<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18038e44c">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2007-04-30</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>78 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-07-657</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-657</identifier>
<identifier type="local">P0b002ee18038e44c</identifier>
<identifier type="former package identifier">f:d07657</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-23</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-07-657</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-07-657</accessId>
 <reportNumber>GAO-07-657</reportNumber>
 <subject>Computer security</subject>
 <subject>Computer security incidents</subject>
 <subject>Identity theft</subject>
 <subject>Information security</subject>
 <subject>Information technology</subject>
 <subject>Larceny</subject>
 <subject>Lessons learned</subject>
 <subject>Monitoring</subject>
 <subject>Policy evaluation</subject>
 <subject>Privacy law</subject>
 <subject>Right of privacy</subject>
 <subject>Security policies</subject>
 <type>Other Written Product</type>
 <accountNo>A68865</accountNo>
 <law congress="109" isPrivate="false" number="461"></law>
</extension>
<titleInfo>
 <title>Privacy: Lessons Learned about Data Breach Notification</title>
</titleInfo>
<abstract>A May 2006 data breach at the Department of Veterans Affairs (VA)
and other similar incidents since then have heightened awareness 
of the importance of protecting computer equipment containing	 
personally identifiable information and responding effectively to
a breach that poses privacy risks. GAO&apos;s objective was to	 
identify lessons learned from the VA data breach and other	 
similar federal data breaches regarding effectively notifying	 
government officials and affected individuals about data	 
breaches. To address this objective, GAO analyzed documentation  
and interviewed officials at VA and five other agencies regarding
their responses to data breaches and their progress in		 
implementing standardized data breach notification procedures.	 
The cases at the other agencies were chosen because, like the VA 
case, they involved loss or theft of computing equipment and	 
relatively large numbers of affected individuals (10,000 or	 
more).</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-657/html/GAOREPORTS-GAO-07-657.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-657/pdf/GAOREPORTS-GAO-07-657.pdf</url>
</location>
<identifier type="preferred citation">GAO-07-657</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-657</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-07-657; Privacy: Lessons Learned about Data Breach Notification;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Computer security incidents</topic>
 <topic>Identity theft</topic>
 <topic>Information security</topic>
 <topic>Information technology</topic>
 <topic>Larceny</topic>
 <topic>Lessons learned</topic>
 <topic>Monitoring</topic>
 <topic>Policy evaluation</topic>
 <topic>Privacy law</topic>
 <topic>Right of privacy</topic>
 <topic>Security policies</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 461 (109th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 109-461</identifier>
</relatedItem>
</mods>