AR 380-53 governs Army communications security monitoring, Information Operations Red Team activities, and Computer Defense Association Program activities.
View AR 380-53 on armypubs.army.mil
It covers authorization, notification, training, operations, reporting, equipment safeguards, red teaming, and network assistance. It requires approval, formal training, privacy protections, notification, and oversight for covered activities.
Applies to: The principles of this regulation apply to all forms of COMSEC monitoring conducted by Army elements.
Official DOD telecommunications systems are subject to monitoring at all times. (paragraph 2-4)
Each individual involved in the conduct (collection and analysis) of COMSEC monitoring will receive formal training before participating in monitoring or penetration operations. (paragraph 2-4)
A defined rules of engagement (ROE) (support agreement and charter) must be developed and signed prior to all Red Team assessments. (paragraph 3-2)
The execution of tactical overwatch operations and network surveillance of Army networks and networked devices connected to the LWN that may be performed on a 24 hours a day/7 days a week basis. (paragraph 3-5)
Individuals who discover a violation of the activities described in this regulation will promptly report the violation to the unit commander, IG, intelligence oversight officer, or the command security manager. (paragraph 5-2)