afman33-152.pdf
PDF 391 KB Posted
- Attached to
- Facilitate Other Maintenance Federal contract opportunity
- Solicitation number
- FA8224-16-R-0021
About this file
afman33-152
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BY ORDER OF THE
SECRETARY OF THE AIR FORCE
AIR FORCE MANUAL 33-152
1 JUNE 2012
Communications and Information
USER RESPONSIBILITIES AND GUIDANCE
FOR INFORMATION SYSTEMS
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
ACCESSIBILITY: Publications and forms are available for downloading or ordering on the e-
Publishing website at www.e-publishing.af.mil/.
RELEASABILITY: There are no releasability restrictions on this publication.
OPR: AF/A3CP/A6CP
Supersedes: AFI33-100, 19 November 2008;
AFI33-113, 6 February 2007;
AFI33-119, 24 January 2005;
AFI33-127, 1 May 1998; and
AFMAN33-128, 1 March 1997
Certified by: AF/A3C/A6C
(Maj Gen Earl Matthews)
Pages: 36
This instruction implements Air Force Policy Directive (AFPD) 33-1, Information Resources
Management, AFPD 33-2, Information Assurance (IA) Program, and identifies policies and procedures for the use of cyberspace support systems/services and compliance requirements of
Secretary of the Air Force, Chief of Warfighting Integration and Chief Information Officer
(SAF/CIO A6) managed programs. These programs ensure availability, interoperability, and maintainability of cyberspace support systems/services in support of Air Force mission readiness and warfighting capabilities. This manual applies to all Air Force military, civilians, contractor personnel under contract by the Department of Defense (DOD), and other individuals or organizations as required by binding agreement or obligation with the Department of the Air
Force. This manual applies to the Air National Guard (ANG) and the Air Force Reserve
Command (AFRC). Failure to observe the prohibitions and mandatory provisions of this instruction as stated in paragraphs 3.2, 4.5.4.2, 4.10.1, and 5.1.1.2 by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article 92, Failure to Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract. Additionally violations of paragraph 3.2 by ANG military personnel may subject members to prosecution under their respective State Military Code or result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Direct questions or comments on the http://www.e-publishing.af.mil/
2 AFMAN33-152 1 JUNE 2012
contents of this instruction, through appropriate command channels, to Cyberspace Operations, Cyberspace Policy Division (AF/A3CP/A6CP). Send recommended changes and conflicts between this and other publications, using Air Force (AF) Form 847, Recommendation for
Change of Publication, to AF/A3CP/A6CP, with information copy to SAF/CIO A6, Policy and
Compliance Division (SAF/A6PP). This publication may be supplemented at any level, but all direct supplements must be routed to the OPR of this publication for coordination prior to certification and approval. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN) 33-363, Management of Records, and disposed of in accordance with Air Force Records Disposition
Schedule (RDS) located at https://www.my.af.mil/afrims/afrims/afrims/rims.cfm. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force. See Attachment 1 for a glossary of references and supporting information.
SUMMARY OF CHANGES
This is a total revision to replace and update AFI 33-100, User Responsibilities and Guidance for
Information Systems. It incorporates and replaces AFI 33-113, AFI 33-119, AFI 33-127, and
AFMAN 33-128. It incorporates guidance for responsible use of the Internet that was previously covered by AFI 33-129, Web Management and Internet. This manual was rewritten and must be completely reviewed.
Chapter 1—INTRODUCTION 5
1.1. Introduction
1.2. Applicability
1.3. Objective
1.4. Assistance
1.5. Waiver Authority
Chapter 2—INFORMATION SYSTEMS AND END USER DEVICES 6
2.1. Overview
2.2. Training Requirement
2.3. Information System Access
2.4. Loss of Access
2.5. Disabling Accounts
2.6. General Protection
2.7. Notice and Consent to Monitoring
2.8. Information Technology Asset Procurement
2.9. Communications and IS Relocations or Modifications
2.10. Hardware and Software Security
https://www.my.af.mil/afrims/afrims/afrims/rims.cfm
AFMAN33-152 1 JUNE 2012 3
2.11. Malicious Logic Protection
2.12. Privately-Owned Hardware and Software
2.13. Peripheral Devices
2.14. Mobile Computing Devices
2.15. Removable Media
2.16. Collaborative Computing
2.17. Public Computing Facilities
2.18. Security Incident Reporting
CHAPTER 3—RESPONSIBLE AND EFFECTIVE USE OF INTERNET-BASED
CAPABILITIES 12
3.1. Limited Authorized Personal Use
3.2. Inappropriate Use
3.3. Official Use, Authorized Use, and Use of Internet-Based Capabilities
3.4. Managing Web Content
CHAPTER 4—VOICE COMMUNICATIONS SERVICES 15
4.1. Calls From Base Telephones
4.2. Collect Calls to Base Telephones
4.3. Personal Calls Over Official Telephones
4.4. Cordless Telephones Guidance
4.5. Commercial Cellular Telephone (CT) Service
4.6. Official Telephone Service in Personal Quarters is permitted for certain officials when necessary for national defense purposes
4.7. Unofficial Commercial Telephone/Voice Service In Quarters
4.8. Air Force Instruction on Defense Switched Network (DSN) On- or Off-Net
Calling
4.9. Health, Morale, and Welfare (HMW) Calls
4.10. Official Government Issued Calling Card Use
CHAPTER 5—RECORDS MANAGEMENT 20
5.1. Records Management
5.2. Records Authentication
CHAPTER 6—ELECTRONIC MESSAGING 22
6.1. General
6.2. Air Force Messaging
4 AFMAN33-152 1 JUNE 2012
6.3. Use of Subscription Services
6.4. Electronic Message Format
6.5. Protection and Disposition of Electronic Message Information
6.6. Digitally Signing and Encrypting Electronic Messages
6.7. Message Forwarding (Manual and Automated)
6.8. Message Management
6.9. Organizational Messaging
Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 29
AFMAN33-152 1 JUNE 2012 5
Chapter 1
INTRODUCTION
1.1. Introduction. In an effort to meet the growing needs of today’s war fighter, great strides are being made to improve the capabilities offered by the Air Force provisioned portion of the
Global Information Grid (GIG). Today’s Air Force is increasingly using these capabilities in almost all activities of warfighting and operations support. This increased reliance on technology and its integration requires each individual to take responsibility for ensuring effective, efficient, and authorized use of these resources as they carry out their responsibilities.
1.2. Applicability. This publication applies to all Air Force Information Systems (ISs) and devices, including stand-alone ISs, IS components of weapon systems where Platform
Information Technology (PIT) interconnections exist, ISs connected to external networks via authorized Internet Service Providers, ISs that provide the management infrastructure, and connections among other ISs and ISs used to process, store, display, transmit, or protect Air
Force information, regardless of classification or sensitivity.
1.2.1. This publication is binding on all authorized users to include military, civilian, contractor, temporary employees, volunteers, and interns who are authorized to operate the
ISs owned, maintained, and controlled by the Air Force.
1.2.2. More restrictive Federal, DOD, and Office of the Director of National Intelligence directive requirements governing non-Air Force space, Special Access Programs
(SAP)/Special Access Requirements (SAR), and Intelligence information take precedence over this publication.
1.3. Objective. The objective of this publication is to ensure users understand how to protect and secure United States (US) government information processed by Air Force ISs with the assistance of their applicable organizational IA workforce personnel (e.g., organizational
Information Assurance Officers [IAOs], Client System Technicians [CSTs]). This publication identifies policies and procedures for the use of cyberspace support systems/services and compliance requirements of Secretary of the Air Force, Chief of Warfighting Integration and
Chief Information Officer (SAF/CIO A6) managed programs.
1.4. Assistance. Users contact the organizational IAO for clarification on any Information
System requirements outlined within this publication.
1.5. Waiver Authority. AF/A3CP/A6CP is the waiver authority for the provisions in this manual. Waiver requests shall contain compelling justification and must be submitted via emailto AF/A3CP/A6CP.
6 AFMAN33-152 1 JUNE 2012
Chapter 2
INFORMATION SYSTEMS AND END USER DEVICES
2.1. Overview. Information systems are a set of information resources. End user devices include ISs such as desktop PCs, laptops, notebooks, tablets, smartphones, executive mobile devices, etc. as used by users. Access control is one of the measures taken to ensure ISs are protected against threats and vulnerabilities. This chapter provides user responsibilities for ISs including end user devices whereas AFMAN 33-282, Computer Security provides policies for all
Air Force ISs including IAO responsibilities for ISs.
2.2. Training Requirement. All IS users will complete DOD IA training prior to granting access to an IS according to DOD 8570.01-M, IA Workforce Improvement Program.
2.2.1. Users reaccomplish IA training annually using the Advanced Distributed Learning
System (ADLS) computer based training which reports compliance to the IAO.
2.2.2. When a user requires a new account or modification to an existing account (due to change of station or assignment, Temporary Duty [TDY], etc.), users are not required to retake the DOD IA training provided the user has a valid and current (within a year) course completion record.
2.3. Information System Access. Access to an Air Force IS is a privilege and continued access is contingent on personal conduct, personnel actions, changes in need to know, or operational necessity. Users request IS access and specific authorizations within the system through the organization or system IAO using the DD Form 2875, System Authorization Access Request
(SAAR). DD Form 2875 signatures may be handwritten or digital. Contact the organization or system IAO for identification and authentication guidance and see AFMAN 33-282, Computer
Security. See paragraph 2.14 for wireless mobile device requirements.
2.3.1. All authorized IS users will sign the standardized AF Form 4394, Air Force User
Agreement Statement-Notice and Consent Provision prior to initial IS access and submit to the organization IAO with a handwritten or digital signature. Only one AF Form 4394 is required per user as maintained by the organization IAO regardless of the number of system access requests inside or outside the organization.
2.3.2. Access to classified ISs also requires a Standard Form 312, Nondisclosure Agreement, according to AFI 31-401, Information Security Program Management.
2.3.3. Users may transport or email their user agreement (AF 4394) upon permanent change of station and present it to the gaining organization IAO at in-processing. Wireless Mobile
Device user agreements must be reaccomplished due to new authorizing/issuing personnel.
2.3.4. Each user is responsible and accountable for their password/Personal Identification
Number (PIN).
2.3.5. Users must protect all passwords and PINs based on the sensitivity of the information or critical operations they protect (e.g., a password used to gain access to a SECRET network is itself classified SECRET). Follow all CAC individual responsibilities according to AFI
36-3026_IP, Volume 1, Identification Cards for Members of the Uniformed Services, Their
Eligible Family Members, and Other Eligible Personnel.
AFMAN33-152 1 JUNE 2012 7
2.3.6. Interim system access may be granted for less than 5 duty days if system access is required to complete electronic versions of DD Form 2875 and/or AF Form 4394.
2.3.7. DoD Visitor access allows any user with a DoD Common Access Card (CAC) temporary access on any supported computer when they are away from their normal duty station. This allows for limited access to the basic capabilities of the computer to enable access to available enterprise capabilities. Full access and privileges to additional capabilities requires a request for IS access.
2.4. Loss of Access. User’s conduct that is inconsistent with IA policies and guidelines may result in immediate suspension of access to unclassified and classified ISs.
2.4.1. Supervisors follow the guidance in AFMAN 33-282, Computer Security for suspension actions once a violation is confirmed. Violations of IA policies and guidelines include, but are not limited to:
2.4.1.1. Unauthorized use of the network.
2.4.1.2. Failure to maintain annual DOD IA awareness training.
2.4.1.3. Actions that threaten the security of a network or a governmental communications system (e.g., willful downloading of malicious software, attempting to add unauthorized software, unauthorized flash drive usage).
2.4.1.4. Actions that knowingly threaten or damage DOD IS or communications security
(hacking or inserting malicious code or viruses, theft, destruction of IT assets, willfully not using encryption).
2.4.2. If an individual’s security clearance is suspended or revoked, access to IS will be suspended. If an organizational commander feels the member should have access restored on an interim basis, they shall follow reinstatement procedures outlined in AFMAN 33-282.
2.5. Disabling Accounts. Supervisors and/or users are responsible for notifying system privileged users (e.g., CSTs) or the IAO when an account is no longer required (e.g., individual leaves organization for local accounts or service for enterprise accounts) or if it is believed the account has been compromised.
2.6. General Protection. All authorized users will protect networked and/or stand-alone ISs against tampering, theft, and loss. Protect ISs from insider and outsider threats by controlling physical access to the facilities and data by implementing procedures identified in Joint, DOD, AF publications, and organizationally created procedures.
2.6.1. Backing up personal data stored locally on an IS (e.g. desktop computer, laptop) is the responsibility of the user. Local organizational policy dictates frequency and limitation factors.
2.6.2. Protect sensitive information (e.g. Controlled Unclassified Information [CUI], For
Official Use Only [FOUO], Personal Identifiable Information [PII], Health Insurance
Portability and Accountability Act [HIPAA], Privacy Act [PA], proprietary, contracts, etc.)
with encryption when transmitting data.
2.7. Notice and Consent to Monitoring. Users of DOD telecommunications devices and information systems are to be notified the use of these systems constitutes consent to monitoring.
8 AFMAN33-152 1 JUNE 2012
2.7.1. All users of DOD information systems will sign the standardized AF Form 4394.
Local organizational commanders must restrict access to DOD information systems for those personnel who fail to sign the agreement. Organization IAOs are required to report to the
Enterprise Service Desk (ESD) any failures to sign the agreement for revocation of access to enterprise capabilities.
2.7.2. To maintain continuous notifications to all users using DOD telecommunications devices including Voice over Internet Protocol (VoIP) phone instruments, user will report to the IAO any of following deficiencies:
2.7.2.1. A DD Form 2056, Telephone Monitoring Notification Decal, is missing or not readable on the front of all official telephones and VoIP phone instruments.
2.7.2.2. A DD Form 2056 is missing or not readable on fax machines.
2.7.2.3. Locally created organizational/unit fax cover sheets do not contain the exact notice and consent statement: ―Do not transmit classified information over unsecured telecommunications systems. Official DOD telecommunications systems are subject to monitoring. Using DOD telecommunications systems constitutes consent to monitoring.‖
2.7.3. The banner on DOD information systems functions to remind users of the conditions that are set forth in the AF Form 4394, regardless of whether the banner describes these conditions in full detail or provides a summary of such conditions, and regardless of whether the banner expressly references the AF Form 4394.
2.8. Information Technology Asset Procurement. Procurement activities must adhere to AFI
33-112, Information Technology Hardware Asset Management.
2.8.1. Adhere to locally defined requirements process when acquiring IT hardware, cellular, and peripheral devices (e.g., desktops, laptops, servers, smartphones, cell phones, printers, scanners).
2.8.2. The installation Communications and Information Systems Officer (CSO) supports the information systems requirements process enabling requesting organizations to obtain new communications and information capabilities. Contact the AFWay, NETCENTS, or
NETCENT-2 program management offices for purchase of information technology products and services using an enterprise procurement contract before locally acquiring information technology.
2.9. Communications and IS Relocations or Modifications. Contact the IAO prior to any project to install, relocate, modify, or remove end user devices. The IAO will provide guidance before initiating any project to install, relocate, modify, or remove end user devices to ensure the user submits requests in accordance with organizational policy.
2.10. Hardware and Software Security. Coordinate with the Information System Owner
(ISO) and/or system Information Assurance Manager (IAM), and contracting office for security approval required as a part of any software purchase. Do not install software or hardware on an
IS without coordination with the system IAO. The system IAO is responsible for the proper coordination and implementation in accordance with AFI 33-200, Information Assurance (IA)
Management and AFMAN 33-282, Computer Security.
AFMAN33-152 1 JUNE 2012 9
2.11. Malicious Logic Protection. Protect ISs from malicious logic (e.g., virus, worm, Trojan horse) attacks by applying a mix of human and technological preventative measures. Contact the
IAO for additional guidance to protect ISs from malicious logic.
2.11.1. Scan approved removable media devices for viruses before and after use if scans are not automated.
2.11.2. Report any suspected IS abnormalities (i.e., antivirus errors, virus alerts, unexpected file size increases, unexpected disk access, strange activity by applications, etc.) immediately to the organizational IAO.
2.12. Privately-Owned Hardware and Software. Using privately-owned hardware and software for government work is strongly discouraged; however, it may be used for processing unclassified and sensitive information with justification and approval. Contact your organizational IAO for assistance and requirements and see AFMAN 33-282, Computer
Security.
2.12.1. Do not connect or use any privately-owned media or peripheral devices (including but not limited to music/video CD/DVDs, digital music players, mobile phones, tablets, Universal Serial Bus [USB] drives, external hard drives, and flash media devices) to AF ISs and government furnished equipment (GFE).
2.12.2. Do not install and use copies of government-owned software on a home computer unless the software license explicitly allows users to do so and the installation CSO has authorized such use. Reference AFI 51-303, Intellectual Property--Patents, Patent Related
Matters, Trademarks and Copyrights.
2.13. Peripheral Devices. A computer peripheral is any external device that provides input and output for the computer (e.g. mouse, scanners, smart boards, pointers, and keyboard devices are input devices). Do not connect any peripheral device not already preapproved for use on the AF-
GIG without notifying the IAO.
2.14. Mobile Computing Devices. Mobile computing devices are IS devices such as Portable
Electronic Devices (PED), laptops, and other handheld devices that can store data locally and access AF-managed networks through mobile access capabilities.
2.14.1. All authorized wireless mobile device users will sign the standardized AF Form
4433, US Air Force Unclassified Wireless Mobile Device User Agreement, and adhere to guidance contained within the agreement when using a wireless mobile computing device.
The AF Form 4433 is not required for mobile computing devices issued with wireless capabilities disabled.
2.14.2. Encrypt all sensitive information (e.g. Controlled Unclassified Information [CUI], For Official Use Only [FOUO], Personal Identifiable Information [PII], Health Insurance
Portability and Accountability Act [HIPAA], Privacy Act [PA], proprietary, contracts, etc.)
transmitted through a commercial or wireless network (e.g., mobile hotspot, commercial
Internet café) using an encrypted Virtual Private Network (VPN) connection or other authorized encryption solution whenever practical. Contact the Enterprise Service Desk
(ESD) or see your base Communications Focal Point (CFP) for installation and usage instructions.
10 AFMAN33-152 1 JUNE 2012
2.14.3. Do not operate unclassified wireless technology, devices or services (used for storing, processing, and/or transmitting information), in areas where classified information is discussed, electronically stored, electronically processed, or electronically transmitted without approval of the organizational IAO. See AFMAN 33-282, Computer Security for additional guidance.
2.14.4. Only use approved classified wireless devices to store, process, or transmit classified information.
2.14.5. Lost or stolen government mobile computing devices must be reported immediately to your IAO.
2.14.6. Complete additional PED and removable storage media training at the organization’s discretion here: http://iase.disa.mil/eta/pedrm_v2/pedrm_v2/launchPage.htm.
2.14.7. Do not alter or remove any pre-installed software/configurations on end user devices without contacting the IAO.
2.15. Removable Media. Removable media refers to information system storage media that can be removed from its reader device, conferring portability on the data it carries (e.g., diskettes, CDs, DVDs, USB storage devices, or any other device on which data is stored and which normally is removable from the system by the user or operator).
2.15.1. Safeguard, mark, and label removable media according to the requirements for the highest level of information contained on the media using applicable information security guidance in AFI 31-401, Information Security Program Management and AFI 33-332, Air
Force Privacy Program. External and internal labeling guidance for media can be found in
AFMAN 33-363, Management of Records.
2.15.2. Do not remove removable media with sensitive information from protected workplaces unless encrypted with an authorized encryption method and signed in and out with a supervising official. Contact the IAO for specific guidance.
2.15.3. Immediately report loss or suspected loss of removable media containing classified, CUI, or PII to the IAO and according to AFI 31-401, Information Security Program
Management and AFI 33-332, Air Force Privacy Program.
2.15.4. Obtain guidance and/or approval from the organizational IAO before attaching any external storage devices (to include USB storage devices, hard drives, and flash media) to an
IS.
2.15.5. Immediately contact the IAO if it appears information of higher classification introduced onto a lower classification IS or there is spillage between compartments.
Disconnect the suspected systems from the network and/or power off and secure the device appropriately.
2.15.6. Writing to any type of removable media from classified systems is prohibited unless appropriately approved. Organizations with a mission requirement to write to removable media must first submit requests for a waiver through the IAO.
2.16. Collaborative Computing. Collaborative computing (video teleconferencing, etc) provides an opportunity for a group of individuals and/or organizations to share and relay information in such a way that cultivates team review and interaction in the accomplishment of http://iase.disa.mil/eta/pedrm_v2/pedrm_v2/launchPage.htm
AFMAN33-152 1 JUNE 2012 11
duties and attainment of mission accomplishment. Contact the IAO for guidance on connecting video cameras and microphones to ISs.
2.17. Public Computing Facilities. Do not use public computing ISs (Internet cafés and kiosks, hotel business centers, etc.) for processing government-owned unclassified, sensitive or classified information. Public computing ISs include any information technology resources not under your private or the United States (US) Government’s control.
2.17.1. Using these resources to access web-based government services (e.g., webmail) constitutes a compromise of log-in credentials and must be reported to your IAO.
2.17.2. Connection of privately owned or United States (US) Government controlled mobile computing devices to public networks is permitted to remotely access government services
(e.g., webmail) if mobile computing device encryption and connection policies are followed.
Public networks include internet service providers for private residences.
2.18. Security Incident Reporting. A security incident is an assessed occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an IS. Security incidents can include but are not limited to:
2.18.1. Data Spillage. Data spillage occurs when a higher classification level of data is placed on a lower classification level system/device or across compartments.
2.18.2. Classified Message Incidents. A classified message incident occurs when a higher classification level of data is transferred to a lower classification level system/device via messaging systems. Users must:
2.18.2.1. Report all suspected and/or actual unauthorized network activities or incidents to the IAO ensuring notification continues up the chain of command. Use appropriate systems and methods to report incidents including secure voice if required or appropriate.
Do not allow the incident to become widespread knowledge. Exercise ―Need to know‖ in these situations.
2.18.2.2. Security incident response must include appropriate tasks to secure the computing environment from further malicious activity and preserve computer forensic evidence for analysis. User must disconnect affected IS or media from the network (i.e.
removal of network cable, turn off wireless capability, etc.). Do not turn off the IS.
2.18.2.3. User notifies IAO or other designated representative as outlined in local operating instructions such as the Unit Security Manager (USM). USM notifies the wing
Information Protection (IP) office within 24 hours of incident.
12 AFMAN33-152 1 JUNE 2012
Chapter 3
RESPONSIBLE AND EFFECTIVE USE OF INTERNET-BASED CAPABILITIES
3.1. Limited Authorized Personal Use. Government-provided hardware and software are for official use and limited authorized personal use only. Limited personal use must be of reasonable duration and frequency that have been approved by the supervisors and do not adversely affect performance of official duties, overburden systems or reflect adversely on the
Air Force or the DOD.
3.1.1. All personal use must be consistent with the requirements of DOD 5500.7-R, Joint
Ethics Regulation.
3.1.2. Internet-based capabilities are all publicly accessible information capabilities and applications available across the Internet in locations not owned, operated, or controlled by the Department of Defense or the Federal Government. Internet-based capabilities include collaborative tools such as SNS, social media, user-generated content, social software, e-mail, instant messaging, and discussion forums (e.g., YouTube, Facebook, MySpace, Twitter, Google Apps).
3.1.2.1. When accessing Internet-based capabilities using Federal Government resources in an authorized personal or unofficial capacity, individuals shall comply with OPSEC guidance (AFI 10-701, Operations Security) and shall not represent the policies or official position of the Air Force or DOD.
3.1.3. Examples of authorized limited personal use include, but are not limited to:
3.1.3.1. Notifying family members of official transportation or schedule changes.
3.1.3.2. Using government systems to exchange important and time-sensitive information with a spouse or other family members (i.e., scheduling doctor, automobile, or home repair appointments, brief Internet searches, or sending directions to visiting relatives).
3.1.3.3. Educating or enhancing the professional skills of employees, (i.e., use of communication systems, work-related application training, etc.).
3.1.3.4. Sending messages on behalf of a chartered organization, (i.e., organizational
Booster Club, Base Top 3, Base Company Grade Officers Association, etc.).
3.1.3.5. Limited use by deployed or TDY members for morale, health, and welfare purposes.
3.1.3.6. Job searching.
3.2. Inappropriate Use. Using the Internet for other than official or authorized use may result in adverse administrative or disciplinary action. The activities listed in paragraphs 3.2.1. through
3.2.13. involving the use of government-provided computer hardware or software are specifically prohibited. Failure to observe the prohibitions and mandatory provisions of paragraphs
3.2.1 through 3.2.13 by military personnel is a violation of the Uniform Code of Military
Justice (UCMJ), Article 92, Failure to Obey Order or Regulation. Violations by ANG military personnel may subject members to prosecution under their respective State
AFMAN33-152 1 JUNE 2012 13
Military Code or result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.
3.2.1. Use of Federal government communications systems for unauthorized personal use.
See DOD 5500.7-R, Joint Ethics Regulation (JER).
3.2.2. Uses that would adversely reflect on the DOD or the Air Force such as chain letters, unofficial soliciting, or selling except on authorized Internet-based capabilities established for such use.
3.2.3. Unauthorized storing, processing, displaying, sending, or otherwise transmitting prohibited content. Prohibited content includes: pornography, sexually explicit or sexually oriented material, nudity, hate speech or ridicule of others on the bases of protected class
(e.g., race, creed, religion, color, age, sex, disability, national origin), gambling, illegal weapons, militancy/extremist activities, terrorist activities, use for personal gain, and any other content or activities that are illegal or inappropriate.
3.2.4. Storing or processing classified information on any system not approved for classified processing.
3.2.5. Using copyrighted material in violation of the rights of the owner of the copyrights.
Consult with the servicing Staff Judge Advocate for ―fair use‖ advice.
3.2.6. Unauthorized use of the account or identity of another person or organization.
3.2.7. Viewing, changing, damaging, deleting, or blocking access to another user’s files or communications without appropriate authorization or permission.
3.2.8. Attempting to circumvent or defeat security or modifying security systems without prior authorization or permission (such as for legitimate system testing or security research).
3.2.9. Obtaining, installing, copying, storing, or using software in violation of the appropriate vendor’s license agreement.
3.2.10. Permitting an unauthorized individual access to a government-owned or government-operated system.
3.2.11. Modifying or altering the network operating system or system configuration without first obtaining written permission from the administrator of that system.
3.2.12. Copying and posting of FOUO, CUI, Critical Information (CI), and/or PII on DOD– owned, –operated, or –controlled publically accessible sites or on commercial Internet-based capabilities.
3.2.13. Downloading and installing freeware/shareware or any other software product without DAA approval.
3.3. Official Use, Authorized Use, and Use of Internet-Based Capabilities. Official use of
Internet-based capabilities unrelated to public affairs is permitted. However, because these interactions take place in a public venue, personnel acting in their official capacity shall maintain
14 AFMAN33-152 1 JUNE 2012
liaison with their public affairs and operations security staff to ensure organizational awareness.
Use of Internet-based capabilities for official purposes shall:
3.3.1. Comply with guidance in AFI 10-701, Operations Security, AFI 33-322, Records
Management, AFI 33-364, Records Disposition-Procedures and Responsibilities, AFI 33-
332, Privacy Act Program, and AFMAN 33-363, Management of Records.
3.3.2. Be consistent with the requirements of DOD 5500.7-R, Joint Ethics Regulation (JER).
3.3.3. Comply with public affairs Internet-based capabilities guidance.
3.3.4. Ensure that the information posted is relevant and accurate and provide no information not approved for public release, including personally identifiable information (PII).
3.3.5. Provide links to official Air Force content hosted Air Force-owned, -operated, or – controlled sites where applicable.
3.3.6. Include a disclaimer when personal opinions are expressed (e.g., ―This statement is my own and does not constitute an endorsement by or opinion of the Air Force or the
Department of Defense‖).
3.3.7. Air Force personnel may subscribe to official government-sponsored news, mail lists, and discussion groups. Some of these products are managed and approved by SAF/PA and accessible from the Air Force Link (http://www.af.mil). Using non-government subscription services without prior approval is misuse of a government system. Subscription or participation in subscription services will be in support of official duties only.
3.4. Managing Web Content. Information systems provide the capability to quickly and efficiently disseminate information. Web content must be managed in compliance with all information management policies and procedures including AFMAN 37-104, Managing
Information to Support the Air Force Mission.
3.4.1. All DOD telecommunications systems and information systems are subject to monitoring for authorized purposes as prescribed by AFI 33-200, Information Assurance (IA)
Management and AFI 10-712, Telecommunications Monitoring and Assessment Program
(TMAP). Prominently display the exact notice and consent banner specified in AFI 10-712, Telecommunications Monitoring and Assessment Program (TMAP) on the first page of all private/intranet web homepages. Notice and consent requirements do not apply to publicly accessible web sites/pages.
3.4.2. The publication of web content available to the public must comply with AFI 35-107, Public Web Communications and AFI 35-102, Security and Policy Review Process in addition to the official use policies in this chapter.
http://www.af.mil/
AFMAN33-152 1 JUNE 2012 15
Chapter 4
VOICE COMMUNICATIONS SERVICES
4.1. Calls From Base Telephones.
4.1.1. Do not discuss classified or critical information over an unsecured telephone.
4.1.2. Long Distance Calls From Base Telephones.
4.1.2.1. Use the Defense Switched Network (DSN), not commercial long distance carriers, to call other DOD activities unless DSN service is not available in a timely manner. Use the DSN system only for official business or when in the best interest of the government.
4.1.2.2. User will contact their Telephone Control Officer (TCO) to obtain a personal identification number (PIN) for accessing commercial long distance voice service. This service is authorized for official uses only.
4.1.2.3. Callers without direct long distance dialing capability must request a control or billing account number from their TCO. Give the control or billing account number to the base switchboard operator when making a call.
4.1.2.4. For verification purposes, document all commercial long distance calls on AF
Form 1072, Authorized Long Distance Telephone Calls. This is only required when PINs are not established or the host base does not have the capability to capture source caller identification information for each call.
4.2. Collect Calls to Base Telephones. The installation commander provides local guidance for official collect calls.
4.3. Personal Calls Over Official Telephones.
4.3.1. All government communications systems are subject to monitoring, interception, search, and seizure for all authorized purposes, reference Directive-Type Memorandum 08-
060, Policy on Use of Department of Defense (DoD) Information Systems – Standard
Consent Banner and User Agreement. Commanders and supervisors may allow personal calls during work hours using official telephones if:
4.3.1.1. The telephone call does not interfere with official duties.
4.3.1.2. The calls do not exceed reasonable duration and frequency, and whenever possible, are made during the employee’s personal time such as after-duty hours or lunch periods.
4.3.1.3. The telephone calls serve a legitimate public interest (such as usage reduces time away from the work area or improves unit morale).
4.3.1.4. The telephone call does not reflect adversely on DOD or the Air Force (e.g., uses involving pornography; unofficial advertising, soliciting, or selling; and discussion of classified information).
4.3.1.5. The government does not incur any long distance or per-call charges above and beyond normal local charges. Normal local charges are based upon historical averages.
16 AFMAN33-152 1 JUNE 2012
4.3.1.6. Personal calls may be made for "morale purposes" during deployments and
TDYs as authorized by the organizational commander, see paragraph 4.9. for specific guidance.
4.4. Cordless Telephones Guidance.
4.4.1. The installation CSO, or designated representative, approves the use of cordless telephones on a case-by-case basis. For security purposes, the use of cordless phones on military installation work centers is highly discouraged. Cordless telephones can be
―stepped-on‖ due to limited frequency allocation and overlapping of voice frequencies.
Cordless telephones used outside the United States and Possessions will be host nation approved.
4.4.2. Use of cordless phones for command and control (C2) is prohibited.
4.4.3. Operating cordless phones within a classified environment will be certified for use by the installation Emission Security (EMSEC) manager within the Wing IA office.
4.5. Commercial Cellular Telephone (CT) Service.
4.5.1. Organizations must request host base CSO approval before purchasing commercial cellular equipment.
4.5.2. Personal calls to CT service providers from the host base official service may be authorized if the Air Force does not incur a long-distance toll or per-call charge. Cellular telephone services that provide per-call charges by billing the originating (calling) party, should be limited by the host base voice information system to official calls only.
4.5.3. Official Use of CT Service.
4.5.3.1. Use CT services only when it is the most cost-effective way to provide necessary communications or mobility is required.
4.5.3.2. Do not use an unclassified CT for C2 purposes. For security purposes, use a regular telephone (land line) as a first priority when and where available.
4.5.3.3. Do not transmit classified or critical information over unsecured CTs.
4.5.3.4. Minimize use of government-issued CTs while operating a moving vehicle.
Comply with local policies, on or off-base.
4.5.4. Personal Use of CT Service.
4.5.4.1. The same rules that govern use of land line telephones apply to the use of Air
Force CTs. Reference paragraph 4.9. for official and authorized purposes.
4.5.4.2. Members making inappropriate CT calls, text messages, or emails are subject to disciplinary action even if the usage does not cause additional expense. Failure to observe the prohibitions and mandatory provisions of paragraph 4.5.4.2.1 by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article 92, Failure to Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.
AFMAN33-152 1 JUNE 2012 17
4.5.4.2.1. Do not use Air Force issued CTs to conduct personal commercial activities. Some examples of inappropriate calls include those related to personal solicitation or sales matters and those of a harassing or obscene nature. If a caller has any questions concerning proper use of government cell phones, it is the caller’s responsibility to check with a supervisor before making the call.
4.5.4.3. Dual line CTs. Individuals may elect at their option to activate the secondary line as a personal number and place personal calls on that line.
4.5.4.3.1. Activation of a dual-number capability is not permitted on secure CTs.
4.5.4.3.2. Authorized end user of a government-owned, dual-number capable CT:
4.5.4.3.2.1. Shall sign an agreement, produced in accordance with Base Judge
Advocate and Contracting office guidance, that contains appropriate ―hold harmless‖ and ―personal liability‖ clauses, prior to being issued a dual-number capable CT, without regard to whether or not the user elects to immediately activate the secondary number capability.
4.5.4.3.2.2. Must ensure all bills associated with the personal account are mailed directly to the user’s home address or post office box if a secondary number is activated.
4.5.4.3.2.3. Shall ensure that the personal account is closed and the secondary number zeroized by the vendor prior to returning the CT to the local Personal
Wireless Communications System (PWCS) manager for reuse when a CT is no longer required for the performance of duties.
4.6. Official Telephone Service in Personal Quarters is permitted for certain officials when necessary for national defense purposes. Contact your organizational TCO for more information. Specific policy and procedures are contained in AFI 33-111, Voice Systems
Management.
4.7. Unofficial Commercial Telephone/Voice Service In Quarters.
4.7.1. The individual subscriber must pay for renting, acquiring, and maintaining end-user instruments, as well as all usage charges for personal telephone service.
4.7.2. If required by the housing manager, housing occupants must restore telephone wiring and outlets to the original configuration before clearing quarters.
4.8. Air Force Instruction on Defense Switched Network (DSN) On- or Off-Net Calling.
4.8.1. Authorized Actions:
4.8.1.1. Placing an official call to a DSN operator (base operator) from a commercial network and having the operator extend the call over DSN to a DSN number (on-netting).
4.8.1.2. Placing an official call to a DSN operator from a DSN number and having the operator extend the call to a local commercial number (off-netting).
4.8.1.2.1. The installation CSO determines local guidance on the off-netting of an official DSN call to an official long-distance toll number. The installation CSO is directly responsible for toll charges and determines billing procedures, recourse for
18 AFMAN33-152 1 JUNE 2012
reimbursement, and/or acceptable appropriated fund support for off-netting official installation toll calls.
4.9. Health, Morale, and Welfare (HMW) Calls.
4.9.1. HMW calls are authorized over the DSN as prescribed in Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6215.01C, Policy for Department of Defense Voice Networks with Real Time Services (RTS). HMW calls are not authorized on government-issued CT, or via the FTS-2001 (or its designated replacement) network. However, satellite phones may be approved for HMW calls by the Organizational Commander on a case-by-case basis. You can obtain copies of CJCS publications at http://www.dtic.mil/doctrine/index.html.
4.9.1.1. HMW calls are intended for military and Department of the Air Force civilians.
HMW calls are authorized when:
4.9.1.1.1. In an unaccompanied status at overseas or remote geographic locations.
4.9.1.1.2. Single at overseas or remote geographic locations.
4.9.1.1.3. Performing temporary duty (TDY).
4.9.1.2. Immediate family members or the parents of single active duty personnel and/or the guardian of the child of a single parent or military/military couple, both of whom are deployed, may be permitted to participate in the HMW program under procedures established by the Airman and Family Readiness Center (i.e., as part of ―Hearts Apart‖ or similar programs) and the host commander. It is both the deployed commander and the host base commander’s responsibility to provide guidance on the limitations and opportunities made available by this program.
4.9.1.3. The primary method for placing HMW calls is Automated Health and Morale
System (AHAMS). AHAMS eliminates the need for base operator involvement and automatically controls time limits. If AHAMS is not available then place DSN HMW calls at routine precedence, normally not to exceed 15 minutes.
4.9.1.4. DSN HMW calls should not exceed a reasonable frequency as designated by the installation commander in conjunction with the installation CSO. Reasonable frequency is based upon installation/theater policy and determined by system capabilities, mission needs and restrictions. EXCEPTION: Emergency calls may exceed the established threshold.
4.9.1.5. Extending DSN HMW calls to a commercial number (off-netting) is authorized, provided it does not interfere with operational requirements. Off-net DSN HMW calls will not incur a toll charge to the government even if the intent is to reimburse the government. If the call incurs a toll charge, base operators may extend the call if the caller uses a credit/calling card to charge the call or the called party agrees to accept the charges (e.g., reversing of charges). See paragraph 4.8.1.2 for definition of off-netting.
4.9.1.6. On-netting of DSN HMW calls is permissible when placed from within the
Continental United States (CONUS) as part of Airman and Family Readiness ―Hearts
Apart‖ or other similar programs. See paragraph 4.8.1.1. for definition of on-netting.
4.10. Official Government Issued Calling Card Use.
http://www.dtic.mil/doctrine/index.html
AFMAN33-152 1 JUNE 2012 19
4.10.1. Government issued calling cards are issued for official use only. Cardholders must not use the calling card for any purpose other than official use. Failure to observe the prohibitions and mandatory provisions of this paragraph by military personnel is a violation of the Uniform Code of Military Justice (UCMJ), Article 92, Failure to Obey
Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws. Violations by contactor personnel will be handled according to local laws and the terms of the contract.
4.10.2. Cardholders must sign a statement acknowledging receiving the government issued calling card and that the card is for official use only.
20 AFMAN33-152 1 JUNE 2012
Chapter 5
RECORDS MANAGEMENT
5.1. Records Management. Records management will be established as applicable for Air
Force External Official Presence and for Air Force-wide, -operated, or –controlled publically accessible Internet sites. All uses must comply with AFI 33-322, AFI 33-332, AFI 33-364, and
AFMAN 33-363. Records play a vital role in managing and operating Air Force activities. In simple terms, records document official business, serve as the memory of the organization, a record of past events, and are the basis for future actions. Every Air Force activity must manage its records to comply with legal accountability requirements. The key to an effective records management program is the integrity of the filing system--a system that ensures a standard methodology for filing, storing, discovering, retrieving, and ultimately disposing of records according to published retention and disposition schedules. Discovery of records must be facilitated by the creator of the information asset by assuring that metadata describing the information is captured or generated. AFMAN 33-363 establishes the requirement to use the Air
Force Records Information Management System (AFRIMS); establishes guidelines for managing all records (regardless of media); and defines methods and the format for record storage, file procedures, converting paper records to other media or vice versa, and outlines the minimum to comply with records management legal and policy requirements.
5.1.1. All personnel:
5.1.1.1. Will receive annual government records management and PII training.
5.1.1.2. Must not conceal, remove, mutilate, obliterate or destroy government records without proper authority. Unauthorized concealment, removal, mutilation, obliteration or destruction of records, or any attempt to do so, may be a violation of Title 18, U.S.C., Section 2071 and may be punished by up to three years confinement and a fine.
Violations by military personnel are a violation of the Uniform Code of Military
Justice (UCMJ), Article 92, Failure to Obey Order or Regulation. Violations by civilian employees may result in administrative disciplinary action without regard to otherwise applicable criminal or civil sanctions for violations of related laws.
Violations by contactor personnel will be handled according to local laws and the terms of the contract.
5.1.1.3. Must inform officials of any actual or potential unlawful removal, change, or destruction of Air Force records.
5.1.1.4. Must distinguish government records from non-record materials and maintain…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .