<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee180387820">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2001-08-13</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-01-751</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-751</identifier>
<identifier type="local">P0b002ee180387820</identifier>
<identifier type="former package identifier">f:d01751</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-01-751</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-01-751</accessId>
 <reportNumber>GAO-01-751</reportNumber>
 <subject>Computer security</subject>
 <subject>Information resources management</subject>
 <subject>Information systems</subject>
 <subject>Internet</subject>
 <subject>National Plan for Information Systems</subject>
 <subject>Protection</subject>
 <type>Other Written Product</type>
 <accountNo>A01555</accountNo>
 <law congress="99" isPrivate="false" number="74"></law>
</extension>
<titleInfo>
 <title>Information Security: Weaknesses Place Commerce Data and Operations at Serious Risk</title>
</titleInfo>
<abstract>The Department of Commerce generates and disseminates important
economic information that is of paramount interest to U.S.	 
businesses, policymakers, and researchers. The dramatic rise in  
the number and sophistication of cyberattacks on federal	 
information systems is of growing concern. This report provides a
general summary of the computer security weaknesses in the	 
unclassified information systems of seven Commerce organizations 
as well as in the management of the department&apos;s information	 
security program. The significant and persuasive weaknesses in	 
the seven Commerce bureaus place the data and operations of these
bureaus at serious risk. Sensitive economic, personnel, 	 
financial, and business confidential information is exposed,	 
allowing potential intruders to read, copy, modify, or delete	 
these data. Moreover, critical operations could effectively cease
in the event of accidental or malicious service disruptions. Poor
detection and response capabilities exacerbate the bureaus&apos;	 
vulnerability to intrusions. As demonstrated during GAO&apos;s	 
testing, the bureaus&apos; general inability to notice GAO&apos;s 	 
activities increases the likelihood that intrusions will not be  
detected in time to prevent or minimize damage. These weaknesses 
are attributable to the lack of an effective information security
program with a lack of centralized management, a risk-based	 
approach, up-to-date security policies, security awareness and	 
training, and continuous monitoring of the bureaus&apos; compliance	 
with established policies and the effectiveness of implemented	 
controls. These weaknesses are exacerbated by Commerce&apos;s highly  
interconnected computing environment. A compromise in a single	 
poorly secured system can undermine the security of the multiple 
systems that connect to it.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-01-751/html/GAOREPORTS-GAO-01-751.htm</url>
</location>
<identifier type="preferred citation">GAO-01-751</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-01-751</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-01-751; Information Security: Weaknesses Place Commerce Data and Operations at Serious Risk;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information resources management</topic>
 <topic>Information systems</topic>
 <topic>Internet</topic>
 <topic>National Plan for Information Systems</topic>
 <topic>Protection</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 74 (99th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 99-74</identifier>
</relatedItem>
</mods>