<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803994ae">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">1999-06-08</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>22 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:AIMD-99-161</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-AIMD-99-161</identifier>
<identifier type="local">P0b002ee1803994ae</identifier>
<identifier type="former package identifier">f:aimd9916</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-AIMD-99-161</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-AIMD-99-161</accessId>
 <reportNumber>AIMD-99-161</reportNumber>
 <subject>Computer security</subject>
 <subject>Information systems</subject>
 <subject>Confidential communication</subject>
 <subject>Information resources management</subject>
 <subject>Financial management systems</subject>
 <subject>Internal controls</subject>
 <subject>Veterans benefits</subject>
 <type>Letter Report</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
 <accountNo>D99161</accountNo>
</extension>
<titleInfo>
 <title>VA Information Systems: The Austin Automation Center Has</title>
</titleInfo>
<abstract>Pursuant to a legislative requirement, GAO assessed the effectiveness of
information system general controls at the Department of Veterans
Affairs&apos; (VA) Austin Automation Center (AAC).&lt;p/&gt;GAO noted that: (1) AAC had made substantial progress in correcting
specific computer security weaknesses that GAO identified in its
previous evaluation of information system controls; (2) AAC had
established a solid foundation for its computer security planning and
management program by creating a centralized computer security group,
developing a comprehensive security policy, and promoting security
awareness; (3) however, AAC had not yet established a framework for
continually assessing risks and routinely monitoring and evaluating the
effectiveness of information system controls; (4) GAO also identified
additional computer security weaknesses that increased the risk of
inadvertent or deliberate misuse, fraudulent use, improper disclosure,
and destruction of financial and sensitive veteran medical and benefit
information on AAC systems; (5) an effective computer security planning
and management program would have allowed AAC to identify and correct
the types of additional weaknesses that GAO identified; (6) in addition,
AAC continues to run the risk that unauthorized access may not be
detected because it had not established a program to identify and
investigate unusual or suspicious patterns of successful access to
sensitive data and resources; (7) these weaknesses could also affect
other agencies that depend on AAC information technology services; (8)
AAC was very responsive to addressing new security exposures identified
and corrected several weaknesses before GAO&apos;s fieldwork was completed;
(9) the Acting Assistant Secretary for Information Technology said VA
would implement all of GAO&apos;s recommendations by September 30, 1999; and
(10) addressing the remaining issues will help ensure that an effective
computer security environment is achieved and maintained.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-99-161/html/GAOREPORTS-AIMD-99-161.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-AIMD-99-161/pdf/GAOREPORTS-AIMD-99-161.pdf</url>
</location>
<identifier type="preferred citation">GAO/AIMD-99-161</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-AIMD-99-161</url>
</location>
<note>Letter Report</note>
<extension>
 <searchTitle>GAO/AIMD-99-161; VA Information Systems: The Austin Automation Center Has;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information systems</topic>
 <topic>Confidential communication</topic>
 <topic>Information resources management</topic>
 <topic>Financial management systems</topic>
 <topic>Internal controls</topic>
 <topic>Veterans benefits</topic>
</subject>
</mods>