PAM 25-2-16 governs Army communications security procedures for information technology capabilities and protection of classified information.
View PAM 25-2-16 on armypubs.army.mil
It covers national security systems, controlled unclassified information, cryptographic solutions, wireless systems, key management, and NSA support requests. It requires approved products, accountability for cryptographic material, planning for key and certificate management, and defined request processes.
Only NSA/Central Security Services-approved COMSEC products and services (to include Commercial Solutions for Classified (CSfC) and cryptographic high value property (CHVP)) will be used to secure NSI and systems. (paragraph 2-1)
Do not use foreign cryptographic systems or products to protect U.S. classified NSI. (paragraph 2-1)
The KCMP will describe accountability/tracking of the keying material over the entire life cycle of the system from generation, distribution, storage, accounting, and entry of key into the system through use, deletion, and final destruction. (paragraph 1-4)
The use of commercial non-encrypted radio systems in support of command and control functions is strictly prohibited. (paragraph 1-4)
Any Army organization seeking NSA services to support mission requirements must submit a request by means of a client questionnaire. (paragraph 2-8)