<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803931bd">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-09-06</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>36 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:AIMD-00-295</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-AIMD-00-295</identifier>
<identifier type="local">P0b002ee1803931bd</identifier>
<identifier type="former package identifier">f:ai00295</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-AIMD-00-295</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-AIMD-00-295</accessId>
 <reportNumber>AIMD-00-295</reportNumber>
 <subject>Computer security</subject>
 <subject>Information resources management</subject>
 <subject>Internal controls</subject>
 <subject>Internal audits</subject>
 <subject>Computer crimes</subject>
 <subject>Computer viruses</subject>
 <subject>Computer software</subject>
 <identifier>ILOVEYOU Computer Virus</identifier>
 <identifier>Melissa Computer Virus</identifier>
 <identifier>National Plan for Information Systems Protection</identifier>
 <type>Letter Report</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Information Security: Serious and Widespread Weaknesses</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO reviewed inspectors&apos; general
information security audit findings for 24 federal agencies, focusing
on: (1) information security weaknesses identified in audit reports
issued from July 1999 through August 2000 and GAO&apos;s findings with
similar information that GAO reported in September 1998; (2) weaknesses
and the related risks at selected individual agencies; and (3) the most
significant types of weaknesses in each of six categories of general
controls that GAO used in its analysis.&lt;p/&gt;GAO noted that: (1) evaluations of computer security published since
July 1999 continue to show that federal computer security is fraught
with weaknesses and that, as a result, critical operations and assets
continue to be at risk; (2) as in 1998, GAO&apos;s analysis identified
significant weaknesses in each of the 24 agencies covered by its review;
(3) since July 1999, the range of weaknesses in individual agencies has
broadened, at least in part because the scope of audits being performed
is more comprehensive than in prior years; (4) while these audits are
providing a more complete picture of the security problems agencies
face, they also show that agencies have much work to do to ensure that
their security programs are complete and effective; (5) the weaknesses
identified place a broad array of federal operations and assets at risk
of fraud, misuse, and disruption; (6) for example, weaknesses at the
Department of the Treasury increase the risk of fraud associated with
billions of dollars of federal payments and collections, and weaknesses
at the Department of Defense increase the vulnerability of various
military operations that support the department&apos;s war-fighting
capability; (7) further, information security weaknesses place enormous
amounts of confidential data, ranging from personal and tax data to
proprietary business information, at risk of inappropriate disclosure;
(8) for example, in 1999, a Social Security Administration employee pled
guilty to unauthorized access of the administration&apos;s systems; (9) the
related investigation determined that the employee had made many
unauthorized queries, including obtaining earnings information for
members of the local business community; (10) for most agencies, the
weaknesses reported covered the full range of computer security
controls; (11) security program planning and management were inadequate;
(12) physical and logical access controls also were not effective in
preventing or detecting system intrusions and misuse; (13) software
change controls were ineffective in ensuring that only properly
authorized and tested software programs were implemented; (14) duties
were not adequately segregated to reduce the risk that one individual
could execute unauthorized transactions or software changes without
detection; (15) sensitive operating system software was not adequately
controlled, and adequate steps had not been taken to ensure continuity
of computerized operations; and (16) more needs to be done, especially
in the area of security program planning and management, which involves
instituting routine risk management activities aimed at ensuring that
risks are understood and controls are implemented.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-00-295/html/GAOREPORTS-AIMD-00-295.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-00-295/pdf/GAOREPORTS-AIMD-00-295.pdf</url>
</location>
<identifier type="preferred citation">GAO/AIMD-00-295</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-AIMD-00-295</url>
</location>
<note>Letter Report</note>
<extension>
 <searchTitle>GAO/AIMD-00-295; Information Security: Serious and Widespread Weaknesses;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information resources management</topic>
 <topic>Internal controls</topic>
 <topic>Internal audits</topic>
 <topic>Computer crimes</topic>
 <topic>Computer viruses</topic>
 <topic>Computer software</topic>
 <topic>ILOVEYOU Computer Virus</topic>
 <topic>Melissa Computer Virus</topic>
 <topic>National Plan for Information Systems Protection</topic>
</subject>
</mods>