.
Serves as the DAF Risk Executive ensuring individual system risk reflects organizational risk tolerance and is considered along with other risk affecting mission/business success IAW AFI 17-
130, and NIST SP 800-39, Managing Information Security Risk.
2.3. The Director of Civil Engineers (AF/A4C). Responsible for organizing, training, and equipping the engineering force along with providing policy, strategy, oversight, and resource advocacy for Civil Engineer portfolio responsibilities (to include control systems cybersecurity).
(T-1).
2.4. Air Force Installation and Mission Support Center (AFIMSC). AFIMSC/RM (Resource
Management Directorate) develops the funding line and distributes funding for execution.
Coordinates with SAF/CN to ensure the cybersecurity risk posture, risk tolerance levels, and risk acceptance decisions for DAF systems meet mission and business needs (T-1).
2.5. Authorizing Official (AO). Appointed by SAF/CN and responsible for all roles listed in
AFI 17-101 para 3.3, including managing the risk of control systems and tailoring controls to balance security and mission needs. (T-1).
2.6. Authorizing Official Designated Representative (AODR). Appointed by the AO and responsible for all roles listed in AFI 17-101 para 3.5 including CE Control System asset portfolio oversight and management (including cybersecurity requirements) via the Facility
Operations Enterprise Manager, reviewing and validating annual requirements for OAC18 funding and distributes funding based on availability, and performing Program Objective
Memorandum (POM) duties including interaction with AF/A4P. (T-1).
2.7. Security Controls Assessor (SCA). Appointed by the CISO and responsible for all roles listed in AFI 17-101 para 3.6, including supporting the AO in making assessment determinations and authorization recommendations. (T-1).
2.8. Security Controls Assessor Representative (SCAR). Appointed by SCA per AFI 17-101, Table 3.1, and responsible for fulfilling duties under the SCA’s direction. (T-1).
2.9. Air Force Civil Engineer Center (AFCEC).
2.9.1. AFCEC will ensure incorporation of cybersecurity requirements and costs into all phases of each Directorate’s activities and products (see para 3.3). This shall include, but is not limited to, a review process on the effectiveness of holding design agents accountable for AFCEC-managed requirements. (T-1).
2.9.2. AFCEC/COO (Operations Maintenance Division) will provide technical and
Attachment 4
FA301024R0007
DAFGM2023-32-01 JUNE 2023 7
“execution” guidance to CE units on control systems cybersecurity activities to supplement this DAFGM, to include, but not limited to, the subject-matter in this DAFGM (e.g., paras
2.8.3, 2.8.5, 2.10.3, 2.10.4, 3.1). (T-1).
2.9.3. Pertaining to RMF-related duties, AFCEC/COO is the execution organization directly supporting the AO to enable and facilitate the RMF process and assists CE units in that process for CE control systems. AFCEC/COO shall:
2.9.3.1. Support RMF authorization processes in the Civil Engineer enterprise for control systems aligned with RMF roles (para 2.3-2.6, 2.9-2.12), para 3.2.1, and para
3.5.1 in coordination with the AO. (T-1).
2.9.3.2. Perform RMF activities: establish Security Control Baseline, validate
Authorization to Operate (ATO) packages for SCA review and AO signature, process entries into Enterprise Mission Assurance Support Service (eMASS), and oversee and track CE unit’s continuous monitoring program and mitigation of identified vulnerabilities in RMF Plans of Actions and Milestones (POA&Ms). (T-1).
2.9.3.3. Maintain “RMF continuous monitoring plan” template and determine “RMF continuous monitoring” control set (both approved by the AODR) that installations can leverage for each control system’s continuous monitoring plan (per para 3.5.1). (T-1).
2.9.4. AFCEC/COO will assist installations in completing the following:
2.9.4.1. Perform local RMF activities: conduct system testing, review each system’s
RMF continuous monitoring plan, identify mitigations, and process entries into eMASS.
(T-2).
2.9.4.2. In coordination with the installation’s Comm/Cyber unit, install a control systems network enclave (see para 3.4) when requested at the installation-level (only control systems to be entered into Information Technology Investment Portfolio Suite
(ITIPS) are hybrid systems). (T-1).
2.9.4.3. In coordination with the installation’s Civil Engineer unit, ISO, Comm/Cyber unit, and system vendor, migrate (when appropriate) AO-approved control systems into the installed control systems network enclave in a prioritized manner (see para 3.4). (T-
1).
