<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18039d7d1">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2007-06-14</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>10 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-07-899R</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-899R</identifier>
<identifier type="local">P0b002ee18039d7d1</identifier>
<identifier type="former package identifier">f:d07899r</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-07-899R</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-07-899R</accessId>
 <reportNumber>GAO-07-899R</reportNumber>
 <subject>Accountability</subject>
 <subject>Computer security</subject>
 <subject>Databases</subject>
 <subject>Financial statement audits</subject>
 <subject>Information security</subject>
 <subject>Information systems</subject>
 <subject>Internal controls</subject>
 <subject>Public debt</subject>
 <subject>Security assessments</subject>
 <subject>Bureau of the Public Debt Schedule of</subject>
 <subject>Federal Debt</subject>
 <type>Correspondence</type>
 <accountNo>A70749</accountNo>
 <USCode title="31">
                      <section number="720"></section>
                </USCode>
</extension>
<titleInfo>
 <title>Bureau of the Public Debt: Areas for Improvement in Information Security Controls</title>
</titleInfo>
<abstract>In connection with fulfilling our requirement to audit the
financial statements of the U.S. government, we audited and	 
reported on the Schedules of Federal Debt Managed by the Bureau  
of the Public Debt (BPD) for the fiscal years ended September 30,
2006 and 2005. As part of these audits, we performed a review of 
the general and application information security controls over	 
key BPD financial systems. In our audit report on the Schedules  
of Federal Debt for the fiscal years ended September 30, 2006 and
2005, we concluded that BPD maintained, in all material respects,
effective internal control relevant to the Schedule of Federal	 
Debt related to financial reporting and compliance with 	 
applicable laws and regulations as of September 30, 2006, that	 
provided reasonable assurance that misstatements, losses, or	 
noncompliance material in relation to the Schedule of Federal	 
Debt would be prevented or detected on a timely basis. We found  
matters involving information security controls that we do not	 
consider to be reportable conditions but that nevertheless	 
warrant BPD management&apos;s attention and action. BPD mitigated the 
potential effect of such issues with physical security measures, 
a program of monitoring user and system activity, and		 
compensating management and reconciliation controls. This report 
presents the issues identified during our fiscal year 2006	 
testing of the general and application information security	 
controls that support key BPD automated financial systems	 
relevant to BPD&apos;s Schedule of Federal Debt. This report also	 
includes the results of our follow-up on the status of BPD&apos;s	 
corrective actions to address recommendations that were contained
in our prior years&apos; audits and open as of September 30, 2005. In 
a separately issued Limited Official Use Only report, we	 
communicated detailed information regarding our findings to BPD  
management. We also assessed the general and application	 
information security controls over key BPD financial systems that
the Federal Reserve Banks (FRB) maintain and operate on behalf of
BPD. We have communicated the results of such testing to the	 
Board of Governors of the Federal Reserve System.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-899R/html/GAOREPORTS-GAO-07-899R.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-07-899R/pdf/GAOREPORTS-GAO-07-899R.pdf</url>
</location>
<identifier type="preferred citation">GAO-07-899R</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-07-899R</url>
</location>
<note>Correspondence</note>
<extension>
 <searchTitle>GAO-07-899R; Bureau of the Public Debt: Areas for Improvement in Information Security Controls;
            </searchTitle>
</extension>
<subject>
 <topic>Accountability</topic>
 <topic>Computer security</topic>
 <topic>Databases</topic>
 <topic>Financial statement audits</topic>
 <topic>Information security</topic>
 <topic>Information systems</topic>
 <topic>Internal controls</topic>
 <topic>Public debt</topic>
 <topic>Security assessments</topic>
 <topic>Bureau of the Public Debt Schedule of</topic>
 <topic>Federal Debt</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Code</title>
  <partNumber>Title 31 Section 720</partNumber>
</titleInfo>
 <identifier type="USC citation">31 U.S.C. 720</identifier>
</relatedItem>
</mods>