DAFI16-1402 — Counter-insider Threat Program Management

DAFI16-1402 governs the Department of the Air Force framework for detecting, deterring, and mitigating insider threats to national security and DAF assets.

Search DAFI16-1402

  • Publication number: DAFI16-1402
  • Title: COUNTER-INSIDER THREAT PROGRAM MANAGEMENT
  • Date: 2024-05-10

View DAFI16-1402 on armypubs.army.mil


It establishes the DAF Counter-Insider Threat Program, the DAF C-InT Hub, and the DAF Counter-Insider Threat Working Group. It addresses network monitoring, information sharing, training, reporting thresholds, privacy, and civil liberties.

Topics covered

  • DAF Counter-Insider Threat Program
  • DAF C-InT Hub
  • Insider threat reporting thresholds
  • Network monitoring and auditing
  • Information sharing
  • Training and awareness
  • Privacy and civil liberties

Questions and answers

What does the DAF C-InT Hub do with insider threat information?

The DAF C-InT Hub provides the DAF a centralized capability where all insider threat-related information flows and is subsequently disseminated to the proper functional entities for action or resolution. (paragraph 2)

Can the DAF C-InT Hub take disciplinary action?

The DAF C-InT Hub provides mitigation recommendations for Commanders but does not take independent adjudicative or disciplinary action. (paragraph 2)

What events are not reported as an insider threat?

Seeking voluntary mental health counseling or being the victim of sexual assault or other violent crimes are examples of events that shall not be reported as an insider threat. (paragraph 2)

What are the DoD Insider Threat Program enterprise reporting thresholds?

The 13 DoD Insider Threat Program enterprise reporting thresholds are: serious threat, allegiance to the United States, espionage/foreign considerations, personal conduct, behavioral considerations, criminal conduct, unauthorized disclosure, unexplained personnel disappearance, handling protected information, misuse of information technology, terrorism, criminal affiliations, and adverse clearance actions. (paragraph 2)

What legal and policy requirements apply to network monitoring?

All monitoring will be conducted in accordance with applicable law and policy. (paragraph 3)

Ask Reggie.Bot a question about DAFI16-1402