<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18039bac5">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-02-29</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>30 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-280</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-280</identifier>
<identifier type="local">P0b002ee18039bac5</identifier>
<identifier type="former package identifier">f:d08280</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-23</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-280</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-280</accessId>
 <reportNumber>GAO-08-280</reportNumber>
 <subject>Computer systems</subject>
 <subject>Information security</subject>
 <subject>Information security management</subject>
 <subject>Information systems</subject>
 <subject>Internal controls</subject>
 <subject>Securities regulation</subject>
 <subject>Stocks (securities)</subject>
 <subject>System security plans</subject>
 <subject>System vulnerabilities</subject>
 <subject>Systems analysis</subject>
 <subject>Systems evaluation</subject>
 <subject>Systems management</subject>
 <subject>Security standards</subject>
 <subject>GAO High Risk Series</subject>
 <type>Other Written Product</type>
 <accountNo>A81172</accountNo>
 <statuteAtLarge volume="116">
                      <pages pages="2946"></pages>
                </statuteAtLarge>
</extension>
<titleInfo>
 <title>Information Security: Securities and Exchange Commission Needs to Continue to Improve Its Program</title>
</titleInfo>
<abstract>In carrying out its mission to ensure that securities markets are
fair, orderly, and efficiently maintained, the Securities and	 
Exchange Commission (SEC) relies extensively on computerized	 
systems. Integrating effective information security controls into
a layered control strategy is essential to ensure that SEC&apos;s	 
financial and sensitive information are protected from		 
inadvertent or deliberate misuse, disclosure, or destruction. As 
part of its audit of SEC&apos;s fiscal year 2007 financial statements,
GAO assessed (1) the status of SEC&apos;s actions to correct 	 
previously reported information security weaknesses and (2) the  
effectiveness of SEC&apos;s controls for ensuring the confidentiality,
integrity, and availability of its information systems and	 
information. To do this, GAO examined security plans, policies,  
and practices; interviewed pertinent officials; and conducted	 
tests and observations of controls in operation.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-280/html/GAOREPORTS-GAO-08-280.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-280/pdf/GAOREPORTS-GAO-08-280.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-280</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-280</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-08-280; Information Security: Securities and Exchange Commission Needs to Continue to Improve Its Program;
            </searchTitle>
</extension>
<subject>
 <topic>Computer systems</topic>
 <topic>Information security</topic>
 <topic>Information security management</topic>
 <topic>Information systems</topic>
 <topic>Internal controls</topic>
 <topic>Securities regulation</topic>
 <topic>Stocks (securities)</topic>
 <topic>System security plans</topic>
 <topic>System vulnerabilities</topic>
 <topic>Systems analysis</topic>
 <topic>Systems evaluation</topic>
 <topic>Systems management</topic>
 <topic>Security standards</topic>
 <topic>GAO High Risk Series</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Statutes at Large</title>
  <partNumber>Volume 116 Page 2946</partNumber>
</titleInfo>
 <identifier type="Statute citation">116 Stat. 2946</identifier>
</relatedItem>
</mods>