<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18039551a">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-02-14</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>33 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-496T</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-496T</identifier>
<identifier type="local">P0b002ee18039551a</identifier>
<identifier type="former package identifier">f:d08496t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-496T</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-496T</accessId>
 <reportNumber>GAO-08-496T</reportNumber>
 <subject>Computer security</subject>
 <subject>Computer systems</subject>
 <subject>Controlled access</subject>
 <subject>Federal agencies</subject>
 <subject>Information security</subject>
 <subject>Information security management</subject>
 <subject>Information security regulations</subject>
 <subject>Internal controls</subject>
 <subject>Policy evaluation</subject>
 <subject>Program evaluation</subject>
 <subject>Program management</subject>
 <subject>Reporting requirements</subject>
 <subject>Risk assessment</subject>
 <subject>Risk management</subject>
 <subject>Systems integrity</subject>
 <subject>Program implementation</subject>
 <subject>GAO High Risk Series</subject>
 <type>Testimony</type>
 <accountNo>A80794</accountNo>
 <law congress="107" isPrivate="false" number="347"></law>
 <statuteAtLarge volume="116">
                      <pages pages="2899"></pages>
                </statuteAtLarge>
</extension>
<titleInfo>
 <title>Information Security: Although Progress Reported, Federal Agencies Need to Resolve Significant Deficiencies</title>
</titleInfo>
<abstract>Information security is especially important for federal
agencies, where the public&apos;s trust is essential and poor	 
information security can have devastating consequences. Since	 
1997, GAO has identified information security as a governmentwide
high-risk issue in each of its biennial reports to the Congress. 
Concerned by reports of significant weaknesses in federal	 
computer systems, Congress passed the Federal Information	 
Security Management Act (FISMA) of 2002, which permanently	 
authorized and strengthened information security program,	 
evaluation, and annual reporting requirements for federal	 
agencies. GAO was asked to testify on the current state of	 
federal information security and compliance with FISMA. This	 
testimony summarizes (1) agency progress in performing key	 
control activities, (2) the effectiveness of information security
at federal agencies, and (3) opportunities to strengthen	 
security. In preparing for this testimony, GAO reviewed prior	 
audit reports; examined federal policies, guidance, and budgetary
documentation; and analyzed agency and inspector general (IG)	 
reports on information security.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-496T/html/GAOREPORTS-GAO-08-496T.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-496T/pdf/GAOREPORTS-GAO-08-496T.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-496T</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-496T</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO-08-496T; Information Security: Although Progress Reported, Federal Agencies Need to Resolve Significant Deficiencies;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Computer systems</topic>
 <topic>Controlled access</topic>
 <topic>Federal agencies</topic>
 <topic>Information security</topic>
 <topic>Information security management</topic>
 <topic>Information security regulations</topic>
 <topic>Internal controls</topic>
 <topic>Policy evaluation</topic>
 <topic>Program evaluation</topic>
 <topic>Program management</topic>
 <topic>Reporting requirements</topic>
 <topic>Risk assessment</topic>
 <topic>Risk management</topic>
 <topic>Systems integrity</topic>
 <topic>Program implementation</topic>
 <topic>GAO High Risk Series</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Statutes at Large</title>
  <partNumber>Volume 116 Page 2899</partNumber>
</titleInfo>
 <identifier type="Statute citation">116 Stat. 2899</identifier>
</relatedItem>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 347 (107th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 107-347</identifier>
</relatedItem>
</mods>