GSA Information Technology (IT) Security Policy

Number: 2100.1R CIO
Status: Active
Signature Date: 06/16/2026
Expiration Date: 06/30/2029

Purpose:

This Order sets forth the General Services Administration’s (GSA) IT Security Policy and establishes the GSA’s risk-based management approach of employing management, technical, and operational controls to achieve GSA’s security objectives to comply with Federal laws and regulations, Executive Orders, Office of Management and Budget (OMB) Memoranda, and Cybersecurity & Infrastructure Security Agency (CISA) Cybersecurity Directives.

Background:

Public Law 113-283, “Federal Information Security Modernization Act of 2014 (FISMA)” and OMB Circular A-130, “Managing Information as a Strategic Resource” require each agency to establish an information security program, including policies and procedures that provide security for the information and information systems supporting the agency’s operations and assets. This Order and GSA IT’s security procedural guides and other security policies provide the procedures and processes to meet those requirements. As required in Executive Order (EO) 13800, “Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure”, the GSA has organized this Order to reflect the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework (CSF) 2.0 core functions of Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS), and Recover (RC). The Govern function is covered within this Order, the other core functions are covered in the GSA Cybersecurity Handbook.

Applicability:

This Order applies to:

  1. GSA Federal employees, contractors, and vendors of GSA, who manage, maintain, operate, or protect GSA systems or data;
  2. Except for Section 2, paragraph 2.23, this policy applies to the Office of Inspector General (OIG) only to the extent that the OIG determines it is consistent with the OIG’s independent authority under the IG Act and it does not conflict with other OIG policies or the OIG mission.

Cancellation:

This Order cancels and supersedes CIO 2100.1Q, GSA Information Technology (IT) Security Policy, dated October 16, 2024. 

Summary of Changes:

This Order includes the following updates:

  1. Restructured to include a GSA Cybersecurity Handbook and to align to NIST CSF 2.0 functions.
  2. Updated format to comply with OAS 1832.1C, “Internal Directives Management.”
  3. Updated the roles and responsibilities involved in Cybersecurity within the GSA.
  4. Revised, consolidated, and clarified many security requirements in both the Policy and the Handbook.
  5. Updated the OCISO Divisions based on FY26 GSA IT reorganization.