To make sure we are protecting GSA systems from hackers and other cyber attacks at all times, each of us plays an important part in this security effort. The policies linked on this page will help you understand these efforts.
GSA orders related to IT security
2183.1A CIO Order (Dec 25, 2025)
Enterprise Identity, Credential, and Access Management (ICAM) Policy.
IT Security Policy - CIO 2100.1R GSA Information Technology (IT) Security Policy (June 6, 2026)
Newly updated IT Security Policy outlines all aspects of IT security required to keep GSA’s assets protected. Objectives of the policy are to ensure the confidentiality, integrity, and availability of all IT resources by employing security controls and managing risk.
GSA Information Technology (IT) Rules of Behavior - 2104.1C CIO (November 5, 2024)
This order sets forth GSA’s policy on user responsibilities for the secure use of the agency’s IT assets. The General Rules of Behavior implement federal policies and GSA directives and are included in GSA mandatory training.