DAFI17-101_AFRLSUP governs AFRL-specific cybersecurity risk management guidance, policies, and procedures for Department of the Air Force IT.
View DAFI17-101_AFRLSUP on armypubs.army.mil
The supplement addresses authorization officials, security control assessment, information system ownership, cybersecurity management, and working groups. It requires designated appointments, documentation, software certification, and use of AFRL cybersecurity systems or DAF eMASS for specified submissions and RMF activities.
Applies to: This supplement applies to all AFRL military, civilian and contractor support personnel in accordance with (IAW) appropriate provisions contained in binding support agreements and AFRL contracts.
The DAF Science &Technology (S&T) AO is the Official with the authority to make authorization decision(s) (e.g., Authorization to Operate (ATO), Denial of Authorization to Operate (DATO), Interim Authorization to Test (IATT)) within the DAF S&T AO Boundary.
AFRL Mission Organization (Msn Org) must officially appoint, in writing, a government official to serve as the Information System Owner (ISO) IAW DAFI 17-101 and Portfolio Manager IAW DAFI 17-110 for all AFRL owned IS to include AFRL owned IS residing in another AO’s boundary.
The AFRL Cybersecurity Guidebook, located on the AFRL Cybersecurity SharePoint site, is the authoritative source for detailed AFRL-specific guidance for RMF implementation, planning, and execution. (paragraph 17-110)
System authorization and change packages must be submitted via eMASS for all new systems and all classified systems. (paragraph 17-110)
Each Msn Org must appoint a primary and alternate representative in writing using the “AFRL Cybersecurity WG Appointment Memo” template located at the AFRL Cybersecurity WG SharePoint site. (paragraph 17-110)