afi33-200.pdf
PDF 610 KB Posted
- Attached to
- Facilitate Other Maintenance Federal contract opportunity
- Solicitation number
- FA8224-16-R-0021
About this file
afi33-200
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BY ORDER OF THE
SECRETARY OF THE AIR FORCE
AIR FORCE INSTRUCTION 33-200
31 AUGUST 2015
Communications and Information
AIR FORCE CYBERSECURITY
PROGRAM MANAGEMENT
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
ACCESSIBILITY: Publications and forms are available on the e-Publishing website at www.e-publishing.af.mil for downloading or ordering.
RELEASABILITY: There are no releasability restrictions on this publication.
OPR: SAF CIO/A6SC
Supersedes: AFI 33-200, 23 December
2008; AFI 33-220, 21 November 2007
Certified by: SAF/CIO A6S
(Col Mary Hanson, AF SISO)
Pages: 50
This Air Force Instruction (AFI) implements Air Force Policy Directive (AFPD) 33-2, Information Assurance (IA) Program, and establishes Air Force (AF) cybersecurity requirements for compliance with: Committee on National Security Systems Instruction (CNSSI) No. 4005, (FOUO) Safeguarding Communications Security(COMSEC) Facilities and Materials;
Committee on National Security Systems Instruction (CNSSI) No. 4016, (FOUO), National
Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information
Technology (IT) Products, CNSSP -11; Department of Defense (DoD) Chief Information Officer
(CIO) Memorandum, Commercial Mobile Device (CMD) Interim Policy; DoD Directive
(DoDD) 8100.2, Use of Commercial Wireless Devices, Services and Technologies in the
Department of Defense (DoD) Global Information Grid (GIG); DoD Instruction (DoDI)
5205.13, Defense Industrial Base (DIB) Cyber Security/Information Assurance (CS/IA)
Activities; DoDI 8500.01, Cybersecurity; DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT); DoDI 8420.01, Commercial Wireless Local-Area Network
(WLAN) Devices, Systems, and Technologies; DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling; DoDI 8540.01. Cross Domain (CD) Policy; DoDI 8520.03, Identity Authentication for Information Systems; DoDI O-8530.2, Support to Computer Network
Defense (CND); DoDI 8551.01, Ports, Protocols, and Services Management (PPSM); DoDI
8580.1, Information Assurance (IA) in the Defense Acquisition System; DoDI 8581.01, Information Assurance (IA) Policy for Space Systems Used by the Department of Defense; and
DoDI 8582.01, Security of Unclassified DoD Information on Non-DoD Information Systems.
This instruction is consistent with Chairman Joint Chiefs of Staff Instruction CJCSI 6510.01F, Information Assurance (IA) and Computer Network Defense (CND); CJCSI 6211.02D, Defense
Information Systems network (DISN) Responsibilities and; Chairman Joint Chiefs of Staff
Certified Current 16 February 2016 http://www.e-publishing.af.mil/
2 AFI33-200 31 AUGUST 2015
Manual (CJCSM) 6510.01A, Information Assurance (IA) and Computer Network Defense (CND)
Volume 1 (Incident Handling Program). This instruction applies to all AF military, civilian, and contractor personnel under contract by DoD, regardless of Air Force Specialty Code (AFSC), who develop, acquire, deliver, use, operate, or manage AF Information Technology (IT). This instruction applies to the Air National Guard (ANG) and Air Force Reserve Command (AFRC).
The term major command (MAJCOM), when used in this publication, includes field operating agencies (FOA) and direct reporting units (DRU). Use of extracts from this instruction is encouraged. CNSSI 4009, National Information Assurance (IA) Glossary, explains other terms.
Direct questions, comments, recommended changes, or conflicts to this publication through command channels using the AF Form 847, Recommendation for Change of Publication, to
SAF/CIO A6. Send any supplements to this publication to SAF/CIO A6 for review, coordination, and approval prior to publication. Unless otherwise noted, the SAF/CIO A6 is the waivering authority to policies contained in this publication. The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See AFI 33-360, Publications and Forms Management, Table 1.1 for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the Publication OPR for non-tiered compliance items. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with
(IAW) AFMAN 33-363, Management of Records, and disposed of IAW Air Force Records
Disposition Schedule (RDS) located in the Air Force Records Information Management System
(AFRIMS). The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force.
SUMMARY OF CHANGES
This document is substantially changed and should be reviewed in its entirety. The change is a result of a DoD policy directive update and establishes the AF Cybersecurity program and risk management framework as an essential element to accomplishing the AF mission.
Chapter 1— GENERAL INFORMATION 6
1.1. Introduction
1.2. Applicability
1.3. Objectives
Figure 1.1. Tiered Risk Management Approach (NIST SP 800-39)
Chapter 2— ROLES AND RESPONSIBILITIES 8
2.1. Secretary of the Air Force, Office of Information Dominance and Chief
Information Officer (SAF/CIO A6) will develop strategies, policy and programs to integrate warfighting and combat support capabilities according to DoDI 8500. 8
2.2. Assistant Secretary of the Air Force (Acquisition) (SAF/AQ) will:
AFI33-200 31 AUGUST 2015 3
2.3. Air Force Office of Special Investigations (AFOSI) will:
2.4. Mission Area Owner (MAO)
2.5. Twenty-Fourth Air Force (24AF (AFCYBER)) will:
2.6. AF Senior Information Security Officer (SISO) will develop, implement, maintain, and enforce the AF Cybersecurity Program
2.7. Air Force Office of Cyberspace Strategy and Policy (SAF CIO A6S) will:
2.8. Authorizing Official (AO)
2.9. AO Designated Representative (AODR) will:
2.10. Security Control Assessor (SCA)
2.11. Security Controls Assessor Representative (SCAR) will:
2.12. Agent of the Security Controls Assessor (ASCA)
2.13. Information System Owners (ISO)
2.14. Program Manager (PM)/System Manager (SM)
2.15. Information System Security Manager (ISSM)
2.16. Information System Security Officer (ISSO)
2.17. Cybersecurity Liaison
2.18. Information Systems Security Engineer (ISSE)
2.19. Information Owner/Steward
2.20. Headquarters Air Force Space Command (HQ AFSPC)
2.21. MAJCOM Cybersecurity Office or Function will:
2.22. Wing Cybersecurity Office (WCO)
2.23. Organizational Commander
2.24. Privileged User with cybersecurity responsibilities (e
Chapter 3— CYBERSECURITY GOVERNANCE 27
3.1. Cybersecurity Governance
Figure 3.1. Air Force Cybersecurity Governance
3.2. Governance Process
4 AFI33-200 31 AUGUST 2015
3.3. Governance Bodies
3.4. Air Force Risk Management Council (AFRMC)
3.5. AF Cybersecurity Technical Advisory Group (AFCTAG)
3.6. AF AO Summit
Chapter 4— CYBERSECURITY IMPLEMENTATION 29
4.1. Air Force Cybersecurity Program
4.2. Cybersecurity Workforce Training and Certification
4.3. Information Assurance Workforce System Architecture and Engineering
4.4. Cybersecurity Inspections
4.5. Notice and Consent Monitoring and Certification
4.6. Connection Management
4.7. Commercial Internet Service Providers (ISPs)
4.8. Cross-Domain Solutions (CDS)
4.9. Security Configuration Management and Implementation
4.10. IT Acquisitions and Procurement
4.11. Air Force KMI
4.12. Public Key Infrastructure (PKI)
4.13. System Security Engineering (SSE)
4.14. COMPUSEC
4.15. Communications Security
4.16. TEMPEST
4.17. Operations Security (OPSEC)
4.18. Incident Response and Reporting
4.19. Mobile Code
4.20. Ports, Protocols, and Services (PPS)
4.21. Physical Security
AFI33-200 31 AUGUST 2015 5
4.22. Information Security
4.23. Malicious Logic Protection
4.24. Data Encryption
4.25. Mobile Computing Devices
4.26. Personal Activity Monitor (PAM) / Wearable Technology
4.27. Wireless Services
4.28. Non-Air Force IT utilized on AF installations
4.29. Peripheral Devices
4.30. Removable Media
4.31. Collaborative Computing
4.32. Spillage
Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 37
6 AFI33-200 31 AUGUST 2015
Chapter 1
GENERAL INFORMATION
1.1. Introduction. This AFI provides general direction for implementation of cybersecurity and management of cybersecurity programs according to AFPD 33-2. Compliance ensures appropriate measures are taken to ensure the confidentiality, integrity, and availability (CIA) of
AF IT and the information they process. This AFI ensures the use of appropriate levels of protection against threats and vulnerabilities, helps prevent denial of service, corruption and compromise of information, and potential fraud, waste, and abuse of government resources.
1.1.1. The AF cybersecurity program incorporates strategy, policy, awareness/training, assessment, authorization, implementation and remediation.
1.1.2. The cybersecurity discipline aligns with the AF Cybersecurity strategy key concept that total risk avoidance is not practical and therefore risks assessment and management is required.
1.1.3. Cybersecurity encompasses the following disciplines/functions: Air Force Risk
Management Framework (RMF), IT controls/countermeasures, Communications Security
(COMSEC), Computer Security (COMPUSEC), TEMPEST (formerly known as Emissions
Security [EMSEC]), AF Assessment and Authorization (A&A) (formerly known as
Certification and Accreditation Program [AFCAP]), and Cybersecurity Workforce
Improvement Program (WIP).
1.2. Applicability. This publication is binding on all military, civilian and contractors or other persons through the contract or other legally binding agreement with the Department of the Air
Force, who develop, acquire, deliver, use, operate, or manage AF IT. This publication applies to all AF IT used to process, store, display, transmit, or protect AF information, regardless of classification or sensitivity. AF IT includes but is not limited to: Information Systems (Major applications & Enclaves), Platform Information Technology (PIT) & PIT systems, IT Services
(Internal & External), and IT Products (Software, Hardware, Applications).
1.2.1. More restrictive Federal, DoD, and Director of National Intelligence (DNI) directive requirements governing Special Access Program (SAP) information take precedence over this publication. The latest version of all publications (e.g., Federal, Joint, DoD, AF) referenced within this publication are to be used.
1.2.2. This publication and implementation guidance identified within is not applicable to
Intelligence Community ISs to include Sensitive Compartmented Information (SCI) ISs.
Refer to the Intelligence Community (IC) Directive (ICD) 503, Intelligence Community
Information Technology Systems Security Risk Management, Certification and Accreditation and or the Unified Cross Domain Services Management Office (UCDSMO) as applicable.
1.2.3. Authority for AF space systems rests with Air Force Space Command (AFSPC) as delegated by US Strategic Command (USSTRATCOM). AF space systems generally follow
AF Cybersecurity policy and processes; where exceptions exist, this instruction is annotated accordingly. NOTE: Non-AF space systems follow cybersecurity policy and guidance in
DoDI 8581.01, Information Assurance (IA) Policy for Space Systems Used by the
Department of Defense.
AFI33-200 31 AUGUST 2015 7
1.2.4. Effective implementation and resultant residual risk associated with cybersecurity controls is assessed, documented, and mitigated according to DoDI 8510.01, DoD Risk
Management Framework (RMF), Air Force Manual (AFMAN) 33-210, Air Force
Assessment and Authorization Program, and the AF RMF Knowledge Service, for inclusion in the AF Information Technology (IT) A&A package.
1.3. Objectives. The objective of the AF Cybersecurity Program is to manage the risk presented by adversary cyber capabilities (purposeful attacks) and intelligence, environmental disruptions, human or machine errors, and to maintain mission survivability under adversary offensive cyber operations. The AF implements and maintains the Cybersecurity Program to adequately secure its information and IT assets. The Cybersecurity Program:
1.3.1. Ensures AF IT operate securely by protecting and maintaining IS / PIT resources and information processed throughout the system's life cycle.
1.3.2. Protects information commensurate with the level of risk and magnitude of harm resulting from loss, misuse, unauthorized access, or modification.
1.3.3. Leverages the multi-tiered organization-wide risk management approach defined in
NATIONAL Institute of Standards and technology (NIST) Special Publication (SP) 800-39, Managing Information Security Risk (See figure 1.1).
1.3.3.1. Tier 1 – Organization: Risk management at this tier is performed through cybersecurity governance bodies at the AF enterprise level.
1.3.3.2. Tier 2 – Mission/Business Process: risk management at this tier is performed by mission owner level and is informed by the risk context, risk decisions, and risk activities at Tier 1.
1.3.3.3. Tier 3 – Information System: risk management at this tier is performed by individuals responsible for the management of individual IT and is guided by the risk context, risk decisions and risk activities at Tiers 1 and 2.
Figure 1.1. Tiered Risk Management Approach (NIST SP 800-39).
8 AFI33-200 31 AUGUST 2015
Chapter 2
ROLES AND RESPONSIBILITIES
2.1. Secretary of the Air Force, Office of Information Dominance and Chief Information
Officer (SAF/CIO A6) will develop strategies, policy and programs to integrate warfighting and combat support capabilities according to DoDI 8500. 01 and AFPD 33-2. SAF/CIO A6 will:
2.1.1. Oversee the establishment of risk tolerance and baseline cybersecurity controls for the
AF IT. SAF CIO A6 will provide guidance to organizations on how to implement solutions for operational requirements exceeding the established National, DoD, Joint Chiefs of Staff
(JCS), AF baseline cybersecurity controls for IT and remain within established risk tolerance levels
2.1.2. Maintain visibility of assessment and authorization status of AF IT through automated assessment and authorization tools or designated repositories for the AF in support of DoD
CIO and Principle Authorizing Officials (PAO) IAW DoDI 8500.01, Cybersecurity.
2.1.3. Provide guidance to organizations on how to implement solutions for operational requirements exceeding the established National, DoD, Joint Chiefs of Staff (JCS), AF baseline cybersecurity controls for IT and remain within established risk tolerance levels.
2.1.4. Define cybersecurity performance measures and metrics to identify enterprise-wide cybersecurity trends and status of mitigation efforts.
2.1.5. On behalf of the SECAF, and IAW AFPD 33-2, appoint all Authorizing Officials
(AO).
2.1.6. Appoint an Air Force Senior Information Security Officer (SISO) to direct and oversee the Air Force Cybersecurity Program.
2.1.7. IAW AFI 33-401, Air Force Architecting, appoint the AF Chief Architect with responsibility for the AF Cybersecurity Architecture.
2.1.8. Serve as the Mission Area Owner (MAO) for the Enterprise Information Environment
Mission Area (EIEMA).
2.1.9. Chair the Air Force AO Summit.
2.1.10. Represent the EIEMA in the Air Force AO Summit.
2.1.11. Provide AF Enterprise oversight of the Air Force Information Technology Asset
Management (ITAM) program.
2.2. Assistant Secretary of the Air Force (Acquisition) (SAF/AQ) will:
2.2.1. Build cybersecurity into all acquisitions by ensuring all cybersecurity requirements are implemented in all phases and contracts for research, development, test, and evaluation of IT.
2.2.2. Provide streamlined guidance to enable Program Executive Officers (PEO) and
Program Managers (PM) to adhere to the mandated standards outlined in this instruction, DoDI 8580.1, DoDI 8581.1, DoDI 8510.01, AFMAN 33-152, and the A&A requirements of
AFMAN 33-210.
AFI33-200 31 AUGUST 2015 9
2.2.3. Ensure contracts include appropriate Defense Federal Acquisition Regulation
Supplement (DFARS) clauses for safeguarding unclassified DoD information on non-DoD
ISs IAW DoDI 8582.01 and DFARS 204.7304 as applicable.
2.2.4. For all space acquisitions, ensure cybersecurity requirements are implemented in all phases of acquisitions according to the provisions in DoDI 5000.02, Operation of the
Defense Acquisition System. SAF/AQ will provide streamlined guidance to enable each program and system under its span of control to develop a cybersecurity strategy meeting the requirements of this instruction, DoDI 5000.02, and DoDI 8580.1, and AFMAN 33-407, Air
Force Clinger-Cohen Act (CCA) Compliance Guide.
2.2.5. Manage the process for preparing and reviewing AF acquisition program strategies and ensure cybersecurity has been appropriately addressed.
2.2.6. Represent the AF on policy and procedural matters regarding cybersecurity in the acquisition system.
2.2.7. Coordinate with USAF/A2 to ensure Intelligence acquisition programs address cybersecurity life cycle requirements. SAF/AQ will coordinate with USAF/A2 assigning AF
PM representatives for Intelligence systems, equipment, networks, or services on the Air
Force Information Network (AFIN) or utilizing AFIN capabilities that were developed and/or acquired by non-AF entities.
2.3. Air Force Office of Special Investigations (AFOSI) will:
2.3.1. AFOSI is the office of primary responsibility (OPR) for on-hook telephone technical security matters, to include providing guidance for installing and operating telephone systems within the Air Force, and department of defense facilities occupied by Air Force personnel.
2.3.2. Provide Air Force representation to the U.S. Government intelligence community's
National Telephone Security Working Group (NTSWG). (T-0). The group is the primary technical and policy resource in the U.S. intelligence community for all aspect of the
Technical Surveillance Countermeasures (TSCM) program involving telephone systems in areas where sensitive government information is discussed.
2.3.3. Examine the TSCM needs of the Air Force and tailor Air Force telephone security standards to those established by the NTSWG. (T-0).
2.3.4. Provide guidance to Air Force organization on selecting local equipment for installing telephone systems in sensitive discussion areas in conjunction with the host base
Communications and Information Systems Officer (CSO) (AFMAN 33-145, Collaboration
Services and Voice Systems Management) in accordance with CNSSI No. 5006, National
Instruction for Approved Telephone Equipment, and The Defense Information Systems
Agency (DISA) Approved Products List Integrated Tracking System (UC system acquisition). (T-0).
2.3.5. Determine the effectiveness and applicability of protective security devices and
TSCM procedures for qualified facilities; when warranted provide technical threat information and briefings concerning telephone systems and the countermeasures intended to nullify existing threats. (T-0). Further information on requesting TSCM services or threat briefing is contained in AFI 71-101, Volume 3, The Air Force Technical Surveillance
Countermeasures Program.
10 AFI33-200 31 AUGUST 2015
2.4. Mission Area Owner (MAO). A MAO is appointed for the Air Force portion of each of the DoD MAs. MAOs will:
2.4.1. Oversee and establish direction for the strategic implementation of cybersecurity and risk management within their MAs. (T-0).
2.4.2. Assist the SAF/CIO A6 and the AF SISO in assessing the effectiveness of AF cybersecurity. (T-1).
2.4.3. Coordinate with the DoD PAO for cybersecurity and risk management within their
MAs. (T-0).
2.4.4. Represent the interest of the MA, as defined in Reference DoDD 8115.01, Information
Technology Portfolio Management, and, as required issue authorization guidance specific to the MA, consistent with this instruction. (T-0).
2.4.5. Resolve authorization issues within their respective MAs and work with other MAOs to resolve issues among MAs, as needed. (T-0).
2.4.6. Nominate AOs for MA IS and PIT systems supporting MA COIs specified in
Reference DoD 8320.02, in coordination with SAF/CIO A6, consistent with this instruction.
(T-1). SAF/CIO A6 will appoint those nominated by the MAO.
2.4.7. Designate information security architects or IS security engineers for MA segments
(overlapping spans of influence (enclaves)) or systems of systems, as needed. (T-1).
2.4.8. Work with the AF SISO and other MAOs to ensure cybersecurity checks and balances occur through the appropriate mission area governance boards. (T-1).
2.5. Twenty-Fourth Air Force (24AF (AFCYBER)) will:
2.5.1. Serve as the single point of contact for processing and supporting AF cybersecurity-related intelligence requests from AF and DoD intelligence entities (e.g., threat assessment against the AFIN) for the AFIN. 24 AF (AFCYBER) will provide SAF/CIO A6 Staff with courtesy copies of requests and responses for assessment of impact on the AF cybersecurity
Program.
2.5.2. Coordinate with Joint and Defense-wide program offices to ensure interoperability of cybersecurity solutions across the DODIN.
2.5.3. Provide support to national, DoD, and AF level Technical Advisory Groups (TAG)
(i.e., AFIA TAG, RMF TAG, DoD PPS TAG, etc.), as requested by SAF/CIO A6.
2.5.4. Oversee, manage, and control AF enclave boundary defense activities, measures, and operations.
2.5.5. Issue time compliance technical orders and modification kits for cybersecurity and cybersecurity-enabled products or components of AF ITs.
2.5.6. Ensure Ports Protocols and Services (PPS) requirements for the AFIN are limited to only those required for official use with proper approval, PPS’s not properly approved follow the deny by default, allow by exception access philosophy, and that PPS information is validated annually.
AFI33-200 31 AUGUST 2015 11
2.6. AF Senior Information Security Officer (SISO) will develop, implement, maintain, and enforce the AF Cybersecurity Program. The AF SISO will direct and coordinate any associated budgets and advocate for AF-wide cybersecurity solutions through the planning, programming, budget and execution process on behalf of the SAF/CIO A6 according to DoDI
8500.01, DoDI 8510.01, AFPD 33-2, and AFMAN 33-210. The SISO is referred to as Senior
Agency Information Security Officer [SAISO] or Chief Information Security Officer [CISO] in
CNSSI 4009. The AF SISO will:
2.6.1. Be a DoD official (O-6 or GS-15 at a minimum), and a United States citizen.
2.6.2. Complete training and maintain cybersecurity certifications IAW AFMAN 33-285, Cybersecurity Workforce Improvement Program.
2.6.3. Monitor, evaluate, and provide advice to the SAF/CIO A6 regarding AF cybersecurity posture.
2.6.4. Serve as the AF CIO’s primary liaison to DoD SISO, Component SISO’s, MAJCOM
Cybersecurity Offices, AF AOs, and SCAs.
2.6.5. In coordination with the SAF/CIO A6 and AO’s, ensure cybersecurity risk posture and risk tolerance decisions for AF IT meet mission and business needs while also minimizing the operations and maintenance burden on the organization. The AF SISO will represent the
AF at Federal, DoD, and Joint cybersecurity steering groups and forums.
2.6.6. Ensure that IT guidelines are incorporated into acquisition, implementation, and operations and maintenance functions.
2.6.7. Provide direction on how cybersecurity metrics are determined, established, defined, collected, and reported for compliance with statutory, DoD, Joint, and AF policies and directives.
2.6.8. Appoint Security Control Assessors (SCAs) for all AF IT (excluding Special-Access
Program/Special Access Required [SAP/SAR], IC, Space, NC3, and Medical).
2.6.9. Perform as the SCA or formally delegate the security control assessment role for governed information technologies.
2.6.10. Provide guidance and direction on Agent of the Security Control Assessor (ASCA) establishment in support of Assessment and Authorization (A&A) requirements.
2.6.11. Oversee establishment and enforcement of the A&A process, roles, and responsibilities; review approval thresholds and milestones within the AF A&A Program.
2.6.12. Chair the Air Force Cybersecurity Risk Management Council (AFCRMC).
2.6.13. Adjudicate IT determinations, in coordination with the Air Force Risk Management
Council, when there is a conflict in the IT determination process.
2.6.14. Appoint in writing the AF Certified TEMPEST Technical Authority (AF CTTA).
2.6.15. Appoint AF members to the DoD RMF TAG.
2.6.16. Review and approve Cybersecurity Strategies for all AF IT IAW DoDI 5000.02 and
AFMAN 33-407, AF Clinger-Cohen Act (CCA) Compliance Guide. The approval of the
Cybersecurity Strategies cannot be delegated.
12 AFI33-200 31 AUGUST 2015
2.6.17. Review and approve Privacy Impact Assessments (PIAs) submitted IAW AFI 33-
332, The AF privacy and Civil Liberties Program. The approval of the PIA may be not be delegated.
2.6.18. Approve National Security System (NSS) designations for AF IT.
2.6.19. Approve Defense Industrial Base Cybersecurity/Information Assurance (DIB/CS/IA)
Damage Assessment Reports (as needed) IAW DoDI 5205.13.
2.6.20. Ensure AF RMF guidance is posted to the DoD Component portion of the KS, and is consistent with DoD policy and guidance.
2.6.21. Validate and prioritize (with the support of the AF Risk Management Council
(AFRMC)) all AF cryptographic certification requests prior to submission for NSA action.
2.7. Air Force Office of Cyberspace Strategy and Policy (SAF CIO A6S) will:
2.7.1. Provide cyberspace policy, guidance, & oversight. SAF CIO A6S will inform
Headquarters United States Air Force, and MAJCOMs about changes to DoD and AF cybersecurity policies and procedures in accordance with HAFMD1-26 Chief, Information
Dominance and Chief Information Officer.
2.7.2. Ensure AF acquisition guidance reflects national, federal, DoD, and AF cybersecurity policy and procedures.
2.7.3. Develop and evaluate cybersecurity performance measurements for compliance with statutory, DoD, Joint, and AF policies and directives.
2.7.4. Establish and enforce the RMF process, roles, and responsibilities; review approval thresholds and milestones within the AF RMF Program.
2.7.5. Provide AF IT PEO’s guidance on completion and submission of Cybersecurity
Strategies and submit for AF SISO approval.
2.7.6. Collect and report cybersecurity management, financial, and readiness data to meet
DoD cybersecurity and Office of Management and Budget (OMB) reporting requirements.
2.7.7. Serve as the single cybersecurity coordination point for joint or Defense-wide programs that are deploying IT (guest systems) to AF enclaves.
2.7.8. Participate in Federal, DoD and Joint cybersecurity and RMF technical working groups and forums (e.g. RMF TAG, DSAWG).
2.7.9. Develop and implement AF cybersecurity requirements planning, programming, budgeting, and execution in the AF budget process in compliance with SISO direction.
Through the Air Force budget request, SAF CIO A6S will advocate for cybersecurity funding and manning with the Office of the Secretary of Defense and Congress.
2.7.10. Establish and maintain cybersecurity checklists for use with the AF Inspection
Systems, currently the Management Internal Control Toolset (MICT) in accordance with AFI
90-201 Air Force Inspection System.
2.7.11. Develop concepts and establish strategy for integrated support and configuration management of cybersecurity equipment.
AFI33-200 31 AUGUST 2015 13
2.7.12. Oversee, plan, implement, manage, and support the COMSEC aspects of programs, including centralized record maintenance of COMSEC equipment, components, and material.
2.7.13. Carry out Federal Information Security Management Act of 2002 (FISMA)-related
CIO responsibilities.
2.7.14. Provide detailed information on the FISMA requirements via the annual AF FISMA
Reporting Guidance.
2.7.15. Manage the annual assessment of the AF Cybersecurity Programs as required by
FISMA. Requests, through channels, support from AF organizations. Organizational support allows the AF SISO to answer the annual FISMA report questions posed by the
OMB.
2.7.16. Ensure cybersecurity requirements are addressed and visible in all investment portfolios and investment programs according to AFI 33-401, Air Force Architecting, and
AFMAN 33-210
2.7.17. Implement and enforce the education, training, and certification of AF cybersecurity professionals and users according to DoD 8570.01-M, Information Assurance (IA) Training, Certification, and Workforce Management, and AFMAN 33-285.
2.7.18. Coordinate Inspector General (IG) inspections and associated responsibilities according to and AFI 90-201.
2.7.19. Collect and report on qualification metrics and submits reports to the DoD CIO as directed such as for Federal Information Security Management Act (FISMA) reporting, standardizing reporting across Air Force.
2.7.20. Review and provide guidance in support of MAJCOM or equivalent provided commercial internet waivers and facilitates presentation to the DoDIN waiver panel; is a voting member of the DoDIN waiver panel. For additional information, AFI 33-115 and
AFMAN 33-282.
2.7.21. Review Cross Domain Solution (CDS) requests and presents to the Defense Security
Accreditation Working Group (DSAWG) for approval.
2.7.22. Manage the implementation of policy and standardized procedures to catalog, regulate, and control the use and management of ports, protocols, and services (PPS) in IT and applications IAW DoDI 8551.01.
2.7.23. Serve as the AF Public Key Infrastructure (PKI Management Authority (PMA). SAF
CIO A6S will direct policy, requirements, and implementation of PKI integration across all
AF networks. SAF CIO A6S will participate in DoD and Federal working groups and forums involved in PKI and IdAM, and is the AF OPR to DoD, NSS, and Federal PKI and Identity and Access Management (IdAM) groups.
2.7.24. Represent the AF as a voting member on DoD PPS Configuration Control Boards
(CCB). Designates AF A6S as primary and one or more alternate voting representatives for the DoD PPS CCB.
2.7.25. Designate a primary and one or more alternate representatives for the DoD PPS
TAG.
14 AFI33-200 31 AUGUST 2015
2.7.26. Designate points of contact to register the PPS used by AF IS in the DoD PPS
Registry (also known as DoD PPS Database) according to this instruction and DoD policy.
2.7.27. Manage PPS procedures for the AF according to this instruction, DoD guidance, and
USCYBERCOM orders and directives. Responsibilities include advocating issues from customers with Air Staff and the DoD PPS Program Manager at the Defense Information
Systems Agency (DISA); providing guidance and support to customers; and processing waiver, deviations, and exceptions.
2.7.28. Establish a Defense Industrial Base Cyber Security/ Information Assurance (DIB
CS/IA) Program Office. The DIB CS/IA Program Office works cooperatively with participating Cleared Defense Contractors (CDCs) to enhance their ability to safeguard DoD information residing on or transiting DIB unclassified networks IAW DoDI 5205.13, Defense Industrial Base Cyber Security/Information Assurance Activities. In accordance with DoDI 5205.13, the AF established the AF Damage Assessment Management Office (AF
DAMO) within SAF/CIO A6.
2.7.29. The AF DAMO will conduct damage assessments on data compromised as a result of adversary intrusions into those contractor networks. AF DAMO determines the extent of intelligence obtained by adversary cyber intrusions into DIB networks, and assesses the overall impact of the data loss on current and future weapons programs, scientific and research projects, and warfighting capabilities.
2.7.30. Set policy for managing AF electronic (EM) spectrum use to support the AF mission and exercise control over the frequency management process IAW AFI 33-580, Spectrum
Management
2.7.31. Upon request from the AF SISO, AF functional authorities and MAJCOMs are required to provide appropriate programmatic, operational, and technical SMEs, intelligence analysts, or cyber forces to assess the compromised information as part of Integrated Process
Teams (IPTs). All IPTs convene at the DoD Cyber Crime Center (DC3) in Linthicum, MD, where AF DAMO personnel assist the IPT in the damage assessment process. The participants provide expert opinion on the extent of damage caused as a result of the compromise and make recommendations on mitigation efforts required due to the loss of that information. Damage assessment reports are drafted for each case and disseminated to the appropriate AF program offices, agencies, and stakeholders for review and possible mitigation actions.
2.8. Authorizing Official (AO). The AO is the official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. The AO renders authorization decisions for DoD ISs and PIT systems under their purview in accordance with DoDI 8510.01. A current listing of AOs is available on the AF Cybersecurity Knowledge Service located at:
https://cs1.eis.af.mil/sites/SAFCIOA6/A6S/afcks/Compliance/AFAAP/SitePages/Home.aspx
. The AO will:
2.8.1. Be appointed from senior leadership positions within business owner and mission owner organizations to promote accountability in authorization decisions that balance mission and business needs and security concerns/risks.
2.8.2. Be a DoD official (O-7 or SES at a minimum), and be a United States citizen.
https://cs1.eis.af.mil/sites/SAFCIOA6/A6S/afcks/Compliance/AFAAP/SitePages/Home.aspx https://cs1.eis.af.mil/sites/SAFCIOA6/A6S/afcks/Compliance/AFAAP/SitePages/Home.aspx
AFI33-200 31 AUGUST 2015 15
2.8.3. Complete AF AO training IAW AFMAN 33-285.
2.8.4. Be appointed by SAF CIO/A6 in coordination with the appropriate MAO. The appointment grants authority to authorize IS and PIT systems within the authorization boundary as needed.
2.8.5. Not delegate ATO granting authority. (T-1).
2.8.6. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program.
2.9. AO Designated Representative (AODR) will:
2.9.1. Complete AO training and maintain cybersecurity certifications consistent with duties and responsibilities of an SCA and IAW AFMAN 33-285. (T-1).
2.9.2. Perform responsibilities as assigned by the AO. NOTE: AODR’s may perform any and all duties of an AO except for accepting risk by issuing an authorization decision. (T-1).
2.9.3. Make recommendations to the AO to approve ATO based on input from RMF team members, and other AOs and AODRs. (T-1).
2.9.4. Be appointed by the AO, and, at a minimum, be an O-5 or GS-14. (T-1).
2.10. Security Control Assessor (SCA).
2.10.1. The SCA is the senior official having the authority and responsibility for the certification of all ISs and PIT systems governed by the Air Force.
2.10.2. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program.
2.11. Security Controls Assessor Representative (SCAR) will:
2.11.1. Complete training and maintain appropriate cybersecurity certification IAW
AFMAN 33-285. It is highly recommended SCARs complete both the AO training module and attain the CNSSI 4016 certificate for supplemental training. Proof of training (e.g.
certificate) is included as an artifact to the IS’s or PIT system’s A&A package.
2.11.2. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program
2.12. Agent of the Security Controls Assessor (ASCA). The ASCA is a licensed organization which may be contracted by the PM to assist in certification activities and will:
2.12.1. Report directly to the SCA for guidance related to validation activities and procedures. (T-1).
2.12.2. Maintain ASCA license IAW SISO guidance and the ASCA licensing guide. (T-1).
2.12.3. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program
2.13. Information System Owners (ISO). Official responsible for the overall procurement, development, integration, modification, or operation and maintenance of an information or PIT system. An ISO will be appointed in writing for every IS and PIT System. (T-1). For those systems that are Air Force-wide systems (e.g., AFNET, LOGMOD, etc.), they will be appointed
16 AFI33-200 31 AUGUST 2015
by the HAF/SAF 3-letter responsible for the capability. For MAJCOM, base-level IS/PIT systems, and base enclaves, the appropriate MAJCOM 2-letter will appoint the ISO. No further appointment is necessary. The ISO will:
2.13.1. Identify the requirement for IT and requests funds, operates and maintains the IT in order to enhance mission effectiveness. (NOTE: Do not confuse this with the ISO role in
TEMPEST.) (T-2).
2.13.2. Identify, implement, and ensure full integration of cybersecurity into all phases of their acquisition, upgrade, or modification programs, including initial design, development, testing, fielding, operation, and sustainment. (T-0). Reference DoDI 8510.01, AFI 63-101, and AFMAN 33-210 for guidance.
2.13.3. Develop, maintain, and track the security plan for assigned IS and PIT systems. (T-
1).
2.13.4. Develop and document a system-level continuous monitoring (CM) strategy to monitor the effectiveness of security controls employed within or inherited by the system, and monitoring of any proposed or actual changes to the system and its environment of operation. (T-1). The ISO must ensure the strategy includes the plan for annual assessments of a subset of implemented security controls, and the level of independence required of the assessor (e.g., SCA or ASCA). (T-1).
2.13.5. Ensure the PMO is resourced with individuals knowledgeable in all areas of cybersecurity to support security engineering and security technical assessments of the IS or
PIT systems for the SCA’s authorization determination, AOs authorization decision, and other security related assessments (e.g., Financial Improvement and Audit Readiness (FIAR)
IT testing, Inspector General audits). (T-1).
2.13.6. Ensure that applicable CTO’s are received and acted upon per the CTO directions.
(T-1).
2.13.7. Ensure stakeholders are identified that may be affected by the implementation and operation of the IT. (T-2).
2.13.8. Ensure the IT has a designated Information System Security Manager (ISSM) with the support, authority, and resources to satisfy established responsibilities for managing the
IT’s cybersecurity posture. (T-1).
2.13.9. Plan and budget for all software assurance (SwA) activities (e.g. adopt SwA best practices, third party, secure coding standards, automated scans, etc…) during all phases of the software development lifecycle (SDLC). (T-2).
2.13.10. In coordination with the Information Owner/Steward, decide who has access to the system (and with what types of privileges or access rights) and ensure system users and support personnel receive the requisite security training (e.g., instruction in rules of behavior). (T-2).
2.13.11. Based on guidance from the SCA and AO, inform appropriate organizational officials of the need to conduct the full RMF assessment and authorization; ensure the necessary resources are available for the effort, and provides the required IT access, information, and documentation to the SCA. (T-2).
AFI33-200 31 AUGUST 2015 17
2.13.12. Receive the security assessment results from the SCA and develop a POA&M for all identified weaknesses. (T-1). After taking appropriate steps to reduce or eliminate weaknesses, the ISO will assemble the authorization package and submit the package to the
SCA for assessment and subsequently to the AO for an authorization decision. (T-1).
2.13.13. Ensure open POA&M items are closed on time. (T-2).
2.13.14. Ensure consolidated A&A documentation is maintained for systems with instances at multiple locations. (T-2).
2.13.15. Ensure, with the assistance of the ISSM, the system is deployed and operated according to the approved System Security Plan (SSP) and the authorization package (i.e., the AO’s authorization decision). (T-1).
2.13.16. Conduct specific duties outlined in the KS. (T-2).
2.14. Program Manager (PM)/System Manager (SM). PM/SMs will:
2.14.1. Identify, implement, and ensure full integration of cybersecurity into all phases of their acquisition, upgrade, or modification programs, including initial design, development, testing, fielding, operation, and sustainment IAW AFI 63-101, Acquisition and Sustainment
Life Cycle Management, DoDI 8510.01 and AFMAN 33-210 for guidance. (T-0).
2.14.2. Plan and coordinate for all IT cybersecurity requirements IAW applicable guidance.
(T-2).
2.14.3. Ensure that ISs and PIT systems under their purview have cybersecurity-related positions assigned in accordance with AFMAN 33-285. (T-2).
2.14.4. Assign an ISSM for the program office and ensure they have the proper certification
IAW AFMAN 33-285. (T-1).
2.14.5. Ensure the IS or PIT system is registered IAW AFI 33-141, AF IT Portfolio
Management and Investment Review.
2.14.6. Develop and maintain a cybersecurity strategy as applicable and IAW AFMAN 33-
407.
2.14.7. Ensure operational systems maintain a current ATO. (T-1).
2.14.8. Ensure all changes are approved through a configuration management process, are assessed for cybersecurity impacts and reported to the SCA as applicable. (T-2).
2.14.9. Track and implement the corrective actions identified in the POA&M in the
Enterprise Mission Assurance Support Service (eMASS). (T-0). POA&Ms provide visibility and status of security weaknesses to the ISO, Information Owner(s), AO and AF SISO.
2.14.10. Ensure annual and milestone security reviews are conducted and selected RMF controls are tested IAW this instruction, the CM plan and OMB Circular A-130, Management of Federal Information Resources ISO FISMA. (T-0). The PM/SM will brief the results of both security reviews and the RMF control tests at the governance boards for the appropriate mission area in accordance with the board requirements. (T-0).
2.14.11. Report security incidents to stakeholder organizations. (T-2). The PM/SM will conduct root cause analysis for incidents and develop corrective action plans. (T-2).
18 AFI33-200 31 AUGUST 2015
2.14.12. Ensure the program is resourced with individuals knowledgeable in security engineering and security technical assessments IAW AFMAN 33-285. (T-2). These efforts support the SCA’s assessment and the AO’s authorization decision for IT that is subject to the RMF process IAW AFMAN 33-210.
2.14.13. In coordination with the Information Owner/Steward, ensure that a Privacy Impact
Assessment is completed for IT that process and/or stores Personal Identifiable Information
(PII). (T-0).
2.15. Information System Security Manager (ISSM). The ISSM is the primary cybersecurity technical advisor to the AO for AF IT. For base enclaves, the ISSM manages the installation cybersecurity program, typically as a function of the Wing Cybersecurity Office. That program
ISSM may also serve as system ISSM for the enclave and reports to the CS/CC as the PM for the base enclave. The ISSM will:
2.15.1. Act on behalf of the AO to maintain the authorization of the system throughout its lifecycle; therefore, if the ISSM is not qualified to serve, the AO or the AODR may request the PM/SM designate a suitable replacement. (T-3).
2.15.2. Complete training and maintains cybersecurity certification IAW AFMAN 33-285
(Individuals in this position must be US citizens). (T-0). Proof of training (e.g. certificate) is included as an artifact to the IS’s or PIT systems A&A package.
2.15.3. Support the ISO on behalf of the AO in implementing the RMF. (T-3).
2.15.4. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program.
2.16. Information System Security Officer (ISSO). The ISSO is responsible for ensuring the appropriate operational security posture is maintained for AF IT under their purview. This includes the following activities related to maintaining situational awareness and initiating actions to improve or restore cybersecurity posture. ISSOs (formerly system level IA Officers), or the ISSM if no ISSO is appointed, will:
2.16.1. Implement and enforce all AF cybersecurity policies, procedures, and countermeasures using the guidance within this instruction and applicable cybersecurity publications. (T-1).
2.16.2. Complete and maintain required cybersecurity professional certification IAW
AFMAN 33-285 (Individuals in this position must be US citizens). (T-0).
2.16.3. For additional information on this position, see AFMAN 33-210, Air Force
Assessment and Authorization Program.
2.17. Cybersecurity Liaison. Each organizational command or other cognizant authority (i.e., group commander, Wing Cybersecurity Office) must appoint a Cybersecurity Liaison (formerly
Organizational IAO) when cybersecurity functions are consolidated to a central location or activity. (T-1). Additional (subordinate) cybersecurity liaison positions may be assigned for additional support at the discretion of organizations or based upon mission requirements, however, only one primary and one alternate cybersecurity liaison is mandatory. A cybersecurity liaison will:
AFI33-200 31 AUGUST 2015 19
2.17.1. Develop, implement, oversee, and maintain an organization cybersecurity program that identifies cybersecurity requirements, personnel, processes, and procedures. (T-1).
2.17.2. Supervise the organization’s cybersecurity program. (T-2).
2.17.3. Implement and enforce all Air Force cybersecurity policies and procedures using the guidance within this instruction and applicable specialized (COMSEC, COMPUSEC, TEMPEST etc.) cybersecurity publications. (T-1).
2.17.4. Assist the wing cybersecurity office in meeting their duties and responsibilities. (T-
3).
2.17.5. Ensure all users have the requisite security clearances, supervisory need-to-know authorization, and are aware of their cybersecurity (via cybersecurity training) before being granted access to Air Force IT according to AFMAN 33-282, chapter 4, AFI 31-501 and
AFMAN 33-152. (T-1).
2.17.6. Ensure all users receive cybersecurity refresher training on an annual basis. (T-2).
2.17.7. Ensure IT is acquired, documented, operated, used, maintained, and disposed of properly and in accordance with the IT’s security A&A documentation as prescribed by
AFMAN 33-210. (T-1).
2.17.8. Ensure proper CM procedures are followed. (T-1). Prior to implementation and contingent upon necessary approval according to this instruction and AFMAN 33-210, the cybersecurity liaison will coordinate any changes or modifications to hardware, software, or firmware with the wing cybersecurity office and system-level ISSM or ISSO. (T-1).
2.17.9. Report cybersecurity incidents or vulnerabilities to the wing cybersecurity office. (T-
3).
2.17.10. In coordination with the wing cybersecurity office, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered. (T-3).
2.17.11. Implement and maintain required cybersecurity (COMSEC, COMPUSEC and
TEMPEST) countermeasures and compliance measures IAW AFI 10-712, Telecommunications Monitoring and Assessment Program (TMAP). (T-1).
2.17.12. Initiate requests for temporary and permanent exceptions, deviations, or waivers to cybersecurity requirements or criteria according to this instruction and applicable specialized cybersecurity publications. (T-1).
2.17.13. When called upon to assist with an assessment conducted by the DIB
CS/Cybersecurity program office, provide subject matter experts to analyze the data and provide recommendations for further action. (T-3).
2.17.14. Maintain all IS authorized user access control documentation IAW the applicable
Air Force records Information Management System (AFRIMS). (T-3).
2.18. Information Systems Security Engineer (ISSE). The ISSE is any individual, group, or organization responsible for conducting information system security engineering activities.
Reference NIST SP 800-37, Applying the Risk Management Framework to Federal Information
Systems, for additional details.
20 AFI33-200 31 AUGUST 2015
2.18.1. Information system security engineering is a process that captures and refines information security requirements and ensures that the requirements are effectively integrated into information technology component products and information systems through purposeful security architecting, design, development, and configuration.
2.18.2. Information system security engineers are an integral part of the development team
(e.g., integrated project team) designing and developing organizational information systems or upgrading legacy systems.
2.18.3. Information system security engineers employ best practices when implementing security controls within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
2.18.4. System security engineers coordinate their security-related activities with information security architects, senior information security officers, information system owners, common control providers, and information system security officers.
2.18.5. IAW DoD 8570.01-M, Personnel performing any IA Workforce System Architecture and Engineering (IASAE) specialty function(s) (one or more functions) at any level must be certified to the highest level function(s) performed. (T-0).
2.19. Information Owner/Steward. An organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal as defined in CNSSI 4009, National Information Assurance Glossary. The Information
Owner/Steward will:
2.19.1. Plan and budget for security control implementation, assessment, and sustainment throughout the system life cycle, including timely and effective configuration and vulnerability management. (T-2).
2.19.2. Establish the rules for appropriate use and protection of the subject information (e.g., rules of behavior) and retain that responsibility even when the information is shared with or provided to other organizations. (T-1).
2.19.3. Provide input to ISOs on the security controls selection and on the derived security requirements for the systems where the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .