afman33-282.pdf
PDF 577 KB Posted
- Attached to
- Facilitate Other Maintenance Federal contract opportunity
- Solicitation number
- FA8224-16-R-0021
About this file
afman33-282
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF THE AIR FORCE
WASHINGTON, DC
OFFICE OF THE SECRETARY
AFMAN33-282_AFGM2015-01
19 March 2015
MEMORANDUM FOR DISTRIBUTION C
MAJCOMs/FOAs/DRUs
FROM: SAF/CIO A6
1800 Air Force Pentagon Washington DC 20330-1720
SUBJECT: Air Force Guidance Memorandum to AFMAN 33-282, Computer Security (COMPUSEC), 28 March 2012, Incorporating Change 1, 15 January 2015
By Order of the Secretary of the Air Force, this Air Force Guidance Memorandum immediately changes AFMAN 33-282, COMPUSEC. Compliance with this Memorandum is mandatory. To the extent its directions are inconsistent with other Air Force publications; the information herein prevails, in accordance with AFI 33-360, Publications and Forms Management.
Enterprise activated Commercial Mobile Devices (CMDs) in the Air Force are government-issued smart phones and tablets IAW DoD Commercial Mobile Device Interim Policy, 17 Jan 2012 and DoD Commercial Mobile Device Implementation Plan, 15 February 2013. The following policy is added to AFMAN 33-282, paragraph 6.18 clarifying Enterprise Activated CMD use in the Air Force:
6.18.1. Air Force organizations using Defense Enterprise Email (DEE).
6.18.1.1. CMDs must use DoD Enterprise Mobility (DEM) solutions (T-0).
6.18.1.2. CMDs must be purchased utilizing the Network Enterprise Technology Command Blanket Purchase Agreement (BPA) and be on the DISA Approved Products List (T-0).
6.18.1.3. CMDs must be managed by DISA’s approved Mobile Device Management (MDM), Mobile Content Management (MCM) or Mobile Application Management (MAM) system (T-0).
6.18.2. Air Force organizations not using DEE.
6.18.2.1. CMDs must use Air Force Enterprise Mobility Solutions (T-1).
6.18.2.2. CMDs must be purchased utilizing the Network Enterprise Technology Command Blanket Purchase Agreement (BPA) and be on the Air Force Approved Products List (T-0).
6.18.2.3. CMDs must be managed by an AF-approved MDM, MCM, or MAM system (T-1).
Customers requiring other new IT services, to include Non-enterprise Activated CMDs, (see para. 6.17 of this manual) or with questions regarding procedures for non-program office fielded systems may forward requirements/questions to HQ AFSPC/A2/3/6 A6CI, Network/Infrastructure Branch, a6.wf@us.af.mil or via memorandum (see AFI 33-115, para 4.10.3.1).
Questions regarding this policy may be forwarded to the SAF/CIO A6SS Strategy and Policy Division, usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil. This memorandum becomes void after one year has elapsed from the date of this memorandum, or upon publication of an Interim Change or rewrite of AFMAN 33-282, whichever is earlier.
WILLIAM J. BENDER, Lt Gen, USAF Chief, Information Dominance and Chief Information Officer mailto:usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil
BY ORDER OF THE
SECRETARY OF THE AIR FORCE
AIR FORCE MANUAL 33-282
28 MARCH 2012
Incorporating Change 1, 15 January 2015
Communications and Information
COMPUTER SECURITY (COMPUSEC)
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
ACCESSIBILITY: Publications and forms are available on the e-Publishing website at www.e-publishing.af.mil for downloading or ordering.
RELEASABILITY: There are no releasability restrictions on this publication.
OPR: SAF/A6OI
Supersedes: AFSSI 8502, 18 September 2008;
AFSSI 8520, 18 June 2009;
AFSSI 8522, 9 June 2008; and
AFSSI 8580, 17 November 2008
Certified by: SAF/A6O
(Mr. Kenneth Brodie)
Pages: 62
This Air Force Manual (AFMAN) implements Computer Security in support of Air Force Policy
Directive (AFPD) 33-2, Information Assurance (IA) Program and Air Force Instruction (AFI)
33-200, Information Assurance (IA) Management. Computer Security (COMPUSEC) is defined within the Information Assurance (IA) portion of AFI 33-200. This publication applies to Air
Force military, civilian and contractor personnel under contract to the Department of Defense
(DoD), who manage COMPUSEC for Air Force organizations. This publication applies to the
Air National Guard and Air Force Reserve Command. Additional instructions and manuals are listed on the Air Force Publishing Website at http://www.e-publishing.af.mil under Electronics
Publications. Direct questions, recommended changes, or conflicts to this publication, through command channels using AF Form 847, Recommendation for Change of Publication, to
SAF/CIO A6SS. Unless otherwise noted, the SAF/CIO A6 is the waivering authority to policies contained in this publication. The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See AFI 33-360, Publications and Forms Management, Table 1.1 for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the Publication
OPR for non-tiered compliance items. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with AFMAN 33-363, Management of Records, and disposed of according to Air Force Records Disposition Schedule (RDS) located http://www.e-publishing.af.mil/ http://www.e-publishing.af.mil/
2 AFMAN33-282 28 MARCH 2012
in the Air Force Records Information Management System (AFRIMS). The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force.
SUMMARY OF CHANGES
This interim change revises AFMAN 33-282 by (1) eliminating the use of the Air Force
Communications Quality Control Checklists (CQCC) to perform annual COMPUSEC self-assessments, (2) mandating SHA-256 compliance, (3) adding policy pointers for the AF Internal
Basic Assurance (IBA) Certificate Policy and the Certificate Practice Statement (CPS), and (4) adding security policy on the use of Blackberry® and other DoD-approved smartphones, Bluetooth®, and commercial mobile devices (CMDs). References, Acronyms, and Terms have also been updated. A margin bar ( | ) indicates newly revised material.
Chapter 1—INTRODUCTION 5
1.1. Introduction
1.2. Applicability
1.3. Objective
Chapter 2—ROLES AND RESPONSIBILITIES 6
2.1. Secretary of the Air Force, Office of Information Dominance and Chief
Information Officer (SAF/CIO A6)
2.2. Air Education and Training Command (HQ AETC)
2.3. Designated Accrediting Authorities
2.4. Air Force Senior Information Assurance Officer (AF SIAO)
2.5. Air Force Space Command
2.6. 24th Air Force
2.7. Air Force Network Integration Center (AFNIC)
2.8. Information System Owners (ISO)
2.9. System Information Assurance Officer/Manager (IAO/IAM)
2.10. Wing Information Assurance Office (WIAO) (To become Wing Cybersecurity
Office (WCSO))
2.11. DELETED
2.12. Organizational IAO (To be called Cybersecurity Liaison)
2.13. Information System Users
AFMAN33-282 28 MARCH 2012 3
Chapter 3—COMPUSEC 7
3.1. General
3.2. Notice and Consent to Monitoring
3.3. Security Configuration Specifications
3.4. IA Community of Practice (CoP)
3.5. Information Technology Asset Procurement
3.6. COMPUSEC Methods and Procedures Technical Orders (MPTO)
3.7. Operations Security (OPSEC)
3.8. IAO Functions
3.9. Risk Management Framework (RMF) Roles
Chapter 4—INFORMATION SYSTEM ACCESS CONTROL 9
4.1. Introduction
4.2. Authorized Users
4.3. Loss of Access
Table 4.1. Network Access Suspension Matrix
4.4. Account Management
4.5. Password/PIN Management
4.6. Biometric Management
4.7. Account Auditing
Chapter 5—PUBLIC KEY INFRASTRUCTURE 19
5.1. Introduction
5.2. NIPRNET PKI
5.3. SIPRNET PKI
5.4. External PKI
5.5. Escrowed Certificates
5.6. Software Certificate Issuance and Control
5.7. Group Accounts Utilizing PKI
5.8. Key Compromise
5.9. Server Certificates
5.10. Code Signing Certificates
5.11. Certificate Reissuance Prior to Expiration
5.12. Network Authentication
4 AFMAN33-282 28 MARCH 2012
5.13. PKI Waivers
Chapter 6—END POINT SECURITY 25
6.1. Introduction
6.2. General Protection
6.3. Periods Processing
6.4. Software Security
6.5. Malicious Logic Protection
6.6. Telework
6.7. Data Encryption
6.8. Privately-Owned hardware and software
6.9. Contractor-Owned Information Systems
6.10. Foreign-Owned Information Systems
6.11. Other Service or Agency Owned Information Systems
6.12. Mobile Computing Devices
6.13. Peripheral Devices
6.14. Removable Media
6.15. Wireless Services
6.16. Collaborative Computing
6.17. Non-enterprise activated (NEA) Commercial Mobile Devices (CMD)
6.18. Enterprise activated CMD
Chapter 7—DATA SPILLAGE AND COMPUSEC INCIDENT REPORTING 40
7.1. Introduction
7.2. Data Spillage
7.3. Classified Message Incidents
7.4. Incident Response Flow
7.5. CMD Spillage
Chapter 8—REMANENCE SECURITY 42
8.1. Introduction
Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 43
AFMAN33-282 28 MARCH 2012 5
Chapter 1
INTRODUCTION
1.1. Introduction. Computer Security (COMPUSEC) is an IA discipline identified in AFI 33-
200, Information Assurance (IA) Management. Compliance ensures appropriate implementation of measures to protect all Air Force Information System (IS) resources and information.
1.1.1. The framework of the AF COMPUSEC IA program consists of a cyclic sequential security management model for risk management. This model is specific to information processed on AF computing systems and incorporates strategy, policy, awareness/training, implementation, assessment, remediation, and mitigation controls.
1.2. Applicability. This publication applies to all AF ISs and devices used to process, store, display, transmit, or protect AF information, regardless of classification or sensitivity, unless exempted in Para 1.2.3 or 1.2.4.
1.2.1. AF ISs and devices include but are not limited to: Stand-alone systems, Platform IT
(PIT) systems, IS components of systems where PIT interconnections (PITI) exist, Modeling and simulation systems/networks, ISs connected to external networks via authorized internet service providers (ISPs), ISs providing the management infrastructure, Connections/interfaces with other ISs
1.2.2. This publication is binding on all users, military, civilian and contract employees, that operate, connect, or interact with the ISs owned, maintained, and controlled by the AF.
1.2.3. More restrictive Federal, DoD, and Director of Central Intelligence Agency directive requirements governing Special Access Program information take precedence over this publication. The latest version of all publications (e.g., Federal, Joint, DoD, AF) referenced within this publication must be utilized.
1.2.4. This publication and implementation guidance identified within are not applicable to
Sensitive Compartmented Information (SCI) ISs. For SCI systems, refer to the Intelligence
Community Directive (ICD) 503, Intelligence Community Information Technology Systems
Security Risk Management, Certification and Accreditation.
1.2.5. Compliance with IA controls will be assessed, documented, and mitigated according to DoD Instruction (DoDI) 8500.2, Information Assurance (IA) Implementation, and DoDI
8510.01, DoD Information Assurance Certification and Accreditation Process (DIACAP), for inclusion in the AF IS Certification and Accreditation (C&A) package.
1.3. Objective. The objective of COMPUSEC is to ensure the employment of countermeasures to protect and secure United States (US) government information processed by AF ISs by protecting the confidentiality, integrity, availability, authentication, and non-repudiation of ISs.
6 AFMAN33-282 28 MARCH 2012
Chapter 2
ROLES AND RESPONSIBILITIES
2.1. Secretary of the Air Force, Office of Information Dominance and Chief Information
Officer (SAF/CIO A6). Develops, implements, and oversees all cybersecurity disciplines.
2.2. Air Education and Training Command (HQ AETC). Conducts and integrates IA education and training into initial military training courses, Air Force accession programs, formal schools, professional military education courses, and specialized training in Air Force Specialty
Code-awarding courses according to AFI 36-2201, Air Force Training Program, and the specific
IA education and training requirements of DoD 8570.01-M, IA Workforce Improvement
Program.
2.3. Designated Accrediting Authorities. Executes Designated Accrediting Authority (DAA) duties according to AFI 33-210 Air Force Certification and Accreditation (C&A) Program
(AFCAP). Reference AFI 33-210 for DAA appointment, assignment, delegation, training requirements, and key roles and responsibilities.
2.4. Air Force Senior Information Assurance Officer (AF SIAO). Reference AFI 33-200 and AFI 33-210 for AF SIAO assignment, roles, and responsibilities.
2.5. Air Force Space Command. Designated as the lead command for cyberspace and related subject matter experts in support of policy development for the Air Force future goal of one Air
Force Network (the AFNet).
2.6. 24th Air Force. Directs Air Force Network Defense (NetD) in accordance with AFPD 10-
7, Information Operations.
2.7. Air Force Network Integration Center (AFNIC). Designated by HQ AFSPC as the organization for IA policy subject matter expertise in support of HQ AFSPC’s future goal of one
Air Force Network (AFNet).
2.8. Information System Owners (ISO). Reference AFI 33-210 for ISO assignment, roles, and responsibilities.
2.9. System Information Assurance Officer/Manager (IAO/IAM). Reference AFI 33-200, AFI 33-210 and DoDI 8510.01 for system IAO/IAM roles and responsibilities.
2.10. Wing Information Assurance Office (WIAO) (To become Wing Cybersecurity Office
(WCSO)). Responsible for the development, implementation, oversight and maintenance of host wing cybersecurity programs.
2.11. DELETED.
2.12. Organizational IAO (To be called Cybersecurity Liaison). Conducts annual
COMPUSEC self-assessments using the COMPUSEC Self-Assessment Checklist (SAC) located in the Inspector General’s Management Internal Control Toolset (MICT).
2.13. Information System Users. Authorized IS users must comply with the guidance within
AFMAN 33-152, User Responsibilities and Guidance for Information Systems (T-1).
AFMAN33-282 28 MARCH 2012 7
Chapter 3
COMPUSEC
3.1. General. Safeguard ISs and information against sabotage, tampering, denial of service, espionage, fraud, misappropriation, misuse, or release to unauthorized persons.
3.2. Notice and Consent to Monitoring. Configure all DoD telecommunications devices according to AFI 10-712, Telecommunications Monitoring and Assessment Program (TMAP).
3.3. Security Configuration Specifications. Securely configure and implement all Information
Technology (IT) products. IA reference documents, such as National Institute of Standards and
Technology (NIST) Special Publications (SP), Defense Information Systems Agency (DISA)
Security Technical Implementation Guides (STIGs), National Security Agency (NSA) Security
Configuration Guides, AF specialized publications (AF System Security Instructions, AF
Technical Orders [TO], etc.), and other relevant publications are used for the security configuration and implementation guidance. Apply these reference documents according to AFI
33-200 and AFI 33-210 to establish and maintain a minimum baseline security configuration and posture. References to various documents are cited throughout this publication, where applicable.
3.3.1. Document all configuration requirements within this publication in the IS C&A package according to AFI 33-210.
3.3.2. Document any deviation to guidance within this publication as part of the applicable
IS C&A package. If the DAA has not been delegated the approval authority for the deviation, then the deviations must be submitted, on an AF Form 4169, through IA channels to the OPR of the governing publication prior to DAA approval.
3.4. IA Community of Practice (CoP). The AF IA CoP serves as the primary IA support resource for Wing IA officers and managers, providing a collaborative one-stop-shop for IA ideas, questions, discussions, and hosts dynamic web content for information sharing
(https://afkm.wpafb.af.mil/community/views/home.aspx?Filter=OO-SC-IA-01).
3.5. Information Technology Asset Procurement. All IT hardware, firmware, and software components or products incorporated into DoD ISs must comply with evaluation and validation requirements in DoDI 8500.01, Cybersecurity (T-0).
3.5.1. Procurement activities of all IT hardware, cellular, and peripheral devices (e.g., desktops, laptops, servers, BlackBerry® devices, cell phones, printers, scanners, and
Bluetooth® peripheral devices) must follow the guidance in AFMAN 33-153, Information
Technology Asset Management, and the AF Information Technology Commodity Council
(ITCC) guidance available on the AF Portal.
3.6. COMPUSEC Methods and Procedures Technical Orders (MPTO). MPTOs present procedural guidance to the IA workforce to implement and manage methods and processes pertaining to COMPUSEC directed by this policy.
3.6.1. This publication directs the use of the implementation guidance and procedures as identified in the MPTOs for the COMPUSEC program.
3.6.2. Obtain MPTOs via your organizational Technical Order Distribution Account
(TODA).
https://afkm.wpafb.af.mil/community/views/home.aspx?Filter=OO-SC-IA-01
8 AFMAN33-282 28 MARCH 2012
3.7. Operations Security (OPSEC). Follow OPSEC measures according to AFI 10-701, Operations Security (OPSEC), when using IT assets. OPSEC training and guidance can be obtained from the Installation OPSEC Program Manager or Signature Management Officer.
3.8. IAO Functions. Within this publication where both organizational and system IAO functions overlap, the “IAO” term is all inclusive. In all other specific situations, the terms
“organizational” or “system” will be indicated. Furthermore, the new term for organizational
IAO will become “Cybersecurity Liaison” in the rewrite of AFI 33-200. The term
“cybersecurity” has replaced the term “information assurance” in future policy updates and rewrites.
3.9. Risk Management Framework (RMF) Roles. With the publishing of DoDI 8510.01, RMF, many role designations have been replaced with new terminology. Designated
Accrediting Authority (DAA) has been replaced with Authorizing Official (AO); Information
Assurance Manager (IAM) has been replaced with Information System Security Manager
(ISSM); System Information Assurance Officer (IAO) has been replaced with Information
System Security Officer (ISSO); the AF Senior Information Assurance Officer (SIAO) has been replaced with the AF Senior Information Security Officer (SISO). Future policy rewrites will change the old terms to match DODI 8510.01.
AFMAN33-282 28 MARCH 2012 9
Chapter 4
INFORMATION SYSTEM ACCESS CONTROL
4.1. Introduction. Every individual who has access to the Non-Classified Internet Protocol
Router Network (NIPRNET) or Secret Internet Protocol Router Network (SIPRNET), standalone systems, specialized ISs, and/or mission systems is an IS user.
4.1.1. Access to AF ISs is a revocable privilege and will be granted to individuals based on need-to-know and according to DoDI 8500.2, Information Assurance (IA) Implementation;
NSTISSP No. 200, National Policy on Controlled Access Protection; DoD 5200.2-R, Personnel Security Program; and Chairman of the Joint Chiefs of Staff Instruction (CJCSI)
6510.01, Information Assurance (IA) and Support to Computer Network Defense (CND).
4.2. Authorized Users. Authorized user account creation and administration must be configured with role-based access schemes according to system policy requirements in DoDI
8500.2.
4.2.1. All authorized users (e.g., military, civilian, contractor, temporary employees, volunteers, interns, key spouses, and American Red Cross personnel) complete DoD IA training prior to being granted access to an IS. IA training will be re-accomplished annually by the user and compliance maintained by the IAO according to DoD 8570.01-M.
4.2.1.1. DoD IA training is located on Advanced Distributed Learning System (ADLS) accessible via the AF Portal. A publically accessible version of the DoD IA training is located on the Information Assurance Support Environment (IASE) website
(http://iase.disa.mil/eta/ProductDownload/awareness_download.html).
4.2.1.2. When a user requires a new/modification to his/her account (due to change of station or assignment, Temporary Duty [TDY], etc.), the gaining IAO will verify the user meets access requirements before granting access to the IS. Users are not required to retake the DoD IA training provided the user has a valid and current (within a year) course completion record. In emergency or deployment situations, the IAO may rely on a training record review or ADLS to validate course completion.
4.2.2. For IS access, the IAO ensures the DD Form 2875, System Authorization Access
Request (SAAR), is completed and signed. Document access requests, DoD IA training completion, and justification for access and clearance/background investigation verification as referenced by DoD 5200.2-R and AFI 31-501, Personnel Security Program. DD Form
2875 signatures can be “wet” or digitally signed.
4.2.2.1. All authorized IS (to include Mobile Computing Devices) users will sign the standardized AF Form 4394, Air Force User Agreement Statement-Notice and Consent
Provision (See AFI 33-100, to become AFMAN 33-152) prior to initial IS access. See paragraph 6.12 for wireless mobile device requirements.
4.2.2.2. Access to classified ISs also requires a Standard Form 312, Nondisclosure
Agreement, according to AFI 31-401, Information Security Program Management.
4.2.2.3. IAOs, in coordination with the organizational security manager, verify user background investigation requirements according to DoD 5200.2-R.
http://iase.disa.mil/eta/ProductDownload/awareness_download.html
10 AFMAN33-282 28 MARCH 2012
4.2.3. A user must obtain an approved hardware token according to current processes prior to obtaining NIPRNET (and SIPRNET when tokens are available) access.
4.2.3.1. The locally appointed Contractor Verification System (CVS) Trusted Agent
(TA) individual (e.g. organizational security manager) verifies contractor access against a valid contract in the CVS before approving the request for a contractor to be issued a
Common Access Card (CAC).
4.2.4. The ISO ensures methods are in place to verify user access requests before granting IS access.
4.2.5. All user accounts are created using applicable TOs published by the 24 AF (e.g.
MPTO 00-33D-2001, Active Directory Naming Conventions).
4.2.6. Privileged User. A privileged user is an authorized user who has access to IS control, monitoring, or administration functions. Grant privileged access to unclassified and classified
ISs based on the assigned duties and the position categories identified in DoDI 8500.2:
Category IT-I (Privileged) and Category IT-II (Limited Privileged).
4.2.6.1. Privileged users must meet all the requirements of an authorized user as specified in paragraphs 4.2.1 – 4.2.3.
4.2.6.2. Privileged users are established and administered with a role-based access scheme according to the system policy and DoDI 8500.2.
4.2.6.3. System access requires Public Key Infrastructure (PKI) access methods as specified in Chapter 5, Public Key Infrastructure.
4.2.6.4. Privileged users access only data, control information, software, hardware, and firmware that they are authorized access and still have a requirement for “need to know.”
4.2.6.5. To maintain separation of duties and least privilege, users maintain separate accounts, a user account for day-to-day or “non-privileged” functions, and a privileged account for administrative functions according DoD 8570.01-M and DoDI 8500.2.
4.2.6.6. The system IAM tracks and maintains visibility over all privileged users according to AFI 33-200 and DoDI 8500.2.
4.2.6.7. Prohibit sharing of privileged user accounts between users.
4.2.6.8. Configure privileged user remote access according to the DISA Enclave STIG.
4.2.6.9. Privileged users must be position-certified according to DoD 8570.01-M and qualified according to AFMAN 33-285, Information Assurance (IA) Workforce
Improvement Program.
4.2.6.10. Privileged users must complete a Privileged Access Agreement according to
DoD 8570.01-M.
4.2.7. Foreign Nationals/Local Nationals. A Foreign National/Local National (FN/LN) user is anyone who is not a US citizen or permanent resident, according to Title 8, Code of
Federal Regulations, “Aliens and Nationality.” Before authorizing FN/LN access to unclassified and/or classified ISs, the ISO ensures compliance with the IS access requirements in paragraphs 4.2.1-4.2.3 and the following constraints:
AFMAN33-282 28 MARCH 2012 11
4.2.7.1. Constraints. MAJCOM Foreign Disclosure Office (FDO) determines authorized and privileged need-to-know for the administrative access and control of information, software, hardware and firmware to include controlled unclassified information (CUI) and classified information, in accordance with DoD Manual (DODM) 5200.01, Volume
4, Controlled Unclassified Information (CUI).
4.2.7.1.1. Base or Wing IA offices must consult the Host or MAJCOM FDO before authorizing access by FN/LN users to ISs processing, storing, or transmitting classified and controlled unclassified information. Note: Specific FN/LN access guidance can be found in the following publications: AFI 16-107, Military Personnel
Exchange Program; AFI 16-201, Air Force Foreign Disclosure and Technology
Transfer Program; DoDD 5230.25, Withholding of Unclassified Technical Data from
Public Disclosure; DoDD 5400.7, DoD Freedom of Information Act (FOIA)
Program; DoD 5400.7-R_AFMAN 33-302, Freedom of Information Act Program;
AFI 33-332, Air Force Privacy Program; DoDD 5230.11, Disclosure of Classified
Military Information to Foreign Governments and International Organizations; and
DoDD 5230.20, Visits and Assignments of Foreign Nationals.
4.2.7.2. Administrative Controls. Establish a process between ISOs, system IAMs, and the applicable MAJCOM FDO to determine classified or unclassified access. Direct conflicts in FN/LN access requirements to the MAJCOM FDO for resolution.
4.2.7.2.1. Base or Wing IA offices maintain a list of FN/LN users from each subordinate organization within their assigned organizations. Provide specific documentation indicating FN/LN usage to the system IAM for inclusion in the IS
C&A.
4.2.7.2.2. The IAO tracks and maintains visibility over all FN/LN billets assigned to an IS and/or organization.
4.2.7.2.3. Restrict FN/LN IS user access to IT levels defined in DoDI 8500.2.
4.2.7.2.4. If privileged access is required to an IS, FN/LN user access must be restricted to IT II-level positions only and directly supervised by a U.S. Citizen according to DoDI 8500.2 and CJCSI 6510.01. Furthermore, document access in the
IS C&A package. Pursuant to applicable host-nation agreements, FN/LN privileged users must be baseline computing environment (CE) certified according to DoD
8570.01-M.
4.2.7.3. IS Controls. System IAMs in coordination with privileged users ensure that applicable IA technical safeguards and controls are established and maintained according to CJCSI 6510.01 and DoDI 8500.02.
4.2.7.3.1. Prohibit unlimited FN/LN access to “.mil” websites until specific host
FDO and the MAJCOM FDO approval is accomplished.
4.2.7.3.2. ISOs direct privileged users to setup permissions on ISs that allow for
FN/LN account management in accordance with this publication.
4.2.7.3.3. Establish proper messaging naming conventions (e.g., <john.smith.uk@af.mil>) of FNs as non-US citizens according to CJCSI 6510.01.
mailto:john.smith.uk@af.mil
12 AFMAN33-282 28 MARCH 2012
4.2.7.3.4. At the discretion of the ISO, system access requires PKI access methods as specified in Chapter 5, Public Key Infrastructure. See paragraph 4.2.6.3 MAJCOMs handle token requirements according to host nation agreements.
4.2.7.3.5. IAOs validate implementation of appropriate safeguards (e.g. PKI, email accounts). Employ safeguards that adhere to DoD, Joint, and AF, and if applicable, locally created information security publications.
4.2.7.3.6. Sanitize or configure classified ISs to restrict access by FN/LNs to only classified information authorized for disclosure to the FN/LNs government or coalition, as necessary to fulfill the terms of their assignments according to applicable host MAJCOM FDO requirements.
4.2.7.3.7. For SIPRNET RELEASABLE (SIPR REL) IS specific configuration requirements, follow guidance in the DISA Embedded REL User Enclave Technical
Implementation Instruction (TII)
(http://iase.disa.mil/stigs/net_perimeter/enclave_dmzs/rel.html).
4.2.7.3.8. SIPR REL users do not need FDO approval to access .mil sites. DISA controls website access at the REL DMZ proxy.
4.2.7.4. Other Considerations. Non-US citizens who are permanent legal residents and/or full time permanent employees of the DoD meet the requirements of any US citizen for access to the unclassified network or system.
4.2.8. Grant only unclassified IS access to temporary employees and volunteer personnel in support of their assigned duties.
4.2.8.1. A volunteer is any individual authorized to be DoD volunteers as defined in
DoDI 1100.21, Voluntary Services in the Department of Defense. Restrict volunteers to
IT-III level positions.
4.2.8.2. Temporary employees and volunteers (including key spouses) must meet the requirements as specified in paragraphs 4.2.1 through 4.2.3.
4.2.8.3. Temporary employees and volunteers require PKI access at the discretion of the
ISO and according to IS requirements as outlined in Chapter 5, Public Key
Infrastructure. See paragraph 4.2.6.3
4.2.8.3.1. Eligible volunteers should contact their CVS TA to get their Volunteer
Logical Access Credential (VoLAC).
4.2.8.3.2. The VoLAC is used for logical access (network) and is replacing the
Alternative Token for volunteers.
4.2.9. Public users that access an IS intermittently (i.e. vendors, morale support, technical support, etc.) have only non-privileged access.
4.2.9.1. The system ISO ensures adherence to applicable DISA STIGs (e.g., Web Server
STIG) for private/public IS separation.
4.2.10. All IS users have the responsibility to report suspected inappropriate use, both by authorized and unauthorized personnel, to supervisory chain of command, security manager, organizational IAO, or commander.
http://iase.disa.mil/stigs/net_perimeter/enclave_dmzs/rel.html
AFMAN33-282 28 MARCH 2012 13
4.3. Loss of Access. Access to an AF IS is a privilege and continued access is contingent on personnel actions, changes in need to know, or operational necessity (see AFI 33-100, to become
AFMAN 33-152).
4.3.1. Specific procedural information for account disabling is located in MPTO 00-33B-
5004, Access Control for Information Systems.
4.3.2. Failure to maintain DoD IA training results in immediate suspension of access to unclassified and classified ISs.
4.3.3. Unintentional and/or intentional actions that threaten or damage AF ISs will result in immediate suspension of access to unclassified and classified ISs according to CJCSI
6510.01.
4.3.3.1. According to CJCSI 6510.01, suspend access to classified ISs if the user’s security clearance is suspended, denied, or revoked. If an individual’s clearance is suspended, denied, or revoked, the ISO coordinates with the organization commander and determines if unclassified network access can be maintained according to paragraph
4.3.3.3.
4.3.3.2. The IAO notifies the ISO and/or the organizational commander upon discovery or notification of user activity that is inconsistent with the terms of DoD IA training or inconsistent with approved IS security usage.
4.3.3.3. At the direction of the organizational commander, the IAO suspends user access and the ISO provides reason for the suspension. The ISO identifies requirements required for account reinstatement (at a minimum, DoD IA remedial training, MAJCOM required, or USCYBERCOM CTO-directed requirements). Upon satisfactorily completing retraining and any other requirements, the IAO, on behalf of the ISO and/or organizational commander initiates reinstatement.
4.3.3.4. The ISO reviews all pertinent documentation relating to the justification for the suspension, the risk to the network, and operational requirements. The organizational commander makes a determination as to whether or not to suspend the individual's network access. See Table 4.1, Network Access Suspension Matrix, as guidance for when an individual’s security clearance is suspended, denied, or revoked, for whatever reason.
4.3.4. If the user disputes IS access suspension, follow local command level legal guidance.
Table 4.1. Network Access Suspension Matrix.
R U
L E
A B C
If the system is and the clearance is then
1 Classified
Suspended, denied, or revoked
The individual’s access is immediately suspended.
See AFI 31-501, Personnel Security Program
Management, and CJCSI 6510.01
2 Unclassified Denied or revoked
The IAO will immediately suspend the individual’s access
3 Unclassified Suspended Organizational commanders may make a
14 AFMAN33-282 28 MARCH 2012
recommendation for access reinstatement based on the circumstances surrounding the suspension, threat to the network, and operational requirements
Unclassified with privileged access
Suspended, denied, or revoked
Suspend privileged access immediately.
Organizational commanders may make a recommendation for user access suspension depending on the circumstances surrounding the suspension and operational requirements
4.4. Account Management. AF direction is to use PKI-based access control according to DoDI
8520.03, Identity Authentication for Information Systems and the USCYBERCOM, Public Key
Infrastructure (PKI) Implementation Communications Tasking Order (CTO) 07-015
(https://www.cybercom.mil/J3/orders/default.aspx) for unclassified systems. See Chapter 5, Public Key Infrastructure.
4.4.1. IAO Account Actions. Specific procedural information is located in MPTO 00-33B-
5004, IAOs/IAMs will:
4.4.1.1. Maintain the group account configurations according to the IS C&A documentation and according to DoDI 8500.2.
4.4.1.2. Ensure assignment of individual accounts to privileged users. Group or shared accounts do not support nonrepudiation and least-privilege access controls.
4.4.1.3. Notify privileged users to de-provision all user accounts from an IS whenever the user no longer requires access to the IS within 24 hours of notification (e.g., whenever the user is permanently transferred to another location, termination of employment, retirement).
4.4.1.4. Substitute reusable IS user accounts on systems with frequent user-turnover
(e.g., students, temporary employees, exercise accounts). For specific procedures, see
MPTO 00-33B-5004, Chapter 3.
4.4.1.5. Develop local procedures in coordination with privileged users to log off users manually if automatic log off functions are not technically feasible (e.g., SIPRNET clients, non-Windows based).
4.4.1.6. Develop notification procedures for de-provisioning IS user accounts when an employee (e.g., military, civilian, or contractor) transfers, retires, separates, or is terminated, or for any other loss of IS access.
4.4.1.7. Perform annual audit of user accounts to verify permissions/least privilege and ensure that de-provisioning of accounts has taken place according to DoDI 8500.2.
4.4.2. Privileged User Account Actions. Specific procedural information is located in TO
00-33A-1202, Air Force Network Account Management. Privileged users will:
4.4.2.1. Configure all individual IS accounts with a unique identifier. For group or shared accounts see paragraph 5.7 for group accounts with PKI.
4.4.2.2. Permit group accounts only for reasons of operational necessity on unclassified and classified systems and networks as determined by the organizational commander, https://www.cybercom.mil/J3/orders/default.aspx
AFMAN33-282 28 MARCH 2012 15
reviewed by the system IAM, approved by the ISO, and fully documented in the C&A package.
4.4.2.3. Associate each IS user identity with all auditable actions supporting nonrepudiation and accountability according to DoDI 8500.2.
4.4.2.4. Incorporate electronic or paper tracking and reviewing methods to match individual users to generic usernames (e.g., user log sheet) every 30 days.
4.4.2.4.1. Per direction of the IAO/IAM, disable user accounts once the users no longer require access (e.g., permanent change of station, separation, class graduation).
4.4.2.5. Configure account lockout parameters according to the USCYBERCOM Public
Key Infrastructure (PKI) Implementation CTO 07-015 and CJCSI 6510.01.
4.4.2.6. Configure automatic log off functions due to user inactivity according to the minimum standards identified in according to DoDI 8500.2 and the applicable DISA
OS/Database STIGs.
4.4.2.7. Configure and implement automated IS controls to check and disable IS user accounts that have been dormant more than 30 days according to CJCSI 6510.01. AF
CIO Exception: Disable National Guard and Reserve member IS user accounts only after
90 days of inactivity.
4.4.2.7.1. If an approved hardware token is used as the only IS’s account authentication method, user account access expires when the approved hardware token expires according to CJCSI 6510.01.
4.4.2.7.2. For PK-enabled ISs using Personal Identification Numbers (PINs), disable or limit pin caching features according to the applicable DISA OS (e.g., Windows) and DISA Access Control STIGs.
4.4.2.8. Delete unnecessary (to include service accounts) and/or default accounts and change all factory default or user-generated passwords included in a newly acquired system (software or hardware) according to the configuration information in the IS C&A package before allowing any user access to the system.
4.4.2.8.1. Rename default accounts that cannot be deleted, according to applicable
DISA STIGs.
4.4.2.8.2. Do not execute root-level access in IS applications.
4.4.2.9. Disable user accounts (do not delete) when users are unable to remotely access their accounts due to an extended absence or when a user is suspended from work, IS access is revoked for any reason, or the security clearance is suspended as specified in paragraph 4.3.
4.4.2.10. Before unlocking the user account, a validated mechanism must be in place to validate the user’s identity with the IAO (e.g., in-person identification, digitally signed email).
4.5. Password/PIN Management. ISs must follow PKI requirements in USCYBERCOM
Public Key Infrastructure (PKI) Implementation CTO 07-015 and Chapter 5, Public Key
Infrastructure as an authentication means to the NIPRNET.
16 AFMAN33-282 28 MARCH 2012
4.5.1. Specific procedural information for password management is located in MPTO 00-
33B-5004, Chapter 4.
4.5.2. According to DoDI 8520.02,, Public Key Infrastructure (PKI) and Public Key (PK)
Enabling, and the DISA STIG, Access Control in Support of Information Systems, all DoD networks required by DoDD 8500.1 to authenticate users will perform this authentication using certificates issued by DoD-approved PKI on hardware tokens. The CAC is the primary hardware token, but there are special instances where the CAC cannot be used to perform various missions. To accommodate these various missions, the DoD CIO has approved the use of the Alternate Login Token (ALT). See Chapter 5, Public Key Infrastructure.
4.5.3. In addition to the AF-specific password guidance contained within this publication, configure IS password authentication according to the DISA Access Control STIG. DISA
STIG and/or USCYBERCOM Tasking Order (TO) password requirements take precedence only if more restrictive than guidance in this publication.
4.5.4. The ISO and system IAM will ensure where passwords are used for access to AF-GIG restricted assets (i.e., networks, workstations, or applications), at a minimum, passwords are created and changed in accordance with current USCYBERCOM CTOs and CJCSI 6510.01.
4.5.4.1. Meet the minimum complexity requirements as specified in the applicable DISA
STIGs and MPTO 00-33B-5004. See CTO 07-015 for additional guidance.
4.5.4.2. One-time password generators or hardware token implementation must follow the guidance provided in the DISA STIG, Access Control in Support of Information
Systems,.
4.5.4.3. ISO and system IAM will establish a frequency based on mission, operational needs or IS technical feasibility if not able to meet this requirement (e.g., AF Reserve
Components).
4.5.5. Protect all passwords and PINs based on the sensitivity of the information or critical operations they protect (e.g., a password used to gain access to a SECRET network is itself classified SECRET).
4.5.5.1. Classify passwords and PINs at the highest level of information processed on that system. As a minimum, safeguard passwords as “For Official Use Only” (FOUO).
See Appendix 3 of DoD Regulation 5200.1-R, Information Security Program, for an explanation of FOUO.
4.5.5.2. If necessary for mission accomplishment (i.e., pre-established accounts for contingency or exercise), place the password in a properly marked, sealed envelope or
Standard Form 700, Security Container Information Form, and store in a General
Services Administration (GSA)-approved container as specified in the DISA Access
Control STIG.
4.5.6. The ISO and system IAM ensure compliance with DoDI 8500.2 for shared/group passwords and PINs and obtain approval by the DAA according to CJCSI 6510.01.
Implement system and physical auditing procedures in conjunction with these methods to support non-repudiation and accountability.
4.5.6.1. Consider unauthorized sharing of passwords a security incident according to
CJCSI 6510.01. See Chapter 7, Data Spillage and COMPUSEC Incident Reporting.
AFMAN33-282 28 MARCH 2012 17
4.5.7. In the event of a compromised password or PIN, the ISO and system IAM ensures procedures are in place to implement immediate password and PIN change activities. The
IAO follows established reporting and investigation procedures according to AFI 33-138, Enterprise Network Operations Notification and Tracking (to become AFI 33-115, AF GIG
Services). If the PIN is the access code to an approved PKI token, the compromise of the PIN warrants probable compromise of the certificates. See paragraph 5.8
4.5.8. Protect all passwords and PINs during transmission using Federal Information
Processing Standards (FIPS)-approved encryption according to DoDI 8500.2. If not technically feasible, require the use of a one-time password to access the IS.
4.5.9. Privileged users will incorporate electronic or paper tracking methods to account for user activity when using shared passwords. Shared passwords will meet all requirements as specified in this publication.
4.5.10. Institute automated procedures to reject rapid retries when entering a password incorrectly.
4.5.11. The ISO will ensure the establishment of procedures for manual or automatic password changes by users. The IS will require users to change the one time password at initial logon according to DoDI 8500.2.
4.5.11.1. Configure IS user accounts to enforce password history in accordance with applicable DISA STIG. If ISs cannot support STIG requirements, configure to maximum and document in C&A package.
4.5.11.2. IS privileged users implement policies enforcing a minimum seven-day wait before a user may optionally change the password.
4.5.12. Upon a suspected or confirmed compromised or “cracked” password and/or PIN, the
IAO must immediately take measures to lock down the account in question.
4.5.13. Configure password cracking tools and procedures according to DoDI 8500.2. See
MPTO 00-33B-5004 for password cracking specific guidance.
4.6. Biometric Management. The definition of biometrics is a measurable biological
(anatomical and physiological) and behavioral characteristic used for automated recognition. As a process, biometrics is an automated method of recognizing an individual based on measurable biological (anatomical and physiological) and behavioral characteristics.
4.6.1. Biometrics is an important AF operational enabler that will be fully integrated to conduct the AF mission in support of joint military operations according to DoDD 8521.01E, Department of Defense Biometrics.
4.6.1.1. Design biometrics programs to improve the effectiveness and efficiency of biometrics activities throughout the AF by eliminating duplication and overlap of technology development and information management efforts.
4.6.1.2. Configure biometric programs according to the DISA Biometrics Security
Checklist (http://iase.disa.mil/stigs/checklist/).
4.6.2. At the discretion of the installation commander, the collection and use of biometrics may occur at any time when a person requests or requires access to systems, facilities, and http://iase.disa.mil/stigs/checklist
18 AFMAN33-282 28 MARCH 2012
networks under the responsibility of the AF or according to host nation and Status of Forces
Agreement (SOFA) agreements.
4.6.3. All biometrics activities shall be coordinated via the sponsoring AF functional organization through the Biometrics Identity Management Agency (BIMA) at http://www.biometrics.dod.mil/ and approved by DoD Biometrics Executive Committee
(EXCOM) before acquisition.
4.6.4. When used, biometrics will be collected, matched, transmitted, stored, shared, archived, and received according to AF procedures for each group as defined by the National
Science and Technology Council Subcommittee on Biometrics Glossary; AFI 63-101, Acquisition and Sustainment Life Cycle Management; and AFI 33-332.
4.6.5. In accordance with Office of the DoD CIO disposition definitions, biometrics fall into two groups governing storage and retention.
4.6.5.1. Group 1 consists of military, government civilians, and military dependents;
indefinite storage and retention apply.
4.6.5.2. Group 2 consists of contractors, visitors, and temporary workers; disposition of biometric data occurs at the end of the access period.
4.6.6. All biometrics data and associated information collected as a result of DoD operations or activities will be maintained or controlled by the Department of Defense, unless otherwise specified by BIMA for DoD Biometrics at a later date.
4.7. Account Auditing.
4.7.1. IS auditing events will be configured according to CJCSI 6510.01 and the applicable
DISA STIGs (application, operating system, database, etc).
4.7.1.1. Privileged users must ensure the IS audit trail function is enabled for accounts.
Only privileged users have access to the audit trail file.
4.7.2. The audit trail must not contain unencrypted (clear text) passwords, incorrectly entered passwords, or character strings, as this could expose the password of a legitimate user.
4.7.3. All audit records must be maintained according to AFRIMS, Records Distribution
System (RDS), Table 33-25, Rule 8
(https://www.my.af.mil/afrims/afrims/afrims/rds/rds_series.cfm).
http://www.biometrics.dod.mil/ https://www.my.af.mil/afrims/afrims/afrims/rds/rds_series.cfm
AFMAN33-282 28 MARCH 2012 19
Chapter 5
PUBLIC KEY INFRASTRUCTURE
5.1. Introduction. The DoD and the Committee on National Security Systems (CNSS) PKIs use asymmetric cryptography to identify and authenticate users to systems and networks for the
NIPPRNET and SIPRNET. PKI hardware tokens provides two-factor authentication for access to DoD and AF ISs and networks for both NIPRNET and SIPRNET. Two-factor authentication is a combination of something the user has and something the user knows.
5.2. NIPRNET PKI. The most commonly used unclassified PKI hardware token or smart card is the CAC. On AF installations, the Air Force Military Personnel Flight (MPF) issues the CAC.
On non-AF locations, any Real-time Automated Personnel Identification System (RAPIDS) issues CACs.
5.2.1. The CAC is the primary hardware token for identifying individuals for logical access to NIPRNET assets and physical access to DoD facilities according to Directive-Type
Memorandum (DTM) 08-003, Next Generation Common Access Card (CAC)
Implementation Guidance (to be incorporated into DoD Manual 1000.13-M Volume 1).
5.2.2. Air Force Personnel Center (AFPC) manages the issuance of CACs through Defense
Enrollment Eligibility Reporting System/Real-Time Automated Personal Identification
System (DEERS/RAPIDS).
5.2.2.1. According to AFI 36-3026 IP. Volume 1, Identification (ID) Cards for Members of the Uniformed Services, Their Eligible Family Members, and Other Eligible
Personnel, authorized users are issued PKI certificates on the CAC.
5.2.3. The CAC provides a cryptographic certificate-based logon identity that is valid until expiration of the CAC (not to exceed three years).
5.2.4. Personal Identity Verification (PIV) Authentication certificates can be utilized on
CAC’s to logon to additional accounts in the domain/AF GIG. See TO 31S5-4-7255-8-1, Configuration and Operations Guide for Air Force Certificate-Based Smart Card
Logon/Next Generation Using Personnal Identity Verification (PIV) Certificate for further information on implementing this capability.
5.2.5. DoD PIV Authentication certificates can be utilized on CAC’s for smart card logon to multiple accounts in the domain/AF GIG. See TO 31S5-4-7256-8-1, Configuration and
Operations Guide for Air Force Certificate-Based Smart Card Logon / Next Generation
Using Alternate Security Identification (ALTSECID) for further information on implementing this capability.
5.2.6. The ALT is an unclassified PKI hardware token or smart card containing a computer chip with a certificate issued by the AF PKI Registration Authority (RA). Use of an ALT with DoD PKI certificates is authorized for specific cases when certificates issued on the
CAC cannot be used by various groups of network users.
5.2.6.1. The ALT standard operating procedure defines use categories. Standard operating procedures are available on the AF PKI System Program Office (SPO) site https://afpki.lackland.af.mil.
https://afpki.lackland.af.mil/
20 AFMAN33-282 28 MARCH 2012
5.2.7. The VoLAC is an unclassified PKI hardware token or smart card used for volunteers and issued by MPF for network access only. Request a VoLAC through the organization
CVS TA.
5.2.8. All NIPRNet Systems are required to be SHA-256 compliant NLT 31March 2015.
(T-1) Program managers should follow FIPS 180-4, Secure Hash Standard, FIPS 140-2, and the validation lists available through the NIST Cryptographic Module Validation Program
(CMVP) and the Cryptographic Algorithm Validation Program (CAVP) sites at…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .