PAM 25-2-11 — Cybersecurity Strategy For Programs Of Record

PAM 25-2-11 governs cybersecurity strategies for Army programs of record, including their development, review, approval, and milestones.

Search PAM 25-2-11

  • Publication number: PAM 25-2-11
  • Title: CYBERSECURITY STRATEGY FOR PROGRAMS OF RECORD
  • Date: 04/15/2019
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-11 on armypubs.army.mil

Related publications


It covers CSS management, approval processes, milestone requirements, and an outline template with program information details. The publication requires CSSs for acquisitions of systems utilizing IT and establishes submission, review, update, and approval requirements.

Applies to: This pamphlet applies to the Regular Army, the Army National Guard/Army National Guard of the United States, and the U.S. Army Reserve, unless otherwise stated.

Topics covered

  • Cybersecurity strategies for programs of record
  • CSS management processes
  • CSS review and approval
  • Acquisition milestone requirements
  • Cybersecurity testing and evaluation
  • Risk management framework documentation
  • Program information details

Questions and answers

Which systems must have a cybersecurity strategy?

All acquisitions of systems utilizing IT, including National Security Systems and legacy systems, must have a CSS. (paragraph 2-1)

When must the CSS be submitted for review and approval?

Beginning at Milestone A, the PM will submit the CSS to the Army Chief Information Officer/G6 (CIO/G 6) for review and approval prior to milestone decisions or contract awards. (paragraph 2-1)

How far in advance must CSS submissions be made?

Submissions require a minimum of 120 days prior to the milestone decision date in order to allow sufficient time for Army CIO/G 6 and DOD CIO review. (paragraph 2-2)

When must PMs have an updated and approved CSS?

PMs must have an updated and approved CSS prior to Milestones A, B, and C, to include FRP and FDD. (paragraph 2-2)

What must the ISSM P support during initial program planning meetings?

The ISSM P must be engaged in initial program planning meetings to support (1) Defining the system. (2) Assigning responsibilities. (3) Determining life cycle costs. (4) Incorporating system security engineering into the system design. (paragraph 2-1)

Ask Reggie.Bot a question about PAM 25-2-11