AFI17-101 governs the Risk Management Framework for Air Force information technology and life-cycle cybersecurity risk management.
View AFI17-101 on armypubs.army.mil
It covers Air Force IT categories, RMF roles, methodology, security controls, and Special Access Programs. The publication requires compliance and specifies records, supplements, and waiver processes.
Applies to: This publication applies to all military (active, reserve, guard), civilians, and contractors.
Ensure all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual 33-363, Management of Records, and disposed of in accordance with the Air Force Records Disposition Schedule located in the Air Force Records Information Management System.
Refer recommended changes and questions about this publication to the Office of Primary Responsibility listed above using the Air Force Form 847, Recommendation for Change of Publication; route AF Forms 847 from the field through the appropriate chain of command.
The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement.
Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the Publication Office of Primary Responsibility (OPR) for non-tiered compliance items.