35FWVA17-1 — Cyber Incident Reporting Aid

35FWVA17-1 governs user procedures for classified spillage incidents, suspected computer viruses, and removable media on DoD systems.

Search 35FWVA17-1

  • Publication number: 35FWVA17-1
  • Title: Cyber Incident Reporting Aid
  • Date: 2025-04-03

View 35FWVA17-1 on armypubs.army.mil


It defines a classified spillage incident and sets immediate reporting and system-control actions. It also addresses virus reporting, unauthorized removable media, mission-critical waivers, and incident documentation.

Topics covered

  • Classified spillage incidents
  • Suspected computer viruses
  • Unauthorized removable media
  • Authorized removable media
  • Cyber incident reporting
  • Incident documentation

Questions and answers

How is a classified spillage incident defined?

A Classified Spillage Incident is defined as information classified at a higher level appearing on or connected to a system classified at a level lower than the information.

How must classified incident details be reported?

DO NOT discuss classified details but report incident through Unit Cyber Security Liaison (CSL) to Unit Security Manager (USM) and Comm Focal Point (CFP) immediately.

What should happen when unauthorized removable media is found?

SECURE the device until given further instruction!

What should users do when removable media is needed for a mission-critical purpose?

Consult with your unit CSL for further guidance using removable media on DOD systems. (paragraph 4)

Ask Reggie.Bot a question about 35FWVA17-1