2.9.5. AFCEC/COO is responsible for providing a standardized template and necessary guidance to installations to collect a CE-enterprise inventory of control systems (see para
3.1). (T-1).
2.10. Base Civil Engineer (BCE). Establish a Control System Program that is responsible for maintaining the operations, obtaining resources and ensuring the cybersecurity posture of control systems at the installation (T-1). The Base Civil Engineer shall ensure:
2.10.1. An Information System Owner (ISO) is appointed for installation-level control systems per AFI 17-101 para 1.2.5, since control systems are not centrally managed. (T-2).
2.10.1.1. Identify an ISO for control systems prior to the current ISO vacating the position. (T-3).
2.10.1.2. Provide AFCEC/COO the names of current control system ISO(s) (see para
2.8.1) and Information Security System Manager(s) (ISSM) (see para 2.9.8). (T-3).
2.10.2. Mitigation / remediation actions of identified cyber vulnerabilities for CE-owned control systems (e.g., through regular patching of systems and/or maintenance, sustainment, modernization, or replacement activities and projects) will be delivered in a
Attachment 4
8 DAFGM2023-32-01 JUNE 2023
timely manner. (refer to paras 3.2.2, 3.3., 3.6-3.12, and 4.1-4.6). (T-1).
2.10.3. Coordination to provide physical and IT administrative access to the necessary facilities and systems required to support approved control systems cybersecurity activities
(e.g., assessments, mitigation, data collection, inventory, etc.). (T-3).
2.10.4. Inventory of installation-level control systems is current, accurate, and collected no less than annually (see para 3.1). (T-2).
2.10.5. Incident Response and System Recovery/Contingency Plans are in place as outlined in para 4.7. (T-3).
2.10.6. Personnel have a depth of knowledge regarding control system(s) and associated forms of connectivity to avoid a single individual from being single point of failure. (T-3).
2.10.7. AO-approved control systems are migrated into the CE network enclave. (T-1).
2.11. Information System Owner (ISO).
2.11.1. Ensure execution of the ISO and Program Manager (PM) responsibilities are satisfied for CE-owned control systems per AFI 17-1016 paras 3.9 and 3.10. (T-2).
2.11.2. Maintain cross-organizational awareness of acquisition, installation, maintenance, and security posture of CE-owned control systems. (T-3).
2.11.3. Follow the RMF authorization process identified by the AO (para 3.2) for control systems. (T-2).
2.11.4. Ensure establishment of the security control baseline for each system per
AFCEC/COO guidance. (T-2).
2.11.5. Ensure policies in this Memorandum are satisfied. (T-1).
2.11.6. Ensure CE Project Support Agreement (PSA) requirements for deploying control systems network enclave (refer to para 3.4.2) are satisfied within 60 days of initiation, including physical, connectivity, and configuration requirements. (T-3).
2.11.7. Facilitate RMF, CE network enclave deployment, and system migration activities at the installation-level for control systems as outlined in para 2.8.3. (T-2).
2.10.8. Appoint an ISSM at the installation for control systems to support and assist the ISO per IAW DoDI 8510.01 (T-0) for the program office and ensure the ISSM is certified IAW
AFMAN 17-1303. (T-1).
2.11.9. Ensure the Control System Program Report (CPR) is reviewed monthly, and document corrective actions taken. (T-1).
2.11.10. Meet with the ISSM (and ISSO) at regular interval to discuss RMF status and other related activities as well as review vulnerabilities and suggested mitigations resulting from any assessments that have been conducted. (T-1).
2.12. Information System Security Manager (ISSM).
2.12.1. Appointed per para 2.10.8, and ensure the ISSM responsibilities are satisfied for
6 There is not currently nor is there intended to be a centralized program management office (PMO/PEO/PO) for control systems in the Department of the Air Force; in turn, “those Program Manager duties specified in AFI 17-101, Para 3.10.2 cannot be fulfilled.”
Attachment 4
DAFGM2023-32-01 JUNE 2023 9
CE-owned control systems per AFI 17-101 para 3.12. (T-1).
