<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1803a37fa">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">2000-09-11</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>19 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-314</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-314</identifier>
<identifier type="local">P0b002ee1803a37fa</identifier>
<identifier type="former package identifier">f:ai00314t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-314</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-314</accessId>
 <reportNumber>T-AIMD-00-314</reportNumber>
 <subject>Computer security</subject>
 <subject>Information resources management</subject>
 <subject>Audits</subject>
 <subject>Computer software</subject>
 <subject>Systems analysis</subject>
 <subject>Systems evaluation</subject>
 <subject>Fraud</subject>
 <subject>Internal controls</subject>
 <identifier>Internet</identifier>
 <identifier>ILOVEYOU Computer Virus</identifier>
 <identifier>Melissa Computer Virus</identifier>
 <identifier>Social Security Trust Fund</identifier>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Computer Security: Critical Federal Operations and Assets</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed information security
audits at federal agencies, focusing on: (1) the pervasive weaknesses
that continue since the results of a similar analysis 2 years ago; (2)
the serious risks that these weaknesses pose; and (3) major common
weaknesses that agencies need to address in order to improve their
information security programs.&lt;p/&gt;GAO noted that: (1) evaluations published since July 1999 continue to
show that federal computer systems are riddled with weaknesses that
continue to put critical operations and assets at risk; (2) just as in
1998, weaknesses were reported in all six major areas of general
controls--the policies, procedures, and technical controls that apply to
all or a large segment of an entity&apos;s information systems and help
ensure their proper operation; (3) these weaknesses placed a broad range
of critical operations and assets at risk for fraud, misuse, and
disruption; (4) virtually all federal operations are supported by
automated systems and electronic data, and agencies would find it
difficult, if not impossible, to carry out their missions and account
for their resources without these information assets; (5) hence, the
degree of risk caused by security weaknesses is extremely high; (6) the
nature of agency operations and the related risks vary; (7) each
organization needs a set of management procedures and an organizational
framework for identifying and assessing risk, deciding what policies and
controls are needed, periodically evaluating the effectiveness of these
policies and controls, and acting to address any identified weaknesses;
(8) of the 21 agencies for which security program management was
reviewed, all had deficiencies; (9) access controls were evaluated at
all 24 of the agencies covered by GAO&apos;s analysis, and all were reported
to have significant weaknesses; (10) GAO&apos;s auditors have been
successful, in almost every test, in readily gaining unauthorized access
that would allow intruders to read, modify, or delete data; (11)
weaknesses in software program change controls were identified for 19 of
the 21 agencies where such controls were evaluated; (12) segregation of
duties was evaluated at 20 of the 24 agencies and weaknesses were
identified at 17 of these agencies; (13) weaknesses were identified at
each of the 18 agencies for which operating system controls were
reviewed; (14) service continuity controls were evaluated for 21 of the
24 agencies included in the analysis; and (15) of these 21, weaknesses
were reported for 20 agencies.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-314/html/GAOREPORTS-T-AIMD-00-314.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-314/pdf/GAOREPORTS-T-AIMD-00-314.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-314</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-314</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-314; Computer Security: Critical Federal Operations and Assets;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Information resources management</topic>
 <topic>Audits</topic>
 <topic>Computer software</topic>
 <topic>Systems analysis</topic>
 <topic>Systems evaluation</topic>
 <topic>Fraud</topic>
 <topic>Internal controls</topic>
 <topic>Internet</topic>
 <topic>ILOVEYOU Computer Virus</topic>
 <topic>Melissa Computer Virus</topic>
 <topic>Social Security Trust Fund</topic>
</subject>
</mods>