1. Purpose. This Order sets forth the General Services Administration’s (GSA’s) policy on IT General Rules of Behavior. The IT General Rules of Behavior implement the Federal policies and GSA directives provided in the “References” section of this Order.
2. Cancellation. This Order cancels and supersedes CIO 2104.1B CHGE 1, GSA Information Technology (IT) General Rules of Behavior, dated April 2, 2019.
3. Explanation of Changes.
a. Updated links and clarified terminology throughout.
b. Renumbered document to list references last.
c. Updated information in section 8 on Access, Hardware and Software, and Remote Access; and
d. Added new information to section 8 on Recordkeeping and the Use of External Sites and Social Media.
4. Objective. To communicate to users of GSA’s IT resources and applications their responsibilities and expected behavior in safeguarding those assets. This pertains to government furnished equipment (GFE) and resources unless otherwise specified in Section 8 of this order.
5. Applicability.
a. This Order applies to all GSA employees and contractors using GSA IT resources and applications. This Order also applies to third parties who access GSA IT resources to conduct business on behalf of, or with, GSA or GSA-supported Government organizations.
b. This Order applies to the Office of Inspector General (OIG) only to the extent that the OIG determines it is consistent with the OIG’s independent authority under the IG Act, and it does not conflict with other OIG policies or the OIG mission.
c. This Order applies to the Civilian Board of Contract Appeals (CBCA) only to the extent that the CBCA determines it is consistent with the CBCA’s independent authority under the Contract Disputes Act, and it does not conflict with other CBCA policies or the CBCA mission.
6. Roles and Responsibilities.
a. GSA supervisors must ensure their employees who access GSA IT resources and applications comply with this Order.
b. In accordance with the General Services Acquisition Regulation (GSAR) part 511.171, Contracting Officers must include compliance with this policy in the contract or task order for contractor employees.
c. GSA employees and contractors must acknowledge these IT General Rules of Behavior within 30 calendar days of their first use of a GSA IT resource and annually thereafter.
7. Penalties for Non-Compliance. Users who do not comply with the IT General Rules of Behavior may incur disciplinary action.
8. IT General Rules of Behavior.
Category |
Rules of Behavior |
Personal Use |
|
Privacy |
|
Bring Your Own Device |
These rules only apply to personal devices being used to conduct official business:
|
Access |
|
Hardware and Software |
|
Remote access |
Use approved methods (e.g., Multi-Factor Authentication (MFA), Citrix (via anywhere.gsa.gov), or Virtual Private Network (VPN) to remotely access the GSA network. |
Mobile Security |
|
Prohibited Usage |
|
Social Media |
|
Use of External Sites |
|
|
|
Security Training |
Complete the required GSA IT Security and Awareness Training each year. |
Reporting |
Promptly report suspected or confirmed breaches of security or PII/CUI to the IT Service Desk (or contact via +1-866-450-5250 or email ITServiceDesk@gsa.gov.) |
Recordkeeping |
GSA’s directive CIO 1820.2, GSA Records Management Program, provides direction on implementing recordkeeping requirements as both the development and the use of technology may create agency records. |
9. Deviations. All deviation requests must be submitted to the appropriate Information Systems Security Officer (ISSO) or Authorizing Official (AO), who will coordinate as necessary with GSA’s Chief Information Security Officer (CISO).
10. References.
a. Appendix III, Office of Management and Budget (OMB) Circular A-130 – Security of Federal Automated Information Resources
b. Federal Information Security Modernization Act (FISMA) of 2014 (Public Law 113-283)
c. GSA Order CIO 2103.2, Controlled Unclassified Information (CUI) Policy
d. GSA Order CIO 2100.1M, GSA Information Technology (IT) Security Policy
e. GSA Order CIO 2160.2B CHGE 3, GSA Electronic Messaging and Related Services
f. GSA Order ADM 7800.11A, Personal Use of Agency Office Equipment
g. GSA Order CIO 2180.2, GSA Rules of Behavior for Handling Personally Identifiable Information (PII)
h. GSA Order OSC 2106.2, GSA Social Media Policy
i. General Services Acquisition Regulation (GSAR) part 511.171
j. The Federal Records Act of 1950, as amended
l. Standards of Ethical Conduct for Employees of the Executive Branch