PAM 25-2-1 — Army Cross Domain Solution And Data Transfer Management

PAM 25-2-1 governs Army cross-domain solution approval, connections between security domains, and manual data transfers.

Search PAM 25-2-1

  • Publication number: PAM 25-2-1
  • Title: ARMY CROSS DOMAIN SOLUTION AND DATA TRANSFER MANAGEMENT
  • Date: 04/12/2019
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-1 on armypubs.army.mil

Related publications


It defines security domains and cross-domain solutions, and covers approval support, documentation, and transfer services. It requires coordination, authorization, training, records, and annual review for specified activities.

Applies to: Further, it applies to all Army secret and below interoperability (SABI) CDSs governed by the Department of Defense (DOD) connection approval process, and managed by the Army HQDA CIO/G 6 Cybersecurity Directorate.

Topics covered

  • Cross-domain solution approval
  • Security domain connections
  • Manual data transfers
  • Removable media authorization
  • Data transfer documentation
  • Automated cross-domain services

Questions and answers

What is a security domain?

A security domain is a system or network, operating at a particular sensitivity level, which implements a security policy and is administered by a single authority. (paragraph 2-1)

What is a cross-domain solution?

A CDS is a form of controlled interface that provides the ability to manually or automatically access or transfer information between different security domains. (paragraph 2-1)

When must information system owners contact the Army CDMO?

Information system owners (ISOs) must contact the Army CDMO as soon as a cross domain requirement is identified. (paragraph 3-1)

When can organizations procure cross-domain solution technology?

Organizations requiring a CDS must not acquire or procure CDS technology until their connection requirement is approved by the Defense Security/Cybersecurity Authorization Working Group (DSAWG). (paragraph 3-1)

When are removable media prohibited on SIPRNet systems?

All removable media are prohibited from use on all SIPRNet servers, systems, and stand-alone workstations unless specifically authorized by the AO. (paragraph 4-1)

Ask Reggie.Bot a question about PAM 25-2-1