PAM 25-2-7 governs Privileged Access Agreements for privileged users' acceptance of Army cybersecurity responsibilities.
View PAM 25-2-7 on armypubs.army.mil
It addresses elevated access accounts, separation of duties, least privilege, DD Form 2875 requests, denials, resubmissions, oversight, and monitoring. It requires agreements, cybersecurity training and certification, access justification, quarterly revalidation, and corrective action when privileges cannot be validated.
Individuals requiring elevated access to system control, monitoring, administration, criminal investigation, and/or compliance functions must sign a PAA. (paragraph 2-1)
Request privileged access using DD Form 2875 (System Authorization Access Request (SAAR)). (paragraph 3-1)
The Information System Security Manager (ISSM) or Information System Security Officer (ISSO) who oversees the local cybersecurity program will authorize or deny requests for privileged access before forwarding to the Network Enterprise Center (NEC) or designated service provider. (paragraph 3-1)
Commands and other Army ISSOs and ISSMs will revalidate all users with privileged access on a quarterly basis. (paragraph 4-1)
If the need cannot be revalidated, organizations will take appropriate corrective actions. (paragraph 4-1)