<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee180376270">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2002-05-02</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-02-677T</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-02-677T</identifier>
<identifier type="local">P0b002ee180376270</identifier>
<identifier type="former package identifier">f:d02677t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-02-677T</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-02-677T</accessId>
 <reportNumber>GAO-02-677T</reportNumber>
 <subject>Computer security</subject>
 <subject>Information resources management</subject>
 <subject>Proposed legislation</subject>
 <subject>Reporting requirements</subject>
 <type>Testimony</type>
 <accountNo>A03228</accountNo>
 <law congress="106" isPrivate="false" number="398"></law>
</extension>
<titleInfo>
 <title>Information Security: Comments on the Proposed Federal Information Security Management Act of 2002</title>
</titleInfo>
<abstract>The Federal Information Security Management Act of 2002
reauthorizes and expands the information security, evaluation,	 
and reporting requirements enacted in the National Defense	 
Authorization Act for Fiscal Year 2001. Concerned that pervasive 
information security weaknesses place federal operations at	 
significant risk of disruption, tampering, fraud, and		 
inappropriate disclosures of sensitive information, Congress	 
enacted the Government Security Reform provisions (GISRA) for	 
more effective oversight. The Federal Information Security	 
Management Act also changes and clarifies information security	 
issues noted in the first-year implementation of GISRA. In	 
particular, the bill requires the development, promulgation of,  
and compliance with minimum mandatory management controls for	 
securing information and information systems; requires annual	 
agency reporting to both the Office of Management and Budget and 
the Comptroller General; and defines the evaluation		 
responsibilities for national security systems. To ensure that	 
information security receives appropriate attention and resources
and that known deficiencies are addressed, it will be necessary  
to delineate the roles and responsibilities of the numerous	 
entities involved; obtain adequate technical expertise to select,
implement, and maintain controls; and allocate enough agency	 
resources for information security.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-02-677T/html/GAOREPORTS-GAO-02-677T.htm</url>
</location>
<identifier type="preferred citation">GAO-02-677T</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-02-677T</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO-02-677T; Information Security: Comments on the Proposed Federal Information Security Management Act of 2002;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information resources management</topic>
 <topic>Proposed legislation</topic>
 <topic>Reporting requirements</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 398 (106th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 106-398</identifier>
</relatedItem>
</mods>