21.1 Information Access, Cyber Security, and Mobility (AFH-1 Section 18D)

Key Takeaways

  • The Privacy Act of 1974 prohibits disclosing information from a system of records without the written consent of the subject individual, except that a parent or legal guardian may act for a minor or an incompetent person.
  • FOIA requests are written requests that cite or imply the Freedom of Information Act; agencies have 20 workdays to deny or release records, plus one 10-workday extension for unusual circumstances, and denials must notify appeal rights.
  • Classified information-system access requires a favorable background investigation, a security clearance, and need to know; all Airmen must complete Information Assurance Awareness training before system access.
  • Using a hotel business center or other public computing service to reach web-based government services compromises login credentials and must be reported as a security incident.
  • COMSEC has three components—cryptosecurity, transmission security, and physical security—while TEMPEST denies information derived from compromising emanations inside an inspectable space.
Last updated: August 2026

Staff Sergeant and Technical Sergeant promotion tests both require ADTC Level B on AFH 1, 15 February 2025, Section 18D. Apply the access and cyber rules. This is not Integrated Defense, OPSEC, or Information Protection (18A–18C). It is lawful access to records, protection of systems Airmen log into, and mobility failures from phones, laptops, and hotel business centers.

The Privacy Act (18.15)

The Privacy Act of 1974 (as amended) governs personal information a federal agency keeps in a system of records—records under agency control retrieved by name, number, or unique identifier. It lets the subject seek access and amendment. Those rights belong to the person the record is about and cannot be asserted derivatively, except that the parent of a minor or the legal guardian of an incompetent person may act on that individual's behalf.

A personally identifiable information (PII) breach is a loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or similar event in which persons other than authorized users, for an other than authorized purpose, have access or potential access to PII, physical or electronic. AFI 33-332, Air Force Privacy and Civil Liberties Program, covers safeguarding and reporting. When an email actually transmits personal information, begin with: "This e-mail contains controlled unclassified information which must be protected under The Privacy Act and AFI 33-332." Do not stamp that language on messages that do not contain personal information.

Clearance, consent, and system access

Section 18D does not reprint Confidential/Secret/Top Secret marking rules from 18C. It lists when access is lawful:

Access situationWhat AFH-1 Section 18D requires
Disclose Privacy Act recordsWritten consent of the subject (parent or guardian may act for a minor or incompetent)
Share inside DoD or another federal agencyOfficial need to know, a routine use published in the SORN, or a Privacy Act exception
Collect personal data for a system of recordsPrivacy Act statement; collection limited to law or Executive Order; SORN with a 30-day Federal Register comment period; no First Amendment conflict
User access to classified information systemsFavorable background investigation, security clearance, and need to know
Process DoD information on a wireless or mobile deviceISSO approval first; ISSO keeps documented approval authority and inventory
Hotel business center or other public ITDo not process government-owned unclassified, sensitive, or classified information

The Freedom of Information Act (FOIA) is the other 18D access statute. FOIA provides access to federal agency records except those protected by specific exemptions. A FOIA request is a written request that cites or implies FOIA. The mandatory clock is 20 workdays to deny the request or release the records, plus one additional 10-workday extension when specific unusual circumstances exist. Denials require notification of appeal rights. Requesters may appeal or litigate. DoDM 5400.07-R_AFMAN 33-302 is the procedures reference. FOIA is public access to agency records; the Privacy Act is an individual's own records in a system of records.

Cybersecurity (18.17)

Cybersecurity is the prevention of damage to, protection of, and restoration of computers, electronic communications systems, wire communication, and electronic communication, including information contained therein, to ensure availability, integrity, authentication, confidentiality, and nonrepudiation. Disciplines include the Air Force Risk Management Framework, IT controls and countermeasures, communications security, TEMPEST, Air Force Assessment and Authorization, and the Cybersecurity Workforce Improvement Program. AFI 17-130, Cybersecurity Program Management, is the program reference. All Air Force personnel must complete Information Assurance Awareness training before system access.

Cyber hygiene functions as AFH-1 lists them

FunctionMeaning in AFH-1
IdentifyDevelop and maintain the organizational understanding required to manage cybersecurity risk
ProtectImplement controls to ensure the delivery of mission-critical infrastructure services
DetectPossess the ability to detect cybersecurity events when they occur
RespondPossess the ability to take action regarding detected cybersecurity events
RecoverPossess the ability to remain operationally resilient and to restore capabilities or services impaired by cybersecurity events

Computer security and information systems (18.18–18.19)

Computer security (COMPUSEC) ensures confidentiality, integrity, and availability of information-system assets—hardware, software, firmware, and information processed, stored, and communicated. Government-provided hardware and software are for official use and limited authorized personal use only: supervisor-approved, reasonable duration and frequency, and not adverse to official duties or system capacity. Authorized personal or unofficial use of internet-based capabilities on federal resources must comply with AFI 10-701, Operations Security, and the Joint Ethics Regulation.

An information system is a discrete set of information resources organized for collection, processing, maintenance, use, sharing, dissemination, or disposition of information, including specialized systems such as industrial/process controls and telephone switching. Users protect systems against tampering, theft, and loss through physical access control; a favorable background investigation, security clearance, and need to know for classified; encryption; and protection against casual viewing. A threat is any circumstance or event with potential to adversely impact operations through unauthorized access, destruction, disclosure, modification, or denial of service. A countermeasure counters a threat, vulnerability, or attack by preventing or minimizing damage, or by reporting the event. Section 18D does not title a separate insider-threat program; clearance plus need to know is the insider control.

Every Air Force information system has vulnerabilities. Three steps protect systems from viruses and other malicious logic:

StepWhat it means
InfectionInvasion of information-system applications, processes, or services by virus or malware code that causes the system to malfunction
DetectionA signature- or behavior-based antivirus system that signals when a virus or malware anomaly occurs
ReactionImmediately notify your information system security officer and follow local procedures

Mobility, COMSEC, and TEMPEST (18.20–18.23)

Mobile computing devices are portable electronic devices, laptops, smartphones, and other handhelds that store data locally and reach USAF-managed networks. All wireless systems—peripherals, operating systems, applications, network connection methods, and services—must be approved before processing DoD information. The ISSO keeps documented approval authority and inventory. Unassigned devices must be secured against tampering or theft. Users sign a detailed user agreement.

Do not use public computing facilities such as hotel business centers to process government-owned unclassified, sensitive, or classified information. Public computing is any IT not under your private or U.S. Government control. Using e-mail, messaging, or web applications to reach web-based government services from those machines compromises login credentials and must be reported as a security incident.

COMSEC denies unauthorized persons information derived from U.S. Government information systems related to national security and ensures authenticity. Three components: cryptosecurity (technically sound cryptosystems); transmission security (protect transmissions from interception by means other than cryptanalysis, including registered mail, call signs, authentication, and secure telephone or facsimile); and physical security (need to know and clearance, storage, accountability, authorized transport, and reporting compromise).

TEMPEST, formerly emissions security, denies information derived from compromising emanations from cryptographic equipment, information systems, and telecommunications systems. Inspectable space is the area where intercepting emanations without being detected would be difficult. Countermeasures include classified/unclassified equipment separation, shielding, and grounding.

A Staff Sergeant who forwards a roster without written consent, a routine-use SORN, a need to know, or an exception has a Privacy Act problem. A Technical Sergeant who opens web-based government mail on a hotel kiosk has a reportable credential compromise. Virus alerts go to the ISSO immediately.

Loading diagram...
Section 18D cyber hygiene loop
Test Your Knowledge

Under the Privacy Act of 1974, when may information from a system of records be disclosed without using a published routine use or a Privacy Act exception?

A
B
C
D
Test Your Knowledge

A written request that cites or implies the Freedom of Information Act arrives at a base office. What is the mandatory initial time limit to deny the request or release the records?

A
B
C
D
Test Your Knowledge

For classified information systems, AFH-1 Section 18D bases user access on which combination?

A
B
C
D
Test Your Knowledge

An Airman uses a hotel business-center computer and a web application to reach a web-based government service. How does AFH-1 Section 18D treat that action?

A
B
C
D