Home / Air Force / AFI / AFI 17-203

AFI 17-203 — Cyber Incident Handling

AFI 17-203 is listed as current Current
in the AF e-Publishing catalog as of our last index refresh (2026-08-23). Status is mirrored from that catalog, re-checked weekly — every change is logged. Note: its publication date is 2017-03-16 — 9.4 years old — so check for newer interim changes before citing it.
BranchU.S. Air Force
SeriesAFI
Publication date2017-03-16 (9.4 years ago)
StatusCurrent
Proponent / OPRSAF/CN
Source of recordAF e-Publishing

Download PDF Official document (AF e-Publishing)

What this publication covers

This Instruction provides guidance on AF DCO and the conduct of network incident handling. For the purposes of this instruction, DCO and DoDIN Operations refer to day-to-day network monitoring, analysis, detection, and response. They do not refer to missions/actions associated with deliberate mission planning for named defensive operations.
This Instruction also applies to incidents involving systems which are not directly connected to or part of an AF network, e.g., supervisory control and data acquisi tion (SCADA) systems or information systems that are an integral part of a weapon system and may connect to the DoDIN indirectly through the use of removable media or a wireless connection.
— AFI 17-203, paragraph 1.1.3, p.4

Publications that cite AFI 17-203

If AFI 17-203 changes, these are the documents that point at it. Extracted from the publications' own text, so it reflects what we have read, not a complete dependency map. Every publishing office validates its own document; nobody validates the seams between them.

Watch this publication
Get an email if AFI 17-203 is revised, superseded, or rescinded.

Nearby in the AFI series

This is an unofficial index built from the public catalog. The controlling copy is always the one on AF e-Publishing — verify there before citing AFI 17-203 in an official product.