AFI 31-113 Installation Access Control.pdf
PDF 1 MB Posted
- Attached to
- Repair Structural Components, Bldg 1374 Federal contract opportunity
- Solicitation number
- JBSF_15-0006
About this file
Appendices - Attachment 2 FA3047-15-R-0078
View the file
Other files for this federal contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BY ORDER OF THE
SECRETARY OF THE AIR FORCE
AIR FORCE INSTRUCTION 31-113
26 JANUARY 2012
Security
INSTALLATION PERIMETER ACCESS
CONTROL
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
ACCESSIBILITY: This publication is only available directly from the OPR.
RELEASABILITY: Access to this publication is restricted. This publication is for official use only (FOUO); requests for accessibility must be approved by the OPR.
OPR: AF/A7SO
Certified by: AF/A7S
(Brig Gen Jimmy E. McMillian)
Pages: 102
This Air Force Instruction (AFI) implements Air Force Policy Directive (AFPD) 31-1, Integrated Defense. Compliance with this Instruction is mandatory and applies to all military and civilian Air Force (AF) personnel, members of the Air Force Reserve and Air National
Guard, and other individuals or organizations as required by binding agreement or obligation with the Department of the Air Force. In addition, this Instruction is mandatory for all government-owned, contractor-operated (GOCO) and contractor-owned, contractor-operated
(COCO) facilities when required by contractual agreement. The terms "must," "shall," and
"will" denote mandatory actions in this Instruction. This Instruction requires the collection and maintenance of information protected by the Privacy Act of 1974. System of Records Notices
(SORN) F031 AF SP F, Notification Letters to Persons Barred from Entry to Air Force
Installations, F031 AF SF B, Security Forces Management Information System (SFMIS) and
F031 AF SP O, Documentation for Identification and Entry Authority, applies. Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN) 33-363, Management of Records, and disposed of in accordance with the Air Force Records Disposition Schedule (RDS) located at https://www.my.af.mil/afrims/afrims/afrims/rims.cfm. This Instruction amplifies Department of Defense (DoD) security standards and guidance for authorizing physical access to United
States Air Force (USAF) installations and/or stand-alone facilities, as required by the following:
Section 1069, 2008 National Defense Authorization Act (NDAA); Homeland Security
Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal
Employees and Contractors; Under Secretary of Defense, Intelligence [USD(I)] Directive Type
Memorandum (DTM) 09-012, Interim Policy Guidance for DoD Physical Access Control; DoD
5200.08-R, Physical Security and Federal Information Processing Standards Publication 201-1, FOR OFFICIAL USE ONLY https://www.my.af.mil/afrims/afrims/afrims/rims.cfm
2 AFI31-113 26 JANUARY 2012
Personal Identity Verification (PIV) of Federal Employees and Contractors. Further, it builds upon the minimum installation access standards as established by the Chief of Staff of the Air
Force (CSAF) memorandum dated 3 March 2004 (SUBJ: Protect the Force: Establishing the
New Baseline Force Protection Posture) and expands and rescinds the USAF Vice Chief of Staff
(VCSAF) memorandum dated 8 Sep 09 (SUBJECT: Air Force Policy for Installation Access
Control); and references Air Force tactics, techniques and procedures (AFTTP) 3-31.1, Entry
Control. All Security Forces (SF) units are required to maintain a printed copy of AFI 31-113 in case of emergencies as well as for informational and training purposes. Refer recommended changes and questions about this publication to the Office of Primary Responsibility (OPR) using the AF Form 847, Recommendation for Change of Publication; route AF Form 847s from the field through the appropriate functional chain of command. Contact supporting records managers as required. The use of the name or mark of any specific manufacturer, commercial product, commodity, or service in this publication does not imply endorsement by the AF.
Affected organizations have 180 days from date of publication to implement this AFI or submit applicable deviations to the appropriate deviation authority. Major Commands, Direct Reporting
Units (DRUs) and Field Operating Agencies (FOAs) will send one copy of supplements to
Headquarters, Air Force Security Forces Center (HQ AFSFC), Police Services (SFOP), 1517
Billy Mitchell Boulevard, Lackland Air Force Base (AFB) TX 78236.
Chapter 1—CONCEPT, PLANNING, AND RESPONSIBILITIES 6
1.1. Objective
1.2. Overarching Guidance
1.3. Authority
1.4. The protection of civil liberties, privacy and Personally Identifiable Information (PII). 8
1.5. Responsibilities
Chapter 2—INSTALLATION PERIMETER ACCESS CREDENTIALS 16
2.1. Source Documentation
2.2. Common Access Cards (CAC)
Figure 2.1. Armed Forces of the United States Geneva Conventions Card
Figure 2.2. U.S. DoD and/or Uniformed Services ID Card
Figure 2.3. U.S. DoD and/or Uniformed Services ID and Privilege Card
Figure 2.4. U.S. DoD and/or Uniformed Service Geneva Conventions ID Card for Civilians
Accompanying the Armed Forces
2.3. Non-Common Access Card (CAC) Department of Defense (DoD) Credentials. .. 23
Figure 2.5. DD Form 2, United States Uniformed Services Identification Card (Retired)
Figure 2.6. DD Form 2, Armed Forces of the United States Geneva Conventions Identification Card
(Reserve) (Green)
Figure 2.7. DD Form 2, United States Uniformed Services Identification Card (Reserve Retired). 26
AFI31-113 26 JANUARY 2012 3
Figure 2.8. DD Form 1173, Uniformed Services Identification and Privilege Card
Figure 2.9. DD Form 1173-1, Department of Defense Guard and Reserve Dependent Identification
Card
Figure 2.10. DD Form 1934, Geneva Conventions Identity Card for Medical and Religious Personnel
Who Serve in or Accompany the Armed Forces
Figure 2.11. DD Form 2764, United States DoD/Uniformed Services Civilian Geneva Conventions
Identification Card
Figure 2.12. DD Form 2765, Department of Defense/Uniformed Services Identification and Privilege
Card
Figure 2.13. Civilian Retiree Card
2.4. Non-Department of Defense (DoD) Federal Personal Identity Verification (PIV). 33
Figure 2.14. DHS Federal PIV
2.5. Transportation Worker Identification Credential (TWIC)
Figure 2.15. TWIC
2.6. Personal Identity Verification-Interoperable (PIV-I)
2.7. Locally Produced Physical Access Control System (PACS) Passes/Cards and AF Form
75 Visitor Pass/Vehicle Pass
Figure 2.16. DBIDS Card
2.8. Approved Department of Defense (DoD) Privilege Card Holders
2.9. Veterans Identification Card (VIC)
Figure 2.17. Veterans Identification Card
2.10. Privatized Housing
2.11. Air Force Office of Special Investigation (AFOSI) Special Agents
2.12. Federal Bureau of Investigation (FBI) and United States Secret Service (USSS) Special
Agents
Chapter 3—IDENTITY PROOFING AND REGISTRATION 40
3.1. Identity Proofing Concept
3.2. Common Access Card (CAC) Populations
3.3. Non-Common Access Card (CAC) Department of Defense (DoD) Populations. . 40
3.4. Non-Department of Defense (DoD) Federal Personal Identity Verification (PIV)
Populations
3.5. Transportation Worker Identification Credential (TWIC) Holders
3.6. Personal Identity Verification-Interoperable (PIV-I) Credentials
3.7. Locally Produced Physical Access Control System (PACS) Passes/Cards and AF Form
75 Visitor Pass/Vehicle Pass
4 AFI31-113 26 JANUARY 2012
Figure 3.1. United States Passport
Figure 3.2. Permanent Resident Card/Alien Registration Receipt Card (Form I-551)
Figure 3.3. Foreign passport with a temporary (I-551) stamp or temporary (I-551) printed notation on a machine readable immigrant visa
Figure 3.4. An employment authorization document that contains a photograph (Form I-766). 45
Figure 3.5. Current/Valid Driver’s License
Figure 3.6. Identification card issued by Federal, State or local Government Agencies
Figure 3.7. U.S. Coast Guard Merchant Mariner Legacy Cards
Figure 3.8. U.S. Coast Guard New Merchant Mariner Credential
3.8. Approved Department of Defense (DoD) Privilege Card Holders
3.9. Veterans Identification Card (VIC)
3.10. Outside the Continental United States (OCONUS)
3.11. Registration
3.12. Unique Considerations/Special Events/Exceptions to Policy
Chapter 4—IDENTITY VETTING AND FITNESS DETERMINATION 54
4.1. Identity Vetting Concept
4.2. Common Access Card (CAC) Populations
4.3. Non-Common Access Card (CAC) Department of Defense (DoD) Populations. . 54
4.4. Non-Department of Defense (DoD) Federal Personal Identity Verification (PIV)
Populations
4.5. Transportation Worker Identification Credential (TWIC) Holders
4.6. Personal Identity Verification-Interoperable (PIV-I) Credentials
4.7. Locally Produced Physical Access Control System (PACS) Passes/Cards and AF Form
75 Visitor Pass/Vehicle Pass
4.8. Approved DoD Privilege Card Holders
4.9. Veterans Identification Card (VIC)
4.10. Foreign Visitors
4.11. Housing Privatization Personnel
4.12. Non-authoritative Databases
4.13. Fitness Determination
4.14. Debarment
Chapter 5—PERIODIC SCREENING REQUIREMENTS OVERVIEW 63
5.1. Inherent Vulnerability
AFI31-113 26 JANUARY 2012 5
5.2. Procedures
Chapter 6—INSTALLATION PERIMETER ENTRY CONTROL POINT OPERATIONS 65
6.1. United States Air Force (USAF) Installation Perimeter Access Control Guidance. 65
6.2. Construction Standards
6.3. Installation Perimeter Access Control Measures
6.4. Installation Perimeter Access Control Minimum Standards for Controlling Physical
Access
6.5. Escort Authority
6.6. Sponsorship
6.7. Installation Perimeter Access Control Procedures for Emergency Responders and
Civilian Law Enforcement
6.8. Internal Access (to include Service-determined controlled, restricted, and limited areas). 73
6.9. Identification/Verification
Chapter 7—IDENTITY MANAGEMENT ENTERPRISE SERVICES ARCHITECTURE 74
7.1. Source Documents
7.2. Identity Management Enterprise Services Architecture Requirements
7.3. Continuous Information Management Capability
Chapter 8—BIOMETRICS 76
8.1. Overview
8.2. Requirements
8.3. Biometric Categories
8.4. Biometric Standards
8.5. Local Guidance Requirements
Chapter 9—TRAINING AND EXERCISES 79
9.1. Concept
9.2. Training
9.3. Exercises
9.4. Lessons Learned, Vulnerabilities, and Higher Headquarters Feedback
Attachment 1—GLOSSARY OF REFERENCES AND SUPPORTING INFORMATION 81
6 AFI31-113 26 JANUARY 2012
Chapter 1
CONCEPT, PLANNING, AND RESPONSIBILITIES
1.1. Objective. The objective of installation perimeter access control is to restrict and/or control entrance to property and/or installations to only those authorized persons and their vehicles to protect personnel, resources and missions.
1.1.1. Installation perimeter access control procedures include identity proofing, vetting to determine the fitness of an individual requesting and/or requiring access to installations, and issuance of access credentials.
1.1.1.1. Identity proofing: The process of providing sufficient information (e.g., identity history, credentials, documents) when attempting to establish an identity.
1.1.1.2. Vetting: An evaluation of an applicant’s or a card holder’s character and conduct for approval, acceptance or denial for the issuance of an access control credential for physical access.
