PAM 25-2-14 — Risk Management Framework For Army Information Technology

PAM 25-2-14 governs implementation of the Risk Management Framework for Army information technology across its life cycle.

Search PAM 25-2-14

  • Publication number: PAM 25-2-14
  • Title: RISK MANAGEMENT FRAMEWORK FOR ARMY INFORMATION TECHNOLOGY
  • Date: 04/08/2019
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-14 on armypubs.army.mil

Related publications


It covers Army cybersecurity governance, RMF roles, system categorization, security controls, authorization, monitoring, and assess-only IT. It requires security authorization documentation, risk assessments, secure configuration, and ongoing monitoring for applicable systems.

Applies to: Any Army capability or system owner having or seeking to acquire, develop, integrate, deploy, or decommission IT on Army infrastructure.

Topics covered

  • Army Risk Management Framework process
  • Cybersecurity governance
  • Security control assessment
  • Information system authorization
  • Security authorization packages
  • Assess-only information technology
  • Stand-alone information systems
  • Control systems

Questions and answers

Who should use PAM 25-2-14?

Any Army capability or system owner having or seeking to acquire, develop, integrate, deploy, or decommission IT on Army infrastructure. (paragraph 1-5)

What does PAM 25-2-14 require for DoD IT and information systems?

DoDI 8510.01 requires all DoD IT (referred to in this document as IT) be assessed, and all information systems (ISs) (consisting of major applications and enclaves) and platform information technology (PIT) systems be assessed and authorized. (paragraph 1-6)

What are the six steps in the Risk Management Framework process?

The RMF is a disciplined and structured process that combines IS security and risk management activities into the system development life cycle and authorizes their use within DoD. (paragraph 3-8)

What documents make up the RMF security authorization package?

The security authorization package consists of the SP, SAR, POA&M, and authorization decision document, but are not limited to the components depicted in figure 4 4. (paragraph 4-9)

Is a security assessment report required before an authorization decision?

A SAR is always required before an authorization decision. (paragraph 4-4)

Ask Reggie.Bot a question about PAM 25-2-14