PAM 25-2-11 governs cybersecurity strategies for Army programs of record, including their development, review, approval, and milestones.
View PAM 25-2-11 on armypubs.army.mil
It covers CSS management, approval processes, milestone requirements, and an outline template with program information details. The publication requires CSSs for acquisitions of systems utilizing IT and establishes submission, review, update, and approval requirements.
Applies to: This pamphlet applies to the Regular Army, the Army National Guard/Army National Guard of the United States, and the U.S. Army Reserve, unless otherwise stated.
All acquisitions of systems utilizing IT, including National Security Systems and legacy systems, must have a CSS. (paragraph 2-1)
Beginning at Milestone A, the PM will submit the CSS to the Army Chief Information Officer/G6 (CIO/G 6) for review and approval prior to milestone decisions or contract awards. (paragraph 2-1)
Submissions require a minimum of 120 days prior to the milestone decision date in order to allow sufficient time for Army CIO/G 6 and DOD CIO review. (paragraph 2-2)
PMs must have an updated and approved CSS prior to Milestones A, B, and C, to include FRP and FDD. (paragraph 2-2)
The ISSM P must be engaged in initial program planning meetings to support (1) Defining the system. (2) Assigning responsibilities. (3) Determining life cycle costs. (4) Incorporating system security engineering into the system design. (paragraph 2-1)