<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3090-AJ84</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>201804</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3090</CODE>
            <NAME>General Services Administration</NAME>
            <ACRONYM>GSA</ACRONYM>
        </AGENCY>
        <RULE_TITLE>General Services Acquisition Regulation (GSAR); GSAR Case 2016-G511, Information and Information Systems Security</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>GSA is proposing to update the&nbsp;General Services Administration Acquisition Regulation (GSAR) to streamline and update existing GSA cybersecurity requirements and integrate these requirements within the GSAR. GSA unique policies on cybersecurity have been previously issued through other means. By incorporating cybersecurity requirements into the GSAR, the GSAR will provide centralized guidance to ensure consistent application of cybersecurity principles across the organization. Integrating these requirements into the GSAR will also allow industry to provide public comments through the rulemaking process. &nbsp;</p>
<p>The GSA cybersecurity requirements mandate contractors protect the confidentiality, integrity, and availability of unclassified GSA information and information systems from cybersecurity vulnerabilities,and threats in accordance with the Federal Information Security Modernization Act of 2014 and associated Federal cybersecurity requirements. This rule will require contracting officers to incorporate applicable GSA cybersecurity requirements within the statement of work to ensure compliance with Federal cybersecurity requirements and implement best practices for preventing cyber incidents. These GSA requirements mandate applicable controls and standards (e.g. U.S. National Institute of Standards and Technology, U.S. National Archive and Records Administration Controlled Unclassified Information standards).</p>
<p>Cybersecurity requirements for internal contractor systems, external contractor systems, cloud systems, and mobile systems will be covered by this rule. It will also update existing GSAR provision 552.239-70, Information Technology Security Plan and Security Authorization and GSAR clause 552.239-71, Security Requirements for Unclassified Information Technology Resources to only require the provision and clause when the contract will involve information or information systems connected to a GSA network.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <EO_13771_DESIGNATION>Other</EO_13771_DESIGNATION>
        <CFR_LIST>
            <CFR>48 CFR 501</CFR>
            <CFR>48 CFR 502</CFR>
            <CFR>48 CFR 511</CFR>
            <CFR>48 CFR 539</CFR>
            <CFR>48 CFR 552</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>40 U.S.C. 121(c)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>08/00/2018</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>10/00/2018</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <FURTHER_INFO_URL>www.regulations.gov</FURTHER_INFO_URL>
        <PUBLIC_COMMENT_URL>www.regulations.gov</PUBLIC_COMMENT_URL>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Michelle</FIRST_NAME>
                <LAST_NAME>Bohm</LAST_NAME>
                <TITLE>Contract Specialist</TITLE>
                <AGENCY>
                    <CODE>3090</CODE>
                    <NAME>General Services Administration</NAME>
                    <ACRONYM>GSA</ACRONYM>
                </AGENCY>
                <PHONE>215 446-4705</PHONE>
                <EMAIL>michelle.bohm@gsa.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>100 S. Independence Mall W Room: 9th Floor,</STREET_ADDRESS>
                    <CITY>Philadelphia</CITY>
                    <STATE>PA</STATE>
                    <ZIP>19106-2320</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
