PAM 25-2-2 governs the vetting, approval, acquisition, and use of cybersecurity tools within the Department of the Army.
View PAM 25-2-2 on armypubs.army.mil
It covers cybersecurity tool evaluation, DOD UC APL placement, desktop reviews, fast-track processing, and the duties of Army sponsors and vendors. It requires approved tools to meet validation, acquisition, coordination, and certification conditions.
Applies to: This pamphlet applies to cybersecurity tools used in the Army for strategic, operational, and tactical network environments.
All cybersecurity tools using encryption modules for the protection of Army information will use encryption modules that are FIPS 1402 validated at the appropriate security levels. (paragraph 2-1)
Procure all approved cybersecurity tools through CHESS. (paragraph 2-2)
Procure approved products with the exact hardware models, firmware, and software release versions listed on the DOD UC APL. (paragraph 2-2)
Products with expired certifications/removed from UC APL are no longer approved for purchase. (paragraph 2-2)
The Army sponsor must ensure that critical testing requirements and all findings identified during cybersecurity testing are properly documented. (paragraph 3-3)