Showing posts with label GSA. Show all posts
Showing posts with label GSA. Show all posts

Tuesday, August 27, 2024

Review - GSA Publishes Contract HAZMAT Information 60-day ICR Revision Notice

Today, the General Services Administration published a 60-day information collection request revision notice in the Federal Register (89 FR 68616-68617) for “Hazardous Material Information - GSAR Section Affected: 552.223-72” (Control # 3090-0205). The revision is a minor change in the burden hours estimate for the ICR. The table below shows the change in burden estimate.

Background

According to the Abstract for the current version of the ICR:

“The Federal Hazardous Substance Act (Pub. L. 86-613) and Hazardous Material Transportation Act (Pub. L. 93-633) prescribe standards for packaging of hazardous substances. To meet the requirements of the Acts, the General Services Administration Regulation prescribes provision 552.223-72 [link added], Hazardous Material Information, to be inserted in solicitations that provides for delivery of hazardous materials on an f.o.b. origin basis. The provision requires the contractor to identify for each National Stock Number (NSN) the Department of Transportation (DOT) Shipping Name, DOT Hazards Class, and whether the item requires a DOT label.”

Public Comments

GSA is soliciting public comments on this ICR revision notice. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov: Docket # GSA-GSA-2024-0001-00023). Comments should be submitted by October 28th, 2024

 

For more information on the changes in the ICR burden estimate, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/gsa-publishes-contract-hazmat-information - subscription required. 

Tuesday, October 24, 2023

OMB Approves FACA NPRM

Yesterday, OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the General Services Administration (GSA) on “Federal Management Regulation (FMR); FMR Case 2022-01, Federal Advisory Committee Management”. The NPRM was sent to OIRA on July 27th, 2023.

According to the Spring 2023 Unified Agenda entry for this rulemaking:

“FACA is a transparency statute designed to provide Congress, interested stakeholders, and the public with information on, and access to the activities, membership, meetings, costs, etc. of federal advisory committees established by the Executive Branch. Under section 7 of the Act, GSA is responsible for preparing regulations for implementing FACA. The proposed rule revisions will provide updates and clarification to federal advisory committee management policies and processes. The proposed rule revisions will also encourage diversity and inclusivity in federal advisory committee activities, which is an Administration priority.”

A lot of the nitty-gritty work of development of technical regulations and policy guidance is done by FACAs. So, this regulation could have some interesting unintended consequences to those development processes over the years. 

This NPRM could show up in the Federal Register later this week, but more likely next week.


Wednesday, March 12, 2014

GSA Publishes Cybersecurity RFI

Today the GSA’s Office of Mission Assurance (OMA) published a request for information (RFI) notice in the Federal Register (79 FR 14042) about recommendations that GSA and DOD have made to the President in response to §8(e) of the President’s Executive Order for Improving Critical Infrastructure Cybersecurity (EO 13636). Long time readers may remember a series of blog posts I did about the GSA’s original RFI that supported the preparations for the report about which this RFI is seeking comments.

The actual DOD/GSA report is on the GSA’ EO 13636 web site.

NOTE: There is a problem with the SSL certificate for this site so it is not a secure web site, even though it has ‘https’ in the URL. The Feds certainly seem to have problems maintaining their certificates. Could this be the sign of a cybersecurity problem???

GSA is seeking comments on the six recommendations made in that report so that they can formulate a plan to go forward. The six recommendations are:

• Institute baseline cybersecurity requirements as a condition of contract award for appropriate acquisitions;
• Address cybersecurity relevant training;
• Develop common cybersecurity definitions for Federal acquisitions;
• Institute a Federal acquisition cyber risk management strategy;
• Include a requirement to purchase from original equipment manufacturers, their authorized resellers, or other ‘trusted’ sources, whenever available, in appropriate acquisitions;
• Increase government accountability for cyber risk management.

Most of these seem to be the cybersecurity equivalent of motherhood and apple pie requirements, but the devil is, of course in the detail. There is a lot of verbiage supporting each of these recommendations that deserve a closer look. I’ll add it to my list of things to look at since this may be a harbinger of cybersecurity requirements in other acquisition processes, in and out of the Federal government.


GSA is soliciting public comments. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # OMA-2014-01). Comments need to be submitted by April 28th, 2014. Please note that that is a short, 45 day comment period.

Saturday, May 11, 2013

Cybersecurity EO and FAR Incentives


The General Services Administration (GSA), in conjunction with the Department of Defense (DOD) published a request for information (RFI) in Monday’s Federal Register (78 FR 27966-27968) concerning the “feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration and address what steps can be taken to harmonize, and make consistent, existing procurement requirements related to cybersecurity”.

JWGICRA

The RFI announces the formation of the Joint Working Group on Improving Cybersecurity and Resilience through Acquisition (JWGICRA). The working group, under the leadership of the GSA, consists of members selected from the DoD, GSA, the Department of Homeland Security (DHS), the Office of Federal Procurement Policy (OFPP), and the National Institute of Standards and Technology (NIST).

The JWGICRA was formed to fulfill the 120-day reporting requirement of §8(e) of the President’s cybersecurity executive order (EO 13636). That report is supposed to address the “feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration”.

Definition of ‘Cybersecurity’

The RFI notes that the lack of a common lexicon is a “ is one of the critical gaps in harmonizing federal acquisition requirements related to cybersecurity”. For the purposes of this notice GSA is using the following definition of cybersecurity:

“(T)he term “cybersecurity” is given a broad meaning that includes information security and related areas, like supply chain risk management, information assurance, and software assurance, as well as other efforts to address threats or vulnerabilities flowing from or enabled by connection to digital infrastructure.”

Given this definition it is clear that industrial control systems (ICS) are included, but mainly as an afterthought.

Information Requested

This GSA RFI is looking for answers to a number of questions in a number of general categories. Those categories include:

• The feasibility of incorporating cybersecurity standards into federal acquisitions;
• Information about commercial procurement practices related to cybersecurity; and
• Information about any conflicts in statutes, regulations, policies, practices, contractual terms and conditions, or acquisition processes affecting federal acquisition requirements related to cybersecurity.

Public Comments

The GSA, on behalf of the JWGICRA, is soliciting public input in this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # Notice-OERR-2013). Comments must be submitted by June 12, 2013.

Commentary

This is a very late solicitation of information. The government has used up 90-days of the 120-day reporting limit working out the details of how the JWGICRA is going to operate. The NIST RFI was published within days of the President’s EO; they only had themselves to work with. The NTA-NIST RFI was almost a month in the making, they both worked for the Secretary of Commerce. Here the GSA was supposed to coordinate actions of the representatives of DOD and DHS in the area of acquisitions. I’m surprised that this was done as soon as it was.

The deadline for submitting comments is the same day that the GSA report is due to the President. Either the GSA is going to be late, ignore the public inputs solicited in this RFA, or is going to have a super human team of bureaucrats read, correlate, digest, compile and prepare a report in less than 24 hours.

I will prophesize that the report will be late and the President won’t even notice. I will assume that the public inputs will be generally ignored. And I will flatly state that making the time limit is bureaucratically impossible. Of course, I was saying this well before the EO was even published.
 
/* Use this with templates/template-twocol.html */