PAM 25-2-14 governs implementation of the Risk Management Framework for Army information technology across its life cycle.
View PAM 25-2-14 on armypubs.army.mil
It covers Army cybersecurity governance, RMF roles, system categorization, security controls, authorization, monitoring, and assess-only IT. It requires security authorization documentation, risk assessments, secure configuration, and ongoing monitoring for applicable systems.
Applies to: Any Army capability or system owner having or seeking to acquire, develop, integrate, deploy, or decommission IT on Army infrastructure.
Any Army capability or system owner having or seeking to acquire, develop, integrate, deploy, or decommission IT on Army infrastructure. (paragraph 1-5)
DoDI 8510.01 requires all DoD IT (referred to in this document as IT) be assessed, and all information systems (ISs) (consisting of major applications and enclaves) and platform information technology (PIT) systems be assessed and authorized. (paragraph 1-6)
The RMF is a disciplined and structured process that combines IS security and risk management activities into the system development life cycle and authorizes their use within DoD. (paragraph 3-8)
The security authorization package consists of the SP, SAR, POA&M, and authorization decision document, but are not limited to the components depicted in figure 4 4. (paragraph 4-9)
A SAR is always required before an authorization decision. (paragraph 4-4)