PAM 25-2-1 governs Army cross-domain solution approval, connections between security domains, and manual data transfers.
View PAM 25-2-1 on armypubs.army.mil
It defines security domains and cross-domain solutions, and covers approval support, documentation, and transfer services. It requires coordination, authorization, training, records, and annual review for specified activities.
Applies to: Further, it applies to all Army secret and below interoperability (SABI) CDSs governed by the Department of Defense (DOD) connection approval process, and managed by the Army HQDA CIO/G 6 Cybersecurity Directorate.
A security domain is a system or network, operating at a particular sensitivity level, which implements a security policy and is administered by a single authority. (paragraph 2-1)
A CDS is a form of controlled interface that provides the ability to manually or automatically access or transfer information between different security domains. (paragraph 2-1)
Information system owners (ISOs) must contact the Army CDMO as soon as a cross domain requirement is identified. (paragraph 3-1)
Organizations requiring a CDS must not acquire or procure CDS technology until their connection requirement is approved by the Defense Security/Cybersecurity Authorization Working Group (DSAWG). (paragraph 3-1)
All removable media are prohibited from use on all SIPRNet servers, systems, and stand-alone workstations unless specifically authorized by the AO. (paragraph 4-1)