PAM 25-2-9 governs the vetting, approval, acquisition, and use of wireless technology within the Department of the Army.
View PAM 25-2-9 on armypubs.army.mil
It covers the DOD Unified Capabilities Approved Products List, wireless security standards, network and device requirements, encryption, authentication, and remote access. It requires assessments, authorization, monitoring, configuration, and protection of wireless data according to its classification.
Applies to: This publication applies to all Army-owned, controlled, or contracted wireless networks, systems, and devices that process, store, or transmit unclassified information.
All wireless networks and devices must be assessed and authorized prior to being approved to operate on the NECs LAN. (paragraph 2-1)
All unauthorized wireless devices and networks will be rendered inoperable and restricted from use until an approval is granted through the Armys Risk Management Framework (RMF) process. (paragraph 2-1)
Fielded wireless LAN and PED technologies that are not in compliance with this DA PAM must have mitigation plans developed and submitted to the designated system AO within 90 days, which establishes the systems milestone to meet the requirements of this DA PAM. (paragraph 2-1)
All systems will provide 24/7 continuous scanning and monitoring (see para 21e). (paragraph 2-2)
All WLAN solutions must provide for strong (two-factor) authentication at the network and device level. (paragraph 2-4)