AR 25-2 governs the Army Cybersecurity Program, including cybersecurity policies, responsibilities, risk management, and protection of information technology.
View AR 25-2 on armypubs.army.mil
AR 25-2 addresses cybersecurity governance, risk management, access control, information protection, teleworking, monitoring, incident response, and compliance. It requires authorization, authentication, security controls, vulnerability management, and adherence to applicable Department of Defense and Army policies.
Compliance with this regulation and the supporting DA pamphlets is mandatory. (paragraph 1-8)
Ensure that IT has been granted authorization to operate (ATO) by the assigned authorizing official (AO). (paragraph 6)
Remote privileged access to DOD systems using privately owned IT is prohibited. (paragraph 4-25)
Any use of Army IT is made with the understanding that users will have no expectations as to the privacy or confidentiality of any electronic communication, including minor incidental personal uses. (paragraph 4-26)
The Army reserves and will exercise the right to access, intercept, inspect, record, and disclose any and all electronic communications on Army IT, including minor incidental personal uses, at any time, with or without notice to anyone, unless prohibited by law or privilege. (paragraph 4-26)