USAFAVA17-201 — Network Incident Reporting Aid

USAFAVA17-201 governs computer virus and classified message incident reporting procedures, including INFOCON readiness levels.

Search USAFAVA17-201

  • Publication number: USAFAVA17-201
  • Title: NETWORK INCIDENT REPORTING AID
  • Date: 2025-06-18

View USAFAVA17-201 on armypubs.army.mil


It contains user procedures for suspected computer viruses and classified messages sent or received over unclassified networks. It also defines INFOCON levels and describes readiness conditions for information systems and networks.

Topics covered

  • Computer virus reporting
  • Classified message incidents
  • INFOCON levels
  • Cybersecurity incident response
  • Unclassified network security

Questions and answers

What is a classified message incident?

A CMI is defined as a classified message that has been sent and/or received over an unclassified network.

What actions must be recorded during a suspected virus attack?

WRITE DOWN ALL ACTIONS that occurred during the suspected virus attack. (i.e. Received suspicious e-mail with attachments; Inserted unchecked disk; Downloaded unchecked/unsecured files; etc.)

What information must be provided when reporting a suspected virus?

When reporting a suspected virus to your CSL or the CFP ensure that you answer questions on reverse side of this form and provide the technician with your name and number.

What does INFOCON provide?

INFOCON presents a structured, coordinated approach to defend against and react to adversarial attacks on DoD computer/telecommunication systems and networks.

Ask Reggie.Bot a question about USAFAVA17-201