<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee180395bae">
<name type="corporate">
 <namePart>United States Government Publishing Office</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
  <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
</role>
 <role>
  <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
  <roleTerm authority="marcrelator" type="code">dst</roleTerm>
</role>
</name>
<name type="corporate">
 <namePart>United States</namePart>
 <namePart>Government Accountability Office</namePart>
 <namePart>Accounting and Information Management Division</namePart>
 <role>
  <roleTerm authority="marcrelator" type="text">author</roleTerm>
  <roleTerm authority="marcrelator" type="code">aut</roleTerm>
</role>
 <description>Government Organization</description>
</name>
<typeOfResource>text</typeOfResource>
<genre authority="marcgt">government publication</genre>
<language>
 <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</language>
<extension>
 <collectionCode>GAOREPORTS</collectionCode>
 <category>Legislative Agency Publications</category>
 <waisDatabaseName>gao</waisDatabaseName>
 <branch>legislative</branch>
 <dateIngested>2010-08-12</dateIngested>
</extension>
<originInfo>
 <publisher>U.S. Government Printing Office</publisher>
 <dateIssued encoding="w3cdtf">1999-10-06</dateIssued>
 <issuance>monographic</issuance>
</originInfo>
<physicalDescription>
 <note type="source content type">deposited</note>
 <digitalOrigin>born digital</digitalOrigin>
 <extent>16 p.</extent>
</physicalDescription>
<classification authority="sudocs">GA 1.13:T-AIMD-00-7</classification>
<identifier type="uri">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-7</identifier>
<identifier type="local">P0b002ee180395bae</identifier>
<identifier type="former package identifier">f:ai00007t</identifier>
<recordInfo>
 <recordContentSource authority="marcorg">DGPO</recordContentSource>
 <recordCreationDate encoding="w3cdtf">2010-08-12</recordCreationDate>
 <recordChangeDate encoding="w3cdtf">2011-03-24</recordChangeDate>
 <recordIdentifier source="DGPO">GAOREPORTS-T-AIMD-00-7</recordIdentifier>
 <recordOrigin>machine generated</recordOrigin>
 <languageOfCataloging>
  <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
</languageOfCataloging>
</recordInfo>
<accessCondition type="GPO scope determination">fdlp</accessCondition>
<extension>
 <docClass>REPORT</docClass>
 <accessId>GAOREPORTS-T-AIMD-00-7</accessId>
 <reportNumber>T-AIMD-00-7</reportNumber>
 <subject>Computer security</subject>
 <subject>Hackers</subject>
 <subject>Information systems</subject>
 <subject>Computer crimes</subject>
 <subject>Information resources management</subject>
 <subject>Data encryption</subject>
 <subject>Internal controls</subject>
 <identifier>NIST Federal Computer Incident Response Capability Program</identifier>
 <identifier>Y2K</identifier>
 <type>Testimony</type>
 <seriesAbbrev>AIMD</seriesAbbrev>
</extension>
<titleInfo>
 <title>Critical Infrastructure Protection: Fundamental</title>
</titleInfo>
<abstract>Pursuant to a congressional request, GAO discussed the computer security
aspects of critical infrastructure protection, focusing on federal
agency performance in addressing computer security issues.&lt;p/&gt;GAO noted that: (1) reports issued by GAO and various Inspectors General
over the last 5 years describe persistent computer security weaknesses
that place federal operations at risk of disruption, fraud, and
inappropriate disclosures; (2) GAO&apos;s most recent analysis, of reports
issued during fiscal year 1999, identified significant computer security
weaknesses in 22 of the largest federal agencies; (3) these included
weaknesses in: (a) controls over access to sensitive systems and data;
(b) controls over software development and changes; and (c) continuity
of service plans; (4) this body of audit evidence led GAO, in February
1997 and again in January 1999, to designate information security as a
governmentwide high-risk area in reports to Congress; (5) while a number
of factors have contributed to weak federal information security, the
fundamental underlying problem is poor security program management; (6)
weaknesses continue to surface because agencies have not implemented a
management framework for overseeing information security on an
agencywide and ongoing basis; (7) to provide greater assurance that
critical infrastructure objectives can be met, GAO believes that actions
are needed in seven key areas; (8) it is important that the federal
strategy delineate the roles and responsibilities of the numerous
entities involved in federal information security and related aspects of
critical infrastructure protection; (9) agencies need more specific
guidance on the controls that they need to implement; (10) implementing
such standards for federal agencies would require developing: (a) a
single set of information classification categories for use by all
agencies to define the criticality and sensitivity of the various types
of information they maintain; and (b) minimum mandatory requirements for
protecting information in each classification category; (11) routine
periodic audits must be implemented to allow for meaningful performance
measurement; (12) it is important for agencies to have the technical
expertise they need to select, implement, and maintain controls that
protect their computer systems; (13) agencies must have resources
sufficient to support their computer security and infrastructure
protection activities; and (14) there is a need to more comprehensively
monitor and develop responses to intrusions, viruses, and other
incidents that threaten federal systems.</abstract>
<location>
 <url displayLabel="HTML rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-7/html/GAOREPORTS-T-AIMD-00-7.htm</url>
 <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GAOREPORTS-T-AIMD-00-7/pdf/GAOREPORTS-T-AIMD-00-7.pdf</url>
</location>
<identifier type="preferred citation">GAO/T-AIMD-00-7</identifier>
<location>
 <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GAOREPORTS-T-AIMD-00-7</url>
</location>
<note>Testimony</note>
<extension>
 <searchTitle>GAO/T-AIMD-00-7; Critical Infrastructure Protection: Fundamental;
            </searchTitle>
</extension>
<subject>
 <topic>Computer security</topic>
 <topic>Hackers</topic>
 <topic>Information systems</topic>
 <topic>Computer crimes</topic>
 <topic>Information resources management</topic>
 <topic>Data encryption</topic>
 <topic>Internal controls</topic>
 <topic>NIST Federal Computer Incident Response Capability Program</topic>
 <topic>Y2K</topic>
</subject>
</mods>