<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803a1dd8">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-09-09</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>39 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-825</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-825</identifier>
<identifier type="local">P0b002ee1803a1dd8</identifier>
<identifier type="former package identifier">f:d08825</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-825</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-825</accessId>
 <reportNumber>GAO-08-825</reportNumber>
 <subject>Access control</subject>
 <subject>Classified defense information</subject>
 <subject>Computer incident response capability</subject>
 <subject>Computer security</subject>
 <subject>Confidential communication</subject>
 <subject>Contingency plans</subject>
 <subject>Critical infrastructure</subject>
 <subject>Critical infrastructure protection</subject>
 <subject>Cyber crimes</subject>
 <subject>Cyber security</subject>
 <subject>Federal agencies</subject>
 <subject>Foreign governments</subject>
 <subject>Homeland security</subject>
 <subject>Information access</subject>
 <subject>Information security</subject>
 <subject>Information technology</subject>
 <subject>Interagency relations</subject>
 <subject>Lessons learned</subject>
 <subject>Private sector</subject>
 <subject>Risk assessment</subject>
 <subject>Risk management</subject>
 <subject>State governments</subject>
 <subject>Strategic planning</subject>
 <subject>Program implementation</subject>
 <subject>DHS Cyber Storm Exercise</subject>
 <type>Other Written Product</type>
 <accountNo>A84203</accountNo>
 <law congress="107" isPrivate="false" number="296"></law>
</extension>
<titleInfo>
 <title>Critical Infrastructure Protection: DHS Needs to Fully Address Lessons Learned from Its First Cyber Storm Exercise</title>
</titleInfo>
<abstract>Federal policies establish the Department of Homeland Security
(DHS) as the focal point for the security of cyberspace. As part 
of its responsibilities, DHS is required to coordinate cyber	 
attack exercises to strengthen public and private incident	 
response capabilities. One major exercise program, called Cyber  
Storm, is a large-scale simulation of multiple concurrent cyber  
attacks involving the federal government, states, foreign	 
governments, and private industry. To date, DHS has conducted	 
Cyber Storm exercises in 2006 and 2008. GAO agreed to (1)	 
identify the lessons that DHS learned from the first Cyber Storm 
exercise, (2) assess DHS&apos;s efforts to address the lessons learned
from this exercise, and (3) identify key participants&apos; views of  
their experiences during the second Cyber Storm exercise. To do  
so, GAO evaluated documentation of corrective activities and	 
interviewed federal, state, and private sector officials.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-825/html/GAOREPORTS-GAO-08-825.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-825/pdf/GAOREPORTS-GAO-08-825.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-825</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-825</url>
</location>
<note>Other Written Product</note>
<extension>
 <searchTitle>GAO-08-825; Critical Infrastructure Protection: DHS Needs to Fully Address Lessons Learned from Its First Cyber Storm Exercise;
            </searchTitle>
</extension>
<subject>
 <topic>Access control</topic>
 <topic>Classified defense information</topic>
 <topic>Computer incident response capability</topic>
 <topic>Computer security</topic>
 <topic>Confidential communication</topic>
 <topic>Contingency plans</topic>
 <topic>Critical infrastructure</topic>
 <topic>Critical infrastructure protection</topic>
 <topic>Cyber crimes</topic>
 <topic>Cyber security</topic>
 <topic>Federal agencies</topic>
 <topic>Foreign governments</topic>
 <topic>Homeland security</topic>
 <topic>Information access</topic>
 <topic>Information security</topic>
 <topic>Information technology</topic>
 <topic>Interagency relations</topic>
 <topic>Lessons learned</topic>
 <topic>Private sector</topic>
 <topic>Risk assessment</topic>
 <topic>Risk management</topic>
 <topic>State governments</topic>
 <topic>Strategic planning</topic>
 <topic>Program implementation</topic>
 <topic>DHS Cyber Storm Exercise</topic>
</subject>
<relatedItem type="isReferencedBy">
 <titleInfo>
  <title>United States Public Law 296 (107th Congress)</title>
</titleInfo>
 <identifier type="public law citation">Public Law 107-296</identifier>
</relatedItem>
</mods>