2.12.2. Support the ISO in ensuring the policies in this Memorandum are satisfied. (T-1).
2.12.3. Perform RMF activities: process entries into Enterprise Mission Assurance Support
Service (eMASS), perform the CE unit’s continuous monitoring program, and accomplish and track mitigations of identified vulnerabilities in RMF Plans of Actions and Milestones
(POA&Ms). (T-1).
2.12.4. Meet with the ISO (and ISSO) at regular interval to discuss RMF status and other related activities as well as review vulnerabilities and suggested mitigations resulting from any assessments that have been conducted. (T-1).
2.13. Information System Security Officer (ISSO).
2.13.1. Ensure the ISSO responsibilities are satisfied for CE-owned control systems per AFI
17-101 para 3.13. (T-3).
2.13.2. Support the ISO and ISSM in ensuring the policies in this Memorandum are satisfied. (T-3).
2.14. User Representative (UR) / System Operator.
2.14.1. Ensures the UR responsibilities are satisfied for CE-owned control systems per AFI
17-101 para 3.16.7 (T-3).
2.14.2. Support ISO, ISSM, and ISSO at the installation-level in ensuring the policies in this Memorandum are satisfied. (T-3).
2.15. Air National Guard and Air Force Reserve. HQ NGB/A4 and HQ AFRC/A4 will provide support and supplemental guidance as required for CE control systems under NGB and
AFRC responsibility. (T-1).
2.16. 16th Air force. Develops and implements appropriate activities to monitor and report on the occurrence of cybersecurity events, cybersecurity implementation, and risk management. (T-1).
2.16.1. Guides cybersecurity and control systems experts to detect, mitigate, and recover from malicious cyber activity and carries out responsibilities described in Section 3.5.2 below. (T-1).
2.17. A3 Mission Assurance. Facilitate the coordination and collaboration of AF Mission
Assurance (MA), utilizing the MA Construct to identify, assess, and manage cyber-related risks that endanger strategic mission execution.
2.17.1 Synchronize AF/A4CS, Systems & Data Division with appropriate level of AF MA forum.
2.17.2. Collaborate with AF/A4CS to ensure an inventory of all hardware, software, and related control systems task critical assets (TCA) are reflected in MRT-C mapping. (T-1).
2.18. AF/A2/6. Identifies the capability and intent of specific threats to cause loss or damage to
Defense Critical Infrastructure (DCI) and assess the likelihood that such threats will be carried out.
(T-1).
7 By nature, the UR/System Operator may commonly exist through established positions within the Operations Flight (e.g., shop supervisor, technician, etc.).
Attachment 4
FA301024R0007
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf
10 DAFGM2023-32-01 JUNE 2023
2.18.1. Makes intelligence-based indications and warning information related to DCI available. (T-1).
2.18.2. Identifies counterintelligence and security measures to mitigate risks and protect
DCI. (T-1).
DAFGM2023-32-01 JUNE 2023 11
Chapter 3
CYBERSECURITY IMPLEMENTATION
3.1. Control Systems Inventory. Civil Engineer units shall annually conduct and continuously maintain accurate inventories of all the installation’s CE-owned control systems and associated components and devices. (T-0) All identified hardware and software shall be assigned a unique identifier.
3.1.1. Use of the AFCEC/COO provided inventory template and process (located on CE
Dash) is required and all applicable fields must be appropriately completed (see para
2.8.5). (T-1). The inventory shall contain each instance of a control system (per the types listed in para 1.2) at the installation down to topology Level 2 - Field Control System (IP) 8 in the Purdue Model (as defined in the control system architecture topology diagram and definitions in Unified Facilities Criteria (UFC) 4-010-06, Appendix E). Each instance shall include but is not limited to: assigned IP addresses, MAC addresses, serial number, firmware and software versions, physical location, if applicable. (T-1).
3.1.2. The ISO, ISSM, and/or ISSO shall document any new systems or system modifications and configuration changes (per para 3.9), including but not limited: to install date, version, location, applied patches and updates in the installation’s control systems inventory per NIST SP 800-53r5 para 3.5 and this Guidance Memorandum’s para 3.1. (T-
1).
3.1.3. CE units shall maintain a baseline understanding of which control systems are mission critical. From the installation’s inventory of CE-owned control systems, CE units shall, in coordination with local MA representative and/or mission owners, identify, prioritize, and document those control systems deemed critical for mission(s) execution9
(e.g., directly, or indirectly enable Task Critical Assets (TCA), weapons systems, Mission
Essential Functions (MEF), or locally identified critical missions on base).10 Update the priority list as mission requirements evolve. For new and existing mission critical facilities that are dependent upon CE control systems, design or renovate systems to operate in manual override mode in compliance with UFC 4-010-06 Section 4.2.2.
Degraded Operation. (T-1).
3.1.4. If a control system meets one or more of the statutorily of defined National
Security System (NSS) criteria it is considered an NSS. Further information can be found in Executive Order (EO) 14028, National Security Memorandum 8, and the National
Manager issuance Identification and Inventory of National Security Systems Guidance
(NMM-2022-05.) DoD enclaves intended to support Facility Related Control Systems are considered NSS IAW EO 14028, DoDI 5200.44 and CJCSI 6211.02D. (T-1).
3.1.5. Real Property Designation. CE control systems11 and their associated components and devices may be considered Real Property Installed Equipment (RPIE). To determine if the control system is considered RPIE, use the components list associated to the category code of the facility found in the Real Property Category Code (CATCODE) Book
(https://usaf.dps.mil/teams/10758/citcatcode/module/home.aspx). For more information on
8 Reference Figure E-1 (pg. 45), UFC 4-010-06, Cybersecurity of Facility-Related Control Systems.
9 Further guidance specific to CE control systems deemed “critical” to mission is forthcoming.
10 Refer to Defense Critical Infrastructure (DCI) Line of Effort (LOE) Security Classification Guide (SCG) (27 Jul 2018) and forthcoming Classification Guide for Control Systems (CS) for guidance on security classification of such information.
11 Note that some CE control systems (e.g., automatic door-locks) do not qualify as RPIE.
Attachment 4
FA301024R0007
https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06 https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf https://usaf.dps.mil/teams/10758/citcatcode/module/home.aspx
12 DAFGM2023-32-01 JUNE 2023
RPIE, refer to DAFI 32-9005.
3.1.5.1. If a control system is not found in the CATCODE Book or if unsure of RPIE designation, submit a request to AFCEC.CIT-.A@us.af.mil.
3.2. Mitigating Identified Vulnerabilities & Accepting Risk.
3.2.1. Risk Management Framework (RMF).
3.2.1.1. Civil Engineer units are required to follow RMF and fulfill ATO requirements for authorization of control systems (outlined in para 2.8.3.1 and DAF RMF policy, AFI 17-101). (T-0).
3.2.1.2. Civil Engineer units shall use eMASS for initiating, submitting, tracking, and updating all RMF artifacts. (T-1).
3.2.1.3. All newly initiated authorization packages (e.g., ATO, IATT, DATO, ATC, etc.) for control systems shall be aligned with RMF, as outlined in para 2.7.8.1. (T-0).
3.2.1.4. Civil Engineer units must adhere to the “Civil engineer (CE) Facility Related
Control System (FRCS) Baseline Security Controls” memorandum stating CE units shall perform, at a minimum, the tailored security controls for CE FRCS that are based on functional security groups. (T-2). Expanding upon the minimum requirements, units should execute additional controls based on emerging adversarial threats and DAF mission requirements. (T-3).
3.2.1.5. Control systems determined to be NSS (refer to para 3.1.4) shall have a default
RMF categorization of M-M-M (Moderate-Moderate-Moderate) for Availability, Integrity, and Confidentiality. (T-2). Any deviations up or down (e.g., L-M-M, M-H-
H) from the default categorization require justification and authorization through the
RMF Step 1 categorization process. (T-2).
3.2.1.6. Shall comply with all requirements in DoDI 8510.01 Risk Management
Framework for DoD Systems. (T-2).
3.2.1.7. For RMF continuous monitoring, verification of security controls, and RMF authorization packages, in accordance with para 3.5.1.
3.2.1.8. Refer to Chapter 2 for the RMF responsibilities translated for control systems.
3.2.2. Identifying Vulnerabilities & Mitigations.
3.2.2.1. Identify vulnerabilities from published sources (e.g., RMF assessments, CVE database, Notices to Airmen (NOTAM), joint mission assurance assessments (JMAA), self-assessments, CISA Stakeholder-Specific Vulnerability Categorization (SSVC), etc.
to include all cybersecurity assessments sponsored by government agencies)) and determine the applicability to installation’s hardware and software inventories and discover associated risks to the control system. Develop a local plan to correct the vulnerabilities identified. Additionally, utilize the Vulnerability Exploitability
Exchange (VEX) to communicate whether a product is affected by a vulnerability and enable prioritized vulnerability response (T-3).
3.2.2.1.1. Reference vendor recommended mitigations, where feasible. (T-3).
3.2.2.1.2. To self-assess cyber risks to CE-owned control systems, follow the process in RAND’s Assessing Cybersecurity Risk to CE Infrastructure (pgs. 11-
22) (https://www.milsuite.mil/book/docs/DOC-1024779). (T-3).
3.2.2.2. Capture all identified vulnerabilities and their associated risks in the control
Attachment 4
FA301024R0007
mailto:AFCEC.CIT-.A@us.af.mil
DAFGM2023-32-01 JUNE 2023 13
system’s authorization package and associated POA&M (refer to para 3.2.1). (T-2).
3.2.2.3. Prioritize mitigations to critical vulnerabilities affecting mission critical systems (refer to para 3.1.3). (T-2).
3.2.2.4. Shall use PE 27478F for FRCS hardware / software replacement and cyber training activities to include facility servers, workstations, computers, laptops, tablets. Reference FY23 IMSC Execution Plan Guidance and CE IT Investment
Matrix for details. (T-1)
3.3. Construction, Repair, or Energy Contract Requirements
3.3.1. The Civil Engineer unit and AFCEC must ensure design agents and vendors create and implement control systems in accordance with this DAFGM. (T-3). The local CE control systems ISO shall review and validate requirements from a control systems cybersecurity perspective prior to contract award. CE units should reference the requirements outlined in the Control Systems Cyber Defense Reference Architecture (CSCRDA) when designing control system and network environments, writing contracts, etc. (T-3).
3.3.1.1. For any new acquisition or replacement of control systems or their associated devices at a Level 2 - Field Control System (IP) of the Purdue Model or above (as defined by UFC 4-010-06), consult AFCEC/COO for design reviews, proposals, quotes, statements of work, etc. (T-3).
3.3.2. Performance Contracts (ESPC), Utility Energy Service Contracts (UESC), microgrids, Environmental Security Technology Certification Programs (ESTCP), Advanced Meter Reading Systems (AMRS), etc.) shall follow existing standards and policies to incorporate cybersecurity and associated costs into all phases of delivery. These phases include contract language12, design, development, test and evaluation, integration, execution, construction, operation, maintenance, sustainment, upgrade, or replacement. (T-
0). These existing standards and policies include: Defense Federal Acquisition Regulation
Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and
Cyber Incident Reporting, this Guidance Memorandum, UFC 4-010-06, AF/A4CF Business
Rules for MILCON Program Packages and Preparing the DD Form 1391 & 1390 para
9.1.1.3, NIST SP 800-82r2, NIST SP 800-53r5, and the best practices from the Department of Homeland Security (DHS)’s Cyber Security Procurement Language for Control Systems
(https://www.us-cert.gov/sites/default/files/documents/Procurement_Language_
Rev4_100809_S508C.pdf).
3.3.3. Ensure contract language requires newly acquired and/or substantially upgraded control systems to use open protocols and standards to maximize data interoperability in accordance with UFC 3-410-02, Direct Digital Control for HVAC and Other Building
Control Systems, and in alignment with industry best practices. (T-0). In order to prevent the government from being locked into a single vendor solution, the acquisition of proprietary systems, protocols, and standards is prohibited. (T-2).
3.3.4 Ensure contract language mandates machine-readable data structured formats (e.g., CSV, RDF, XML, JSON) to enable maximum data collection, centralization, and integration. (T-1).
3.3.5. Ensure contract language requires data interconnectivity capability for secure
12 This includes, but is not limited to, clearly articulating the contractor’s cybersecurity responsibilities in contract language requirements, including all required cybersecurity clauses in contracts, and considering cybersecurity specialty clauses.
Attachment 4
FA301024R0007
https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06 https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06
14 DAFGM2023-32-01 JUNE 2023
communication protocols (e.g., SSH, File Transfer Protocol (SFTP,) etc.). (T-1).
3.3.6. Ensure contract language accounts for the security of data in transit and at rest through use of industry best practices (e.g., encryption, firewalls, etc.). (T-3).
3.3.7. Ensure contract language requires the use of government-owned assets (or government furnished equipment (GFE)) (e.g., computer, tablet) for control systems maintenance. (T-0).
3.3.8. Ensure contract language requires on-site maintenance (see para 3.10). (T-2).
3.3.9. Ensure contract language prohibits the connection of removable media (refer to para
3.12) to a control system or control systems network enclave other than as described in para
3.10.6. (T-3).
3.3.10. Ensure contract language requires compliance with vulnerability scanning standards stated in UFGS-25 05 11, Cybersecurity for Facility-Related Control Systems, para 3.11.
(T-1).
3.3.11. Ensure contract language requires the vendor(s) to provide (1) copies of operator, administrator, and maintenance manuals, (2) copies of the system’s topology, hardware/ software inventory, and configuration, (3) training and associated materials, as well as (4) any third-party validation/standardization (e.g., Common Criteria, ISO-9000, etc.) testing results. (T-3).
3.3.12. Ensure contract language requires the vendor(s) to perform an initial security assessment, scan vulnerabilities, provide a copy of the scan results, and recommend and document mitigations for identified vulnerabilities prior to actions specified in para 3.3.15.
(T-3).
3.3.13 Ensure contract language requires vendors to remove and dispose of control systems and their components once no longer deemed necessary or decommissioned. (T-3).
3.3.14 Adjust contract language to include labeling (i.e., unique nomenclature) of hardware and associated components (e.g., cables, ports, servers, etc.) and implement this requirement into new or renewal contracts. (T-3).
3.3.15. Before a control system becomes operational (e.g., begins processing data, supporting mission, supporting facility operations), CE units, under direction of the ISO, must receive an authorization decision document and shall:
3.3.15.1. Ensure initial system authorization under RMF process is adequately resourced (e.g., staffing, funding, vendor artifacts, etc.). (T-3).
3.3.15.2. Mitigate all identified vulnerabilities that do not require additional funding.
For the remaining vulnerabilities, create POA&M’s that state the course of action for addressing remaining mitigation efforts that incur a cost. (T-3).
3.3.15.3. Prioritize, plan, budget, and execute all required mitigations. (T-3).
3.3.15.4. Provide sufficient documentation (refer to AFI 17-101 para 4.3.8) for the
DAF to finalize the authorization of the control system (refer to para 3.2). (T-3).
3.3.15.5. When appropriate, plan to utilize the existing CE control systems network enclave (refer to paras 3.4.2 and 3.4.4). (T-1).
3.3.16. Add newly installed or acquired control systems to the installation’s inventory (para
3.1). (T-0).
DAFGM2023-32-01 JUNE 2023 15
3.3.17. Additionally, Utilities Privatization contracts shall include the DFARS 252.204-
7012 clause and follow standards specified in NIST SP 800-171r1, DoDI 4170.11, and additional cybersecurity direction stated in the Office of the Under Secretary of Defense for
Acquisition and Sustainment (OUSD (A&S)) memos: Supplemental Guidance for the
Utilities Privatization Program (07 Feb 2019) and Interim Defense Federal Acquisition
Regulation Supplement Rule, 2019-D041, Assessing Contractor Implementation of
Cybersecurity Requirements (guidance for utilities privatization) (Nov 2020). (T-0).
3.3.18. For energy projects, follow cybersecurity guidance stated in the Office of the
Assistant Secretary of Defense for Energy, Installations, and Environment (OASD (EI&E)) memo Installation Energy Plans – Energy Resilience and Cybersecurity Update, 30 May
2018. (T-0).
3.3.19. Reference the Control Systems Cyber Defense Reference Architecture (CSCDRA) section 5 “Requirements” for more information.
3.4. Connectivity. Control systems rely on multiple forms of connectivity for uninterrupted operation of the system. For instance, many control systems rely on the Air Force Information
Network, its inherited enterprise services, and a variety of other forms of connectivity for uninterrupted operation of the system. CE units shall aim to consolidate all control systems into a single connectivity architecture. (T-1). Recognizing the disparate system requirements and connectivity landscape, adhere to the tiered approach outlined in this paragraph. All control systems not in the current state (para 3.4.1), protected by a control systems network enclave
(para 3.4.2), or approved through exemption (para 3.4.3) are subject to disconnection from the network.
3.4.1. Current State.
3.4.1.1. Until AFCEC/COO installs a control systems network enclave (para 3.4.2) at the installation, the Civil Engineer unit will monitor their systems’ security controls.
(T-3). To prepare for the network enclave deployment and the migration of control systems into the enclave, all control systems shall go through the “assess only” or
“assess and authorize” process (see para 3.2). (T-3).
3.4.1.2. Once the network enclave is deployed at the installation, follow the policy stated in paras 3.4.2 and 3.4.4. (T-1).
3.4.1.3. Do not connect CE control systems to the SIPRNet or NIPRNet. (T-3).
3.4.2. Network Enclave. In a prioritized manner (based on mission(s) criticality and dependencies of control systems), and in coordination with the local Comm/Cyber unit, AFCEC/COO shall deploy installation-level control systems network enclaves. Through the SAF/CN-appointed authorization boundary, the Civil Engineers have designed type-authorized, AO-sanctioned control systems network enclaves. These enclaves logically segregate control systems on the Air Force Information Network to provide secure access to enterprise services and a defendable and monitored network environment for control systems to operate. (T-1).
3.4.2.1. Leverage existing base Comm infrastructure for the deployment of the network enclave (see para 3.4.3 for exceptions). (T-1).
3.4.2.2. If a control systems network enclave has been deployed to an installation:
3.4.2.2.1. AO-approved control systems (see para 3.2) shall (1)) be segmented from all other connectivity and (2) be migrated into the control system network enclave under direction of the ISO (see para 2.9.7) in coordination with the
Attachment 4
FA301024R0007
https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r1.pdf https://www.acq.osd.mil/dodsc/library/dodi-4170-11-installation.pdf
16 DAFGM2023-32-01 JUNE 2023
installation’s Comm/Cyber unit, AFCEC/COO, and system vendor. (T-2).
3.4.2.2.2. The Civil Engineer unit, specifically the ISO, ISSM, and ISSO (paras
2.9 - 2.11), shall continue to monitor their systems’ security controls. (T-3).
3.4.2.3. If a control systems network enclave has not been deployed to an installation, adhere to the policy outlined in para 3.4.1. (T-1).
3.4.3. Exceptions. If there is a need to have a different form of connectivity other than the control systems network enclave (para 3.4.2) due to the function of the system or mission criticality concerns, the owner shall submit a justification to AFCEC/COO for AO approval. (T-2). An exception may also be directed at the AO’s discretion. Additionally, follow the criteria listed below:
3.4.3.1. Stand-alone systems. Stand-alone systems (refer to “stand-alone” definition in
Attachment 1) are those that do not interface with nor connect to other systems/networks. A system could remain stand-alone due to (1) mission criticality concerns, (2) existing vulnerabilities that cannot be mitigated, or (3) if the control system is a Life Safety system (para 1.2.3) or a system that is determined not technically feasible to migrate into the CE control systems network enclave.
3.4.3.1.1. Provide security, system administration, and authorization for stand-alone systems per DoDI 8510.01 and AFI 17-101. (T-3).
3.4.3.1.2. Implement a RMF continuous monitoring strategy for the system’s security controls, as outlined in para 3.5.1, as part of the authorization requirement. (T-3).
3.4.3.2. Stand-alone networks. Where stand-alone network architecture is approved for control systems, DAF CIO requirements for network security, security protections, and Defensive Cyber Operations (DCO) continuous monitoring (refer to para 3.5.2) shall still be provided by the installation’s stand-alone network design and the network administrator. (T-1).
3.4.3.3. Modems. Remove uncontrolled public access to dial-up modems. Modem connections to the AFIN require DAF Enterprise AO (ACC/A6) approval and an
Approval to Connect (ATC) per AFI 17-101. Modem connections to any other network or network enclave require approval by the owning AO. (T-1).
3.4.3.4. Wireless Communications/Radio Frequency (e.g., Wi-Fi, cellular, Bluetooth, satellite). Using unlicensed frequencies under Federal Communications
Commission Title 47 Part 15 is not allowed. (T-0). Do not procure new control systems using a Part 15 radio frequency device. (T-0). OCONUS installations shall also comply with applicable Host Nation rules, laws, policies, and agreements. (T-0).
Verify radio frequency spectrum certification compliance with the installation’s
Spectrum Manager for any radio frequency devices currently in use. (T-2). Per DoDI
8420.01, Commercial Wireless Local-Area Network (WLAN) Devices, Systems, and
Technologies, DoD requires non-licensed devices operating in the United States and their possessions to be registered with the local spectrum management office. (T-0).
When purchasing new devices, also follow para 3.3. (T-1).
3.4.3.4.1. A wired infrastructure is more secure than one that uses wireless technologies, therefore convert radio frequency networks to wired or fiber where possible. If (1) an existing control system needs to continue using radio frequency devices to transmit and/or receive data or (2) a control system not owned by the
Attachment 4
FA301024R0007
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf https://www.ecfr.gov/cgi-bin/text-idx?SID=1b3056c426adb49468b037e29ac87950&mc=true&node=pt47.1.15&rgn=div5 https://www.ecfr.gov/cgi-bin/text-idx?SID=1b3056c426adb49468b037e29ac87950&mc=true&node=pt47.1.15&rgn=div5 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313
DAFGM2023-32-01 JUNE 2023 17
installation requires radio frequency (e.g., cellular tower leasing), ensure the system complies with DAFI 17-220, Spectrum Management, uses dedicated frequencies per National Telecommunications Information Administration
Chapter 7 and Chapter 4, and is approved by the installation’s Spectrum Manager before seeking a waiver approval. (T-1).
3.4.3.4.2. Check radio frequency devices to ensure data transmission is encrypted
“end-to-end” over an assured channel; the device is aligned to the sensitivity of the data; and the device is validated under the “Cryptographic Module Validation
Program” specified in FIPS PUB 140-3, Security Requirements for Cryptographic
Modules, Overall Level 1 or Level 2, as dictated by the data’s sensitivity. (T-1).
3.4.3.4.3. Any data transmitted by Wi-Fi devices, services, and technologies shall follow IEEE Standard 802.11-2016 per DoD Directive (DoDD) 8100.02, DoDI
8420.01 and DHS’s Guide to Securing Networks for Wi-Fi (https://www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing
_Networks_for_Wi-Fi.pdf). (T-0).
3.4.3.4.4. Authorization will not be granted for control systems using Bluetooth.
(T-2).
3.4.3.4.5. For all other use of radio frequency, approval is required before the purchase, testing, deployment, and usage of the system. (T-3).
3.4.3.5. Commercial Internet & Services. Control system devices should be configured to only utilize private IP addresses. All commercial Internet connections are prohibited unless approved by the AO and the DoD Chief Information Officer has granted a DoD Information Network (DoDIN) waiver. (T-0). Unauthorized connections will result in a Denial of Authorization to Operate (DATO).
3.4.3.5.1. DoDIN Waiver Process. Under DoDI 8010.01 para 4.4 and Air Force
Manual (AFMAN) 17-2101 para 3.1.1, the DoD Chief Information Officer grants
DoDIN waivers for procurement and use of non-Defense Information Systems
Network (DISN) commercial services when in the best interest of the DoD and when Defense Information Systems Agency (DISA) services cannot support mission requirements. For further guidance on the waiver process, contact osd.pentagon.dod-cio.mbx.dcio-cs-ae@mail.mil.
3.4.4. Unnecessary Connectivity. Any form of connectivity or communication protocol that is not used, not necessary for the function of the system, and not explicitly approved shall be disabled in all components of the control system down to the end device. (T-1).
3.4.5. Encryption. Apply secure authentication and encryption protocols for data in transit and utilize encryption for data at rest and data in use (see para. 4.5.1) to the greatest extent possible without hindering functionality. (T-3).
3.5. Continuous Monitoring & Incident Response. There are two forms of continuous monitoring: RMF continuous monitoring & Defensive Cyber Operations (DCO) continuous monitoring for abnormal events/incidents.
3.5.1. RMF Continuous Monitoring. For RMF continuous monitoring, ISO, ISSM, and
ISSO system-level responsibilities for continuous monitoring are outlined by the RMF process (refer to para 3.2.1 and the “CE FRCS Baseline Security Controls” memorandum).
For instance, CE units shall regularly evaluate the RMF security controls of their control systems (e.g., checking (and if needed, modifying) how the security controls are
Attachment 4
FA301024R0007
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-220/afi17-220.pdf https://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook https://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf https://standards.ieee.org/findstds/standard/802.11-2016.html http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/810002p.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 https://www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing_Networks_for_Wi-Fi.pdf…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .