PAM 25-2-9 — Wireless Security Standards

PAM 25-2-9 governs the vetting, approval, acquisition, and use of wireless technology within the Department of the Army.

Search PAM 25-2-9

  • Publication number: PAM 25-2-9
  • Title: WIRELESS SECURITY STANDARDS
  • Date: 04/08/2019
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-9 on armypubs.army.mil

Related publications


It covers the DOD Unified Capabilities Approved Products List, wireless security standards, network and device requirements, encryption, authentication, and remote access. It requires assessments, authorization, monitoring, configuration, and protection of wireless data according to its classification.

Applies to: This publication applies to all Army-owned, controlled, or contracted wireless networks, systems, and devices that process, store, or transmit unclassified information.

Topics covered

  • DOD Unified Capabilities Approved Products List
  • Wireless local area network requirements
  • Component configuration requirements
  • Authentication
  • Encryption
  • Wireless personal area networks
  • Remote access
  • Wireless portable electronic device requirements

Questions and answers

When must wireless networks and devices be assessed and authorized?

All wireless networks and devices must be assessed and authorized prior to being approved to operate on the NECs LAN. (paragraph 2-1)

What happens to unauthorized wireless devices and networks?

All unauthorized wireless devices and networks will be rendered inoperable and restricted from use until an approval is granted through the Armys Risk Management Framework (RMF) process. (paragraph 2-1)

How soon are mitigation plans required for noncompliant wireless technologies?

Fielded wireless LAN and PED technologies that are not in compliance with this DA PAM must have mitigation plans developed and submitted to the designated system AO within 90 days, which establishes the systems milestone to meet the requirements of this DA PAM. (paragraph 2-1)

What monitoring is required for wired and wireless networks?

All systems will provide 24/7 continuous scanning and monitoring (see para 21e). (paragraph 2-2)

What authentication must WLAN solutions provide?

All WLAN solutions must provide for strong (two-factor) authentication at the network and device level. (paragraph 2-4)

Ask Reggie.Bot a question about PAM 25-2-9