<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803a3a31">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2001-04-05</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>22 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-01-600T</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-600T</identifier>
<identifier type="local">P0b002ee1803a3a31</identifier>
<identifier type="former package identifier">f:d01600t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-01-600T</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-01-600T</accessId>
 <reportNumber>GAO-01-600T</reportNumber>
 <subject>Computer security</subject>
 <subject>Computer software</subject>
 <subject>Information resources management</subject>
 <subject>Information systems</subject>
 <subject>ILOVEYOU Computer Virus</subject>
 <subject>Melissa Computer Virus</subject>
 <type>Testimony</type>
 <accountNo>A00746</accountNo>
</extension>
<titleInfo>
 <title>Computer Security: Weaknesses Continue to Place Critical Federal Operations and Assets at Risk</title>
</titleInfo>
<abstract>This testimony discusses GAO&apos;s analysis of security audits at
federal agencies. The widespread interconnectivity of computers  
poses significant risks to federal computer systems and the	 
operations and the infrastructures they support. GAO&apos;s		 
evaluations show that federal computer systems are riddled with  
weaknesses that continue to put critical operations and assets at
risk. These weaknesses covered six major areas of general control
(1) security program management, (2) access controls, (3)	 
software development and change controls, (4) segregation of	 
duties, (5) operating systems controls, and (6) service 	 
continuity. Weaknesses in these areas placed a broad range of	 
critical operations and assets at risk for fraud, misuse, and	 
disruption. Federal agencies have taken steps to address these	 
problems and many have good remedial efforts underway. However,  
these efforts will not be fully effective and lasting unless they
are supported by a strong agencywide security management	 
framework. Establishing such as management framework requires	 
that agencies take a comprehensive approach that involves both	 
(1) senior agency program managers who understand which aspects  
of their missions are the most critical and sensitive and (2)	 
technical experts who know the agencies&apos; systems and can suggest 
appropriate technical security control techniques.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-01-600T/html/GAOREPORTS-GAO-01-600T.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-01-600T/pdf/GAOREPORTS-GAO-01-600T.pdf</url>
</location>
<identifier type="preferred citation">GAO-01-600T</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-600T</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO-01-600T; Computer Security: Weaknesses Continue to Place Critical Federal Operations and Assets at Risk;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Computer software</topic>
 <topic>Information resources management</topic>
 <topic>Information systems</topic>
 <topic>ILOVEYOU Computer Virus</topic>
 <topic>Melissa Computer Virus</topic>
</subject>
</mods>