afi33-115.pdf

PDF 951 KB Posted

Attached to
Facilitate Other Maintenance Federal contract opportunity
Solicitation number
FA8224-16-R-0021
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

About this file

afi33-115

View the file

Other files for this federal contract opportunity

Other files attached to Facilitate Other Maintenance, newest first.
File Type Posted
PWS_AMXG_FOM_27_Apr_16.docx DOCX document
FA8224-16-R-0021-0003.pdf PDF
FA8224-16-R-0021-02.doc DOC document
FOM_Answers_(3).docx DOCX document
PWS_AMXG_FOM_17_Mar_16.docx DOCX document
FOM_Answers.docx DOCX document
afman33-282.pdf PDF
afi32-7086.pdf PDF
afi21-102.pdf PDF
FA8224-16-R-0021-01.doc DOC document
AMXGOI 21-12.pdf PDF
afi23-101.pdf PDF
afi21-101_afmcsup_oo-alcsup.pdf PDF
afman33-152.pdf PDF
afi21-102_afmcsup.pdf PDF
AFI31-101.pdf PDF
FOM_Answers_(2).docx DOCX document
afi31-501_afmcsup_i.pdf PDF
afman23-122.pdf PDF
AMXGOI 24-5.pdf PDF
afi10-701.pdf PDF
afh23-123v1.pdf PDF
afscman21-102.pdf PDF
afi32-7086_hillafbsup_i.pdf PDF
afpd24-3.pdf PDF
afi33-200.pdf PDF
AMXGOI 21-7.pdf PDF
CDRL_A002_Quality_System_Plan.pdf PDF
FA8224-16-R-0021.doc DOC document
CDRL_A005_Management_Plan.pdf PDF
CDRL_A003_Safety_Program_Plan(SSPP).pdf PDF
CDRL_A004_Accident_Report.pdf PDF
PWS_AMXG_FOM_17_Feb_16.docx DOCX document
CDRL_A001_Status_Report.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF THE AIR FORCE

WASHINGTON, DC

OFFICE OF THE SECRETARY

AFI33-115_AFGM2015-01

29 October 2015

MEMORANDUM FOR DISTRIBUTION C

MAJCOMs/FOAs/DRUs

FROM: SAF/CIO A6

1800 Air Force Pentagon Washington DC 20330-1720

SUBJECT: Air Force Guidance Memorandum (AFGM) 2015-01, for Air Force Instruction (AFI) 33-115, Air Force Information Technology (IT) Service Management.

By Order of the Secretary of the Air Force, this Air Force Guidance Memorandum provides Point of Contact (POC) information for customers requesting changes to Information Technology (IT) and/or related services as outlined in para 4.10.3 of AFI 33-115 and further detailed in para 2.2, 2.5, 2.6, and 2.8 of AFI 33-

150. Compliance with this memorandum is mandatory. To the extent its directions are inconsistent with other Air Force publications, the information herein prevails, IAW AFI 33-360, Publications and Forms Management.

The following guidance applies to HAF/SAF levels ONLY. All lower levels must contact their respective Communications Focal Point (CFP) for further guidance (IAW AFI 33-115, para 5.1.7).

New To the Customer Requirements

• The HAF/SAF customer shall coordinate the requirement with the appropriate AFSPC functional directorate. That AFSPC functional directorate shall work with the AFSPC A5/8 and the AFSPC A2/3/6 to determine if the customer request falls under the AF Cyberspace Infrastructure Planning System (CIPS) process or the Joint Capabilities Integration and Development System (JCIDS) process.

• The customer enters a CIPS requirement into the CIPS Program for processing and the implementation is negotiated between the customer and implementing organizations.

• If it is determined that the customer requirement falls under the JCIDS process the requirement is further refined between the AFSPC A5/8 and the HAF/A5.

The Information Dominance Flight Plan provides the strategic framework to articulate the cyber challenges faced by the Air Force as well as specific actions for moving forward across all Air Force core functional areas. The plan guides the efforts of the future Enterprise Architecture as well as the systematic alignment of resources across all Air Force Components. The strategic framework shapes the Portfolio Management and Capital Planning and Investment Control Process that is addressed in AFI 33-141. As such, any IT solutions requested as a result of these AFIs or this AFGM must be aligned to the goals of this strategic framework. This Flight Plan may be found at http://www.safcioa6.af.mil/.

http://www.safcioa6.af.mil/

Questions regarding the strategy or this policy may be forwarded to the SAF/CIO A6SS Strategy and Policy Division, usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil. This memorandum becomes void after one year has elapsed from the date of this memorandum, or upon publication of an Interim Change or rewrite of the affected publication, whichever is earlier.

WILLIAM J. BENDER, Lt Gen, USAF Chief, Information Dominance and Chief Information Officer

Attachment:

1. HAF/SAF IT/Cyberspace Operational Baseline Modification Process mailto:usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil

Attachment 1 HAF/SAF IT/Cyberspace Operational Baseline Modification Process

NOTE: All “e.g.” directorates used as an example only. Your customer may vary.

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE INSTRUCTION 33-115

16 SEPTEMBER 2014

Communications and Information

AIR FORCE INFORMATION TECHNOLOGY

(IT) SERVICE MANAGEMENT

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available for downloading or ordering on the e-Publishing website at http://www.e-publishing.af.mil.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/A6CS

Supersedes: AFI33-115V1, 24 May 2006, AFI33-115V2, 14 April 2004, AFI33-115 V3, 15 April 2004, AFI33-129, 3 February 2005, and

AFI33-138, 28 November 2005

Certified by: SAF/A6C

(Maj Gen Earl Matthews)

Pages: 47

This Air Force Instruction (AFI) defines AF IT Service Management and assigns responsibilities for standardization and management of IT Services in the AF. This instruction implements AF

Policy Directive (AFPD) 33-1, Cyberspace Support, Department of Defense (DoD) Instruction

(DoDI) 8410.01, Internet Domain Name Use and Approval, DoDI 8410.02, NetOps for the

Global Information Grid (GIG), DoDI 8410.03, Network Management (NM) and DoDI 8550.01, DoD Internet Services and Internet-Based Capabilities. This instruction is consistent with

AFPD 33-2, Information Assurance (IA) Program; AFPD 33-3, Information Management;

AFPD 33-4, Information Technology Governance; and AFPD 10-17, Cyberspace Operations.

This instruction provides guidance, direction and assigns responsibilities for the Air Force

Information Networks (AFIN) as the Air Force provisioned portion of the DoD Information

Networks (DoDIN). This directive applies to all military and civilian Air Force personnel, the

Air Force Reserve (AFR), and Air National Guard (ANG). This publication shall be applied to contractors or other persons through the contract or other legally binding agreement with the

Department of the Air Force. The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See AFI 33-360, Publications and Forms Management, Table 1.1 for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the Publication

OPR for non-tiered compliance items. Send recommended changes or comments to the Air http://www.e-publishing.af.mil./

2 AFI33-115 16 SEPTEMBER 2014

Force Cyberspace Strategy & Policy Division (SAF/A6CS) using AF Form 847, Recommendation for Change of Publication.

Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with (IAW) Air Force Manual (AFMAN) 33-363, Management of

Records, and disposed of in accordance with Air Force Records Information Management

System (AFRIMS) Records Disposition Schedule (RDS). See Attachment 1 for a glossary of references and supporting information.

SUMMARY OF CHANGES

This is a total revision of AFI 33-115. Information from AFI 33-115 Volume 1, Network

Operations, AFI 33-115 Volume 2, Licensing Network Users and Certifying Network

Professionals, AFI 33-115 Volume 3, Air Force Network Operating Instructions, AFI 33-129, Web Management and Internet, and AFI 33-138, Enterprise Network Operations Notification and Tracking, were incorporated in this document. AFMAN 33-152, User Responsibilities and

Guidance for Information Systems, provides guidance for responsible use of the Internet that was previously covered by AFI 33-129 and user certification requirements previously covered by AFI

33-115V2. Network professional certification requirements are covered by AFMAN 33-285, Information Assurance (IA) Workforce Improvement Program. Methods and Procedures

Technical Order (MPTO) 00-33A-1109, Vulnerability Management, provides vulnerability notification and tracking processes and procedures previously covered by AFI 33-138. AFPD

10-17, Cyberspace Operations, and supporting AFIs, provides AF policy and assigns responsibility for the planning and execution of Cyberspace Operations including DoDIN

Operations. AFI 10-1701, Command and Control (C2) of Cyberspace, provides Command and

Control (C2) guidance for DoDIN Operations within the AF.

1. Purpose

2. Objectives

3. Background

Figure 1. Information Environment Relationships

4. Roles and Responsibilities

5. AF IT Services Framework

Figure 2. AF IT Services Framework

6. AFIN Baseline Management

7. Operation of AF IT Services within the AFIN

Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 37

AFI33-115 16 SEPTEMBER 2014 3

1. Purpose. This instruction defines AF IT Service Management and assigns responsibilities for the configuration, provisioning, maintenance, and management of AFIN using an IT Service

Management (ITSM) framework to further integrate capabilities and maintain configuration control of AF networks and data servers. This instruction serves as the single reference for AF

IT Service Management policy and applies to all personnel who manage, configure, operate, maintain, defend, or extend any portion of the AFIN or provide support within the AF for the

DoDIN and the Joint Information Environment (JIE).

1.1. Procedural guidance supporting this AFI is contained in Methods and Procedures

Technical Orders (MPTOs) directing standard processes for management, standardization, and maintenance of AF IT Services applicable to all AF personnel, see paragraph 7.3.

1.2. Cyberspace operational orders as defined in AFI 10-1701 (e.g., AF Cyber Tasking

Orders, Cyber Control Orders, AF Time Compliance Network Orders) shall take precedence over information contained in this AFI and supporting MPTOs if there is a conflict.

2. Objectives. The primary objective of this AFI is to establish and define AF IT Service

Management with roles and responsibilities to ensure the AFIN is designed, built, configured, secured, operated, maintained, and sustained to meet mission requirements. This AFI also provides guidance regarding migration of AF enterprise capabilities (core services, applications, and systems) to the JIE according to DoD guidance. AF IT Service Management integrates, secures, and manages the AFNET/AFNET-S with processes and capabilities to enable the seamless, secure, and reliable exchange of information across the AFIN and the DoDIN. The

AFNET is the AF’s underlying unclassified network that enables AF operational capabilities and lines of business. AFNET-S is the secure AFNET.

2.1. This AFI and supporting 00-33 series MPTOs shall not alter or supersede the existing authorities and policies of the Director of National Intelligence (DNI) regarding the protection of Sensitive Compartmented Information (SCI) systems or intelligence, surveillance, reconnaissance mission and mission support systems or higher authoritative guidance governing Special Access Program (SAP) systems. When DNI or SAP authorities fail to address areas covered by this AFI, this AFI and associated MPTOs will be followed.

If there is conflict between this AFI and associated MPTOs with guidance issued by DNI or

SAP authorities, DNI or SAP guidance will take precedence.

2.2. For this instruction, the term Major Command (MAJCOM) also applies to Numbered

Air Force (NAF), Field Operating Agency (FOA) and Direct Reporting Unit (DRU) when not assigned to a MAJCOM.

2.3. All AF organizations will follow this policy when extending AF IT Services.

3. Background. The AF Information Environment consists of AF unique information capabilities across the IT Governance Mission Areas: Business (BMA), Warfighting (WMA), Defense Intelligence (DIMA) and Information Environment (IEMA). The AF Information

Environment includes the IT systems, components and networks of the Defense Business

Systems, National Security Systems (NSS), Platform IT, Enterprise Core Services and Common

Computing Environments as depicted in Figure 1. The AFIN is the globally interconnected, end-to-end set of AF unique information capabilities and associated processes for collecting, processing, storing, disseminating, and managing information on-demand to warfighters, policy makers, and support personnel, including owned and leased communications and computing

4 AFI33-115 16 SEPTEMBER 2014

systems and services, software (including applications), data, and security. The AFIN can be considered the networked AF Information Environment. Where known, this AFI will depict the specific AF capabilities and services which will transition to DoD’s secure joint information environment (JIE). JIE is comprised of shared IT infrastructure, enterprise services, and a single security architecture to achieve full spectrum superiority, improve mission effectiveness, increase security and realize IT efficiencies.

Figure 1. Information Environment Relationships.

3.1. AF IT Service Management enables a robust and resilient net-centric environment providing the means to establish and extend the AFIN. AF IT Service Management supports rapidly evolving mission processes and warfighter requirements which require an optimized, stable, and enterprise managed AFIN postured to integrate with and support the JIE. AF IT

Service Management encompasses management of common IT functions, actions, and capabilities to provide Common Computing Environments, Application Support Services, and Enterprise Core Services. Additionally, AF ITSM standardizes select ITSM processes for all information systems (e.g., Vulnerability Management).

3.2. AF IT Service Management is aligned with the Defense Information Technology

Infrastructure Library (ITIL) as it transitions to the Defense Enterprise Service Management

AFI33-115 16 SEPTEMBER 2014 5

Framework (DESMF), and DoD Directive (DoDD) 8000.01, Management of the Department of Defense Information Enterprise. These services and the standard methods and procedures in the supporting MPTOs will continue to evolve to support the AF’s management of IT under the JIE construct. These services must align with high level guidance and strategic goals of the AF Enterprise Architecture. For more information on enterprise architecture, see

AFI 33-401, Air Force Architecting.

3.3. AFI 10-1701 implements the C2 of Cyberspace Operations and while this AFI directs specific ITSM functions which support DoDIN Operations. Together, these two instructions direct operations and support of the AFIN for the business and warfighting mission areas including the Cyberspace Operations mission. Capabilities to secure and protect the AFIN must be integrated throughout AF networks and systems following Cybersecurity policy

(previously known as IA). Cybersecurity inherent in AF networks and systems are further enhanced by Defensive Cyberspace Operations (DCO) under Cyberspace Operations. DCO may be integrated with or direct changes to cybersecurity in AF networks and systems under

C2 of Cyberspace Operations as it directs AFIN operations and defense. Note: DoD defines

DoDIN Operations as the actions taken to design, build, configure, secure, operate, maintain, and sustain DOD communications systems and networks in a way that creates and preserves data availability, integrity, confidentiality, as well as user/entity authentication and non-repudiation.

4. Roles and Responsibilities. Roles and responsibilities for AF IT Service Management are a coordinated effort between all organizations providing, supporting, and utilizing IT in the AFIN, the DoDIN, and the JIE. AF functional communities or DoD organizations such as Defense

Information Systems Agency (DISA) or AFSPC will have primary or supporting roles when AF

IT Services are consolidated at the DoD-enterprise level and JIE. Roles and responsibilities for

C2 of Cyberspace within AFI 10-1701 provides clear command and control over these collaborative relationships and is to be used in conjunction with this AFI.

4.1. Chief, Information Dominance and Chief Information Officer (SAF/CIO

A6). SAF/CIO A6 has overall responsibility for the AFIN, information technology (IT), IT

Service Management responsibilities for National Security Systems (NSS), defense business systems, and information resource management matters according to AFPD 33-1. SAF/CIO

A6 will:

4.1.1. Provide strategy, policy, guidance, and oversight for the AF portion of the DoD information enterprise, including communications, spectrum management, network management, information systems, and cybersecurity.

4.1.1.1. Develop AF strategy and policy on the operation and protection of all AF IT and information systems within the AFIN as the AF provisioned portion of the

DoDIN, including development and promulgation of enterprise-wide architecture requirements and technical standards, and enforcement, operation, and maintenance of systems, interoperability, collaboration, and interface between AF and non-AF systems, and investment and cost effectiveness of information system acquisition and sustainment.

4.1.1.2. Maintain a consolidated inventory of AF mission-critical and mission-essential information systems, identify interfaces between these systems, and ensure

6 AFI33-115 16 SEPTEMBER 2014

the development and test of contingency plans for responding to disruptions in the operation of any of these information systems.

4.1.1.3. Provide guidance and oversight for AF network management, including the standards for day-to-day security and protection of AF information networks; AF IT support to joint missions; and resilience and reliability of information and communication networks.

4.1.1.4. Provide guidance and oversight on the administration of AF Internet services, use of Internet-based capabilities, and all Internet domain-related functions.

4.1.1.5. Develop strategy, policy, and guidance for AF use of private and public cloud computing services in support of the AFIN. Review DISA’s security model for commercial cloud services and coordinate any modifications needed for alignment between the DoD cloud security model and the AFIN technical architecture security controls provided in the Target Baseline according to AFPD 33-4, Information

Technology Governance.

4.1.2. Provide governance of IT according to AFPD 33-4, Information Technology

Governance, including oversight for compliance with the Target Baseline (TB), Implementation Baseline (IB), and Operational Baseline (OB).

4.1.3. Define the AF IT Service Management for the AFIN and ensure Enterprise Core

Services for the AF are in-line with the DoD Enterprise Services under the DoDIN and/or

JIE.

4.1.4. Provide oversight of the implementation status of AF IT Services on behalf of the

Secretary of the Air Force (SECAF) and Chief of Staff of the Air Force (CSAF).

4.1.5. Fulfill AF CIO responsibilities of DoDI 8550.01, DoD Internet Services and

Internet-Based Capabilities.

4.1.6. Provide oversight and guidance for personnel development, career field management, and training of AF Cyberspace career fields according to AFI 36-2640, Executing Total Force Development.

4.1.7. Provide AF unique requirements to the DoD Enterprise Cloud Service Broker

(ECSB) for commercial cloud providers for interoperability with AF implementations of

Controlled Unclassified Information and the Enterprise Records Management Plan.

4.1.8. Work with Air Force Office of the Judge Advocate General (AF/JA), the Air

Force Office of Special Investigations (AFOSI), the Air Force Office of the Inspector

General (SAF/IG), the Intelligence Community, and the Acquisition Division of the Air

Force General Counsel (SAF/GCQ) to provide requirements to the DoD ECSB to ensure that tools and processes to protect sensitive information and adequate law enforcement tools are available for commercial cloud services.

4.1.9. Work with Air Force Legal Operations Agency (AFLOA), SAF/GC, AF/JAA and

SAF/AQC to provide requirements to the DoD ECSB for Software-as-a-Service (SaaS) compliance with AF e-Discoveryrequirements according to AFMAN 33-363, Management of Records.

AFI33-115 16 SEPTEMBER 2014 7

4.1.10. Act as the approval authority for waiver requests to deviate from the requirements of this publication.

4.1.11. Act as the central AF approval authority for obligations to acquire servers, data centers, and IT technology therein, IAW AFI 33-150, Management of Cyberspace

Support Activities, Attachment 2.

4.2. IT Governance Executive Board (ITGEB) will:

4.2.1. Approve the data centers (Installation Processing Node [IPN], Installation Services

Node [ISN], Special Purpose Processing Node [SPPN]) to serve as AF data center infrastructure. ITGEB-approved data centers are the only authorized data centers for the

AF to employ application hosting and provisioning of private cloud services. See AFPD

33-4 for more information on the ITGEB.

4.2.2. Oversee the execution of application rationalization and migration across the AF to ensure compliance with DoD guidance regarding hosting within IPNs, CDC, and DISA commercial cloud brokered services. This includes directing the capture and reporting of metrics reflecting decommissioned servers and data centers in accordance with the

Federal Data Center Consolidation Initiative (FDCCI).

4.2.3. The scope for the ITGEB includes the entire AF IT enterprise for business and mission capabilities, including business and national security systems (NSS), and excluding the embedded software in support of weapons platforms. This team shall focus on the commoditization and operational configuration management of a baseline IT infrastructure and the business practices to exploit that IT infrastructure for AF users.

The details of membership and processes can be found in AFPD 33-4.

4.3. Secretary of the Air Force Office of Public Affairs (SAF/PA) will:

4.3.1. Develop guidance for the integration of public web sites into the Air Force Public

Web Program. Serve as chair of the Air Force Public Web Policy Board.

4.3.2. Develop guidance governing the public communication program.

4.3.3. Review and approve/disapprove waiver requests for AF public Web sites hosted outside the scope of the Air Force Public Web Program.

4.4. Assistant Secretary of the Air Force for Acquisition (SAF/AQ). As the Senior

Acquisition Executive, SAF/AQ will:

4.4.1. Oversee the acquisition and sustainment of capabilities that support the AFIN.

4.4.2. Work with SAF/CIO A6 and AFSPC to procure, develop, integrate and test the

AFIN components and systems in accordance with the Implementation Baseline.

4.4.3. Collaborate with SAF/CIO A6 in developing the Implementation Baseline (IB) defined in AFPD 33-4. Ensure AF acquisition programs comply with the established IB requirements.

4.4.4. Ensure AF acquisition programs leverage, to the maximum extent possible, the use of JIE Enterprise Core Services, and promote sharing of data, information, and knowledge throughout the AF corporate structure.

8 AFI33-115 16 SEPTEMBER 2014

4.4.5. Work with SAF/CIO A6 to develop strategy, policy, and guidance to provide an

AF enterprise approach for acquiring commercial cloud computing services utilizing the

DoD ECSB.

4.4.6. Ensure all Acquisition Category (ACAT) programs address the requirements of

National Defense Authorization Act (NDAA) Fiscal Year 2012 Section 2867 and AFI 33-

150, Management of Cyberspace Support Activities, Attachment 2, in the acquisition of servers, data centers, and IT technology.

4.5. Air Force Material Command (AFMC). As the Implementing Command defined by

AFI 63-101/20-101, AFMC has overall responsibility for supporting the design, build, and sustainment of the AFIN. AFMC will:

4.5.1. In coordination with AFSPC, provide technical assistance to SAF/CIO A6 to develop policy and guidance for the AFIN.

4.5.2. Provide integration and test capability for IT components to support the development environment of new capabilities and troubleshooting performance issues with fielded capabilities, as required.

4.5.3. Provide direction and guidance to ensure all Program Executive Offices (PEOs) comply with the single AF approach for cloud computing and establish the AF Cloud

Service Lead according to paragraph 4.6.5.

4.5.4. Oversee the work performed by PEO C3I&N on the commoditized infrastructure

Implementation Baseline.

4.5.5. In coordination with AFSPC, oversee the deployment of all AF IT services.

4.5.6. Oversee the standup of the IT lifecycle integration and test capability.

4.6. The Program Executive Office for Command, Control, Communications, Intelligence and Networks (PEO C3I&N). PEO C3I&N will:

4.6.1. Perform Service Design and Development to include engineering, architecture, and provisioning support for AFNET, AFNET-S, and PEO C3I&N-provided systems within the AFIN and JIE in coordination with SAF/CIO A6 and AFSPC. Provides integration of AF IT across all systems centers (e.g., Air Force Life Cycle Management

Center, Space and Missile Systems Center, Air Force Medical Support Agency, Air Force

Nuclear Weapons Center).

4.6.2. Establish, publish, and maintain the commoditized infrastructure Implementation

Baseline in accordance with AFPD 33-4.

4.6.3. Facilitate the standup and operation of an IT lifecycle integration and test capability supporting the development, test, and delivery of new warfighter capabilities utilizing the Implementation Baseline. Leverage existing DoD, AF and Contractor resources to establish a virtual, distributed system development, integration and test capability supporting the delivery of new warfighter capabilities.

4.6.4. Support mission capabilities offices in configuring and provisioning the

Implementation Baseline to meet requirements. Support mission capabilities offices with transitioning their newly developed capabilities into the Implementation Baseline integration environment leading to deployment.

AFI33-115 16 SEPTEMBER 2014 9

4.6.5. Serve as the AF Cloud Service Lead:

4.6.5.1. Review and validate all cloud computing technical requirements prior to engaging with DISA as the DoD cloud broker.

4.6.5.2. Assist AF acquisition programs to define requirements and capabilities that can be implemented utilizing DoD ECSB approved cloud offerings.

4.6.6. Ensure a standardized AF process is adhered to for common computing environments and cloud services, including Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS) as detailed in paragraph 5.3

Fully leverage DoD efforts to provide a DoD Enterprise Cloud Environment under the

JIE in accordance with DoD CIO Memorandum, DoD Cloud Computing Strategy

Memorandum, 5 July 2012 and DoD CIO Supplemental Guidance Memo, 16 December

13.

4.6.6.1. Review all AF cloud computing technical requirements for consistency with the AF framework to cloud computing prior to engaging with DISA as the DoD

ECSB.

4.6.6.2. Work with the DoD ECSB, in conjunction with SAF/AQ and AFMC organizations to ensure a clear, tailorable cost model is established and made available for use of and migration to commercial cloud services.

4.6.7. Implement Network Management (NM) data schemas and net-centric sharing mechanisms to support the development of Service Level Agreements (SLAs), and support the implementation of network management security according to DoDI 8410.03, Network Management (NM).

4.6.8. Ensure that all AF Commercial Cloud Contracts address the additional issues in the DoD Cloud Issue Matrix according to DoD CIO Supplmental Guidance Memo, 16

December 2013.

4.7. Commander, Air Force Space Command (AFSPC/CC). In accordance with AFPD

10-17, AFSPC/CC is responsible for the overall command and control, security and defense of the AFIN. AFSPC/CC is responsible for the command, control, implementation, security, operation, maintenance, sustainment, configuration, and defense of the AFNET/AFNET-S.

These day-to-day authorities may be delegated. In addition to those responsibilities outlined in 10-series AFIs, AFSPC will:

4.7.1. Assist SAF/CIO A6 to develop policy and guidance for the AFIN and AF adoption of JIE capabilities.

4.7.2. Establish and maintain the Operational Baseline in accordance with AFPD 33-4.

4.7.3. Develop and submit to SAF/CIO A6 and HQ AETC requirements for initial, advanced, supplemental, and qualification training for cyberspace career field members.

4.7.4. Fulfill DoDIN Operations responsibilities for the AFNET/AFNET-S in support of

DoDI 8410.02, NetOps for the Global Information Grid (GIG), while remaining consistent with AFPD 10-17, Cyberspace Operations, and AFI 10-1701, Command and

Control for Cyberspace Operations.

10 AFI33-115 16 SEPTEMBER 2014

4.7.4.1. Establish and provide the necessary resources to ensure compliance with SLAs and memorandums of agreement (MOAs) among DoDIN and JIE service providers and users.

4.7.4.2. Participate in the DoDIN Operations Community of Interest (COI) to share information, promote standards, and resolve DoDIN Operations issues.

4.7.4.3. Participate in the DoD CIO and SAF CIO/A6 Enterprise Architecture (EA) efforts described in DoDI 8410.02 and AFPD 33-4.

4.7.4.4. Ensure all AF contractors and other entities operating AF-owned information systems and AF-controlled information systems on behalf of the Air Force that receive, process, store, display, or transmit AF information, regardless of classification or sensitivity, comply with DoDI 8410.02.

4.7.5. Provide Network Management for the AFNET/AFNET-S with automated

Configuration Management and Policy Based Network Management (PBNM) according to DoDI 8410.03.

4.7.6. Ensure the operation of the AF’s DoD Internet Services and official use of

Internet-based Capabilities (IbC) according to DoDI 8550.01.

4.7.7. Ensure that all DoD Internet services and IbC used by the AF to disseminate unclassified DoD information are assessed at least annually for compliance with DoDI

8550.01.

4.7.8. Provide technical procedures, and standards for the AFIN.

4.7.8.1. Develop MPTOs for AF ITSM to configure, operate, and maintain AF IT established in Section 5, AF IT Services Framework.

4.7.8.2. Provide life cycle management of AF ITSM MPTOs with technical content management (TCM) by 24 AF, other subordinate units, AF Program Management

Offices (PMOs), or System Program Offices (SPOs) as needed.

4.7.8.3. Serve as the Command Control Point for MPTOs supporting AF ITSM to include technical content management according to TO 00-5-1, AF Technical Order

System, and TO 00-5-3, AF Technical Order Lifecycle Management.

4.7.9. Develop and implement metrics and measures of effectiveness for the

AFNET/AFNET-S and AF IT Service Management.

4.7.10. Develop processes and implement policies including MPTOs to manage all AF-owned networks and platform IT interconnections behind appropriate cybersecurity boundaries as defined in the Baselines and according to AFI 33-210, Air Force

Certification and Accreditation Program. Review and approve Service Level

Agreements for non-AF owned networks on AF installations.

4.7.11. As the AF Authorizing Official (AO) (previously known as Designated

Accrediting Authority [DAA]) in accordance with AFI 33-200, assess networthiness and serve as the waiver approval authority for web servers, services, applications, or capabilities supporting the AF to be hosted on commercial servers or services (including cloud computing services) outside of military or government cybersecurity boundaries.

Approval requires coordination with the AF Cloud Broker Lead and DoD ECSB. The

AFI33-115 16 SEPTEMBER 2014 11

AF AO has responsibility over AF networks, applications and systems as well as the connection approval authority for non-AF systems and applications that will integrate into the AFIN.

4.7.12. Prior to JIE transitions, manage all networks under a One AF-One Network policy by directing the operation, maintenance, and configuration of all AFNET and

AFNET-S components (see Chapter 7). Serve as the waiver approval authority for allowing management of networks outside of the lead MAJCOM.

4.7.13. Support and facilitate management of the Standard Desktop Configuration

(SDC)/Defense Server Core Configuration (DSCC) by Air Force Enterprise

Configuration Management Office (AFECMO).

4.7.14. Ensure records management procedures are implemented and sustained for all enterprise storage services.

4.7.14.1. Ensure technology solutions meet requirements to support eDiscovery capabilities according to DoD 5012.02-STD, Electronic Records Management

Software Applications Design Criteria Standard and the Federal rules of Civil

Proceedure.

4.7.14.2. Implement policy, advocate for resources, and organize, train, and equip cyberspace forces to identify, locate, protect, and produce electronically-stored information in response to litigation requirements.

4.7.14.3. Cooperate with Air Force Legal Operations Agency and the Air Force

Records Office directing actions to locate and preserve electronic records as well as non-record electronically stored information which become subject to a litigation hold.

4.7.14.4. Cooperate with Air Force Office of Special Investigations (AFOSI) when an investigation requires the location, acquiring and or preservation of electronic records as well as non-record electronically stored information, IAW AFPD 71-1.

4.7.15. Assist AFMC with the development, integration, testing, and fielding of new systems and services, as required (e.g., step 4 of the SDDP to be published or when requested to determine causes of and solutions to deployment and performance issues).

4.7.16. Incorporate AF IT Services into the Core Functions Support Plan (CFSP), as the

CFL for Cyberspace Superiority.

4.7.17. Work with MAJCOM/A6s and Mission/Functional process owners to ensure technical consistency of IT solutions across the AFIN in accordance with AFSPC’s roles and responsibilities as CFL for Cyberspace Superiority.

4.7.18. If a specific approval authority is not identified (see paragraph 4.1.11), act as the AFIN approval authority for:

4.7.18.1. System/equipment waiver requests (i.e., purchases, documentation, preventative maintenance inspections).

4.7.18.2. Proposed temporary modifications, known as T-1 modifications to the

AFNET/AFNET-S system/equipment modifications according to AFI 63-131, Modification Program Management.

12 AFI33-115 16 SEPTEMBER 2014

4.7.19. Manage and administer Domain Name Service (DNS) subdomains assigned to the AF by DISA or approved for AF use according to DoDI 8410.01.

4.7.19.1. Manage AF-level (af.mil and af.smil.mil) DNS and naming convention for the AF according to the MPTO for Directory Services. Maintain a Name Server (NS) record for all AF name servers in the af.mil zone and provide technical support for the af.mil and af.smil.mil domain and sub-domains.

4.7.19.2. Annually verify administrative and technical contact information is correct in the registrations maintained at the DoD Network Information Center/Secret

Internet Protocol Router Network (SIPRNET) Support Center (DoD NIC/SSC) and at the General Services Administration's Government Domain Registration and Services

Web site at http://www.dotgov.gov.

4.7.20. Review and update AF-level SLAs with external agencies and supported

MAJCOMs as required.

4.7.21. Provide network integration and engineering services for the AFNET/AFNET-S and development of JIE capabilities.

4.7.21.1. Ensure operational systems do not introduce vulnerabilities to the

AFNET/AFNET-S or disrupt existing functions, while creating a resilient network environment that preserves operational advantage.

4.7.21.2. Perform networthiness consultation, validation, compliance and assessments of risk to the AFIN to enforce standards for functional and cyberspace systems, applications, and products requiring connection to the AFIN.

4.7.21.3. Develop and implement the AFNET Integration Process to verify compliance with security, interoperability, supportability, sustainability, usability regulations of systems, applications, and/or products, and readiness review criteria.

4.7.21.4. Collaborate with organizations to integrate all AF-owned, contracted or developed systems into the AFNET/AFNET-S.

4.7.21.5. Develop integration and implementation plans for AFIN & AFNET evolution to current and future JIE capabilities.

4.7.22. Provide the AF's engineering center of excellence for developing and implementing technical solutions for the AFIN via subordinate organizations such as the

38th Cyberspace Engineering Installation Group (38 CEIG) and AF Network Integration

Center (AFNIC).

4.7.22.1. Document Main Operating Base AFIN infrastructure, including system life-cycle information, via the Cyberspace Infrastructure Planning System (CIPS)

(Reference MPTO 00-33D-3003, Managing the Cyberspace Infrastructure with the

Cyberspace Infrastructure Planning System).

4.7.22.2. Provide AFIN network operations with enterprise engineering services according to AFI 33-150, Management of Cyberspace Support Activities.

4.7.22.3. Develop and analyze cyberspace requirements and associated impacts on operational architectures and capabilities, and convert AF and DoD technical http://www.dotgov.gov/

AFI33-115 16 SEPTEMBER 2014 13

specifications into standard AFIN and joint solutions to facilitate convergence on a single robust and defensible architecture.

4.7.22.4. Provide network health and vulnerability assessments as coordinated and directed by 24 AF/AFCYBER, including network security and optimization assistance as well as event-driven response action teams.

4.7.22.5. Develop and maintain the AFNET Infrastructure Roadmap and AFNET

Concept of Operations to serve as an input to the Target Baseline and show how the

Operational Baseline would evolve into the Target Baseline. The Roadmap and

Concept of Operations will address Cyber, Situational Awareness of the network, and

Network Management capabilities as well as operational roles and responsibilities.

The Infrastructure Roadmap will contain the collected and prioritized set of requirements.

4.8. 24th Air Force (24 AF (AFCYBER)). 24 AF is the AF component to

USCYBERCOM. AFSPC/CC may delegate certain authorities to 24 AF/CC IAW AFI 10-

1701, Command and Control for Cyberspace Operations.

4.8.1. In coordination with AFSPC, maintain and administer the Operational Baseline including the AFNET/AFNET-S.

4.8.2. Serve as liaison between the AFECMO and the operational community to facilitate the development and implementation of the SDC/DSCC.

4.8.3. Direct the security, operations, and defense of cloud computing services operated for the AF outside of AF network boundaries but logically a part of the AFIN, using authorities designated by the Cyber C2 structure in AFI 10-1701.

4.8.4. Provide assessments of impact to the AFIN in response to requests for web servers, services, applications, or capabilities to be hosted on commercial servers or services outside of military or government cybersecurity boundaries.

4.8.5. In coordination with AFSPC, review and approve/disapprove MAJCOM unique applications, communications systems, and IT Services requests/needs to ensure compatibility with AF IT Services. Include recommended changes affected by use of commercial servers or services (including cloud computing services).

4.8.6. Provide enterprise-level management of AF IT Services.

4.8.7. Monitor subordinate units’ compliance with orders issued and provide assistance on compliance issues when resolution is beyond their scope and/or resources.

4.9. 624th Operations Center (624 OC). 624 OC is the operational-level C2 organization for 24 AF (AFCYBER), providing strategy, planning, execution monitoring and assessment of Air Force cyber operations. 624 OC directs AF cyber operations and the activities of subordinate 24 AF cyber units via the Cyber Tasking Order (CTO) and other cyber orders.

In addition to duties specified in 10-series AFIs and applicable CYBERCOM orders, 624 OC is responsible for the following:

4.9.1. Develop options and directs operational configuration changes, Information

Operations Condition (INFOCON) changes (see AFI 10-710, Information Operations

Condition (INFOCON)), and changes to security postures in response to vulnerabilities

14 AFI33-115 16 SEPTEMBER 2014

and incidents, AF and CCMD operations, USCYBERCOM direction, and outages that cross MAJCOMs, affect the preponderance of the AFIN, or are time critical in nature.

4.9.2. Perform trend analysis and correlation of threat, performance, and compliance metrics as it relates to Vulnerability Management.

4.10. Major Commands (MAJCOMs)/Functionals. MAJCOMs/Functionals implement

AF guidance concerning the operation and maintenance of mission specific

MAJCOM/Functional unique applications, communications systems, and IT.

MAJCOMs/Functionals will:

4.10.1. Manage and provide support for command/functional-unique programs and systems/IT. (T-1).

4.10.1.1. Ensure command/functional-unique programs and systems/IT integrate with, but do not conflict with applicable AF IT Services. (T-1).

4.10.1.2. Ensure command/functional-unique applications do not duplicate infrastructure, services or capabilities provided by the AFIN, AFNET, AFNET-S or

JIE, by reviewing the Target, Implementation, and Operational Baselines for planned or existing services or capabilities. Exceptions must be approved by SAF/CIO A6.

(T-1).

4.10.1.3. Conduct application rationalization within their portfolios for business and mission systems to eliminate duplicity and ensure proper alignment with their business process in accordance with AFI 33-141, Air Force Information Technology

Portfolio Management and IT Investment Review. (T-1).

4.10.1.4. Ensure new applications and systems are fielded within IPNs or CDCs IAW

DoD guidance. (T-0).

4.10.2. Utilize only AFECMO produced standard configurations for command-unique systems. Cloning, repackaging, adding, or removing software from AFECMO standard images with the intent of producing a customized image is strictly prohibited except as waived by the AF AO (previously known as DAA) according to paragraph 4.15.2. (T-

1).

4.10.3. Submit requests to change an Operational Baseline Configuration Item (CI) such as new software or an equipment upgrade. (T-1).

4.10.3.1. For non-program office fielded systems, follow the Change Management process by using the change request module of the Enterprise Information

Technology Service Manager (EITSM), a.k.a. Remedy, or via AFTO Form 265, Request for Change, according to MPTO 00-33A-1100, Change Management,.

4.10.3.2. For program office fielded systems and equipment, submit AF Form 1067 according to AFI 63-131, Modification Program Management.

4.10.4. Plan, program, and budget for the capability to respond to orders released according to AFI 10-1701, that impact command/functional-unique programs and systems/equipment including end user workstations and/or network servers and localized infrastructure supporting command-unique requirements. (T-1).

AFI33-115 16 SEPTEMBER 2014 15

4.10.5. Designate a MAJCOM/AF Forces Communications Control Center (M/ACCC) or equivalent organization to function as the MAJCOM’s advocate for mission impacts to the user community (MAJCOM only). (T-1).

4.11. MAJCOM/AF Forces Communications Control Centers (M/ACCCs) will:

4.11.1. As an operational element of the MAJCOM Commander’s staff , combine situational awareness of networks and information systems supporting the MAJCOM with an in-depth MAJCOM-unique understanding of how those networks and systems are used to accomplish the mission of the command. (T-2).

4.11.2. Generate and disseminate near-real time situational awareness of how MAJCOM missions are being delayed, disrupted, degraded, or terminated due to events associated with the underlying communications networks critical to those missions. (T-2).

4.11.3. Serve as the information dissemination point of contact to the Integrated Network

Operations and Security Centers (I-NOSCs), Enterprise Service Units (ESUs), and AF

Enterprise Service Desk (ESD) on mission impacts and/or degradation to the mission and its user community. (T-1).

4.11.4. Elevate issues beyond the bases’ responsibility or capability to the respective enterprise service support organization. (T-2).

4.12. Communications Focal Point (CFP) within the Communications Squadron or equivalent will:

4.12.1. Serve as the conduit for the AF ESD to resolve communications systems and equipment issues at base level. The AF ESD is responsible for all AFNET users, but will delegate some of that responsibility to the CFPs via the Federated Administrative Rights

(FAR). Tools such as Information Assurance Officer Express (IAO Express) and Virtual

ESD (vESD) will automate certain functions, then re-route tickets that cannot be handled by the tool to either the CFP for Tier 1 or Tier 2 support, as appropriate and/or depending on the FAR authorized, or to the ESD backshop for further processing/support. Tickets that are routed to the CFP will then be routed (by the CFP) to the appropriate production work center for resolution. (T-1).

4.12.2. Operate systems and the AFNET/AFNET-S in the IPN according to AFIN baseline management processes and AF IT Services MPTOs. (T-1).

4.12.3. Maintain accountability of all AFIN components physically present on the installation regardless of the organization operating the equipment. (T-1).

4.12.4. Execute control of production procedures prescribed by AFI 33-150 and MPTO

00-33A-1001, General Cyberspace Support Activities Management Procedures and

Practice Requirements. Execute control of production on AFNET/AFNET-S components when requested by the operating organization, such as the 26 NOS, I-NOSCs or 33 NWS. Control of production includes planning and scheduling production, ordering and managing materials, and maintaining Automated Information Systems

(AISs). (T-2).

4.12.5. Serve as or assign a performing workcenter to provide preventive and touch maintenance on AFNET/AFNET-S, functional, and PMO equipment only as directed by

16 AFI33-115 16 SEPTEMBER 2014

the owning organization (e.g., I-NOSC, ESU, 26 NOS, 33 NWS, MAJCOM, PMO).

(T-1).

4.12.6. Utilize only AFECMO produced standard configurations (e.g., SDC, DSCC).

Cloning, repackaging, adding, or removing software from AFECMO standard images with the intent of producing a customized image is strictly prohibited except as waived by the AF AO (previously known as DAA) according to paragraph 4.15.2. (T-1).

4.12.7. Provide detailed maintenance records in a transferable system such as Remedy for preventive and touch maintenance on AFNET/AFNET-S equipment when directed to execute such maintenance by the owning organization. Utilize Integrated Maintenance

Data System (IMDS) for all maintenance data tracking and actions completed on the

AISs within physical control of CFP, according to MPTO 00-33A-1001. (T-2).

4.12.8. Elevate issues beyond the base’s responsibility or capability to the respective enterprise service support organization. (T-1).

4.12.9. Execute actions to comply with Cyber C2 orders according to paragraph 7.

(T-1).

4.12.9.1. Identify information systems controlled by a PMO which will only be patched or modified upon approval of the PMO or system owner. (T-1).

4.12.9.2. For command/functional systems, coordinate with Functional System

Administrators (FSAs) to take action to comply with Cyber C2 orders. (T-1).

4.12.10. Where remote administration/connectivity fails to resolve an end user service incident or fulfill a AF ITSM responsibility (e.g., Vulnerability Management), the CFP can be assigned network permissions and responsibilities to troubleshoot and resolve end user service incidents or fulfill AF ITSM responsibilities. Perform actions within local control requiring a touch labor solution as directed. (T-1).

4.12.10.1. Document tasking and effort using Service Incident Management and

Problem Management where appropriate.

4.12.11. Identify and resolve network threats, vulnerabilities, and attacks in coordination with the I-NOSCs, so as to minimize risks to operations. (T-1).

4.12.12. Inform base leadership and base populace on network threats, vulnerabilities, and actions. (T-2).

4.12.13. Notify/coordinate Authorized Service Interruptions (ASI) to minimize impact on base-level mission. (T-1).

4.12.14. Maintain situational awareness of their portion of the AFIN. Notify I-NOSCs and M/ACCCs of any issues regarding equipment under CFP control or that may affect base users. (T-1).

4.12.15. Report communications systems/equipment issues to MAJCOM and other higher headquarter functions as required. The CFP will provide situational awareness to the M/ACCC according to MAJCOM or Combatant Commanders guidance. (T-1).

AFI33-115 16 SEPTEMBER 2014 17

4.12.16. Coordinate, correlate, assess de-conflict and eradicate suspicious/malicious activity through appropriate authorities FSAs, M/ACCC, 561 NOS, 83 NOS, 299 NOSS and 33 NWS. (T-2).

4.12.17. Perform information dissemination management. (T-2).

4.12.18. Follow compliance reporting requirements as specified in each Cyber C2 order.

Orders may require compliance-based, task-based, or asset-based reporting. (T-1).

4.12.19. Develop and exercise COOPs. (T-3). The Communications

Squadron/equivalent Plans office will take lead on the development and maintenance of

COOPs and/or Disaster Recovery Plan (DRP) for managed services. Work centers will assist the Plans office with the COOP/DRP development for services under their responsibility. COOP will focus on restoring an organization’s mission-essential functions (MEF) at an alternate site and performing those functions for up to 30 days before returning to normal operations. See National Institute of Standards and

Technology (NIST) Special Publication 800-34, Contingency Planning Guide for

Information Technology Systems, for more details.

4.12.20. Up channel information that may help C2 of the AFIN. (T-2).

4.13. AF Enterprise Configuration Management Office (AFECMO).

4.13.1. AFECMO will provide configuration management of the Standard Desktop

Configuration (SDC), Defense Server Core Configuration (DSCC), Systems Center

Configuration Manager (SCCM) and associated Group Policies, software components and TOs. (T-1).

4.13.2. AFECMO is the only organization authorized to make changes to the SDC and

DSCC installation image/configuration, baseline group policy, or the SCCM configuration baseline except as approved by the AFSPC Operational Baseline process or directed through orders released according to AFI 10-1701. Any organization cloning, repackaging, adding, or removing software from AFECMO standard images with the intent of producing a customized image is strictly prohibited except as waived by the AF

AO (previously known as DAA). (T-1).

4.14. Air Force Program Management Offices (PMOs), System Program Offices

(SPOs), and Organizations Developing, and/or Managing, Operating non-core IT

Services, Applications or Capabilities. Note: In accordance with the acquisition chain of authority and acquisition requirements specified in AFI 63-101/20-101, tiering of the acquisition requirements does not apply and waiver authority resides with the program execution chain.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .