PAM 25-1-2 governs IT contingency planning for continuity of operations and the development of information system contingency plans.
View PAM 25-1-2 on armypubs.army.mil
It covers mission essential functions, maximum tolerable downtime, business impact analysis, preventive controls, recovery strategies, and risk management framework security controls. It also sets out ISCP components, testing, training, exercises, and maintenance requirements.
Applies to: This pamphlet only addresses IT contingency planning supporting continuity of operations (COOP). The Armys COOP program is addressed in AR 500 3.
IT contingency planning is a command responsibility. (paragraph 1)
Planned testing is a critical element of a viable ISCP and will be conducted at least annually. (paragraph 3-2)
RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. (paragraph 3)
Backup is required by both DoD and Federal statute. (paragraph 3-2)
NIST SP 80034 identifies five main components of the contingency plan: supporting information, activation and notification phase, recovery phase, reconstitution phase, and appendixes. (paragraph 3-2)