DAFGM2026-32-01 — Civil Engineer Control Systems Cybersecurity

DAFGM2026-32-01 governs cybersecurity policy, risk mitigation, and Risk Management Framework responsibilities for Civil Engineer-owned control systems.

Search DAFGM2026-32-01

  • Publication number: DAFGM2026-32-01
  • Title: Civil Engineer Control Systems Cybersecurity
  • Date: 2026-08-07

View DAFGM2026-32-01 on armypubs.army.mil


DAFGM2026-32-01 covers control systems cybersecurity implementation, cyber hygiene, zero trust, operational technology, and system boundaries. Compliance is mandatory, and its direction prevails when inconsistent with other Department of the Air Force publications.

Applies to: This guidance memorandum applies to all DAF civilians and uniformed members of the United States Space Force, Regular Air Force, the Air Force Reserve, the Air National Guard, and those with a contractual obligation to abide by the terms of DAF issuances.

Topics covered

  • Control systems cybersecurity
  • Operational technology
  • Cybersecurity implementation
  • Control systems cyber hygiene
  • Zero trust
  • Risk Management Framework
  • Control system authorization boundaries

Questions and answers

Is compliance with DAFGM2026-32-01 mandatory?

Compliance with this memorandum is mandatory.

What happens if this memorandum conflicts with another DAF publication?

To the extent its direction is inconsistent with other DAF publications, the information herein prevails, in accordance with (IAW) Department of the Air Force Instruction (DAFI) 90-160, Publications and Forms Management.

What types of control systems are used throughout the Department of the Air Force?

Some types of control systems may exist such as building automation systems, airfield lighting control systems, fire alarm reporting or industrial control systems. (paragraph 1)

What should security controls and solutions for control systems environments do?

Security controls and solutions applied to control systems environments should be: (1) extensive without sacrificing control systems performance and reliability, (2) tailored to the specific control systems environment, (3) verified to ensure control systems continues to operate as intended in a cyber contested environment. (paragraph 1)

What does the CE control system boundary include?

Per the DAF Chief Information Security Officer’s (CISO) (SAF/CN) Authorizing Official (AO) appointment letter (as required by AFI 17-101, the CE control system boundary includes DAF CE-owned control systems as well as IT that directly supports the operation, maintenance, and security of the logically-segmented, CE control systems network enclave (e.g., Community of Interest Network (COIN)). (paragraph 1)

Ask Reggie.Bot a question about DAFGM2026-32-01