PAM 25-2-13 governs Army identity, credential, access management, and public key infrastructure standards and procedures.
View PAM 25-2-13 on armypubs.army.mil
PAM 25-2-13 covers electronic identity authentication, authorization, PKI credentials, token issuance, and access controls. It addresses exceptions, alternate multi-factor authentication, external PKI trust, and registration authorities.
Applies to: This pamphlet institutes identity, credential, and access management (ICAM) and public key infrastructure (PKI) standards and procedures for all information technology (IT) capabilities used in and by the Army.
Per DoDI 8520.03, all Army systems will use PKI credentials as the primary means of user ID and authentication. (paragraph 3-3)
The CAC is issued to support NIPRNet access, while a separate SIPR token is used on the SIPRNet. (paragraph 3-3)
The SIPRNet and NIPRNet PKIs support issuing certificates to three types of subscribers: name, role, and system or device (also called a NPE). (paragraph 4-1)
Exceptions to Army or DoD policy for users or systems unable to comply with SIPRNet or NIPRNet token use or PKE requirements are limited to 12 months (1 year) but may be renewed. (paragraph 8-2)
Exceptions must be requested and received prior to system deployment and use. (paragraph 8-1)