afman33-282.pdf

PDF 577 KB Posted

Attached to
Facilitate Other Maintenance Federal contract opportunity
Solicitation number
FA8224-16-R-0021
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

About this file

afman33-282

View the file

Other files for this federal contract opportunity

Other files attached to Facilitate Other Maintenance, newest first.
File Type Posted
PWS_AMXG_FOM_27_Apr_16.docx DOCX document
FA8224-16-R-0021-0003.pdf PDF
FA8224-16-R-0021-02.doc DOC document
FOM_Answers_(3).docx DOCX document
PWS_AMXG_FOM_17_Mar_16.docx DOCX document
FOM_Answers.docx DOCX document
afi33-115.pdf PDF
afi32-7086.pdf PDF
afi21-102.pdf PDF
FA8224-16-R-0021-01.doc DOC document
AMXGOI 21-12.pdf PDF
afi23-101.pdf PDF
afi21-101_afmcsup_oo-alcsup.pdf PDF
afman33-152.pdf PDF
afi21-102_afmcsup.pdf PDF
AFI31-101.pdf PDF
afh23-123v1.pdf PDF
afscman21-102.pdf PDF
afi32-7086_hillafbsup_i.pdf PDF
afpd24-3.pdf PDF
afi33-200.pdf PDF
AMXGOI 21-7.pdf PDF
FOM_Answers_(2).docx DOCX document
afi31-501_afmcsup_i.pdf PDF
afman23-122.pdf PDF
AMXGOI 24-5.pdf PDF
afi10-701.pdf PDF
CDRL_A002_Quality_System_Plan.pdf PDF
FA8224-16-R-0021.doc DOC document
CDRL_A005_Management_Plan.pdf PDF
CDRL_A003_Safety_Program_Plan(SSPP).pdf PDF
CDRL_A004_Accident_Report.pdf PDF
PWS_AMXG_FOM_17_Feb_16.docx DOCX document
CDRL_A001_Status_Report.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF THE AIR FORCE

WASHINGTON, DC

OFFICE OF THE SECRETARY

AFMAN33-282_AFGM2015-01

19 March 2015

MEMORANDUM FOR DISTRIBUTION C

MAJCOMs/FOAs/DRUs

FROM: SAF/CIO A6

1800 Air Force Pentagon Washington DC 20330-1720

SUBJECT: Air Force Guidance Memorandum to AFMAN 33-282, Computer Security (COMPUSEC), 28 March 2012, Incorporating Change 1, 15 January 2015

By Order of the Secretary of the Air Force, this Air Force Guidance Memorandum immediately changes AFMAN 33-282, COMPUSEC. Compliance with this Memorandum is mandatory. To the extent its directions are inconsistent with other Air Force publications; the information herein prevails, in accordance with AFI 33-360, Publications and Forms Management.

Enterprise activated Commercial Mobile Devices (CMDs) in the Air Force are government-issued smart phones and tablets IAW DoD Commercial Mobile Device Interim Policy, 17 Jan 2012 and DoD Commercial Mobile Device Implementation Plan, 15 February 2013. The following policy is added to AFMAN 33-282, paragraph 6.18 clarifying Enterprise Activated CMD use in the Air Force:

6.18.1. Air Force organizations using Defense Enterprise Email (DEE).

6.18.1.1. CMDs must use DoD Enterprise Mobility (DEM) solutions (T-0).

6.18.1.2. CMDs must be purchased utilizing the Network Enterprise Technology Command Blanket Purchase Agreement (BPA) and be on the DISA Approved Products List (T-0).

6.18.1.3. CMDs must be managed by DISA’s approved Mobile Device Management (MDM), Mobile Content Management (MCM) or Mobile Application Management (MAM) system (T-0).

6.18.2. Air Force organizations not using DEE.

6.18.2.1. CMDs must use Air Force Enterprise Mobility Solutions (T-1).

6.18.2.2. CMDs must be purchased utilizing the Network Enterprise Technology Command Blanket Purchase Agreement (BPA) and be on the Air Force Approved Products List (T-0).

6.18.2.3. CMDs must be managed by an AF-approved MDM, MCM, or MAM system (T-1).

Customers requiring other new IT services, to include Non-enterprise Activated CMDs, (see para. 6.17 of this manual) or with questions regarding procedures for non-program office fielded systems may forward requirements/questions to HQ AFSPC/A2/3/6 A6CI, Network/Infrastructure Branch, a6.wf@us.af.mil or via memorandum (see AFI 33-115, para 4.10.3.1).

Questions regarding this policy may be forwarded to the SAF/CIO A6SS Strategy and Policy Division, usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil. This memorandum becomes void after one year has elapsed from the date of this memorandum, or upon publication of an Interim Change or rewrite of AFMAN 33-282, whichever is earlier.

WILLIAM J. BENDER, Lt Gen, USAF Chief, Information Dominance and Chief Information Officer mailto:usaf.pentagon.saf-cio-a6.mbx.a3cs-a6cs-strategy-and-policy@mail.mil

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE MANUAL 33-282

28 MARCH 2012

Incorporating Change 1, 15 January 2015

Communications and Information

COMPUTER SECURITY (COMPUSEC)

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available on the e-Publishing website at www.e-publishing.af.mil for downloading or ordering.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/A6OI

Supersedes: AFSSI 8502, 18 September 2008;

AFSSI 8520, 18 June 2009;

AFSSI 8522, 9 June 2008; and

AFSSI 8580, 17 November 2008

Certified by: SAF/A6O

(Mr. Kenneth Brodie)

Pages: 62

This Air Force Manual (AFMAN) implements Computer Security in support of Air Force Policy

Directive (AFPD) 33-2, Information Assurance (IA) Program and Air Force Instruction (AFI)

33-200, Information Assurance (IA) Management. Computer Security (COMPUSEC) is defined within the Information Assurance (IA) portion of AFI 33-200. This publication applies to Air

Force military, civilian and contractor personnel under contract to the Department of Defense

(DoD), who manage COMPUSEC for Air Force organizations. This publication applies to the

Air National Guard and Air Force Reserve Command. Additional instructions and manuals are listed on the Air Force Publishing Website at http://www.e-publishing.af.mil under Electronics

Publications. Direct questions, recommended changes, or conflicts to this publication, through command channels using AF Form 847, Recommendation for Change of Publication, to

SAF/CIO A6SS. Unless otherwise noted, the SAF/CIO A6 is the waivering authority to policies contained in this publication. The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See AFI 33-360, Publications and Forms Management, Table 1.1 for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the Publication

OPR for non-tiered compliance items. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with AFMAN 33-363, Management of Records, and disposed of according to Air Force Records Disposition Schedule (RDS) located http://www.e-publishing.af.mil/ http://www.e-publishing.af.mil/

2 AFMAN33-282 28 MARCH 2012

in the Air Force Records Information Management System (AFRIMS). The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the Air Force.

SUMMARY OF CHANGES

This interim change revises AFMAN 33-282 by (1) eliminating the use of the Air Force

Communications Quality Control Checklists (CQCC) to perform annual COMPUSEC self-assessments, (2) mandating SHA-256 compliance, (3) adding policy pointers for the AF Internal

Basic Assurance (IBA) Certificate Policy and the Certificate Practice Statement (CPS), and (4) adding security policy on the use of Blackberry® and other DoD-approved smartphones, Bluetooth®, and commercial mobile devices (CMDs). References, Acronyms, and Terms have also been updated. A margin bar ( | ) indicates newly revised material.

Chapter 1—INTRODUCTION 5

1.1. Introduction

1.2. Applicability

1.3. Objective

Chapter 2—ROLES AND RESPONSIBILITIES 6

2.1. Secretary of the Air Force, Office of Information Dominance and Chief

Information Officer (SAF/CIO A6)

2.2. Air Education and Training Command (HQ AETC)

2.3. Designated Accrediting Authorities

2.4. Air Force Senior Information Assurance Officer (AF SIAO)

2.5. Air Force Space Command

2.6. 24th Air Force

2.7. Air Force Network Integration Center (AFNIC)

2.8. Information System Owners (ISO)

2.9. System Information Assurance Officer/Manager (IAO/IAM)

2.10. Wing Information Assurance Office (WIAO) (To become Wing Cybersecurity

Office (WCSO))

2.11. DELETED

2.12. Organizational IAO (To be called Cybersecurity Liaison)

2.13. Information System Users

AFMAN33-282 28 MARCH 2012 3

Chapter 3—COMPUSEC 7

3.1. General

3.2. Notice and Consent to Monitoring

3.3. Security Configuration Specifications

3.4. IA Community of Practice (CoP)

3.5. Information Technology Asset Procurement

3.6. COMPUSEC Methods and Procedures Technical Orders (MPTO)

3.7. Operations Security (OPSEC)

3.8. IAO Functions

3.9. Risk Management Framework (RMF) Roles

Chapter 4—INFORMATION SYSTEM ACCESS CONTROL 9

4.1. Introduction

4.2. Authorized Users

4.3. Loss of Access

Table 4.1. Network Access Suspension Matrix

4.4. Account Management

4.5. Password/PIN Management

4.6. Biometric Management

4.7. Account Auditing

Chapter 5—PUBLIC KEY INFRASTRUCTURE 19

5.1. Introduction

5.2. NIPRNET PKI

5.3. SIPRNET PKI

5.4. External PKI

5.5. Escrowed Certificates

5.6. Software Certificate Issuance and Control

5.7. Group Accounts Utilizing PKI

5.8. Key Compromise

5.9. Server Certificates

5.10. Code Signing Certificates

5.11. Certificate Reissuance Prior to Expiration

5.12. Network Authentication

4 AFMAN33-282 28 MARCH 2012

5.13. PKI Waivers

Chapter 6—END POINT SECURITY 25

6.1. Introduction

6.2. General Protection

6.3. Periods Processing

6.4. Software Security

6.5. Malicious Logic Protection

6.6. Telework

6.7. Data Encryption

6.8. Privately-Owned hardware and software

6.9. Contractor-Owned Information Systems

6.10. Foreign-Owned Information Systems

6.11. Other Service or Agency Owned Information Systems

6.12. Mobile Computing Devices

6.13. Peripheral Devices

6.14. Removable Media

6.15. Wireless Services

6.16. Collaborative Computing

6.17. Non-enterprise activated (NEA) Commercial Mobile Devices (CMD)

6.18. Enterprise activated CMD

Chapter 7—DATA SPILLAGE AND COMPUSEC INCIDENT REPORTING 40

7.1. Introduction

7.2. Data Spillage

7.3. Classified Message Incidents

7.4. Incident Response Flow

7.5. CMD Spillage

Chapter 8—REMANENCE SECURITY 42

8.1. Introduction

Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 43

AFMAN33-282 28 MARCH 2012 5

Chapter 1

INTRODUCTION

1.1. Introduction. Computer Security (COMPUSEC) is an IA discipline identified in AFI 33-

200, Information Assurance (IA) Management. Compliance ensures appropriate implementation of measures to protect all Air Force Information System (IS) resources and information.

1.1.1. The framework of the AF COMPUSEC IA program consists of a cyclic sequential security management model for risk management. This model is specific to information processed on AF computing systems and incorporates strategy, policy, awareness/training, implementation, assessment, remediation, and mitigation controls.

1.2. Applicability. This publication applies to all AF ISs and devices used to process, store, display, transmit, or protect AF information, regardless of classification or sensitivity, unless exempted in Para 1.2.3 or 1.2.4.

1.2.1. AF ISs and devices include but are not limited to: Stand-alone systems, Platform IT

(PIT) systems, IS components of systems where PIT interconnections (PITI) exist, Modeling and simulation systems/networks, ISs connected to external networks via authorized internet service providers (ISPs), ISs providing the management infrastructure, Connections/interfaces with other ISs

1.2.2. This publication is binding on all users, military, civilian and contract employees, that operate, connect, or interact with the ISs owned, maintained, and controlled by the AF.

1.2.3. More restrictive Federal, DoD, and Director of Central Intelligence Agency directive requirements governing Special Access Program information take precedence over this publication. The latest version of all publications (e.g., Federal, Joint, DoD, AF) referenced within this publication must be utilized.

1.2.4. This publication and implementation guidance identified within are not applicable to

Sensitive Compartmented Information (SCI) ISs. For SCI systems, refer to the Intelligence

Community Directive (ICD) 503, Intelligence Community Information Technology Systems

Security Risk Management, Certification and Accreditation.

1.2.5. Compliance with IA controls will be assessed, documented, and mitigated according to DoD Instruction (DoDI) 8500.2, Information Assurance (IA) Implementation, and DoDI

8510.01, DoD Information Assurance Certification and Accreditation Process (DIACAP), for inclusion in the AF IS Certification and Accreditation (C&A) package.

1.3. Objective. The objective of COMPUSEC is to ensure the employment of countermeasures to protect and secure United States (US) government information processed by AF ISs by protecting the confidentiality, integrity, availability, authentication, and non-repudiation of ISs.

6 AFMAN33-282 28 MARCH 2012

Chapter 2

ROLES AND RESPONSIBILITIES

2.1. Secretary of the Air Force, Office of Information Dominance and Chief Information

Officer (SAF/CIO A6). Develops, implements, and oversees all cybersecurity disciplines.

2.2. Air Education and Training Command (HQ AETC). Conducts and integrates IA education and training into initial military training courses, Air Force accession programs, formal schools, professional military education courses, and specialized training in Air Force Specialty

Code-awarding courses according to AFI 36-2201, Air Force Training Program, and the specific

IA education and training requirements of DoD 8570.01-M, IA Workforce Improvement

Program.

2.3. Designated Accrediting Authorities. Executes Designated Accrediting Authority (DAA) duties according to AFI 33-210 Air Force Certification and Accreditation (C&A) Program

(AFCAP). Reference AFI 33-210 for DAA appointment, assignment, delegation, training requirements, and key roles and responsibilities.

2.4. Air Force Senior Information Assurance Officer (AF SIAO). Reference AFI 33-200 and AFI 33-210 for AF SIAO assignment, roles, and responsibilities.

2.5. Air Force Space Command. Designated as the lead command for cyberspace and related subject matter experts in support of policy development for the Air Force future goal of one Air

Force Network (the AFNet).

2.6. 24th Air Force. Directs Air Force Network Defense (NetD) in accordance with AFPD 10-

7, Information Operations.

2.7. Air Force Network Integration Center (AFNIC). Designated by HQ AFSPC as the organization for IA policy subject matter expertise in support of HQ AFSPC’s future goal of one

Air Force Network (AFNet).

2.8. Information System Owners (ISO). Reference AFI 33-210 for ISO assignment, roles, and responsibilities.

2.9. System Information Assurance Officer/Manager (IAO/IAM). Reference AFI 33-200, AFI 33-210 and DoDI 8510.01 for system IAO/IAM roles and responsibilities.

2.10. Wing Information Assurance Office (WIAO) (To become Wing Cybersecurity Office

(WCSO)). Responsible for the development, implementation, oversight and maintenance of host wing cybersecurity programs.

2.11. DELETED.

2.12. Organizational IAO (To be called Cybersecurity Liaison). Conducts annual

COMPUSEC self-assessments using the COMPUSEC Self-Assessment Checklist (SAC) located in the Inspector General’s Management Internal Control Toolset (MICT).

2.13. Information System Users. Authorized IS users must comply with the guidance within

AFMAN 33-152, User Responsibilities and Guidance for Information Systems (T-1).

AFMAN33-282 28 MARCH 2012 7

Chapter 3

COMPUSEC

3.1. General. Safeguard ISs and information against sabotage, tampering, denial of service, espionage, fraud, misappropriation, misuse, or release to unauthorized persons.

3.2. Notice and Consent to Monitoring. Configure all DoD telecommunications devices according to AFI 10-712, Telecommunications Monitoring and Assessment Program (TMAP).

3.3. Security Configuration Specifications. Securely configure and implement all Information

Technology (IT) products. IA reference documents, such as National Institute of Standards and

Technology (NIST) Special Publications (SP), Defense Information Systems Agency (DISA)

Security Technical Implementation Guides (STIGs), National Security Agency (NSA) Security

Configuration Guides, AF specialized publications (AF System Security Instructions, AF

Technical Orders [TO], etc.), and other relevant publications are used for the security configuration and implementation guidance. Apply these reference documents according to AFI

33-200 and AFI 33-210 to establish and maintain a minimum baseline security configuration and posture. References to various documents are cited throughout this publication, where applicable.

3.3.1. Document all configuration requirements within this publication in the IS C&A package according to AFI 33-210.

3.3.2. Document any deviation to guidance within this publication as part of the applicable

IS C&A package. If the DAA has not been delegated the approval authority for the deviation, then the deviations must be submitted, on an AF Form 4169, through IA channels to the OPR of the governing publication prior to DAA approval.

3.4. IA Community of Practice (CoP). The AF IA CoP serves as the primary IA support resource for Wing IA officers and managers, providing a collaborative one-stop-shop for IA ideas, questions, discussions, and hosts dynamic web content for information sharing

(https://afkm.wpafb.af.mil/community/views/home.aspx?Filter=OO-SC-IA-01).

3.5. Information Technology Asset Procurement. All IT hardware, firmware, and software components or products incorporated into DoD ISs must comply with evaluation and validation requirements in DoDI 8500.01, Cybersecurity (T-0).

3.5.1. Procurement activities of all IT hardware, cellular, and peripheral devices (e.g., desktops, laptops, servers, BlackBerry® devices, cell phones, printers, scanners, and

Bluetooth® peripheral devices) must follow the guidance in AFMAN 33-153, Information

Technology Asset Management, and the AF Information Technology Commodity Council

(ITCC) guidance available on the AF Portal.

3.6. COMPUSEC Methods and Procedures Technical Orders (MPTO). MPTOs present procedural guidance to the IA workforce to implement and manage methods and processes pertaining to COMPUSEC directed by this policy.

3.6.1. This publication directs the use of the implementation guidance and procedures as identified in the MPTOs for the COMPUSEC program.

3.6.2. Obtain MPTOs via your organizational Technical Order Distribution Account

(TODA).

https://afkm.wpafb.af.mil/community/views/home.aspx?Filter=OO-SC-IA-01

8 AFMAN33-282 28 MARCH 2012

3.7. Operations Security (OPSEC). Follow OPSEC measures according to AFI 10-701, Operations Security (OPSEC), when using IT assets. OPSEC training and guidance can be obtained from the Installation OPSEC Program Manager or Signature Management Officer.

3.8. IAO Functions. Within this publication where both organizational and system IAO functions overlap, the “IAO” term is all inclusive. In all other specific situations, the terms

“organizational” or “system” will be indicated. Furthermore, the new term for organizational

IAO will become “Cybersecurity Liaison” in the rewrite of AFI 33-200. The term

“cybersecurity” has replaced the term “information assurance” in future policy updates and rewrites.

3.9. Risk Management Framework (RMF) Roles. With the publishing of DoDI 8510.01, RMF, many role designations have been replaced with new terminology. Designated

Accrediting Authority (DAA) has been replaced with Authorizing Official (AO); Information

Assurance Manager (IAM) has been replaced with Information System Security Manager

(ISSM); System Information Assurance Officer (IAO) has been replaced with Information

System Security Officer (ISSO); the AF Senior Information Assurance Officer (SIAO) has been replaced with the AF Senior Information Security Officer (SISO). Future policy rewrites will change the old terms to match DODI 8510.01.

AFMAN33-282 28 MARCH 2012 9

Chapter 4

INFORMATION SYSTEM ACCESS CONTROL

4.1. Introduction. Every individual who has access to the Non-Classified Internet Protocol

Router Network (NIPRNET) or Secret Internet Protocol Router Network (SIPRNET), standalone systems, specialized ISs, and/or mission systems is an IS user.

4.1.1. Access to AF ISs is a revocable privilege and will be granted to individuals based on need-to-know and according to DoDI 8500.2, Information Assurance (IA) Implementation;

NSTISSP No. 200, National Policy on Controlled Access Protection; DoD 5200.2-R, Personnel Security Program; and Chairman of the Joint Chiefs of Staff Instruction (CJCSI)

6510.01, Information Assurance (IA) and Support to Computer Network Defense (CND).

4.2. Authorized Users. Authorized user account creation and administration must be configured with role-based access schemes according to system policy requirements in DoDI

8500.2.

4.2.1. All authorized users (e.g., military, civilian, contractor, temporary employees, volunteers, interns, key spouses, and American Red Cross personnel) complete DoD IA training prior to being granted access to an IS. IA training will be re-accomplished annually by the user and compliance maintained by the IAO according to DoD 8570.01-M.

4.2.1.1. DoD IA training is located on Advanced Distributed Learning System (ADLS) accessible via the AF Portal. A publically accessible version of the DoD IA training is located on the Information Assurance Support Environment (IASE) website

(http://iase.disa.mil/eta/ProductDownload/awareness_download.html).

4.2.1.2. When a user requires a new/modification to his/her account (due to change of station or assignment, Temporary Duty [TDY], etc.), the gaining IAO will verify the user meets access requirements before granting access to the IS. Users are not required to retake the DoD IA training provided the user has a valid and current (within a year) course completion record. In emergency or deployment situations, the IAO may rely on a training record review or ADLS to validate course completion.

4.2.2. For IS access, the IAO ensures the DD Form 2875, System Authorization Access

Request (SAAR), is completed and signed. Document access requests, DoD IA training completion, and justification for access and clearance/background investigation verification as referenced by DoD 5200.2-R and AFI 31-501, Personnel Security Program. DD Form

2875 signatures can be “wet” or digitally signed.

4.2.2.1. All authorized IS (to include Mobile Computing Devices) users will sign the standardized AF Form 4394, Air Force User Agreement Statement-Notice and Consent

Provision (See AFI 33-100, to become AFMAN 33-152) prior to initial IS access. See paragraph 6.12 for wireless mobile device requirements.

4.2.2.2. Access to classified ISs also requires a Standard Form 312, Nondisclosure

Agreement, according to AFI 31-401, Information Security Program Management.

4.2.2.3. IAOs, in coordination with the organizational security manager, verify user background investigation requirements according to DoD 5200.2-R.

http://iase.disa.mil/eta/ProductDownload/awareness_download.html

10 AFMAN33-282 28 MARCH 2012

4.2.3. A user must obtain an approved hardware token according to current processes prior to obtaining NIPRNET (and SIPRNET when tokens are available) access.

4.2.3.1. The locally appointed Contractor Verification System (CVS) Trusted Agent

(TA) individual (e.g. organizational security manager) verifies contractor access against a valid contract in the CVS before approving the request for a contractor to be issued a

Common Access Card (CAC).

4.2.4. The ISO ensures methods are in place to verify user access requests before granting IS access.

4.2.5. All user accounts are created using applicable TOs published by the 24 AF (e.g.

MPTO 00-33D-2001, Active Directory Naming Conventions).

4.2.6. Privileged User. A privileged user is an authorized user who has access to IS control, monitoring, or administration functions. Grant privileged access to unclassified and classified

ISs based on the assigned duties and the position categories identified in DoDI 8500.2:

Category IT-I (Privileged) and Category IT-II (Limited Privileged).

4.2.6.1. Privileged users must meet all the requirements of an authorized user as specified in paragraphs 4.2.1 – 4.2.3.

4.2.6.2. Privileged users are established and administered with a role-based access scheme according to the system policy and DoDI 8500.2.

4.2.6.3. System access requires Public Key Infrastructure (PKI) access methods as specified in Chapter 5, Public Key Infrastructure.

4.2.6.4. Privileged users access only data, control information, software, hardware, and firmware that they are authorized access and still have a requirement for “need to know.”

4.2.6.5. To maintain separation of duties and least privilege, users maintain separate accounts, a user account for day-to-day or “non-privileged” functions, and a privileged account for administrative functions according DoD 8570.01-M and DoDI 8500.2.

4.2.6.6. The system IAM tracks and maintains visibility over all privileged users according to AFI 33-200 and DoDI 8500.2.

4.2.6.7. Prohibit sharing of privileged user accounts between users.

4.2.6.8. Configure privileged user remote access according to the DISA Enclave STIG.

4.2.6.9. Privileged users must be position-certified according to DoD 8570.01-M and qualified according to AFMAN 33-285, Information Assurance (IA) Workforce

Improvement Program.

4.2.6.10. Privileged users must complete a Privileged Access Agreement according to

DoD 8570.01-M.

4.2.7. Foreign Nationals/Local Nationals. A Foreign National/Local National (FN/LN) user is anyone who is not a US citizen or permanent resident, according to Title 8, Code of

Federal Regulations, “Aliens and Nationality.” Before authorizing FN/LN access to unclassified and/or classified ISs, the ISO ensures compliance with the IS access requirements in paragraphs 4.2.1-4.2.3 and the following constraints:

AFMAN33-282 28 MARCH 2012 11

4.2.7.1. Constraints. MAJCOM Foreign Disclosure Office (FDO) determines authorized and privileged need-to-know for the administrative access and control of information, software, hardware and firmware to include controlled unclassified information (CUI) and classified information, in accordance with DoD Manual (DODM) 5200.01, Volume

4, Controlled Unclassified Information (CUI).

4.2.7.1.1. Base or Wing IA offices must consult the Host or MAJCOM FDO before authorizing access by FN/LN users to ISs processing, storing, or transmitting classified and controlled unclassified information. Note: Specific FN/LN access guidance can be found in the following publications: AFI 16-107, Military Personnel

Exchange Program; AFI 16-201, Air Force Foreign Disclosure and Technology

Transfer Program; DoDD 5230.25, Withholding of Unclassified Technical Data from

Public Disclosure; DoDD 5400.7, DoD Freedom of Information Act (FOIA)

Program; DoD 5400.7-R_AFMAN 33-302, Freedom of Information Act Program;

AFI 33-332, Air Force Privacy Program; DoDD 5230.11, Disclosure of Classified

Military Information to Foreign Governments and International Organizations; and

DoDD 5230.20, Visits and Assignments of Foreign Nationals.

4.2.7.2. Administrative Controls. Establish a process between ISOs, system IAMs, and the applicable MAJCOM FDO to determine classified or unclassified access. Direct conflicts in FN/LN access requirements to the MAJCOM FDO for resolution.

4.2.7.2.1. Base or Wing IA offices maintain a list of FN/LN users from each subordinate organization within their assigned organizations. Provide specific documentation indicating FN/LN usage to the system IAM for inclusion in the IS

C&A.

4.2.7.2.2. The IAO tracks and maintains visibility over all FN/LN billets assigned to an IS and/or organization.

4.2.7.2.3. Restrict FN/LN IS user access to IT levels defined in DoDI 8500.2.

4.2.7.2.4. If privileged access is required to an IS, FN/LN user access must be restricted to IT II-level positions only and directly supervised by a U.S. Citizen according to DoDI 8500.2 and CJCSI 6510.01. Furthermore, document access in the

IS C&A package. Pursuant to applicable host-nation agreements, FN/LN privileged users must be baseline computing environment (CE) certified according to DoD

8570.01-M.

4.2.7.3. IS Controls. System IAMs in coordination with privileged users ensure that applicable IA technical safeguards and controls are established and maintained according to CJCSI 6510.01 and DoDI 8500.02.

4.2.7.3.1. Prohibit unlimited FN/LN access to “.mil” websites until specific host

FDO and the MAJCOM FDO approval is accomplished.

4.2.7.3.2. ISOs direct privileged users to setup permissions on ISs that allow for

FN/LN account management in accordance with this publication.

4.2.7.3.3. Establish proper messaging naming conventions (e.g., <john.smith.uk@af.mil>) of FNs as non-US citizens according to CJCSI 6510.01.

mailto:john.smith.uk@af.mil

12 AFMAN33-282 28 MARCH 2012

4.2.7.3.4. At the discretion of the ISO, system access requires PKI access methods as specified in Chapter 5, Public Key Infrastructure. See paragraph 4.2.6.3 MAJCOMs handle token requirements according to host nation agreements.

4.2.7.3.5. IAOs validate implementation of appropriate safeguards (e.g. PKI, email accounts). Employ safeguards that adhere to DoD, Joint, and AF, and if applicable, locally created information security publications.

4.2.7.3.6. Sanitize or configure classified ISs to restrict access by FN/LNs to only classified information authorized for disclosure to the FN/LNs government or coalition, as necessary to fulfill the terms of their assignments according to applicable host MAJCOM FDO requirements.

4.2.7.3.7. For SIPRNET RELEASABLE (SIPR REL) IS specific configuration requirements, follow guidance in the DISA Embedded REL User Enclave Technical

Implementation Instruction (TII)

(http://iase.disa.mil/stigs/net_perimeter/enclave_dmzs/rel.html).

4.2.7.3.8. SIPR REL users do not need FDO approval to access .mil sites. DISA controls website access at the REL DMZ proxy.

4.2.7.4. Other Considerations. Non-US citizens who are permanent legal residents and/or full time permanent employees of the DoD meet the requirements of any US citizen for access to the unclassified network or system.

4.2.8. Grant only unclassified IS access to temporary employees and volunteer personnel in support of their assigned duties.

4.2.8.1. A volunteer is any individual authorized to be DoD volunteers as defined in

DoDI 1100.21, Voluntary Services in the Department of Defense. Restrict volunteers to

IT-III level positions.

4.2.8.2. Temporary employees and volunteers (including key spouses) must meet the requirements as specified in paragraphs 4.2.1 through 4.2.3.

4.2.8.3. Temporary employees and volunteers require PKI access at the discretion of the

ISO and according to IS requirements as outlined in Chapter 5, Public Key

Infrastructure. See paragraph 4.2.6.3

4.2.8.3.1. Eligible volunteers should contact their CVS TA to get their Volunteer

Logical Access Credential (VoLAC).

4.2.8.3.2. The VoLAC is used for logical access (network) and is replacing the

Alternative Token for volunteers.

4.2.9. Public users that access an IS intermittently (i.e. vendors, morale support, technical support, etc.) have only non-privileged access.

4.2.9.1. The system ISO ensures adherence to applicable DISA STIGs (e.g., Web Server

STIG) for private/public IS separation.

4.2.10. All IS users have the responsibility to report suspected inappropriate use, both by authorized and unauthorized personnel, to supervisory chain of command, security manager, organizational IAO, or commander.

http://iase.disa.mil/stigs/net_perimeter/enclave_dmzs/rel.html

AFMAN33-282 28 MARCH 2012 13

4.3. Loss of Access. Access to an AF IS is a privilege and continued access is contingent on personnel actions, changes in need to know, or operational necessity (see AFI 33-100, to become

AFMAN 33-152).

4.3.1. Specific procedural information for account disabling is located in MPTO 00-33B-

5004, Access Control for Information Systems.

4.3.2. Failure to maintain DoD IA training results in immediate suspension of access to unclassified and classified ISs.

4.3.3. Unintentional and/or intentional actions that threaten or damage AF ISs will result in immediate suspension of access to unclassified and classified ISs according to CJCSI

6510.01.

4.3.3.1. According to CJCSI 6510.01, suspend access to classified ISs if the user’s security clearance is suspended, denied, or revoked. If an individual’s clearance is suspended, denied, or revoked, the ISO coordinates with the organization commander and determines if unclassified network access can be maintained according to paragraph

4.3.3.3.

4.3.3.2. The IAO notifies the ISO and/or the organizational commander upon discovery or notification of user activity that is inconsistent with the terms of DoD IA training or inconsistent with approved IS security usage.

4.3.3.3. At the direction of the organizational commander, the IAO suspends user access and the ISO provides reason for the suspension. The ISO identifies requirements required for account reinstatement (at a minimum, DoD IA remedial training, MAJCOM required, or USCYBERCOM CTO-directed requirements). Upon satisfactorily completing retraining and any other requirements, the IAO, on behalf of the ISO and/or organizational commander initiates reinstatement.

4.3.3.4. The ISO reviews all pertinent documentation relating to the justification for the suspension, the risk to the network, and operational requirements. The organizational commander makes a determination as to whether or not to suspend the individual's network access. See Table 4.1, Network Access Suspension Matrix, as guidance for when an individual’s security clearance is suspended, denied, or revoked, for whatever reason.

4.3.4. If the user disputes IS access suspension, follow local command level legal guidance.

Table 4.1. Network Access Suspension Matrix.

R U

L E

A B C

If the system is and the clearance is then

1 Classified

Suspended, denied, or revoked

The individual’s access is immediately suspended.

See AFI 31-501, Personnel Security Program

Management, and CJCSI 6510.01

2 Unclassified Denied or revoked

The IAO will immediately suspend the individual’s access

3 Unclassified Suspended Organizational commanders may make a

14 AFMAN33-282 28 MARCH 2012

recommendation for access reinstatement based on the circumstances surrounding the suspension, threat to the network, and operational requirements

Unclassified with privileged access

Suspended, denied, or revoked

Suspend privileged access immediately.

Organizational commanders may make a recommendation for user access suspension depending on the circumstances surrounding the suspension and operational requirements

4.4. Account Management. AF direction is to use PKI-based access control according to DoDI

8520.03, Identity Authentication for Information Systems and the USCYBERCOM, Public Key

Infrastructure (PKI) Implementation Communications Tasking Order (CTO) 07-015

(https://www.cybercom.mil/J3/orders/default.aspx) for unclassified systems. See Chapter 5, Public Key Infrastructure.

4.4.1. IAO Account Actions. Specific procedural information is located in MPTO 00-33B-

5004, IAOs/IAMs will:

4.4.1.1. Maintain the group account configurations according to the IS C&A documentation and according to DoDI 8500.2.

4.4.1.2. Ensure assignment of individual accounts to privileged users. Group or shared accounts do not support nonrepudiation and least-privilege access controls.

4.4.1.3. Notify privileged users to de-provision all user accounts from an IS whenever the user no longer requires access to the IS within 24 hours of notification (e.g., whenever the user is permanently transferred to another location, termination of employment, retirement).

4.4.1.4. Substitute reusable IS user accounts on systems with frequent user-turnover

(e.g., students, temporary employees, exercise accounts). For specific procedures, see

MPTO 00-33B-5004, Chapter 3.

4.4.1.5. Develop local procedures in coordination with privileged users to log off users manually if automatic log off functions are not technically feasible (e.g., SIPRNET clients, non-Windows based).

4.4.1.6. Develop notification procedures for de-provisioning IS user accounts when an employee (e.g., military, civilian, or contractor) transfers, retires, separates, or is terminated, or for any other loss of IS access.

4.4.1.7. Perform annual audit of user accounts to verify permissions/least privilege and ensure that de-provisioning of accounts has taken place according to DoDI 8500.2.

4.4.2. Privileged User Account Actions. Specific procedural information is located in TO

00-33A-1202, Air Force Network Account Management. Privileged users will:

4.4.2.1. Configure all individual IS accounts with a unique identifier. For group or shared accounts see paragraph 5.7 for group accounts with PKI.

4.4.2.2. Permit group accounts only for reasons of operational necessity on unclassified and classified systems and networks as determined by the organizational commander, https://www.cybercom.mil/J3/orders/default.aspx

AFMAN33-282 28 MARCH 2012 15

reviewed by the system IAM, approved by the ISO, and fully documented in the C&A package.

4.4.2.3. Associate each IS user identity with all auditable actions supporting nonrepudiation and accountability according to DoDI 8500.2.

4.4.2.4. Incorporate electronic or paper tracking and reviewing methods to match individual users to generic usernames (e.g., user log sheet) every 30 days.

4.4.2.4.1. Per direction of the IAO/IAM, disable user accounts once the users no longer require access (e.g., permanent change of station, separation, class graduation).

4.4.2.5. Configure account lockout parameters according to the USCYBERCOM Public

Key Infrastructure (PKI) Implementation CTO 07-015 and CJCSI 6510.01.

4.4.2.6. Configure automatic log off functions due to user inactivity according to the minimum standards identified in according to DoDI 8500.2 and the applicable DISA

OS/Database STIGs.

4.4.2.7. Configure and implement automated IS controls to check and disable IS user accounts that have been dormant more than 30 days according to CJCSI 6510.01. AF

CIO Exception: Disable National Guard and Reserve member IS user accounts only after

90 days of inactivity.

4.4.2.7.1. If an approved hardware token is used as the only IS’s account authentication method, user account access expires when the approved hardware token expires according to CJCSI 6510.01.

4.4.2.7.2. For PK-enabled ISs using Personal Identification Numbers (PINs), disable or limit pin caching features according to the applicable DISA OS (e.g., Windows) and DISA Access Control STIGs.

4.4.2.8. Delete unnecessary (to include service accounts) and/or default accounts and change all factory default or user-generated passwords included in a newly acquired system (software or hardware) according to the configuration information in the IS C&A package before allowing any user access to the system.

4.4.2.8.1. Rename default accounts that cannot be deleted, according to applicable

DISA STIGs.

4.4.2.8.2. Do not execute root-level access in IS applications.

4.4.2.9. Disable user accounts (do not delete) when users are unable to remotely access their accounts due to an extended absence or when a user is suspended from work, IS access is revoked for any reason, or the security clearance is suspended as specified in paragraph 4.3.

4.4.2.10. Before unlocking the user account, a validated mechanism must be in place to validate the user’s identity with the IAO (e.g., in-person identification, digitally signed email).

4.5. Password/PIN Management. ISs must follow PKI requirements in USCYBERCOM

Public Key Infrastructure (PKI) Implementation CTO 07-015 and Chapter 5, Public Key

Infrastructure as an authentication means to the NIPRNET.

16 AFMAN33-282 28 MARCH 2012

4.5.1. Specific procedural information for password management is located in MPTO 00-

33B-5004, Chapter 4.

4.5.2. According to DoDI 8520.02,, Public Key Infrastructure (PKI) and Public Key (PK)

Enabling, and the DISA STIG, Access Control in Support of Information Systems, all DoD networks required by DoDD 8500.1 to authenticate users will perform this authentication using certificates issued by DoD-approved PKI on hardware tokens. The CAC is the primary hardware token, but there are special instances where the CAC cannot be used to perform various missions. To accommodate these various missions, the DoD CIO has approved the use of the Alternate Login Token (ALT). See Chapter 5, Public Key Infrastructure.

4.5.3. In addition to the AF-specific password guidance contained within this publication, configure IS password authentication according to the DISA Access Control STIG. DISA

STIG and/or USCYBERCOM Tasking Order (TO) password requirements take precedence only if more restrictive than guidance in this publication.

4.5.4. The ISO and system IAM will ensure where passwords are used for access to AF-GIG restricted assets (i.e., networks, workstations, or applications), at a minimum, passwords are created and changed in accordance with current USCYBERCOM CTOs and CJCSI 6510.01.

4.5.4.1. Meet the minimum complexity requirements as specified in the applicable DISA

STIGs and MPTO 00-33B-5004. See CTO 07-015 for additional guidance.

4.5.4.2. One-time password generators or hardware token implementation must follow the guidance provided in the DISA STIG, Access Control in Support of Information

Systems,.

4.5.4.3. ISO and system IAM will establish a frequency based on mission, operational needs or IS technical feasibility if not able to meet this requirement (e.g., AF Reserve

Components).

4.5.5. Protect all passwords and PINs based on the sensitivity of the information or critical operations they protect (e.g., a password used to gain access to a SECRET network is itself classified SECRET).

4.5.5.1. Classify passwords and PINs at the highest level of information processed on that system. As a minimum, safeguard passwords as “For Official Use Only” (FOUO).

See Appendix 3 of DoD Regulation 5200.1-R, Information Security Program, for an explanation of FOUO.

4.5.5.2. If necessary for mission accomplishment (i.e., pre-established accounts for contingency or exercise), place the password in a properly marked, sealed envelope or

Standard Form 700, Security Container Information Form, and store in a General

Services Administration (GSA)-approved container as specified in the DISA Access

Control STIG.

4.5.6. The ISO and system IAM ensure compliance with DoDI 8500.2 for shared/group passwords and PINs and obtain approval by the DAA according to CJCSI 6510.01.

Implement system and physical auditing procedures in conjunction with these methods to support non-repudiation and accountability.

4.5.6.1. Consider unauthorized sharing of passwords a security incident according to

CJCSI 6510.01. See Chapter 7, Data Spillage and COMPUSEC Incident Reporting.

AFMAN33-282 28 MARCH 2012 17

4.5.7. In the event of a compromised password or PIN, the ISO and system IAM ensures procedures are in place to implement immediate password and PIN change activities. The

IAO follows established reporting and investigation procedures according to AFI 33-138, Enterprise Network Operations Notification and Tracking (to become AFI 33-115, AF GIG

Services). If the PIN is the access code to an approved PKI token, the compromise of the PIN warrants probable compromise of the certificates. See paragraph 5.8

4.5.8. Protect all passwords and PINs during transmission using Federal Information

Processing Standards (FIPS)-approved encryption according to DoDI 8500.2. If not technically feasible, require the use of a one-time password to access the IS.

4.5.9. Privileged users will incorporate electronic or paper tracking methods to account for user activity when using shared passwords. Shared passwords will meet all requirements as specified in this publication.

4.5.10. Institute automated procedures to reject rapid retries when entering a password incorrectly.

4.5.11. The ISO will ensure the establishment of procedures for manual or automatic password changes by users. The IS will require users to change the one time password at initial logon according to DoDI 8500.2.

4.5.11.1. Configure IS user accounts to enforce password history in accordance with applicable DISA STIG. If ISs cannot support STIG requirements, configure to maximum and document in C&A package.

4.5.11.2. IS privileged users implement policies enforcing a minimum seven-day wait before a user may optionally change the password.

4.5.12. Upon a suspected or confirmed compromised or “cracked” password and/or PIN, the

IAO must immediately take measures to lock down the account in question.

4.5.13. Configure password cracking tools and procedures according to DoDI 8500.2. See

MPTO 00-33B-5004 for password cracking specific guidance.

4.6. Biometric Management. The definition of biometrics is a measurable biological

(anatomical and physiological) and behavioral characteristic used for automated recognition. As a process, biometrics is an automated method of recognizing an individual based on measurable biological (anatomical and physiological) and behavioral characteristics.

4.6.1. Biometrics is an important AF operational enabler that will be fully integrated to conduct the AF mission in support of joint military operations according to DoDD 8521.01E, Department of Defense Biometrics.

4.6.1.1. Design biometrics programs to improve the effectiveness and efficiency of biometrics activities throughout the AF by eliminating duplication and overlap of technology development and information management efforts.

4.6.1.2. Configure biometric programs according to the DISA Biometrics Security

Checklist (http://iase.disa.mil/stigs/checklist/).

4.6.2. At the discretion of the installation commander, the collection and use of biometrics may occur at any time when a person requests or requires access to systems, facilities, and http://iase.disa.mil/stigs/checklist

18 AFMAN33-282 28 MARCH 2012

networks under the responsibility of the AF or according to host nation and Status of Forces

Agreement (SOFA) agreements.

4.6.3. All biometrics activities shall be coordinated via the sponsoring AF functional organization through the Biometrics Identity Management Agency (BIMA) at http://www.biometrics.dod.mil/ and approved by DoD Biometrics Executive Committee

(EXCOM) before acquisition.

4.6.4. When used, biometrics will be collected, matched, transmitted, stored, shared, archived, and received according to AF procedures for each group as defined by the National

Science and Technology Council Subcommittee on Biometrics Glossary; AFI 63-101, Acquisition and Sustainment Life Cycle Management; and AFI 33-332.

4.6.5. In accordance with Office of the DoD CIO disposition definitions, biometrics fall into two groups governing storage and retention.

4.6.5.1. Group 1 consists of military, government civilians, and military dependents;

indefinite storage and retention apply.

4.6.5.2. Group 2 consists of contractors, visitors, and temporary workers; disposition of biometric data occurs at the end of the access period.

4.6.6. All biometrics data and associated information collected as a result of DoD operations or activities will be maintained or controlled by the Department of Defense, unless otherwise specified by BIMA for DoD Biometrics at a later date.

4.7. Account Auditing.

4.7.1. IS auditing events will be configured according to CJCSI 6510.01 and the applicable

DISA STIGs (application, operating system, database, etc).

4.7.1.1. Privileged users must ensure the IS audit trail function is enabled for accounts.

Only privileged users have access to the audit trail file.

4.7.2. The audit trail must not contain unencrypted (clear text) passwords, incorrectly entered passwords, or character strings, as this could expose the password of a legitimate user.

4.7.3. All audit records must be maintained according to AFRIMS, Records Distribution

System (RDS), Table 33-25, Rule 8

(https://www.my.af.mil/afrims/afrims/afrims/rds/rds_series.cfm).

http://www.biometrics.dod.mil/ https://www.my.af.mil/afrims/afrims/afrims/rds/rds_series.cfm

AFMAN33-282 28 MARCH 2012 19

Chapter 5

PUBLIC KEY INFRASTRUCTURE

5.1. Introduction. The DoD and the Committee on National Security Systems (CNSS) PKIs use asymmetric cryptography to identify and authenticate users to systems and networks for the

NIPPRNET and SIPRNET. PKI hardware tokens provides two-factor authentication for access to DoD and AF ISs and networks for both NIPRNET and SIPRNET. Two-factor authentication is a combination of something the user has and something the user knows.

5.2. NIPRNET PKI. The most commonly used unclassified PKI hardware token or smart card is the CAC. On AF installations, the Air Force Military Personnel Flight (MPF) issues the CAC.

On non-AF locations, any Real-time Automated Personnel Identification System (RAPIDS) issues CACs.

5.2.1. The CAC is the primary hardware token for identifying individuals for logical access to NIPRNET assets and physical access to DoD facilities according to Directive-Type

Memorandum (DTM) 08-003, Next Generation Common Access Card (CAC)

Implementation Guidance (to be incorporated into DoD Manual 1000.13-M Volume 1).

5.2.2. Air Force Personnel Center (AFPC) manages the issuance of CACs through Defense

Enrollment Eligibility Reporting System/Real-Time Automated Personal Identification

System (DEERS/RAPIDS).

5.2.2.1. According to AFI 36-3026 IP. Volume 1, Identification (ID) Cards for Members of the Uniformed Services, Their Eligible Family Members, and Other Eligible

Personnel, authorized users are issued PKI certificates on the CAC.

5.2.3. The CAC provides a cryptographic certificate-based logon identity that is valid until expiration of the CAC (not to exceed three years).

5.2.4. Personal Identity Verification (PIV) Authentication certificates can be utilized on

CAC’s to logon to additional accounts in the domain/AF GIG. See TO 31S5-4-7255-8-1, Configuration and Operations Guide for Air Force Certificate-Based Smart Card

Logon/Next Generation Using Personnal Identity Verification (PIV) Certificate for further information on implementing this capability.

5.2.5. DoD PIV Authentication certificates can be utilized on CAC’s for smart card logon to multiple accounts in the domain/AF GIG. See TO 31S5-4-7256-8-1, Configuration and

Operations Guide for Air Force Certificate-Based Smart Card Logon / Next Generation

Using Alternate Security Identification (ALTSECID) for further information on implementing this capability.

5.2.6. The ALT is an unclassified PKI hardware token or smart card containing a computer chip with a certificate issued by the AF PKI Registration Authority (RA). Use of an ALT with DoD PKI certificates is authorized for specific cases when certificates issued on the

CAC cannot be used by various groups of network users.

5.2.6.1. The ALT standard operating procedure defines use categories. Standard operating procedures are available on the AF PKI System Program Office (SPO) site https://afpki.lackland.af.mil.

https://afpki.lackland.af.mil/

20 AFMAN33-282 28 MARCH 2012

5.2.7. The VoLAC is an unclassified PKI hardware token or smart card used for volunteers and issued by MPF for network access only. Request a VoLAC through the organization

CVS TA.

5.2.8. All NIPRNet Systems are required to be SHA-256 compliant NLT 31March 2015.

(T-1) Program managers should follow FIPS 180-4, Secure Hash Standard, FIPS 140-2, and the validation lists available through the NIST Cryptographic Module Validation Program

(CMVP) and the Cryptographic Algorithm Validation Program (CAVP) sites at…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .