AFI_33-200 _Information_Assurance_Program.pdf

PDF 378 KB Posted

Attached to
OPERATIONAL TEST AND EVALUATION SERVICES (OTES) Federal contract opportunity
Solicitation number
FA7046-11-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

AFI_33-200 _Information_Assurance_Program

View the file

Other files for this federal contract opportunity

Other files attached to OPERATIONAL TEST AND EVALUATION SERVICES (OTES), newest first.
File Type Posted
FA7046-11-R-0003-0004.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES_RFP_Amendment 2 - 14 Oct 11.doc DOC document
PWS TO_01_Nuclear_Space Amendment 2 - 14 Oct 11.docx DOCX document
OTES Final RFP-PPI QuestionsResponses 14 Oct 11.xls XLS spreadsheet
Section L Amendment 2 - 14 Oct 11.docx DOCX document
Amendment 1Section L 10-7.docx DOCX document
ppi_tool.accdb —
Amendment 1OTES_QASP 10-7.docx DOCX document
AFTECMAN99-101.pdf PDF
Amendment 1 PWS Oct 7.docx DOCX document
Amendment 1 RFP.doc DOC document
Form_4.pdf PDF
Form_6.pdf PDF
Form_2.pdf PDF
Form_1.pdf PDF
Form_2.xfdl XFDL file
Form_5.xfdl XFDL file
Final_ TO_02_Det_5_Bomber_Test_Division.docx DOCX document
Final_Sample_TO_03 JSPDS.docx DOCX document
Form_6.xfdl XFDL file
DRAFT OTES Responses.xlsx XLSX spreadsheet
form_1.xfdl XFDL file
Final_TO_01_Nuclear_Space.docx DOCX document
FINAL OTES_QASP.docx DOCX document
Source_Interested Parties List.xlsx XLSX spreadsheet
OTES PWS 25_ Jul_ 11_AFL_A.docx DOCX document
TO Nuclear Space 15_JUL_11_AFL.docx DOCX document
AFOTEC_99-101 _Conduct_of_Operational_Test_ _Evaluation.pdf PDF
OTES QASP 2 Aug 11.docx DOCX document
AFI_99-103 _Capabilities-based_Test_ _Evaluation.pdf PDF
Defense_Acquisition_Guidebook_(DAG).pdf PDF
DoD_Directive_5000.1 _The_Defense_Acquisition_System.pdf PDF
DoD_5400.7R _DoD_Freedom_of_Information_Act_(FOIA)_Program _AF_Supplement.pdf PDF
JSPDS Task Order 15_Jul_11_AFL.docx DOCX document
OTES CDRLs 27 Jun 11.docx DOCX document
CJCS_Instruction_3170.01G_Joint_Capabilities_Intergration_ _Development_System.pdf PDF
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
AFI_16-1002 _Modeling_ _Simulation_(M S)_Support_to_Acquisition.pdf PDF
AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems.pdf PDF
DoD_Instruction_5000.2 _Operation_of_the_Defense_Acquisition_System.pdf PDF
513408p CBRN DoD Implementation Directive.pdf PDF
AFOTEC_OT E_Guide _6th_Edition.pdf PDF
AFMAN_63-119 _Certification_of_System_Readiness_for_Dedicated_Operational_Test_ _Evaluation.pdf PDF
AFI_63-101 _Acquisition_ _Sustainment_Life_Cycle_Management.pdf PDF
DD254.docx DOCX document
AFOTEC_OT_of_IA_Guide _2nd_Edition.pdf PDF
DoD_Instruction_8500.2 _Information_Assurance_Implementation.pdf PDF
AFOTECPAM_99-104 _AFOTEC_Operational_Suitability_Test_ _Evaluation_Guide.pdf PDF
Show all 50

OPERATIONAL TEST AND EVALUATION SERVICES (OTES) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BY ORDER OF THE

AIR FORCE INSTRUCTION 33-200

SECRETARY OF THE AIR FORCE

23 DECEMBER 2008

Incorporating Change 1, 30 May 2009

Communications and Information

INFORMATION ASSURANCE (IA)

MANAGEMENT

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available on the e-Publishing website at www.e-publishing.af.mil for downloading or ordering.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/XCPP Certified by: SAF/XCP-2

(Brig Gen Ronnie Hawkins)

Supersedes: AFI 33-202, Volume 1, 3 February

2006; AFI 33-204, 1 April 2004

Pages: 44

This Air Force Instruction (AFI) implements Air Force Policy Directive (AFPD) 33-2, Information Assurance (IA) Program, and establishes Air Force information assurance requirements for compliance with Public Law 100-235, Computer Security Act of 1987; Title 44

United States Code Section 3602; Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources; OMB Bulletin 90-08, Guidance for Preparation of Security Plans for Federal Computer Systems that Contain Sensitive Information; Title 10

United States Code (USC), Section 2224; Department of Defense Directive (DoDD) 8500.1, Information Assurance (IA); Department of Defense Instruction (DoDI) 8500.2, Information

Assurance (IA) Implementation; DoDD 8100.2, Use of Commercial Wireless Devices, Services and Technologies in the Department of Defense (DoD) Global Information Grid; Chairman Joint

Chiefs of Staff Instruction (CJCSI) 6510.01D, Information Assurance (IA) and Computer

Network Defense (CND); and Chairman Joint Chiefs of Staff Manual (CJCSM) 6510.01, Defense-In-Depth: Information Assurance (IA) and Computer Network Defense (CND). This instruction provides the directive requirements for IA as outlined in AFPD 33-2. This instruction applies to all Air Force military, civilian, and contractor personnel under contract by DoD who develop, acquire, deliver, use, operate, or manage Air Force information systems (IS). This instruction applies to the Air National Guard and Air Force Reserve Command. The term major command (MAJCOM), when used in this publication, includes field operating agencies (FOA) and direct reporting units (DRU). Use of extracts from this instruction is encouraged.

Committee on National Security Systems Instruction (CNSSI) No. 4009, National Information

Assurance Glossary, explains other terms. Direct questions or comments on the contents of this instruction, through appropriate command channels, to Secretary of the Air Force, Policy and

Resources Directorate (SAF/XCP), 1800 Air Force Pentagon, Suite 4C1059, Washington DC http://www.e-publishing.af.mil/

2 AFI33-200 23 DECEMBER 2008

20330-1800. Refer recommended changes and conflicts between this and other publications to

HQ AFCA/EASD, 203 W. Losey Street, Room 1100, Scott AFB IL 62225-5222, through appropriate channels, using Air Force IMT 847, Recommendation for Change of Publication.

Provide an information copy to SAF/XCP. Send any supplements to this publication to

SAF/XCP for review, coordination, and approval prior to publication. Provide a copy of each final supplement to HQ AFCA/EASD. Ensure all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN)

33-363, Management of Records, and disposed of in accordance with Air Force Records

Information Management System Records Disposition Schedule (RDS) located at https://afrims.amc.af.mil/rds_series.cfm. See Attachment 1 for a glossary of references and supporting information. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force.

SUMMARY OF CHANGES

This interim change modifies paragraph 2.25.2. to allow Wing IA Offices to achieve IA

Certification Level I or II as opposed to only Level II. Air Force has coordinated this change with DoD NII and the change meets the intent of the requirement for local enclave certification requirements (Level I).

Chapter 1—GENERAL INFORMATION 6

1.1. Introduction

1.2. Applicability

1.3. Objectives

Chapter 2—ROLES AND RESPONSIBILITIES 7

2.1. Under Secretary of the Air Force (SAF/US)

2.2. Assistant Secretary of the Air Force (Acquisition) (SAF/AQ)

2.3. Deputy Undersecretary of the Air Force, International Affairs (SAF/IA)

2.4. Secretary of the Air Force, Office of Warfighting Integration and Air Force Chief

Information Officer (SAF/XC)

2.5. Secretary of the Air Force, Policy and Resources Directorate (SAF/XCP)

2.6. Deputy Chief of Staff, Intelligence, Surveillance, and Reconnaissance

(USAF/A2)

2.7. Office of the Air Force Civil Engineer (HQ USAF/A7C)

2.8. Headquarters Air Education and Training Command (HQ AETC)

2.9. Headquarters Air Force Materiel Command (HQ AFMC)

2.10. Headquarters Air Force Space Command (HQ AFSPC)

2.11. Air Force Network Operations Commander (AFNetOps/CC)

2.12. Air Force Network Operations Center (AFNOC)

https://afrims.amc.af.mil/rds_series.cfm

AFI33-200 23 DECEMBER 2008 3

2.13. Air Force Information Operations Center (AFIOC)

2.14. Headquarters Air Force Communications Agency (HQ AFCA)

2.15. Air Force Office of Special Investigations (AFOSI)

2.16. Air Force Personnel Center (AFPC)

2.17. United States Air Force Academy

2.18. Single Manager, Program Manager, or Project Manager

2.19. Other Agencies Acquiring or Developing Information Technology

2.20. Designated Accrediting Authority

2.21. Information System Owners (ISO)

2.22. System Level Information Assurance Manager (IAM)

2.23. System Level Information Assurance Officer (IAO)

2.24. MAJCOM IA Office or Function

2.25. Wing IA Office

2.26. Organizational Commander

2.27. Organizational IAO

2.28. Information System Users

Chapter 3—POLICY 20

Section 3A—Air Force IA Program 20

3.1. Air Force IA Program

3.2. IA Strategy

3.3. Air Force Specialized IA Publications

3.4. IA Workforce

3.5. IA Awareness

3.6. Network Defense (NetD)

3.7. IA Assessments

3.8. Notice and Consent Certification

3.9. Connection Management

3.10. Configuration Management

3.11. IA Products

3.12. Security Configuration and Implementation

3.13. Key Management Infrastructure (KMI)

3.14. Air Force IA Support Services

4 AFI33-200 23 DECEMBER 2008

Section 3B—Air Force Information System IA Program 23

3.15. Air Force Information System IA Program

3.16. IA Controls

3.17. Information System Security Engineering (ISSE)

3.18. IT and IT Service Acquisitions

3.19. Communications Security

3.20. Computer Security for the Computing Environment

3.21. Emissions Security

3.22. Identification and Authentication

3.23. Access Control

3.24. Controlling Maintenance Activities

3.25. Network Security for the Enclave Environment

3.26. Boundary Defense

3.27. Malicious Logic Protection

3.28. Incident Response and Reporting

3.29. Vulnerability Management

3.30. Information Operations Condition

3.31. Interconnections Among Systems and Enclaves

3.32. Cross-Domain Solutions

3.33. Mobile Code

3.34. Ports, Protocols, and Services (PPS)

3.35. Virtual Private Networks (VPN)

3.36. Remote Access

3.37. Notice and Consent for Monitoring

3.38. IA Training and Certification

3.39. IA Awareness and Education

3.40. Security Rules of Behavior or Acceptable Use Policy

3.41. Wireless Services

3.42. Portable Electronic Devices (PED)

3.43. Voice Over Internet Protocol

3.44. Using Hardware or Software Not Owned by the Air Force

3.45. Secure Remote Computing and Telecommuting

3.46. Physical Security

AFI33-200 23 DECEMBER 2008 5

3.47. Information Security

3.48. Remanence Security

3.49. Environmental Controls

3.50. Protected Distribution System (PDS)

3.51. Exceptions, Deviations, and Waivers

3.52. A Plan of Action and Milestones (POA&M)

Section 3C—Information Collections, Records, and Forms or Information Management Tools

(IMT) 31

3.53. Information Collections:

3.54. Prescribed Forms:

Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 33

6 AFI33-200 23 DECEMBER 2008

Chapter 1

GENERAL INFORMATION

1.1. Introduction. This AFI provides general direction for implementation of IA and management of IA programs according to AFPD 33-2. Compliance ensures appropriate measures are taken to ensure the availability, integrity, and confidentiality of Air Force ISs and the information they process. Using appropriate levels of protection against threats and vulnerabilities help prevent denial of service, corruption, compromise, fraud, waste, and abuse.

1.2. Applicability.

1.2.1. Applies to all ISs owned, operated, or supported by the Air Force, including IS components of weapon systems, ISs that provide the management infrastructure and connections among other ISs, and networks that are used to process, store, display, transmit or protect DoD information, regardless of classification or sensitivity. This document is also binding on all users that operate, connect, or interact with information systems owned, maintained, and controlled by the DoD.

1.2.2. More restrictive DoD and Intelligence Community directive requirements governing systems under the purview of the Intelligence Community take precedence over this instruction. For Sensitive Compartmented Information (SCI) systems, refer to Intelligence

Community Directive (ICD) 503 and other Intelligence Community directives.

1.2.3. More detailed implementation guidelines are contained in IA reference documents and specialized publications cited throughout this AFI.

1.3. Objectives. Adequate security of Air Force information and supporting information technology (IT) assets is a fundamental management responsibility. The Air Force implements and maintains the IA Program to adequately secure its information and IT assets. The objectives, listed below, will be met through the effective employment of the Air Force’s core IA disciplines of Communications Security (COMSEC), Computer Security (COMPUSEC), and Emissions

Security (EMSEC). The IA Program:

1.3.1. Ensures Air Force ISs operate securely by protecting and maintaining the confidentiality, integrity, and availability of IS resources and information processed throughout the system's life cycle.

1.3.2. Protects information commensurate with the level of risk and magnitude of harm resulting from loss, misuse, unauthorized access, or modification.

AFI33-200 23 DECEMBER 2008 7

Chapter 2

ROLES AND RESPONSIBILITIES

2.1. Under Secretary of the Air Force (SAF/US).

2.1.1. Ensures all Air Force-owned or controlled space systems meet the system specific IA requirements according to DoDD 8581.1, Information Assurance (IA) Policy for Space

Systems Used by the Department of Defense.

2.1.2. For all space acquisitions, ensures IA requirements are implemented in all phases of acquisitions according to the provisions in NSS 03-01, Guidance for DoD Space Systems

Acquisition Process.

2.2. Assistant Secretary of the Air Force (Acquisition) (SAF/AQ).

2.2.1. Ensures all IA requirements are implemented in all phases of non-space IS and service acquisitions, for research and development, test and evaluation, and in contracts.

2.2.2. Ensures Program Executive Officers (PEO) and Program Managers (PM) adhere to mandated IA acquisition standards outlined in DoDI 8580.1, Information Assurance (IA) in the Defense Acquisition System; the requirements of this instruction; and the certification and accreditation (C&A) requirements of AFI 33-210, Certification and Accreditation (C&A)

Program).

2.2.3. Ensures each program and system under its span of control develops an IA strategy according to this instruction and DoDI 8580.1.

2.2.4. Manages the process for preparing and reviewing Air Force acquisition program strategies and ensures IA has been appropriately addressed.

2.2.5. Represents the Air Force on policy and procedural matters regarding IA in the acquisition system.

2.2.6. Coordinates with USAF/A2 to ensure that Intelligence communications and information equipment, systems, and service acquisition efforts address IA life cycle requirements. Will coordinate with USAF/A2 to assign Air Force PM representatives for

Intelligence systems, equipment, networks, or services that will deploy on the Air Force-provisioned portion of the Global Information Grid (AF-GIG) or will utilize AF GIG capabilities but which were developed and/or acquired by non-Air Force entities.

2.3. Deputy Undersecretary of the Air Force, International Affairs (SAF/IA). Processes all requests for transfers of COMSEC materials and associated information for foreign governments and international organizations.

2.4. Secretary of the Air Force, Office of Warfighting Integration and Air Force Chief

Information Officer (SAF/XC). SAF/XC has the overall responsibility to develop, implement, and enforce policies, standards, strategies, and procedures to ensure the Air Force executes the most effective and efficient acquisition, integration, application, and management of information and IT assets. Further, as the Air Force Chief Information Officer, SAF/XC is the responsible official for Air Force owned and operated ISs.

8 AFI33-200 23 DECEMBER 2008

2.4.1. Ensures IA is an integral part of ISs and applications design, guaranteeing appropriate

IA controls are in place and provided to protect mission data and system resources.

2.4.2. Establishes the AF-GIG acceptable baseline risk level and IA controls.

2.4.3. Provides guidance, to implementing organizations, to mitigate threats commensurate with that risk level.

2.4.4. Provides guidance and solutions to organizations with operational requirements to meet the established national, DoD, Joint Chiefs of Staff, or Air Force baseline risk levels and controls for ISs.

2.4.5. Defines IA performance measures and metrics to identify enterprise-wide IA trends, to include IA related vulnerabilities and measures to mitigate them with an updated status of mitigation efforts using the program guidance in AFI 33-210.

2.4.6. Appoints the Designated Accrediting Authority (DAA) for the AF-GIG (AF-DAA) to execute specific responsibilities as outlined in AFI 33-210.

2.4.7. Review Internet Waiver/User Enclave Waiver requests for compliance to DOD GIG policy, DISN capability, and technical security requirements.

2.5. Secretary of the Air Force, Policy and Resources Directorate (SAF/XCP). SAF/XCP is the Air Force focal point to create an integrated, secure, net-centric environment to enable all aspects of the Air Force mission.

2.5.1. Develops, implements, and oversees an Air Force IA program focused on assurance of

Air Force-specific information and ISs consistent with DoD policies and defense-in-depth.

2.5.2. Directs the establishment of IA policies and procedures. Informs Air Force secretariat, Headquarters Air Force, and MAJCOMs about changes to DoD and Air Force IA management policies and procedures.

2.5.3. Oversees IA requirements planning, programming, budgeting, and execution in the

Air Force budget process and advocates for IA funding and manning with the Office of the

Secretary of Defense and Congress.

2.5.4. Documents required IA capabilities in the Warfighter, Agile Combat Support, and

ConstellationNet sub-enterprise architectures. Ensures IA capabilities are appropriately federated across the Air Force enterprise architecture. Directs and supports HQ AFCA in developing the ConstellationNet IA domain architecture.

2.5.5. Develops concepts and establishes policy for integrated support and configuration management of IA equipment.

2.5.6. Plans, programs, funds, implements, manages, and supports logistically the COMSEC aspects of programs, including centralized record maintenance of COMSEC equipment, components, and material.

2.5.7. Carries out FISMA-related Chief Information Officer (CIO) responsibilities and serves as SAF/XC’s primary liaison to the Air Force’s IA personnel.

2.5.7.1. Provides detailed information on the FISMA requirements via the annual Air

Force FISMA Reporting Guidance.

AFI33-200 23 DECEMBER 2008 9

2.5.7.2. Manages the annual assessment of Air Force IA Programs as required by

FISMA. Requests, through channels, support from Air Force organizations. The support will allow Secretary of the Air Force/Policy and Resources (SAF/XCP-2) to answer the annual FISMA report questions posed by the Office of Management and Budget.

2.5.7.3. Collects and reports IA management, financial, and readiness data to meet DoD

IA internal and external reporting requirements.

2.5.7.4. Ensures IA requirements are addressed and visible in all investment portfolios and investment programs according to AFI 33-401, Implementing Air Force

Architectures, and AFI 33-210.

2.5.8. Manages the IA education, training, and certification for Air Force IA professionals and users according to DoD 8570.01-M, Information Assurance Workforce Improvement

Program, Air Force Information Assurance Certification Implementation Plan.

2.5.8.1. Defines and promulgates IA education, training, and certification standards.

2.5.8.2. Establishes timelines IA professionals must maintain to meet DoD and Air Force standards.

2.5.8.3. Ensures the education, training, and certification of Air Force IA professionals and the awareness and training of Air Force IT users according to paragraph 3.38.

2.5.9. Ensures personnel security is an integral part of the overall Air Force IA program and that personnel assigned to IA duties meet established personnel security requirements in AFI

31-501, Personnel Security Program Management.

2.5.10. Represents the Air Force as voting member on DoD Configuration Control Boards

(CCB) or related to IA programs or issues (i.e., DoD Ports, Protocols, and Services [PPS]

CCB).

2.5.11. Provides Air Force representation on DoD working groups on or related to IA programs or issues.

2.5.12. Coordinates with the other military departments and government agencies to eliminate duplication and to exchange technical data on IA programs.

2.5.13. Appoints in writing the Air Force Certified TEMPEST Technical Authority (CTTA).

2.5.14. Provides Air Force representation to DoD Information Assurance Technology

Analysis Center, a formally chartered DoD institution that helps researchers, engineers, and program managers locate, analyze, use, and exchange scientific and technical information according to DoDD 3200.12, DoD Scientific and Technical Information (STI) Program

(STIP).

2.6. Deputy Chief of Staff, Intelligence, Surveillance, and Reconnaissance

(USAF/A2). Manages, integrates and implements all IA capabilities for all SCI ISs and all ISs within SCI facilities.

2.7. Office of the Air Force Civil Engineer (HQ USAF/A7C). Serves as the Air Force focal point for design and construction of facilities containing radio frequency interference and electromagnetic interference shielding.

10 AFI33-200 23 DECEMBER 2008

2.8. Headquarters Air Education and Training Command (HQ AETC).

2.8.1. Conducts and integrates IA education and training into initial military training courses, Air Force accession programs, formal schools, professional military education courses, and specialized training in Air Force Specialty Code-awarding courses according to

AFI 36-2201V1, Training Development, Delivery, and Evaluation, and the specific IA education and training requirements of DoD 8570.01-M.

2.8.1.1. Provides students with:

2.8.1.1.1. An understanding of IA and of the threat to and vulnerabilities of Air Force

ISs.

2.8.1.1.2. Knowledge of countermeasures available to overcome the threat.

2.8.1.1.3. Ways to apply the countermeasures.

2.8.1.2. Increases the depth of the formal training programs to enhance students’ potential to become involved in planning, programming, managing, operating, or maintaining information systems.

2.8.1.3. Ensures courses address those aspects of IA that could affect the success of critical operations.

2.8.2. Administers IA education to students attending Air University courses.

2.8.3. Coordinates IA education materials and course curriculum with HQ AFCA to ensure they are current and meet the needs of a modern Air Force IA workforce.

2.9. Headquarters Air Force Materiel Command (HQ AFMC).

2.9.1. Supports PEOs and PMs in the research, development, prototyping, test and evaluation, assessment, production, and sustainment of IA or IA-enabled capabilities of non-space Air Force systems, products, and techniques in consultation with the other MAJCOMs.

2.9.1.1. Develops and sustains processes for rapid IA capability insertion to address new or rapidly developing threats to the AF-GIG.

2.9.1.2. Conducts the Air Force Communications-Computer Systems Security Research, Development, Test, and Evaluation Program according to AFI 63-101, Operations of

Capabilities Based Acquisition System.

2.9.2. Ensures non-space PEOs and PMs comply with IA requirements outlined in DoDI

8580.1, AFI 63-101, this instruction, and AFI 33-210.

2.9.3. Ensures advanced development programs are reviewed for interoperability with IA equipment and systems.

2.9.4. Assists HQ AFCA in developing IA guidance and procedures for non-space ISs in the acquisition and development life cycle.

2.9.5. Establishes IA education and training for assigned PEOs and PMs according to the requirements outlined in DoD 8570.01-M.

2.9.6. Sustains a Public Key Infrastructure (PKI) program office to implement the Air Force portion of the DoD PKI and execute the designated responsibilities in AFI 33-202. Volume 6, Identity Management (will become AFSSI 8520, Identity Management).

AFI33-200 23 DECEMBER 2008 11

2.9.7. Sustains a Cryptographic Modernization program office to implement the Air Force portion of NSA’s COMSEC program and execute the designated responsibilities in AFSSI

4000-series publications.

2.9.8. Ensures IA-related configuration control information under its inventory control is available to the operations, maintenance, and logistics support organizations to maintain the integrity of countermeasures during an IS’s life cycle.

2.9.9. Establishes configuration control procedures to ensure the continuity and integrity of countermeasures for information technology processing national security information under its inventory management.

2.9.10. Ensures technical analyses, cost estimates, and modification proposals for information systems that process national security information consider TEMPEST design and installation requirements. Refer to: National Security Telecommunications and

Information Systems Security Advisory Memorandum TEMPEST/2-95, Red/Black

Installation Guidance, and AFSSI 7700, Emissions Security.

2.9.11. Cryptologic Systems Group (CPSG). Provides technical and PM support to IA Lead

Command programs, projects, and initiatives according to Air Force IA specialized publications.

2.10. Headquarters Air Force Space Command (HQ AFSPC).

2.10.1. Supports PEOs and PMs in the research, development, test and evaluation, and sustainment of IA or IA-enabled capabilities of Air Force space systems and products in consultation with the other MAJCOMs. This includes developing and sustaining processes for rapid IA capability insertion to address new or rapidly developing threats to the AF-GIG.

2.10.2. Ensures space PEOs and PMs comply with IA requirements outlined in DoDI

8580.1, NSS 03-01, this instruction, and AFI 33-210.

2.10.3. Assists HQ AFCA in developing IA guidance and procedures for space ISs in the acquisition and development life cycle.

2.10.4. Establishes IA education and training for space PEOs and PMs according to the requirements outlined in DoD 8570.01-M.

2.10.5. Participates in Cross Domain Solutions (CDS) program for AFSPC space mission systems. Advocates issues for customers with AFCA. Attends CDS meetings and participates in activities as required.

2.10.6. Executes the EMSEC program for space mission systems and coordinates with the

Air Force CTTA.

2.11. Air Force Network Operations Commander (AFNetOps/CC).

2.11.1. Directs Air Force Network Defense (NetD) in accordance with AFPD 10-7, Information Operations.

2.11.2. Executes duties as the AF-DAA according to AFPD 33-2 and AFI 33-210.

2.11.3. Serves as the single point of contact for processing and supporting Air Force IA-related intelligence requests from Air Force and DoD intelligence entities (e.g. threat

12 AFI33-200 23 DECEMBER 2008

assessment against the GIG). Provides SAF/XC staff with courtesy copies of requests and responses for assessment of impact on the Air Force IA Program.

2.11.4. Identify Air Force network intelligence requirements to USAF/A2.

2.11.5. Coordinates with Joint and Defense-wide program offices to ensure interoperability of IA solutions across the GIG.

2.11.6. Directs Air Force enclave boundary defense activities, measures, and operations.

2.11.7. Serves as the single IA coordination point for Joint or Defense Programs with plan to deploy ISs to Air Force enclaves according to the responsibilities and procedures outlined in

AFI 33-210.

2.11.8. Provides support to national, DoD, and Air Force level technical advisory groups

(TAG) [i.e., DIACAP TAG, DoD PPS TAG, etc.], as requested by SAF/XC.

2.11.9. Issues time compliance technical orders and modification kits for IA and IA-enabled equipment and ISs processing national security information under its inventory management control and scheduled for modification.

2.12. Air Force Network Operations Center (AFNOC).

2.12.1. Conducts the Air Force portion of Network Defense (NetD) mission.

2.12.2. Employs mechanisms and procedures to monitor all Air Force ISs to detect, report, and document unauthorized activity (successful or unsuccessful).

2.12.3. Institutes appropriate NetD countermeasures or corrective actions. Countermeasures will be coordinated with the OPR of the appropriate policy.

2.13. Air Force Information Operations Center (AFIOC).

2.13.1. Serves as member of DoD TAGs, as requested by SAF/XC or HQ AFCA.

2.13.2. Provides information on threats, vulnerabilities, and countermeasures associated with

IA.

2.13.3. Evaluates IA or IA-enabled products. Provides evaluation reports to HQ AFCA and applicable program management offices.

2.13.4. Develops Tactics, Techniques, and Procedures.

2.13.5. Provides EMSEC technical support according to the AFSSI 7000-series publications.

2.14. Headquarters Air Force Communications Agency (HQ AFCA). On behalf of

SAF/XCP and the Senior IA Officer, as defined in AFPD 33-2:

2.14.1. Reviews, evaluates, and interprets national, federal, and DOD IA policy and doctrine. Makes recommendations on implementation of the policy and doctrine to

SAF/XCPP.

2.14.2. Develops Air Force IA policies and procedures. Develops, coordinates, and maintains SAF/XC approved Air Force publications pertaining to IA.

2.14.3. Develops, coordinates, promulgates, and maintains Air Force (component-level) IA

Controls applicable to ISs residing on or connecting to the AF-GIG, if required.

AFI33-200 23 DECEMBER 2008 13

2.14.4. Provides guidance and support to MAJCOM and wing IA offices in developing, implementing, and managing their IA programs.

2.14.5. Provides guidance to acquisition managers to consider IA requirements early in the system life cycle according to AFI 63-101 and AFI 33-210.

2.14.6. Serves as a member on national, federal, and DoD TAGs as Air Force subject matter expert for IA or IA-related issues (i.e., DIACAP TAG, TEMPEST TAG, DoD PPS TAG, etc.)

2.14.7. Manages the process of assessing security features of government-produced and commercial-off-the-shelf (COTS) software and hardware subsystems, according to AFI 33-

210.

2.14.8. Develops applicable IA techniques and procedures with Air Force-wide implications.

2.14.9. Processes requests for exceptions, deviations, or waivers to Air Force IA policy and instructions.

2.14.10. Serves as the Air Force Lead Command for the Air Force implementation of DoD

IA programs, projects, and initiatives according to AFI 10-901, Lead Operating Command—

Communications and Information Systems Management.

2.14.10.1. Develops the operational and maintenance concepts for all aspects of IA Lead

Command programs, in coordination with participating and operating commands.

2.14.10.2. Identifies, prioritizes, and documents IA user requirements in conjunction with the MAJCOMs.

2.14.11. Manages the Air Force CDS program.

2.14.11.1. Advocates issues from customers with Air Staff and the CDS Secret Internet

Protocol Router Network (SIPRNet) Connection Approval Office at Defense Information

Systems Agency (DISA).

2.14.11.2. Attends CDS meetings and participates in activities as required.

2.14.11.3. Serves as the Air Force focal point for coalition networking issues specific to the Command, Control, Communications and Computers Infostructure, core e-mail, file sharing, print, collaboration tools, VTC, and web browsing capabilities. Coordinates with focal points of other functional communities (HAF/A2, etc.) on coalition networking issues for other infostructures (Intelligence, Surveillance and Reconnaissance, etc.).

2.14.12. Manages the Air Force PPS program. Advocates issues from customers with Air

Staff and the DoD PPS Program Manager at DISA.

2.14.13. Manages and executes the IA Notice and Consent certification process for the Air

Force according to the procedures within AFI 33-219, Telecommunications Monitoring and

Assessment Program (Section C) (will become AFSSI 8561, IA Notice and Consent.

2.14.14. Executes funding provided by OSD to train and certify the Air Force IA workforce according to DoDD 8570.01 and DoD 8570.01-M.

2.14.15. Advocates and coordinates IA manpower requirements with operating and participating commands.

14 AFI33-200 23 DECEMBER 2008

2.14.16. Maintains a list of recommended COTS products supporting IA and IA-enabled solutions using the Infostructure Technology Reference Model (i-TRM) process.

2.14.17. Ensures Air Force contracting guidance reflects national, federal, DoD, and Air

Force IA policy and procedures.

2.14.18. Advises HQ AETC on IA education materials and course curriculum.

2.14.19. Executes the Air Force COMSEC program.

2.14.19.1. Manages COMSEC incident processing and analysis.

2.14.19.2. Manages Cryptographic Access Program. Includes development and promulgation of AFCOMSEC Form 9, Cryptographic Access Certificate.

2.14.19.3. Performs COMSEC responsibilities as mandated by the AFSSI 4000-series publications. This includes developing necessary forms:

2.14.19.3.1. AF Form 4167, Two Person COMSEC Material Inventory

2.14.19.3.2. AF Form 4168, COMSEC Responsible Officer and User Training

Checklist

2.14.20. Executes the Air Force EMSEC program.

2.14.20.1. Acts as the Air Force CTTA.

2.14.20.2. Performs EMSEC responsibilities as mandated by the AFSSI 7000-series publications. This includes developing necessary forms to include AF Form 4170, Emission Security Assessments/Emission Security Countermeasures Reviews

2.14.21. Manages the Air Force Information Assurance Assessment and Assistance Program

(IAAP) according to AFI 33-230 (will become AFSSI 8560, Information Assurance

Assessment and Assistance Program).

2.14.22. Develops the ConstellationNet IA domain architecture, related IA service profiles, and implementation guidance.

2.15. Air Force Office of Special Investigations (AFOSI). To the extent authorized by statute, Executive Order, and regulation, provides (on a recurring basis) to SAF/XC, SAF/AQ, SAF/US, AFNetOps, and other appropriate organizations with the following:

2.15.1. Threat information,

2.15.2. Analysis of counterintelligence (CI) threats, and

2.15.3. Cyber-CI threat assessments concerning current and emerging threats to the AF-GIG for developing IA countermeasure capabilities in support of the Air Force IA Program and IS

IA Program.

2.16. Air Force Personnel Center (AFPC) . Provides IA awareness and education for

PALACE ACQUIRE-accessioned civilians through the civilian career programs according to the requirements outlined in DoD 8570.01-M.

2.17. United States Air Force Academy.

2.17.1. Conducts IA education during initial military training according to the requirements outlined in DoD 8570.01-M.

AFI33-200 23 DECEMBER 2008 15

2.17.2. Coordinates IA education materials with HQ AFCA.

2.18. Single Manager, Program Manager, or Project Manager. Identifies, implements, and ensures full integration of IA into all phases of their acquisition, upgrade, or modification programs, including initial design, development, testing, fielding, operation, and sustainment.

Reference AFI 63-101, Operations of Capabilities Base Acquisition System and AFI 33-210 for guidance.

2.19. Other Agencies Acquiring or Developing Information Technology. Assume single manager responsibilities when developing systems or software outside a program management office structure. Reference AFI AFI 63-101 and AFI 33-210 for guidance.

2.20. Designated Accrediting Authority. Reference AFI 33-210 for DAA appointment, assignment, delegation, training requirements, and key roles and responsibilities.

2.20.1. Manages and executes the Air Force IS IA Program according to this instruction and

AFI 33-210.

2.20.2. Makes appropriate decisions to balance security requirements, mission, and resources against the defined or perceived threat.

2.20.3. Approves exceptions, deviations or, waivers to Air Force IA requirements according to this instruction and AFI 33-210 for ISs under their purview.

2.21. Information System Owners (ISO). Reference AFPD 33-2 and AFI 33-210 for ISO assignment, roles and responsibilities.

2.22. System Level Information Assurance Manager (IAM). (NOTE: For system-level IA program see AFI 33-210.

2.22.1. Develops an IS-level IA program that identifies:

2.22.1.1. IA Architecture, requirements, objectives, and policies.

2.22.1.2. Personnel.

2.22.1.3. Processes and procedures.

2.22.2. Receives training and certification to DoD baseline requirements at IA Technical

Level II or III, as applicable. Completes and maintains required IA Workforce Management training according to Air Force Implementation Plan For DoD 8570.01-M.

2.22.3. Implements and maintains an IS-level IA program and documents the IA program through the Air Force C&A process in AFI 33-210.

2.23. System Level Information Assurance Officer (IAO). (NOTE: For system-level IA program see AFI 33-210. Assists the enclave or information system-level IAM in meeting the duties and responsibilities outlined in paragraph 2.23., above and:

2.23.1. Receives training and certification to DoD baseline requirements at IA Technical

Level I or II, as applicable. Completes and maintains required IA Workforce Management training according to Air Force Implementation Plan For DoD 8570.01-M.

2.23.2. Ensures all users have the requisite security clearances and supervisory need-to-know authorization, and are aware of their IA responsibilities before being granted access to

Air Force ISs according to AFSSI 8522, Access to Information Systems.

16 AFI33-200 23 DECEMBER 2008

2.23.3. In coordination with the IAM, initiates protective or corrective measures when an IA incident or vulnerability is discovered according to AFI 33-138, Enterprise Network

Operations Notification and Tracking.

2.23.4. Ensures IA and IA-enabled software, hardware, and firmware comply with appropriate security configuration guidelines as referenced in Chapter 3 of this instruction.

2.23.5. Ensures all IS IA-related documentation is current and accessible to properly authorized individuals.

2.23.6. Implements and enforces all Air Force IS IA policies and procedures, as defined by its security C&A documentation as prescribed by AFI 33-210.

2.24. MAJCOM IA Office or Function. Develops, implements, oversees, and maintains a

MAJCOM IA program that identifies IA architecture, requirements, objectives and policies;

personnel; and processes and procedures.

2.24.1. Designates an IAM (for organization-level IA program) to SAF/XCPP and AFCA.

Individuals in this position must be US citizens.

2.24.2. Receives training and certification to DOD baseline requirements at IA Management

Level III. Completes and maintains required IA Workforce Management training according to Air Force Information Assurance Certification Implementation Plan (will become AFSSI

8570). NOTE: If the individual is performing only COMSEC management duties, DoD

8570.01-M does not require the individual to be certified under this program.

2.24.3. Plans, organizes, implements, and controls MAJCOM COMSEC activities. Acts as the MAJCOM COMSEC office of primary responsibility. Executes roles and responsibilities in the AFSSI 4000-series publications.

2.24.4. Establishes COMPUSEC within the MAJCOM IA office and is the office of primary record for MAJCOM COMPUSEC. Executes roles and responsibilities in the AFSSI 8500-series publications.

2.24.5. Establishes EMSEC within the MAJCOM IA office and is the office of primary responsibility for MAJCOM EMSEC requirements. Executes roles and responsibilities in the

AFSSI 7000-series publications.

2.24.6. Serves as a member of any appropriate Configuration Control Boards (CCB) or steering groups to address MAJCOM IA program issues.

2.24.7. Coordinates IAAP visits and associated responsibilities according to AFI 33-230

(will become AFSSI 8560).

2.24.8. Ensures proper identification of manpower and personnel assigned to IA functions.

Ensure this information is entered and maintained in the appropriate Air Force personnel databases.

2.24.9. Maintain organizational e-mail account with an SMTP alias of

<majcom>.ia@us.af.mil.

2.25. Wing IA Office. Develops, implements, oversees and maintains a wing IA program that identifies IA architecture, requirements, objectives and policies; personnel; and processes and procedures. NOTE: For bases with more than one wing, the designated host wing is responsible

AFI33-200 23 DECEMBER 2008 17

to provide this function, unless otherwise indicated in an agreement (e.g. Memorandum of

Understanding).

2.25.1. Designates an IAM (for organization-level IA program) to their MAJCOM IA office.

Individuals in this position must be US citizens.

2.25.2. Receives training and certification to DOD baseline requirements at IA Management

Level I or Level II for all assigned IA personnel. Completes and maintains required IA

Workforce Management training according to Air Force Information Assurance Certification

Implementation Plan (will become AFSSI 8570). NOTE: If the individual is performing only

COMSEC management duties, DoD 8570.01-M does not require the individual to be certified under this program.

2.25.3. Manages the overall COMSEC posture of their installation. Appoints one primary and at least one alternate COMSEC manager to oversee the wing COMSEC program and to assist and advise them in COMSEC matters. The wing commander may delegate appointment authority to the unit commander of the supporting COMSEC account.

2.25.4. Establishes COMPUSEC in the host wing IA office. The IA office addresses all

COMPUSEC requirements on the base, including those of tenant units (i.e., FOAs, DRUs, and other MAJCOM units) unless formal agreements exist.

2.25.5. Establishes EMSEC in the host wing IA office. The IA office addresses all EMSEC requirements on the base, including those of tenant units (i.e., FOAs, DRUs, and other

MAJCOM units) unless there are other formal agreements.

2.25.6. Assists all base organizations and tenants in the development and management of their IA program.

2.25.7. Provides oversight and direction to IAOs (for organization-level IA programs) according to this instruction and specialized IA publications. Specific responsibilities include but are not limited to:

2.25.7.1. Ensures IAOs receive proper IA management training.

2.25.7.2. Ensures IAOs are aware of and follow IA policies and procedures.

2.25.7.3. Ensures IAOs review weekly alerts, bulletins, and advisories impacting the security of an organization’s IA program.

2.25.8. Ensures security instructions, guidance, and standard operating procedures (SOP) are prepared, maintained, and implemented by each unit.

2.25.9. Monitors implementation of security guidance and directs appropriate actions to remedy security deficiencies.

2.25.10. Ensures IA inspections, tests, and reviews are coordinated.

2.25.11. Ensures all IA management review items are tracked and reported.

2.25.12. Develops reporting procedures.

2.25.12.1. Report security violations and incidents to the DAA and Air Force network operations activities according to AFI 33-138, Enterprise Network Operations

Notification and Tracking.

18 AFI33-200 23 DECEMBER 2008

2.25.12.2. Ensures incidents are properly reported to the DAA and the Air Force network operations reporting chain, as required, and that responses to IA-related alerts are coordinated; all according to the requirements of AFI 33-138.

2.25.13. Ensures procedures are developed and implemented according to configuration management (CM) policies and practices for authorizing use of software on ISs.

2.25.14. Serves as member of the base-level CM board or delegates this responsibility to an appropriate IAO.

2.25.15. Maintain organizational e-mail account with an SMTP alias of

<wing>.ia@us.af.mil.

2.26. Organizational Commander. The organizational commander may locate his/her information assurance related roles and responsibilities in AFI 33-101, Commanders Guidance and Responsibilities.

2.27. Organizational IAO. IAOs are assigned to each organization by the organization commander or other cognizant authority (i.e., group-level commander, Wing IA office) when IA functions are consolidated to a central location or activity. Additional (subordinate) IAO positions may be assigned for additional support at the discretion of organizations or based upon mission requirements, however, only one primary and one alternate IAO is required. An organizational IAO:

2.27.1. Develops, implements, oversees, and maintains an organization IA program that identifies IA requirements, personnel, processes, and procedures.

2.27.2. Receives training and certification to DoD baseline requirements at IA Management

Level I. Completes and maintains required IA Workforce Management training according to

Air Force Information Assurance Certification Implementation Plan (will become AFSSI

8570).

2.27.3. Supervises the organization’s IA program.

2.27.4. Implements and enforces all Air Force IA policies and procedures using the guidance within this instruction and applicable specialized IA publications.

2.27.5. Assists the wing IA office in meeting their duties and responsibilities.

2.27.6. Ensures all users have the requisite security clearances, supervisory need-to-know authorization, and are aware of their IA responsibilities (via IA training) before being granted access to Air Force ISs according to AFSSI 8522.

2.27.7. Ensures all users receive IA refresher training on an annual basis.

2.27.8. Ensures IT is operated, used, maintained, and disposed of properly and in accordance with the IT’s security C&A documentation as prescribed by AFI 33-210.

2.27.9. Ensures proper CM procedures are followed. Prior to implementation and contingent upon necessary approval, according to this instruction and AFI 33-210, coordinates any changes or modifications to hardware, software, or firmware with the wing IA office and system-level IAM or IAO.

2.27.10. Reports IA incidents or vulnerabilities to the wing IA office.

AFI33-200 23 DECEMBER 2008 19

2.27.11. In coordination with the wing IA office, initiates protective or corrective measures when an IA incident or vulnerability is discovered.

2.27.12. Implements required IA (COMSEC, COMPUSEC and EMSEC) countermeasures.

2.27.13. Maintains IA countermeasures.

2.27.14. Initiates requests for temporary and permanent exceptions, deviations, or waivers to

IA requirements or criteria according to this instruction and applicable specialized IA publications.

2.27.15. Works with client support administrator(s) and unit security manager(s) in resolving classified message incidents.

2.28. Information System Users. Authorized users shall comply with the guidance within AFI

33-100, User Responsibilities and Guidance For Information Systems.

20 AFI33-200 23 DECEMBER 2008

Chapter 3

POLICY

Section 3A—Air Force IA Program

3.1. Air Force IA Program. The Air Force IA Program synchronizes and standardizes the IA requirements of Air Force ISs through the following means:

3.1.1. Integration of IA into all aspects of the Air Force Enterprise Architecture according to

AFI 33-401.

3.1.2. Coordination of IA projects across multiple investments through Lead Command management according to AFI 10-901.

3.1.3. Improving the Air Force IT and National Security Systems (NSS) acquisition and fielding process through the IT Lean Process according to AFI 63-101 and AFI 33-210.

Improvements are achieved in this streamlined process through appropriate oversight, standardized design and test, networthiness assessment, and fielding processes. The IT Lean

Process aligns with the DIACAP required for all DoD-owned or controlled ISs that receive, process, store, display, or transmit DoD information. It does not alleviate the need to execute the DIACAP; however, the IT Lean Process and the integrated IA Controls in the Security, Interoperability, Supportability Sustainability, and Usability (SISSU) checklist can help the program team identify IA requirements. Refer to AFI 33-210 for complete policy and pointers to implementation procedures.

3.1.4. Clear assignment of Air Force organizational and IT level IA roles and responsibilities are outlined via this instruction and supporting IA specialized publications.

3.1.5. Development and management of a professional IA workforce according to the Air

Force Information Assurance Certification Implementation Plan (will become AFSSI 8570).

3.2. IA Strategy. IA is traced, by SAF/XCP, as a programmatic entity in the Planning, Programming, Budgeting, and Execution system with visibility extended into budget execution.

Air Force strategic IA goals and annual IA objectives are established (according to the DoD

Information Management Strategic Plan). Funding and progress toward those objectives are tracked, reported, and validated through the Air Force IA Strategic Plan (upon approval of the plan).

3.3. Air Force Specialized IA Publications. These publications document implementation of

Air Force IA policy objectives, under the authority of AFI 33-102, Communications and

Information Specialized Publications. These publications are numbered based upon the primary subject groups cited below. Publication OPRs will regularly update or expand the content to keep pace with new threats and manage any challenges associated with introduction of emerging technologies.

3.3.1. AFSSI 3000 Series – COMSEC Equipment.

3.3.2. AFSSI 4000 Series – COMSEC Operations.

3.3.3. AFSSI 7000 Series – EMSEC.

3.3.4. AFSSI 8500 Series – IA Implementation.

AFI33-200 23 DECEMBER 2008 21

3.3.5. As described in AFI 33-102, the unclassified specialized publications will be hosted on the Air

Force IA website (https://private.afca.af.mil/ip). The For Official Use Only (FOUO) specialized publications will be hosted on the Air Force IA Documentation (FOUO) Community of Practice

(CoP) (Hhttps://afkm.wpafb.af.mil/ASPs/CoP/ClosedCOP.asp?Filter=OO-SC-CA-11H).

Classified specialized publications will be acquired from the office of primary responsibility.

3.4. IA Workforce. This instruction and supporting IA specialized publications standardize the naming conventions and functions of Air Force organizational (management) and IT level

(technical or system-level) IA personnel. These documents also prescribe training and certification requirements according to national and DoD policy consistent with and supplementary to the guidance outlined in the Air Force Information Assurance Certification

Implementation Plan (will become AFSSI 8570).

3.5. IA Awareness. All authorized users of Air Force IT must maintain an understanding of Air

Force IA policies and procedures commensurate with their individual responsibilities. For a list of these and other user responsibilities, reference AFI 33-100.

3.6. Network Defense (NetD). Reference the below guidance for NetD:

3.6.1. AFPD 10-7, Information Operations, and subordinate AFIs govern Network Defense and INFOCON procedures.

3.6.2. AFPD 13-3, Air Force Network Operations (AFNetOps), governs command and control of the AF-GIG.

3.7. IA Assessments. Designated Air Force (and DoD) activities will regularly and systematically assess the IA posture of Air Force networks and ISs as well as IA services and supporting infrastructures.

3.7.1. Auditors perform audits according to Air Force Audit Agency guidance.

3.7.2. Authorized activities perform host and network vulnerability or penetration testing according to guidance published by USAF/A3O-CN.

3.7.3. ISOs and PMs comply with formal testing and certification activities according to AFI

33-210.

3.7.4. Performance measures and metrics will assess enterprise-wide (and individual elements where appropriate) IA performance and assess IA trends. The measurements and metrics will encompass, but are not limited to, federal and DoD IA reporting requirements.

3.7.5. Information Assurance Assessment and Assistance Program. The IAAP is a staff function whose purpose is to ―find and fix‖ wing level IA problems. It is neither a function of, nor does it replace Inspector General or Air Force Audit Agency activities. The IAAP accomplishes ―staff assistance‖ by reviewing and assessing processes, identifying problems, providing assistance to help resolve the problems, and recommending solutions. The IAAP team provides technical and training assistance in all IA areas. The IAAP consists of two parts: assessment and assistance. IAAPs are performed according to AFI 33-230 (will become AFSSI 8560) through the review of areas itemized on AF Form 4160, Information

Assurance Assessment and Assistance Program (IAAP) Criteria.

3.8. Notice and Consent Certification. All Air Force installations, circuits, and ISs must comply with DoD notice and consent certification requirements for monitoring to occur by https://private.afca.af.mil/ip https://afkm.wpafb.af.mil/ASPs/CoP/ClosedCOP.asp?Filter=OO-SC-CA-11H

22 AFI33-200 23 DECEMBER 2008

authorized activities. Comply with installation certification procedures found in AFI 33-219, (Section C) (will become AFSSI 8561).

3.9. Connection Management. SAF/XCD provides Air Force representation to the Defense

Information Systems Network (DISN) Security Accreditation Working Group (DSAWG). The

DSAWG represents the DISN community and advises the DISN…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .