PAM 25-2-17 — Incident Reporting

PAM 25-2-17 governs requirements and criteria for all personnel to report cybersecurity related events.

Search PAM 25-2-17

  • Publication number: PAM 25-2-17
  • Title: INCIDENT REPORTING
  • Date: 04/08/2019
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-17 on armypubs.army.mil

Related publications


It covers incident reporting, reporting duties, incident categories, serious incident reports, and incident response exercises. It requires reporting through specified systems and channels while safeguarding incident reports and preserving affected systems.

Applies to: This pamphlet addresses the requirement and criteria for all personnel to report cybersecurity related events.

Topics covered

  • Cybersecurity-related event reporting
  • Incident categories
  • Serious incident reports
  • Incident response exercises
  • IS incident examples
  • COMSEC incident reporting

Questions and answers

How is an IS incident defined?

CNSSI 4009 defines an IS incident as an occurrence that results in actual or potential jeopardy to the confidentiality, integrity, or availability of an IS or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. (paragraph 2-1)

Which incidents must be reported to DOD law enforcement and counterintelligence?

Reportable events or incidents that may lead to criminal investigations require notification and reporting to law enforcement (LE) and CI. At a minimum, Category 1, 2, and 4 incidents are reported to DOD LE/CI as described and in accordance with established procedures in CJCSM 6510.01B. (paragraph 2-1)

How often must incident response procedures be exercised?

Cybersecurity personnel will ensure incident response procedures are exercised at least annually for low and moderate impact systems and every 6 months for high impact systems to assure continued effectiveness. (paragraph 2-1)

How must IS incident reports be safeguarded?

All personnel will safeguard IS incident reports as sensitive controlled unclassified information (CUI) or to the classification level at which the affected system is approved to operate. (paragraph 2-1)

What must a person do after observing or suspecting a network or system incident?

An individual who suspects or observes an unusual or obvious network or system incident or occurrence will stop all activities and notify his or her cybersecurity personnel (ISSO/information system security manager (ISSM)) immediately.

Ask Reggie.Bot a question about PAM 25-2-17