AFI17-203 — Cyber Incident Handling

AFI17-203 governs Air Force and Department of Defense cyber incident handling and related cyberspace operations.

Search AFI17-203

  • Publication number: AFI17-203
  • Title: CYBER INCIDENT HANDLING
  • Date: 2017-03-16

View AFI17-203 on armypubs.army.mil


The publication covers incident handling processes, event detection and reporting, analysis, response and recovery, exercises, and coordination with Defensive Cyberspace Operations and DoD Information Networks Operations. It requires compliance with the publication and maintenance of records created by its prescribed processes.

Applies to: It applies to all military and civilian AF personnel, members of the AF Reserve, Air National Guard, DoD contractors, and individuals or activities under legal agreements or obligations with the Department of the AF.

Topics covered

  • Cyber incident handling
  • Event detection and reporting
  • Preliminary incident analysis
  • Response and recovery
  • Defensive Cyberspace Operations
  • DoD Information Networks Operations
  • Cyber exercises
  • Air Force cyberspace weapon systems

Questions and answers

What are Defensive Cyberspace Operations?

DCO are passive and active cyberspace operations intended to preserve the ability to utilize friendly cyberspace capabilities and protect data, networks, and net-centric capabilities.

What records must be maintained under AFI17-203?

Ensure that all records created as a result of processes prescribed in this publication are maintained in accordance with AF Manual (AFMAN) 33-363, Management of Records, and disposed of in accordance with the Air Force Records Disposition Schedule (RDS) located in the AF Records Information Management System (AFRIMS).

How are waiver authorities identified in AFI17-203?

The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement.

Ask Reggie.Bot a question about AFI17-203