<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803a1f85">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-03-29</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>14 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-135</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-135</identifier>
<identifier type="local">P0b002ee1803a1f85</identifier>
<identifier type="former package identifier">f:ai00135t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-23</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-135</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-135</accessId>
 <reportNumber>T-AIMD-00-135</reportNumber>
 <subject>Computer security</subject>
 <subject>Computer software verification and validation</subject>
 <subject>Information resources management</subject>
 <subject>Internal controls</subject>
 <subject>Classified information</subject>
 <subject>Strategic information systems planning</subject>
 <subject>Security classification (government documents)</subject>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Federal Information Security: Actions Needed to Address</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed federal information
security, focusing on actions federal agencies can take immediately to
strengthen their security programs as well as other actions required to
make more fundamental and long-term improvements.&lt;p/&gt;GAO noted that: (1) federal agencies can act immediately to address
federal information security weaknesses and reduce the related risks;
(2) specifically, they can: (a) increase awareness; (b) ensure that
existing controls are operating effectively; (c) ensure that software
patches are up-to-date; (d) use automated scanning and testing tools to
quickly identify problems; (e) propagate their best practices; and (f)
ensure that their most common vulnerabilities are addressed; (3) none of
these actions alone will ensure good security; (4) however, they take
advantage of readily available information and tools and, thus, do not
involve significant new resources; and (5) as a result, they are steps
that can be made without delay.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-135/html/GAOREPORTS-T-AIMD-00-135.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-135/pdf/GAOREPORTS-T-AIMD-00-135.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-135</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-135</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-135; Federal Information Security: Actions Needed to Address;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Computer software verification and validation</topic>
 <topic>Information resources management</topic>
 <topic>Internal controls</topic>
 <topic>Classified information</topic>
 <topic>Strategic information systems planning</topic>
 <topic>Security classification (government documents)</topic>
</subject>
</mods>