<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee18039d3c0">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-06-22</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>14 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-229</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-229</identifier>
<identifier type="local">P0b002ee18039d3c0</identifier>
<identifier type="former package identifier">f:ai00229t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-28</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-229</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-229</accessId>
 <reportNumber>T-AIMD-00-229</reportNumber>
 <subject>Computer security</subject>
 <subject>Information systems</subject>
 <subject>Data collection</subject>
 <subject>Internal controls</subject>
 <subject>Proposed legislation</subject>
 <subject>Joint ventures</subject>
 <subject>Interagency relations</subject>
 <subject>Private sector</subject>
 <subject>Information resources management</subject>
 <identifier>ILOVEYOU Computer Virus</identifier>
 <identifier>Y2K</identifier>
 <identifier>NIST Federal Computer Incident Response Capability Program</identifier>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Critical Infrastructure Protection: Comments on the</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed the proposed Cyber
Security Information Act of 2000 (H.R. 4246), focusing on how it can
enhance critical infrastructure protection and the formidable challenges
involved with achieving the goals of the bill.&lt;p/&gt;GAO noted that: (1) by removing key barriers that are precluding private
industry from sharing information about infrastructure threats and
vulnerabilities, H.R. 4246 can help build the meaningful private-public
partnerships that are integral to protecting critical infrastructure
assets; (2) however, to successfully engage the private sector, the
federal government itself must be a model of good information security;
(3) currently, it is not; (4) significant computer security
weaknesses--ranging from poor controls over access to sensitive systems
and data, to poor control over software development and changes, to
nonexistent or weak continuity of service plans--pervade virtually every
major agency; (5) and, as illustrated by the recent ILOVEYOU computer
virus, mechanisms already in place to facilitate information sharing
among federal agencies about impeding threats and vulnerabilities have
not been working effectively; and (6) moreover, the federal government
may not yet have the right tools for identifying, analyzing,
coordinating, and disseminating the type of information that H.R. 4246
envisions collecting from the private sector.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-229/html/GAOREPORTS-T-AIMD-00-229.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-229/pdf/GAOREPORTS-T-AIMD-00-229.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-229</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-229</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-229; Critical Infrastructure Protection: Comments on the;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information systems</topic>
 <topic>Data collection</topic>
 <topic>Internal controls</topic>
 <topic>Proposed legislation</topic>
 <topic>Joint ventures</topic>
 <topic>Interagency relations</topic>
 <topic>Private sector</topic>
 <topic>Information resources management</topic>
 <topic>ILOVEYOU Computer Virus</topic>
 <topic>Y2K</topic>
 <topic>NIST Federal Computer Incident Response Capability Program</topic>
</subject>
</mods>