<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803947e7">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-05-10</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>12 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-171</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-171</identifier>
<identifier type="local">P0b002ee1803947e7</identifier>
<identifier type="former package identifier">f:ai00171t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-171</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-171</accessId>
 <reportNumber>T-AIMD-00-171</reportNumber>
 <subject>Computer networks</subject>
 <subject>Computer security</subject>
 <subject>Computer crimes</subject>
 <subject>Information resources management</subject>
 <subject>Electronic mail</subject>
 <subject>Computer viruses</subject>
 <subject>Internal controls</subject>
 <identifier>Internet</identifier>
 <identifier>Melissa Computer Virus</identifier>
 <identifier>ILOVEYOU Computer Virus</identifier>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Information Security: &quot;ILOVEYOU&quot; Computer Virus Emphasizes</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed the &quot;ILOVEYOU&quot;
computer virus, focusing on the need for agency and governmentwide
improvements in information security.&lt;p/&gt;GAO noted that: (1) ILOVEYOU is both a virus and a worm; (2) the damage
resulting from this particular hybrid is limited to users of the
Microsoft Windows operating system; (3) ILOVEYOU typically comes in the
form of an electronic mail (e-mail) message from someone the recipient
knows; (4) as long as recipients do not run the attached file, their
systems will not be affected and they need only to delete the e-mail and
its attachment; (5) if opened, the ILOVEYOU can spread and infect
systems by sending itself to everyone in the recipient&apos;s address book;
(6) there are areas of management and general control that are integral
to improving problems in information security; (7) most agencies do not
develop security plans for major systems based on risk, have not
formally documented security policies, and have not implemented programs
for testing and evaluating the effectiveness of controls they rely on;
(8) these are fundamental activities that allow an organization to
manage its information security risks cost-effectively rather than by
reacting to individual problems ad hoc; (9) agencies often lack
effective access controls to their computer resources and, as a result,
are unable to protect these assets against unauthorized modification,
loss, and disclosure; (10) these controls would normally include
physical protections such as gates and guards and logical controls,
which are controls built into software that: (a) require users to
authenticate themselves through passwords or other identifiers; and (b)
limit the files and other resources that an authenticated user can
access and the actions that he or she can take; (11) testing procedures
are undisciplined and do not ensure that implemented software operates
as intended, and access to software program libraries is inadequately
controlled; (12) GAO found that computer programmers and operators are
authorized to perform a wide variety of duties; (13) this, in turn,
provides them with the ability to independently modify, circumvent, and
disable system security features; (14) GAO&apos;s reviews frequently identify
systems with insufficiently restricted access to the powerful programs
and sensitive files associated with the computer system&apos;s operation;
(15) such free access makes it possible for knowledgeable individuals to
disable or circumvent controls; (16) service continuity controls are
incomplete and often not fully tested for ensuring that critical
operations can continue when unexpected events occur; and (17) agencies
can act immediately to address computer weaknesses and reduce their
vulnerability to computer attacks.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-171/html/GAOREPORTS-T-AIMD-00-171.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-171/pdf/GAOREPORTS-T-AIMD-00-171.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-171</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-171</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-171; Information Security: &quot;ILOVEYOU&quot; Computer Virus Emphasizes;
            </searchTitle>
</extension>
<subject>
 <topic>Computer networks</topic>
 <topic>Computer security</topic>
 <topic>Computer crimes</topic>
 <topic>Information resources management</topic>
 <topic>Electronic mail</topic>
 <topic>Computer viruses</topic>
 <topic>Internal controls</topic>
 <topic>Internet</topic>
 <topic>Melissa Computer Virus</topic>
 <topic>ILOVEYOU Computer Virus</topic>
</subject>
</mods>