DAFI17-101_AFRLSUP — Risk Management Framework (RMF) For Department of Air Force Information Technology (IT)

DAFI17-101_AFRLSUP governs AFRL-specific cybersecurity risk management guidance, policies, and procedures for Department of the Air Force IT.

Search DAFI17-101_AFRLSUP

  • Publication number: DAFI17-101_AFRLSUP
  • Title: Risk Management Framework (RMF) For Department of Air Force Information Technology (IT)
  • Date: 2025-08-28

View DAFI17-101_AFRLSUP on armypubs.army.mil


The supplement addresses authorization officials, security control assessment, information system ownership, cybersecurity management, and working groups. It requires designated appointments, documentation, software certification, and use of AFRL cybersecurity systems or DAF eMASS for specified submissions and RMF activities.

Applies to: This supplement applies to all AFRL military, civilian and contractor support personnel in accordance with (IAW) appropriate provisions contained in binding support agreements and AFRL contracts.

Topics covered

  • Risk Management Framework implementation
  • Information system authorization
  • Security control assessment
  • Software certification
  • Cybersecurity working groups
  • DAF eMASS transition
  • Information system ownership

Questions and answers

Who can make authorization decisions within the DAF S&T AO Boundary?

The DAF Science &Technology (S&T) AO is the Official with the authority to make authorization decision(s) (e.g., Authorization to Operate (ATO), Denial of Authorization to Operate (DATO), Interim Authorization to Test (IATT)) within the DAF S&T AO Boundary.

Who must AFRL Mission Organizations appoint as Information System Owner?

AFRL Mission Organization (Msn Org) must officially appoint, in writing, a government official to serve as the Information System Owner (ISO) IAW DAFI 17-101 and Portfolio Manager IAW DAFI 17-110 for all AFRL owned IS to include AFRL owned IS residing in another AO’s boundary.

What is the AFRL Cybersecurity Guidebook the authoritative source for?

The AFRL Cybersecurity Guidebook, located on the AFRL Cybersecurity SharePoint site, is the authoritative source for detailed AFRL-specific guidance for RMF implementation, planning, and execution. (paragraph 17-110)

When must system authorization and change packages be submitted via eMASS?

System authorization and change packages must be submitted via eMASS for all new systems and all classified systems. (paragraph 17-110)

What must each Mission Organization do for the AFRL Cybersecurity Working Group?

Each Msn Org must appoint a primary and alternate representative in writing using the “AFRL Cybersecurity WG Appointment Memo” template located at the AFRL Cybersecurity WG SharePoint site. (paragraph 17-110)

Ask Reggie.Bot a question about DAFI17-101_AFRLSUP