<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18039a106">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2001-09-12</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-01-1067</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-1067</identifier>
<identifier type="local">P0b002ee18039a106</identifier>
<identifier type="former package identifier">f:d011067</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-01-1067</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-01-1067</accessId>
 <reportNumber>GAO-01-1067</reportNumber>
 <subject>Computer security</subject>
 <subject>Financial management</subject>
 <subject>Information systems</subject>
 <subject>Information technology</subject>
 <subject>Internal controls</subject>
 <subject>Dept. of Education Central Automated</subject>
 <subject>Processing System</subject>
 <type>Other Written Product</type>
 <accountNo>A01697</accountNo>
</extension>
<titleInfo>
 <title>Education Information Security: Improvements Made But Control Weaknesses Remain</title>
</titleInfo>
<abstract>The Department of Education places significant reliance on its
Central Automated Processing System (EDCAPS) to support the	 
department&apos;s core financial management information functions,	 
including general ledger and funds management, grant planning and
payment processing, and purchasing and contract management.	 
Education&apos;s Inspector General (IG) has reported serious 	 
information system control weaknesses in this system. Such	 
reported weaknesses in information system controls increased the 
risk of unauthorized access or disruption of services and made	 
Education&apos;s sensitive grant and loan data vulnerable to 	 
inadvertent or deliberate misuse, fraudulent use, improper	 
disclosure, or destruction, which could have occurred without	 
being detected. Education is making progress in correcting	 
security weaknesses identified by the IG and the department has  
taken other actions to improve security. However, GAO identified 
weaknesses that place critical financial and sensitive grant	 
information at risk of unauthorized access and disclosure, and	 
key operations at risk disruption. Specifically, Education did	 
not sufficiently protect its network from unauthorized users,	 
effectively manage user IDs and passwords, appropriately limit	 
access to unauthorized users, effectively maintain system	 
software controls, or routinely monitor user access activity.	 
Further, Education was not providing adequate physical security  
for its computer resources, appropriately segregating all key	 
operations and computer functions, effectively controlling	 
changes to its applications, or fully addressing all aspects of  
its service continuity needs. Education has since corrected some 
of the weaknesses and developed a corrective action plan to	 
address the remaining weaknesses.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-01-1067/html/GAOREPORTS-GAO-01-1067.htm</url>
</location>
<identifier type="preferred citation">GAO-01-1067</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-1067</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-01-1067; Education Information Security: Improvements Made But Control Weaknesses Remain;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Financial management</topic>
 <topic>Information systems</topic>
 <topic>Information technology</topic>
 <topic>Internal controls</topic>
 <topic>Dept. of Education Central Automated</topic>
 <topic>Processing System</topic>
</subject>
</mods>