AR 25-1 governs Army information management, data management, and information technology planning, budgeting, governance, acquisition, and management.
View AR 25-1 on armypubs.army.mil
AR 25-1 addresses Army IT mission areas, enterprise architecture, investment analysis, procurement, interoperability, cybersecurity, websites, email, and records. It requires Army organizations to manage information resources, develop performance measures, and protect and share Army information with authorized users.
Applies to: This regulation applies to IT contained in mission-command systems; intelligence systems (except as noted); weapon systems (except as noted); business systems; and, when identified, National Security Systems (NSS) developed or purchased by the DA.
Except where restricted for reasons of national security, privacy, sensitivity, or proprietary rights, personnel will manage information as a shared resource and make it available to all authorized users to accomplish their mission and functions. (paragraph 1-7)
Functional processes must be examined and streamlined to improve their effectiveness and reduce cost before investing in IT solutions to support and enable them. (paragraph 1-6)
All Army organizations will have portfolio managers to execute a process to analyze the life cycle of each of their IT investments. (paragraph 3-7)
The performance measures will determine the value-added contribution of the IT initiative or IT investment to missions, goals, and objectives; and provide a clear basis for assessing accomplishments, aiding decisionmaking, and assigning accountability at each management level. (paragraph 3-43)
All intranet web applications will be enabled to use DOD PKI certificates for user access, unless waived by the CIO/G6. (paragraph 4-9)