<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803745ee">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-04-02</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>20 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-373R</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-373R</identifier>
<identifier type="local">P0b002ee1803745ee</identifier>
<identifier type="former package identifier">f:d08373r</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-373R</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-373R</accessId>
 <reportNumber>GAO-08-373R</reportNumber>
 <subject>Classified defense information</subject>
 <subject>Confidential communication</subject>
 <subject>Critical infrastructure</subject>
 <subject>Critical infrastructure protection</subject>
 <subject>Defense capabilities</subject>
 <subject>Defense contingency planning</subject>
 <subject>Defense industry</subject>
 <subject>Defense operations</subject>
 <subject>Federal intelligence agencies</subject>
 <subject>Information infrastructure</subject>
 <subject>Military intelligence</subject>
 <subject>Risk assessment</subject>
 <subject>Risk management</subject>
 <subject>Standards</subject>
 <subject>Defense Critical Infrastructure Program</subject>
 <type>Correspondence</type>
 <accountNo>A81555</accountNo>
</extension>
<titleInfo>
 <title>Defense Critical Infrastructure: DOD&apos;s Risk Analysis of Its Critical Infrastructure Omits Highly Sensitive Assets</title>
</titleInfo>
<abstract>The Department of Defense (DOD) relies on a global network of
critical physical and cyber infrastructure to project, support,  
and sustain its forces and operations worldwide. The		 
incapacitation, exploitation, or destruction of one or more of	 
its assets would seriously damage DOD&apos;s ability to carry out its 
core missions. To identify and help assure the availability of	 
this mission-critical infrastructure, in August 2005, DOD	 
established the Defense Critical Infrastructure Program (DCIP),  
assigning overall responsibility for the program to the Assistant
Secretary of Defense for Homeland Defense and Americas&apos; Security 
Affairs (ASD[HD&amp;ASA]). Since 2006, ASD(HD&amp;ASA) has collaborated  
with the Joint Staff to compile a list of all DOD- and		 
non-DOD-owned infrastructure essential to accomplish the National
Defense Strategy. Each critical asset on the list must undergo a 
vulnerability assessment, which identifies weaknesses in relation
to potential threats and suggests options to address those	 
weaknesses. Data and material designated as Sensitive		 
Compartmented Information (SCI) or associated with Special Access
Programs (SAP) are among the nation&apos;s most valued and closely	 
guarded assets, and DOD faces inherent challenges in		 
incorporating them into DCIP. The number of individuals 	 
authorized to access SCI and SAPs is a relatively small subset of
those authorized to access collateral-level classified		 
information--that is, Confidential, Secret, or Top Secret	 
information. Congress requested that GAO review a number of	 
issues related to defense critical infrastructure. To date, GAO  
have issued two reports in response to that request. GAO&apos;s first 
report examined the extent to which DOD had developed a 	 
comprehensive management plan for DCIP and had identified,	 
prioritized, and assessed defense critical infrastructure. GAO&apos;s 
second report examined DOD&apos;s efforts to implement a risk	 
management approach for critical assets in the Defense Industrial
Base Defense Sector. As part of GAO&apos;s ongoing work on DOD&apos;s	 
critical infrastructure protection efforts, this report focuses  
on challenges DOD faces in incorporating critical SCI and SAP	 
assets into DCIP. Specifically, this report evaluates the extent 
to which DOD is (1) identifying and prioritizing critical SCI and
SAP assets in DCIP and (2) assessing critical SCI and SAP assets 
for vulnerabilities in a comprehensive manner consistent with	 
that used by DCIP for collateral-level assets.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-373R/html/GAOREPORTS-GAO-08-373R.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-373R/pdf/GAOREPORTS-GAO-08-373R.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-373R</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-373R</url>
</location>
<note>Correspondence</note>
<extension>
 <searchTitle>GAO-08-373R; Defense Critical Infrastructure: DOD&apos;s Risk Analysis of Its Critical Infrastructure Omits Highly Sensitive Assets;
            </searchTitle>
</extension>
<subject>
 <topic>Classified defense information</topic>
 <topic>Confidential communication</topic>
 <topic>Critical infrastructure</topic>
 <topic>Critical infrastructure protection</topic>
 <topic>Defense capabilities</topic>
 <topic>Defense contingency planning</topic>
 <topic>Defense industry</topic>
 <topic>Defense operations</topic>
 <topic>Federal intelligence agencies</topic>
 <topic>Information infrastructure</topic>
 <topic>Military intelligence</topic>
 <topic>Risk assessment</topic>
 <topic>Risk management</topic>
 <topic>Standards</topic>
 <topic>Defense Critical Infrastructure Program</topic>
</subject>
</mods>