16.4 Information Access, Cybersecurity & Mobility

Key Takeaways

  • The Freedom of Information Act imposes a mandatory time limit of 20 workdays to deny a request or release records, with a 10-workday extension permitted for specific unusual circumstances.
  • The Privacy Act prohibits disclosure of information from a system of records without the written consent of the subject individual, and System of Records Notices require a 30-day public comment period.
  • The five functions of the Air Force Cybersecurity Program are identify, protect, detect, respond, and recover.
  • All Air Force personnel must complete Information Assurance Awareness training prior to system access and annually thereafter.
  • Using public computing facilities such as hotel business centers to access web-based government services constitutes a compromise of login credentials and must be reported as a security incident.
Last updated: August 2026

The Privacy Act

"The Privacy Act of 1974 (as amended) establishes a code of fair information practices that govern the collection, maintenance, use, and dissemination of personal information about individuals that is maintained in a system of records by federal agencies." It provides individuals a means to seek access to and amend their records and sets forth agency record-keeping requirements.

TopicRules
DisclosurePrivacy Act rights are personal to the individual who is the subject of the record and cannot be asserted derivatively by others. The Act prohibits disclosure from a system of records without the written consent of the subject individual. The parent of any minor, or the legal guardian of an incompetent, may act on behalf of that individual
CollectionLimited to what the law or executive orders authorize. System of Records Notices (SORNs) must be published in the federal register allowing the public a 30-day comment period. Collection must not conflict with the rights guaranteed by the First Amendment. A Privacy Act statement must be given when individuals are asked to provide personal information for collection in a system of records
System of records"A group of any records under the control of any agency from which information is retrieved by the individual's name, number, or unique identifier"

When disclosure is permitted: DoD personnel may disclose records to other DoD offices when there is "an official need to know," and to other federal agencies or individuals when the disclosure is a "routine use" published in the SORN or authorized by a Privacy Act exception. Information may also be released for a disclosed specified purpose with the subject's consent. The office of primary responsibility should keep an account of all information released.

Personally identifiable information must be safeguarded to ensure "an official need to know" access and to avoid actions that could result in harm, embarrassment, or unfairness to the individual. The Office of Management and Budget defines a PII breach as "a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar term referring to situations where persons other than authorized users and for an other than authorized purpose have access or potential access to personally identifiable information, whether physical or electronic."

The "retrieved by name, number, or unique identifier" definition is the discriminator — a collection of records is only a system of records if information is retrieved by an individual identifier.

The Freedom of Information Act

"The Freedom of Information Act provides access to federal agency records (or parts of these records) except those protected from release by specific exemptions." FOIA requests are written requests that cite or imply the Act.

TimelineValue
Mandatory time limit to deny the request or release the records20 workdays
Additional extension permitted for specific unusual circumstances10 workdays

Denials require notification of appeal rights, and requesters can file an appeal or litigate. The reference is DoDM 5400.07-R / AFMAN 33-302.

20 plus 10 workdays is the single most testable pair in Section 18D. Note both are workdays, not calendar days.

Cybersecurity

"Cybersecurity is defined as the prevention of damage to, protection of, and restoration of computers, electronic communications systems, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation."

The five properties — availability, integrity, authentication, confidentiality, and nonrepudiation — are worth memorizing as a set.

Cybersecurity disciplines named by AFH 1: Air Force Risk Management Framework, IT controls/countermeasures, communications security, TEMPEST (formerly emissions security), AF Assessment and Authorization (formerly Certification and Accreditation), and the Cybersecurity Workforce Improvement Program. The reference is AFI 17-130, Cybersecurity Program Management.

Training requirement: "All USAF personnel are required to complete Information Assurance Awareness training prior to system access and annually thereafter."

The Five Functions of the Air Force Cybersecurity Program

FunctionWhat it means
IdentifyDevelop and maintain the organizational understanding required to manage cybersecurity risk
ProtectImplement controls to ensure the delivery of mission critical infrastructure services
DetectPossess the ability to detect cybersecurity events when they occur
RespondPossess the ability to take action regarding detected cybersecurity events
RecoverPossess the ability to remain operationally resilient and to restore capabilities or services that were impaired

Identify, protect, detect, respond, recover. Note the overlap with the emergency management mission areas (prevention, protection, response, recovery, mitigation) and the integrated defense effects — three different five-part frameworks in three different chapters, which is exactly why the exam mixes them. The cybersecurity set is the one beginning with Identify and ending with Recover.

Computer and Information Systems Security

Computer security consists of "measures and controls that ensure confidentiality, integrity, and availability of information systems assets including hardware, software, firmware, and information being processed, stored, and communicated."

An information system is "a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information," and also includes specialized systems such as industrial/process controls, telephone switching and private branch systems, and environmental controls. That last clause surprises candidates — HVAC controls are an information system.

Protection is achieved by:

  • Controlling physical access to facilities and data
  • Ensuring user access is based upon a favorable background investigation, security clearance, and need to know (for classified)
  • Ensuring protection of unclassified, sensitive, and classified information through encryption per Federal Information Processing Standard Publication 140-2

A countermeasure is "any action, device, procedure, or technique that meets or opposes (counters) a threat, vulnerability, or attack by eliminating, preventing, or minimizing damage, or by discovering and reporting the event so corrective action can be taken."

The Three Steps of Malicious Logic Protection

StepDefinition
Infection"The invasion of information system applications, processes, or services by a virus or malware code causing the information system to malfunction"
Detection"A signature or behavior-based antivirus system that signals when an anomaly caused by a virus or malware occurs"
Reaction"When notified of a virus or malware detection, react by immediately notifying your information system security officer and following local procedures"

Infection, detection, reaction — and the required action in the third step is to immediately notify the information system security officer, which is the answer to any scenario item about discovering malware.

Mobile Devices and Public Computing

Mobile computing devices are information systemsportable electronic devices, laptops, smartphones, and other handheld devices that can store data locally and access USAF managed networks. The rules:

  • All wireless systems — including peripheral devices, operating systems, applications, network connection methods, and services — must be approved prior to processing Department of Defense information
  • The information systems security officer maintains documented approval authority and inventory information on all approved devices
  • All mobile computing devices not assigned or in use must be secured to prevent tampering or theft
  • Users will sign a detailed user agreement outlining responsibilities and restrictions

Public computing facilities. "Do not use public computing facilities or services, such as hotel business centers, to process government-owned unclassified, sensitive, or classified information." These include any information technology resources not under your private or U.S. Governmental control.

The consequence clause is the tested part: "Use of e-mail applications, messaging software, or web applications to access web-based government services constitutes a compromise of login credentials and must be reported as a security incident." It is not merely discouraged — it is automatically a reportable security incident.

Communications Security

COMSEC refers to "measures and controls taken to deny unauthorized persons information derived from information systems of the U.S. Government related to national security and to ensure the authenticity of such information systems."

ComponentDefinition
Cryptosecurity"A component of communications security resulting from the provision and proper use of technically sound cryptosystems"
Transmission securityResults from "measures designed to protect transmissions from interception and exploitation by means other than cryptoanalysis." Examples: secured communications systems, registered mail, secure telephone and facsimile equipment, manual cryptosystems, call signs, or authentication
Physical securityResults from "all physical measures necessary to safeguard communications security material from access by unauthorized persons"control procedures and physical barriers. Common measures: verifying need to know and clearance, proper storage and handling, accurate accounting, authorized transport, and immediately reporting loss or possible compromise

The transmission security definition carries a key qualifier — "by means other than cryptoanalysis." Protecting against codebreaking is cryptosecurity; protecting against interception is transmission security.

TEMPEST

"TEMPEST, formerly known as emissions security, is protection resulting from all measures taken to deny unauthorized persons information of value that may be derived from the interception and analysis of compromising emanations from cryptographic equipment, information systems, and telecommunications systems."

The objective: "to deny access to classified, and in some instances unclassified, information that contains compromising emanations within an inspectable space."

The inspectable space is "the area in which it would be difficult for an adversary with specialized equipment to attempt to intercept compromising emanations without being detected."

TEMPEST countermeasures named by AFH 1: classified and unclassified equipment separation, shielding, and grounding.

Three facts to hold: TEMPEST was formerly called emissions security, it addresses compromising emanations, and the protected zone is the inspectable space.

Test Your Knowledge

What mandatory time limits does the Freedom of Information Act impose?

A
B
C
D
Test Your Knowledge

An Airman on temporary duty uses a hotel business center computer to log into a web-based government service. How does AFH 1 treat this?

A
B
C
D
Test Your Knowledge

Which set names the five functions of the Air Force Cybersecurity Program?

A
B
C
D