<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803859d4">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2008-06-16</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>9 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:GAO-08-836R</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-836R</identifier>
<identifier type="local">P0b002ee1803859d4</identifier>
<identifier type="former package identifier">f:d08836r</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-GAO-08-836R</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-GAO-08-836R</accessId>
 <reportNumber>GAO-08-836R</reportNumber>
 <subject>Access control</subject>
 <subject>Accountability</subject>
 <subject>Computer security</subject>
 <subject>Federal debt</subject>
 <subject>Federal regulations</subject>
 <subject>Federal reserve banks</subject>
 <subject>Financial management</subject>
 <subject>Financial management systems</subject>
 <subject>Financial records</subject>
 <subject>Financial statement audits</subject>
 <subject>Financial statements</subject>
 <subject>Information access</subject>
 <subject>Information management</subject>
 <subject>Information security</subject>
 <subject>Information security management</subject>
 <subject>Information security regulations</subject>
 <subject>Information systems</subject>
 <subject>Internal controls</subject>
 <subject>Physical security</subject>
 <subject>Reporting requirements</subject>
 <subject>Risk factors</subject>
 <subject>Risk management</subject>
 <subject>System software</subject>
 <subject>Security standards</subject>
 <subject>Bureau of the Public Debt Schedule of</subject>
 <subject>Federal Debt</subject>
 <type>Correspondence</type>
 <accountNo>A82364</accountNo>
</extension>
<titleInfo>
 <title>Federal Reserve Banks: Areas for Improvement in Information Security Controls</title>
</titleInfo>
<abstract>In connection with fulfilling our requirement to audit the
financial statements of the U.S. government, we audited and	 
reported on the Schedules of Federal Debt Managed by the Bureau  
of the Public Debt (BPD) for the fiscal years ended September 30,
2007 and 2006. As part of these audits, we performed a review of 
the general and application information security controls over	 
key financial systems maintained and operated by the Federal	 
Reserve Banks (FRBs) on behalf of the Department of the 	 
Treasury&apos;s BPD relevant to the Schedule of Federal Debt. In our  
audit report on the Schedules of Federal Debt for the fiscal	 
years ended September 30, 2007 and 2006, we concluded that BPD	 
maintained, in all material respects, effective internal control 
relevant to the Schedule of Federal Debt related to financial	 
reporting and compliance with applicable laws and regulations as 
of September 30, 2007, that provided reasonable assurance that	 
misstatements, losses, or noncompliance material in relation to  
the Schedule of Federal Debt would be prevented or detected on a 
timely basis. However, we found matters involving information	 
security controls that we do not consider to be significant	 
deficiencies. As it relates to controls over financial reporting 
and compliance with applicable laws and regulations, the	 
potential effect of such control deficiencies was mitigated by	 
the FRBs and BPD. The FRBs mitigated the potential effect of such
control deficiencies with physical security measures and a	 
program of monitoring user and system activity, and BPD with	 
compensating management and reconciliation controls.		 
Nevertheless, the matters relating to key financial systems	 
maintained and operated by the FRBs on behalf of BPD warrant FRB 
management&apos;s attention and action. This report presents the	 
control deficiencies identified during our fiscal year 2007	 
testing of the general and application information security	 
controls over key financial systems maintained and operated by	 
the FRBs on behalf of the Department of theTreasury&apos;s BPD	 
relevant to the Schedule of Federal Debt. In a separately issued 
Limited Official Use Only report, we communicated detailed	 
information regarding our findings to FRB management.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-836R/html/GAOREPORTS-GAO-08-836R.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-08-836R/pdf/GAOREPORTS-GAO-08-836R.pdf</url>
</location>
<identifier type="preferred citation">GAO-08-836R</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-GAO-08-836R</url>
</location>
<note>Correspondence</note>
<extension>
 <searchTitle>GAO-08-836R; Federal Reserve Banks: Areas for Improvement in Information Security Controls;
            </searchTitle>
</extension>
<subject>
 <topic>Access control</topic>
 <topic>Accountability</topic>
 <topic>Computer security</topic>
 <topic>Federal debt</topic>
 <topic>Federal regulations</topic>
 <topic>Federal reserve banks</topic>
 <topic>Financial management</topic>
 <topic>Financial management systems</topic>
 <topic>Financial records</topic>
 <topic>Financial statement audits</topic>
 <topic>Financial statements</topic>
 <topic>Information access</topic>
 <topic>Information management</topic>
 <topic>Information security</topic>
 <topic>Information security management</topic>
 <topic>Information security regulations</topic>
 <topic>Information systems</topic>
 <topic>Internal controls</topic>
 <topic>Physical security</topic>
 <topic>Reporting requirements</topic>
 <topic>Risk factors</topic>
 <topic>Risk management</topic>
 <topic>System software</topic>
 <topic>Security standards</topic>
 <topic>Bureau of the Public Debt Schedule of</topic>
 <topic>Federal Debt</topic>
</subject>
</mods>