1.1.1.3. Fitness: Level of character and conduct determined necessary for the basis of access control decisions. For the purposes of this instruction, fitness is further defined as follows:
1.1.1.3.1. Person presenting the credential has been properly identity proofed and vetted. Note: Dependents are currently exempt from vetting, and the authorized card holder sponsoring them assumes the risk.
1.1.1.3.2. Person has a credential authorized to facilitate access.
1.1.1.3.3. Person matches the credential authorized to facilitate access.
1.1.1.3.4. Person with credential authorized to facilitate access is authorized access to that particular installation. Note: Possession of a valid/authorized credential does not automatically authorize access to that installation. The individual must still have a valid purpose to be on the installation and properly sponsored, as applicable.
1.1.1.3.5. Authorized credential is still valid and not expired.
1.1.1.3.6. Person with credential authorized to facilitate access is still fit since last vetting as determined via continuous information management. Note: This continuous information management will be accomplished via the Identity
Management Enterprise Services Architecture detailed in Chapter 7.
1.1.1.3.6.1. Person is not on a terrorist watch list.
1.1.1.3.6.2. Person is not on the installation’s debarment list.
1.1.1.3.6.3. Person is not on a felony wants and warrants list.
1.1.2. Persons authorized access shall be either escorted or unescorted:
1.1.2.1. Escorted Individuals—Personnel who require access, without determination of fitness, who must be accompanied by a sponsor with authorization to escort the
AFI31-113 26 JANUARY 2012 7
individual. The escort requirement is mandated for the duration of the individual’s visitation period.
1.1.2.2. Unescorted Individuals—Personnel who have been identity proofed and favorably vetted are eligible for unescorted access within the installation; but are still subject to any controlled or restricted area limitations, as appropriate.
1.1.3. Commanders or directors will employ access control measures at an installation perimeter to enhance security and protect personnel, resources and installations.
1.1.4. Successful installation access control is:
1.1.4.1. Pivotal to integrated defense (ID) and force protection (FP) because it improves the probability of detection and provides a strong psychological deterrent to those who may pose a threat to installation resources and personnel.
1.1.4.2. Accomplished by establishing a physical boundary around installations, channeling personnel and vehicles to designated entry control points (ECPs) for processing, developing a standard to determine who is authorized physical access, and maximizing the ability to detect those individuals attempting to subvert established procedures and gain unauthorized access to the installation.
1.2. Overarching Guidance.
1.2.1. The standards prescribed herein are the minimum required for United States Air Force
(USAF) installations and must be adhered to. Combatant Commanders (COCOM), Major
Command (MAJCOM) Commanders and Installation Commanders may authorize additional security requirements based upon the type of installation, mission, enemy, terrain and weather, troops and support available-time available and civil considerations (METT-TC), resources, category of individuals requiring access, Force Protection Conditions (FPCONs), a completed Integrated Defense Risk Management Process (IDRMP), level of access to be granted and other emerging contingencies, as necessary.
1.2.2. USAF installations will meet applicable physical security standards for installation perimeters in accordance with (IAW) Air Force Instruction (AFI) 31-101, Integrated
Defense.
1.2.3. New and modified facilities will comply with either Unified Facilities Criteria (UFC)
4-022-01, Security Engineering: Entry Control Facilities/Access Control Points, or with a properly approved waiver or exemption.
1.2.4. For OCONUS locations, MAJCOMs and Installation Commanders may deviate from the requirements where local conditions, treaties, agreements, foreign governments and allied forces require different standards. Commanders will work with local and foreign authorities to identity proof and vet applicants to the greatest extent practical and lawful.
1.2.5. This AFI does not negate other USAF protection and security requirements governed by instructions and manuals implementing and guiding force protection, physical security, nuclear security, and antiterrorism (AT).
1.2.6. To ensure effective use of resources, long-term sustainability and joint interoperability, installations will coordinate all installation and internal access control
8 AFI31-113 26 JANUARY 2012
systems and components with MAJCOM A7S Divisions and the AFSFC/SFXR
(Requirements Branch) prior to funding obligation and execution.
1.2.7. Any systems which connect to the USAF Global Information Grid (GIG) must be accredited and certified in concert with local and USAF communications entities and a thorough Privacy Impact Assessment (PIA) accomplished IAW AFI 33-332, Air Force
Privacy Program. Note: For clarification, a PIA is required for systems that collect personally identifiable information (PII). This process is completed on a DD Form 2930, Privacy Impact Assessment, and sent to the Air Force Privacy Officer to be staffed for approval.
1.2.8. Installation Commanders will coordinate and seek to standardize and integrate access control procedures and local credentials with other military installations in the local area as defined in all regionally located Services’ directives.
1.3. Authority. Authority to control access to USAF installations varies based on jurisdiction, property rights, and geographic location.
1.3.1. Continental United States (CONUS), Alaska, Hawaii and US Territories and
Possessions. Within United States (US) jurisdiction, commanders publish and enforce guidance to protect installation resources IAW DoD and USAF policy. In addition, Department of Defense Instruction (DoDI) 5200.08, Security of DoD Installations and
Resources and the DoD Physical Security Review Board (PSRB), prohibits individuals from entering military installations within the jurisdiction of the United States for a purpose prohibited by law or lawful regulation or reentering an installation after being ordered not to reenter by any officer in command of the installation.
1.3.2. Outside the Continental United States (OCONUS). Outside the United States, a commander's right to exercise this authority comes from United States laws and Status of
Forces Agreements (SOFAs) applying in the overseas area and from bilateral and multilateral agreements between the United States and the host nation.
1.3.2.1. Expeditionary Locations. In addition to OCONUS jurisdiction as indicated in paragraph 1.3.2., jurisdiction, rules of engagement (ROE) and legal authority may also be determined by laws of war and supplemental general orders (GO).
1.3.2.2. Commanders at all levels are responsible to ensure USAF personnel understand their legal authority, jurisdiction and ROE.
