DAFGM2026-32-01 governs cybersecurity policy, risk mitigation, and Risk Management Framework responsibilities for Civil Engineer-owned control systems.
View DAFGM2026-32-01 on armypubs.army.mil
DAFGM2026-32-01 covers control systems cybersecurity implementation, cyber hygiene, zero trust, operational technology, and system boundaries. Compliance is mandatory, and its direction prevails when inconsistent with other Department of the Air Force publications.
Applies to: This guidance memorandum applies to all DAF civilians and uniformed members of the United States Space Force, Regular Air Force, the Air Force Reserve, the Air National Guard, and those with a contractual obligation to abide by the terms of DAF issuances.
Compliance with this memorandum is mandatory.
To the extent its direction is inconsistent with other DAF publications, the information herein prevails, in accordance with (IAW) Department of the Air Force Instruction (DAFI) 90-160, Publications and Forms Management.
Some types of control systems may exist such as building automation systems, airfield lighting control systems, fire alarm reporting or industrial control systems. (paragraph 1)
Security controls and solutions applied to control systems environments should be: (1) extensive without sacrificing control systems performance and reliability, (2) tailored to the specific control systems environment, (3) verified to ensure control systems continues to operate as intended in a cyber contested environment. (paragraph 1)
Per the DAF Chief Information Security Officer’s (CISO) (SAF/CN) Authorizing Official (AO) appointment letter (as required by AFI 17-101, the CE control system boundary includes DAF CE-owned control systems as well as IT that directly supports the operation, maintenance, and security of the logically-segmented, CE control systems network enclave (e.g., Community of Interest Network (COIN)). (paragraph 1)