AR 70-1 governs Army-managed acquisition programs under the Department of Defense Adaptive Acquisition Framework.
View AR 70-1 on armypubs.army.mil
AR 70-1 establishes policy and assigns responsibilities for acquisition, engineering, testing and evaluation, sustainment, affordability, cost analysis, information technology, cybersecurity, and intellectual property. It includes requirements for program cost, fielding, and performance goals, cybersecurity implementation, systems engineering, affordability constraints, and intellectual property planning.
Applies to: This publication applies to all Army-managed acquisition programs, including national security systems (NSS) and acquisition special access programs (unless specifically excepted by a program charter) (see chap 2).
All acquisition of IT must incorporate cybersecurity requirements, in accordance with DoDI 8500.01. (paragraph 10-3)
Cybersecurity must be addressed throughout the entire acquisition and sustainment life cycle in all acquisition programs, regardless of the acquisition pathway applied or classification level, including those that are unclassified. (paragraph 11-1)
PMs, assisted by personnel in organizations supporting the acquisition community, are responsible for the cybersecurity of their programs, systems, and information. (paragraph 1-8)
In coordination with the information systems security manager (ISSM) and systems security engineer (SSE), the system owner is responsible for the development, implementation, and maintenance of the security plan. (paragraph 1-8)
Systems engineering activities will be performed as part of concept and system development to inform developmental decisions and ensure the Army is systematically investing in the appropriate capabilities to meet mission needs. (paragraph 4-2)