1.4. The protection of civil liberties, privacy and Personally Identifiable Information
(PII). PII collected and utilized in the execution of this AFI must be safeguarded to prevent any unauthorized use, disclosure and/or loss. Installations shall ensure that the collection, use and release of PII complies with the requirements of DoD Directive (DoDD), 5400.11, DoD Privacy
Program, DoD 5400.11-R, Department of Defense Privacy Program, DoDI 5400.16, DoD
Privacy Impact Assessment (PIA) Guidance, and AFI 33-332.
1.5. Responsibilities.
1.5.1. Office of Information Dominance and Chief Information Officer (SAF/CIO A6):
1.5.1.1. Serves as the USAF lead agency for biometrics, network integration and the principal Air Force representative to the Biometrics Identity Management Agency
(BIMA), the DoD’s Executive Agent for Biometrics.
AFI31-113 26 JANUARY 2012 9
1.5.1.2. In concert with the BIMA and DoD General Counsel, provides oversight to the implementation of biometrics within access control systems in accordance with DoD and
USAF policy and directives.
1.5.2. Office of the Legislative Liaison, Foreign Disclosure and Technology Transfer
Division (SAF/IAPD): Serves as the USAF proponent for Foreign Visit System (FVS) and
FVS-Confirmation Module (FVS-CM).
1.5.3. The Office of the Deputy Chief of Staff for Logistics, Installations and Mission
Support, Directorate of Security Forces (AF/A7S):
1.5.3.1. Is the Chief of Staff of the Air Force’s (CSAF’s) primary advisor for law and order operations and installation access control.
1.5.3.2. Assists Under Secretary of Defense, Intelligence (USD(I)) with the development of DoD access control policy and the minimum DoD security standards for controlling entry to DoD installations and stand-alone facilities.
1.5.3.3. Develops overarching, USAF installation perimeter access control policy and is the approval authority for law and order and access control guidance.
1.5.3.4. Plans, develops and monitors all USAF access control programs.
1.5.3.5. Develops and coordinates USAF law and order policy directives and approves and publishes identification (ID) specific Air Force tactics, techniques and procedures
(AFTTPs) and Air Force Manuals (AFMANs).
1.5.3.6. Manages distribution of access control equipment and systems received through central procurement.
1.5.3.7. Manages the access control Program Objective Memorandum (POM) funding process.
1.5.3.8. Serves as functional approval authority for manpower standards related to installation access control.
1.5.4. Air Force Security Forces Center (AFSFC):
1.5.4.1. Drafts and coordinates USAF access control instructions, manuals and tactics, techniques, and procedures (TTPs).
1.5.4.2. Defines Security Forces (SF) capability sets and defines capability standards, applicability and effects of delivery.
1.5.4.3. Develops mission essential task lists (METLs) and associated training tasks, conditions and standards.
1.5.4.4. Coordinates access control guidance with other programs and functional specialties.
1.5.4.5. Incorporates and adapts access control guidance into AFIs; develops installation access control standards and procedures; and monitors the effectiveness of the access control program.
1.5.4.6. Provides expertise in operational guidance development in the areas of law and order operations and military working dog (MWD) employment.
10 AFI31-113 26 JANUARY 2012
1.5.4.7. Plans, develops and reviews programs concerning access control training.
1.5.4.8. Reviews access control training requirements and recommends curriculum changes.
1.5.4.9. Incorporates findings into the AFSFC Lessons Learned process.
1.5.4.10. Develops SF tactical doctrine and concepts in order to execute the access control mission (home station and deployed bases).
1.5.4.11. Drafts guidance to support new SF initiatives.
1.5.4.12. Reviews AF policy and recommends changes to support development of SF concepts and guidance.
1.5.4.13. Manages the Air Force Vulnerability Assessment (AFVA) programs and conducts AFVAs as required. Evaluates access control policy and procedures during vulnerability assessments.
1.5.5. Logistics, Installations & Mission Support Directorate, Asset Management &
Operations Division (AF/A7CA): Provides recommendations and inputs to access control procedures relative to AFI 32-6007, Privatized Family Housing.
1.5.6. Air Force Civil Engineer Support Agency (AFCESA):
1.5.6.1. Provides field expertise, recommendations, support and other input for structural, environmental, Fire Emergency Services, Explosive Ordnance Disposal
(EOD), Emergency Management (EM), Chemical, Biological, Radiological, Nuclear or
High Yield Explosives (CBRNE) operations, and other engineer areas of expertise.
1.5.6.2. Provides recommendations to MAJCOMs in reconciling force protection construction standards with airfield planning and design standards.
1.5.6.3. Ensures engineers have input in acquiring necessary equipment and resources by coordinating their conditions and limitations into Air Force requirements for research and development efforts.
1.5.6.4. Is responsible for the UFC system.
1.5.7. Air Force Office of Special Investigations (AFOSI):
1.5.7.1. Provides counterintelligence (CI) activities to include collection and production of information concerning foreign intelligence, investigations of terrorism, sabotage and related acts, offensive operations against foreign intelligence services and AT services.
1.5.7.2. Provides the Defense Force Commander (DFC) CI information within the area of interest as well as establishing an effective liaison with host nation (HN) intelligence, security, and law enforcement sources.
1.5.7.3. Maintains the capability to respond to criminal activities.
1.5.7.4. Provides immediate, worldwide, complementary support to the deployed area commander by conducting specialized CI support to FP, protective service operations, and counter-threat operations.
1.5.7.5. Plans and programs support to counter-threat operations.
AFI31-113 26 JANUARY 2012 11
1.5.8. MAJCOM Commanders:
1.5.8.1. Establish assessment and planning staffs as appropriate.
1.5.8.2. Direct development of operational level access control planning as required.
1.5.8.3. Direct validation of manpower and resource allocation in support of access control.
1.5.9. Air National Guard (ANG): Organizes, trains, and equips ANG SF units for wartime duties in coordination with the gaining MAJCOM/A7S and AF/A7S.
1.5.10. Air Force Reserve Command (AFRC): Organizes, trains and equips AFRC SF personnel for garrison and/or expeditionary roles/duties and coordinates with the gaining
MAJCOM Security Forces (MAJCOM/A7S) and USAF/A7S as required.
1.5.11. MAJCOM/A7S:
1.5.11.1. Identifies command-wide training requirements.
1.5.11.2. Incorporates access control into SF Phase I and II Training programs as necessary IAW AFI 36-2225, Security Forces Training and Standardization and
Evaluation Programs.
1.5.11.3. Develops procedures for documenting training results.
1.5.11.4. Prepares plans and documents for acquisition of necessary installation perimeter access control equipment.
1.5.11.5. Makes recommendations to AF/A7S and AFSFC on policies concerning organizing, training and equipping units and forces to provide installation perimeter access control.
1.5.11.6. Develops and submits security requirements in supplements to this instruction, security requirements for MAJCOM-unique systems, resources and facilities.
1.5.11.7. Validates entry control posts during the manpower standard implementation post validation process.
1.5.11.8. Ensures force protection and security construction projects are integrated with
MAJCOM Airfield/Community Planner airfield design and protection criteria.
1.5.12. Installation Commanders:
1.5.12.1. Responsible for the defense and protection of the installation.
1.5.12.2. Responsible for chartering the Integrated Defense Council (IDC) to implement programs for the protection of personnel, property, resources and missions under their control. Programs must meet DoD and USAF protection criteria.
1.5.12.3. Establish commander’s intent and define risk tolerance in relation to installation perimeter access control.
1.5.12.4. Assume, accept, remediate or mitigate risk for assigned assets as appropriate.
1.5.12.5. Elevate risk decisions to higher echelons when appropriate.
12 AFI31-113 26 JANUARY 2012
1.5.12.6. Appoint the DFC as the installation’s OPR to coordinate installation access control IAW this instruction.
1.5.12.7. Establish working groups, staffs, and executive councils to conduct and oversee defense and protection assessments and planning as necessary and as required by instruction.
1.5.12.8. Maintain liaison with adjacent installations, base clusters and supporting HN security agencies, and civil authorities within the joint base boundary as defined in Joint
Publication 3-10, Joint Security Operations in Theater, or around the Installation
Commander’s jurisdictional boundaries. See AFI 31-101, AFI 10-245, Antiterrorism, and AFTTP 3-10.2, Integrated Base Defense Command and Control, for additional information. Note: Responsibilities for liaison may be retained by higher authority or delegated to subordinate commands as local circumstances dictate.
1.5.12.9. Where applicable, integrate area security plans with the Joint Security Office and the appropriate operations center that coordinates security in areas where security forces operate.
1.5.12.10. In alignment with DoD, Service, COCOM, combined joint forces command, and MAJCOM policies, identify specific procedures for access credential issuance on the installation. This includes rules associated with sponsorship/need determination, identity proofing, identity vetting/fitness determination, credential issuance (form of temporary credentials as well as the visual authenticators associated with them) or denial, access control operations/screening, periodic re-vetting of identities, and vehicle and container searches, as applicable.
1.5.12.11. Determine local credential requirements for personnel under the age of 18 who require non-recurring access and are not in possession of an authorized identification credential or identity source document listed in Chapter 2.
1.5.12.12. Implement procedures for off base first responders’ physical access requirements during emergencies.
1.5.12.13. Delegate personnel to perform identity proofing, vetting and determination of fitness, and access authorizations and privileges.
1.5.12.14. Determine the number of personnel that approved escorts are authorized to escort and sponsorship and escort rules for DoD dependents under the age of 18.
1.5.12.15. Ensures force protection and security construction projects are integrated with
MAJCOM Airfield/Community Planner airfield design and protection criteria.
1.5.13. Unit Commanders:
1.5.13.1. Each unit commander, tenant unit commander, or agency chief or equivalent staff agency chief must ensure their personnel understand and follow installation access control guidance and procedures.
1.5.13.2. Each unit commander, tenant unit command, or agency chief or equivalent staff agency chief must identify to the IDC key missions and associated resources required to execute this instruction continuously or with minimal delay even in heightened security
AFI31-113 26 JANUARY 2012 13
situations; and coordinate and integrate all associated IDC processes to enhance mission continuity.
1.5.14. Defense Force Commanders (DFCs):
1.5.14.1. Serves as the Installation Commander’s primary advisor for Law and Order operations and installation access control. On USAF installations, the SF squadron commander is the DFC. On USAF installations with more than one SF squadron, the
DFC is the SF commander responsible for installation security and Law and Order operations.
1.5.14.2. Maintains command and control (C2) of Law and Order operations. This C2 is executed through the Base Defense Operations Center (BDOC).
1.5.14.3. Exercises operational control (OPCON) over all assigned Law and Order forces.
1.5.14.4. Conducts access control assessments and planning.
1.5.14.5. Develops and publishes the IDP, incorporates law and order and installation access control policies and procedures into the IDP, and develops installation access control standards and procedures.
1.5.14.6. Establishes procedures for DoD ID-card holders to register in and withdraw from the Physical Access Control Systems (PACS) during in and out-processing at the servicing location.
1.5.14.7. Coordinates the inclusion of registration and deregistration into PACS on base/installation in-processing and out-processing checklists. Since PACS are designed to associate each DoD ID with a specific individual, re-registration is required anytime an
ID card is reissued for any reason (e.g. loss, confiscation or normal replacement).
1.5.14.8. Establishes procedures for ensuring responsible sections/organizations retrieve
PACS credentials and locally created access credentials from individuals who no longer require installation access.
1.5.14.9. Establishes provisions to ensure only users who have been trained to operate the PACS have access to the equipment.
1.5.14.10. Establishes procedures to protect PACS equipment against theft or damage at operating locations and access control points. Note: If the facility where the equipment is housed cannot be secured, the equipment must be removed at the end of the duty day.
1.5.14.11. Manages current and future requirements based on operational deficiencies and provides oversight in the development, review and validation of emerging technology to fulfill operational capabilities at the installation level.
1.5.14.12. Participates in installation working groups as required.
1.5.14.13. Works closely with installation AT Officers and Information Protection
Offices (IPO) to develop local guidance and concepts to execute the law and order and access control missions.
1.5.14.14. Documents required entry control posts in the post priority chart annex of the
IDP.
14 AFI31-113 26 JANUARY 2012
1.5.14.15. Determines posts that will go unmanned and how available resources will be used during times of funding or personnel shortages.
1.5.14.16. Ensures current debarment information is loaded into the Security Forces
Management Information System (SFMIS) and appropriate PACS databases as necessary.
1.5.14.17. Identifies an SF section for the registration and issuance of installation access credentials listed below and ensures section personnel are trained, proficient, and certified in their assigned responsibilities relating to:
1.5.14.17.1. Air Force (AF) Form 75, Visitor/Vehicle Pass.
1.5.14.17.2. PACS created passes/cards.
1.5.14.17.3. Access Control Lists, or other measures associated with accounting for access control and who is authorized entry.
1.5.14.18. Establishes procedures to receive reports of lost/stolen ID cards or access credentials IAW paragraph 1.5.17.4.
1.5.15. Force Support Squadron (FSS) Commanders will:
1.5.15.1. Ensure Military Personnel Elements issue CACs to applicable populations IAW
Homeland Security Presidential Directive -12 (HSPD-12), Policy for a Common
Identification Standard for Federal Employees and Contractors; Under Secretary of
Defense for Personnel and Readiness (USDP&R) Directive Type Memorandum (DTM)
08-003, Next Generation Common Access Card (CAC) Implementation Guidance, and
AFI 36-3026 (IP), Volume 1, Identification Cards for Members of the Uniformed
Services, Their Eligible Family Members, and Other Eligible Personnel.
1.5.15.2. Ensure procedures for DoD ID-card holders are followed to register and withdraw from PACS during in and out processing.
1.5.15.3. Ensure individuals requiring access are properly vetted prior to issuance, as appropriate.
1.5.15.4. If a local access credential is not returned, the installation commander may consider base debarment, as applicable. If debarment occurs, promptly notify the applicable contracting officer.
1.5.16. Sponsoring Organizations will ensure:
1.5.16.1. The appropriate registration form is prepared for each access credential applicant.
1.5.16.2. The applicant registers his or her vehicle according to the procedures established in the Area of Operation (AO).
1.5.16.3. Prospective contractor employees are escorted from the installation entry control point to the appropriate office to initiate identity proofing and vetting for the appropriate credential issuance as determined by the duration of the contract.
1.5.16.4. Include in all purchase requests the requirements for contractor personnel to return all local access credentials to the issuing office when the contract is completed or
AFI31-113 26 JANUARY 2012 15
when a contractor employee no longer requires access to the installation (e.g. quits, contract is terminated, etc.).
1.5.16.5. Include a contract provision to ensure that contractors return all local access credentials to the issuing office when the contract is completed or when a contractor employee no longer requires access to the installation (e.g. quits, contract is terminated).
1.5.16.6. Issued access credentials are retrieved and returned to the issuing office when the relationship that served as justification changes or is terminated.
1.5.16.7. Provide information relevant to the FVS and FVS-CM on CONUS installations.
1.5.16.8. Personnel designated authority to serve as approving officials are identified to the credential issuance office.
1.5.17. All personnel requiring recurring and unescorted access to USAF installations with
PACS must:
1.5.17.1. Enroll their credential authorized to facilitate access in the PACS according to locally established guidance.
1.5.17.2. Carry their DoD ID card or approved credential on their person while in duty status or when on a USAF installation.
1.5.17.3. On request, present their DoD ID card or approved access credential to Law and Order or security personnel. Individuals who refuse to present their DoD ID card or approved credential are subject to immediate surrender of the credential and may be subject to further administrative or punitive action.
1.5.17.4. Immediately report a lost or stolen DoD ID card or access credential to the local SF, and issuance office so the card can be deregistered.
1.5.17.4.1. For CACs, the individual shall be required to present documentation from the local security office or CAC sponsor confirming that the CAC has been reported lost or stolen.
1.5.17.4.2. This documentation must be scanned and stored in Defense Enrollment
Eligibility Reporting System (DEERS). Inform the sponsoring organization of any change to the official relationship that served as the basis for access.
1.5.17.5. Turn in access credentials to the issuance office or sponsoring organization when the credential expires or when the basis for obtaining the credential no longer exists.
1.5.17.6. Register their privately owned vehicle (POV) in accordance with Joint, Combatant Commander and installation guidance.
16 AFI31-113 26 JANUARY 2012
Chapter 2
INSTALLATION PERIMETER ACCESS CREDENTIALS
2.1. Source Documentation.
2.1.1. Per DoDI 1000.13, Identification (ID) Cards for Members of the Uniformed Services, Their Dependents, and Other Eligible Individuals, and AFI 36-3026 (IP), Volume 1, the DoD provides members of the Uniformed Services with a distinct ID card identifying them as active duty, Guard, Reserve, or retired members and authorizing them to receive Uniformed
Services’ benefits and privileges.
2.1.2. The DoD also authorizes a distinct ID card for eligible family members and other individuals entitled to receive Uniformed Services’ benefits and privileges, civilian affiliates
(e.g. Red Cross employees), foreign affiliates (e.g. qualifying foreign military and foreign civilian liaisons), and a Service specific civilian ID card for DoD civilian employees and eligible contractor personnel.
2.1.3. In addition to DoD issued credentials, per DTM 09-012, Interim Policy Guidance for
DoD Physical Access Control, the other non DoD credentials listed in this chapter are also authorized to facilitate access to Air Force installations.
2.2. Common Access Cards (CAC).
2.2.1. It is Department of Defense (DoD) policy that:
2.2.1.1. The CAC, a form of DoD ID card, shall serve as the Federal PIV card for DoD implementation of HSPD 12.
2.2.1.2. Per AFI 31-101, the CAC is the principal PIV credential used to facilitate physical access to facilities and installations.
2.2.2. The DoD is currently migrating the CAC in order to meet the Federal requirements for credentialing contained within HSPD-12 and Federal Information Processing Standards
(FIPS) Publication 201-1, Personal Identity Verification for Federal Employees and
Contractors.
2.2.2.1. Migration of the CAC will take place over multiple years as the card issuance hardware and software are upgraded.
2.2.2.2. CACs issued in conjunction with previous CAC policies, USD(P&R) DTM 08-
003, and DTM 09-012 will remain valid until replaced with the next generation CAC.
2.2.3. HSPD-12 Implications. Office of Management and Budget Memorandum M-05-04, Implementation of HSPD 12 – Policy for a Common Identification Standard for Federal
Employees and Contractors, and DTM 08-003 define rules on the CAC and to whom it applies.
2.2.4. CAC Eligibility.
2.2.4.1. Automatic CAC Eligible Populations.
2.2.4.1.1. Specific populations are automatically eligible for a CAC based on their personnel category within the DoD.
AFI31-113 26 JANUARY 2012 17
2.2.4.1.2. Examples include Uniformed Services personnel, DoD civilian employees, and specific categories of personnel assigned overseas in support of the Department.
2.2.4.2. Other Eligible CAC Populations.
2.2.4.2.1. CAC eligibility for other populations, including DoD contractors, non-
DoD Federal Civilians, State employees, and other non-DoD affiliates, is based on the DoD government sponsor’s determination of the type and frequency of access required to DoD facilities or networks that will effectively support the mission.
2.2.4.2.2. To be eligible for a CAC, the access requirement must meet one of the following criteria:
2.2.4.2.2.1. The individual requires access to multiple DoD facilities or access to multiple non-DoD Federal facilities on behalf of the Department (applicable to
DoD contractors only) on a recurring basis for a period of 6 months or more.
2.2.4.2.2.2. The individual requires both physical access to a DoD facility and access, via logon, to DoD networks on site or remotely. Access to the DoD network must require the use of a computer with Government-controlled configuration or use of a DoD-approved remote access procedure in accordance with the Secure Remote Computing Security Technical Implementation Guide
Version 1, Release 2.
2.2.4.2.2.3. The individual requires remote access, via logon, to a DoD network using DoD-approved remote access procedures.
2.2.4.3. CAC eligibility for non-U.S. persons (non US Citizen/nonpermanent resident alien).
2.2.4.3.1. CAC eligibility for non-U.S. persons is based on DoD Government sponsorship.
2.2.4.3.2. Non-U.S. persons are eligible for CACs only if they meet one or more of the following:
2.2.4.3.2.1. Possess legal residence status within the United States for a minimum of 3 years, a favorable result from the Federal Bureau of Investigations fingerprint check, and an initiated National Agency Check with Written Inquiries (NACI) or equivalent investigation.
2.2.4.3.2.2. Possess a successfully adjudicated NACI or equivalent investigation.
2.2.4.3.2.3. Meet (as direct/indirect DoD hire personnel) the investigative requirements for DoD employment as recognized through international agreements pursuant to DoD 1400.25-M, Civilian Personnel Manual, Subchapter
1231, Employment of Foreign Nationals, and AFI 36-102, Basic Authority and
Responsibility for Civilian Personnel Management and Administration.
2.2.4.3.2.4. Possess (as foreign military, employee, or contract support personnel) a visit status and security assistance that has been confirmed, documented, and processed in accordance with international agreements pursuant to DoD Directive
5230.20, Visits and Assignment of Foreign Nationals, AFI 16-107, Military
Personnel Exchange Program (MPEP),AFI 16-201, Air Force Disclosure and
18 AFI31-113 26 JANUARY 2012
Technology Transfer Program, and Air Force Policy Directive (AFPD) 16-1, International Affairs.
2.2.5. CAC Topology Specifications. CAC Stripe Color Coding. Note: If a person meets more than one condition below, priority will be given to the blue stripe to denote a non-U.S.
citizen unless the card serves as a Geneva Conventions Card.
2.2.5.1. No Stripe. U.S. military and DoD civilian personnel or any personnel eligible for a Geneva Conventions card.
2.2.5.2. Blue. Non-U.S. personnel, including DoD contract employees (other than those persons requiring a Geneva Conventions card).
2.2.5.3. Green. All U.S. personnel under contract to the Department (other than those persons requiring a Geneva Conventions card).
2.2.5.4. Red. Reserved for First Responder personnel.
2.2.5.4.1. FIPS-201 reserves the color red to distinguish emergency first responder officials. However, policy governing the requirements for a first responder program has not been codified within the Department.
2.2.5.4.2. Until the DoD Implementation of HSPD-12 is complete, the color red will also be used to denote non-U.S. personnel in the same manner as the blue stripe.
2.2.6. CAC Printed Statements.
2.2.6.1. Eligible individuals who are permanently assigned in foreign countries for at least 365 days (it should be noted that local nationals are in their home country, not a foreign country) will have the word ―OVERSEAS‖ printed within the authorized patronage area of the CAC.
2.2.6.2. The authorized patronage area for eligible individuals permanently assigned within the continental United States (CONUS) will be blank. Travel orders authorize access for these individuals while en-route to the deployment site.
2.2.6.3. The medical area on the card for individuals on permanent assignment in a foreign country will contain a statement, "When Temporary Assigned Duty/Temporary
Duty (TAD/TDY) or stationed overseas on a space-available fully reimbursable basis."
However, civilian employees and contractor employees providing support when forward deployed during a conflict, combat, or contingency operation are treated according to
DoD Directive 1404.10, DoD Civilian Expeditionary Workforce, Joint Publication 1-02, Department of Defense Dictionary of Military and Associated Terms, the Deputy
Secretary of Defense Memorandum, Policy Guidance for Provision of Medical Care for
Department of Defense Civilian Employees Injured or Wounded While Forward
Deployed in Support of Hostilities and AFI 36-507, Mobilization of the Civilian Work
Force.
2.2.7. Types of CAC Credentials. There are currently four CAC types that are used within the Department, based on cardholder eligibility. Each type will evolve into a next generation
CAC type.
2.2.7.1. Armed Forces of the United States Geneva Conventions Card.
AFI31-113 26 JANUARY 2012 19
Figure 2.1. Armed Forces of the United States Geneva Conventions Card.
2.2.7.1.1. This CAC is the primary ID card for active duty uniformed services members and shall be used to identify the member’s eligibility for benefits and privileges administered by the uniformed services and shall also be used to facilitate standardized, uniform access to DoD facilities, installations and computer systems.
2.2.7.1.2. The following population categories are eligible for this CAC:
2.2.7.1.2.1. Members of the regular components of the Military Services.
2.2.7.1.2.2. Members of the Selected Reserve of the Ready Reserve of the
Reserve Components.
2.2.7.1.2.3. Members of the Individual Ready Reserve of the Ready Reserve authorized according to regulations prescribed by the Secretary of Defense to perform duty in accordance with section 10147 of Title 10, U.S.C.
2.2.7.1.2.4. Military members of the Coast Guard, National Oceanic Atmospheric
Administration (NOAA) and U.S. Public Health Service (USPHS).
2.2.7.1.3. Status area of the card will show the Agency/Department the individual is associated with for members on Active duty, and for members of the Selected
Reserve not on active duty or full-time National Guard duty for 31 days or more.
2.2.7.1.4. This version of the CAC will be modified (from Armed Forces) to state
―Uniformed Services‖ for members of the National Oceanic and Atmospheric
Administration and the U.S. Public Health Service.
2.2.7.2. U.S. DoD and/or Uniformed Services ID Card.
20 AFI31-113 26 JANUARY 2012
Figure 2.2. U.S. DoD and/or Uniformed Services ID Card.
2.2.7.2.1. This CAC is the primary ID card for Service Academy students, eligible civilian employees, contractors, and foreign national affiliates and shall be used to facilitate standardized, uniform access to DoD facilities, installations and computer systems.
2.2.7.2.2. DoD civilian employees are eligible for this CAC, to include:
2.2.7.2.2.1. Individuals appointed to appropriated fund and non-appropriated fund (NAF) positions (to include civilian employees of the U.S. Coast Guard and
NOAA).
2.2.7.2.2.2. Permanent or time-limited employees on full-time, part-time, or intermittent work schedules for 6 months or more.
2.2.7.2.2.3. Senior Executive Service, Competitive Service, and Excepted Service employees.
2.2.7.2.3. Eligibility for additional populations shall be based on a combination of the personnel category and the DoD Government sponsor’s determination of the type and frequency of access required to DoD networks and facilities. These personnel categories include:
2.2.7.2.3.1. Non-DoD civilian employees to include:
AFI31-113 26 JANUARY 2012 21
2.2.7.2.3.1.1. NOAA civilian employees.
2.2.7.2.3.1.2. State employees working in support of the National Guard.
2.2.7.2.3.1.3. Intergovernmental Personnel Act employees.
2.2.7.2.3.1.4. DoD contractors.
2.2.7.2.3.1.5. NOAA Contractors.
2.2.7.2.3.2. Persons whose affiliation with DoD is established through:
2.2.7.2.3.2.1. Direct and Indirect Hiring Overseas. Non-U.S. citizens hired under an agreement with the host nation and paid directly by the Uniformed
Services (direct hire) or paid by an entity other than the Uniformed Services for the benefits of the Uniformed Services (indirect hire).
2.2.7.2.3.2.2. Assignment as Foreign Military, Foreign Government Civilians, or Foreign Government Contractors to Support DoD Missions. Non-U.S.
citizens who are sponsored by their government as part of an official visit or assignment to work with DoD.
2.2.7.3. U.S. DoD and/or Uniformed Services ID and Privilege Card.
Figure 2.3. U.S. DoD and/or Uniformed Services ID and Privilege Card.
2.2.7.3.1. This CAC is the primary ID card for civilian employees, contractors, and foreign national military, as well as other eligible individuals entitled to benefits and privileges administered by the uniformed services. The CAC shall be used to
22 AFI31-113 26 JANUARY 2012
facilitate standardized, uniform access to DoD facilities, installations, and computer systems.
2.2.7.3.2. Specific population categories entitled to benefits and privileges are eligible for this CAC, to include:
2.2.7.3.2.1. DoD and uniformed services civilian employees (both appropriated and non-appropriated) when required to reside in a household on a military installation within the CONUS, Hawaii, Alaska, Puerto Rico, and Guam.
2.2.7.3.2.2. DoD and uniformed services civilian employees when stationed or employed and residing in foreign countries for a period of at least 365 days.
2.2.7.3.2.3. Other U.S. Government agency civilian employees when stationed or employed and residing in foreign countries for a period of at least 365 days.
2.2.7.3.2.4. DoD contractors when stationed or employed and residing in foreign countries for a period of at least 365 days.
2.2.7.3.2.5. DoD Presidential appointees who have been appointed with the advice and consent of the Senate.
2.2.7.3.2.6. Civilian employees of the Army and Air Force Exchange System, Navy Exchange System, and Marine Corps Exchange System and NAF activity employees of the Coast Guard Exchange Service.
2.2.7.3.2.7. Uniformed and non-uniformed full-time paid personnel of the Red
Cross assigned to duty with…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .