PAM 25-2-17 governs requirements and criteria for all personnel to report cybersecurity related events.
View PAM 25-2-17 on armypubs.army.mil
It covers incident reporting, reporting duties, incident categories, serious incident reports, and incident response exercises. It requires reporting through specified systems and channels while safeguarding incident reports and preserving affected systems.
Applies to: This pamphlet addresses the requirement and criteria for all personnel to report cybersecurity related events.
CNSSI 4009 defines an IS incident as an occurrence that results in actual or potential jeopardy to the confidentiality, integrity, or availability of an IS or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. (paragraph 2-1)
Reportable events or incidents that may lead to criminal investigations require notification and reporting to law enforcement (LE) and CI. At a minimum, Category 1, 2, and 4 incidents are reported to DOD LE/CI as described and in accordance with established procedures in CJCSM 6510.01B. (paragraph 2-1)
Cybersecurity personnel will ensure incident response procedures are exercised at least annually for low and moderate impact systems and every 6 months for high impact systems to assure continued effectiveness. (paragraph 2-1)
All personnel will safeguard IS incident reports as sensitive controlled unclassified information (CUI) or to the classification level at which the affected system is approved to operate. (paragraph 2-1)
An individual who suspects or observes an unusual or obvious network or system incident or occurrence will stop all activities and notify his or her cybersecurity personnel (ISSO/information system security manager (ISSM)) immediately.