<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18037dfef">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-03-12</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>35 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-571T</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-571T</identifier>
<identifier type="local">P0b002ee18037dfef</identifier>
<identifier type="former package identifier">f:d08571t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-23</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-571T</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-571T</accessId>
 <reportNumber>GAO-08-571T</reportNumber>
 <subject>Access control</subject>
 <subject>Computer systems</subject>
 <subject>Cyber security</subject>
 <subject>Data integrity</subject>
 <subject>Federal agencies</subject>
 <subject>Federal law</subject>
 <subject>Government information</subject>
 <subject>Government information dissemination</subject>
 <subject>Information disclosure</subject>
 <subject>Information infrastructure</subject>
 <subject>Information management</subject>
 <subject>Information security</subject>
 <subject>Information security management</subject>
 <subject>Information systems</subject>
 <subject>Information technology</subject>
 <subject>Internal controls</subject>
 <subject>Performance measures</subject>
 <subject>Policy evaluation</subject>
 <subject>Program evaluation</subject>
 <subject>Reporting requirements</subject>
 <subject>Risk assessment</subject>
 <subject>Risk management</subject>
 <subject>Systems evaluation</subject>
 <subject>Systems integrity</subject>
 <subject>Systems testing</subject>
 <subject>Program implementation</subject>
 <subject>GAO High Risk Series</subject>
 <type>Testimony</type>
 <accountNo>A81297</accountNo>
 <law congress="107" isPrivate="false" number="347"></law>
 <statuteAtLarge volume="116">
                      <pages pages="2899"></pages>
                </statuteAtLarge>
</extension>
<titleInfo>
 <title>Information Security: Progress Reported, but Weaknesses at Federal Agencies Persist</title>
</titleInfo>
<abstract>Information security is especially important for federal
agencies, where the public&apos;s trust is essential and poor	 
information security can have devastating consequences. Since	 
1997, GAO has identified information security as a governmentwide
high-risk issue in each of our biennial reports to Congress.	 
Concerned by reports of significant weaknesses in federal	 
computer systems, Congress passed the Federal Information	 
Security Management Act (FISMA) of 2002, which permanently	 
authorized and strengthened information security program,	 
evaluation, and annual reporting requirements for federal	 
agencies. GAO was asked to testify on the current state of	 
federal information security and compliance with FISMA. This	 
testimony summarizes (1) the status of agency performance of	 
information security control activities as reported by major	 
agencies and their inspectors general (IG), (2) the effectiveness
of information security at federal agencies, and (3)		 
opportunities to improve federal information security. In	 
preparing for this testimony, GAO analyzed agency, IG, Office of 
Management and Budget (OMB), and GAO reports on information	 
security and reviewed OMB FISMA reporting instructions, 	 
information technology security guidance, and information on	 
reported security incidents.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-571T/html/GAOREPORTS-GAO-08-571T.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-571T/pdf/GAOREPORTS-GAO-08-571T.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-571T</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-571T</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO-08-571T; Information Security: Progress Reported, but Weaknesses at Federal Agencies Persist;
            </searchTitle>
</extension>
<subject>
 <topic>Access control</topic>
 <topic>Computer systems</topic>
 <topic>Cyber security</topic>
 <topic>Data integrity</topic>
 <topic>Federal agencies</topic>
 <topic>Federal law</topic>
 <topic>Government information</topic>
 <topic>Government information dissemination</topic>
 <topic>Information disclosure</topic>
 <topic>Information infrastructure</topic>
 <topic>Information management</topic>
 <topic>Information security</topic>
 <topic>Information security management</topic>
 <topic>Information systems</topic>
 <topic>Information technology</topic>
 <topic>Internal controls</topic>
 <topic>Performance measures</topic>
 <topic>Policy evaluation</topic>
 <topic>Program evaluation</topic>
 <topic>Reporting requirements</topic>
 <topic>Risk assessment</topic>
 <topic>Risk management</topic>
 <topic>Systems evaluation</topic>
 <topic>Systems integrity</topic>
 <topic>Systems testing</topic>
 <topic>Program implementation</topic>
 <topic>GAO High Risk Series</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Statutes at Large</title>
  <partNumber>Volume 116 Page 2899</partNumber>
</titleInfo>
 <identifier type="Statute citation">116 Stat. 2899</identifier>
</relatedItem>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 347 (107th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 107-347</identifier>
</relatedItem>
</mods>