AR 70-77 governs protection planning for critical program information and technologies, trusted systems, and damage assessments.
View AR 70-77 on armypubs.army.mil
It covers program protection, cyber incident damage assessment, and science and technology protection. It requires S&TPPs to identify critical technologies, threats, vulnerabilities, and risk mitigation measures, with annual revisions or updates when risks change.
Applies to: It applies to acquisition activities subject to AR 701, AR 252, or both; laboratories as defined in Section 3710a(d)(2), Title 15, United States Code (15 USC 3710a(d)(2)) or centers.
The S&TPP must include, at a minimum, the identification of critical technology elements and enabling technologies, threats to and vulnerabilities associated with these items, an operations security plan, and selected risk mitigation measures to counter these threats. (paragraph 5-2)
At a minimum, S&TPPs must be revised annually, or if any new or changed threat, vulnerability, or compromise is identified. (paragraph 5-2)
With the exception of basic research (budget activity 6.1), the results of which ordinarily are published and shared broadly within the scientific community, as distinguished from proprietary research and from industrial development, design, production, and product utilization, the results of which ordinarily are restricted for proprietary or national security reasons, all Army S&T efforts must prepare S&TPPs. (paragraph 5-2)
S&TPP development must be a collaborative activity between the S&T, security, and intelligence communities. (paragraph 5-2)
Ensure program executive officers (PEOs) appoint a program protection lead responsible for ensuring assigned programs have effective and valid PPPs that comply with the policy in this regulation and report status of PPPs no less than every quarter. (paragraph 2-1)