AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems.pdf

PDF 334 KB Posted

Attached to
OPERATIONAL TEST AND EVALUATION SERVICES (OTES) Federal contract opportunity
Solicitation number
FA7046-11-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems

View the file

Other files for this federal contract opportunity

Other files attached to OPERATIONAL TEST AND EVALUATION SERVICES (OTES), newest first.
File Type Posted
FA7046-11-R-0003-0004.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES_RFP_Amendment 2 - 14 Oct 11.doc DOC document
PWS TO_01_Nuclear_Space Amendment 2 - 14 Oct 11.docx DOCX document
OTES Final RFP-PPI QuestionsResponses 14 Oct 11.xls XLS spreadsheet
Section L Amendment 2 - 14 Oct 11.docx DOCX document
Amendment 1Section L 10-7.docx DOCX document
ppi_tool.accdb —
Amendment 1OTES_QASP 10-7.docx DOCX document
AFTECMAN99-101.pdf PDF
Amendment 1 PWS Oct 7.docx DOCX document
Amendment 1 RFP.doc DOC document
Form_4.pdf PDF
Form_6.pdf PDF
Form_2.pdf PDF
Form_1.pdf PDF
Form_2.xfdl XFDL file
Form_5.xfdl XFDL file
Final_ TO_02_Det_5_Bomber_Test_Division.docx DOCX document
Final_Sample_TO_03 JSPDS.docx DOCX document
Form_6.xfdl XFDL file
DRAFT OTES Responses.xlsx XLSX spreadsheet
form_1.xfdl XFDL file
Final_TO_01_Nuclear_Space.docx DOCX document
FINAL OTES_QASP.docx DOCX document
Source_Interested Parties List.xlsx XLSX spreadsheet
OTES PWS 25_ Jul_ 11_AFL_A.docx DOCX document
TO Nuclear Space 15_JUL_11_AFL.docx DOCX document
AFOTEC_99-101 _Conduct_of_Operational_Test_ _Evaluation.pdf PDF
OTES QASP 2 Aug 11.docx DOCX document
AFI_99-103 _Capabilities-based_Test_ _Evaluation.pdf PDF
Defense_Acquisition_Guidebook_(DAG).pdf PDF
DoD_Directive_5000.1 _The_Defense_Acquisition_System.pdf PDF
DoD_5400.7R _DoD_Freedom_of_Information_Act_(FOIA)_Program _AF_Supplement.pdf PDF
JSPDS Task Order 15_Jul_11_AFL.docx DOCX document
AFI_33-200 _Information_Assurance_Program.pdf PDF
OTES CDRLs 27 Jun 11.docx DOCX document
CJCS_Instruction_3170.01G_Joint_Capabilities_Intergration_ _Development_System.pdf PDF
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
AFI_16-1002 _Modeling_ _Simulation_(M S)_Support_to_Acquisition.pdf PDF
DoD_Instruction_5000.2 _Operation_of_the_Defense_Acquisition_System.pdf PDF
513408p CBRN DoD Implementation Directive.pdf PDF
AFOTEC_OT E_Guide _6th_Edition.pdf PDF
AFMAN_63-119 _Certification_of_System_Readiness_for_Dedicated_Operational_Test_ _Evaluation.pdf PDF
AFI_63-101 _Acquisition_ _Sustainment_Life_Cycle_Management.pdf PDF
DD254.docx DOCX document
AFOTEC_OT_of_IA_Guide _2nd_Edition.pdf PDF
DoD_Instruction_8500.2 _Information_Assurance_Implementation.pdf PDF
AFOTECPAM_99-104 _AFOTEC_Operational_Suitability_Test_ _Evaluation_Guide.pdf PDF
Show all 50

OPERATIONAL TEST AND EVALUATION SERVICES (OTES) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE INSTRUCTION 33-100

19 NOVEMBER 2008

Incorporating Change 1, 23 June 2009

Communications and Information

USER RESPONSIBILITIES AND GUIDANCE

FOR INFORMATION SYSTEMS

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available for downloading or ordering on the e-Publishing website at www.e-publishing.af.mil/.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/XCPP Certified by: SAF/XCP-2

(Col Robert Skinner)

Pages: 36

This instruction implements Air Force Policy Directive (AFPD) 33-1, Information Resources

Management, AFPD 33-2, Information Assurance (IA) Program, and identifies policies and procedures for the use of communications and information (C&I) systems/services and compliance requirements of Secretary of the Air Force, Chief of Warfighting Integration and

Chief Information Officer (SAF/XC) managed programs. These programs ensure availability, interoperability, and maintainability of C&I systems/services in support of Air Force mission readiness and warfighting capabilities. This publication applies to all military and civilian Air

Force personnel, members of the Air Force Reserve and Air National Guard, and other individuals or organizations as required by binding agreement or obligation with the Department of the Air Force. Failure to observe the prohibitions and mandatory provisions of this instruction as stated in paragraph 3.9.1., 4.5.4.2.1., 4.11.1., 6.2.1.1.1. through 6.2.1.1.8, 6.2.3.1., and 7.1.1.2. by military personnel is a violation of the Uniform Code of Military

Justice (UCMJ), Article 92, Failure to Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.

Additionally violations of paragraph 3.9.1. by ANG military personnel may subject members to prosecution under their respective State Military Code or result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Direct questions or comments on the contents of this instruction, through appropriate command channels, to Air Force Communications Agency (HQ

AFCA/EASD), 203 W. Losey Street, Room 1100, Scott AFB IL 62225-5222. Send recommended changes and conflicts between this and other publications, using Air Force (AF) http://www.e-publishing.af.mil/

2 AFI33-100 19 NOVEMBER 2008

Form 847, Recommendation for Change of Publication, to HQ AFCA/EASD, with an information copy to the Office of the Secretary of the Air Force for Warfighting Integration and

Chief Information Officer, Policy and Governance Division (SAF/XCPP), 1800 Air Force

Pentagon, Washington DC 20330-1800. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN)

33-363, Management of Records, and disposed of in accordance with Air Force Records

Information Management System (AFRIMS) Records Disposition Schedule (RDS) located at https://afrims.amc.af.mil/rds_series.cfm. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force. See Attachment 1 for a glossary of references and supporting information.

SAF/XC is changing all their publications from “stove-piped” system/program based to audience/role based by consolidating like information from existing Air Force instructions

(AFIs). The initial targets for consolidations are based around general users, commanders, implementers, and support enablers. During this phase, the consolidation will address the first three audiences. Existing AFIs will retain support enabler information containing detailed system/program guidance and/or procedural information. The information contained in this publication was extracted from the publications identified in Attachment 5.

SUMMARY OF CHANGES

This interim change implements DoD CIO Memorandum, 9 May 2008, Policy on Use of

Department of Defense (DoD) Information Systems-Standard Consent Banner and User

Agreement. All Users of DoD information systems will sign the standardized AF Form 4394, Air Force User Agreement Statement-Notice and Consent Provision. It also corrects out dated references to AFI 33-202v1, that was superseded by AFI 33-200.

1. Introduction

2. Network and Information System Access

3. Information Technology (IT) and Information Systems

4. Voice Communications Services

5. Software

6. Electronic Messaging

7. Records Management

8. Information Collection, Records, and Forms https://afrims.amc.af.mil/rds_series.cfm

AFI33-100 19 NOVEMBER 2008 3

Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING

INFORMATION 24

Attachment 2—TRANSMITTING UNCLASSIFIED INFORMATION ON

CLASSIFIED NETWORKS 33

Attachment 3—ELECTRONIC MESSAGE SIGNATURE BLOCK EXAMPLES 34

Attachment 4—PASSWORD MANAGEMENT QUICK REFERENCE SHEET 35

Attachment 5—LISTING OF PUBLICATIONS THAT USER POLICY C&I

INFORMATION WAS EXTRACTED FROM 36

1. Introduction.

1.1. In an effort to meet the growing needs of today‟s warfighter, great strides are being made to improve the capabilities offered by the Air Force provisioned portion of the Global

Information Grid (GIG). Today‟s Air Force is increasingly using these capabilities in almost all activities of warfighting and operations support. This increased reliance on technology and its integration requires each individual to take responsibility for ensuring effective, efficient, and authorized use of these resources as they carry out their responsibilities.

2. Network and Information System Access.

2.1. Access Control. Access control is one of the measures taken to ensure Information

Systems (ISs) are protected against threats and vulnerabilities. To control ISs access, identification and authentication techniques and procedures are used. The two IS access control methods used are the Common Access Card (CAC) with a Personal Identification

Number (PIN) or a username with password.

2.1.1. CAC. The CAC is the DoD identification card and is used to digitally sign electronic messages, travel orders, travel vouchers, and other documents and establish secure web-based sessions. See AFI 36-3026(I), Identification Cards for Members of the

Uniformed Services, Their Eligible Family Members, and Other Eligible Personnel, for additional information.

2.1.1.1. Users must not share their PIN and must protect their CAC from unauthorized access at all times. A user who suspects that these have been compromised must notify their organizational Information Assurance Officer (IAO) or Client Support Administrator (CSA) immediately.

2.1.2. Username with Password. Some ISs are not CAC-enabled and use a username and password for access.

2.1.2.1. Password Composition. All passwords must be a minimum of nine characters. Passwords must contain a mix of at least two lowercase letters, two uppercase letters, two numbers, and two special characters. Passwords must not contain dictionary words spelled frontward or backward, slang words, names of persons, places or things, including derivatives or modifications of such words, or split with a number or special character. The passwords must not be patterns of letters

4 AFI33-100 19 NOVEMBER 2008

on the keyboard, must not contain any personal identity (to include username or user-id), history, or environment, and must not mimic previous passwords. (See

Attachment 4 for additional information).

2.1.2.2. Password Protection. Each user is responsible and accountable for their password.

2.1.2.2.1. Memorize your password. Do not place passwords on desks, walls, sides of terminals, or store them in a function key, log-in script, batch file, or other communications software. If documentation is necessary for mission accomplishment (i.e., pre-established accounts for contingency or exercise), place the password in a properly marked, sealed envelope and store it in a safe. In the case of web-based log-in, the fact that an individual user has authenticated can be tracked for that session only (i.e., through the use of nonpersistent cookies or preferences) but the actual password used cannot be stored or passed on.

2.1.2.2.2. Upon initial access to an information system, each user must enter his username and password. A user must enter a password in such a manner that the password is not revealed to anyone observing the entry process.

2.1.2.2.3. Do not share your password. If password sharing is necessary for mission accomplishment, ensure the password is changed immediately after shared access is no longer required.

2.1.2.3. Password Classification. Protect all passwords based on the sensitivity of the information or critical operations they protect (i.e., a password used to gain access to a SECRET network is itself classified SECRET). At a minimum, you must safeguard all passwords as “For Official Use Only” (FOUO).

2.2. Training Requirement. All Air Force military, civilian, and contractors will receive documented Information Assurance (IA) training prior to receiving access to the IS. Contact your CSA for the required training.

2.3. Favorable Background Investigation. All individuals accessing the Air Force Global

Information Grid (AF-GIG) must meet the investigative requirements of AFI 31-501, Personnel Security Management Program.

2.4. Loss of Security Clearance. If an individual‟s security clearance is suspended or revoked, access to IS may be suspended. If an organizational commander feels the member should have access restored on an interim basis, they shall follow waiver request procedures outlined in AFI 33-200, Information Assurance (IA) Management).

2.5. Access Suspension. User‟s conduct inconsistent with the Air Force Information

Assurance (IA) principles, may experience suspension of access to IS.

2.5.1. Actions inconsistent with IA principles include, but are not limited to:

2.5.1.1. Failure to maintain an acceptable level of proficiency on a critical program

(based upon determination by the system‟s Designated Accrediting Authority [DAA] or Information System Owner [ISO])

2.5.1.2. Actions that threaten the security of a network or a governmental communications system

AFI33-100 19 NOVEMBER 2008 5

2.5.1.3. Actions that may result in damage or harm to a network or governmental communications system

2.5.1.4. Actions that constitute unauthorized use under the provisions in paragraph

3.9.1. in this instruction.

2.5.2. Once the violation is confirmed, the user is notified in writing of the access suspension by their commander (or designee), including the specific reason for the suspension and the steps the user must take to have access reinstated. The user may accept the suspension or dispute the grounds for the suspension by providing a written request for reconsideration within three duty days. Dispute resolution and interim access to information systems will be processed according to AFI 33-200.

2.5.3. The user will reaccomplish appropriate training prior to reinstatement of access to

IS.

3. Information Technology (IT) and Information Systems.

3.1. General Guidelines.

3.1.1. Appropriate Use. All government communications systems are subject to monitoring, interception, search, and seizure for all authorized purposes, reference DoD

Chief Information Officer (CIO) Memorandum, Policy on Use of Department of Defense

(DoD) Information Systems Standard Consent Banner and User Agreement, dated 9 May

2008. Government-provided hardware and software are for official use and authorized purposes only. Appropriate officials may authorize personal uses consistent with the requirements of DoD 5500.7-R, Joint Ethics Regulation (JER), after consulting with their ethics counselor. Such policies should be explicit, as unofficial uses that exceed the authorized purposes may result in adverse administrative or disciplinary action. For guidance on the use of the Internet, see paragraph 3.9. Using Internet and IT Resources.

3.1.2. Report unauthorized network activities or incidents to the CSA or ISO to ensure notification continues up the chain of command.

3.1.3. Do not input or store government information on privately owned IS and media without specific approval of the DAA. Contact your CSA or ISO for assistance.

3.1.4. Do not operate any wireless technology, devices or service (used for storing, processing, and/or transmitting information), in areas where classified information is discussed, electronically stored, electronically processed, or electronically transmitted without approval of the installation Emission Security (EMSEC) manager.

3.1.5. Lost or stolen government wireless devices must be reported immediately to your

CSA or ISO.

3.2. Acquiring Information Technology (IT) Assets.

3.2.1. Adhere to locally defined requirements process when acquiring IT assets. The installation Communications and Information Systems Officer (CSO) supports the information systems requirements process enabling requesting organizations to obtain new communications and information capabilities.

3.2.2. Acquire desktop computers and laptops IAW established acquisition policy.

6 AFI33-100 19 NOVEMBER 2008

3.3. Communications and Information System Relocations or Modifications.

3.3.1. The CSO must be involved in all projects involving communications and information infrastructure or assets.

3.3.2. The user submits requests in accordance with organization policy before initiating any project to install, relocate, modify, or remove communication and information systems.

3.4. Portable Electronic Devices (PED). PED is a generic title used to describe the myriad of small electronic items (e.g. Personal Digital Assistants (PDAs), Cellular Telephones

(CTs), two-way pagers, audio/video recording devices, and hand-held/laptop computers) widely available. Almost all have wireless telecommunications capabilities that offer tremendous advantages for government users. It is becoming difficult to differentiate between these electronic devices, as the trend is to combine capabilities and functions in various forms and format. PED users must:

3.4.1. Comply with Air Force IS operating instructions. Contact your ISO or CSA for assistance.

3.4.2. Connecting non-government-owned PEDs to an Air Force network is prohibited.

If individuals have a requirement to use a PED on an Air Force network, they must request issuance of a government-owned PED.

3.4.3. Encrypt data transmitted through a commercial or wireless network (data-in-transit).

3.4.4. Protect data stored or processed by the PED against tampering, theft, and loss.

3.4.5. Encrypt all stored information (data-at-rest) not otherwise approved for public release. Contact your CSA for approved procedures for encrypting. Contact your

Freedom of Information Act Officer or Public Affairs Officer for information on determining what information is releasable to the public.

3.4.6. Obtain DAA approval before using a PED for storing or processing High Impact

Personally Identifiable Information (PII) (see Terms, Attachment 1). Restrict use to protected workplaces (see Terms, Attachment 1). PEDs taken outside protected workplaces must adhere to the following additional security requirements:

3.4.6.1. The PED must be signed in and out of protected workplaces with a supervising official (for logging and tracking procedures).

3.4.7. Not use wireless-enabled PEDs for storing, processing or transmitting classified information without explicit written approval of the DAA and cognizant security authority.

3.4.7.1. If the PED is for classified use, encrypt transmission (data-in-transit) of the information using approved cryptography. Follow information security requirements for physically controlling and safeguarding the device and information according to

AFI 31-401, Information Security Program Management.

3.4.7.2. In the event classified information is processed or maintained on an unclassified PED, the individual discovering the incident will immediately notify their CSA or ISO.

AFI33-100 19 NOVEMBER 2008 7

3.4.8. Do not connect PEDs to more than one network at a time. PEDs connected directly to a Department of Defense (DoD)-wired network (e.g., via a hot synch connection to a workstation) must not be permitted to operate wirelessly.

3.4.9. Do not use wireless-enabled PEDs in areas where classified information is discussed or processed without coordination from the installation EMSEC manager.

3.4.10. Do not enable wireless capability unless necessary for the mission and approved by the DAA.

3.4.11. Immediately report lost or stolen PEDs to the CSA or ISO.

3.5. Removable Information Systems Storage Media Control. Removable media refers to information system storage media that can be removed from its reader device, conferring portability on the data it carries (e.g., diskettes, CDs, Universal Serial Bus (USB) storage devices, or any other device on which data is stored and which normally is removable from the system by the user or operator).

3.5.1. Safeguard, mark, and label removable media according to the requirements for the highest level of information ever contained on the media using applicable information security guidance in AFI 31-401 and AFI 33-332, Privacy Act Program. Additionally follow external and internal labeling guidance in AFMAN 33-363.

3.5.2. Restrict the use of removable media containing controlled unclassified information

(CUI) (see Terms, Attachment 1).

3.5.2.1. Removable media shall not be removed from protected workplaces unless encrypted and signed in and out with a supervising official. (See paragraph 7.1.1.5.

for additional details on encryption.)

3.5.3. Removable media containing High Impact PII (see Terms, Attachment 1) requires

DAA approval.

3.5.4. Immediately report loss or suspected loss of removable media containing CUI or

PII to CSA or ISO.

3.5.5. Clear, sanitize, or destroy removable media used to store sensitive information before release to unauthorized personnel or outside DoD control. Contact the organizational Information Assurance Officer (IAO) for assistance.

3.5.6. Obtain approval from the organizational IAO before attaching a Universal Serial

Bus (USB) storage device to an IS. These devices include but are not limited to memory sticks, jump drives, and Zip drives.

3.5.6.1. Using disguised USB storage devices (designed to look like anything other than a USB storage device, e.g., watch, pen, flashlight) is prohibited.

3.5.7. Users are responsible for backing up their data stored locally on their IT system

(e.g. desktop computer). Local policy may indicate the frequency or limitations of backing up data.

3.5.8. Unclassified media introduced into a classified computer becomes classified at the same classification level as the system. Limited exceptions may exist as approved by the system DAA in the systems accreditation package according to AFI 33-200.

8 AFI33-100 19 NOVEMBER 2008

3.6. Wireless Devices. Wireless devices (i.e. mice, keyboards, etc.) are widely available and use various wireless technologies to transmit data to the computer. Consult with your CSA for proper configuration. When used in areas where classified information is processed, they must be approved by the installation EMSEC manager.

3.7. Privately Owned information system (i.e., hardware or software) in Government and non-Government facilities. Storage of controlled unclassified information on personally owned information systems is prohibited.

3.7.1. Classified Processing. Do not use privately-owned information systems to process classified information. Privately-owned information systems contaminated with classified information will be confiscated and sanitized.

3.7.2. Unclassified and Sensitive Processing. Using privately-owned hardware and software for government work is strongly discouraged; however, it may be used for processing unclassified and sensitive information with justification and DAA approval.

Justification must include mission requirement, government availability, and rationale as to why privately-owned information systems must be used.

3.8. Public computing facilities. Do not use public computing facilities (Internet cafés and kiosks, hotel business centers, etc.) for processing government-owned unclassified, sensitive or classified information. Public computing facilities include any information technology resources not under your private or the United States (US) Government‟s control. Using these resources to access web-based government services (e.g. MyPay) constitutes a compromise of log-in credentials and must be reported to your CSA.

3.9. Using Internet and Information Technology (IT) Resources.

3.9.1. Inappropriate Use. Using the Internet for other than official or authorized use may result in adverse administrative or disciplinary action. The activities listed in paragraphs

3.9.1.1. through 3.9.1.14. involving using government-provided computer hardware or software is specifically prohibited. Failure to observe the prohibitions and mandatory provisions of these paragraphs by military personnel is a violation of the Uniform

Code of Military Justice (UCMJ), Article 92, Failure to Obey Order or Regulation.

Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract. Violations by ANG military personnel may subject members to prosecution under their respective State Military Code or result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws.

3.9.1.1. Using Federal government communications systems for unauthorized personal use.

3.9.1.2. Uses that would adversely reflect on the DoD or the Air Force such as chain letters, unofficial soliciting, or selling, except on authorized bulletin boards established for such use.

3.9.1.3. Unauthorized storing, processing, displaying, sending, or otherwise transmitting offensive or obscene language or material. Offensive material includes, AFI33-100 19 NOVEMBER 2008 9 but is not limited to, “hate literature” such as racist literature, materials or symbols;

sexually harassing materials, pornography and other sexually explicit materials.

3.9.1.4. Storing or processing classified information on any system not approved for classified processing.

3.9.1.5. Knowingly using copyrighted material in violation of the rights of the owner of the copyrights. Consult with the servicing Staff Judge Advocate for “fair use” advice.

3.9.1.6. Participating in non-DoD or nongovernment “chat lines,” “chat groups,”

“blogs,” or open forum discussion to or through a public site, unless it is for official purposes and approved through SAF/XCP and DoD Global Information Grid (GIG)

Waiver Board.

3.9.1.7. Unauthorized use of the account or identity of another person or organization.

3.9.1.8. Viewing, changing, damaging, deleting, or blocking access to another user‟s files or communications without appropriate authorization or permission.

3.9.1.9. Attempting to circumvent or defeat security or modifying security systems without prior authorization or permission (such as for legitimate system testing or security research).

3.9.1.10. Obtaining, installing, copying, storing, or using software in violation of the appropriate vendor‟s license agreement.

3.9.1.11. Permitting an unauthorized individual access to a government-owned or government-operated system.

3.9.1.12. Modifying or altering the network operating system or system configuration without first obtaining written permission from the administrator of that system.

3.9.1.13. Copying and posting official information to unauthorized Web sites.

3.9.1.14. Downloading and installing freeware/shareware or any other software product without DAA approval.

3.10. Air Force User Agreement Statement – Notice and Consent Provision.

3.10.1. In accordance with the DoD Chief Information Officer (CIO) Memorandum, Policy on Use of Department of Defense (DoD) Information Systems – Standard Consent

Banner and User Agreement, 9 May 2008, all users of DoD information systems will sign the standardized AF Form 4394. Commanders should restrict access to DoD information systems for those personnel who fail to sign the agreement.

3.10.2. CSAs or IAOs will keep the user agreement on file, and will ensure a copy is on file before allowing access for new members.

4. Voice Communications Services.

4.1. Calls From Base Telephones.

10 AFI33-100 19 NOVEMBER 2008

4.1.1. Use the following Defense Switched Network (DSN) and Commercial network access digits: 94 DSN ROUTINE; 98 COMMERCIAL LONG DISTANCE; 99

COMMERCIAL LOCAL.

4.1.2. Do not discuss classified information over an unsecured telephone.

4.1.3. Long Distance Calls From Base Telephones.

4.1.3.1. Use the Defense Switched Network (DSN), not commercial long distance carriers, to call other DoD activities unless DSN service is not available in a timely manner. Use the DSN system only for official business or when in the best interest of the government.

4.1.3.2. User will contact their Telephone Control Officer (TCO) to obtain a personal identification number (PIN) for accessing commercial long distance voice service.

This service is authorized for official uses only.

4.1.3.3. Callers without direct long distance dialing capability must request a control or billing account number from their TCO. Give the control or billing account number to the base switchboard operator when making a call.

4.1.3.4. For verification purposes, document all commercial long distance calls on

AF Form 1072, Authorized Long Distance Telephone Calls. This is only required when PINs are not established or the host base does not have the capability to capture source Caller ID information for each call.

4.2. Collect Calls to Base Telephones.

4.2.1. The installation commander provides local guidance for official collect calls.

4.3. Personal Calls Over Official Telephones.

4.3.1. All government communications systems are subject to monitoring, interception, search, and seizure for all authorized purposes, reference DoD Chief Information Officer

(CIO) Memorandum, Policy on Use of Department of Defense (DoD) Information

Systems Standard Consent Banner and User Agreement, dated 9 May 2008. Commanders and supervisors may allow personal calls during work hours using official telephones if:

4.3.1.1. The telephone call does not interfere with official duties.

4.3.1.2. The calls do not exceed reasonable duration and frequency, and whenever possible, are made during the employee‟s personal time such as after-duty hours or lunch periods.

4.3.1.3. The telephone calls serve a legitimate public interest (such as usage reduces time away from the work area or improves unit morale).

4.3.1.4. The telephone call does not reflect adversely on DoD or the Air Force (e.g., uses involving pornography; unofficial advertising, soliciting, or selling; and discussion of classified information).

4.3.1.5. The government does not incur any long distance or per-call charges above and beyond normal local charges. Normal local charges are based upon historical averages.

AFI33-100 19 NOVEMBER 2008 11

4.3.1.6. Personal calls may be made for "morale purposes" during Deployments and

TDYs as authorized by the organizational commander, see paragraph 4.9. for specific guidance.

4.4. Cordless Telephones Guidance.

4.4.1. The installation CSO, or designated representative, approves the use of cordless telephones on a case-by-case basis. For security purposes, the use of cordless phones on military installation work centers are highly discouraged. Conversations from cordless telephones can easily be intercepted as well as “stepped-on” due to limited frequency allocation and overlapping of voice frequencies. Cordless telephones used outside the

United States and Possessions (US&P) will be host nation approved.

4.4.2. Limit cordless phone use to non-command and control (C2) users and in buildings where operating cordless telephones are fully warranted by the mission and do not pose an Operations Security (OPSEC) risk.

4.4.3. Operating cordless phones within a classified environment will be approved by the installation emission security (EMSEC) manager.

4.5. Commercial Cellular Telephone (CT) Service.

4.5.1. Organizations must request host base CSO approval before purchasing commercial cellular equipment.

4.5.2. Personal calls to CT service providers from the host base official service may be authorized if the Air Force does not incur a long-distance toll or per-call charge. Cellular telephone services that provide per-call charges by billing the originating (calling) party, should be limited by the host base voice information system to official calls only.

4.5.3. Official Use of CT Service.

4.5.3.1. Use CT services only when it is the most cost-effective way to provide necessary communications or mobility is required.

4.5.3.2. Do not use an unclassified CT for C2 purposes. For security purposes, use a regular telephone (land line) as a first priority when and where available.

4.5.3.3. Do not transmit classified information over unsecured CTs.

4.5.3.4. Use government-issued CTs while driving on or off base according to local policies.

4.5.4. Personal Use of CT Service.

4.5.4.1. The same rules that govern use of land line telephones apply to the use of Air

Force CTs. Reference paragraph 4.9. for official and authorized purposes.

4.5.4.2. Members making inappropriate CT calls are subject to disciplinary action even if the call does not cause additional expense. Failure to observe the prohibitions and mandatory provisions of paragraph 4.5.4.2.1 by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article

92, Failure to Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by

12 AFI33-100 19 NOVEMBER 2008

contactor personnel will be handled according to local laws and the terms of the contract.

4.5.4.2.1. Do not use Air Force issued CTs to conduct personal commercial activities. Some examples of inappropriate calls include those related to personal solicitation or sales matters and those of a harassing or obscene nature. If a caller has any questions concerning proper use of government cell phones, it is the caller‟s responsibility to check with a supervisor before making the call.

4.5.4.3. Dual line CTs. Individuals may elect at their option to activate the secondary line as a personal number and place personal calls on that line.

4.5.4.3.1. Activation of a dual-number capability is not permitted on secure CTs.

4.5.4.3.2. Authorized end user of a government-owned, dual-number capable CT:

4.5.4.3.2.1. Shall sign an agreement, produced in accordance with Base Judge

Advocate and Contracting office guidance, that contains appropriate “hold harmless” and “personal liability” clauses, prior to being issued a dual-number capable CT, without regard to whether or not the user elects to immediately activate the secondary number capability.

4.5.4.3.2.2. If a secondary number is activated, the user must ensure all bills associated with the personal account are mailed directly to the user‟s home address or post office box.

4.5.4.3.2.3. When a CT is no longer required for the performance of duties, the user shall ensure that the personal account is closed and the secondary number zeroized by the vendor, prior to returning the CT to the local Personal

Wireless Communications System (PWCS) manager for reuse.

4.6. Official Telephone Service in Personal Quarters is permitted for certain officials when necessary for national defense purposes. Contact your organizational TCO for more information, specific policy and procedures are contained in AFI 33-111, Voice Systems

Management.

4.7. Unofficial Commercial Telephone/Voice Service In Quarters.

4.7.1. The individual subscriber must pay for renting, acquiring, and maintaining end-user instruments, as well as all usage charges for personal telephone service.

4.7.2. If required by the housing manager, housing occupants must restore telephone wiring and outlets to the original configuration before clearing quarters.

4.8. Air Force Instruction on Defense Switched Network (DSN) On- or Off-Net Calling.

4.8.1. Authorized Actions:

4.8.1.1. Placing an official call to a DSN operator (base operator) from a commercial network and having the operator extend the call over DSN to a DSN number (on-netting).

4.8.1.2. Placing an official call to a DSN operator from a DSN number and having the operator extend the call to a local commercial number (off-netting).

AFI33-100 19 NOVEMBER 2008 13

4.8.1.2.1. The installation CSO determines local guidance on the off-netting of an official DSN call to an official long-distance toll number. The installation CSO is directly responsible for toll charges and determines billing procedures, recourse for reimbursement, and/or acceptable appropriated fund support for off-netting official installation toll calls.

4.9. Health, Morale, and Welfare (HMW) Calls.

4.9.1. HMW calls are authorized over the DSN as prescribed in CJCSI 6215.01C, Policy for Department of Defense Voice Networks with Real Time Services (RTS). HMW calls are not authorized on government-issued CT, or via the FTS-2001 (or its designated replacement) network. However, satellite phones may be approved for HMW calls by the

Organizational Commander on a case-by-case basis. You can obtain copies of CJCS publications at http://www.dtic.mil/doctrine/index.html.

4.9.1.1. HMW calls are intended for military and Department of the Air Force civilians. HMW calls are authorized when:

4.9.1.1.1. In an unaccompanied status at overseas or remote geographic locations.

4.9.1.1.2. Single at overseas or remote geographic locations.

4.9.1.1.3. Performing extended temporary duty (TDY) for more than 14 days.

4.9.1.2. Immediate family members or the parents of single active duty personnel and/or the guardian of the child of a single parent or military/military couple, both of whom are deployed, may be permitted to participate in the HMW program under procedures established by the Airman and Family Readiness Center (i.e., as part of

“Hearts Apart” or similar programs) and the host commander. It is both the deployed commander and the host base commander‟s responsibility to provide guidance on the limitations and opportunities made available by this program.

4.9.1.3. Place DSN HMW calls at routine precedence, normally not to exceed 15 minutes.

4.9.1.4. DSN HMW calls should not exceed a reasonable frequency as designated by the installation commander in conjunction with the installation CSO. Reasonable frequency is based upon installation/theater policy and determined by system capabilities, mission needs and restrictions. EXCEPTION: Emergency calls may exceed the established threshold.

4.9.1.5. Extending DSN HMW calls to a commercial number (off-netting) is authorized, provided it does not interfere with operational requirements. Off-net DSN

HMW calls will not incur a toll charge to the government even if the intent is to reimburse the government. If the call incurs a toll charge, base operators may extend the call if the caller uses a credit/calling card to charge the call or the called party agrees to accept the charges (e.g., reversing of charges). See paragraph 4.8.1.2. for definition of off-netting.

4.9.1.6. On-netting of DSN HMW calls is permissible when placed from within the continental United States (CONUS) as part of Airman and Family Readiness “Hearts

Apart” or other similar programs. See paragraph 4.8.1.1. for definition of on-netting.

http://www.dtic.mil/doctrine/index.html

14 AFI33-100 19 NOVEMBER 2008

4.10. Emergency Service Calls.

4.10.1. Dial 911 for all emergency services (e.g., police, fire, and medical emergencies) unless local guidance advises additional or alternate contact information for Emergency

Services.

4.11. Official Government Issued Calling Card Use.

4.11.1. Government issued calling cards are issued for official use only. Cardholders must not use the calling card for any purpose other than official use. Failure to observe the prohibitions and mandatory provisions of this paragraph by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article 92, Failure to

Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.

4.11.2. Cardholders must sign a statement acknowledging receiving the government issued calling card and that the card is for official use only.

5. Software.

5.1. Government-owned Commercial Off-The-Shelf Software. Do not install and use copies of government-owned software on a home computer unless the software license explicitly allows users to do so and the installation CSO has authorized such use. Personal use may be a violation of The Copyright Act, rendering the individual user accountable and liable. Reference AFI 51-303, Intellectual Property--Patents, Patent Related Matters, Trademarks and Copyrights.

5.2. Do not install software or hardware on an IS without coordination with the IAO. The

IAO is responsible for the proper coordination and implementation through IA channels.

6. Electronic Messaging.

6.1. General. All government communications systems are subject to monitoring, interception, search, and seizure for all authorized purposes, reference DoD Chief

Information Officer (CIO) Memorandum, Policy on Use of Department of Defense (DoD)

Information Systems Standard Consent Banner and User Agreement, dated 9 May 2008.

Government-provided messaging systems are for official or authorized purposes only. Any other use is prohibited.

6.1.1. Electronic messaging users will:

6.1.1.1. Maintain responsibility for the content of their electronic messages and ensure that messages sent meet Air Force acceptable use of electronic messaging

(paragraphs 6.2.).

6.1.1.2. Maintain sent and received information according to Air Force records management directives: AFMAN 33-363; AFI 33-322, Records Management

Program; and AFRIMS RDS (https://afrims.amc.af.mil/rds_series.cfm).

6.1.1.3. Adhere to local policy on sending electronic messages to a large number of recipients.

AFI33-100 19 NOVEMBER 2008 15

6.1.1.4. Adhere to local policy when sending an electronic message to mail distribution lists.

6.1.1.5. Only reply to electronic messages that absolutely require a response and minimize the use of the “Reply to All” function.

6.1.1.6. Bear sole responsibility for material accessed and sent.

6.1.1.7. Properly coordinate and staff electronic messages according to local directives.

6.1.1.8. Take appropriate action on non-delivery notices or message rejects to ensure messages reach the intended recipient.

6.1.1.9. Not auto-forward electronic messages from the “.mil” domain to a commercial Internet Service Provider (ISP).

6.1.1.10. Do not indiscriminately release electronic messaging addresses to the public. For further information, reference the Air Force Freedom of Information Act

“Release of E-mail Addresses” (http://www.foia.af.mil).

6.1.1.11. Not add special backgrounds, special stationeries, digital images, unusual fonts, etc., to the body of their electronic messages.

6.1.2. Individual electronic messages are considered official when the sender is conducting mission-related or official business.

6.1.3. Special delivery instructions should be included as part of the message text to identify the specific addressee to whom the message is to be delivered. Type “FOR” followed by the name or position title when there is a specific person identified for delivery or “PASS TO” for address instructions to direct the message to a particular organization, unit, or office.

6.1.4. Messages with special delivery instructions should not be distributed through normal delivery channels unless specifically requested by the recipient.

6.1.5. Special Handling Requirements. Do not transmit controlled unclassified information (i.e. Privacy Act, FOUO) on or to systems not approved for that information.

Reference AFI 31-401.

6.1.5.1. Transmitting unclassified information on classified networks is authorized unless specifically prohibited by the network operating instructions. The guidelines listed in Attachment 2 apply to all unclassified electronic messages sent across a classified network.

6.1.5.2. Identify all Privacy Act and For Official Use Only (FOUO) electronic messages in the subject line with FOUO.

6.2. Official Use, Authorized Use, and Use of Subscription Services. Using Air Force messaging systems for other than official or authorized uses may result in adverse administrative or disciplinary action. Failure to observe the prohibitions and mandatory provisions of 6.2.1.1.1. through 6.2.1.1.8. and 6.2.3.1. by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article 92, Failure to Obey Order or

Regulation. Violations by civilian employees may result in administrative disciplinary http://www.foia.af.mil/

16 AFI33-100 19 NOVEMBER 2008

action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.

6.2.1. Official use includes communications, including emergency communications determined necessary in the interest of the Federal government. Official use includes, when approved by the theater commander in the interest of morale and welfare, those personal communications by military members and other Air Force employees who are deployed for extended periods away from home on official business.

6.2.1.1. The following do not constitute official use of government communications systems and are prohibited:

6.2.1.1.1. Distributing knowingly copyrighted materials by electronic messaging without consent from the copyright owner. Failure to maintain consent may violate federal copyright infringement laws and could subject the individual to civil liability or criminal prosecution.

6.2.1.1.2. Sending or receiving electronic messages for commercial or personal financial gain.

6.2.1.1.3. Intentionally or unlawfully misrepresenting your identity or affiliation in electronic messaging communications.

6.2.1.1.4. Sending harassing, intimidating, abusive, or offensive material to, or about others.

6.2.1.1.5. Using someone else‟s identity (user identification [ID] name).

6.2.1.1.6. Causing congestion on the network by such things as the propagation of chain letters, junk E-mails, and broadcasting inappropriate messages to groups or individuals.

6.2.1.1.7. Using government systems for political lobbying.

6.2.1.1.8. Accessing commercial web mail accounts and instant messaging services (i.e., Yahoo, AOL, or MSN mail accounts).

6.2.1.2. Access to personal GI Mail and other instant messaging services on official

Air Force web sites (i.e., AF Portal and AF Crossroads) is authorized since these services reside within the “.af.mil” domain and are specifically provided as a risk-mitigated alternative to their commercial counterparts. Wireless devices with web access are authorized to access official Air Force web mail services provided the devices are government issued and accountable.

6.2.2. Authorized Limited Personal Use Examples. Examples of authorized limited personal use include, but are not limited to:

6.2.2.1. Notifying family members of official transportation or schedule changes.

6.2.2.2. Using government systems to exchange important and time-sensitive information with a spouse or other family members (i.e., scheduling doctor, automobile, or home repair appointments, brief Internet searches, or sending directions to visiting relatives).

AFI33-100 19 NOVEMBER 2008 17

6.2.2.3. Educating or enhancing the professional skills of employees, (i.e., use of communication systems, work-related application training, etc.).

6.2.2.4. Sending messages on behalf of a chartered organization, (i.e., organizational

Booster Club, Base Top 3, Base Company Grade Officers Association, etc.).

6.2.2.5. Limited use by deployed members for morale, health, and welfare purposes.

6.2.2.6. Job searching.

6.2.3. Use of Subscription Services. Internet electronic messaging access grants users the ability to subscribe to a variety of news, mail lists, and discussion groups. These services may include professional groups sponsored by Air Force agencies and other newsgroups sponsored by non-Air Force agencies, including the DoD, other Federal agencies, educational institutions, and commercial activities (i.e., product information updates and technical newsletters).

6.2.3.1. Air Force personnel may subscribe to official Air Force-sponsored news, mail lists, and discussion groups. Obtain written approval from the commander before subscribing to or participating in electronic message newsgroups except official Air

Force internal information products. These products are managed and approved by

SAF/PA and accessible from the Air Force Link (http://www.af.mil). Using such services without prior approval is misuse of a government system and is subject to disciplinary action, see paragraph 6.2. in this instruction. Subscription or participation in e-message news groups will be in support of official duties only.

6.2.3.2. When an extended absence will not allow access to your electronic messaging account, unsubscribe or suspend mail from any mail lists or newsgroups.

This alleviates large backlogs of received messages that consume valuable server storage resources.

6.2.3.3. Participation in newsgroups whose content is contrary to the standards set by

DoD 5500.7-R (i.e., obscene, offensive, etc.) is prohibited. Organizational commanders may direct electronic messaging administrators to set up permanent blocks on a specific site or newsgroup addresses to prevent subscription to such services.

6.3. Electronic Message Signature Blocks.

6.3.1. Electronic messages, to include official communications such as memorandums

(letters), notes, messages, reports, etc., follow specific formats found in this instruction, Air Force Handbook (AFH) 33-337, The Tongue and Quill, AFI 33-321, Authentication of Air Force Records, and AFMAN 33-326, Preparing Official Communications.

6.3.1.1. Senders include a signature block on all official electronic messaging sent from individual or organizational accounts. Includes “//SIGNED//” in upper case before the signature block to signify it contains official Air Force information (e.g., instructions, directions, or policies). Restrict the signature block to name, rank, service affiliation, duty title, and phone numbers (DSN and/or commercial as appropriate) after the “//SIGNED//” entry, do not add slogans and quotes. Examples of appropriate signature blocks are in Attachment 3.

6.4. Protecting Electronic Message Information.

http://www.af.mil/

18 AFI33-100 19 NOVEMBER 2008

6.4.1. Controlled Unclassified Messages. There is information, other than classified information, that has been determined to require some type of protection or control.

6.4.1.1. Encrypt electronic messages when they contain controlled unclassified information, (i.e. Privacy Act, FOUO). See paragraph 6.5.2. for further information on encryption. See AFI 31-401 for additional guidance on controlled unclassified information.

6.4.1.2. Protecting FOUO Information. When transmitting FOUO information, add

“FOUO” to the beginning of the subject line, followed by the subject. FOUO attachments shall be marked with a statement similar to this one: “FOR OFFICIAL

USE ONLY ATTACHMENT.” Additional protection methods may include password protecting the information in a separate Microsoft Word™ document. See AFI 31-

401 for additional guidance on protecting FOUO information.

6.4.1.3. Protecting Personal Information. Transmitting personal information exempt under the Freedom of Information Act must be marked “FOUO” at the beginning of the subject line IAW guidance contained in AFI 31-401 and DoD 5200.1-R, Information Security Program, and apply the following statement at the beginning of the message:

“This email contains For Official Use Only (FOUO) information that may be exempt under the

Freedom of Information Act, 5 United States Code (U.S.C.) 552.”

Do not indiscriminately apply this statement to messages. Use it only in situations when you are actually transmitting personal information. Personal information may not be disclosed to anyone outside DoD unless specifically authorized by The Privacy Act.

6.4.1.3.1. Do not send Privacy Act information to distribution lists or group E-mail addresses unless each member has an official need to know the personal information.

6.4.1.4. Protecting Exempt Freedom of Information Act (FOIA) Information, Title 5, U.S.C., Section 552. Do not send FOIA information normally exempt in electronic messages without an appropriate level of protection to prevent unintentional or unauthorized disclosure. Refer to AFI 31-401 and DoD 5200.1-R for additional guidance or consult your local FOIA representative. Appropriate level of protection includes proper marking and encryption, see paragraphs 6.4.1.2. and 6.5.2.

6.4.2. Classified Electronic Messages.

6.4.2.1. Marking Classified Electronic Messages. Mark all classified electronic messages with a level of classification equivalent to the information they contain or reveal.

6.4.2.1.1. Mark all electronic messages on classified networks by entering the appropriate classification in parenthesis by using these symbols: “(S)” for

SECRET, “(C)” for CONFIDENTIAL, and “(U)” for UNCLASSIFIED, as the first marking in the “Subject” box of the message template.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .