AFMAN_17-1301_Computer_Security_(COMPUSEC).pdf

PDF 761 KB Posted

Attached to
C-17 Roll-On Conference Capsule (ROCC) Program Federal contract opportunity
Solicitation number
FA8614-17-R-0001
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Wright Patterson Air Force Base

View the file

Other files for this federal contract opportunity

Other files attached to C-17 Roll-On Conference Capsule (ROCC) Program, newest first.
File Type Posted
Post-RFP_Release_Questions_and_Answers_Update_20_Jul_2018.pdf PDF
Post-RFP_Release_Questions_and_Answers_Update_11_July_2018.pdf PDF
Post-RFP_Release_Questions_and_Answers_Update_5_Jul_2018.pdf PDF
Post-RFP_Release_Questions_and_Answers_Update_26_Jun_2018.pdf PDF
Post-RFP_Release_Questions_and_Answers.pdf PDF
Section_M_11_Jun_2018.pdf PDF
ppi_tool.accdb MDB file
Industry_Day_Q_and_A_Sheet.pdf PDF
7133042_H.PDF PDF
7031843_N.PDF PDF
C-17_ROCC_Section_L__(31_May).docx DOCX document
7231256_Rev_B_Disro_A.PDF PDF
TO_1-1A-9_Aerospace_Metals_-_General_Data.pdf PDF
C-17_ROCC_Section_L__(31_May).pdf PDF
TO_1-1-691_Cleaning_and_Corrosion_Prevention_and_Control.pdf PDF
9579776_Rev_N_-_Product_Data_Specification.pdf PDF
RFP_31_MAY_2018.pdf PDF
7231258_Rev_D_Distro_A.PDF PDF
EN-SB-10-002_Rev_A,_Crash_Loads_and_Cargo_Restraint_EN-SB-10-002.pdf PDF
523025p.pdf PDF
AFMAN_17-1301_Computer_Security_(COMPUSEC).pdf PDF
EN-SB-10-002_App_A,_Crash_Loads_and_Cargo_Restraint_Appendices.pdf PDF
Copy_of_ROCC_Pricing_Matrix.xlsx XLSX spreadsheet
7133043_(RING_ASSEMBLY-PALLET)_Disto_A.PDF PDF
C-17_ROCC_Section_M_(31_May).pdf PDF
7031839_Rev_C_Distro_A.PDF PDF
TO_35-1-3_Corrosion_Prevention_and_Control_Cleaning_Painting_and_Marking_of_USAF_SE.pdf PDF
C-17_ROCC_TAA_Signed_Certification_Basis_27_March_2018.pdf PDF
Copy_of_C-17_ROCC_TAA_Approved_Certification_Basis_27_March_2018.xlsx XLSX spreadsheet
Industry_Day_10_May.pdf PDF
H001_(FBO).pdf PDF
TO_1-1-8_Application_and_Removal_of_Organic_Coatings.pdf PDF
7133042_H.PDF PDF
7031839_Rev_C_Distro_A.PDF PDF
7231258_Rev_D_Distro_A.PDF PDF
7133043_(RING_ASSEMBLY-PALLET)_Disto_A.PDF PDF
TO_1-1-691_Cleaning_and_Corrosion_Prevention_and_Control.pdf PDF
H002_(FBO).pdf PDF
9579777_Rev_B_-_Clarification_fo_Detailed_Test_Criteria.pdf PDF
Draft_RFP_V2.pdf PDF
Copy_of_C-17_ROCC_TAA_Approved_Certification_Basis_27_March_2018.xlsx XLSX spreadsheet
C-17_ROCC_TAA_Signed_Certification_Basis_27_March_2018.pdf PDF
9579776_Rev_N_-_Product_Data_Specification.pdf PDF
7031843_N.PDF PDF
EN-SB-10-002_App_A,_Crash_Loads_and_Cargo_Restraint_Appendices.pdf PDF
7231256_Rev_B_Disro_A.PDF PDF
EN-SB-10-002_Rev_A,_Crash_Loads_and_Cargo_Restraint_EN-SB-10-002.pdf PDF
TO_1-1A-9_Aerospace_Metals_-_General_Data.pdf PDF
C-17_ROCC_SRD.pdf PDF
ROCC_CDRL_Package.pdf PDF
Show all 50

C-17 Roll-On Conference Capsule (ROCC) Program has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BY ORDER OF THE

SECRETARY OF THE AIR FORCE

AIR FORCE MANUAL 17-1301

10 FEBRUARY 2017

Cyberspace

COMPUTER SECURITY (COMPUSEC)

COMPLIANCE WITH THIS PUBLICATION IS MANDATORY

ACCESSIBILITY: Publications and forms are available for downloading or ordering on the e-Publishing website at www.e-publishing.af.mil.

RELEASABILITY: There are no releasability restrictions on this publication.

OPR: SAF/CIO A6CS

Supersedes: AFMAN33-282, 28 March 2012

Certified by: SAF/CIO A6S

(Brigader General Patrick Higby)

Pages: 69

This Air Force Manual (AFMAN) implements Computer Security in support of Air Force Policy

Directive (AFPD) 17-1, Information Dominance Governance and Management, and Air Force

Instruction (AFI) 17-130, Air Force Cybersecurity Program Management. Computer Security

(COMPUSEC) is identified as a cybersecurity discipline in AFI 17-130 and defined within this document. This instruction applies to all AF military, civilian, and contractor personnel under contract by DoD, regardless of Air Force Specialty Code (AFSC), who develop, acquire, deliver, use, operate, or manage COMPUSEC for Air Force (AF) organizations. This instruction applies to the Air National Guard (ANG) and Air Force Reserve Command (AFRC). The term major command (MAJCOM), when used in this publication, includes field operating agencies (FOA) and direct reporting units (DRU). Additional instructions and manuals are listed on the AF

Publishing Website at http://www.e-publishing.af.mil under “Electronics Publications.” Direct questions, recommended changes, or conflicts to this publication through command channels using the AF Form 847, Recommendation for Change of Publication, to SAF/CIO A6. Send any supplements to this publication to SAF/CIO A6 for review, coordination, and approval prior to publication. Unless otherwise noted, the SAF/CIO A6 is the waiver approving authority to policies contained in this publication. The authorities to waive wing/unit level requirements in this publication are identified with a Tier number (“T-0, T-1, T-2, and T-3”) following the compliance statement. See AFI 33-360, Publications and Forms Management, Table 1.1, for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, http://www.e-publishing.af.mil/ http://www.e-publishing.af.mil/

2 AFMAN17-1301 10 FEBRUARY 2017

to the Publication OPR for non-tiered compliance items. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with (IAW)

AFMAN 33-363, Management of Records, and disposed IAW AF Records Disposition Schedule

(RDS) located in the Air Force Records Information Management System (AFRIMS). The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the AF.

SUMMARY OF CHANGES

This document is substantially changed, updating Public Key Infrastructure (PKI) policy, incident management, and access control as a result of a DoD and AF policy directive updates.

Review this manual in its entirety.

Chapter 1— INTRODUCTION 6

1.1. Introduction

1.2. Applicability

1.3. Exceptions

Chapter 2— ROLES AND RESPONSIBILITIES 7

2.1. AFSPC Cyberspace Support Squadron (AFSPC CYSS)

2.2. Air Force Life Cycle Management Center (AFLCMC), Cryptologic and

Cyber Systems Division, Responsive Cyber Acquisition Branch, Information Assurance Section (AFLCMC/HNCYP)

2.3. Wing Cybersecurity Office (WCO)

2.4. Organizational Commander (or Equivalent)

2.5. Information System Security Manager (ISSM)

2.6. Information System Security Officer (ISSO)

2.7. Commanders Support Staff (CSS)

Chapter 3— TRAINING AND RESOURCES 10

3.1. General

3.2. COMPUSEC Training Requirements

3.3. Information Assurance Collaborative Environment (IACE)

3.4. Methods and Procedures Technical Orders (MPTO)

3.5. Information Technology Asset Procurement

3.6. Configuration Management Resources

AFMAN17-1301 10 FEBRUARY 2017 3

Chapter 4— INFORMATION SYSTEM ACCESS CONTROL 14

4.1. Introduction

4.2. Authorized Users

4.3. Required Account Access Documentation

4.4. Token Access

4.5. Loss of Access

4.6. Account Management

Chapter 5— END POINT SECURITY 20

5.1. Introduction

5.2. General Protection

5.3. Software

5.4. Malicious

5.5. Data Spillage/Classified Message Incidents (CMIs)

5.6. Telework

5.7. Data

5.8. Personally

5.9. Wireless

5.10. Mobile Computing Devices

5.11. Peripheral

5.12. Removable Media

5.13. Collaborative Computing

5.14. Contractor-Owned Information Systems

5.15. Foreign-Owned Information Systems

5.16. Other Service or Agency Owned Information Systems

Chapter 6— REMANENCE SECURITY 33

6.1. Introduction

6.2. Sanitization

6.3. Media Reuse

6.4. Disposal

6.5. Mixed Media Devices

4 AFMAN17-1301 10 FEBRUARY 2017

Chapter 7— COMPUSEC ASSESSMENTS 37

7.1. Purpose

7.2. Objective

7.3. Assessment Process

7.4. Reports

Chapter 8— PUBLIC KEY INFRASTRUCTURE 39

8.1. Introduction

8.2. PKI Guidance

8.3. NIPRNet PKI

8.4. SIPRNet PKI

8.5. User or Administrator Password/PIN Management

8.6. PIN Caching Setting

8.7. Organizational Electronic Mailbox

8.8. Organizational Accounts

8.9. Group Accounts Utilizing PKI

8.10. External PKI

8.11. Enterprise Certificate Trust Governance

8.12. Escrowed Certificates

8.13. Software Certificate Issuance and Control

8.14. LRA Guidance

8.15. CMD Hardware Token Readers

8.16. Key Compromise

8.17. Server Certificates

8.18. Code Signing and Mobile Code Certificates

8.19. Certificate Reissuance Prior to Expiration

8.20. Network Authentication

8.21. Directory Services Service Accounts

8.22. PKI Waivers

8.23. PKI LRA Assessments

8.24. Biometric Management

AFMAN17-1301 10 FEBRUARY 2017 5

Attachment 1— GLOSSARY OF REFERENCES AND SUPPORTING

INFORMATION 52

6 AFMAN17-1301 10 FEBRUARY 2017

Chapter 1

INTRODUCTION

1.1. Introduction. Computer Security (COMPUSEC) is a cybersecurity discipline identified in

AFI 17-130. Compliance ensures appropriate implementation of measures to protect all AF

Information System (IS) resources and information.

The COMPUSEC objective is to employ countermeasures designed for the protection of confidentiality, integrity, availability, authentication, and non-repudiation of United States (US) government information processed by AF ISs.

1.2. Applicability. This publication applies to all AF ISs and devices used to process, store, display, transmit, or protect AF information, regardless of classification or sensitivity, unless exempted.

1.2.1. This publication is binding on all military, civilian and contract employees, who develop, acquire, deliver, use, operate, or manage AF Information Technology (IT). This publication applies to all AF IT used to receive, process, store, display, transmit, or protect

AF information, regardless of classification or sensitivity. AF IT includes but is not limited to ISs (major applications and enclaves), Platform Information Technology (PIT) and PIT systems, IT services (internal and external), standalone systems, and IT products (software, hardware, and applications).

1.2.2. More restrictive Federal, DoD, AF guidance take precedence over this publication.

1.2.3. This publication and implementation guidance identified within is not applicable to

Special Access Programs or Intelligence Community (IC) ISs to include Sensitive

Compartmented Information (SCI) ISs. Refer to the IC Directive (ICD) 503, Intelligence

Community Information Technology Systems Security Risk Management, Certification and

Accreditation, and AFI 16-701, Management, Administration and Oversight of Special

Access Programs.

1.3. Exceptions. Document exceptions and deviations to guidance in this publication affecting

ISs as part of the applicable IS security authorization package, IAW AFI 17-101, The Risk

Management Framework (RMF) for Air Force Information Technology (IT). Submit modifications, exceptions, and deviations through the system/enclave change management process.

1.3.1. Process equipment acquisition waiver requests IAW AFMAN 17-1203, Information

Technology (IT) Asset Management (ITAM).

1.3.2. See AFI 17-100, Air Force Information Technology (IT) Service Management, for

Commercial Internet Service Provider (CISP) waiver guidance.

1.3.3. See AFMAN 17-1303, Cybersecurity Workforce Improvement Program, for certification requirement waiver guidance.

AFMAN17-1301 10 FEBRUARY 2017 7

Chapter 2

ROLES AND RESPONSIBILITIES

2.1. AFSPC Cyberspace Support Squadron (AFSPC CYSS). Provides cyber networking expertise to HQ AFSPC for COMPUSEC activities and functions.

2.1.1. Provides COMPUSEC policy and technical subject matter expertise for the AF

Enterprise.

2.1.2. Provides field support and program management for COMPUSEC to SAF CIO/A6, AFSPC, and all MAJCOMs/FOAs/DRUs. Supports SAF/CIO A6 and AFSPC cybersecurity initiatives. Reviews, evaluates, and interprets AF COMPUSEC doctrine, policy, and procedures. Develops/coordinates recommendations on implementation of the doctrine, policy, and procedures to AFSPC A2/3/6.

2.1.3. Coordinates with the AFSPC Cybersecurity Division as required and accomplishes other roles and responsibilities as directed by HQ AFSPC.

2.2. Air Force Life Cycle Management Center (AFLCMC), Cryptologic and Cyber

Systems Division, Responsive Cyber Acquisition Branch, Information Assurance

Section(AFLCMC/HNCYP). AF Public Key Infrastructure (PKI) System Program Office

(SPO). Manages the AF PKI and carries out tasks/actions as the SAF/CIO A6 PKI Management

Authority (PMA) and/or the pertinent DoD organizations direct. This includes the implementation, operation, and sustainment of PKIs and all associated enabling efforts.

2.2.1. Identifies all PKI requirements to SAF/CIO A6.

2.2.2. Integrates PKI into existing ISs as identified in the PKI implementation and program plans. Ensures future IS programs are fully compatible and interoperable with the DoD PKI, as required by DoD and Air Force policy.

2.2.3. Assists the MAJCOMs and supported Combatant Commands (COCOMs) with PK

Enablement (PKE) of systems.

2.2.4. Provides PKI Helpdesk and field support to the AF.

2.2.5. Develops and sustains new PKI capabilities for the Air Force and/or for DoD.

2.2.6. Maintains and enforces the integrity of the PKI and its use.

2.3. Wing Cybersecurity Office (WCO). The WCO addresses all COMPUSEC requirements on the base, including those of tenant units (i.e., FOAs, DRUs, and other MAJCOM units), unless formal agreements exist IAW AFI 17-130. Personnel assigned to the WCO will:

2.3.1. Evaluate modifications, exceptions, and deviations to ISs for accuracy and completeness before forwarding to the appropriate agency; see Chapter 1. (T-1).

2.3.2. Train designated representatives of the Commanders Support Staff (CSS) on Air Force

Network (AFNet) account management and COMPUSEC administrative processes and procedures; conduct annual or “as needed” refresher training; see Chapter 3. (T-1).

2.3.3. Consult with host or MAJCOM Foreign Disclosure Office (FDO) before authorizing

Foreign National/Local National (FN/LN) access to ISs; see Chapter 4. (T-1).

8 AFMAN17-1301 10 FEBRUARY 2017

2.3.4. Conduct COMPUSEC assessments; see Chapter 7. (T-1).

2.3.5. Assist with assessment or analysis supporting Vulnerability Management; see

Chapter 3 and AFI 17-100. (T-1).

2.3.6. Coordinate with the system/enclave ISSO/ISSM before deciding whether to sanitize media for reuse or disposal; see Chapter 6. (T-0).

2.4. Organizational Commander (or Equivalent). Maintains the COMPUSEC program IAW this publication, ensuring AF ISs operate effectively by protecting and maintaining the confidentiality, integrity, and availability of IS resources and information processed throughout the system’s life cycle. Organizational commanders will:

2.4.1. Suspend access to unclassified and classified ISs when actions threaten or damage AF

ISs; see Chapter 4. (T-0).

2.4.2. Ensure proper procedures are followed in response to classified information spillages affecting AF ISs; see Chapter 5. (T-0).

2.4.3. Review all approved removable media waivers semi-annually to ensure continuous validation of mission requirements; see Chapter 5. (T-0).

2.4.4. Endorse follow-up COMPUSEC assessment reports validating the status of open findings; see Chapter 7. (T-1).

2.5. Information System Security Manager (ISSM). An ISSM (formerly an Information

Assurance Manager [IAM]) is responsible for the cybersecurity of a program, organization, system, or enclave and provides direction to the Information System Security Officer (ISSO)

(formerly a system Information Assurance Officer [IAO]). Duties of the ISSM are outlined in

DoDI 8500.01, Cybersecurity, AFI 17-130, and AFI 17-101. ISSMs will:

2.5.1. Obtain required training and maintain applicable cybersecurity workforce certification; see Chapter 3. (T-0).

2.5.2. Perform risk identification and assessment activities supporting the change management activities for the system/enclave; see Chapter 3. (T-0).

2.5.3. Maintain approval and inventory documentation for Authorizing Official (AO)-authorized personally-owned hardware and software; see Chapter 5. (T-1).

2.5.4. Process removable media waivers; see Chapter 5. (T-1).

2.5.5. Protect collaborative computing devices used in classified environments; see Chapter

5. (T-0).

2.5.6. Participate in remanence security (REMSEC) risk management processes; see

Chapter 6. (T-1).

2.5.7. Conduct annual unit/organization COMPUSEC self-assessments using the AFMAN

17-1301 COMPUSEC Self-Assessment Communicator (SAC) located in the AF Inspector

General (IG) Management Internal Control Toolset (MICT). (T-1).

2.5.8. Assist with AFMAN 17-1301 COMPUSEC SAC review and remediation activities;

see Chapter 7. (T-1).

AFMAN17-1301 10 FEBRUARY 2017 9

2.5.9. FNs/LNs are not authorized to hold ISSM positions IAW DoD 8570.01-M, IA

Workforce Improvement Program. (T-0).

2.6. Information System Security Officer (ISSO). An ISSO (formerly a system IAO) is responsible for the technical implementation of a cybersecurity program. When circumstances warrant, a single individual may fulfill both the ISSM and the ISSO roles. DoDI 8500.01, AFI

17-130, and AFI 17-101 outline the duties of the ISSO. ISSOs will:

2.6.1. Provide protection from threats through implementation of technical and physical security mechanisms; see Chapter 5. (T-0).

2.6.2. Maintain approval and inventory documentation for AO-authorized personally-owned hardware and software; see Chapter 5. (T-1).

2.6.3. Participate in REMSEC risk management processes; see Chapter 6. (T-1).

2.6.4. Execute procedures that identify the residual risk and risk tolerance; see Chapter 6.

(T-0).

2.6.5. Conduct annual COMPUSEC self-assessments using the AFMAN 17-1301

COMPUSEC SAC located in the IG MICT; see Chapter 7. (T-1).

2.6.6. Assist with AFMAN 17-1301 COMPUSEC SAC review and remediation activities;

see Chapter 7. (T-1).

2.6.7. FNs/LNs are not authorized to hold ISSO positions IAW DoDI 8500.01. (T-0).

2.7. Commanders Support Staff (CSS). Organizations implement and enforce AFNet account management and COMPUSEC administrative processes and procedures using the guidance within this instruction IAW AFI 17-130. Personnel performing administrative cybersecurity functions will:

2.7.1. Verify user compliance with annual CyberAwareness Challenge training; see Chapter

4. (T-0).

2.7.2. Maintain AFNet network access documentation; see Chapter 4. (T-0).

2.7.3. Assist the WCO with administrative cybersecurity functions (administrative tasking orders, in/out-processing checklists, distribute user training materials, etc.); see Chapter 5.

(T-0).

2.7.4. Conduct annual unit/organization self-assessments using the AFMAN 17-1301

COMPUSEC SAC located in the IG MICT; see Chapter 7. (T-1).

10 AFMAN17-1301 10 FEBRUARY 2017

Chapter 3

TRAINING AND RESOURCES

3.1. General. COMPUSEC includes all measures to safeguard ISs and information against sabotage, tampering, denial of service, espionage, fraud, misappropriation, misuse, or release to unauthorized persons. Successful implementation of COMPUSEC requires adequate training and proper application of cybersecurity/IA resources.

3.2. COMPUSEC Training Requirements

3.2.1. Military personnel in the 3D0X3 career field attend technical school training in the following courses. Upon successful completion of the final course, trainees are awarded a 3-skill level and a DoD 8570.01-M certification as an IA Management (IAM) Level I/IA

Technical (IAT) Level II. . Current course identification, status, length, and prerequisite information may be found at the Education and Training Course Announcements website at https://etca.randolph.af.mil/default1.asp under “AETC.”

3.2.1.1. E3AQR3D033, IT Fundamentals Basic, at Keesler AFB.

3.2.1.2. E3AQR3D033, Cyber Surety, at Keesler AFB.

3.2.1.3. E3ABR3D033, Cyber Surety Security+ Certification, at Keesler AFB.

3.2.2. All civilian, military, and contractor personnel performing ISSM duties:

3.2.2.1. Attend the Air Education and Training Command (AETC)- formal training course E3AZR3D053, Information System Security Manager (ISSM) at Keesler AFB within 6 months of assuming ISSM duties.

3.2.2.2. Complete the Air Force Qualification Training Package (AFQTP) 3D0X3-

211RA, Information Assurance Manager Handbook. Use the AFQTP:

3.2.2.2.1. As an interim training measure while an individual waits for a class date for the ISSM course.

3.2.2.2.2. As refresher training for individuals that have ISSM experience but have not performed duties as an ISSM within 3 years.

3.2.2.2.3. Contractor personnel may substitute the AFQTP when contract limitations do not allow ISSM course attendance.

3.2.2.3. Follow the Cybersecurity workforce security certification requirements relative to the function, category (technical or managerial), and level of the position as specified in AFMAN 17-1303, DoD Directive (DoDD) 8140.01, Cyberspace Workforce

Management, and DoD 8570.01-M, Information Assurance Workforce Improvement

Program. Additional training and/or certifications may be necessary depending on specific requirements of the ISSM position. More information on DoD-approved 8570 baseline certifications is available in an extension to Appendix 3 of DoD 8570.01-M on the Defense Information Systems Agency (DISA) Information Assurance Support

Environment (IASE) website (http://iase.disa.mil/iawip/Pages/iabaseline.aspx).

https://etca.randolph.af.mil/default1.asp http://iase.disa.mil/iawip/Pages/iabaseline.aspx

AFMAN17-1301 10 FEBRUARY 2017 11

3.2.3. Cybersecurity Workforce. Training and certification of cybersecurity personnel depend upon the types of tasks assigned by the organizational commander. Determine the tasks performed and consult DoD 8570.01-M and AFMAN 17-1303 for training and certification requirements.

3.2.3.1. Cybersecurity Workforce categories are IAT and IAM. Specialties are

Computer Network Defense Service Providers (CND-SPs) and IA System Architects and

Engineers (IASAEs).

3.2.3.2. Cybersecurity Workforce personnel performing IAT/IAM level tasks require the appropriate certifications.

3.2.4. CSS Training. The WCO provides direction, oversight, and annual training for designated representatives of the CSS. The WCO locally develops the CSS cybersecurity training programs and includes the following COMPUSEC-specific items:

3.2.4.1. Authorized users, access requirements, and access documentation.

3.2.4.2. Account management and trouble reporting functions (including IAO

Express/Enterprise Service Desk [ESD]).

3.2.4.3. SIPRNet token recovery actions.

3.3. Information Assurance Collaborative Environment (IACE). The AF IACE serves as the primary cybersecurity/IA support resource for WCO and managers, providing a collaborative one-stop-shop for cybersecurity/IA ideas, questions, discussions, and hosts dynamic content for information sharing (https://cs.eis.af.mil/sites/10060).

For classified content, the IACE- Secret Internet Protocol Router Network (SIPRNet) (IACE-S) is available at http://intelshare.intelink.sgov.gov/sites/af_cybersecurity/SitePages/Home.aspx.

3.4. Methods and Procedures Technical Orders (MPTO). MPTOs provide procedural guidance to the cybersecurity workforce to implement and manage methods and processes pertaining to COMPUSEC policy. Specific COMPUSEC-related MPTOs are MPTO 00-33B-

5004, Access Control for Information Systems; MPTO 00-33B-5006, End Point Security for

Information Systems; and MPTO 00-33B-5008, Remanence Security for Information Systems.

Obtain MPTOs via the organizational Technical Order Distribution Account (TODA) on

Enhanced Technical Information Management System (ETIMS) https://www.my.af.mil/etims/ETIMS/index.jsp).

3.5. Information Technology Asset Procurement. Comply with evaluation and validation requirements in DoDI 8500.01 for all IT services, hardware, firmware, software components, or products incorporated into DoD ISs.

3.5.1. Follow the guidance in AFMAN 17-1203 and the AF Information Technology

Commodity Council (ITCC) guidance available on the AF Portal or AFWAY

(https://www.afway.af.mil/) for procurement activities of all IT hardware, cellular, and peripheral devices (e.g., desktops, laptops, servers, commercial mobile devices [CMDs], multifunction devices [MFDs] printers, scanners, and wireless peripheral devices).

3.5.2. Comply with the evaluation and validation requirements of Committee on National

Security Systems Policy (CNSSP) 11, National Policy Governing the Acquisition of https://cs.eis.af.mil/sites/10060 https://www.my.af.mil/etims/ETIMS/index.jsp https://www.afway.af.mil/

12 AFMAN17-1301 10 FEBRUARY 2017

Information Assurance (IA) and IA-Enabled Information Technology Products, for all IA and

IA-enabled products.

3.5.3. Life Cycle Management. Procure products and adopt risk-based program management IAW AFI 63-101/20-101, Integrated Life Cycle Management.

3.5.4. Unified Capabilities (UC). Modernizing IT capabilities while aligning with joint solutions remain two of the AF's key goals. AFMAN 17-1202, Collaboration Services and

Voice Systems Management, and DoDI 8100.04, DoD Unified Capabilities (UC), provide guidance related to Voice and Video over Internet Protocol (VVoIP), Video

Teleconferencing (VTC), and interoperability.

3.5.4.1. In accordance with DoDI 8100.04, use/obtain UC products certified by the DISA

Joint Interoperability Test Command (JITC), JITC certifies interoperability and the UC-implementing DoD component AO or the DISA Certifying Authority (CA) certifies for

Cybersecurity under RMF. Approved products are listed on the DISA UC Approved

Products List (APL) (https://aplits.disa.mil/processAPList.action) and should be added to the enclave security authorization package and assessed for Cybersecurity through the

RMF process.

3.5.4.2. As a general rule, Section 508-compatible Voice over Internet Protocol (VoIP) devices are not listed on the DISA UC APL unless the vendor has included the assistive technology (AT) end device as part of the VoIP system’s evaluation package.

Organizations may request that the vendor add the product to the current UC APL certification package and request a “desktop review” from the DISA Unified Capabilities

Certification Office (UCCO). The DISA UCCO (Email: disa.meade.ns.list.unified-capabilities-certification-office@mail.mil) has a listing of all product representatives.

This review ensures the product operates with the current fielded VoIP system. If the vendor is unable or unwilling to add the AT product to the UC APL certification, identify compliance with AFMAN 17-1202 in the enclave/IS security authorization package.

3.5.4.3. All Air Force VTC suites are transitioning off the Integrated Services Digital

Network (ISDN)-based Defense Information System Network (DISN) Video Service-

Global (DVS-G) to Global Video Services (GVS), IAW Maintenance Tasking Order

(MTO) 2014-295-001. AF organizations should not expend funds on the upgrade, replacement, and acquisition of voice, video, and/or data services equipment outside of the GVS program.

3.5.5. Cloud Services. Acquire and implement private and/or public cloud computing services in support of the Air Force Information Network (AFIN) IAW AFI 17-100.

3.5.6. Foreign produced products. Under Title 10, United States Code (U.S.C.), Section

2533a (Requirement to Buy Certain Articles from American Sources; Exceptions) and reflected in Federal Acquisition Regulation (FAR) Subpart 25.1, Buy American – Supplies,

25.103 Exceptions, and Defense Federal Acquisition Regulation Supplement (DFARS) Part

225 – Foreign Acquisition, Subpart 225.1, Buy American – Supplies, 225.103 Exceptions, there are exceptions allowing the purchase of foreign-made commercial technology. For guidance go to https://www.acquisition.gov/ to access the FAR and DFARS (under

“Supplemental Regulations”).

https://aplits.disa.mil/processAPList.action mailto:disa.meade.ns.list.unified-capabilities-certification-office@mail.mil mailto:disa.meade.ns.list.unified-capabilities-certification-office@mail.mil https://www.acquisition.gov/

AFMAN17-1301 10 FEBRUARY 2017 13

3.5.6.1. Use an approved importer or through a World Trade Organization Government

Procurement Agreement (WTO GPA) country. AFWay, ITCC, and General Services

Administration (GSA) offer foreign-made products secured from an approved importer or

WTO GPA.

3.5.6.2. Countries barred from providing products and services are listed on the

“Domestic Preference Restrictions” table available at the Defense Procurement and

Acquisition Policy website under the “Restrictions on Purchasing from Non-U.S.

Sources” area

(http://www.acq.osd.mil/dpap/cpic/ic/restrictions_on_purchases_from_non-us_sources.html).

3.6. Configuration Management Resources. Securely configure and implement all IT products. Cybersecurity/IA reference documents, such as National Institute of Standards and

Technology (NIST) Special Publications (SP), DISA Security Technical Implementation Guides

(STIGs), DISA Security Requirements Guides (SRGs), National Security Agency (NSA)

Security Configuration Guides, AF Technical Orders (TOs), and other specialized publications are used for the security configuration and implementation guidance. Apply these reference documents IAW DoDI 85xx.xx series, AFI 33-xxx series, and AFI 17-xxx series publications to establish and maintain a minimum baseline security configuration and posture. Document all configuration changes with the enclave/system ISSM in the IS security authorization package

IAW AFI 17-101 and the system change management process.

http://www.acq.osd.mil/dpap/cpic/ic/restrictions_on_purchases_from_non-us_sources.html http://www.acq.osd.mil/dpap/cpic/ic/restrictions_on_purchases_from_non-us_sources.html

14 AFMAN17-1301 10 FEBRUARY 2017

Chapter 4

INFORMATION SYSTEM ACCESS CONTROL

4.1. Introduction. AF ISs connect to the DoD Information Network (DoDIN) subnetworks

(e.g., SIPRNet, Non-classified Internet Protocol Router Network [NIPRNet], GVS, etc.) IAW

Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6211.02, Defense Information Systems

Network (DISN) Responsibilities. Every individual who has access to standalone systems, specialized/functional ISs, enterprise ISs, and/or mission systems is an IS user.

4.1.1. Access to AF ISs is a revocable privilege and is granted to individuals based on need to know and IAW National Security Telecommunications and Information Systems Security

Policy (NSTISSP) No. 200, National Policy on Controlled Access Protection; DoD 5200.2-

R, Personnel Security Program; and CJCSI 6510.01, Information Assurance (IA) and

Support to Computer Network Defense (CND). Follow procedural guidance in MPTO 00-

33B-5004.

4.1.2. The Information System Owner (ISO) ensures methods are in place to verify user access requests before granting IS access. Address delegation of authority for specific system/enclave access in the system authorization package.

4.2. Authorized Users. An authorized user is any appropriately cleared individual required to access a DoD IS to carry out or assist in a lawful and authorized governmental function.

Configure authorized user account creation and administration using role-based access schemes;

see AFMAN 17-1201, User Responsibilities and Guidance for Information Systems. Consult

AFI 31-501, Personnel Security Program Management, for investigation requirements for access to an Automated Information System (AIS) position, as outlined in DoD 5200.2-R, Appendix 10.

4.2.1. All authorized users (e.g., military, civilian, contractor, temporary employees, volunteers, interns, key spouses, and American Red Cross personnel) will complete

CyberAwareness Challenge training prior to being granted access to an IS. (T-0). Users annually re-accomplish CyberAwareness Challenge training; organizations maintain compliance IAW DoD 8570.01-M. Authorized user access to unclassified and classified ISs based on the assigned duties and the Automated Data Processing (ADP) position categories identified in DoD 5200.2-R, Appendix 10: Category ADP-III (also referred to as IT-III) are nonsensitive positions.

4.2.1.1. CyberAwareness Challenge training is located on the Advanced Distributed

Learning Service (ADLS) accessible via the AF Portal.

4.2.1.2. A publically accessible version of the CyberAwareness Challenge training is located on the DISA website (http://iase.disa.mil). Users without an ADLS account may substitute this training for initial network access.

4.2.1.3. When a user requires a new/modification to his/her account (due to change of station or assignment, Temporary Duty [TDY], etc.), the gaining CSS verifies the user meets access requirements before granting access to the IS. Users are not required to retake the CyberAwareness Challenge training provided the user has a valid and current

(within a year) course completion record. Verification of completion may be http://iase.disa.mil/

AFMAN17-1301 10 FEBRUARY 2017 15

accomplished using the printed or electronic copy of CyberAwareness Challenge training certificate from DISA or ADLS or confirmation by the CSS.

4.2.1.4. System access by authorized users requires PKI access methods as specified in

DoDI 8520.03, Identity Authentication for Information Systems, and CJCSI 6510.01.

4.2.2. Privileged User. Grant privileged access to unclassified and classified ISs based on the assigned duties and the ADP position categories identified in DoD 5200.2-R, Appendix

10: Category ADP-I (also referred to as IT-I) are Privileged positions and Category ADP-II

(also referred to as IT-II) are Limited Privileged positions.

4.2.2.1. Administrative and privileged accounts require PKI user authentication IAW

United States Cyber Command (USCYBERCOM) Tasking Order (TASKORD) 2015-

0102, Implementation and Reporting of DoD Public Key Infrastructure (PKI) System

Administrator and Privileged User Authentication.

4.2.2.2. Privileged users should meet all the requirements of an authorized user as specified in AFMAN 17-1303 and paragraph 4.2.1.

4.2.2.3. Privileged users are established and administered with a role-based access scheme IAW the system policy and Chapter 3 of DoD 5200.2-R and AFMAN 17-1303.

4.2.2.4. System access requires PKI access methods as specified in DoDI 8520.03 and

CJCSI 6510.01.

4.2.2.5. Privileged users access only data, control information, software, hardware, and firmware that they are authorized access and fulfills the “need to know” requirement.

4.2.2.6. To maintain separation of duties and least privilege, users maintain separate accounts, a user account for day-to-day or “non-privileged” functions, and a privileged account for administrative functions IAW DoD 8570.01-M.

4.2.2.7. Prohibit sharing of privileged user accounts and credentials between users.

4.2.2.8. Configure privileged user remote access IAW the applicable DISA STIGs (i.e., Enclave, Operating System, Remote Access, Directory Services Domain, etc.) and the selected security controls within the RMF package.

4.2.2.9. Privileged users are position-certified IAW DoD 8570.01-M and qualified IAW

AFMAN 17-1303.

4.2.2.10. Privileged users complete an Information System Privileged Access Agreement and Acknowledgement of Responsibilities IAW DoD 8570.01-M (Appendix 4).

4.2.3. Foreign Nationals/Local Nationals. A FN/LN user is anyone who is not a US citizen or permanent resident, IAW Title 8, Code of Federal Regulations, Aliens and Nationality.

4.2.3.1. The MAJCOM FDO determines authorized and privileged “need to know” for the administrative access and control of information, software, hardware and firmware to include controlled unclassified information (CUI) and classified information, IAW DoD

Manual (DoDM) 5200.01, Volume 4, DoD Information Security Program: Controlled

Unclassified Information (CUI).

4.2.3.1.1. WCOs consult the Host or MAJCOM FDO and applicable ISSM before authorizing access by FN/LN users to ISs processing, storing, or transmitting

16 AFMAN17-1301 10 FEBRUARY 2017

classified and CUI. Note: Specific FN/LN access guidance can be found in the following publications: MPTO 00-33A-1301, Foreign National NIPRNet Access

Core Services; MPTO 00-33B-5004; MPTO 00-33B-5006; MPTO 00-33A-1202, Air

Force Network Account Management; MPTO 00-33D-2001, AFNET Enterprise

Services Naming Conventions; AFI 16-107, Military Personnel Exchange Program;

AFI 16-201, Air Force Foreign Disclosure and Technology Transfer Program;

DoDD 5230.25, Withholding of Unclassified Technical Data from Public Disclosure;

DoDD 5400.7, DoD Freedom of Information Act (FOIA) Program; DoD 5400.7-

R_AFMAN 33-302, Freedom of Information Act Program; AFI 33-332, Air Force

Privacy and Civil Liberties Program; DoDD 5230.11, Disclosure of Classified

Military Information to Foreign Governments and International Organizations; and

DoDD 5230.20, Visits and Assignments of Foreign Nationals.

4.2.3.1.2. Pursuant to applicable host-nation agreements, FN/LN privileged users are certified to baseline computing environment (CE) IAW DoD 8570.01-M. If privileged access is required to an IS, restrict FN/LN user access to IAT I/II level positions and only under the immediate supervision of a US citizen. Furthermore, document access in the IS security assessment package.

4.2.3.1.3. At the discretion of the ISO, FN/LN system access requires PKI access methods as specified in Chapter 8.

4.2.3.1.4. Sanitize or configure classified ISs to restrict access by FN/LNs to only classified information authorized for disclosure to the FN/LNs government or coalition, as necessary to fulfill the terms of their assignments IAW applicable host

MAJCOM FDO requirements.

4.2.3.1.5. Other Considerations. Non-US citizens who are permanent legal residents are required to meet the same requirements of any US citizen for access to the unclassified network or system, as outlined in paragraph 4.2.1.

4.2.3.2. Before authorizing FN/LN access to unclassified ISs, the ISO ensures compliance with the IS access requirements in MPTO 00-33A-1301.

4.2.4. Group Accounts. The Enterprise AO (or applicable AO if entirely within their boundary) is the approving authority for group accounts and may require a Defense

Information Assurance Security Accreditation Working Group (DSAWG) waiver IAW

CJCSI 6510.01 and DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK)

Enabling. Document authorization in the system/enclave authorization package.

4.2.4.1. Requests for group accounts using individual/unique authentication should be submitted via email to AFSPC CYSS/CYZ PKI (afspc.cyss.cys.2@us.af.mil).

4.2.4.2. Group accounts that do not use an individual/unique authenticator require

DSAWG approval. To submit requests to the DSAWG for approval, contact AFSPC

CYSS/CYZ PKI (afspc.cyss.cys.2@us.af.mil).

mailto:afspc.cyss.cys.2@us.af.mil

AFMAN17-1301 10 FEBRUARY 2017 17

4.2.5. Temporary and Volunteer Accounts. Grant only unclassified IS access to temporary employees and volunteer personnel in support of their assigned duties.

4.2.5.1. A volunteer is any individual (including key spouses) authorized to be DoD volunteers as defined in DoDI 1100.21, Voluntary Services in the Department of Defense.

Restrict volunteers to ADP-III/IT-III level positions IAW DoDI 5200.2-R, Appendix 10.

4.2.5.2. Temporary employees and volunteers are required to meet the requirements as specified in paragraph 4.2.1.

4.2.5.3. Temporary employees and volunteers require PKI access as outlined in

Chapter 8.

4.3. Required Account Access Documentation

4.3.1. When required by the ISO for IS access, the CSS or ISSO ensures the DD Form 2875, System Authorization Access Request (SAAR), is completed and signed. Document access requests, Annual Information Awareness (CyberAwareness Challenge) training completion, and justification for access and clearance/background investigation verification as referenced by DoD 5200.2-R and AFI 31-501. DD Form 2875 signatures can be “wet” or digitally signed. Do not combine multiple system access requests on the same DD Form 2875.

4.3.1.1. CSSs/ISSOs, in coordination with the organizational security manager, verify user background investigation requirements IAW DoD 5200.2-R.

4.3.1.2. The ISSO/ISSM (referred to as the “Information Assurance Officer” on the DD

Form 2875) retains the DD Form 2875 IAW instructions outlined on the form for non-

AFNet ISs. The CSS retains the DD Form 2875 according to the instructions on the form for AFNet ISs.

4.3.1.2.1. Original DD Form 2875s for unprivileged AFNet accounts may be transferred when duty assignments change; the gaining unit’s CSS may use local methods to update duty information in the “IAO Express” tool and shared drive access requirements. The losing unit’s CSS ensures termination of shared drive access prior to users out-processing. Changes to privileged account access requirements require a new DD Form 2875.

4.3.1.2.2. Re-accomplish DD Form 2875s for AFNet-SIPRNet (AFNet-S) accounts when access requirements change.

4.3.2. In accordance with AFMAN 17-1201, users of all authorized IS devices (to include

Mobile Computing Devices) sign the standardized AF Form 4394, Air Force User

Agreement Statement-Notice and Consent Provision, prior to initial IS access. For wireless devices, users complete the standardized AF Form 4433, US Air Force Unclassified Wireless

Mobile Device User Agreement. Maintain copies of signed AF Forms 4433 within the CSS.

4.3.3. Access to classified ISs also requires a Standard Form (SF) 312, Nondisclosure

Agreement, IAW AFI 16-1404, Air Force Information Security Program.

4.4. Token Access. IAW DoDI 8520.02 and DoDI 8520.03, users authenticating to DoD networks require the use of a hardware token. Follow guidance in Chapter 8 to obtain a hardware token prior to being granted access to AFNet and AFNet-S Directory Services

Domains and authenticating to NIPRNet or SIPRNet PK-Enabled websites.

18 AFMAN17-1301 10 FEBRUARY 2017

4.5. Loss of Access. Access to an AF IS is a privilege and continued access is contingent on personnel actions, changes in need to know, or operational necessity; see AFMAN 17-1201. The

ISO has the authority to re-instate users who have lost access.

4.5.1. Specific procedural information for account disabling is located in MPTO 00-33B-

5004.

4.5.2. Failure to complete annual CyberAwareness Challenge training results in immediate suspension of access to unclassified and classified ISs.

4.5.3. Actions that threaten or damage AF ISs may result in immediate suspension of access to unclassified and classified ISs IAW CJCSI 6510.01 and DoD 5200.2-R. Deliberate inappropriate use of user accounts or systems may result in administrative disciplinary action

IAW AFMAN 17-1201.

4.5.3.1. If an individual’s clearance is suspended, denied, or revoked, immediately suspend access to classified ISs. Commanders should review circumstances surrounding the suspension, denial, or revocation to determine if continued access to unclassified systems is warranted and if revocation of the hardware token is required. Commanders may provide recommendations regarding user access to the ISO.

4.5.3.2. If an individual violates the IS terms of use, commanders should consider suspending access pending re-accomplishment of CyberAwareness Challenge training.

Additional restrictions on reinstatements for classified ISs are determined locally and should follow the guidelines of DoD 5200.2-R.

4.6. Account Management. AF direction is to use PKI-based identification and authentication

IAW DoDI 8520.02, DoDI 8520.03 and the USCYBERCOM Communications Tasking Order

(CTO) 07-015, Public Key Infrastructure (PKI) Implementation, Phase 2

(https://www.cybercom.mil/J3/orders/Pages/CTOs.aspx). Manage all user accounts using applicable system configuration guidance; follow TOs published by AFSPC (e.g., MPTO 00-

33B-5004, MPTO 00-33A-1202 [for AFNet accounts], and the applicable DISA STIGs [enclave, application security, operating system, database, etc.]).

4.6.1. ISSM/ISSOs implement automated IS controls to check and disable IS user accounts that have been dormant more than 30 days IAW CJCSI 6510.01.

4.6.1.1. AF CIO Exception: Disable National Guard and Reserve member IS user accounts only after 90 days of inactivity.

4.6.1.2. Document system specific IS user account disabling requirements after periods of inactivity in the IS security authorization package.

4.6.1.3. ISSMs provide a monthly list of disabled SIPRNet accounts to the base Local

Registration Authority (LRA) for SIPRNet hardware token recovery actions; see

Chapter 8.

4.6.2. Delete unnecessary (to include service accounts) and/or default accounts and change all factory default or user-generated passwords included in a newly acquired system

(software or hardware) IAW the configuration information in the IS security authorization package before allowing any user access to the system.

4.6.2.1. Rename default accounts that cannot be deleted, IAW applicable DISA STIGs.

https://www.cybercom.mil/J3/orders/Pages/CTOs.aspx

AFMAN17-1301 10 FEBRUARY 2017 19

4.6.2.2. Do not execute root-level access in IS applications.

4.6.2.3. Disable/deactivate user accounts (do not delete/deprovision) when users are unable to remotely access their accounts due to an extended absence or when a user is suspended from work, IS access is revoked for any reason, or the security clearance is suspended as specified in paragraph 4.5.3.

20 AFMAN17-1301 10 FEBRUARY 2017

Chapter 5

END POINT SECURITY

5.1. Introduction. End point security provides the basis for overall protection of AF-controlled

IT assets. Follow CJCSI 6510.01 on the use of DoD-provided, enterprise-wide automated tools/solutions (e.g., Host Based Security System [HBSS]) to ensure interoperability with DoD and AF provided enterprise-wide solutions for remediation of vulnerabilities for endpoint devices.

5.2. General Protection. All authorized users should protect networked and/or standalone ISs against tampering, theft, and loss. Protect ISs from insider and outsider threats by controlling physical access to the facilities and data by implementing procedures identified in Joint, DoD, AF publications, and organizationally created procedures. See AFI 31-101, Integrated Defense, for physical access security guidance. End point security procedures are located in MPTO 00-

33B-5006.

5.2.1. Identify and authenticate users before gaining access to any government IS IAW guidance in Chapter 4.

5.2.2. ISSM/ISSO provide protection from threats by ensuring proper configuration of technical security mechanisms and establishing physical controls for the removal and secure storage of information from unattended ISs (e.g., Common Access Card [CAC] removal lock feature, keyboard locks, secure screen savers, add-on security software). This is done IAW the DISA Operating Systems STIGs and the system security plan (SSP) (found in the system authorization package in the Enterprise Mission Assurance Support Service [eMASS]). See

NIST SP 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, for more information about SSPs.

5.2.3. Treat devices released to or potentially accessed by unauthorized personnel (outside

DoD control) as an untrusted device until IS security policy requirements are re-established and validated IAW the DISA Removable Media Storage and External Connections STIG.

5.2.4. Protect devices at the applicable security classification of the information stored in the device IAW CJCSI 6510.01 and this publication.

5.2.5. Protect display devices to prevent inadvertent viewing of classified and controlled or sensitive information by unauthorized users (e.g., away from windows, doorways, public areas); for more information see the DISA Traditional Security Checklist.

5.2.6. Control viewing of US-Only ISs and equipment by FNs/LNs IAW CJCSI 6510.01; see the DISA Traditional Security Checklist.

5.2.7. Ensure transmission of sensitive information is encrypted using NIST-certified cryptography at a minimum IAW CJCSI 6510.01.

5.2.8. Ensure the transmission of classified information is encrypted using NSA-approved cryptography IAW AFMAN 17-1302, Communications Security (COMSEC) Operations, and

CJCSI 6510.01.

AFMAN17-1301 10 FEBRUARY 2017 21

5.2.9. In areas where classified information is processed, ensure ISs meet TEMPEST requirements IAW Air Force Systems Security Instruction (AFSSI) 7700, Emission Security

(to become AFMAN 17-1305).

5.2.10. Appropriately mark and label IT devices IAW the highest level of classification processed or displayed on the device IAW DoDM 5200.01, Volume 2 DoD Information

Security Program: Marking of Classified Information, and DoD 5220.22-M, National

Industrial Security Program Operating Manual (NISPOM), if appropriate.

5.2.10.1. Display/peripheral devices (e.g., monitors, projectors, televisions) are required to be either physically marked or technically configured to display the classification banner.

5.2.10.1.1. Display devices located within the same classification environment or mixed environments attached to approved Keyboard, Video, Monitor (KVM) device are not required to be physically labeled if the desktop backgrounds are configured through the IS to identify the classification level.

5.2.10.1.2. Mark and label all KVM switches (regardless of classification environment) to identify the switch position and the associated classification of the connected systems IAW the DISA Keyboard, Video, Mouse Switch Security STIG.

5.2.10.2. Physically mark and label all mobile computing devices with the potential to be located/used in mixed environments or publically accessible areas with the highest classification level of the information approved to be processed by the device. If necessary due to mission or operating environment requirements, coordinate with WCO and Wing Information Protection (IP) Office in developing alternate marking and labeling methods.

5.2.11. Contact the organizational security manager for devices involved in data spillage or security incidents IAW AFI 16-1404. For REMSEC guidance, see Chapter 6.

5.3. Software Security. The ISSM ensures all software is included in the IS security authorization package IAW AFI 17-101 and CJCSI 6510.01. Comply with AFMAN 17-1203 for software accountability guidance.

5.3.1. Freeware, public domain software, shareware originating from questionable or unknown sources (e.g., World Wide Websites), and Peer-to-Peer file sharing software are highly susceptible to malicious logic and can only be used after a risk assessment (see AFI

17-101) has been conducted.

5.3.2. Prohibit use of trial or demonstration software due to its unreliability and potential source-code flaws.

5.4. Malicious Logic Protection. Protect ISs from malicious logic (e.g., virus, worm, Trojan horse) attacks by applying a mix of human and technological preventative measures IAW the

DISA STIGs and CJCSI 6510.01.

5.4.1. Implement antivirus software with current signature files IAW DoD Antivirus

Security Guidance (http://www.disa.mil/cybersecurity/network-defense/antivirus). The

ISSM documents a process for updating devices that are not able to receive automatic updates (i.e., standalone systems, TDY laptops, etc.) in the SSP IAW with the NIST SP 800-

53.

http://www.disa.mil/cybersecurity/network-defense/antivirus

22 AFMAN17-1301 10 FEBRUARY 2017

5.4.2. Use only security patches and antivirus tools/signature files/data files obtained from the Defense Asset Distribution Systems (DADS) hosted at the DoD Patch Repository at https://patches.csd.disa.mil/.

5.4.3. Configure virus scanning frequency and real-time protection IAW the applicable

DISA STIG; document scanning frequency in the SSP IAW NIST SP 800-53.

5.4.4. Using additional antivirus software may be approved through the security authorization process; any additional antivirus software should be used in conjunction with

DoD-approved antivirus software (http://www.disa.mil/cybersecurity/network-defense/antivirus).

5.4.5. Users report malicious logic intrusions or any other deviation and misconfiguration

IAW AFI 16-1404.

5.4.6. Implement malicious logic protection for Mobile Code Technologies IAW the DISA

Application Security and Development STIG and the DoD Policy Memorandum, Mobile

Code Technologies Risk Category List Update (http://iase.disa.mil/policy-guidance/Pages/index.aspx).

5.5. Data Spillage/Classified Message Incidents (CMIs). Data spillage incidents occur when a higher classification level of data is placed on a lower classification level system/device

(including CMDs) IAW the Committee on National Security Systems (CNSS) Glossary 4009.

When classified information is processed or maintained on an unclassified IS, the individual discovering the incident initiates security incident procedures IAW DoDM 5200.01, Volume 3, DoD Information Security Program: Protection of Classified Information, and AFI 16-1404.

5.6. Telework . Criteria for determining eligibility for telework are identified in DoDI 1035.01, Telework Policy, and AFI 36-816, Civilian Telework Program. See DoD Administration

Instruction (AI) 117, Telework Program, for implementation guidance

(http://www.dtic.mil/whs/directives/index.html). For detailed information on telework methods reference NIST SP 800-46, Guide to Enterprise Telework and Remote Access Security

(http://csrc.nist.gov/publications/PubsSPs.html).

5.6.1. Configure all teleworking government furnished equipment (GFE) for remote access with an approved encryption solution (e.g., virtual private network…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.