<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18037e1f4">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2007-08-31</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>47 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-07-528</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-528</identifier>
<identifier type="local">P0b002ee18037e1f4</identifier>
<identifier type="former package identifier">f:d07528</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-07-528</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-07-528</accessId>
 <reportNumber>GAO-07-528</reportNumber>
 <subject>Computer security</subject>
 <subject>Employee training</subject>
 <subject>Information security</subject>
 <subject>Information systems</subject>
 <subject>Internal controls</subject>
 <subject>Testing</subject>
 <subject>Reporting requirements</subject>
 <subject>Risk management</subject>
 <subject>Government agency oversight</subject>
 <subject>Program implementation</subject>
 <type>Other Written Product</type>
 <accountNo>A75567</accountNo>
 <law congress="107" isPrivate="false" number="347"></law>
</extension>
<titleInfo>
 <title>Information Security: Selected Departments Need to Address Challenges in Implementing Statutory Requirements</title>
</titleInfo>
<abstract>The Federal Information Security Management Act of 2002 (FISMA)
strengthened security requirements by, among other things,	 
requiring federal agencies to establish programs to provide	 
cost-effective security for information and information systems. 
In overseeing FISMA implementation, the Office of Management and 
Budget (OMB) has established supporting processes and reporting  
requirements. However, 4 years into implementation of the act,	 
agencies have not yet fully implemented key provisions. In this  
context, GAO determined what challenges or obstacles inhibit the 
implementation of the information security provisions of FISMA at
the Departments of Defense, Homeland Security, Justice, and	 
State. To do this, GAO reviewed and analyzed department policies,
procedures, and reports related to department information	 
security programs and interviewed agency officials.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-528/html/GAOREPORTS-GAO-07-528.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-528/pdf/GAOREPORTS-GAO-07-528.pdf</url>
</location>
<identifier type="preferred citation">GAO-07-528</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-528</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-07-528; Information Security: Selected Departments Need to Address Challenges in Implementing Statutory Requirements;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Employee training</topic>
 <topic>Information security</topic>
 <topic>Information systems</topic>
 <topic>Internal controls</topic>
 <topic>Testing</topic>
 <topic>Reporting requirements</topic>
 <topic>Risk management</topic>
 <topic>Government agency oversight</topic>
 <topic>Program implementation</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 347 (107th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 107-347</identifier>
</relatedItem>
</mods>